bestonlinecasinosiceland.is
Privacy Policy

How bestonlinecasinosiceland.is Handles Your Data — A Step-by-Step Privacy Notice

Effective Date: 25/05/2026
Data Controller: bestonlinecasinosiceland.is
Privacy Contact: [email protected]

This Privacy Notice is issued by bestonlinecasinosiceland.is ("the Controller") and applies to all personal data processed in connection with your use of our platform, website, mobile service, and related products. It is structured to follow your actual journey with us — from the moment you visit our site to the controls you may exercise over your data at any time. We operate in full compliance with the General Data Protection Regulation (EU) 2016/679 ("GDPR") and applicable national data protection legislation. All privacy enquiries should be addressed to [email protected].

I. When You First Visit bestonlinecasinosiceland.is

In plain terms: Before you create an account, we automatically collect a limited set of technical data to keep the platform secure and functioning correctly. We also ask for your cookie preferences.

In legal detail: Upon accessing the Controller's website or mobile platform, technical data is automatically generated and collected by our systems. This includes your Internet Protocol (IP) address, device type and model, operating system, browser type and version, referring URL, pages accessed, and session duration. This processing is conducted on the basis of the Controller's legitimate interests pursuant to Article 6(1)(f) GDPR — specifically the interests of maintaining platform security, detecting fraudulent or unauthorised access attempts, diagnosing technical errors, and analysing aggregate usage patterns to improve service delivery. This data does not identify you personally at this stage and is not used to build individual visitor profiles.

At first visit, the platform presents a cookie consent interface. Cookies fall into four categories. Strictly necessary cookies operate without consent, providing session management, login authentication, and security token functions; they expire within twenty-four hours or at session end. Functional cookies preserve language and display preferences and persist for up to twelve months; they are necessary for the user experience and do not require consent. Analytical cookies collect anonymised platform performance data, are retained for up to thirteen months, and require your affirmative consent before activation. Marketing cookies support personalised promotional content and affiliate attribution, persist for up to twenty-four months, and require consent. Cookie preferences may be reviewed and amended at any time through the Cookie Settings panel located in the platform footer.

II. When You Register an Account

In plain terms: Creating an account requires personal information to verify your identity, confirm your age, and open your player account. This information forms the foundation of our contractual relationship with you.

In legal detail: Account registration requires submission of the following personal identity data: full legal name, date of birth, email address, country of residence, and chosen account credentials. This data is processed on the basis of Article 6(1)(b) GDPR — performance of the contract between you and the Controller. Prior to the activation of real-money functionality, the Controller is obligated under applicable anti-money laundering legislation and gambling regulatory requirements to verify the identity and address of all players. Identity verification ("Know Your Customer" or "KYC") requires submission of a valid government-issued photographic identification document, a documentary proof of current address dated within ninety days, and where required, a contemporaneous selfie alongside the identification document.

KYC data is processed by the Controller's regulated identity verification partner under a binding data processing agreement that restricts processing to the purpose of verification only. The legal basis for KYC processing is compliance with a legal obligation pursuant to Article 6(1)(c) GDPR. Registration and identity data is shared with no third party beyond the verification provider, except where disclosure is required by regulatory or law enforcement authority. Players who do not complete identity verification will not be permitted to conduct real-money transactions and may have account functionality restricted in accordance with our regulatory obligations.

III. When You Play

In plain terms: Each game session generates records we are required to keep for regulatory purposes and use to monitor for signs of gambling-related harm. We do not use gameplay data to target you with advertising without your consent.

In legal detail: Every interaction with the Controller's game library generates gameplay data, comprising the titles accessed, wager amounts placed, win and loss outcomes, session start and end timestamps, bonus activations and completions, and responsible gambling tool engagement records. This data is processed on two legal bases. Pursuant to Article 6(1)(b) GDPR, gameplay data is processed as necessary to perform the contractual service — specifically to operate game sessions, calculate outcomes, apply bonus terms, and maintain accurate account records. Pursuant to Article 6(1)(f) GDPR, gameplay data is additionally processed on the basis of the Controller's legitimate interests in monitoring for statistical indicators of disordered gambling behaviour, including but not limited to escalating session frequency, rapid loss progression, deviation from established play patterns, and repeated manual override of responsible gambling controls.

