Effective Date: 25/05/2026
Data Controller: casinosiniceland.is
Privacy Contact: [email protected]
This Privacy Policy is issued by casinosiniceland.is in compliance with the General Data Protection Regulation (EU) 2016/679 ("GDPR") and applicable national data protection law. Unlike conventional privacy documents that bury your rights at the bottom, this Policy opens with them — because knowing what you are entitled to is the most important thing you can take from this page. All privacy requests should be directed to [email protected].
II. What Personal Data We Collect
We collect data across four categories. The table below identifies each category, its specific data points, when it is collected, and the legal basis under which it is processed.
| Category | Data Points Collected | When Collected | Legal Basis (GDPR Art. 6) |
|---|---|---|---|
| Personal Identity | Full legal name, date of birth, email address, country of residence, username, encrypted password | Account registration | Art. 6(1)(b) — Contract performance |
| Identity Verification (KYC) | Government-issued photo ID, proof of address (≤90 days), selfie verification where required | Pre-transaction verification | Art. 6(1)(c) — Legal obligation |
| Financial | Payment method type, partial identifier, transaction amounts, currencies, timestamps, provider reference numbers | Every deposit and withdrawal | Art. 6(1)(b) + Art. 6(1)(c) |
| Gameplay | Games played, bet sizes, session duration, win/loss records, bonus activity, RG tool interactions | Every game session | Art. 6(1)(b) + Art. 6(1)(f) |
| Technical | IP address, device type, browser, OS, session logs, page interaction data, referral source | Every platform visit | Art. 6(1)(f) — Legitimate interests |
| Communication | Support chat transcripts, email correspondence, ticket records | Every support interaction | Art. 6(1)(f) — Legitimate interests |
| Marketing Preference | Opted-in channels, campaign interaction data, promotional signals | At consent opt-in | Art. 6(1)(a) — Consent |
Full payment card numbers are never stored on casinosiniceland.is systems. Card data is handled exclusively within a PCI DSS-compliant environment operated by our payment service provider.
III. Why We Use Your Data — Purposes Mapped
Every processing purpose at casinosiniceland.is has a defined legal basis and a specific operational scope. We process nothing beyond the purposes listed below.
| Processing Purpose | What We Do | Legal Basis |
|---|---|---|
| Service delivery | Operate your account, process payments, deliver game access, administer bonuses | Contract performance |
| Legal and regulatory compliance | KYC verification, AML transaction monitoring, gambling licence record-keeping | Legal obligation |
| Responsible gambling monitoring | Analyse gameplay for statistical harm indicators; human-reviewed welfare responses only — no automated enforcement | Legitimate interests |
| Fraud and security | Detect unauthorised access, suspicious transactions, multi-accounting, and platform abuse | Legitimate interests |
| Marketing | Send promotional communications via consented channels; personalise on-platform offers | Consent (withdrawable) |
| Platform improvement | Aggregate, anonymised analysis of usage patterns to resolve errors and enhance navigation | Legitimate interests |
| Automated risk flagging | Flag accounts for human review based on behavioural patterns — no legally significant decisions made without human oversight | Legitimate interests + Art. 22 safeguards |
Regarding automated decision-making: our fraud and responsible gambling systems flag patterns algorithmically, but no account restriction, closure, or regulatory action is taken by automated means alone. A human operator reviews every flagged case before action is taken, in compliance with Article 22 GDPR.
IV. Cookies — Types, Purposes and Your Controls
casinosiniceland.is uses four categories of cookies. The table below details each type.
| Cookie Type | What It Does | Retention | Consent Required |
|---|---|---|---|
| Strictly Necessary | Session management, login, security tokens | Session / up to 24 hours | No — essential to platform function |
| Functional | Language, display preferences, saved settings | Up to 12 months | No — necessary for user experience |
| Analytical | Anonymised performance data, error monitoring | Up to 13 months | Yes — activated on consent only |
| Marketing | Personalised offers, retargeting, affiliate tracking | Up to 24 months | Yes — activated on consent only |
Manage your cookie preferences at any time through the Cookie Settings panel in our platform footer. Withdrawing consent for analytical or marketing cookies does not restrict access to any core platform feature.
V. Protections — Sharing, Retention and Security
Who We Share Your Data With
We do not sell, rent, or commercially transfer your data. Sharing occurs only in these defined circumstances:
| Recipient | Data Shared | Basis |
|---|---|---|
| Service providers (processors) | Minimum data necessary for contracted function — payments, KYC, hosting, support, email | Data processing agreement; GDPR-compliant standards required |
| Regulatory and law enforcement authorities | Identity, transaction, and account data | Legal obligation or lawful demand only |
| Responsible gambling registers | Minimum data to enforce self-exclusion across operators | Legal obligation under licensing conditions |
| Business successors | Account data in merger, acquisition, or asset sale | Legitimate interests; prior written player notification required |
All processors outside the European Economic Area operate under Standard Contractual Clauses pursuant to Article 46(2)(c) GDPR before any data transfer.
How Long We Keep Your Data
| Data Type | Retention Period | Basis |
|---|---|---|
| Account identity and KYC records | 5 years from account closure | AML and gambling regulation |
| Financial transaction records | 7 years from transaction date | Tax and financial law |
| Gameplay session records | 3 years from session date | Regulatory audit requirement |
| Support communications | 2 years from resolution | Dispute resolution |
| Technical and log data | 12 months from generation | Security monitoring |
| Marketing preference data | Until consent withdrawn | Consent |
| Cookie data | Per category duration above | Consent or necessity |
Data is permanently and securely deleted upon expiry of the applicable period from all Controller and processor systems.
Security Measures
casinosiniceland.is maintains the following technical and organisational safeguards:
- TLS 1.2+ encryption for all data in transit between your device and our platform
- AES-256 encryption for sensitive personal and financial data stored at rest
- Role-based access controls with comprehensive logging and quarterly internal audit
- PCI DSS-compliant payment data handling; full card numbers never stored
- Independent penetration testing and vulnerability assessments on a regular schedule
- Breach response protocol — supervisory authority notification within 72 hours; affected individuals notified without undue delay per Articles 33–34 GDPR
VI. Policy Updates and How to Reach Us
This Privacy Policy is reviewed and updated periodically to reflect changes in our data practices, platform functionality, or applicable legislation. When material changes occur, registered users receive advance notification by email, and the revised Policy is published with an updated effective date. Continued use of the platform following such notification constitutes acknowledgement of the revised terms.
For all privacy matters — including data subject requests, complaints, and general enquiries about how your data is handled — contact us at:
casinosiniceland.is
[email protected]
We are committed to resolving all privacy concerns transparently and within the timeframes prescribed by GDPR. Where resolution through the Controller is not satisfactory, your right to escalate to a national supervisory authority remains unconditional and unrestricted.