GDPR
SpinEmpire processes player data under the General Data Protection Regulation.
Processing covers three groups. Identification data supplied at registration and verification: name, date of birth, email, identity documents. Transactional data: deposits, withdrawals, wagering and game history. Technical data generated in use: IP address, device characteristics, browser type, session logs.
Optional marketing preferences form a fourth, consent-controlled group.
Under GDPR each purpose requires a stated basis, and the mapping here is conventional: account operation and payment processing rest on contractual necessity; age verification, KYC and anti-money-laundering controls rest on legal obligation arising from licence OGL/2024/589/0556; fraud detection and platform security rest on legitimate interest; marketing rests on consent, revocable at any time with no consequence for the account.
No processing occurs outside these four purposes.
Cookies maintain login sessions, record preferences and support usage analysis. Strictly necessary cookies are integral to the service and cannot be refused without losing functionality. Non-essential cookies are manageable through browser controls, and declining them does not restrict access to games or account features.
Recipients are limited to functional necessity: payment providers, for executing deposits and withdrawals; verification partners, for KYC processing; and supervisory or regulatory bodies where disclosure is legally mandated. Personal data is not sold or traded. Each recipient receives only the subset of data its role requires.
Records persist for the life of the account plus the retention periods imposed by gambling regulation, anti-money-laundering law and accounting requirements. On expiry, data is erased or irreversibly anonymised. Verification documents follow the identical schedule — retained under legal obligation, then removed.
The regulation grants, and the operator honours: the right of access to held data; rectification of inaccurate records; erasure where no retention obligation intervenes; portability of your data in structured machine-readable form; and objection to legitimate-interest processing. All requests are free of charge and answered within statutory timeframes. The right to lodge a complaint with a supervisory authority remains available throughout.
Security architecture rests on SSL encryption for all data in transit, role-restricted internal access to player records, and segregated storage for verification documents. These controls address the practical threat model — interception and unauthorised access — while recognising that no system offers absolute guarantees.
Rights requests and privacy questions go through live chat or by email to [email protected], marked as a data protection matter. The operator may confirm the requester's identity before releasing data — a required safeguard against disclosure to impostors.