At Casinoaward.net, we may collect some personal data from our users. We care about the privacy of our visitors, and that's why we collect and use only the minimum amount of personal data in order for our website to offer a high quality service.
1. Types of Data collected
Among the types of Personal Data that Casinoaward.net collects there are: usage and analytics data, country, cookies, email address, name and any information provided through the contact form.
Complete details about each category of personal information collected are available in individual sections in paragraph "2. Purposes of processing".
Personal Data may be freely provided by the User, or collected after explicit consent, or (in case of usage and analytics data in some countries) collected automatically when browsing our website.
2. Purposes of processing
2.1 Why and how we use User Data
We use data we collect to provide an efficient and functional service and for the following reasons: to provide country-level targeted contents (Country Geolocation), to anonymously monitor traffic on our website (Usage and Analytics Data), to answer questions and enquiries by our users (Contact Form and E-mails), to distribute contents from servers located all around the world in order to reduce waiting times and enforce security (Content Delivery Network), to provide advanced functionalities offered by third-parties such as YouTube video integration (3rd Party Services).
Users can find further detailed information about such purposes of processing and about the specific Personal Data used for each purpose in the respective sections of this document.
2.2 Detailed information for each purpose
Personal Data is collected for the following purposes and using the following services:
Our server is capable of automatically determine which country the user is connecting from (with a very low margin of uncertainty).
This enables us to provide contents that are compliant with regulations in each of the countries we target. For example, if a user accesses a page that shows an offer that is not valid for his or her country, we are able to show an appropriate warning message.
This piece of information is used automatically by our system and only lasts for the duration of the session, then is discarded; it is neither saved or used for any other purpose besides the one just described.
Personal Data collected: country.
Lawful basis: Legitimate Interest (?).
Casinoaward.net uses a website traffic monitoring system to collect anonymous and aggregate information about the way users browse the website. This information includes (but is not limited to): dates and times of access, time spent on the website, country of origin, landing and leaving pages, etc.
The use of such a monitoring system allows us to determine which contents are the most interesting (and which the least) for users, which time periods see the highest traffic peaks, as well as discover bugs in the code or detect potential abuse in the usage of the service.
Web traffic analysis on our website is performed using Matomo Analytics (also known as Piwik). We agreed to the DPA for this service.
Personal Data collected: cookies, anonymized IP address (111.222.xxx.xxx), location of the user (country level), date and time, title and url of the page being viewed, browser version, device type and version, browser language, screen resolution, pseudonymized User ID, referral website, outgoing links clicked. This data is not used for marketing or profiling purposes and it is neither passed on to third-parties or related to other data that might directly identify a single individual.
Lawful basis: Legitimate Interest (?).
We believe one of the best ways to offer a high quality service is to pay attention to feedback provided by the users and, where possible, reply to them appropriately.
In order to achieve this, we provide the users with a contact form and an email address with which they can contact us.
Data related to this purpose are used solely to interact with the user after their request. It is not saved inside the database of our website and it is neither used for profiling purposes, or shared with any third-party.
It is however possible that this data is saved in the mailbox and, for security reasons, on the server of our hosting provider inside system backups. Further information about this can be found in paragraph "4.3 Retention of data".
When users get in touch with us using the contact form, their explicit consent is requested via a checkbox. Should users contact us by directly sending an email, since in that case it is not possible to have an explicit consent mechanism, we consider the act of willingly sending the email as implicit consent.
Personal Data collected: email address, name, any information freely provided by the user.
Lawful basis: Consent.
A Content Delivery Network allows Casinoaward.net to distribute contents using servers located across different countries, to optimize performance and to enforce security.
The function of a CDN is to filter communications between Casinoaward.net and the User's device, delivering to the user assets and contents from the nearest server available. Considering the widespread distribution of this system, it is difficult to determine the locations to which the contents that may contain Personal Information are transferred.
Contents that may contain personal information are not cached on CDN servers, but the CDN manager might process some functional personal information (such as the user's IP address) in order to provide their security or performance services and might create access logs for a limited period of time.
We make use of Cloudflare CDN (Cloudflare Inc.). We agreed to the DPA for this service.
