Privacy Policy
Information Gathering
The following categories of personal data are collected and processed by SpeedAU Casino (hereinafter referred to as "the Operator"), operating through the domain speedaucasino.co, in accordance with the applicable data protection regulations of Curaçao and internationally recognized standards governing the processing of personal information.
Personal identification data, including full legal name, date of birth, nationality, and government-issued identification numbers, are collected from registered users at the time of account registration and during mandatory identity verification procedures. Such data is required to be furnished by the data subject prior to the commencement of any gaming or financial activities on the platform.
Contact information, including electronic mail addresses, telephone numbers, and residential addresses, is obtained and retained for the purposes of account administration, regulatory compliance, and the facilitation of communications between the Operator and the data subject.
Financial data, including bank account details, payment card information, transaction histories, and records of deposits and withdrawals, is processed in connection with the execution of monetary transactions conducted through the platform. Such data is handled exclusively through secured and encrypted financial channels.
Technical and behavioral data, including Internet Protocol addresses, browser type and version, device identifiers, session durations, navigation patterns, and geolocation information, is gathered automatically through the use of cookies, tracking pixels, and related technologies during user interaction with the website.
Documentation submitted for identity verification purposes, including copies of passports, national identity cards, utility bills, and other supporting materials, is collected and stored as part of the Know Your Customer (KYC) obligations imposed upon the Operator under the terms of its operating license issued in Curaçao.
How We Use Data
All personal data collected by the Operator is processed exclusively for legitimate, specified, and documented purposes in accordance with applicable legal frameworks. The processing of personal data is carried out only to the extent necessary for the fulfillment of the stated objectives.
Personal identification and contact data is utilized for the creation, maintenance, verification, and administration of user accounts registered on the SpeedAU Casino platform. Such processing is considered necessary for the performance of contractual obligations between the Operator and the registered user.
Financial and transactional data is processed for the purpose of executing payment operations, verifying the legitimacy of financial transfers, preventing unauthorized transactions, and maintaining accurate financial records in compliance with the regulatory requirements applicable to licensed gaming operators in Curaçao.
Personal data may be processed for the purpose of fulfilling legal obligations incumbent upon the Operator, including anti-money laundering (AML) compliance, counter-terrorism financing measures, and the implementation of responsible gambling policies. Such processing is mandated by applicable law and cannot be waived upon request by the data subject.
Technical and behavioral data is processed for purposes related to the optimization of website functionality, the detection and prevention of fraudulent activity, the enhancement of platform security, and the monitoring of service performance. Analytical processing of such data is conducted in an aggregated and, where feasible, anonymized form.
Electronic communications, including promotional materials and service notifications, may be transmitted to registered users where explicit consent has been obtained or where such communications are deemed necessary for the performance of the contractual relationship. Data subjects retain the right to withdraw consent for marketing communications at any time.
Personal data is not sold, rented, or otherwise transferred to third parties for independent commercial purposes. Disclosure to third parties is limited to circumstances in which such disclosure is required by law, necessitated by the performance of contracted services, or consented to by the data subject.
Data Protection
The Operator has implemented a comprehensive framework of technical and organizational security measures designed to protect personal data against unauthorized access, accidental loss, unlawful destruction, alteration, disclosure, or any other form of unauthorized processing.
Technical security measures applied to the protection of personal data include, but are not limited to, the implementation of Transport Layer Security (TLS) encryption protocols for all data transmitted between the user's device and the Operator's servers, the application of industry-standard encryption algorithms to stored sensitive data, and the deployment of firewall systems and intrusion detection mechanisms to safeguard network infrastructure.
Access to personal data maintained by the Operator is restricted on a strict need-to-know basis. Personnel authorized to access personal data are bound by confidentiality obligations and are required to undergo appropriate training in data protection practices. Unauthorized access by internal personnel is subject to disciplinary and legal consequences.
Organizational measures implemented by the Operator include the maintenance of documented data processing policies, the conduct of periodic internal assessments of data security practices, the establishment of data breach response procedures, and the designation of responsible personnel for the oversight of data protection compliance.
Third-party service providers engaged by the Operator in connection with the processing of personal data are required, as a condition of engagement, to implement equivalent or superior data security standards and to process personal data exclusively in accordance with the Operator's documented instructions and applicable legal requirements.
Personal data is retained only for the duration necessary to fulfill the purposes for which it was collected, subject to any extended retention periods mandated by applicable legal, regulatory, or licensing obligations. Upon the expiration of applicable retention periods, personal data is securely destroyed or rendered permanently anonymous in accordance with established procedures.
User Rights
Registered users and other data subjects whose personal data is processed by the Operator are entitled to exercise a defined set of rights with respect to their personal data. These rights may be exercised by submitting a written request to the Operator through the designated contact channels specified herein.
The right of access entitles the data subject to obtain confirmation as to whether personal data relating to them is being processed, and, where such processing is confirmed, to receive a copy of the personal data concerned along with relevant information regarding the nature, purposes, and legal basis of such processing.
The right to rectification permits the data subject to request the correction of personal data that is found to be inaccurate, incomplete, or outdated. Requests for rectification are processed without undue delay upon verification of the data subject's identity and the accuracy of the information provided.
The right to erasure, commonly referred to as the right to be forgotten, entitles the data subject to request the deletion of their personal data where such data is no longer necessary for the purposes for which it was collected, where consent has been withdrawn, or where processing is determined to be unlawful. This right is subject to limitations arising from legal retention obligations and regulatory requirements applicable to the Operator.
The right to data portability enables the data subject to request the transmission of personal data provided by them to the Operator in a structured, commonly used, and machine-readable format, or to request the direct transfer of such data to another controller where technically feasible.
The right to restriction of processing permits the data subject to request that the processing of their personal data be temporarily suspended under specific circumstances, including where the accuracy of the data is contested, where the processing is unlawful, or where the data subject has objected to processing pending verification of the Operator's legitimate grounds.
The right to object entitles the data subject to raise objections to the processing of their personal data on grounds relating to their particular situation, including processing carried out for the purposes of legitimate interests pursued by the Operator. The Operator shall cease such processing unless compelling legitimate grounds are demonstrated to override the interests of the data subject.
All requests pertaining to the exercise of data subject rights are subject to identity verification procedures and are processed within the timeframes prescribed by applicable data protection regulations. In circumstances where requests are considered manifestly unfounded or excessive, the Operator reserves the right to charge a reasonable administrative fee or to decline to act upon the request, with written justification provided to the data subject.
Contact Us
All formal inquiries, complaints, and requests relating to the processing of personal data by SpeedAU Casino, including requests for the exercise of data subject rights as described herein, shall be directed to the Operator through the following designated communication channel.
Electronic correspondence may be addressed to the Operator at the following electronic mail address: [email protected]
Upon receipt of a formal inquiry or request, acknowledgment of receipt shall be issued to the data subject within a reasonable period, and a substantive response shall be provided in accordance with the timelines prescribed by applicable data protection legislation. The Operator is committed to addressing all data protection matters with the diligence and transparency required by law.
Where a data subject considers that the processing of their personal data has not been conducted in accordance with applicable legal requirements, they retain the right to lodge a complaint with the competent supervisory authority having jurisdiction over data protection matters in the relevant territory.