This Privacy Notice explains how incaspincasino geschäftsbedingungen gathers, manages, retains, and secures personal data belonging to players located in Germany. The document operates within the framework of the European Union’s General Data Protection Regulation (GDPR) and the German Federal Data Protection Act (Bundesdatenschutzgesetz, BDSG-neu). Incaspin Casino acts as the data controller for personal information submitted through its website, mobile applications, and related services. German players enjoy specific statutory rights regarding their data, and this notice outlines the lawful bases for processing, data retention periods, third-party sharing protocols, and the technical safeguards deployed to prevent unauthorised access. The document also describes the responsibilities of the Data Protection Officer and the supervisory authority contact procedures. Every section has been compiled to ensure transparency and compliance with Article 13 and Article 14 of the GDPR, offering German users with a complete overview of how their casino account data, payment details, identification documents, and behavioural analytics are managed during the entire customer lifecycle.
1. Data Controller Identity a kontaktní údaje
The data controller pro všechny osobní údaje zpracovávané na platformě the Incaspin Casino webové stránky představuje právnická osoba vystupující pod the brand name Incaspin Casino, registered in jurisdikci uznávané pro přijetím standardů ochrany údajů odpovídajících EU. The registered office address and company registration number are available upon žádost s ověřením totožnosti e-mailem na adresu pracovníkovi pro ochranu osobních údajů, or by consulting sekce otisku of the main website. Hráči z Německa may direct veškeré dotazy ohledně ochrany soukromí na the designated Data Protection Officer, jenž pracuje samostatně a podává zprávy přímo vrcholovému vedení. Pověřenec je k zastižení přes speciální šifrovanou e-mailovou adresu uvedenou v the full privacy policy text. Incaspin Casino maintains oprávněného zástupce na území Evropské unie for purposes of Article 27 GDPR, čímž zajišťuje, že německé dozorové úřady and data subjects disponují přímým kontaktem pro regulační záležitosti. mehr finden Tento subjekt determines the purposes and means zpracování všech osobních údajů získaných při vytváření účtu, Know Your Customer verification, transakcích vkladů a výběrů, and ongoing gameplay activity. To zahrnuje informace generované pomocí cookies, device fingerprinting technologies, a serverových logů. German players should note, že správce vykonává full decision-making power ohledně činností zpracování dat a zároveň zadává pečlivě prověřené zpracovatele for specific technical services např. hosting, platební brány, a CRM platformy. Každá smluvní dohoda se zpracovatelem je upravena závaznou smlouvou o zpracování údajů jež vyhovuje podmínkám článku 28 GDPR, s možností provádět povinné audity ze strany Incaspin Casino k ověření trvalého dodržování předpisů. Podrobné kontakty zástupce v EU byly sděleny příslušnému německému úřadu pro ochranu osobních údajů v souladu s právními předpisy.
4. Data Sharing and External Recipients
4.1 In-House Data Access Model
In the Incaspin Casino operational system, personal data access utilizes a strict least-privilege model implemented across four distinct personnel tiers. Customer support agents view basic account information and communication history but cannot view full financial records or identity documents. Compliance officers hold permissions to review verification documents, transaction patterns, and risk scores. Financial department personnel handle withdrawal requests and view payment instrument details required to execute transfers. IT security staff review system logs and security event data but do not typically interact with player-identifiable records. Every access event is logged with a timestamp, user identifier, and purpose code, creating an immutable audit trail that is examined quarterly by the Data Protection Officer. German players may request a copy of the access log entries pertaining to their account by submitting a subject access request through the designated privacy channel.
4.2 Third-Party Services and Authorities
Incaspin Casino utilizes specialist external processors comprising cloud hosting providers operating ISO 27001-certified data centres inside the European Economic Area, payment processors authorised by the German Federal Financial Supervisory Authority, identity verification services that match submitted documents against authoritative databases, email delivery platforms for transactional communications, and CRM software vendors for customer engagement analytics. Each processor undergoes a rigorous vendor assessment encompassing technical security measures, sub-processor transparency, international transfer safeguards, and business continuity capabilities. Contracts mandate data processing solely on documented instructions from Incaspin Casino, with no entitlement for the processor to repurpose data for its own objectives. Regulatory disclosures to German law enforcement agencies, tax authorities, or gambling regulators take place only when legally mandated, and unless prohibited by law, the casino will alert affected players of such disclosures. The following key principles regulate all third-party data sharing arrangements:
- Processors receive only the least personal data required to perform their specified function, with field-level data minimisation enforced to every integration.
