This policy explains how SpinEmpire Casino collects, uses and protects the personal data of players in Ireland. Processing complies with the EU General Data Protection Regulation (GDPR), which applies in full to Irish residents and gives every account holder concrete, enforceable rights described at the end of this document.
Categories of data processed:
Collection is limited to these categories, and each item ties to at least one of the purposes below.
| Purpose | Legal Basis |
|---|---|
| Operating your account and paying out winnings | Performance of contract |
| Age verification and KYC checks | Legal obligation |
| Fraud and money-laundering prevention | Legal obligation / legitimate interest |
| Responsible gambling monitoring | Legal obligation / legitimate interest |
| Service improvement and security | Legitimate interest |
| Marketing communications | Consent (withdrawable at any time) |
Data is never processed for purposes incompatible with those listed. Withdrawing marketing consent stops promotional contact and has no effect on account operation.
Cookies keep you logged in, remember preferences and support security and analytics. Essential cookies are required for the platform to function; non-essential cookies can be controlled through your browser settings.
Blocking essential cookies may prevent login or gameplay. Browser controls also allow deletion of existing cookies at any time, though doing so ends active sessions.
Personal data is shared only where necessary: with payment providers to process deposits and withdrawals, with KYC verification services to meet legal identity-check obligations, and with authorities where the law requires disclosure. Each recipient receives only the data its function requires.
Data is not sold to third parties, and it is not shared for advertising purposes.
All data in transit is protected by SSL encryption, and access to personal data internally is restricted to staff who need it for their role.
Data is kept only as long as its purpose requires. Account and transaction records are retained for the periods mandated by anti-money-laundering and licensing rules after account closure — a legal requirement rather than an operator preference. Marketing data is deleted when consent is withdrawn.
Once no retention obligation remains, data is erased or anonymised.
Under GDPR you may exercise the following rights at any time, free of charge:
Requests receive a response within the timeframes GDPR sets, normally one month. You also retain the right to lodge a complaint with the Data Protection Commission in Ireland.
Data requests and privacy questions can be sent to [email protected] or raised through 24/7 live chat. Include the email address linked to your account so the request can be matched and verified before any data is released.