Cloudflare takes responsibility in complying to regulations about user privacy (more information about this: https://www.cloudflare.com/gdpr/introduction/).
Lawful basis: Legitimate Interest (?).
YouTube video streaming embedding
This service is used to insert YouTube (Google Inc.) streaming videos in some of our pages.
Since this service is not fundamental for correctly viewing the contents of our website, and being a third-party application, we ask for consent to its usage by the user in the "short notice".
To minimize the impact on user privacy, videos are provided via the youtube-nocookie.com domain, a more privacy-friendly version of the platform.
Personal Data collected: Cookies and various types of Data
Lawful basis: Consent.
*Read sections "4. Modes and places of processing the Data" and "4.4 Our Hosting Providers" for more details.
4. Modes and places of processing the Data
4.1 Data Protection Principles
We will comply with data protection law and principles which means that collected data will be:
- Used in compliance with the law and for clearly stated purposes.
- Collected only for appropriate purposes, described in this policy document.
- Used only for the mentioned purposes, and for no other purpose.
- Stored only for the time necessary to fulfill their purpose.
- Stored in a protected and secure way.
4.2 Security of data
We behave in accordance to all best-practices to ensure the maximum security of Personal Information. Despite the fact that an information technology system can never be considered totally risk-free, following are the measures we apply to comply to the highest security standards:
- Our website uses the most up-to-date version of the SSL standard, to establish secure connections between the user's device and our web server.
- All the accounts of services we use are protected by firewalls and strong passwords.
- Hosting Providers we use keep high security standards and actively monitor the website against external threats.
As stated by the regulations, in case of a data breach and if we reckon there might be risks for individuals, we will notify authorities and users within 72 hours.
4.3 Retention of data
Collected data is used and stored for a varying period of time depending on the purpose with which it has been collected, as described in the following section.
However, we reserve the right to store some of this data for an indefinite period of time, should it be necessary to comply with legal obligations, resolve disputes, or protect our website from misuse.
- Country Geolocation Data: browser session.
- Usage and Analytics Data: one year or less.
- Contact Form and E-mails: as necessary to provide users with the services requested.*
*To grant the security and availability of our website, our system creates automatic backups of the whole infrastructure. These backups might also involve services such as mailboxes, inside which user data might be present. Technical reasons make it impossible to exclude or extract single sets of Personal Information from these backups, thus the data might be kept for the entire lifecycle duration of the backup files, currently set to 1 month. After that period of time, they are permanently automatically deleted.
4.4 Our Hosting Providers
Like the majority of websites, Casinoaward.net makes use of hosting providers to offer contents and services on the web.
- Webserver and related services Hosting Provider: Kualo Limited, Second Floor, 20-22 Wenlock Road, London N1 7GU, United Kingdom (https://www.kualo.com). Servers location: United Kingdom.
- Analytics service Hosting Provider: InnoCraft, 150 Willis St, 6011 Wellington, New Zealand (https://www.innocraft.com/). Servers location: Germany.
- Content Delivery Network: Cloudflare, Inc. 101 Townsend St. San Francisco, CA 94107 or Cloudflare, Ltd. 2nd Floor 25 Lavington Street London (https://www.cloudflare.com) Servers location: multiple countries around the World.
4.5 Automated decision-making and profiling
Casinoaward.net is not doing any automated decision-making or profiling.
5. Users' rights
Users may exercise certain rights regarding their Data, in particular:
- You have to be informed on Data collection and usage.
- You can withdraw your consent at any time. Users have the right to withdraw consent where they have previously given their consent to the processing of their Personal Data.
- You can object to, or restrict processing of your Data.
- You can ask us at any time to access your personal data.
- You can ask us at any time to delete all the personal data we are processing about you.
- You can ask us at any time for a copy of all the personal data we are processing about you.
- If you think that the way we process your personal data is infringing the law, you have the right to lodge a complaint with a supervisory authority.
Please note: as previously stated, our website collects a minimal amount of Personal Information. Exception made for the sole data provided by the users themselves with "Contact Form and E-mails", it could be impossible to distinguish between single visitors of our website. For this reason, we might not be able to satisfy some requests, as for example the right to data portability, the reason being that we do not have data available as individual sets of data, but rather in an aggregated form.