Where such indicators are detected, a human member of the Controller's player welfare team will review the data before any intervention is initiated. No welfare action — including proactive contact, temporary account restriction, or escalation to a responsible gambling support service — is taken solely on the basis of automated processing. Players retain the right to object to profiling based on legitimate interests at any time by contacting [email protected], pursuant to Article 21 GDPR. Gameplay records are retained for three years from the date of the relevant session in compliance with regulatory audit requirements.

IV. When You Make Transactions

In plain terms: Every deposit and withdrawal generates financial records we are required to keep for several years under tax and financial law. We never store your full card number, and your payment data is never sold.

In legal detail: Each deposit, withdrawal, or bonus transaction generates financial data, including the payment method category, partial payment identifier where applicable, transaction amount, currency, timestamp, and the reference identifier assigned by the Controller's payment service provider. The Controller processes this data on the basis of Article 6(1)(b) GDPR for the purpose of executing the requested transaction, and Article 6(1)(c) GDPR for the purpose of maintaining records required under applicable tax legislation and anti-money laundering regulation. Full payment card numbers are processed exclusively within the Controller's PCI DSS-compliant payment environment and are not stored on the Controller's own systems at any point. Financial transaction records are retained for seven years from the transaction date in compliance with applicable financial legislation. Account identity records linked to financial activity are retained for five years following permanent account closure in accordance with anti-money laundering regulatory requirements.

Financial data is shared with payment service providers acting as data processors under binding data processing agreements, and with regulatory or law enforcement authorities where disclosure constitutes a legal obligation. All payment processors operating outside the European Economic Area are subject to Standard Contractual Clauses adopted pursuant to Article 46(2)(c) GDPR prior to any international transfer of financial data. The Controller does not sell, rent, or commercially transfer financial data under any circumstances.

V. Your Controls and Data Subject Rights

In plain terms: You have seven enforceable rights over your data. This section explains each one and how to use it. All requests are free of charge and handled within thirty days.

In legal detail: As a data subject under GDPR, you are entitled to exercise the following rights in relation to personal data held by the Controller.

The right of access under Article 15 GDPR entitles you to receive a copy of all personal data held by the Controller, together with information concerning its processing purposes, legal bases, recipients, retention periods, and source. The right to rectification under Article 16 GDPR entitles you to correction of inaccurate or incomplete personal data without undue delay. The right to erasure under Article 17 GDPR entitles you to request deletion of personal data where it is no longer necessary for the purpose collected, where consent is withdrawn and no other lawful basis exists, or where processing has been unlawful. The Controller will honour erasure requests in full except where retention is mandated by a legal obligation, in which case the applicable obligation will be identified in writing. The right to restriction under Article 18 GDPR permits you to request that processing be suspended pending resolution of a dispute concerning accuracy or lawfulness. The right to data portability under Article 20 GDPR entitles you, where processing is automated and based on consent or contract, to receive your data in a structured, machine-readable format or to request its direct transmission to another controller. The right to object under Article 21 GDPR permits you to object at any time to processing based on legitimate interests, including profiling; the Controller will cease such processing unless compelling legitimate grounds are demonstrated. The right to withdraw consent under Article 7(3) GDPR permits withdrawal of consent at any time where consent is the basis for processing, without affecting the lawfulness of prior processing.

To exercise any right, submit a written request to [email protected] with sufficient information to verify your identity. The Controller will respond within thirty calendar days. No fee is charged for standard requests. Where a request is manifestly unfounded or excessive, the Controller may charge a reasonable fee or decline, with written justification. Where the Controller's response is unsatisfactory, you retain the unconditional right to lodge a complaint with your national data protection supervisory authority and to seek judicial remedy.

VI. Security and Policy Governance

The Controller maintains a documented technical and organisational security programme, including: TLS 1.2 or higher encryption for all data in transit; AES-256 encryption for sensitive data stored at rest; role-based access controls with full access logging and regular audit; PCI DSS-compliant payment data handling; independent penetration testing on a regular schedule; and a formal breach response protocol providing for supervisory authority notification within seventy-two hours and individual notification without undue delay, in accordance with Articles 33 and 34 GDPR.

This Notice is reviewed periodically and updated to reflect changes in data practices, platform functionality, or applicable legal requirements. Material amendments will be communicated to registered users by email in advance of the revised effective date. Continued use of the platform following notification constitutes acknowledgement of the updated Notice.