Privacy Policy of Casiny Casino
1. Scope and responsible entity
This Privacy Policy explains how Casiny, operating the website at casiny-au-casinos.com, collects, uses, discloses, and protects personal information in connection with the provision of online gambling services in Australia. For the purposes of applicable data protection law, including the Australian Privacy Act 1988 (Cth) and the Australian Privacy Principles (APPs), Casiny acts as the responsible entity for the personal information processed through the website and associated services.
Casiny Casino may also be subject to regulatory and compliance requirements connected with its gambling operations, including anti-money laundering and counter-terrorism financing obligations. Where relevant, the gambling services are operated under a licence issued by Curaçao eGaming (Curaçao), which may require verification, recordkeeping, and reporting measures. Questions, requests, or complaints regarding privacy and data protection should be directed to [email protected].
2. Categories of collected data
Casiny collects personal information that is reasonably necessary to provide, secure, and administer gambling services and to meet legal and regulatory requirements. The categories of personal information that may be collected include:
- Account and master data: full name, date of birth, residential address, email address, telephone number, username, and account identifiers.
- Identity verification and KYC/AML data: copies or images of government-issued identification (such as a passport or driver licence), proof of address (such as a utility bill issued within the last 90 days), and in some cases source-of-funds or source-of-wealth information.
- Financial and transaction data: deposit and withdrawal amounts, payment method identifiers, bank details where applicable, wallet identifiers, chargeback information, and transaction history.
- Technical and device data: IP address, device type, operating system, browser type and version, language settings, and time zone.
- Usage and behavioural data: login timestamps, gameplay activity, session duration, pages viewed, responsible gambling interactions (such as limit-setting actions), and security-related logs.
- Communications and support data: correspondence with customer support, chat transcripts, email content, and records of complaints or disputes.
3. Purposes of data processing
Casiny processes personal information for defined operational and compliance purposes consistent with Australian privacy principles of necessity, proportionality, and transparency. Key purposes include:
- Account creation and administration, including registration, authentication, and customer support handling.
- Identity verification and compliance checks, including KYC, AML/CTF screening, age verification (18+), fraud prevention, and sanctions screening where required.
- Payment processing and transaction management, including deposits, withdrawals, reconciliations, chargeback handling, and payment risk assessment.
- Security and integrity controls, including detecting suspicious activity, preventing unauthorised access, and maintaining audit trails.
- Responsible gambling operations, including the administration of self-exclusion, deposit limits, loss limits, and related recordkeeping.
- Service improvement and analytics, including performance monitoring, error diagnostics, and aggregated reporting to understand how the website functions.
- Compliance with legal obligations, including responding to lawful requests from regulators, dispute resolution bodies, or law enforcement agencies.
4. Legal bases for processing
Casiny processes personal information only where a lawful basis applies under relevant legal frameworks and in accordance with recognised privacy principles. Depending on the circumstances, the lawful bases include:
- Performance of a contract: processing necessary to provide the requested services, operate a player account, execute transactions, and deliver support.
- Compliance with legal obligations: processing required to meet AML/CTF, licensing, tax, recordkeeping, and consumer protection requirements, including mandatory verification steps.
- Legitimate interests: processing necessary to protect the website, prevent fraud, ensure network security, and maintain the integrity of services, provided those interests are not overridden by the individual’s rights.
- Consent (where applicable): processing based on consent for certain non-essential technologies or settings; where consent is relied upon, it may be withdrawn at any time through available controls, subject to legal constraints.
5. Data security
Casiny applies technical and organisational measures designed to protect personal information against accidental or unlawful destruction, loss, alteration, unauthorised disclosure, or access. Measures may include:
- Encryption in transit using TLS (including configurations equivalent to 256-bit encryption), and secure handling of credentials.
- Network protections such as firewalls, intrusion detection or prevention tooling, and rate-limiting to reduce automated attacks.
- Access controls, including role-based access, least-privilege principles, and multi-factor authentication for administrative systems.