As for exercising user rights regarding any external services we make use of, we suggest reading the privacy policies of the external service providers (following the links found in this document).
6. Other information
6.1 Lawful bases for processing
The lawful bases for processing are:
- Consent: the individual has given clear consent for you to process their personal data for a specific purpose.
- Contract: the processing is necessary for a contract you have with the individual, or because they have asked you to take specific steps before entering into a contract.
- Legal obligation: the processing is necessary to comply with the law.
- Vital interests: the processing is necessary to protect someone's life.
- Public task: the processing is necessary for you to perform a task in the public interest or for your official functions, and the task or function has a clear basis in law.
- Legitimate interests: the processing is necessary for your legitimate interests or the legitimate interests of a third party, unless there is a good reason to protect the individual's personal data which overrides those legitimate interests.
Depending on the intended purpose, Casinoaward.net services relies on Consent or Legitimate Interest, as specified in section "2.2 Detailed information for each purpose".
6.2 Legitimate Interest disclosure
In order to maximize transparency towards our users, we will now describe "how" and "why" we use Legitimate Interest as the base for data processing.
Online gambling is an activity that is subject to different regulations in different countries. Our system needs to be able to determine which country the user connects from for the following reasons:
- Provide the user with notices and warnings about online gambling in compliance with regulations from the authorities in the different countries we target.
- Provide partially customized content to users coming from different countries, and allowing them to filter-out content not relative to their geography.
- Show warnings and notices should users reach a page that contains information that is not appropriate for their country.
This activity does not put user privacy at risk
Why do we not ask for consent? Because already from the very first moment you land on our website, we want to make sure we are showing you only valid and correct content.
Monitoring in an anonymous and aggregate way traffic on our website allows us to improve the service we offer and provide the users with a better experience:
- We can determine which contents are relevant for the user, and which are not, and subsequently modify the structure of the website.
- We can detect bugs and fix them faster. For example, we can detect an error by observing a sudden drop to zero of visits to a page that was previously very popular.
- We can determine which time frames see the most traffic, and which the least, being thus able to schedule our update and maintenance activities in time frames that have a minimal impact on user experience.
- We can monitor the evolution of devices through which the users connect (for example mobile or desktop device, Safari or Chrome web browser, ...) and adjust the graphical structure of the website for a better layout of contents on the screen.
This activity is performed by making use of personal data anonymization and pseudonymization techniques, without any profiling purpose. The risk for the privacy of users is thus extremely low.
Why do we not ask for consent? Because we apply techniques to anonymize data to grant you privacy and because we want to be aware of any abuse performed against the website (such as attempts to access reserved areas by a bot) and/or bugs in our pages.
Our website uses a Content Delivery Network, aka a network of servers distributed all around the world, to deliver part of our essential contents and assets. Why do we do it?
- For security reasons: the CDN protects the origin server against external threats, providing an additional security layer.
- For performance reasons: the CDN delivers contents and assets from a location nearer to the user. By doing this both waiting times and load on the origin server are reduced, and users can experience faster and fluent browsing.
- For reasons related to specific regulations of this sector: using a CDN enables us to determine the country the user connects from and thus deliver specifically targeted and appropriate content.
The CDN we use (Cloudflare) is compliant with the General Data Protection Regulation (GDPR) and privacy regulations.
Why do we not ask for consent? Because using a CDN is outside of the scope of our website, aka the user device first connects to the CDN, and only afterwards to the origin server.
6.4 Do Not Track (DNT) Requests
Since the DNT standard is not yet widespread and there is not yet an extended culture about it among users, at the moment we do not take automatic DO Not Track requests.
Users can however manage their preferences through the tools directly available on this website.
6.4 Data Processing Information
You can find useful information about everything that concerns Personal Data regulations on the UK ICO's website (https://ico.org.uk/your-data-matters/).
Owner contact email: info[at]casinoaward.net (please replace "[at]" with "@")
You can write to this email address to have further information about the topics discussed in this document.
8. Changes to this document
This document may be subject to modification at any time without notice. Should it be modified, users will be requested to provide their consent anew, where necessary.
Last update: 03 August 2019.