Privacy Policy
Data We Collect
This Privacy Policy governs the collection, processing, and retention of personal data by Nexus Digital N.V. (hereinafter referred to as "the Company"), the operator of casinomrpunter.me.uk. The Company is incorporated under the laws of Curaçao and holds a valid gaming licence issued by Antillephone N.V. under licence reference 8048/JAZ, sub-licence 8048/JAZ2020-1301. All personal data processed by the Company is handled in strict accordance with applicable data protection legislation and the regulatory requirements governing licensed online gambling operations.
The following categories of personal data are subject to collection and processing when individuals access, register with, or otherwise interact with the services provided through this website:
- Identity Data: Full legal name, date of birth, nationality, and copies of government-issued identification documents, including passports, driving licences, and national identity cards, as required for the purposes of age verification and Know Your Customer (KYC) compliance.
- Contact Data: Residential address, electronic mail address, and telephone number, as provided during account registration or subsequent correspondence with the Company.
- Financial Data: Payment card details, bank account information, e-wallet identifiers, transaction histories, deposit and withdrawal records, and any documentation submitted in connection with anti-money laundering (AML) obligations.
- Technical Data: Internet Protocol (IP) addresses, browser type and version, operating system, device identifiers, session tokens, cookie data, and log files generated through interaction with the website.
- Usage Data: Wagering history, game participation records, betting patterns, session duration, promotional redemption activity, and responsible gambling self-assessment responses.
- Communications Data: Records of electronic correspondence, live chat transcripts, customer support enquiries, and any documentation submitted by the data subject in connection with disputes or complaints.
- Verification Data: Source of funds declarations, proof of address documentation, and enhanced due diligence materials collected pursuant to AML and Counter-Terrorist Financing (CTF) regulatory requirements.
Personal data is collected directly from data subjects upon registration and throughout the course of account usage, as well as from third-party verification service providers, payment processors, fraud prevention agencies, and regulatory databases where such collection is required by law or is necessary for the performance of the Company's regulatory obligations.
Use of Information
Personal data collected through the operation of this website is processed for the following specified, explicit, and legitimate purposes. Data subjects are advised that processing activities are conducted on the basis of one or more lawful grounds, including the performance of a contract, compliance with legal obligations, the protection of legitimate interests, and, where applicable, the explicit consent of the data subject.
- Account Registration and Management: Personal data is processed for the purposes of creating, administering, and maintaining player accounts, verifying the identity and age of registrants, and ensuring that access to gambling services is restricted to eligible individuals in accordance with applicable licensing conditions.
- Regulatory Compliance: Data is processed to fulfil obligations arising under anti-money laundering legislation, counter-terrorist financing regulations, and the requirements of the Curaçao gaming licence, including mandatory reporting duties and the maintenance of records for prescribed retention periods.
- Payment Processing: Financial data is processed to facilitate the acceptance of deposits, the execution of withdrawal requests, the prevention of fraudulent transactions, and the fulfilment of chargebacks or dispute resolution procedures.
- Responsible Gambling: Usage data and wagering records are analysed to identify indicators of problem gambling behaviour, to enforce self-exclusion arrangements, to apply account limitations requested by players, and to comply with responsible gambling obligations as stipulated by the licensing authority.
- Customer Support: Communications data is processed to respond to enquiries, manage complaints, and resolve disputes in a timely and effective manner.
- Fraud Prevention and Security: Technical data and usage patterns are monitored to detect, investigate, and prevent fraudulent activity, account compromise, collusion, bonus abuse, and other conduct contrary to the Company's terms and conditions or applicable law.
- Service Improvement: Aggregated and anonymised usage data may be analysed for the purpose of improving the functionality, performance, and user experience of the website, subject to the condition that such data cannot be used to identify individual data subjects.
- Marketing Communications: Where explicit consent has been obtained, contact data may be used to deliver promotional communications, including information regarding bonuses, offers, and new gaming products. Data subjects retain the right to withdraw such consent at any time without prejudice to the lawfulness of processing carried out prior to withdrawal.
- Legal Proceedings: Personal data may be processed where necessary for the establishment, exercise, or defence of legal claims, or where disclosure is required by a court order, regulatory direction, or other legally binding instrument.
Security Measures
The Company implements a comprehensive suite of technical and organisational measures designed to protect personal data against unauthorised access, accidental loss, destruction, alteration, or disclosure. These measures are reviewed and updated on a regular basis in light of evolving technological standards and identified risk factors.
The technical safeguards applied to the processing of personal data include, but are not limited to, the following:
- Encryption: All data transmitted between the data subject's device and the Company's servers is protected through Transport Layer Security (TLS) encryption protocols. Sensitive data held at rest, including financial records and identity documentation, is encrypted using industry-standard cryptographic algorithms.
- Access Controls: Access to personal data is restricted on the basis of role-based access control principles. Only those members of staff whose duties require access to specific categories of data are authorised to process such data, and all access is subject to authentication procedures.
- Firewalls and Intrusion Detection: Network perimeter defences, including firewalls and intrusion detection and prevention systems, are deployed to monitor and restrict unauthorised access to the Company's information systems.
- Secure Payment Infrastructure: Payment processing operations are conducted in accordance with the Payment Card Industry Data Security Standard (PCI DSS), and cardholder data is handled exclusively through certified and compliant payment service providers.
- Audit Logging: Comprehensive audit logs are maintained in respect of access to and processing activities performed upon personal data, enabling the detection and investigation of any anomalous or unauthorised activity.
- Data Minimisation: Personal data is collected and retained only to the extent strictly necessary for the fulfilment of the purposes described within this Privacy Policy. Data that is no longer required for such purposes is securely deleted or anonymised in accordance with the Company's data retention schedule.
The organisational measures implemented by the Company include the maintenance of internal data protection policies, the designation of personnel responsible for data protection oversight, the provision of data protection training to staff engaged in the processing of personal data, and the establishment of procedures for detecting, reporting, and managing personal data breaches. In the event that a breach of personal data security is identified and determined to present a risk to the rights and freedoms of data subjects, the Company shall take all steps required by applicable law to notify the relevant supervisory authority and, where necessary, the affected individuals within the prescribed timeframes.
Privacy Rights
Data subjects whose personal data is processed by the Company are entitled to exercise the rights enumerated below. Requests relating to the exercise of any of these rights should be submitted in writing to the electronic mail address set out in the Contact Us section of this Privacy Policy. The Company shall respond to all valid requests within the timeframe prescribed by applicable data protection law, which is ordinarily one calendar month from the date of receipt, subject to extension where the complexity or volume of requests necessitates additional time.
- Right of Access: Data subjects are entitled to request confirmation as to whether their personal data is being processed by the Company, and, where such processing is confirmed, to obtain a copy of the personal data held together with information regarding the purposes of processing, the categories of data concerned, the recipients or categories of recipient to whom data has been disclosed, and the intended retention period.
- Right to Rectification: Data subjects are entitled to request the correction of personal data that is inaccurate, incomplete, or out of date. The Company shall take all reasonable steps to rectify such data promptly upon receipt of a valid request and without undue delay.
- Right to Erasure: Data subjects may request the deletion of their personal data in circumstances where such data is no longer necessary for the purposes for which it was collected