Privacy Policy

Privacy Policy

Last updated: 15.04.2024

Definitions

Lucky Circus Personal Data means any information relating to an identified or identifiable natural person (‘data subject’); an identifiable natural person is one who can be identified, directly or indirectly, by reference to identifiers such as a name, an identification number, location data, an online identifier, or factors specific to the physical, physiological, genetic, mental, economic, cultural, or social identity of that person.

Processing means any operation or set of operations performed on personal data or sets of personal data, whether or not by automated means. This includes collection, recording, organization, structuring, storage, adaptation, alteration, retrieval, consultation, use, disclosure by transmission, dissemination, making available, alignment, combination, restriction, erasure, or destruction.

Profiling means any form of automated processing of personal data to evaluate certain personal aspects relating to a natural person, particularly to analyze or predict aspects concerning that person’s performance at work, economic situation, health, personal preferences, interests, reliability, behavior, location, or movements.

Controller is the natural or legal person, public authority, agency, or other body which, alone or jointly with others, determines the purposes and means of processing personal data. Where the purposes and means are determined by Union or Member State law, the controller or specific criteria for its nomination may be provided for by Union or Member State law.

Processor is a natural or legal person, public authority, agency, or other body which processes personal data on behalf of the controller.

Recipient is a natural or legal person, public authority, agency, or other body to which the personal data are disclosed, whether a third party or not. However, public authorities that may receive personal data in the framework of a particular inquiry shall not be regarded as recipients; the processing of those data by those public authorities must comply with the applicable data protection rules according to the processing purposes.

Third Party is a natural or legal person, public authority, agency, or body other than the data subject, controller, processor, and persons who, under the direct authority of the controller or processor, are authorized to process personal data.

Consent of the data subject is any freely given, specific, informed, and unambiguous indication of the data subject’s wishes by which he or she, by a statement or by a clear affirmative action, signifies agreement to the processing of personal data relating to him or her.

Personal data breach means a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to, personal data transmitted, stored, or otherwise processed.

Group of undertakings means a controlling undertaking and its controlled undertakings.

Supervisory authority means an independent public authority established by a Member State pursuant to Article 51 GDPR.

General

This notice, along with the General Terms and Conditions available on our site, sets out the basis on which any personal data we collect from you, or that you provide to us, will be processed by us. Please read the following carefully to understand our practices regarding your personal data and how we will treat it. By registering a Player Account with the Website, you confirm your consent with this Privacy Policy. If you do not agree with the terms of this Privacy Policy and do not wish to provide us with the personal information we require, please do not use this website.

Note that this Privacy Policy constitutes an agreement between you and the Company. We may periodically make modifications to this Policy. While we will do our best to notify you of such changes, we recommend that you revisit this Privacy Policy regularly. Your continued use of the Website and/or its services will constitute your consent to the Privacy Policy.

Lucky Circus Casino values your privacy immensely and is committed to managing your personal data transparently, fairly, and lawfully. This privacy policy sets out the basis on which Lucky Circus Casino collects, stores, and uses your personal data when you visit our website, detailing your rights and how the law protects those rights according to the General Data Protection Regulation (GDPR).

This website is intended solely for persons over the age of 18, and we do not knowingly collect data relating to persons under this age. If it becomes apparent that we have collected personal data from persons under the age of 18 due to misuse, we will handle such data in accordance with applicable law.

About Us

We take your privacy seriously, which is why we have appointed a Data Protection Officer (DPO) whose responsibility is to ensure that we comply with our legal obligations regarding the processing of your personal data. For any inquiries about this policy, including any request to exercise your legal rights and complaints about violations of your rights, please contact our DPO at [email protected].

Contact Us

You may contact us regarding this Policy if you wish to:

  • Confirm the accuracy of the personal information we have collected about you.
  • Inquire about our use of your personal information.
  • Prohibit future use of your data for direct marketing purposes.
  • Receive a copy of the personal information stored about you.

Unless you have opted out of receiving promotional materials, we may use your Personal Information, including your email address and phone number, to send you marketing communications. This may include information about products and services from our business partners, such as casino game providers. You can opt out of receiving such marketing and advertising material at any time via your Player Account settings, or by contacting our customer support at [email protected] and/or live chat.

