Privacy & Security
Information Collection
The following categories of personal data are subject to collection and processing by Metlait SRL, operating the digital platform accessible at goldencrown-casino.co, in accordance with applicable data protection legislation and the conditions established under licence reference ALSI-202509073-FI2:
- Identification Data: Full legal name, date of birth, nationality, and government-issued identification document details are collected for the purpose of identity verification and regulatory compliance.
- Contact Data: Electronic mail addresses, telephone numbers, and residential addresses are recorded to facilitate service-related communications and account administration.
- Financial Data: Payment instrument details, transaction histories, deposit and withdrawal records, and associated banking information are processed in connection with the provision of financial operations on the platform.
- Technical Data: Internet Protocol addresses, browser type and version, operating system identifiers, device characteristics, session duration metrics, and navigational behavioural data are automatically collected upon interaction with the platform.
- Account Data: Username credentials, account preferences, gaming activity records, self-exclusion declarations, and responsible gaming parameters are maintained as part of the registered user profile.
- Verification Data: Documentation submitted in satisfaction of Know Your Customer obligations, including copies of identity documents and proof of address materials, is retained in accordance with statutory requirements.
Personal data is collected through direct submission by the data subject via registration forms and account management interfaces, as well as through automated technical means during platform usage. No personal data pertaining to minors under the age of eighteen years is knowingly collected or processed.
Data Usage
Personal data collected by Metlait SRL is processed exclusively for specified, explicit, and legitimate purposes. The following enumeration sets forth the principal purposes for which personal data is utilised in connection with service provision:
- Account Registration and Administration: Personal data is processed to establish, maintain, and administer user accounts, including authentication of user identity and management of account settings.
- Regulatory and Legal Compliance: Data processing is conducted to satisfy obligations imposed by applicable laws and regulations, including anti-money laundering requirements, responsible gaming mandates, and conditions attached to licence ALSI-202509073-FI2.
- Identity Verification: Submitted documentation and personal particulars are processed to verify the age, identity, and eligibility of users prior to and during the provision of services.
- Financial Transaction Processing: Payment-related data is processed to facilitate the execution, recording, and reconciliation of deposits, withdrawals, and associated financial operations.
- Fraud Prevention and Security: Behavioural, technical, and transactional data is analysed for the detection and prevention of fraudulent activity, unauthorised access, and other security incidents.
- Customer Support: Personal data is accessed and utilised by authorised personnel to address enquiries, resolve disputes, and provide assistance in connection with the use of the platform.
- Service Improvement: Aggregated and anonymised usage data is analysed for the purpose of enhancing platform functionality, user experience, and service quality.
- Communication: Contact data is utilised to transmit service-related notifications, regulatory disclosures, and responses to user-initiated correspondence.
Data processing activities are grounded in one or more of the following lawful bases: the performance of a contract to which the data subject is party; compliance with a legal obligation to which Metlait SRL is subject; the pursuit of legitimate interests; or, where applicable, the explicit consent of the data subject.
Data Protection
Metlait SRL has implemented a comprehensive framework of technical and organisational measures designed to ensure an appropriate level of security with respect to the risks associated with the processing of personal data. The measures enumerated herein are applied systematically and are subject to periodic review and enhancement.
Technical Measures
- Encryption: All personal data transmitted between users and the platform is protected through the application of Transport Layer Security protocols. Sensitive data stored within organisational systems is subject to encryption at rest utilising recognised cryptographic standards.
- Access Controls: Access to personal data is restricted on a need-to-know basis through the implementation of role-based access control mechanisms. Multi-factor authentication is required for access to systems containing personal data.
- Network Security: Perimeter security measures, including firewall configurations and intrusion detection systems, are maintained to prevent unauthorised external access to data processing infrastructure.
- Vulnerability Management: Regular security assessments, penetration testing, and vulnerability scanning procedures are conducted to identify and remediate potential security weaknesses.
- Data Integrity: Technical controls are maintained to ensure the accuracy, completeness, and consistency of personal data throughout its processing lifecycle.
Organisational Measures
- Personnel Training: All personnel with access to personal data are required to complete data protection training and are bound by confidentiality obligations.
- Data Processing Agreements: Where personal data is processed by third-party service providers on behalf of Metlait SRL, appropriate contractual arrangements are established to govern such processing.
- Incident Response: Documented procedures are maintained for the identification, assessment, and notification of personal data breaches in accordance with applicable regulatory requirements.
- Data Minimisation: Personal data is collected and retained only to the extent necessary for the fulfilment of the purposes for which it was obtained.
- Retention Schedules: Personal data is retained only for periods determined to be necessary in light of legal obligations and processing purposes, following which it is securely deleted or anonymised.
User Rights
Data subjects whose personal data is processed by Metlait SRL are afforded a set of rights under applicable data protection legislation. The exercise of such rights is subject to conditions and limitations prescribed by law. The rights available to data subjects are set forth as follows:
- Right of Access: Data subjects are entitled to obtain confirmation as to whether personal data concerning them is being processed and, where such processing is occurring, to receive a copy of the personal data together with supplementary information regarding the nature and circumstances of that processing.
- Right to Rectification: Data subjects are entitled to request the correction of inaccurate personal data concerning them and the completion of incomplete personal data, without undue delay.
- Right to Erasure: Data subjects are entitled to request the deletion of personal data concerning them where specified grounds exist, including where the data is no longer necessary for the purposes for which it was collected, subject to any overriding legal obligations requiring its retention.
- Right to Restriction of Processing: Data subjects are entitled to request that the processing of their personal data be restricted in circumstances defined by applicable law, including where the accuracy of the data is contested or the processing is determined to be unlawful.
- Right to Data Portability: Data subjects are entitled to receive personal data concerning them, which has been provided by them and is processed on the basis of consent or contract, in a structured, commonly used, and machine-readable format, and to have such data transmitted to another controller where technically feasible.
- Right to Object: Data subjects are entitled to object to the processing of personal data concerning them where such processing is based upon legitimate interests, including processing for direct marketing purposes.
- Right to Withdraw Consent: Where processing is based upon consent, data subjects are entitled to withdraw such consent at any time, without affecting the lawfulness of processing carried out prior to withdrawal.
- Right to Lodge a Complaint: Data subjects are entitled to lodge a complaint with the competent supervisory authority where it is considered that the processing of personal data infringes applicable data protection legislation.
Requests relating to the exercise of any of the rights enumerated above should be directed to Metlait SRL through the contact channel specified herein. Responses to duly submitted requests shall be provided within the timeframes prescribed by applicable law. Verification of the identity of the requesting party may be required prior to the processing of such requests.
Get in Touch
All enquiries, requests, and correspondence relating to the processing of personal data by Metlait SRL, including the exercise of data subject rights as described within this document, shall be directed to the following electronic correspondence address:
Electronic Correspondence: [email protected]
Correspondence should be submitted in written form and should include sufficient particulars to enable the identification of the data subject and the nature of the request or enquiry. Metlait SRL is committed to responding to all legitimate data protection enquiries within applicable statutory timeframes. All communications received through the above channel are treated with strict confidentiality and are processed exclusively for the purpose of addressing the subject matter of the correspondence.