- Sub-processor engagements require prior written consent from Incaspin Casino, and any unlicensed subcontracting constitutes a material breach of the data processing agreement.
- All processors must hold ISO 27001 certification or comparable independently audited security qualifications, with current certificates filed with Incaspin Casino before data flows begin.
- No personal data is disclosed to advertising technology platforms, data brokers, or any entity whose primary business centers on monetising personal information.
Třetím Purposes and Legal Bases for Processing
Incaspin Casino processes osobní data under several distinct GDPR právních základů, selected podle dané činnosti zpracování. Realizace smlouvy pursuant to Article 6(1)(b) GDPR zahrnuje all data processing potřebné k vytvoření a vedení účtu hráče, provádění vkladů a výběrů, a doručení interaktivních herních služeb that German players actively request při registraci. This includes předávání platebních instrukcí zúčtovacím bankám a kontrolu that players dosahují the minimum age requirement 18 let dle německé legislativy. Povinné zpracování under Article 6(1)(c) GDPR zahrnuje anti-money laundering customer due diligence, hlášení podezřelých transakcí příslušným finančním zpravodajským jednotkám, uchovávání záznamů k uspokojení požadavků obchodního a daňového práva, and compliance with German gambling regulations concerning player protection standards. The applicable legal frameworks zahrnují Geldwäschegesetz and the stipulations Glücksspielstaatsvertragu kde je to relevantní to data retention mandates.
Legitimate interests sledované Incaspin Casino dle Article 6(1)(f) GDPR zahrnují network and information security monitoring, fraud prevention and detection, direct marketing of similar products to existing customers tam, kde je to dovoleno podle Section 7 of the German Act Against Unfair Competition, and business analytics pro zlepšení služeb. German players retain nezpochybnitelné právo odmítnout zpracování based on legitimate interests, including profiling pro účely přímého marketingu, a takové námitky budou ctěny bez zbytečného odkladu. Povolení under Article 6(1)(a) GDPR je využíván pro nepovinná marketingová sdělení e-mailem a SMS pokud hráč se aktivně přihlásil, pro umístění nepodstatných cookies a sledovacích technologií, a pro zpracování citlivých údajů in specific circumstances. Mechanismy pro odvolání souhlasu jsou výrazně umístěny v nastavení účtu a v patičce každého marketingového sdělení, přičemž odvolání nabývá účinnosti bez retroaktivních následků pro dříve legální zpracování. German players kteří dosud nedosáhli věku 18 let are not permitted to open accounts, a jakákoli neúmyslně shromážděná data nezletilých is deleted immediately upon discovery.
Two Classes of Individual Data Obtained
Two Point One Identification Validation and Player Data
German players must supply certain personal data to create and maintain an active Incaspin Casino account. This category covers entire statutory name, home address, birth date, birthplace, nationality, and gender. For identity confirmation aims needed under German anti-money laundering laws, the casino collects government-issued ID papers such as copy of passport, scans of national ID, and residence permit documentation. The platform also logs the document number, issuer, validity end, and a biometrical comparison score created during the automated confirmation process. Address validation is finished through current utility bills, bank statements, or formal communication that clearly shows the player’s full name, on-file address, and an issue date inside the past three months. Incaspin Casino uses these confirmation prerequisites consistently to conform with the Fourth and Fifth Anti-Money Laundering Directives as implemented into Germany’s law, guaranteeing that every account fulfills the legal identity certainty level before any withdrawals are authorized.
Two Point Two Monetary and Transaction Data
Transaction records encompasses all deposit records, including payment method details, masked card numbers, e-wallet account email addresses, bank account IBAN details for SEPA transfers, and digital wallet addresses where applicable. Incaspin Casino keeps complete transaction histories showing timestamps, amounts in EUR or equivalent cryptocurrency, processing statuses, and any intermediary payment processor references. Source of funds declarations and backing documents such as payslips, tax returns, or business financial statements are collected when players reach specific deposit thresholds or trigger enhanced due diligence procedures. This data is segregated in encrypted database tables with access restricted to compliance personnel and senior financial officers. German players using Sofort, Giropay, or other local payment methods should be aware that the chosen payment provider will also process transaction data according to its own privacy policy, with Incaspin Casino receiving only the information necessary to credit the player account.
