Slotoro Casino treats the safety and secrecy of your personal data as a top priority https://slotoro.bg/legal-and-affiliates/. This Data Protection Policy explains, in clear wording, how we obtain, process, store, and safeguard the data of users, with a focus on those using our services from Bulgaria. The policy follows international data protection standards, including the General Data Protection Regulation (GDPR). Every step we take is designed to offer you a protected gaming experience while keeping you in command of your private information. Slotoro Casino serves as a data controller, which indicates we decide why and how your data is processed. This policy includes all contacts with the Slotoro website, mobile apps, customer support platforms, and any associated services. Transparency is important to us, so we encourage every player to go through this document before utilizing the platform.
6. Information Keeping and Removal Practices
We store personal data for as long as necessary to accomplish the objectives it was gathered for, or to comply with statutory record-keeping rules set by gaming regulators and tax authorities. Account information is maintained for the entire customer relationship, then is archived for five years after account closure. That five-year period matches anti-money laundering directives and the time limit for potential legal claims. Financial transaction records are held a minimum of seven years for tax reporting. Identity verification documents are securely deleted once the verification outcome is documented, unless a law or a specific investigation demands us to keep them longer. Technical logs and security monitoring data are cycled on a rolling basis, usually held for twelve months before automatic deletion. We use automated data lifecycle tools that mark records nearing their retention limit and then activate secure erasure. If we respect a deletion request under the right to erasure, we delete all personal data except for what we must keep for compelling reasons, such as addressing legal claims or following a binding regulatory order. https://www.reddit.com/r/poker/comments/u0pum8/are_there_any_online_poker_sites_with_live_dealer/
Frequently Asked Questions
Which personal details must be provided to Slotoro Casino for account creation?
For account setup, we require your full legal name, date of birth, home address, email address, and a username and password of your choice. Upon making a deposit, we will also request your phone number and payment method information. Subsequently, we will request identity verification documents to comply with regulatory standards.
What is the process for a player to request removal of their personal data?
You may request deletion by contacting our Data Protection Officer via email at the address specified in the site’s privacy area. Provide your details and indicate which data you want erased. We’ll review your request against the legal requirements and reply within 30 calendar days.
Does Slotoro Casino share data with other gaming operators?
No, we do not share your personal information with other gaming operators for marketing or cross-promotional purposes. We may share data with regulators and law enforcement if the law demands it, and with service providers who help run our platform—under strict contracts.

For how long are identity verification documents kept?
We retain your ID documents only for as long as necessary to finish verification and comply with anti-money laundering regulations. Typically, they are securely archived for five years following the last transaction on your account, then permanently removed using certified erasure techniques.
What protections are in place for financial transaction data?

Financial data is protected with end-to-end encryption, tokenization of card details, and compliance with PCI DSS. Payment processing runs on isolated networks, and only a small, background-checked team with confidentiality agreements can access financial records.
Can a player object to the use of their data for promotional?
Absolutely. Every marketing message we send has an unsubscribe link that lets you opt out immediately. You can also adjust your preferences in your account settings or contact customer support to object to direct marketing.
In what way does Slotoro Casino handle data breaches?
We have a formal breach response plan: immediate containment, forensic investigation, and notification to the supervisory authority within 72 hours of discovery. If a breach puts your rights and freedoms at high risk, we’ll tell you without delay and give you clear steps to protect yourself.
Which is the lawful basis for processing affiliate data?
We process affiliate data mainly because it’s needed to perform the contract: manage the relationship, track referrals, and pay commissions. We also rely on legitimate interest for fraud prevention and programme analytics, always balanced against what affiliates reasonably expect.
5. Global Data Transfers and Safeguards
Because Slotoro Casino is reachable internationally, we might transmit your personal data to servers and service providers situated outside your country of residence. When transfers occur from the European Economic Area to third countries, we establish safeguards in place so that GDPR protection levels are not weakened. Standard Contractual Clauses endorsed by the European Commission are the main mechanism we utilize; they commit recipients to the same data protection duties. We also evaluate the legal system of the destination country, considering things like government surveillance laws and if you’d have a way to obtain redress. If a service provider is certified under an approved framework or operates in a country with an adequacy decision, we check that before any transfer begins. Bulgarian players can request the Data Protection Officer for a copy of the relevant safeguard documents. We remain accountable for your data even after it’s transferred, and we perform regular audits and require any service provider to inform us immediately about any security incident affecting that data.
2. Groups of Personal Data Obtained
We gather several distinct groups of personal data, each for a specific reason. Identification data forms the basis of your player profile: full legal name, date of birth, residential address, nationality, and a government-issued ID number. Communication details includes the email address and phone number you provide when registering, employed for account notifications and security alerts. Financial information encompasses payment method details, transaction histories, deposit and withdrawal amounts, and partial card numbers (retained for fraud prevention). System data is automatically captured via cookies and similar tools, recording IP addresses, device fingerprints, browser types, operating system versions, and session duration. Verification information consists of documents uploaded for Know Your Customer checks, such as passport scans, utility bills, and proof of payment ownership. Additionally, behavioral information includes gaming preferences, betting patterns, bonus usage, and self-imposed limit settings. We obtain each category only where a lawful basis exists, and retention periods are tailored to the exact purpose for which the data was originally obtained.
