- 1. Introduction
- 2. Data Collection
- 3. Data Usage
- 4. Data Sharing with Third Parties
- 5. Cookies Policy
- 6. Data Retention
- 7. Your Data Rights
- 8. Security Measures
- 9. Contact Details for Data Requests
- 10. GDPR Compliance for Netherlands Players
- 11. Special Categories of Data
- 12. Additional Provisions
- 13. Conclusion
- Information We Collect
- How We Use It
- Data Security
- Your Rights
1. Introduction
Carlospin Online Casino ("we," "us," "our," or "Company") is committed to protecting your privacy and ensuring you have a positive experience on our platform. This Privacy Policy outlines how we collect, use, disclose, and safeguard your personal information when you visit our website, use our services, and engage in online gambling activities.
Please read this Privacy Policy carefully. If you do not agree with our data practices, please do not use our platform. We reserve the right to update this policy periodically, and we will notify you of any material changes via email or prominent notice on our website.
2. Data Collection
2.1 What Personal Data We Collect
Carlospin collects various categories of personal information to provide our services effectively:
Account Registration Data:
- Full legal name
- Date of birth
- Email address
- Phone number
- Physical address
- Username and password
- Gender
- Preferred language
Financial Information:
- Bank account details
- Credit card information
- Debit card details
- Digital wallet information
- Payment transaction history
- Deposit and withdrawal records
Identification and Verification Data:
- Government-issued identification numbers (passport, driver's license, national ID)
- Proof of address documents
- Copies of identity documents
- Facial recognition data for identity verification purposes
Behavioral and Gaming Data:
- Gaming history and preferences
- Betting patterns and wagering amounts
- Game participation records
- Login times and frequency
- Device and browser information
- IP addresses
- Geolocation data
Communication Data:
- Customer support inquiries and responses
- Marketing communication preferences
- Survey responses
- Feedback and complaints
Technical Data:
- Cookie identifiers
- Session information
- Device type and operating system
- Internet service provider information
- Referral sources
2.2 Why We Collect This Data
We collect personal data for several legitimate business purposes:
Legal and Regulatory Compliance:
- Compliance with gambling licensing requirements from regulatory bodies in jurisdictions where we operate
- Anti-money laundering (AML) and know-your-customer (KYC) verification
- Prevention of fraud and illegal activities
- Responsible gambling compliance
Service Delivery:
- Creating and managing your player account
- Processing deposits and withdrawals
- Delivering gaming services and features
- Managing player balances and transactions
- Providing customer support and assistance
Security and Fraud Prevention:
- Detecting and preventing fraudulent activities
- Protecting against unauthorized access
- Verifying player identity
- Monitoring suspicious gaming patterns
- Protecting our platform and other players
Marketing and Business Development:
- Sending promotional offers and bonuses (with your consent)
- Conducting marketing campaigns
- Analyzing player preferences
- Improving our services and user experience
- Developing new features and games
2.3 How We Collect Data
Direct Collection:
- Information you voluntarily provide during registration and account setup
- Data submitted through account verification processes
- Information shared during customer support interactions
- Payment information provided during deposit processes
Automatic Collection:
- Cookies and similar tracking technologies
- Server logs and analytics tools
- Device identifiers and hardware information
- Geolocation services
- Web beacons and pixel tracking
Third-Party Sources:
- Credit reference agencies for verification purposes
- Identity verification service providers
- Payment processors and financial institutions
- Affiliate and referral partners
- Marketing data providers
3. Data Usage
3.1 Primary Uses of Your Data
Your personal information is utilized for:
- Account creation, management, and authentication
- Processing financial transactions and payments
- Verifying your identity and age (ensuring you're at least 18 years old)
- Complying with legal obligations and regulatory requirements