2.3 Behavioral and Technical Information
While German players access the Incaspin Casino platform, the system captures technical data points including IP addresses, device types, operating system versions, browser fingerprints, screen resolutions, language settings, and mobile carrier details. Session data includes login timestamps, page navigation paths, game launches, bet amounts, win and loss records, and in-game feature activations. This technical corpus enables the casino to deliver optimised gaming experiences, spot fraudulent activity patterns, and honour responsible gambling self-exclusion settings. Behavioural analytics monitor betting frequency, average stake sizes, session duration, and deposit velocity to supply the responsible gambling algorithms that create personalised risk alerts. All technical logs are pseudonymised where possible and stored apart from core identity records, with re-identification possible only through a tightly controlled cryptographic lookup procedure reserved exclusively to the fraud and compliance teams under documented access justification.
7. Information Security Safeguards
Incaspin Casino deploys a tiered security architecture aligned with the ISO 27001 control framework and the technical requirements set forth in Article 32 of the GDPR. Network-level protections include enterprise-grade firewalls set up with stateful packet inspection, intrusion detection and prevention systems that monitor traffic patterns for indicators of compromise, and distributed denial-of-service mitigation services that neutralize volumetric attacks before they reach the application layer. All data sent between German player devices and casino servers is encrypted using Transport Layer Security version 1.3 with forward secrecy enabled, avoiding retrospective decryption of captured traffic even if long-term private keys are eventually leaked. Internal administrative interfaces are separated on a management network inaccessible from the public internet, with access granted only through multi-factor authenticated VPN tunnels starting from pre-registered static IP addresses owned by authorised personnel. At the application layer, the platform mandates strong password policies necessitating minimum character lengths and complexity standards, with passwords hashed using bcrypt with per-user salts before storage. Account access anomalies activate step-up authentication challenges or temporary account locks pending manual review by the security team. Database-level encryption protects data at rest, with separate encryption keys for personal data columns, financial fields, and identity document stores, each administered through a hardware security module that records every key access operation. Regular vulnerability scanning and annual penetration testing by an independent CREST-accredited security firm verify the effectiveness of these controls, with critical findings resolved within 48 hours. Security incident response procedures are tested through bi-annual tabletop exercises engaging the Data Protection Officer, with a documented breach notification workflow ensuring German players and the supervisory authority receive notification within the 72-hour deadline mandated by GDPR.
8. Entitlements of German-resident Data Subjects
German gamblers enjoy the full suite of data subject entitlements specified in Articles 15 through 21 of the GDPR, along with the option to file a complaint with a supervisory authority. The right of access allows players to obtain verification of if Incaspin Casino processes their private data and to obtain a copy of that data including particulars about processing purposes, types, receivers, retention durations, and the occurrence of automated decision-making. Access inquiries are fulfilled within one month, free of charge for the primary request, with the answer delivered in a organized, commonly used, machine-readable format. The right of correction allows players to correct incorrect personal data or supplement partial records, a particularly applicable prerogative for identity document revisions following name changes or address transfers. Incaspin Casino processes rectification applications within ten business days and acknowledges amendments to any third-party addressees to whom the wrong data was shared. The erasure right holds true where the personal data is no longer required for the purposes for which it was obtained, where permission is revoked, where the player objects to processing and no prevailing legitimate grounds are present, or where processing is illegal. However, statutory retention duties override erasure applications, and data necessary for legal compliance will be confined from further processing rather than removed until the retention period expires. The right to restriction of processing acts as an substitute where the precision of data is disputed, processing is unlawful but the player objects to deletion, or the player requires the data for legal assertions despite the controller no longer needing it. Data portability entitlements under Article 20 GDPR extend only to data supplied by the player and dealt with by automated ways based on consent or agreement, signifying gameplay history and transaction logs qualify for portability while fraud detection assessments coming from internal algorithms do not. Rights inquiries should be sent to the Data Protection Officer email address, with legitimate proof of identity necessary before any data is disclosed.
