Privacy Policy

Last updated: August 14, 2025

1. Notice Purpose and Responsible Company

1.1. Why this notice is provided

This Privacy and Data Safety Notice describes how Personal Data is handled when you access the Website, use the Services, communicate with support, or interact with the platform through available service channels.

The purpose of this notice is to explain how Personal Data may be collected, used, retained, transferred, disclosed, protected, and removed or anonymized where applicable. It also outlines your rights, complaint options, cookie controls, and the possible consequences of not providing Personal Data required for legal, contractual, or service-related purposes.

1.2. Company responsible for Personal Data

The Website is owned and operated by Carletta N.V., a company incorporated in Curaçao.

Company information:

  • Registered office: Dr. Henri Fergusonweg 1, Curaçao
  • Company registration number: 142346
  • Licensing authority: Curaçao Gaming Control Board
  • Licensed since: 24/Jun/2025
  • License number: OGL/2024/580/0570
  • Applicable framework: National Ordinance on Games of Chance (LOK)

Carletta N.V. is the controller of your Personal Data. This means that the Company determines the reasons for Processing Personal Data and the manner in which such Processing is carried out in connection with the Website and Services.

1.3. Channels covered by this notice

This notice applies to Personal Data processed through:

  • the Website;
  • email communications via [email protected];
  • phone calls with us;
  • support chat sessions.

2. Terms Used in This Safety Notice

2.1. Account

Account means the unique account created for you to access the Services or specific Service areas.

An Account may be subject to identity checks and Regulatory Compliance requirements before access is granted or continued.

2.2. Company

Company, we, us, or our means Carletta N.V., registered under Curaçao law with registration number 142346 and office address at Dr. Henri Fergusonweg 1, Curaçao.

2.3. Service

Service means the Website, its features, and the related online gaming and interactive services made available by the Company.

2.4. Website

Website means this website and includes subdomains, associated platforms, and applications operated by the Company.

2.5. Personal Data

Personal Data means any information relating to an identified or identifiable person, as defined under the General Data Protection Regulation and the Curaçao Data Protection Framework.

2.6. Processing of Personal Data

Processing of Personal Data means any action or set of actions performed with Personal Data, whether by automated or manual means.

This may include collecting, recording, organizing, structuring, storing, changing, retrieving, consulting, using, disclosing, transmitting, disseminating, aligning, combining, restricting, erasing, or destroying Personal Data.

2.7. Regulatory Compliance

Regulatory Compliance means the Company’s legal obligation to process Personal Data under applicable laws and rules, including the National Ordinance on Games of Chance and Anti-Money Laundering regulations.

Processing carried out for Regulatory Compliance is required by law and does not depend on user consent.

3. Safety Area: Account Access and Authentication

3.1. Why Account data is needed

Personal Data is processed to register, activate, secure, and manage your Account and to allow access to the Services or selected parts of them.

This Processing helps ensure that Account access is connected to the correct user and that access logs can support Account security.

3.2. Legal basis

The legal basis for Account-related Processing is performance of a contract or steps taken before entering into a contract under GDPR Article 6(1)(b).

3.3. Personal Data involved

For Account registration and access, the Company may process:

  • email address and/or phone number;
  • hashed password;
  • chosen currency;
  • account identifiers;
  • basic device or access logs used to activate and secure the Account.

4. Safety Area: Identity, Age, and Compliance Checks

4.1. Why verification is required

The Company may process Personal Data to verify identity, confirm age, complete KYC checks, and meet AML/CFT, LOK, and NORUT obligations.

These checks are part of legal and regulatory safeguards and are not optional where they are required by law.

4.2. Legal basis

The legal basis is compliance with legal obligations under GDPR Article 6(1)(c), including AML/CFT, LOK, and NORUT.

Where relevant, the Company may also rely on legitimate interests in protecting platform integrity under GDPR Article 6(1)(f).

4.3. Personal Data involved

Verification and compliance checks may require:

  • passport;
  • ID card;
  • driver’s license;
  • proof of address;
  • date of birth or age attestation;
  • selfies;
  • liveness checks.

5. Safety Area: Payments and Financial Records

5.1. Why payment data is processed

Personal Data may be used to process deposits, withdrawals, refunds, payout confirmations, and other payment-related operations.