- Providing customer service and technical support
- Sending account notifications and updates
- Delivering promotional content and special offers
- Analyzing player behavior to improve our services
- Conducting internal analytics and business intelligence
- Preventing fraud and criminal activity
- Enforcing our Terms and Conditions
- Protecting the rights, property, and safety of our company, players, and public
3.2 Legal Basis for Processing
Under GDPR and applicable privacy laws, our legal basis for processing personal data includes:
- Contract Performance: Processing is necessary to execute our service agreement with you
- Legal Obligation: We must process certain data for compliance with gambling regulations and AML/KYC requirements
- Legitimate Interest: We process data to operate our business securely and prevent fraud
- Consent: We obtain explicit consent for marketing communications and certain tracking activities
- Vital Interest: Protection of health and safety in urgent situations
4. Data Sharing with Third Parties
4.1 Parties We Share Data With
Carlospin shares personal information with carefully selected third parties:
Payment Processors and Financial Institutions:
- Payment gateway providers
- Bank partners for transaction processing
- Credit card networks
- Digital wallet operators
Regulatory and Legal Authorities:
- Gambling licensing authorities and commissions
- Government agencies for AML/KYC compliance
- Law enforcement agencies when legally required
- Tax authorities for reporting obligations
Verification and Compliance Service Providers:
- Identity verification companies
- Credit reference agencies
- Background check services
- Age verification providers
Technical Service Providers:
- Web hosting and cloud infrastructure providers
- Analytics and reporting tools
- Customer relationship management (CRM) systems
- Customer support platform providers
- Cybersecurity and fraud prevention services
Marketing Partners:
- Affiliate marketing networks (when applicable)
- Email marketing service providers
- Advertising partners (only with your consent)
- Analytics companies
Other Third Parties:
- Professional advisors (lawyers, accountants, auditors)
- Insurance providers
- Business partners and operators
- Potential acquirers in case of merger or acquisition
4.2 Data Sharing Restrictions
We impose strict contractual obligations on all third parties regarding data protection, requiring them to:
- Process data only as instructed by Carlospin
- Maintain confidentiality and security
- Comply with applicable privacy laws
- Not use data for their own marketing purposes without consent
- Delete or return data upon request
- Report any data breaches immediately
5. Cookies Policy
5.1 What Are Cookies
Cookies are small text files stored on your device that help us recognize you and enhance your experience on Carlospin.
5.2 Types of Cookies We Use
Essential Cookies:
- Session management and authentication
- Security and fraud prevention
- Platform functionality and stability
- These cookies are necessary for our service and cannot be disabled
Performance and Analytics Cookies:
- Track website performance and user behavior
- Measure page load times and error rates
- Understand how players interact with our platform
- Improve service quality and user experience
Marketing and Advertising Cookies:
- Enable targeted advertising
- Track conversion rates
- Measure marketing campaign effectiveness
- Remember your preferences for promotional content
Social Media Cookies:
- Allow integration with social media platforms
- Enable social sharing features
- Track social media referrals
5.3 Cookie Management
You can control cookie preferences through your browser settings, though disabling certain cookies may affect website functionality. Most browsers allow you to:
- Accept or reject cookies
- Delete existing cookies
- Receive alerts when cookies are placed
- Set preferences for specific websites
Popular browsers provide cookie management through:
- Chrome: Settings > Privacy and Security > Cookies
- Firefox: Preferences > Privacy & Security > Cookies
- Safari: Preferences > Privacy > Manage Website Data
- Edge: Settings > Privacy > Cookies
5.4 Third-Party Cookies
Some third-party partners may place cookies on your device for analytics and marketing purposes. You can opt out of many third-party cookies through industry opt-out tools like the Network Advertising Initiative (NAI) or Digital Advertising Alliance (DAA).
