Effective Date: 25/05/2026
Data Controller: casinosiniceland.is
Privacy Contact: [email protected]

This Privacy Policy is issued by casinosiniceland.is in compliance with the General Data Protection Regulation (EU) 2016/679 ("GDPR") and applicable national data protection law. Unlike conventional privacy documents that bury your rights at the bottom, this Policy opens with them — because knowing what you are entitled to is the most important thing you can take from this page. All privacy requests should be directed to [email protected].

II. What Personal Data We Collect

We collect data across four categories. The table below identifies each category, its specific data points, when it is collected, and the legal basis under which it is processed.

Category Data Points Collected When Collected Legal Basis (GDPR Art. 6)
Personal Identity Full legal name, date of birth, email address, country of residence, username, encrypted password Account registration Art. 6(1)(b) — Contract performance
Identity Verification (KYC) Government-issued photo ID, proof of address (≤90 days), selfie verification where required Pre-transaction verification Art. 6(1)(c) — Legal obligation
Financial Payment method type, partial identifier, transaction amounts, currencies, timestamps, provider reference numbers Every deposit and withdrawal Art. 6(1)(b) + Art. 6(1)(c)
Gameplay Games played, bet sizes, session duration, win/loss records, bonus activity, RG tool interactions Every game session Art. 6(1)(b) + Art. 6(1)(f)
Technical IP address, device type, browser, OS, session logs, page interaction data, referral source Every platform visit Art. 6(1)(f) — Legitimate interests
Communication Support chat transcripts, email correspondence, ticket records Every support interaction Art. 6(1)(f) — Legitimate interests
Marketing Preference Opted-in channels, campaign interaction data, promotional signals At consent opt-in Art. 6(1)(a) — Consent

Full payment card numbers are never stored on casinosiniceland.is systems. Card data is handled exclusively within a PCI DSS-compliant environment operated by our payment service provider.

III. Why We Use Your Data — Purposes Mapped

Every processing purpose at casinosiniceland.is has a defined legal basis and a specific operational scope. We process nothing beyond the purposes listed below.

Processing Purpose What We Do Legal Basis
Service delivery Operate your account, process payments, deliver game access, administer bonuses Contract performance
Legal and regulatory compliance KYC verification, AML transaction monitoring, gambling licence record-keeping Legal obligation
Responsible gambling monitoring Analyse gameplay for statistical harm indicators; human-reviewed welfare responses only — no automated enforcement Legitimate interests
Fraud and security Detect unauthorised access, suspicious transactions, multi-accounting, and platform abuse Legitimate interests
Marketing Send promotional communications via consented channels; personalise on-platform offers Consent (withdrawable)
Platform improvement Aggregate, anonymised analysis of usage patterns to resolve errors and enhance navigation Legitimate interests
Automated risk flagging Flag accounts for human review based on behavioural patterns — no legally significant decisions made without human oversight Legitimate interests + Art. 22 safeguards

Regarding automated decision-making: our fraud and responsible gambling systems flag patterns algorithmically, but no account restriction, closure, or regulatory action is taken by automated means alone. A human operator reviews every flagged case before action is taken, in compliance with Article 22 GDPR.

IV. Cookies — Types, Purposes and Your Controls

casinosiniceland.is uses four categories of cookies. The table below details each type.

Cookie Type What It Does Retention Consent Required
Strictly Necessary Session management, login, security tokens Session / up to 24 hours No — essential to platform function
Functional Language, display preferences, saved settings Up to 12 months No — necessary for user experience
Analytical Anonymised performance data, error monitoring Up to 13 months Yes — activated on consent only
Marketing Personalised offers, retargeting, affiliate tracking Up to 24 months Yes — activated on consent only

Manage your cookie preferences at any time through the Cookie Settings panel in our platform footer. Withdrawing consent for analytical or marketing cookies does not restrict access to any core platform feature.

V. Protections — Sharing, Retention and Security

Who We Share Your Data With

We do not sell, rent, or commercially transfer your data. Sharing occurs only in these defined circumstances:

Recipient Data Shared Basis
Service providers (processors) Minimum data necessary for contracted function — payments, KYC, hosting, support, email Data processing agreement; GDPR-compliant standards required
Regulatory and law enforcement authorities Identity, transaction, and account data Legal obligation or lawful demand only
Responsible gambling registers Minimum data to enforce self-exclusion across operators Legal obligation under licensing conditions
Business successors Account data in merger, acquisition, or asset sale Legitimate interests; prior written player notification required

All processors outside the European Economic Area operate under Standard Contractual Clauses pursuant to Article 46(2)(c) GDPR before any data transfer.

How Long We Keep Your Data

Data Type Retention Period Basis
Account identity and KYC records 5 years from account closure AML and gambling regulation
Financial transaction records 7 years from transaction date Tax and financial law
Gameplay session records 3 years from session date Regulatory audit requirement
Support communications 2 years from resolution Dispute resolution
Technical and log data 12 months from generation Security monitoring
Marketing preference data Until consent withdrawn Consent
Cookie data Per category duration above Consent or necessity

Data is permanently and securely deleted upon expiry of the applicable period from all Controller and processor systems.

Security Measures

casinosiniceland.is maintains the following technical and organisational safeguards:

  • TLS 1.2+ encryption for all data in transit between your device and our platform
  • AES-256 encryption for sensitive personal and financial data stored at rest
  • Role-based access controls with comprehensive logging and quarterly internal audit
  • PCI DSS-compliant payment data handling; full card numbers never stored
  • Independent penetration testing and vulnerability assessments on a regular schedule
  • Breach response protocol — supervisory authority notification within 72 hours; affected individuals notified without undue delay per Articles 33–34 GDPR

VI. Policy Updates and How to Reach Us

This Privacy Policy is reviewed and updated periodically to reflect changes in our data practices, platform functionality, or applicable legislation. When material changes occur, registered users receive advance notification by email, and the revised Policy is published with an updated effective date. Continued use of the platform following such notification constitutes acknowledgement of the revised terms.

For all privacy matters — including data subject requests, complaints, and general enquiries about how your data is handled — contact us at:

casinosiniceland.is
[email protected]

We are committed to resolving all privacy concerns transparently and within the timeframes prescribed by GDPR. Where resolution through the Controller is not satisfactory, your right to escalate to a national supervisory authority remains unconditional and unrestricted.