Payment information may also be required for financial records, AML obligations, fraud prevention, audits, and dispute handling.

5.2. Legal basis

Payment Processing may rely on:

  • performance of a contract under GDPR Article 6(1)(b);
  • compliance with financial record-keeping and AML obligations under GDPR Article 6(1)(c);
  • legitimate interests in fraud prevention under GDPR Article 6(1)(f).

5.3. Personal Data involved

Payment-related Processing may include:

  • payment instrument data;
  • transaction history;
  • currency;
  • payout channel confirmations.

6. Safety Area: Fraud Prevention and Platform Security

6.1. Why technical data is monitored

The Company may process technical information to detect suspicious activity, prevent unauthorized access, reduce platform abuse, and protect the security of the Services and users.

This Processing supports the safe operation of the Website and assists with compliance where AML/CTF obligations apply.

6.2. Legal basis

The legal bases are:

  • legitimate interests in securing the Service and users under GDPR Article 6(1)(f);
  • legal obligations under AML/CTF requirements under GDPR Article 6(1)(c).

6.3. Personal Data involved

Security and fraud prevention may involve:

  • IP address;
  • device type;
  • browser data;
  • device identifiers;
  • technical identifiers.

7. Safety Area: Responsible Gaming and Player Protection

7.1. Why player protection data is used

The Company may process Personal Data to support responsible gaming measures, player protection obligations, self-exclusion, cooling-off tools, limits, and risk-related interventions.

This Processing is used to meet regulatory duties and to support safeguards connected with user welfare.

7.2. Legal basis

The legal bases are:

  • compliance with LOK / CGA Responsible Gaming requirements under GDPR Article 6(1)(c);
  • legitimate interests in player welfare and Regulatory Compliance under GDPR Article 6(1)(f).

7.3. Personal Data involved

Responsible gaming and player protection Processing may include:

  • self-exclusion status;
  • self-exclusion duration;
  • cooling-off selections;
  • play limits;
  • gameplay frequency;
  • spend metrics indicative of risk;
  • communications related to responsible gaming interventions.

8. Safety Area: Support Communications

8.1. Why support data is handled

When you contact support, Personal Data may be processed to identify the request, provide a response, resolve the issue, review relevant Account or transaction information, and maintain service quality.

Support records may also be needed if a dispute arises or if the Company must verify how a request was handled.

8.2. Legal basis

The legal bases are:

  • performance of a contract under GDPR Article 6(1)(b);
  • legitimate interests in service quality and dispute resolution under GDPR Article 6(1)(f).

8.3. Personal Data involved

Support-related Processing may include:

  • support tickets;
  • chat transcripts;
  • email correspondence;
  • call notes;
  • account identifiers;
  • transaction references tied to the inquiry.

9. Safety Area: Marketing Communications

9.1. When marketing data may be used

Where permitted by law, the Company may process Personal Data for marketing communications.

Such Processing remains subject to applicable opt-out rights and responsible gaming restrictions.

9.2. Legal basis

Electronic marketing is based on consent under GDPR Article 6(1)(a).

Where allowed by law, similar-product soft opt-in may be based on legitimate interests under GDPR Article 6(1)(f).

9.3. Personal Data involved

Marketing-related Processing may include:

  • email address;
  • phone number;
  • push token;
  • marketing preferences;
  • engagement metrics;
  • non-sensitive bonus eligibility status.

10. Safety Area: Website Performance, Analytics, and Cookies

10.1. Why Website usage data is processed

The Company may process Website usage and technical data to operate the Website, measure performance, understand how visitors interact with the Website, and improve functionality.

Some Processing may occur through cookies or similar technologies.

10.2. Legal basis

The legal bases are:

  • legitimate interests in operating and improving the Website under GDPR Article 6(1)(f);
  • consent under GDPR Article 6(1)(a), where required for non-essential cookies.

10.3. Personal Data involved

Website performance and analytics Processing may include:

  • usage logs;
  • cookie identifiers;
  • browser type and version;
  • traffic data;
  • on-site interaction metrics.

11. Safety Area: Regulatory Reporting, Audits, and Legal Matters

11.1. Why official records may be processed

The Company may process Personal Data where needed for regulatory cooperation, compliance audits, legal proceedings, dispute resolution, or legal claims.

