This Privacy Notice explains how Incaspin Casino gathers, manages, retains, and protects personal data belonging to players located in Germany https://incaspincasino.de.com/legal-and-affiliates/. The document works within the context of the European Union’s General Data Protection Regulation (GDPR) and the German Federal Data Protection Act (Bundesdatenschutzgesetz, BDSG-neu). Incaspin Casino functions as the data controller for personal information submitted through its website, mobile applications, and related services. German players enjoy specific statutory rights concerning their data, and this notice details the lawful bases for processing, data retention periods, third-party sharing protocols, and the technical safeguards used to prevent unauthorised access. The document also explains the responsibilities of the Data Protection Officer and the supervisory authority contact procedures. Every section is prepared to ensure transparency and compliance with Article 13 and Article 14 of the GDPR, providing German users with a complete overview of how their casino account data, payment details, identification documents, and behavioural analytics are managed throughout the entire customer lifecycle.
Six. Information Retention and Erasure Rules
Incaspin Casino implements a precise data retention plan designed to fulfill statutory record-keeping requirements while limiting the storage of personal data past its necessary purpose. Player account data and complete transaction logs are kept for the full duration of the active business relationship, described as the time from account creation until the account is closed, plus an supplementary statutory retention duration stipulated by German anti-money laundering laws and commercial law. Under the Geldwäschegesetz, identification files, transaction vouchers, and due diligence papers must be preserved for at least five years following the end of the calendar year in which the business relationship ended. Accounting records relevant to tax duties are retained for ten years in compliance with the German Fiscal Code. Following the expiration of these mandatory intervals, personal data is either permanently de-identified so that re-identification becomes unfeasible with all methods reasonably probable to be applied, or securely erased through cryptographic erasure and physical storage media cleaning procedures. Technical logs and security event data observe a briefer retention cycle of twelve months, after which they are compiled into anonymised statistical summaries. Inactive accounts demonstrating no login activity for a consecutive period of 24 months are flagged for dormancy assessment, and the related personal data is reduced to keep only the core ID and transaction records required for the leftover statutory retention timeline. The casino utilizes automated data lifecycle management routines that run weekly to locate records past their retention thresholds, triggering deletion procedures without human intervention, with the results documented for compliance audit reasons.
3. bod Důvody a právní základy pro zpracování
Incaspin Casino processes personal data na základě několika různých GDPR právních důvodů, zvolených according to dané činnosti zpracování. Plnění smlouvy pursuant to Article 6(1)(b) GDPR pokrývá all data processing nezbytné k vytvoření a vedení hráčského účtu, process deposits and withdrawals, a doručení interaktivních herních služeb that German players aktivně vyžadují při registraci. This obsahuje zasílání platebních pokynů to acquiring banks a ověřování that players meet minimální věkový požadavek 18 let podle německého práva. Zpracování na základě právní povinnosti dle Article 6(1)(c) GDPR encompasses anti-money laundering customer due diligence, oznamování podezřelých obchodů příslušným finančním zpravodajským jednotkám, record retention to satisfy požadavků obchodního a daňového práva, and compliance s německými herními předpisy týkajících se standardů ochrany hráčů. Relevantní právní rámce include the Geldwäschegesetz and the stipulations státní smlouvy o hazardu kde je to relevantní k mandátům uchovávání údajů.
Legitimní zájmy pursued by Incaspin Casino podle Article 6(1)(f) GDPR zahrnují network and information security monitoring, fraud prevention and detection, direct marketing of similar products to existing customers tam, kde je to dovoleno podle Section 7 of the German Act Against Unfair Competition, and business analytics pro zlepšení služeb. German players zachovávají si absolutní právo vznášet námitky proti zpracování založeném na oprávněných zájmech, včetně vytváření profilů for direct marketing purposes, a tyto námitky budou respektovány without undue delay. Consent dle Article 6(1)(a) GDPR is relied upon for optional marketing communications prostřednictvím e-mailu a SMS kde the player has actively opted in, pro umístění nepodstatných cookies a sledovacích technologií, a pro zpracování citlivých údajů za specifických okolností. Consent withdrawal mechanisms jsou nápadně umístěny v nastavení účtu and every marketing communication footer, s tím, že odvolání má účinek bez zpětných důsledků pro dříve zákonné zpracování. German players kteří dosud nedosáhli věku 18 let nemají povoleno otevírat účty, and any inadvertently collected minor data is deleted immediately upon discovery.
