Privacy & Security
Information Gathering
This Privacy Policy governs the collection, processing, and storage of personal data by Pirca Limitada, operator of the website odinfortunecasino.me.uk, licensed under Curaçao eGaming licence number 8048/JAZ. The processing of personal data is conducted in strict accordance with applicable data protection legislation and regulatory requirements imposed by the licensing authority.
The following categories of personal data are subject to collection and processing in connection with the provision of services through this platform:
- Identity Data: Full legal name, date of birth, nationality, and government-issued identification document details, including passport numbers, national identity card numbers, and driving licence references.
- Contact Data: Residential address, electronic mail address, and telephone number, including mobile contact details provided at the time of registration or subsequently updated by the data subject.
- Financial Data: Banking account details, payment card information, transaction histories, deposit and withdrawal records, and any additional financial documentation submitted for the purpose of identity or source-of-funds verification.
- Account Data: Username credentials, account registration details, login timestamps, session data, and records of account preferences and configurations established by the data subject.
- Verification Data: Documentation submitted in compliance with Know Your Customer obligations, including proof of identity, proof of address, and source-of-funds documentation as required under anti-money laundering regulatory frameworks.
- Usage Data: Information pertaining to interaction with the platform, including pages accessed, features utilised, gaming activity records, wagering histories, and behavioural patterns observed during the use of services.
- Technical Data: Internet Protocol address, browser type and version, device identifiers, operating system specifications, referral source data, and cookie-related information collected through automated technological means.
- Communications Data: Records of correspondence conducted between the data subject and the operator, including electronic mail communications, live chat transcripts, and support ticket histories.
Personal data is collected directly from data subjects at the point of registration, during the completion of verification procedures, through ongoing use of the platform, and via communications initiated by either party. Data may additionally be obtained from third-party verification service providers, fraud prevention agencies, and regulatory databases where such collection is lawfully permitted and operationally necessary.
How We Use Data
Personal data collected through the operation of this platform is processed exclusively for lawful and specified purposes directly related to the provision, management, and improvement of services offered by Pirca Limitada. The following purposes constitute the basis upon which personal data is processed:
- Account Administration: Personal data is processed for the purpose of establishing, maintaining, and administering user accounts, including the verification of eligibility to register, the authentication of account access, and the management of account settings and preferences.
- Service Provision: Data pertaining to the data subject is processed as necessary to facilitate the delivery of gaming and entertainment services available through the platform, including the processing of wagers, the crediting and debiting of account balances, and the administration of promotional participation where applicable.
- Identity Verification and Regulatory Compliance: Personal data, including identity documentation and financial information, is processed in fulfilment of obligations arising under Curaçao eGaming licence conditions, anti-money laundering legislation, counter-terrorism financing requirements, and responsible gambling regulatory standards. Such processing is mandatory and constitutes a condition of continued service provision.
- Financial Transaction Processing: Payment data and associated financial information are processed for the purpose of executing deposits, withdrawals, and account balance adjustments, as well as for the prevention, detection, and investigation of fraudulent or unauthorised financial activity.
- Responsible Gambling Obligations: Account and usage data are processed for the purpose of monitoring gaming behaviour, identifying indicators of problematic gambling, implementing self-exclusion measures, and ensuring compliance with responsible gambling policies mandated by the applicable regulatory framework.
- Fraud Prevention and Security: Technical and usage data are processed to detect, prevent, and respond to fraudulent activity, security breaches, unauthorised account access, and other threats to the integrity of the platform and the security of data subjects.
- Legal Obligation Fulfilment: Data may be processed where such processing is required for compliance with legal obligations, including the disclosure of information to competent regulatory authorities, law enforcement agencies, or judicial bodies in accordance with applicable law.
- Service Improvement and Analytics: Anonymised or pseudonymised usage data may be processed for the purpose of analysing platform performance, identifying technical deficiencies, and informing improvements to the functionality and user experience of services provided.
- Customer Support: Communications data and account information are processed for the purpose of responding to enquiries, resolving disputes, and providing technical or administrative assistance to data subjects.
Personal data shall not be processed for purposes incompatible with those specified herein, nor shall data be sold, leased, or otherwise transferred to third parties for independent commercial purposes without the explicit consent of the data subject, except where such disclosure is required by applicable law or regulatory obligation.
Data Security
Pirca Limitada is committed to the implementation and maintenance of appropriate technical and organisational measures designed to protect personal data against unauthorised access, accidental loss, destruction, alteration, or disclosure. The security measures employed reflect the nature, scope, and sensitivity of the personal data processed, as well as the risks presented by current technological environments.
The following technical measures are applied to safeguard personal data processed in connection with the operation of odinfortunecasino.me.uk:
- Encryption: All data transmitted between data subjects and the platform is protected through the application of Secure Socket Layer or Transport Layer Security encryption protocols. Sensitive personal data, including financial information and identity documentation, is stored in encrypted form utilising industry-standard cryptographic methodologies.
- Access Controls: Access to personal data is restricted on a strict need-to-know basis. Internal access privileges are assigned in accordance with defined roles and responsibilities, and access rights are subject to periodic review and revocation where no longer operationally required.
- Authentication Mechanisms: Systems containing personal data are protected by robust authentication requirements, including multi-factor authentication where applicable, to prevent unauthorised access by internal or external parties.
- Firewall and Intrusion Detection Systems: Network infrastructure is protected by firewall systems and intrusion detection mechanisms designed to identify and respond to anomalous activity, potential breaches, and unauthorised access attempts in a timely manner.
- Vulnerability Management: Regular security assessments, penetration testing, and vulnerability analyses are conducted to identify and remediate weaknesses within the technical infrastructure. Software and system updates are applied in accordance with established patch management procedures.
- Data Minimisation: Personal data is collected and retained only to the extent necessary for the purposes for which it is processed. Data that is no longer required for operational or regulatory purposes is subject to secure deletion or anonymisation in accordance with applicable retention policies.
The following organisational measures are maintained to support the secure processing of personal data:
- Staff Training: Personnel with access to personal data are required to undergo training regarding data protection obligations, information security protocols, and procedures applicable to the handling of sensitive information.
- Data Processing Agreements: Where personal data is processed by third-party service providers on behalf of Pirca Limitada, appropriate contractual arrangements are established to ensure that such processors implement adequate security measures and process data solely in accordance with documented instructions.
- Incident Response Procedures: Documented procedures are maintained for the identification, assessment, containment, and notification of personal data breaches in accordance with applicable regulatory requirements.
- Retention Policies: Personal data is retained for periods no longer than necessary to fulfil the purposes for which it was collected, subject to extended retention obligations imposed by applicable law or regulatory requirements, including those arising under anti-money laundering legislation.
Notwithstanding the measures described herein, no method of electronic transmission or data storage can be warranted as entirely secure. In the event that a personal data breach is identified that is reasonably likely to result in a risk to the rights and freedoms of affected data subjects, appropriate notification procedures shall be initiated in accordance with the obligations applicable to the operator.
User Rights
Data subjects whose personal data is processed by Pirca Limitada in connection with the operation of odinfortunecasino.me.uk are entitled to exercise the following rights in relation to their personal data. The exercise of these rights is subject to applicable legal conditions and may be restricted where processing is required for compliance with regulatory or legal obligations binding