This may include cooperation with competent authorities where required by law.

11.2. Legal basis

The legal bases are:

  • legal obligation under GDPR Article 6(1)(c), including cooperation with the Curaçao Gaming Authority, FIU, tax authorities, and other authorities;
  • legitimate interests in establishing, exercising, or defending legal claims under GDPR Article 6(1)(f).

11.3. Personal Data involved

The Company may process relevant records required for:

  • regulatory cooperation;
  • compliance audits;
  • legal proceedings;
  • dispute resolution, as permitted by applicable laws.

12. Personal Data Sources

12.1. Information collected from you

The Company collects Personal Data directly from you when you interact with the Services.

This may occur when you:

  • create an Account;
  • complete verification steps;
  • make deposits;
  • request withdrawals;
  • communicate with support.

12.2. Information generated through Service use

Certain data is created through activity on the platform.

This may include:

  • gameplay;
  • transaction history;
  • device information;
  • log information;
  • cookie data in accordance with the Cookie Policy.

12.3. Information from trusted service providers

The Company may receive or verify Personal Data through trusted third parties that support:

  • compliance;
  • security;
  • payment-related functions;
  • identity verification.

12.4. Information from public and legitimate sources

Where necessary, the Company may supplement information you provide with information from publicly available and legitimate sources.

This is limited to:

  • compliance;
  • verification;
  • risk management.

12.5. Information from authorities

In some circumstances, the Company may receive Personal Data from regulatory or law enforcement authorities in connection with legal and compliance obligations.

13. Data Retention and End-of-Life Handling

13.1. Retention approach

Personal Data is kept only for as long as needed for the purposes for which it was collected and processed, or for as long as applicable legal or regulatory obligations require.

13.2. Retention criteria

The retention period may depend on:

  • the reason for Processing;
  • the need to provide the Services;
  • contractual obligations;
  • legitimate interests;
  • AML requirements;
  • gaming regulations;
  • tax regulations;
  • legal claims;
  • audits;
  • supervisory requirements.

13.3. Deletion, anonymization, or archiving

When the relevant retention period ends, Personal Data is securely deleted, anonymized, or archived in a way that prevents association with you, unless further retention is required by law.

14. Storage and International Transfer Safety

14.1. Storage locations

Personal Data is stored on secure servers operated by the Company and trusted service providers.

Depending on operational and regulatory requirements, servers may be located:

  • within the European Economic Area;
  • outside the European Economic Area;
  • in Curaçao.

14.2. Transfers outside the EEA

Where Personal Data is transferred outside the EEA, the Company applies measures required under applicable data protection laws.

14.3. Adequacy decisions

Personal Data may be transferred to countries recognized by the European Commission as providing an adequate level of data protection.

14.4. Standard Contractual Clauses

Where no adequacy decision applies, the Company uses Standard Contractual Clauses approved by the European Commission to support protection of Personal Data transferred outside the EEA.

15. Sharing and Disclosure Safety

15.1. General disclosure rule

Personal Data is shared only where necessary and only for the purposes described in this Privacy Policy.

Any disclosure is handled in accordance with applicable data protection laws, contractual requirements, and security measures.

15.2. Regulatory and supervisory authorities

Personal Data may be disclosed to:

  • Curaçao Gaming Authority;
  • Financial Intelligence Unit;
  • tax authorities;
  • governmental bodies;
  • law enforcement bodies.

Such disclosure may be required by law or regulatory obligations, including AML and responsible gaming requirements.

15.3. Identity verification and compliance providers

Personal Data may be shared with service providers that assist with customer identity verification and compliance with AML and Know Your Customer obligations.

15.4. Payment processors and financial institutions

Personal Data may be shared to enable:

  • deposits;
  • withdrawals;
  • refunds;
  • other payment-related services.

This may include transaction details, payment method information, and account identifiers.

15.5. Customer support and communication tools

External providers may process Personal Data to support email delivery, live chat, or other communication channels.

This may include:

  • contact details;
  • support messages.

15.6. Fraud prevention and security partners

Trusted service providers may process Personal Data to help secure the platform and detect or prevent potentially fraudulent or unauthorized activity.