To update or rectify any information you have provided, please provide any evidence we may reasonably require to effect such changes. It is illegal to provide us with false information about yourself, and it is your responsibility to ensure that we are always updated with your correct data.

To fulfill your requests in accordance with this privacy policy, you can use the following means of communication:

Please note that emails may end up in your spam folder or may not reach us at all due to technical reasons. If your request is not addressed within 10 days, we strongly recommend you contact us again using alternative communication methods. You can always reach out to our Data Protection Officer at [email protected] if:

  • You believe your privacy has been violated
  • Deadlines for the execution of requests for a copy of data are violated
  • You need clarification on provisions of this privacy policy
  • You wish to receive a copy of your personal data stored across all Lucky Circus Casino licenses

We aim to respond to all legitimate requests within one month. Sometimes it may take us longer than a month if your request is particularly complex or if you have made several requests. In this case, we will notify you and keep you updated.

Information We Collect

Information you provide us: This includes information that you provide when filling in forms on our account registration pages, or any other data that you further submit via the Website or email. It includes information you provide when you register to use our site, subscribe to our service, make deposits, bets, or withdrawals on our site, participate in chat rooms, accept bonuses or other promotions available on our site, any due diligence documentation you share with us, and when you report a problem or make a complaint with us. The information you give us may include your name, username, address, date of birth, country of residence and nationality, identification number, email address, phone number, financial and credit card information, personal description, proof of identification, proof of address, proof of funds, and photograph.

Technical information: Includes the Internet protocol (IP) address used to connect your computer to the Internet, your login information, browser type and version, time zone setting, browser plug-in types and versions, operating system and platform, information about your visit, including the full Uniform Resource Locators (URL), and information received from cookies. Please refer to our Cookie Notice for further details on the types of cookies in use.

Gameplay information: Includes games you played, duration on each game and page, page interaction information.

Analytics information: We collect information about your use of the Services for research and analytics purposes, such as applications’ usage, log files, user activity (e.g., pages viewed, the amount of time spent on particular pages, online browsing, clicks, actions, etc.), time stamps, alerts, etc.

Information from other sources: This includes information we receive about you if you use any of our other websites or services operated by the Group. If you use accounts on multiple sites operated by the Group, we may collate information generated from each site into one data repository. This data is used for statistical purposes and is also particularly relevant in the context of our Anti-Money Laundering and Responsible Gambling responsibilities.

During the course of delivering services to you, we also work closely with third-party data processors (including, for example, business partners, subcontractors in technical, payment, and delivery services, and for the delivery of marketing information). These processors may include CRM Tool Providers, Email Marketing Partners, SMS Providers, Direct Mail Distributors, Outbound Call providers, advertising networks and affiliate networks, analytics providers, due diligence intelligence companies, search information providers, and credit reference agencies. These third parties process personal data according to our written instructions and are restricted to processing activities needed to assist us in delivering the service to you.

Categories of Data We Store About You

Personal Data refers to any information about an individual from which that person can be identified. It may include data where the identity has been removed (anonymous data).

The personal data we collect and process about you may include the following categories:

Identity Data: Includes first name, middle name, last name, username or similar identifier, date of birth, and gender.

Contact Data: Includes residential address, email address, telephone numbers, and other available means of communication.

Financial Data: Includes details of your financial status, sources of funds used to deposit with us, bank account details, payment card details, and documentation such as bank statements or scans confirming your income, collected primarily for KYC purposes.

Transaction Data: Includes details about deposits and withdrawals, wagering, and other details of games you have played on our sites.

Technical Data: Includes the internet protocol (IP) address, your login data, browser type and version, time zone setting and location, browser plug-in types and versions, operating system and platform, and other technologies on the devices you use to access this website.

Usage Data: Includes information about how you use our website, products, and services, online identifiers to log in, encrypted passwords, games played, login and logout times, duration of play, claimed bonuses and promotions, responsible gaming information, limits and history, and AML classification.

Marketing and Communications Data: Includes your preferences in receiving marketing from us and our third parties, and your communication preferences.

