Privacy Policy

Last updated: August 14, 2025

1. General Information

1.1. What is this Privacy Policy about?

This Privacy Policy explains how Personal Data is collected, used, stored, disclosed, and protected when you access or use this Website and the related Services.

It also explains what categories of Personal Data may be processed, why such processing is carried out, what legal grounds apply, how long Personal Data may be retained, who may receive it, what rights you have, and how you can exercise those rights.

1.2. Who owns and operates this Website?

This Website is owned and operated by Carletta N.V., a company registered under the laws of Curaçao.

Carletta N.V. has its office at Dr. Henri Fergusonweg 1, Curaçao, and is registered under company registration number 142346.

Carletta N.V. has been licensed by the Curaçao Gaming Control Board since 24/Jun/2025 to offer games of chance under license number OGL/2024/580/0570 in accordance with the National Ordinance on Games of Chance (LOK).

1.3. Who is responsible for your Personal Data?

Carletta N.V. acts as the controller of your Personal Data.

This means that the Company determines the purposes and means of Processing Personal Data in connection with your use of the Website and Services.

1.4. When does this Privacy Policy apply?

This Privacy Policy applies to the collection, use, and Processing of Personal Data through:

  • the Website;
  • communications via [email protected];
  • phone calls with us;
  • support chat sessions with us.

2. Definitions Used in This FAQ

2.1. What does “Account” mean?

An Account means a unique account created for you to access the Services or specific parts of the Services.

Access to an Account may be subject to identity verification and Regulatory Compliance requirements.

2.2. What does “Company” mean?

Company, we, us, or our means Carletta N.V., a company registered in Curaçao under company registration number 142346, with registered address at Dr. Henri Fergusonweg 1, Curaçao.

2.3. What does “Service” mean?

Service means the Website, its functionalities, and related online gaming and interactive services provided by the Company.

2.4. What does “Website” mean?

Website means this website, including any subdomains, associated platforms, or applications operated by the Company.

2.5. What does “Personal Data” mean?

Personal Data means any information that relates to an identified or identifiable individual, as defined under the General Data Protection Regulation and the Curaçao Data Protection Framework.

2.6. What does “Processing of Personal Data” mean?

Processing of Personal Data means any operation or set of operations performed on Personal Data, whether by automated or manual means.

This includes collection, recording, organization, structuring, storage, adaptation, alteration, retrieval, consultation, use, disclosure by transmission, dissemination, alignment, combination, restriction, erasure, or destruction.

2.7. What does “Regulatory Compliance” mean?

Regulatory Compliance means the Company’s legal obligation to process Personal Data in accordance with applicable laws, including the National Ordinance on Games of Chance and Anti-Money Laundering regulations.

Processing for Regulatory Compliance is based on legal requirements and does not rely on user consent.

3. Personal Data We Process and Why

3.1. What Personal Data is processed for Account registration?

For Account registration and access to the Services, we may process contact credentials such as email address and/or phone number, hashed password, chosen currency, account identifiers, and basic device or access logs used to activate and secure the Account.

The purpose of this processing is to create, activate, secure, and manage your Account and allow access to the Services.

The legal basis is performance of a contract or steps prior to entering into a contract under GDPR Article 6(1)(b).

3.2. What Personal Data is processed for identity verification and compliance?

For identity verification, age confirmation, and AML / LOK compliance, we may process government-issued identification documents such as passport, ID card, or driver’s license, proof of address, date of birth or age attestation, selfies, or liveness checks.

The purpose of this processing is to verify identity, confirm age, meet KYC obligations, and comply with AML/CFT, LOK, and NORUT requirements.

The legal basis is compliance with legal obligations, including AML/CFT, LOK, and NORUT, under GDPR Article 6(1)(c). Where applicable, legitimate interests in platform integrity under GDPR Article 6(1)(f) may also apply.

3.3. What Personal Data is processed for payments?

For deposits, withdrawals, refunds, and other payment-related services, we may process payment instrument data, transaction history, currency, and payout channel confirmations.

The legal bases are performance of a contract under GDPR Article 6(1)(b), compliance with financial record-keeping and AML obligations under GDPR Article 6(1)(c), and legitimate interests in fraud prevention under GDPR Article 6(1)(f).

3.4. What Personal Data is used for security and fraud prevention?

For fraud detection, security monitoring, and platform abuse prevention, we may process device and technical identifiers, including IP address, device type, and browser data.

The legal bases are legitimate interests in securing the Service and users under GDPR Article 6(1)(f), and legal obligations under AML/CTF rules under GDPR Article 6(1)(c).

3.5. What Personal Data is processed for responsible gaming and player protection?

For responsible gaming, player protection, and self-exclusion management, we may process self-exclusion status and duration, cooling-off selections, play limits, gameplay frequency, spend metrics indicative of risk, and communications related to responsible gaming interventions.

The legal bases are compliance with LOK / CGA Responsible Gaming requirements under GDPR Article 6(1)(c), and legitimate interests in player welfare and Regulatory Compliance under GDPR Article 6(1)(f).

3.6. What Personal Data is processed when I contact support?

When you contact customer support, we may process support tickets, chat transcripts, email correspondence, call notes, account identifiers, and transaction references tied to the inquiry.

The purpose is to respond to your request, provide service communications, maintain service quality, and resolve disputes where necessary.

The legal bases are contract performance under GDPR Article 6(1)(b) and legitimate interests in service quality and dispute resolution under GDPR Article 6(1)(f).