2. Classes of Personal Data Obtained
2.1 Identification Validation and Account Data
German players must submit specific private data to create and sustain an active Incaspin Casino account. This group covers complete official full name, physical address, DOB, birthplace, nationality, and gender. For identity verification reasons mandatory under Germany’s anti-money laundering laws, the casino collects government-issued ID files such as copy of passport, national ID copies, and proof of residency. The platform also records the document number, issuer, validity end, and a biometric comparison score created during the computerized confirmation process. Address confirmation is completed through latest utility bills, bank statements, or authorized communication that plainly shows the player’s full name, on-file location, and an issuing date within the past three months. Incaspin Casino uses these confirmation requirements uniformly to conform with the Fourth and Fifth Anti-Money Laundering Directives as implemented into German law, making sure that all account satisfies the statutory identity certainty level before any withdrawals are allowed.
2.2 Fiscal and Deal Data
Transaction records encompasses all deposit records, including payment method details, masked card numbers, e-wallet account email addresses, bank account IBAN numbers for SEPA transfers, and crypto wallet addresses where applicable. Incaspin Casino stores complete transaction histories showing timestamps, amounts in EUR or digital currency equivalents, processing statuses, and any intermediary payment processor references. Source of funds declarations and supporting documents such as payslips, tax returns, or business financial statements are collected when players exceed specific deposit thresholds or trigger enhanced due diligence procedures. This data is separated in encrypted database tables with access limited to compliance personnel and senior financial officers. German players using Sofort, Giropay, or other local payment methods should be aware that the chosen payment provider will also process transaction data according to its own privacy policy, with Incaspin Casino receiving only the information necessary to credit the player account.
2.3 Technical and Behavioural Data
As German players log into the Incaspin Casino platform, the system automatically collects technical markers including IP addresses, device types, operating system versions, browser fingerprints, screen resolutions, language settings, and mobile carrier details. Session data includes login timestamps, page navigation paths, game launches, bet amounts, win and loss records, and in-game feature activations. This technical corpus permits the casino to deliver optimised gaming experiences, spot fraudulent activity patterns, and honour responsible gambling self-exclusion settings. Behavioural analytics monitor betting frequency, average stake sizes, session duration, and deposit velocity to inform the responsible gambling algorithms that generate personalised risk alerts. All technical logs are pseudonymised where possible and stored apart from core identity records, with re-identification possible only through a tightly controlled cryptographic lookup procedure reserved exclusively to the fraud and compliance teams under documented access justification.
7. Information Security Safeguards
Incaspin Casino implements a tiered security architecture conforming to the ISO 27001 control framework and the technical requirements set forth in Article 32 of the GDPR. Network-level protections include enterprise-grade firewalls configured with stateful packet inspection, intrusion detection and prevention systems that monitor traffic patterns for indicators of compromise, and distributed denial-of-service mitigation services that withstand volumetric attacks before they hit the application layer. All data sent between German player devices and casino servers is encrypted using Transport Layer Security version 1.3 with forward secrecy enabled, avoiding retrospective decryption of captured traffic even if long-term private keys are eventually leaked. Internal administrative interfaces are separated on a management network not accessible from the public internet, with access granted only through multi-factor authenticated VPN tunnels originating from pre-registered static IP addresses belonging to authorised personnel. At the application layer, the platform imposes strong password policies demanding minimum character lengths and complexity standards, with passwords hashed using bcrypt with per-user salts before storage. Account access anomalies activate step-up authentication challenges or temporary account locks awaiting manual review by the security team. Database-level encryption protects data at rest, with separate encryption keys for personal data columns, financial fields, and identity document stores, each administered through a hardware security module that records every key access operation. Regular vulnerability scanning and annual penetration testing by an independent CREST-accredited security firm confirm the effectiveness of these controls, with critical findings fixed within 48 hours. Security incident response procedures are practiced through bi-annual tabletop exercises engaging the Data Protection Officer, with a documented breach notification workflow guaranteeing German players and the supervisory authority receive notification within the 72-hour deadline mandated by GDPR.
