Privacy & Security
Data We Collect
Genesis Global Limited, operating the website casinovegashero.me.uk and licensed under the Malta Gaming Authority under licence reference MGA/B2C/314/2015, processes personal data in accordance with applicable data protection legislation, including the General Data Protection Regulation (EU) 2016/679. The following categories of personal data are subject to collection and processing:
- Identification Data: Full legal name, date of birth, nationality, and government-issued identification document details, including passport numbers and national identity card references, are collected for the purposes of account registration and mandatory identity verification.
- Contact Information: Electronic mail addresses, postal addresses, and telephone numbers are recorded to facilitate communication between the data controller and the data subject.
- Financial Data: Payment method details, transaction histories, deposit and withdrawal records, and associated banking information are processed in connection with the provision of gaming services and compliance with anti-money laundering obligations.
- Technical Data: Internet Protocol (IP) addresses, browser type and version, operating system identifiers, device identifiers, session duration data, and cookie-derived information are automatically collected upon interaction with the website.
- Behavioural Data: Gameplay activity records, wagering histories, session logs, and user preferences are processed in the course of service delivery and responsible gambling monitoring.
- Verification Data: Documentation submitted for Know Your Customer (KYC) compliance purposes, including proof of identity and proof of address documentation, is retained as required by regulatory obligations imposed by the Malta Gaming Authority.
- Communication Data: Records of correspondence conducted between the data subject and the customer support function are maintained for quality assurance and dispute resolution purposes.
Data Usage
Personal data collected through the casinovegashero.me.uk platform is processed exclusively for specified, explicit, and legitimate purposes. The following purposes constitute the lawful basis upon which data processing operations are conducted:
- Service Provision: Personal data is processed as necessary for the performance of the contractual relationship established upon account registration, including the administration of player accounts, the facilitation of deposits and withdrawals, and the delivery of gaming services.
- Regulatory Compliance: Data processing is conducted to fulfil legal obligations arising from applicable gaming legislation, anti-money laundering directives, and requirements imposed by the Malta Gaming Authority under licence MGA/B2C/314/2015. Such obligations necessitate identity verification, transaction monitoring, and the maintenance of comprehensive activity records.
- Responsible Gambling: Behavioural and gameplay data is analysed for the purpose of identifying patterns indicative of problem gambling behaviour. Such processing enables the implementation of appropriate safeguarding measures in accordance with responsible gambling obligations.
- Fraud Prevention and Security: Technical and transactional data is processed for the detection, investigation, and prevention of fraudulent activity, money laundering, and other forms of financial crime or abuse of the platform.
- Customer Support: Communication data and account information are accessed by authorised personnel for the purpose of responding to enquiries, resolving disputes, and providing technical assistance to data subjects.
- Legal Claims: Where necessary, personal data may be processed for the establishment, exercise, or defence of legal claims in the context of regulatory proceedings or civil litigation.
- Analytics and Service Improvement: Aggregated and anonymised technical and behavioural data may be subjected to analysis for the purpose of improving platform functionality, user experience, and operational efficiency, provided that such processing does not result in the identification of individual data subjects.
Data Protection
Genesis Global Limited implements appropriate technical and organisational measures to ensure a level of security commensurate with the risks presented by the processing of personal data. The following safeguards are maintained:
- Encryption: All personal data transmitted between the data subject's device and the website servers is protected through industry-standard Transport Layer Security (TLS) encryption protocols. Sensitive data stored within internal systems is subject to encryption at rest.
- Access Controls: Access to personal data is restricted on a need-to-know basis. Authorisation procedures and role-based access control mechanisms are applied to ensure that personal data is accessible only to personnel whose functions require such access.
- Data Minimisation: Only personal data that is adequate, relevant, and limited to what is necessary in relation to the specified processing purposes is collected and retained. Unnecessary data accumulation is prohibited by internal data governance policy.
- Retention Limitations: Personal data is retained for no longer than is necessary to fulfil the purposes for which it was collected, subject to any extended retention periods mandated by applicable regulatory or legal obligations. Upon expiry of the applicable retention period, personal data is securely deleted or anonymised.
- Third-Party Processor Management: Where personal data is disclosed to third-party processors engaged in the provision of supporting services, such processors are required to implement equivalent security standards and are bound by contractual obligations consistent with applicable data protection law.
- Incident Response: Procedures for the detection, assessment, and notification of personal data breaches are maintained in accordance with Article 33 of the General Data Protection Regulation. Where a breach is determined to present a risk to the rights and freedoms of data subjects, notification to the competent supervisory authority is conducted within the prescribed statutory timeframe.
- Staff Training: Personnel engaged in the processing of personal data are subject to mandatory data protection training and are bound by confidentiality obligations extending beyond the termination of their engagement with Genesis Global Limited.
User Rights
Data subjects whose personal data is processed by Genesis Global Limited are entitled to exercise the following rights in accordance with applicable data protection legislation. Requests submitted in the exercise of these rights will be assessed and responded to within the statutory timeframe of one calendar month from receipt, subject to any permissible extension in cases of complexity or volume:
- Right of Access: Data subjects are entitled to obtain confirmation as to whether personal data concerning them is being processed and, where such processing is confirmed, to receive a copy of the personal data together with information regarding the purposes of processing, the categories of data processed, and the recipients to whom data has been or will be disclosed.
- Right to Rectification: Where personal data held by Genesis Global Limited is found to be inaccurate or incomplete, data subjects are entitled to request the rectification or completion of such data without undue delay.
- Right to Erasure: Data subjects are entitled to request the deletion of personal data where the data is no longer necessary for the purposes for which it was collected, where consent has been withdrawn and no alternative lawful basis for processing exists, or where processing has been determined to be unlawful. This right is subject to applicable exemptions, including those arising from legal or regulatory retention obligations.
- Right to Restriction of Processing: Data subjects are entitled to request the restriction of processing in circumstances prescribed by applicable data protection law, including where the accuracy of personal data is contested or where processing is unlawful but erasure is not requested.
- Right to Data Portability: Where processing is based upon consent or the performance of a contract and is carried out by automated means, data subjects are entitled to receive personal data provided by them in a structured, commonly used, and machine-readable format, and to transmit such data to another controller without hindrance.
- Right to Object: Data subjects are entitled to object, on grounds relating to their particular situation, to the processing of personal data where such processing is based upon legitimate interests. Upon receipt of a valid objection, processing of the relevant data shall cease unless compelling legitimate grounds for processing are demonstrated that override the interests, rights, and freedoms of the data subject.
- Right to Withdraw Consent: Where processing is conducted on the basis of consent, data subjects are entitled to withdraw such consent at any time. Withdrawal of consent does not affect the lawfulness of processing conducted prior to such withdrawal.
- Right to Lodge a Complaint: Data subjects are entitled to lodge a complaint with the competent supervisory authority in the member state of their habitual residence, place of work, or place of the alleged infringement, where they consider that the processing of their personal data is in violation of applicable data protection legislation.
Contact Us
All requests, enquiries, or correspondence relating to the processing of personal data, including the exercise of data subject rights as set out in this policy, shall be directed to the data controller using the following means of electronic communication:
Electronic correspondence: info@casinov