Effective Date: 25.05.2026
Data Controller: casinoicelandonline.is
Data Protection Enquiries: [email protected]

§1 — Scope, Controller Identity and Governance Structure

Summary: This Notice applies to everyone who uses casinoicelandonline.is. We are the data controller — legally responsible for how your personal data is handled.

The Controller bears sole responsibility for determining the purposes and means of personal data processing as described in this Notice, in accordance with the definition of "controller" under Article 4(7) GDPR. The Controller's principal place of business is registered. All formal communications concerning data protection matters, including the exercise of data subject rights and the submission of complaints, shall be directed in writing to [email protected]. The Controller commits to acknowledging all such communications within five working days of receipt and to providing a substantive response within the statutory timeframe of thirty calendar days, extendable by a further sixty days where justified by the complexity or volume of requests, with prior written notice to the requesting party.

This Notice applies to all natural persons engaging with the Controller's services, including prospective players browsing the platform without a registered account, registered account holders regardless of activity status, and former players whose data is retained pursuant to statutory retention obligations following account closure. The Notice does not extend to legal entities. Processing activities not described herein will be the subject of separate, purpose-specific notices issued at the relevant point of collection.

§2 — Categories of Personal Data Collected

Summary: We collect four types of data: who you are, how you pay, what you play, and how your device connects to us. Each type has a specific reason for collection.

The Controller collects personal data across four principal categories, each arising from a discrete aspect of the player relationship and governed by a specific legal basis.

Personal identity data is collected at registration and during account management. It encompasses full legal name, date of birth, verified email address, country of residence, and account credentials. Where identity verification is required prior to real-money activity, the Controller additionally collects government-issued photographic identification, documentary proof of current address, and in applicable circumstances, biometric verification material in the form of a contemporaneous selfie image. Identity verification data is processed by a regulated third-party verification provider operating under a binding data processing agreement.

Financial data is generated at each transactional interaction with the platform. It includes payment method category, partial payment identifiers where technically applicable, transaction amounts, currencies, timestamps, and reference identifiers assigned by payment service providers. The Controller does not retain full payment card numbers on its own systems; all card data is processed exclusively within a Payment Card Industry Data Security Standard ("PCI DSS") compliant environment maintained by the Controller's payment processing partner.

Gameplay data is generated continuously during active sessions and comprises game titles accessed, wager amounts, session start and end times, win and loss outcomes, bonus activation and completion records, and responsible gambling tool interaction logs.

Technical and behavioural data is collected automatically during platform access and includes Internet Protocol addresses, device identifiers, browser type and version, operating system, referring URL, session logs, page interaction records, and error reports.

§3 — Purposes and Legal Bases of Processing

Summary: Every use of your data has a legal reason. We process your data to run your account, comply with the law, protect you, prevent fraud, and — only with your permission — send you offers.

The Controller processes personal data exclusively for purposes supported by a lawful basis under Article 6 GDPR. Service delivery — encompassing account operation, transaction processing, game access, and bonus administration — is conducted under Article 6(1)(b), being necessary for the performance of a contract. Regulatory and legal compliance — including KYC verification, anti-money laundering transaction monitoring, and gambling licence record-keeping — is conducted under Article 6(1)(c), being necessary to fulfil a legal obligation. Responsible gambling monitoring, comprising the analysis of gameplay data for statistical harm indicators and the delivery of human-reviewed welfare interventions, is conducted under Article 6(1)(f), being necessary for the Controller's legitimate interests in player protection, subject to the balancing assessment required by Recital 47 GDPR. Fraud detection, security monitoring, and platform integrity maintenance are similarly processed under Article 6(1)(f). Direct marketing communications are processed exclusively under Article 6(1)(a), being based on the data subject's freely given, specific, informed, and unambiguous consent, withdrawable at any time without detriment. Platform development through aggregated and anonymised data analysis proceeds under Article 6(1)(f).

§4 — Cookies and Tracking Technologies

Summary: We use four types of cookies. Two work without your consent because they're essential. Two require your permission because they're used for analysis and personalisation.