Special Categories of Personal Data: In cases where you voluntarily provide such information or we are required to collect it to fulfill our legal obligations, this may include:

  • Information related to responsible gaming, which may be considered medical data.
  • Information about your racial or ethnic origin, as obtained from documents you uploaded.

How We Use Your Information

Information you provide us is used to:

  • Fulfill our obligations from any contracts entered into between you and us, provide the gaming services you request, process transactions, manage fraud, respond to inquiries or complaints, and other related services.
  • Contact you with marketing information from the Group, subject to your consent, regarding our services, promotional offers, and products from related sites operated by the Group.
  • Provide personalized advertising on the site based on your interactions or Usage Data.
  • Notify you about changes to our service.
  • Meet obligations from Anti-Money Laundering Legislation and other applicable laws.

Information we collect about you is used to:

  • Administer our site and for internal operations, including troubleshooting, data analysis, testing, research, statistical and survey purposes, typically via Cookies (see our Cookie Policy for more details).
  • Contact you with information about services, bonuses, and promotions, depending on the preferences you have expressed.
  • Manage fraud and risk, including assigning risk profiles to your account.
  • Build detailed customer profiles to assess your behavior and preferences for responsible gambling and anti-money laundering purposes.
  • Create registers of high-risk or problematic gamblers and bonus abusers to exclude them from promotions or restrict access to our services.
  • Screen, monitor, and analyze your transactions and interaction with our site for responsible gambling, ensuring your engagement remains safe and fun.
  • Combine information received from third-party sources such as age verification tools, identity or address verification services, regulators, or databases to enhance our understanding of your profile and gambling behavior.

Information from Other Sources

We combine information from third-party sources with information you provide and information we collect about you. This information is used for the purposes outlined above, including improving our services, managing risks, and complying with legal obligations.

Please note, we partially use profiling for these purposes with final decisions performed by humans, though the logic behind profiling cannot be disclosed to prevent circumvention of our control mechanisms aimed at protecting our business and complying with legal standards.

Lawful Basis for Processing Personal Data

We have outlined below the ways in which we use your personal data, along with the legal bases we rely on to do so. Where appropriate, we have also identified our legitimate interests.

Categories of Data Collected:

  1. Identification Data – Includes full name, username, date of birth, and gender.
    • Collection Method: Requested upon registration.
    • Purpose for Collection: Customer identification, creation of a unique customer profile, and customer verification for Anti-Money Laundering (AML) purposes.
    • Legal Basis for Processing: Performance of a contract and legal obligations.
  2. Contact Details – Includes email address, home address, mobile phone number, and other available means of communication.
    • Collection Method: Requested upon registration and/or during the KYC procedure.
    • Purpose for Collection: Customer identification, support communication, marketing communications from Lucky Circus Casino and other Group brands, and verification of player identity.
    • Legal Basis for Processing: Performance of a contract, consent for marketing communications, and legal obligations for identity verification.
  3. Financial Data – Includes bank details, payment card details, and details related to deposit and withdrawal methods.
    • Collection Method: Collected when you make a deposit or withdrawal.
    • Purpose for Collection: To process transactions, perform KYC checks, conduct cybercrime checks, and ensure a closed-loop policy.
    • Legal Basis for Processing: Performance of a contract and legal obligations.
  4. Transaction Data – Includes details about payments made to and by you.
    • Collection Method: Automatically generated during deposits and withdrawals.
    • Purpose for Collection: Service provision, compliance with AML laws, and tracking of activities for social responsibility measures.
    • Legal Basis for Processing: Performance of a contract and legal obligations.
  5. Gaming Data – Includes details about the games you play on our website.
    • Collection Method: Automatically generated with gaming activity.
    • Purpose for Collection: To provide gaming services and comply with remote gaming laws.
    • Legal Basis for Processing: Performance of a contract and legal obligations.
  6. Communication Data – Includes data from your communications with us via email, live chat, and phone calls.
    • Collection Method: Collected when you contact us.
    • Purpose for Collection: To provide customer service and potentially for risk management and legal claims.
    • Legal Basis for Processing: Performance of a contract and legitimate interest in managing risks and legal claims.
  7. Profile Data – Includes data about your gaming habits and preferences.
    • Collection Method: Generated automatically with gameplay or via cookies.
    • Purpose for Collection: Service improvement, personalized user experience, AML segmentation, and targeted marketing.
    • Legal Basis for Processing: Legitimate interest for aggregated data, consent for personalized marketing and profiling.
  8. Responsible Gaming Data – Includes information from self-assessment tests.
    • Purpose for Collection: Responsible gaming profiling and investigation.
    • Legal Basis for Processing: Legal obligation and legitimate interest in promoting responsible gaming.
  9. Technical and Usage Data – Includes IP address, login data, browser details, and usage details.
    • Purpose for Collection: To ensure compliance with geographic restrictions, enhance site functionality, and improve user experience.
    • Legal Basis for Processing: Legal obligations and legitimate interest in security and site optimization.
  10. My RTP Data – Includes data on your return to player rates and gaming behavior.
    • Purpose for Collection: To ensure compliance with RTP requirements.
    • Legal Basis for Processing: Legal obligation.

