casinoiniceland.is
Privacy Policy

What Happens to Your Data at casinoiniceland.is — From First Touch to Final Deletion

Effective Date: 25.05.2026
Data Controller: casinoiniceland.is
Privacy Contact: [email protected]

This Privacy Policy governs how casinoiniceland.is ("we," "us," "our") collects, processes, stores, shares, and ultimately deletes your personal data. It follows the natural lifecycle of your data — starting from the first moment we receive it and ending with its permanent removal. We comply fully with the General Data Protection Regulation (EU) 2016/679 ("GDPR") and all applicable national data protection laws. Direct any privacy questions to [email protected].

The Moment We Receive Your Data — What Gets Collected and Why

What data enters our system when I first interact with casinoiniceland.is?

Data collection begins the instant you visit our platform, before any account is created. Our systems automatically receive technical information — your IP address, browser type, device model, operating system, referring webpage, and session behaviour such as pages visited and time spent. This collection is automatic, not optional, and supports platform security and service delivery under our legitimate interests (Article 6(1)(f) GDPR).

What additional data do you collect when I register?

Creating an account adds a richer layer of personal identity data: your full legal name, date of birth, email address, country of residence, and chosen login credentials. This forms the backbone of our contractual relationship with you, processed under Article 6(1)(b) GDPR. Before any real-money activity is permitted, regulatory law requires us to complete identity verification. You will be asked to submit a government-issued photo ID, a recent proof of address, and in some cases a verification selfie. This Know Your Customer ("KYC") data is processed on the basis of legal obligation under Article 6(1)(c) GDPR.

What data is generated when I play games and make transactions?

Every game session creates gameplay data: titles played, bet sizes, session length, win and loss records, and responsible gambling tool interactions. Every financial transaction creates a parallel record: payment method type, transaction amount, currency, timestamp, and provider reference. Together, these four categories — personal identity, KYC verification, gameplay, and financial — constitute the complete picture of your data at casinoiniceland.is. We collect no data beyond these categories without separate and specific notice.

What about cookies — do you collect data just from browsing?

Yes, and we are transparent about it. casinoiniceland.is uses four categories of cookies. Strictly necessary cookies keep your session active, manage login authentication, and provide security functions. They require no consent and expire within twenty-four hours. Functional cookies remember your language and display preferences for up to twelve months — also deployed without consent as they are integral to service delivery. Analytical cookies capture anonymised platform performance data, retained up to thirteen months, and activated only with your consent. Marketing cookies personalise promotional content and track affiliate attribution, persisting up to twenty-four months, and requiring your explicit consent. You may update cookie preferences at any time via the Cookie Settings panel in our platform footer.

How We Process Your Data — The Purposes Behind Every Use

Why does casinoiniceland.is actually need to use my data?

We process your data for six defined purposes, each with a clear legal basis. First, service delivery: operating your account, executing transactions, delivering game access, and administering bonuses — all performed under contract performance (Article 6(1)(b)). Second, regulatory compliance: age and identity verification, anti-money laundering transaction monitoring, and gambling licence record-keeping — performed under legal obligation (Article 6(1)(c)). Third, responsible gambling monitoring: analysing gameplay patterns for statistical indicators of gambling harm and initiating human-led welfare responses where warranted — conducted under legitimate interests (Article 6(1)(f)), with human review applied to every case before any action is taken. Fourth, fraud and security: detecting unauthorised access, transaction fraud, and platform abuse — legitimate interests. Fifth, marketing: sending promotional communications through channels you have opted into — consent only (Article 6(1)(a)), withdrawable at any time. Sixth, platform improvement: analysing anonymised, aggregated usage data to enhance navigation and resolve errors — legitimate interests.

Do you make automated decisions about me?

Our fraud detection and responsible gambling monitoring systems analyse data automatically to flag patterns for review. However, no decision that produces a significant legal or similarly significant effect — such as account closure, fund restriction, or regulatory reporting — is made by automated means alone. Every flagged case receives human review before any action is taken. You have the right under Article 22 GDPR to request human review of any decision affecting your account. Exercise this right by contacting [email protected].

