Your data matters, so here's exactly what happens to it — in line with the GDPR, which gives you concrete, enforceable rights over your own information.
From the moment you register, several kinds of information build up:
Nothing beyond these categories is collected, and none of it is gathered without a reason listed below.
GDPR requires a legal basis for every use, and here they are matched up:
Withdrawing marketing consent stops promotional messages without affecting your account. Play continues exactly as before.
Cookies keep your session alive, remember your preferences and help with security and analytics. The essential ones can't be switched off without breaking login and gameplay; everything else you can manage through your browser settings. You can also clear existing cookies whenever you like, though doing so logs you out of your active session.
Sharing happens only where the service requires it: payment providers receive what they need to process your deposits and withdrawals, KYC partners verify the documents the law obliges the operator to check, and authorities receive data only when legally compelled. Each party gets its slice and nothing more — your payment provider never sees your game history, for instance.
Your information is never sold, and it isn't handed to advertisers.
On the technical side, SSL encryption protects everything moving between your device and the platform, and internal access is limited to staff whose role requires it. Your KYC documents get the same protection as your financial records.
Only as long as necessary. Financial and account records stay for the periods anti-money-laundering and licensing law demands, even after you close your account — that's the law's requirement, not the operator's choice. Marketing data disappears when you withdraw consent.
When no legal reason to keep something remains, it's deleted or anonymised. Anonymised data can't be traced back to you, which is why it falls outside GDPR entirely.
As an Irish player under GDPR you can, at any time and free of charge:
Responses arrive within GDPR's deadlines, normally a month. If you're unhappy with the outcome, you can complain to Ireland's Data Protection Commission — and you don't need the operator's permission or a completed complaint process to do so.
Send data requests to [email protected] or start a 24/7 live chat. Use the email address on your account so we can verify it's really you before releasing anything — a safeguard that protects your data from anyone pretending to be you.