15.7. Analytics and optimization platforms

Third-party services may help analyze Website usage, conduct A/B testing, and improve user experience.

Where possible, such data is anonymized or pseudonymized.

15.8. Game content providers

Licensed third-party game providers may receive only the minimum Personal Data required for certain platform features.

This may include:

  • player identifiers;
  • game session data.

15.9. Internal tools and IT infrastructure providers

The Company may use secure hosting and productivity solutions to store and manage data needed for the operation of the Services.

16. Cookie Safety Information

16.1. What cookies are used for

The Website may use cookies and similar technologies to improve the user experience, enable essential Website functions, and measure performance.

Cookies are small text files stored on your device when you visit the Website. They help the Website recognize your device and remember preferences or previous actions.

16.2. Strictly necessary cookies

Strictly necessary cookies are required for core Website operation.

They support:

  • page navigation;
  • secure-area access;
  • user authentication.

These cookies cannot be switched off in the Company’s systems.

16.3. Functional cookies

Functional cookies support enhanced functionality and personalization.

They may remember:

  • language preferences;
  • user settings.

They may be set by the Company or by third-party providers whose services are used.

16.4. Analytical or performance cookies

Analytical or performance cookies collect aggregated and anonymized information about Website use.

This may include:

  • page visits;
  • click-through rates;
  • traffic sources;
  • on-site interaction metrics.

The purpose is to measure and improve Website performance.

16.5. Advertising or targeting cookies

Advertising or targeting cookies may be set by the Company or advertising partners.

They may be used to:

  • build a profile of interests;
  • deliver relevant advertising on this Website or other websites;
  • limit how often an advertisement appears;
  • assess advertising effectiveness.

16.6. Session and persistent cookies

Session cookies expire when your browser is closed.

Persistent cookies remain on your device for a predetermined period or until deleted by you.

16.7. First-party and third-party cookies

First-party cookies are set by the Company.

Third-party cookies are set by service providers acting on the Company’s behalf, including providers of analytics, customer support tools, or advertising networks.

16.8. Cookie management

You can manage cookies through your browser settings.

Most browsers allow you to refuse or delete cookies. If certain cookies are restricted, some Website features may become unavailable or may not function properly.

17. Minor Protection Notice

17.1. Minimum age

The Services are intended only for individuals who are at least eighteen (18) years old or who have reached the legal age in their jurisdiction, whichever is higher.

By accessing or registering for the Services, you confirm that you meet the applicable age requirement.

17.2. Underage access prevention

In alignment with the Curaçao Gaming Authority’s Responsible Gaming Policy introduced in February 2025, the Company applies measures intended to prevent underage access to the Services.

17.3. Document checks

Users may be required to provide valid government-issued identification documents during registration.

These checks help confirm age and support compliance with access restrictions.

17.4. Monitoring and security review

The Company may use automated monitoring to identify inconsistencies or possible signs of underage access attempts.

If underage access is suspected, security reviews may be conducted, including checks of registration data and financial transactions.

17.5. Data submitted by minors

Personal Data submitted by individuals identified as minors is deleted immediately.

17.6. Parental controls and education

Parents and guardians are encouraged to use available parental control tools and to educate minors about responsible online behavior so that unauthorized access to the Services can be prevented.

17.7. Responsible gaming safeguards

The Company’s responsible gaming measures include adherence to CGA guidance on player protection and age verification.

Policies are reviewed and enhanced to meet or exceed applicable regulatory standards.

18. Your Rights and Control Options

18.1. Right of Access

Under Article 15 GDPR, you may request confirmation of whether your Personal Data is processed and may obtain a copy of that data together with information on how it is used.

18.2. Right to Rectification

Under Article 16 GDPR, you may request correction of inaccurate or incomplete Personal Data without undue delay.

18.3. Right to Erasure

Under Article 17 GDPR, you may request deletion of Personal Data where applicable legal grounds exist.

This may apply, for example, where data is no longer needed for the purposes for which it was collected or where consent is withdrawn and no other lawful basis applies.

18.4. Right to Restrict Processing

Under Article 18 GDPR, you may request that Processing of your Personal Data be limited in specific cases, including where data accuracy is contested or Processing is unlawful.