The Controller deploys cookies and analogous tracking technologies in four defined categories. Strictly necessary cookies are deployed without consent as essential to platform operation, providing session management, login authentication, and security token functionality; they expire within twenty-four hours or at session termination. Functional cookies preserve user preferences including language and display settings and persist for up to twelve months; they are necessary for service delivery as requested and require no consent. Analytical cookies collect anonymised performance and error data to support platform improvement, are retained for up to thirteen months, and are activated exclusively upon affirmative consent. Marketing cookies support personalised promotional displays and affiliate attribution, persist for up to twenty-four months, and require explicit consent prior to deployment. Data subjects may review, modify, or withdraw cookie consent at any time through the Cookie Settings panel accessible in the platform footer without affecting their access to core platform functionality.

§5 — Third-Party Sharing

Summary: We never sell your data. We share it only with companies that help us run the platform, regulators who require it by law, and responsible gambling services where legally necessary.

The Controller does not sell, license, or commercially transfer personal data to any third party. Disclosure occurs solely in the following defined circumstances. Data processors engaged to deliver platform services — including payment processors, identity verification providers, cloud infrastructure operators, customer support platforms, and marketing delivery services — receive personal data to the minimum extent necessary for their contracted function and are bound by data processing agreements prohibiting secondary use and requiring GDPR-compliant standards. Regulatory authorities, gambling supervisory bodies, financial intelligence units, and law enforcement agencies receive data where disclosure constitutes a legal obligation or arises from a lawful and documented authority demand. Multi-operator responsible gambling exclusion registers receive the minimum data necessary to enforce self-exclusion across participating operators under applicable regulatory frameworks. In the event of a merger, acquisition, or asset transfer, data may pass to a successor entity, subject to prior written notification to affected data subjects and preservation of all rights conferred by this Notice. All processors and recipients outside the European Economic Area are subject to Standard Contractual Clauses pursuant to Article 46(2)(c) GDPR before any international transfer is executed.

§6 — Data Retention

Summary: We keep your data only as long as the law requires or the service needs. The table below gives you the exact timeframe for each data type.

Data Category Retention Period Legal or Operational Basis
Account identity and login data 5 years post-account closure AML regulation; gambling licence
KYC verification documents 5 years post-account closure Legal obligation
Financial transaction records 7 years from transaction date Tax and financial legislation
Gameplay session records 3 years from session date Regulatory audit requirement
Support correspondence 2 years from resolution Dispute resolution
Technical and log data 12 months from generation Security and fraud monitoring
Marketing preference records Until consent is withdrawn Consent
Cookie data Per category as stated in §4 Consent or necessity

Upon expiry of the applicable period, personal data is permanently and securely deleted from the Controller's systems and those of all engaged processors. Where a data subject submits an erasure request prior to the expiry of a mandatory retention period, the Controller will delete all data not subject to a statutory hold and provide written identification of any data retained with the applicable legal basis.

§7 — Data Subject Rights

Summary: You have seven rights. All are free to exercise, all are actioned within thirty days, and none of them require you to justify yourself.

Pursuant to the GDPR, data subjects hold the following enforceable rights. The right of access (Article 15) to receive a complete copy of personal data held and information about its processing. The right to rectification (Article 16) to correct inaccurate or incomplete data. The right to erasure (Article 17) to request deletion where grounds exist and no statutory retention obligation applies. The right to restriction (Article 18) to suspend processing pending resolution of accuracy or lawfulness disputes. The right to data portability (Article 20) to receive data in a structured, machine-readable format or request its direct transmission to another controller where processing is automated and based on consent or contract. The right to object (Article 21) to processing based on legitimate interests including profiling, with immediate effect for direct marketing objections. The right to withdraw consent (Article 7(3)) at any time without prejudice to prior lawful processing. All requests are submitted in writing to [email protected] with identity verification. Response within thirty days. No fee charged for standard requests. Unsatisfied data subjects retain the unconditional right to escalate to their national supervisory authority.

§8 — Security Standards and Policy Amendments

Summary: We use industry-leading technical protections. If we ever update this Notice materially, we will tell you in advance.

The Controller maintains a multi-layered security programme encompassing TLS 1.2 or higher encryption for data in transit; AES-256 encryption for sensitive data at rest; role-based access controls with full logging and periodic audit; PCI DSS-compliant payment handling; regular independent penetration testing; and a documented breach response protocol providing for supervisory authority notification within seventy-two hours and individual data subject notification without undue delay, pursuant to Articles 33 and 34 GDPR respectively. This Notice is subject to periodic review. Material amendments will be communicated to registered data subjects by email in advance of the revised effective date. Continued platform use following notification constitutes acknowledgement of the updated Notice.