Sharing of Data

Due to our service’s nature, we may need to share your data with trusted third parties, including:

  • Other members of the Group for fraud prevention, AML purposes, and direct marketing, given your consent.
  • Payment processors and game providers as necessary for providing the gaming services.
  • Legal and regulatory authorities as required by law.

Our commitment is to ensure that any third party handling your data agrees to respect its security and treat it in accordance with the law. We only allow such third parties to process your personal data for specified purposes and in accordance with our instructions.

Data Retention

We retain your personal data only as long as necessary for the purposes for which it was collected. This includes fulfilling legal, accounting, or reporting requirements.

Factors influencing the retention period for your data include the purpose of data collection, legal and regulatory obligations, the sensitivity of the personal data, and potential risks of unauthorized use or disclosure.

Under our Terms and Conditions, both you and Lucky Circus Casino can decide to close your Player Account at any time. After account closure, we retain your personal data as required by law, accessible only if needed by competent authorities for financial, fraud, money laundering investigations, or other legal activities.

Anonymized data derivatives may be retained to enhance our content and marketing efforts without involving automated decision-making.

Due to anti-money laundering regulations in EU licensed gaming jurisdictions, we must retain personal data from registration and the operational period of a Player Account for a minimum of five years from the last transaction or account closure. Therefore, requests for data erasure before this period cannot be fulfilled.

Your Rights

Data protection laws provide you with rights under certain conditions, including the right to:

  • Request access to your personal data. You can ask for a copy of the personal data we hold about you.
  • Request correction of the personal data we hold about you. This enables you to have any incomplete or inaccurate data corrected.
  • Request erasure of your personal data when there is no good reason for us to continue processing it. Note, this is not an absolute right and only applies under certain conditions.
  • Object to processing of your personal data where we are relying on a legitimate interest (or those of a third party) and your situation makes you want to object to processing on this ground.
  • Request the restriction of processing of your personal data, allowing you to ask us to suspend the processing of personal data about you, for example if you want us to establish its accuracy or the reason for processing it.
  • Request the transfer of your personal data to another party.
  • Withdraw consent at any time where we are relying on consent to process your personal data. However, this will not affect the lawfulness of any processing carried out before you withdraw your consent.

If you wish to exercise any of the rights set out above, please contact our data protection officer (DPO) at [email protected].

We try to respond to all legitimate requests within one month. Occasionally it may take us longer if your request is particularly complex or you have made a number of requests. In this case, we will notify you and keep you updated.

Automated Decision Making

We generally do not use fully automated decision-making processes in establishing or conducting business relationships. If we do use such processes in individual cases, we will inform you separately if required by law.

Security of Your Data

We are committed to protecting your personal data and respect your privacy in accordance with best business practices and applicable regulations. We take all reasonable precautions to ensure that the data you have submitted to us remains secure.

We have implemented appropriate security measures to prevent your personal data from being accidentally lost, used, accessed, altered, or disclosed without authorization. Access to your personal data is limited to employees, agents, contractors, and other third parties who have a business need to know.

Player Accounts are secured with unique ID and password access. You can enhance security through two-factor authentication (2FA) to protect your account from unauthorized use. You are responsible for keeping your login credentials confidential and secure.

For any inquiries or concerns about our data handling practices, please contact our DPO at [email protected].