6. Data Retention
6.1 Retention Periods
Carlospin retains personal data for periods determined by regulatory requirements, business necessity, and applicable law:
Account and Transaction Data:
- Maintained for the duration of your player account
- Retained for minimum 5-7 years after account closure for regulatory and AML compliance purposes
- Financial transaction records kept according to tax and financial regulations
Identity Verification Documents:
- Retained for minimum 5 years after account closure
- Longer periods may apply based on regulatory requirements in your jurisdiction
Marketing Data:
- Retained until you unsubscribe from communications
- Deleted upon request or after 2 years of inactivity (where permitted by law)
Technical and Analytical Data:
- Server logs retained for 1 year
- Cookies deleted according to your browser settings and our cookie policy
- Analytics data aggregated after 12-18 months
Customer Support Records:
- Maintained for 3 years or longer if disputes are unresolved
- Extended retention for complaints and investigations
6.2 Data Deletion Procedures
Upon account closure or data subject request, we securely delete personal data in accordance with:
- Applicable privacy laws and regulations
- Regulatory retention requirements
- Legitimate business needs
- Technical feasibility considerations
7. Your Data Rights
7.1 Access to Your Data
Right to Access:
You have the right to request and obtain a copy of all personal data we hold about you. This includes:
- Complete data inventory
- Purposes of processing
- Recipients of your data
- Data retention periods
- Your rights regarding the data
Submit access requests through:
- Your Carlospin account dashboard (privacy settings)
- Email to [email protected]
- Written request to our registered office
We will respond within 30 days of receiving a verifiable request.
7.2 Right to Rectification
You can request correction or updating of inaccurate, incomplete, or outdated personal information:
- Update account information directly through your profile
- Submit correction requests to our privacy team
- Provide documentation supporting necessary changes
7.3 Right to Erasure ("Right to be Forgotten")
You may request deletion of your personal data, subject to:
- Completion of ongoing regulatory requirements (AML/KYC)
- Fulfillment of legal obligations
- No active disputes or investigations
- Compliance with financial record-keeping requirements
Limitations: We cannot delete data legally required to be retained, particularly for regulatory and anti-fraud purposes.
7.4 Right to Restrict Processing
You can request limitation of how we use your data:
- Restricting marketing communications
- Limiting analytics and profiling
- Requesting data processing suspension during disputes
- Restricting automated decision-making
Restricted data will be marked and not used except for:
- Storage purposes
- Legal claims processing
- Protecting others' rights
- Important public interest reasons
7.5 Right to Data Portability
You have the right to receive your personal data in a structured, commonly-used, machine-readable format and transmit it to another controller:
- Request portable data formats (CSV, JSON, XML)
- Direct transmission to third parties (where technically feasible)
- Includes data you provided or generated through gaming activity
7.6 Right to Object
You can object to certain types of processing:
- Marketing communications and promotional offers
- Profiling and behavioral analytics
- Automated decision-making
- Processing based on legitimate interest
We will cease processing for objected purposes, except where:
- Overriding legitimate interests exist
- Legal obligations require continued processing
- Necessary for establishing or defending legal claims
7.7 Rights Related to Automated Decision-Making
You have rights regarding automated decisions producing legal or similarly significant effects:
- Right not to be subject to wholly automated decisions
- Right to human review and intervention
- Right to explain automated decisions
- Right to challenge automated determinations
7.8 Withdrawing Consent
When we rely on consent for data processing, you can withdraw it at any time by:
- Updating privacy preferences in your account
- Unsubscribing from marketing communications
- Contacting our privacy team
- Opting out through preference centers
Withdrawal doesn't affect the lawfulness of prior processing.