4. Information Sharing and Third Parties
4.1 Internal Data Access Structure
In the Incaspin Casino operational system, personal data access utilizes a strict least-privilege model implemented across four distinct personnel tiers. Customer support agents retrieve basic account information and communication history but cannot view full financial records or identity documents. Compliance officers hold permissions to examine verification documents, transaction patterns, and risk scores. Financial department personnel manage withdrawal requests and view payment instrument details needed to execute transfers. IT security staff monitor system logs and security event data but do not regularly interact with player-identifiable records. Every access event is recorded with a timestamp, user identifier, and purpose code, creating an immutable audit trail that is checked quarterly by the Data Protection Officer. German players can request a copy of the access log entries pertaining to their account by submitting a subject access request through the designated privacy channel.
4.2 Third-Party Services and Authorities
Incaspin Casino utilizes specialist external processors such as cloud hosting providers running ISO 27001-certified data centres within the European Economic Area, payment processors licensed by the German Federal Financial Supervisory Authority, identity verification services that compare submitted documents against authoritative databases, email delivery platforms for transactional communications, and CRM software vendors for customer engagement analytics. Each processor undergoes a rigorous vendor assessment covering technical security measures, sub-processor transparency, international transfer safeguards, and business continuity capabilities. Contracts require data processing solely on documented instructions from Incaspin Casino, with no right for the processor to repurpose data for its own objectives. Regulatory disclosures to German law enforcement agencies, tax authorities, or gambling regulators take place only when legally mandated, and unless prohibited by law, the casino will notify affected players of such disclosures. The following key principles govern all third-party data sharing arrangements:
- Processors get only the least personal data needed to perform their agreed function, with field-level data minimisation applied to every integration.
- Sub-processor engagements require prior written approval from Incaspin Casino, and any unapproved subcontracting represents a material breach of the data processing agreement.
- All processors must hold ISO 27001 certification or equivalent independently audited security qualifications, with current documentation filed with Incaspin Casino before data flows commence.
- No personal data is sold to advertising technology platforms, data brokers, or any entity whose primary business involves monetising personal information.
Summary
Incaspin Casino has organized its data protection structure to satisfy the high standards expected by German players and stipulated by the GDPR and the BDSG-neu. From the initial collection of identity and contact details through to the conclusive deletion or anonymisation of records years after account closure, every personal data life cycle stage operates under written policies, contractual safeguards, and technical controls that are regularly audited and improved. The casino maintains transparent communication channels for rights requests, supplies granular cookie consent options, and limits data sharing to vetted processors and legally mandated disclosures. German players are encouraged to read this Privacy Notice alongside the general Terms and Conditions and the Responsible Gambling Policy available on the Incaspin Casino website, and to contact the Data Protection Officer with any questions about how their personal information is handled.
8. Prerogatives of German Data Subjects
German users hold the entire suite of data subject prerogatives specified in Articles 15 through 21 of the GDPR, along with the entitlement to file a appeal with a supervisory authority. The right of access enables players to receive assurance of whether Incaspin Casino processes their individual data and to get a copy of that data including information about processing aims, categories, addressees, retention durations, and the occurrence of automated decision-making. Access requests are fulfilled within one month, free of charge for the first request, with the response delivered in a ordered, commonly used, machine-readable structure. The right to rectification allows players to amend wrong personal data or complete partial records, a notably relevant entitlement for identity document updates following name alterations or address moves. Incaspin Casino handles rectification inquiries within ten business days and verifies amendments to any third-party receivers to whom the incorrect data was disclosed. The erasure right holds true where the personal data is no longer necessary for the objectives for which it was gathered, where permission is canceled, where the player raises objection to processing and no overriding legitimate grounds are in place, or where processing is not permitted. Nevertheless, statutory retention duties supersede erasure inquiries, and data necessary for legal compliance will be confined from further processing rather than erased until the retention period lapses. The right of limitation of processing serves as an substitute where the precision of data is disputed, processing is illegal but the player opposes deletion, or the player needs the data for legal assertions despite the controller no longer demanding it. Data portability prerogatives under Article 20 GDPR are limited to data supplied by the player and handled by automated means based on authorization or contract, meaning gameplay history and transaction logs are suitable for portability while fraud detection ratings coming from internal systems do not. Rights inquiries should be addressed to the Data Protection Officer email address, with valid proof of identity required before any data is shared.
9. Cookie Policy and Tracking Technologies
9.1 Essential and Operational Cookies
The Incaspin Casino platform and mobile platform implement a variety of cookies and similar tracking technologies to ensure core functionality. Strictly necessary cookies manage session state across page loads, preserve login authentication tokens, and maintain security context for CSRF protection. These first-party session cookies expire when the browser is closed and do not require prior consent under German law transposing the ePrivacy Directive, as they are necessary for the requested service delivery. Functional cookies store language preferences, preferred currency displays, and responsible gambling limit settings across visits, making sure that returning players encounter a coherent personalised environment without reconfiguring their preferences. The maximum lifespan of functional cookies is 365 days, after which they expire automatically if the player has not returned to the platform. Incaspin Casino does not use flash cookies, supercookies, or any respawning techniques that bypass browser deletion actions.