1. Scope and Purpose of the Data Protection Guidelines
Slotoro Casino’s data protection framework includes all points where we obtain personal information from registered users and visitors. This comprises account registration forms, identity verification submissions, payment processing interfaces, live chat transcripts, emails, and automated logs of technical parameters during browsing sessions. We collect personal data primarily to offer a fully functional, legally compliant, and personalized gaming experience. Without certain mandatory information, we are unable to establish a contractual relationship, process payments, or meet anti-money laundering requirements. We also employ aggregated and anonymized data for statistical analysis, platform improvements, and to improve responsible gambling tools. The framework also reaches to data shared with carefully selected third-party providers who carry out essential tasks like payment processing, game hosting, and customer relationship management. Each provider is bound by contracts that mirror the protections in this policy, so the same standard of care accompanies the data throughout its entire life.
8. Safety Steps Securing Player Data
We use various layers of safeguards to secure your private data from unapproved intrusion, alteration, exposure, or destruction. Encryption is the primary line: Transport Layer Security (TLS) safeguards data in transfer between your equipment and our servers, and Advanced Encryption Standard (AES) protects data at storage in our data stores. Access restrictions are stringent: role-based permissions, multi-factor authentication for admin profiles, and the concept of least privilege, implying staff can exclusively view the data they definitely must have for their job. Our network protection features next-generation protection systems, intrusion detection and blocking solutions, and round-the-clock traffic monitoring by a specialized Security Operations Center. We maintain our systems protected through regular code audits, vulnerability testing, and penetration assessments by independent cybersecurity companies. Data facilities have biometric access controls, 24/7 surveillance, and backup power and environmental infrastructure. We also have a thorough incident reaction plan that covers immediate isolation, removal, and restoration, plus a breach reporting protocol that assures authorities and impacted users are told within 72 time of us learning about a applicable personal data violation.
7. Player Entitlements In Accordance with Data Protection Legislation
Bulgarian players have a full set of rights pursuant to the GDPR, and we have established internal processes to handle each one within the one-month deadline. The right of access enables you to request whether we’re processing your data and receive a copy of it accompanied by information about why and with which parties we share it. The right to rectification signifies you can rectify inaccurate or incomplete personal data, usually through your account dashboard or by reaching out to support. The right to erasure (right to be forgotten) applies when, for example, your data is not necessary anymore or you rescind consent. You can invoke the right to restrict processing while a dispute about accuracy or lawfulness is being resolved. Data portability lets you receive your data in a structured, machine-readable format and transfer it to another controller. The right to object addresses processing based on legitimate interests, encompassing profiling for direct marketing. And we will not make decisions that have legal effects on you based solely on automated processing without human involvement. We charge no fee for exercising these rights save when a request is clearly unfounded or excessive.
The 9th Affiliate Programme Data Handling Standards
The affiliate programme follows the same strict data protection practices as the main gaming platform. Affiliates who join give us business contact data, payment information for commission payments, and marketing performance data generated through tracking links and unique identifiers. We process this data based on contract performance and legitimate basis (monitoring campaign effectiveness and preventing fraud). Tracking technologies on affiliate landing pages collect referral source details, click times, and conversion actions; we anonymize this data wherever possible. Affiliates are contractually expected to have their own compliant privacy statements and to obtain valid consent from users before tracking commences, in line with ePrivacy guidelines. Commission payment data is retained for the life of the affiliate relationship and then for the legally required fiscal term. Affiliates have the same data subject rights as players, including access to their stored information and the ability to submit corrections. We perform periodic compliance reviews on affiliate partners to make sure their data handling conforms with this standard, and we can terminate partnerships if we find breaches.
3. Legal Bases for Processing Player Information
We handle your personal data only when we have a proper legal reason to do so. The six lawful bases we rely on are those set out in data protection law. First, processing often happens because it’s essential to fulfill our contract with you: handling your registration details, supporting deposits and withdrawals, and delivering the gaming services you signed up for. Second, we handle some data to comply with legal obligations, including identity verification, anti-money laundering screening, and notifying suspicious transactions to authorities. Third, we rely on legitimate interests for things like network security monitoring, fraud detection, internal analytics, and direct marketing of similar products to existing customers, always after making sure your rights don’t override our interests. Consent is another basis, which we seek explicitly when you consent to non-essential cookies, promotional newsletters, or certain marketing campaigns. You can withdraw consent at any time, but it won’t change the lawfulness of processing that took place before. In very rare cases, processing might be necessary to protect someone’s vital interests or to perform a task in the public interest. вътрешен поглед We note the lawful basis for each processing activity and can share that information if you ask.
4. Data Distribution and Third-Party Notifications
We partner with a network of reliable third-party service providers to manage the platform in a secure manner, and data sharing is restricted to what each partner needs to perform their tasks. Payment processors obtain only the transaction details required to handle deposits and withdrawals; they function under Payment Card Industry Data Security Standard (PCI DSS) certifications. Game providers get a unique player identifier and balance information, in no case your full personal profile. Identity verification agencies obtain the documents you provide for KYC checks and return verification results through encrypted channels. Cloud hosting providers hold data on infrastructure with enterprise-grade security controls, in server locations chosen to maintain adequate protection. Marketing platforms process email addresses and engagement metrics exclusively to run campaigns and measure performance. We also share personal data to regulators, law enforcement, and financial intelligence units when the law requires it. Outside these cases, we never trade your data to external parties. Every third-party relationship is controlled by a written data processing agreement that spells out what data is handled, for how long, and for what purpose, with strict confidentiality obligations.