Číslo 5: International Data Transfers
The primary data storage infrastructure for Incaspin Casino resides within secure facilities located in the European Economic Area, specifically configured to serve the German market with latency-optimized connectivity while maintaining full GDPR jurisdictional coverage. Certain specialised processing activities may involve international data transfers beyond the EEA, including fraud detection services operating from certified facilities in third countries and customer support continuity arrangements during peak demand periods. For every such transfer, Incaspin Casino implements the safeguards mandated by Chapter V of the GDPR. Standard contractual clauses approved by the European Commission form the foundational transfer mechanism for processor relationships, with supplementary technical and organisational measures implemented where the recipient country lacks an adequacy decision from the European Commission. German players should understand that supplementary measures include end-to-end encryption of data in transit and at rest using AES-256 standards, strict key management policies that prevent the foreign processor from accessing plaintext data, and contractual obligations requiring the processor to challenge any government access request and notify Incaspin Casino immediately when legally permitted. Transfer impact assessments are conducted prior to onboarding any non-EEA processor and are reviewed whenever the legal landscape of the recipient jurisdiction changes materially. The Data Protection Officer maintains a current register of all international transfers, which is made available to the competent German data protection authority upon request and can be summarised for data subjects who wish to understand the geographical flow of their information.
6. Data Storage and Removal Guidelines
Incaspin Casino runs a detailed data retention policy aimed to fulfill statutory record-keeping requirements while reducing the retention of personal data beyond its intended purpose. Player account data and full transaction logs are kept for the complete period of the ongoing business relationship, described as the period from account creation up to the account is terminated, plus an extra statutory retention term mandated by German anti-money laundering legislation and commercial law. Under the Geldwäschegesetz, identification documents, transaction vouchers, and due diligence papers must be maintained for at least five years following the end of the calendar year in which the business relationship terminated. Accounting records pertinent to tax requirements are kept for ten years in conformity with the German Fiscal Code. Following the end of these mandatory periods, personal data is either permanently masked so that re-identification becomes impracticable with all ways reasonably likely to be used, or safely deleted through cryptographic erasure and physical storage media cleaning processes. Technical logs and security event data follow a shorter retention cycle of twelve months, after which they are compiled into anonymised statistical overviews. Inactive accounts demonstrating no login activity for a continuous period of 24 months are designated for dormancy check, and the associated personal data is limited to keep only the core ID and transaction records necessary for the leftover statutory retention schedule. The casino deploys automated data lifecycle management processes that execute weekly to find records over their retention thresholds, initiating deletion workflows without human involvement, with the results documented for compliance audit reasons.
9. Cookie Policy and Tracking Technologies
9.1 Essential and Technical Cookies

The Incaspin Casino platform and mobile platform utilize a set of cookies and similar tracking technologies to provide core functionality. Strictly necessary cookies control session state across page loads, preserve login authentication tokens, and maintain security context for CSRF protection. These first-party session cookies expire when the browser is closed and do not require prior consent under German law transposing the ePrivacy Directive, as they are essential for the required service delivery. Functional cookies save language preferences, preferred currency displays, and responsible gambling limit settings across visits, guaranteeing that returning players encounter a coherent personalized environment without reconfiguring their preferences. The maximum lifespan of functional cookies is 365 days, after which they are deleted automatically if the player has not revisited the platform. Incaspin Casino does not use flash cookies, supercookies, or any regenerating techniques that bypass browser deletion actions.
9.2 Analytics and Marketing Cookies
Analytics and marketing cookies are set only after German players provide explicit, freely given consent through the cookie consent management platform presented on first visit. The consent tool displays clear descriptions of each cookie category, the specific providers participating, the purposes of data collection, and the retention duration for each cookie type. Players may give or refuse consent for each category independently, and consent preferences are logged as documentary evidence in an encrypted consent log with timestamp and IP address. Analytics cookies from a privacy-focused measurement service track aggregated page interaction metrics without cross-site tracking or user-level profiling. Marketing cookies facilitate campaign attribution and frequency capping for promotional banners presented within the logged-in casino environment. German players may adjust their consent choices at any time by visiting the cookie settings panel linked in the website footer. Rejecting analytics or marketing cookies does not affect gameplay functionality or account standing in any manner. The consent tool asks again players annually to reaffirm or update their preferences.
Summary
Incaspin Casino has structured its data protection structure to satisfy the high standards anticipated by German players and stipulated by the GDPR and the BDSG-neu. From the first collection of identity and contact details through to the final deletion or anonymisation of records years after account closure, every personal data life cycle stage works under documented policies, contractual safeguards, and technical controls that are regularly audited and improved. The casino keeps transparent communication channels for rights requests, provides granular cookie consent options, and limits data sharing to vetted processors and legally mandated disclosures. German players are urged to read this Privacy Notice alongside the general Terms and Conditions and the Responsible Gambling Policy available on the Incaspin Casino website, and to contact the Data Protection Officer with any questions about how their personal information is handled.