Where Your Data Is Stored and How We Protect It

Where do you keep my data — is it secure?

All personal data is stored on servers located within the European Economic Area ("EEA"). Where any third-party processor operates infrastructure outside the EEA, we require Standard Contractual Clauses approved by the European Commission (Article 46(2)(c) GDPR) to be in place before any transfer occurs. Our security architecture is layered and independently tested:

  • Encryption in transit: Transport Layer Security (TLS) 1.2 or higher protects all data moving between your device and our platform
  • Encryption at rest: Sensitive personal and financial data is encrypted using AES-256 standard
  • Access controls: Personal data is accessible only to staff with a documented operational requirement; all access is role-restricted, logged, and subject to quarterly audit
  • Payment security: Handled within a PCI DSS-compliant environment; full card numbers are never stored on casinoiniceland.is systems
  • Infrastructure testing: Independent penetration testing and vulnerability assessments are conducted on a regular schedule
  • Breach protocol: In the event of a breach likely to risk your rights, we notify the relevant supervisory authority within seventy-two hours and inform affected individuals without undue delay, per Articles 33–34 GDPR

How long do you actually keep different types of data?

Retention periods at casinoiniceland.is are governed by legal obligation and operational necessity — nothing more.

Data Type Retention Period Governing Requirement
Account identity and KYC records 5 years from account closure AML regulation and gambling licence
Financial transaction records 7 years from transaction date Tax and financial legislation
Gameplay session records 3 years from session date Regulatory audit obligations
Support communications 2 years from resolution date Dispute resolution
Technical and log data 12 months from generation Security monitoring
Marketing preference data Until consent is withdrawn Consent-based processing
Cookie data As per category duration above See cookie section

When a retention period expires, data is permanently and securely deleted. If you request erasure before a mandatory period expires, we will delete everything not subject to a legal hold and clearly identify what remains with the applicable basis.

Who We Share Your Data With — and Who We Don't

Does casinoiniceland.is sell or share my data commercially?

No. casinoiniceland.is does not sell, rent, license, or commercially transfer personal data under any circumstances. Sharing occurs only in the following four defined situations.

Service providers acting as processors: Payment processors, identity verification services, cloud hosting providers, customer support platforms, and email delivery services receive the minimum data necessary to perform their contracted function. All are bound by data processing agreements that prohibit secondary use of your data.

Regulatory and law enforcement authorities: Where applicable law, a gambling licensing condition, or a lawful authority demand requires disclosure, we comply to the extent legally required — no further.

Responsible gambling registers: Where self-exclusion obligations require data sharing with multi-operator exclusion programmes, we share the minimum necessary data to give effect to your exclusion.

Corporate transfers: In a merger, acquisition, or asset sale, data may transfer to the successor entity. We will notify affected players in writing before any such transfer and their rights under this policy will be preserved.

Your Rights and How to Exercise Them

What can I actually do about my data?

Under GDPR you hold seven rights, all exercisable by writing to [email protected]:

  • Access (Art. 15): Receive a full copy of your data and how it is used — response within 30 days
  • Rectification (Art. 16): Correct inaccurate or incomplete data — completed within 30 days
  • Erasure (Art. 17): Request deletion where grounds exist — honoured except where legal retention applies
  • Restriction (Art. 18): Pause processing during a dispute about accuracy or lawfulness
  • Portability (Art. 20): Receive your data in a machine-readable format or transfer it to another controller
  • Objection (Art. 21): Object to legitimate interest processing including profiling — we stop unless compelling grounds exist
  • Withdraw consent (Art. 7(3)): End consent-based processing immediately — use the unsubscribe link or contact [email protected]

If you are unsatisfied with our response, you may escalate to your national data protection supervisory authority without restriction or seek judicial remedy. There is no charge for exercising any of these rights.

Keeping This Policy Current — Changes and Contact

This Privacy Policy is reviewed periodically. When material changes are made, registered users receive advance email notification and the revised policy is published with an updated effective date. Continued use of the platform after notification constitutes acknowledgement of the updated terms.