9.2 Analytics and Marketing Cookies
Analytics and marketing cookies are set only after German players provide explicit, freely given consent through the cookie consent management platform displayed on first visit. The consent tool offers clear descriptions of each cookie category, the specific providers participating, the purposes of data collection, and the retention duration for each cookie type. Players may give or deny consent for each category independently, and consent preferences are recorded as documentary evidence in an encrypted consent log with timestamp and IP address. Analytics cookies from a privacy-focused measurement service track aggregated page interaction metrics without cross-site tracking or user-level profiling. Marketing cookies facilitate campaign attribution and frequency capping for promotional banners shown within the logged-in casino environment. German players may modify their consent choices at any time by using the cookie settings panel located in the website footer. Refusing analytics or marketing cookies does not influence gameplay functionality or account standing in any manner. The consent tool re-prompts players annually to update or update their preferences.
5: International Data Transfers
The main data storage infrastructure for Incaspin Casino is located in secure facilities located in the European Economic Area, specifically engineered to serve the German market with low-latency connectivity while maintaining full GDPR jurisdictional coverage. Specific specialised processing activities may involve international data transfers beyond the EEA, including fraud detection services operating from certified facilities in third countries and customer support continuity arrangements during peak demand periods. For every such transfer, Incaspin Casino implements the safeguards mandated by Chapter V of the GDPR. Standard contractual clauses approved by the European Commission form the foundational transfer mechanism for processor relationships, with supplementary technical and organisational measures implemented where the recipient country lacks an adequacy decision from the European Commission. German players should understand that supplementary measures include end-to-end encryption of data in transit and at rest using AES-256 standards, strict key management policies that prevent the foreign processor from accessing plaintext data, and contractual obligations requiring the processor to challenge any government access request and notify Incaspin Casino immediately when legally permitted. Transfer impact assessments are conducted prior to onboarding any non-EEA processor and are reviewed whenever the legal landscape of the recipient jurisdiction changes materially. The Data Protection Officer maintains a current register of all international transfers, which is made available to the competent German data protection authority upon request and can be summarised for data subjects who wish to understand the geographical flow of their information.
1. Data Controller Identity and Contact Details
Osobou odpovědnou za zpracování údajů pro všechny osobní údaje zpracovávané prostřednictvím the Incaspin Casino webové stránky představuje the legal entity operating under the brand name Incaspin Casino, registered in jurisdikci uznávané pro its adherence to standardů ekvivalentních ochraně údajů EU. The registered office address a identifikační číslo společnosti are available upon žádost s ověřením totožnosti zasláním e-mailu pověřenci pro ochranu osobních údajů, nebo nahlédnutím do the imprint section webové prezentace. Němečtí hráči may direct veškeré dotazy ohledně ochrany soukromí to určenému pověřenci pro ochranu osobních údajů, který působí nezávisle a podává zprávy přímo vrcholovému vedení. Tento pracovník je k zastižení prostřednictvím speciální šifrovanou e-mailovou adresu zveřejněnou v rámci the full privacy policy text. Incaspin Casino maintains a legal representative v Evropské unii z důvodu ustanovení čl. 27 GDPR, ensuring that German supervisory authorities and data subjects disponují přímým kontaktem for regulatory matters. Tento subjekt stanovuje cíle a způsoby zpracování veškerých osobních dat shromážděných během account registration, Know Your Customer verification, platebních transakcích vkladů a výběrů, a průběžné aktivitě při hraní. This includes data generated through cookies, technologií otisku zařízení, a serverových logů. German players should note, že správce vykonává full decision-making power over data processing operations while commissioning carefully vetted processors k zajištění konkrétních technických služeb such as hosting, payment gateways, and CRM platforms. Každý vztah se zpracovatelem is governed by právně závaznou dohodou o zpracování dat that meets the requirements of ustanovení čl. 28 GDPR, with mandatory audit rights reserved ze strany Incaspin Casino pro ověření průběžného souladu. The contact details zástupce v EU are provided to the competent German data protection authority jak vyžaduje zákon.