18.5. Right to Data Portability

Under Article 20 GDPR, you may request the Personal Data you provided to the Company in a structured, commonly used, and machine-readable format.

Where technically feasible, that data may be transferred to another controller.

18.6. Right to Object

Under Article 21 GDPR, you may object to Processing based on legitimate interests for reasons related to your particular situation.

You may also object to Processing for direct marketing purposes.

18.7. How to submit a rights request

To exercise your data protection rights, contact the Company through:

19. Consent Withdrawal Notice

19.1. Right to withdraw consent

Where Processing is based on consent, you may withdraw that consent at any time.

19.2. Effect of withdrawal

Withdrawal does not affect the lawfulness of Processing carried out before consent was withdrawn.

19.3. How withdrawal is processed

To withdraw consent, use the contact channels listed in this Privacy Policy.

After the request is received, the Company will stop the relevant Processing unless continued retention or Processing is required for legal or regulatory reasons.

19.4. Possible service impact

If withdrawal of consent affects the Company’s ability to provide certain Services, the Company will explain the consequences before the withdrawal process is completed.

20. Complaints and Concerns

20.1. Complaint right

Under Article 77 GDPR, you may lodge a complaint if you believe that your Personal Data is being processed unlawfully or that your privacy rights have been violated.

20.2. Authorities that may receive complaints

A complaint may be lodged with:

  • the supervisory authority in the EU Member State where you reside;
  • the supervisory authority in the EU Member State where you work;
  • the supervisory authority in the EU Member State where the alleged violation occurred;
  • the Curaçao Gaming Authority;
  • any other relevant data protection authority in Curaçao.

20.3. Contact before escalation

If you have concerns or unresolved questions about Personal Data Processing, you are encouraged to contact the Company directly first.

The Company will make every reasonable effort to address concerns in a timely and lawful manner.

21. Required Personal Data Notice

21.1. Legal requirement

Some Personal Data must be provided so that the Company can comply with applicable laws and regulations, including Anti-Money Laundering obligations and responsible gaming requirements.

21.2. Contractual requirement

Certain Personal Data is needed to enter into and perform a contract with you, including data required to provide access to the Services and process transactions.

21.3. Service access requirement

Some Services cannot be made available unless required Personal Data is provided.

Without such data, the Company may be unable to fulfill contractual or legal obligations.

21.4. Consequences of not providing required data

Failure to provide required Personal Data may lead to:

  • inability to create or maintain an Account;
  • restrictions on use of the Services;
  • termination of the contractual relationship;
  • failure to comply with regulatory obligations, which may prevent the Company from providing Services.

22. Legal Safety Disclaimer

22.1. Service basis

The Services are provided on an “AS-IS” and “AS-AVAILABLE” basis.

The Company does not warrant or guarantee uninterrupted or error-free performance.

22.2. Security limitation

The Company applies reasonable precautions to protect Personal Data.

However, absolute security cannot be guaranteed due to the complexity of technology and changing cybersecurity threats.

22.3. Liability limitations

To the maximum extent permitted by law, the Company is not liable for:

  • events beyond its direct control, including system failures, cyberattacks, or unauthorized access;
  • indirect, incidental, consequential, or punitive damages arising from data breaches, unauthorized disclosure, or misuse of Personal Data;
  • errors, inaccuracies, or security vulnerabilities on third-party websites linked from the platform.

22.4. Third-party services

The Company does not bear responsibility for external websites or services operated by third parties, even if they are linked from the platform.

By using the Services, you acknowledge and agree to this limitation.

23. Policy Acceptance, Updates, and Language

23.1. Acceptance

Continued use of the Services signifies explicit acceptance of this Privacy Policy.

This document is the complete and exclusive Privacy Policy and replaces any prior versions.

23.2. Related documents

This Privacy Policy should be read together with:

  • the Terms and Conditions;
  • any additional applicable notices posted on the platform.

23.3. Updates

The Company reserves the right to modify this Privacy Policy at any time.

Changes will be posted on the platform. Continued use of the Services after modifications constitutes acceptance of the revised Policy.

23.4. Review recommendation

You are strongly encouraged to review this Privacy Policy regularly to remain informed about updates.

23.5. Language priority

All versions of this Privacy Policy other than the English version are provided for informational purposes only.