8. Security Measures
8.1 Security Infrastructure
Carlospin implements comprehensive security measures to protect your personal data:
Encryption Technology:
- SSL/TLS encryption for data in transit
- AES-256 encryption for sensitive data at rest
- End-to-end encryption for financial transactions
- Encrypted secure communications channels
Access Controls:
- Role-based access control (RBAC)
- Multi-factor authentication for employee accounts
- Password complexity requirements
- Regular access reviews and privilege audits
- Principle of least privilege implementation
Network Security:
- Advanced firewalls and intrusion detection systems
- DDoS protection and mitigation
- Regular vulnerability scanning
- Penetration testing and security assessments
- Network segmentation and isolation
Data Protection Measures:
- Anonymization and pseudonymization where applicable
- Secure data backup and recovery systems
- Database activity monitoring
- Secure destruction of obsolete data
- Isolated secure environments for sensitive processing
8.2 Compliance and Certifications
Carlospin maintains:
- ISO 27001 Information Security Management certification
- PCI DSS (Payment Card Industry Data Security Standard) compliance
- Regular third-party security audits
- Responsible gambling certifications
- Licensed and regulated gaming operator status
8.3 Data Breach Response
In the event of a data breach, we will:
- Conduct immediate investigation and containment
- Notify affected individuals without undue delay (within 72 hours or as legally required)
- Inform regulatory authorities where legally obligated
- Provide breach details, risks, and mitigation measures
- Offer free credit monitoring or identity theft protection services
- Cooperate with law enforcement investigations
- Publish transparency reports regarding breaches
8.4 Employee Security
- Mandatory data protection training for all staff
- Confidentiality agreements and NDAs
- Background checks for access to sensitive data
- Regular security awareness programs
- Strict disciplinary policies for violations
- Limited access to personal data based on job function
9. Contact Details for Data Requests
9.1 Data Protection Officer and Privacy Team
Carlospin Privacy Department:
- Email: [email protected]
- Mailing Address:
Carlospin Online Casino
Data Protection Department
Amsterdam, Netherlands
[Specific address]
- Response Time: 30 days for subject access requests (extendable by 60 days for complex requests)
- Support Hours: Monday-Sunday, 09:00-23:00 CET
9.2 Data Protection Officer
DPO Contact:
- Email: [email protected]
- Dedicated DPO inquiry line for GDPR-specific concerns
9.3 How to Submit Requests
Online Portal:
- Access through "Account Settings" > "Privacy & Data"
- Submit formal data subject access requests
- Track request status and receive responses
Email:
- [email protected] for all data requests
- Include clear subject line (e.g., "Subject Access Request")
- Provide sufficient identification information
- Specify exactly what data or actions you're requesting
Mail:
- Written requests sent to our registered office address
- Include copy of identification
- Reference request type clearly
In-Person:
- Available by appointment at our physical office
- Contact privacy team to schedule
- Bring valid identification
9.4 Verification of Identity
To protect your privacy and security, we will verify your identity before responding to data requests through:
- Account login credentials
- Government-issued identification
- Additional security questions
- Video verification for sensitive requests
10. GDPR Compliance for Netherlands Players
10.1 Legal Framework
Carlospin is subject to the General Data Protection Regulation (GDPR) and Dutch data protection laws, including the Dutch Data Protection Act (Wet bescherming persoonsgegevens). We comply fully with:
- GDPR Articles 1-99
- Dutch Gaming Authority (KSA) regulations
- Dutch Personal Data Protection Act
- ePrivacy Directive compliance
10.2 Lawful Basis under GDPR
Article 6 - Lawful Processing:
Our processing is based on:
Article 6(1)(a) - Consent:
- Marketing communications
- Profiling for personalized promotions
- Non-essential cookies and tracking
- Social media integration
Article 6(1)(b) - Contract:
- Account creation and management
- Service delivery and platform access
- Payment processing
- Account verification
Article 6(1)(c) - Legal Obligation:
- KYC/AML verification (Dutch gambling regulations)
- Financial record-keeping
- Money laundering prevention
- Responsible gambling compliance
- Tax compliance
Article 6(1)(f) - Legitimate Interest:
- Fraud prevention and detection
- Platform security and protection
- Service improvement and analytics
- Customer support and communication
- Regulatory compliance monitoring
10.3 International Data Transfers
If we transfer personal data outside the European Economic Area (EEA):
- We use only adequacy decisions (US Privacy Shield alternatives)
- Standard Contractual Clauses (SCCs) are implemented
- Binding Corporate Rules (BCRs) where applicable
- You have rights regarding such transfers
Transfer Recipients:
- US-based payment processors (with SCCs)
- Cloud infrastructure providers (GDPR-compliant services)
- Analytics platforms (with Data Processing Agreements)
10.4 Your GDPR Rights
As a Netherlands resident, you have enhanced rights under GDPR:
- Right of Access (Article 15)
- Right to Rectification (Article 16)
- Right to Erasure (Article 17, subject to limitations)
- Right to Restrict Processing (Article 18)
- Right to Data Portability (Article 20)
- Right to Object (Article 21)
- Rights regarding Automated Decision-Making (Article 22)
- Right to Lodge a Complaint with Dutch DPA
10.5 Data Protection Authority
Dutch Data Protection Authority (Autoriteit Persoonsgegevens):
- Address: Bezuidenhoutseweg 30, 2594 AA The Hague
- Email: [email protected]
- Phone: +31 (0)70 888 8500
- Website: www.autoriteitpersoonsgegevens.nl
You have the right to lodge a complaint if you believe we have violated your data protection rights.