- Monitoring and logging, including security event review, anomaly detection, and controlled retention of audit logs.
- Vendor and platform security assessments, patch management, and periodic security testing.
Despite these measures, no method of transmission over the internet or method of electronic storage is completely secure. Users should take reasonable precautions, including using unique passwords and maintaining device security, and should promptly notify [email protected] if they suspect unauthorised access.
6. Data sharing with third parties
Casiny discloses personal information only to the extent necessary for the purposes described in this Privacy Policy and subject to appropriate contractual and security safeguards. Categories of recipients may include:
- Payment processors and financial service providers involved in deposits, withdrawals, fraud screening, and chargeback management.
- Identity verification, KYC/AML, and fraud-prevention providers that validate documents, perform screening checks, and support compliance controls.
- Hosting, cloud, and IT service providers that support website delivery, storage, incident response, and operational tooling.
- Professional advisers, including legal, audit, and compliance advisers, where necessary for managing obligations and disputes.
- Regulatory authorities, dispute resolution bodies, and law enforcement agencies where disclosure is required or permitted by law.
Casiny does not sell personal information to third parties for marketing purposes. Where service providers act as processors or contractors, they are required to handle information only on documented instructions and to implement appropriate security measures.
7. Use of cookies and similar technologies
Casiny uses cookies and similar technologies to support core website functionality, security, and performance. Cookies may be set by the website or by service providers acting on Casiny’s behalf. Types of technologies used may include:
- Strictly necessary cookies: required for login, session management, security controls, and fraud prevention.
- Preference cookies: used to remember settings such as language and certain account preferences.
- Analytics cookies: used to collect aggregated statistics about website usage, such as page interactions and error events.
Users may manage cookies through browser settings, including blocking or deleting cookies. Disabling certain cookies may result in loss of functionality, such as persistent login sessions or parts of the account area not operating correctly.
8. Data subject rights and how to exercise them
Individuals have rights in relation to their personal information under applicable Australian privacy law and, where relevant, equivalent international principles. Subject to lawful limitations and verification of identity, requests may include the following 6 rights:
- Access: to request access to personal information held about you.
- Rectification: to request correction of inaccurate or incomplete information.
- Erasure: to request deletion where information is no longer required or where deletion is otherwise legally available.
- Restriction: to request limitation of processing in certain circumstances.
- Objection: to object to processing based on legitimate interests in appropriate cases.
- Data portability: to request a copy of certain information in a commonly used format where feasible.
Requests should be submitted to [email protected]. Casiny may require reasonable proof of identity before processing a request and will respond within a reasonable timeframe consistent with the nature and complexity of the request.
9. Data retention
Casiny retains personal information only for as long as necessary to fulfil the purposes described in this Privacy Policy and to comply with legal and regulatory obligations. Retention periods vary depending on the nature of the data and the context in which it was collected.
By way of example, identification and AML/CTF records may be retained for at least 5 years after account closure or completion of the relevant transactions, where required for compliance and audit purposes. Security logs may be retained for 12 months to support incident investigation and integrity monitoring, unless a longer period is required due to an active investigation or legal hold. After expiry of applicable retention periods, personal information is deleted or irreversibly de-identified, unless continued retention is required or permitted by law.
10. External links
The website may contain links to third-party websites, including payment provider pages, verification services, or informational resources. Casiny is not responsible for the privacy practices, content, or security of external websites that are not operated by Casiny.
Users should review the privacy policies and terms of any third-party website before providing personal information. Accessing external links is done at the user’s own discretion and subject to the third party’s applicable terms.
11. Changes to this privacy policy
Casiny may update this Privacy Policy from time to time to reflect changes in legal requirements, operational practices, security measures, or the features offered through casiny-au-casinos.com. Where changes are material, reasonable steps may be taken to provide notice through the website or account communications.
The updated version will apply from the date it is published on the website. Users should review this Privacy Policy periodically to remain informed about how Casiny Casino processes and protects personal information.