10.6 GDPR Compliance Measures
Data Protection Impact Assessments (DPIA):
- Conducted for high-risk processing activities
- Regular reviews of processing activities
- Risk mitigation measures implemented
- Documented compliance procedures
Data Processing Agreements (DPA):
- Executed with all third-party processors
- Clear processor responsibilities defined
- Sub-processor authorizations documented
- Regular processor audits conducted
Privacy by Design and Default:
- Privacy considerations in all product development
- Data minimization principles applied
- Privacy-protective features implemented by default
- Regular privacy impact reviews
Documentation and Records:
- Complete Records of Processing Activities (ROPA)
- Documented consent mechanisms
- Processing purpose documentation
- Data retention schedule documentation
10.7 Cookies Consent for Netherlands
Under Dutch law and GDPR ePrivacy rules:
- Explicit consent required before placing tracking cookies
- Consent mechanism clearly presented before service use
- Consent easily withdrawn through preference centers
- Consent records maintained for compliance demonstration
11. Special Categories of Data
11.1 Sensitive Data Processing
Carlospin minimizes collection of special categories of data (sensitive personal data):
Health Information:
- Limited collection for responsible gambling assessment only
- Self-exclusion program administration
- Problem gambling support coordination
- Never shared without explicit consent
Biometric Data:
- Facial recognition only for identity verification
- Stored separately with enhanced security
- Used solely for anti-fraud purposes
- Not used for profiling or tracking
Financial Information:
- Handled with highest security standards
- PCI DSS compliance strictly maintained
- Encrypted at all times
- Limited to authorized personnel only
11.2 Legal Basis for Sensitive Data
Processing of special categories relies on:
- Explicit consent (Article 9(2)(a) GDPR)
- Employment law obligations (Article 9(2)(b))
- Vital interest protection (Article 9(2)(c))
- Legitimate activities of organizations (Article 9(2)(d))
- Data manifestly made public by data subject (Article 9(2)(e))
- Legal claims processing (Article 9(2)(f))
- Substantial public interest (Article 9(2)(g))
12. Additional Provisions
12.1 Children and Minors
Carlospin does not knowingly collect data from individuals under 18 years old. Our services are only available to individuals aged 18 or older (21 in some jurisdictions).
- Age verification mandatory during registration
- Accounts created by minors will be terminated
- Parental consent cannot authorize minor account creation
- If we discover minor data, it will be immediately deleted
12.2 California and Other US Privacy Laws
For California residents and other applicable US jurisdictions:
- Right to Know what personal data is collected
- Right to Delete personal data collected
- Right to Opt-Out of sale of personal data
- Right to Correct inaccurate personal data
- Right to Limit use and disclosure of sensitive personal data
- Right to non-discrimination for exercising privacy rights
12.3 Policy Updates
This Privacy Policy may be updated periodically:
- Significant changes will be emailed to registered players
- Continued use of services implies acceptance of updates
- Previous versions available upon request
- Effective date of any update will be clearly specified
12.4 Disclaimer Regarding Third-Party Links
Carlospin is not responsible for privacy practices of linked external websites. Review their privacy policies before providing information.
13. Conclusion
Carlospin is committed to protecting your privacy while providing excellent gaming services. We balance your privacy rights with our regulatory obligations and business needs. If you have questions or concerns about our privacy practices, please contact our privacy team immediately.
Your privacy is our priority.
---
Document Version: 2.0
Last Updated: January 2024
Next Review Date: January 2025
Carlospin is committed to protecting your personal information and your right to privacy.
Information We Collect
We collect information you provide when registering, including name, email, date of birth and payment details.
How We Use It
To provide services, process transactions, send promotional communications and comply with legal obligations.
Data Security
We implement SSL encryption and industry-standard security measures to protect your data.
Your Rights
You have the right to access, update or delete your personal information. Contact us to exercise these rights.