3.7. What Personal Data is processed for marketing communications?

Where permitted, we may process contact details such as email address, phone number, or push token, marketing preferences, engagement metrics, and non-sensitive bonus eligibility status.

The legal basis for electronic marketing is consent under GDPR Article 6(1)(a). Where allowed by law, legitimate interests under GDPR Article 6(1)(f) may apply for similar-product soft opt-in.

Marketing communications are always subject to opt-out and responsible gaming restrictions.

3.8. What Personal Data is processed for Website performance and analytics?

For Website performance, analytics, and cookies, we may process usage logs, cookie identifiers, browser type and version, traffic data, and on-site interaction metrics.

The legal bases are legitimate interests in operating and improving the Website under GDPR Article 6(1)(f), and consent under GDPR Article 6(1)(a) where required for non-essential cookies.

3.9. What Personal Data is processed for regulatory reporting and disputes?

For regulatory reporting, audits, and dispute resolution, we may process records required for regulatory cooperation, compliance audits, legal proceedings, or dispute resolution, as permitted by applicable laws.

The legal bases are legal obligations under GDPR Article 6(1)(c), including cooperation with the Curaçao Gaming Authority, FIU, tax authorities, and other authorities, and legitimate interests in establishing, exercising, or defending legal claims under GDPR Article 6(1)(f).

4. Data Sources

4.1. Where does the Company obtain Personal Data from?

We collect Personal Data primarily from you when you interact with the Services.

This may happen when you create an Account, complete verification steps, make deposits or withdrawals, use the Website, or communicate with our support team.

4.2. Can Personal Data be collected from your use of the Services?

Yes. Data may be generated through your activity on the platform.

This may include gameplay, transaction history, device and log information, and cookie data in accordance with the Cookie Policy.

4.3. Can Personal Data come from third parties?

Yes. We may obtain Personal Data from trusted third-party verification and compliance services that support compliance, security, and payment-related functions.

4.4. Can publicly available sources be used?

Where necessary, we may supplement information you provide with data obtained from publicly available and legitimate sources.

This is done solely for compliance, verification, or risk management purposes.

4.5. Can authorities provide Personal Data?

In some cases, we may receive Personal Data from regulatory or law enforcement authorities in connection with legal and compliance obligations.

5. Retention of Personal Data

5.1. How long is Personal Data kept?

Personal Data is retained only for as long as necessary to fulfill the purposes for which it was collected and processed, or as required under applicable legal and regulatory obligations.

5.2. What determines the retention period?

Retention periods are determined based on:

  • the purpose of processing, including provision of the Services, compliance with contractual obligations, or protection of legitimate interests;
  • applicable statutory retention requirements, including Anti-Money Laundering, gaming, and tax regulations;
  • the need to establish, exercise, or defend legal claims;
  • audit and supervisory requirements.

5.3. What happens when the retention period expires?

Once the relevant retention period expires, Personal Data is securely deleted, anonymized, or archived in a way that ensures it can no longer be associated with you, unless further retention is required by law.

6. Data Storage and International Transfers

6.1. Where is Personal Data stored?

Personal Data is stored on secure servers operated by us and by trusted service providers.

These servers may be located within the European Economic Area and in jurisdictions outside the European Economic Area, including Curaçao, depending on operational and regulatory requirements.

6.2. What safeguards apply to transfers outside the EEA?

When Personal Data is transferred outside the EEA, we ensure that such transfers comply with applicable data protection laws.

Appropriate safeguards may include adequacy decisions or Standard Contractual Clauses.

6.3. What are adequacy decisions?

Adequacy decisions are decisions by the European Commission recognizing that a country provides an adequate level of data protection.

Where such a decision applies, Personal Data may be transferred on that basis.

6.4. What are Standard Contractual Clauses?

Standard Contractual Clauses are clauses approved by the European Commission.

Where no adequacy decision exists, we may use Standard Contractual Clauses to help ensure that Personal Data remains protected when transferred outside the EEA.

7. Sharing of Personal Data

7.1. When may Personal Data be shared?

Personal Data may be shared only when necessary and for the purposes outlined in this Privacy Policy.

Sharing is carried out in compliance with applicable data protection laws, contractual obligations, and security measures.

7.2. Can Personal Data be shared with authorities?

Yes. Personal Data may be shared with regulatory and supervisory authorities, such as the Curaçao Gaming Authority, the Financial Intelligence Unit, tax authorities, and other governmental or law enforcement bodies.

Such sharing may be required by law and regulatory obligations, including AML and responsible gaming requirements.

7.3. Can Personal Data be shared with identity verification providers?

Yes. Identity verification and compliance service providers may receive Personal Data to help verify customer identity and comply with AML and Know Your Customer obligations.

7.4. Can Personal Data be shared with payment processors?

Yes. Payment processors and financial institutions may receive Personal Data to enable deposits, withdrawals, refunds, and other payment-related services.

This may include transaction details, payment method information, and account identifiers.

7.5. Can Personal Data be shared with customer support tools?

Yes. External service providers that facilitate email delivery, live chat, or other communication channels may process Personal Data such as contact details and support messages to assist in providing customer service.

7.6. Can Personal Data be shared with fraud prevention and security partners?

Yes. Trusted service providers may assist in protecting the security and integrity of the platform, including detecting and preventing potentially fraudulent or unauthorized activity.

7.7. Can Personal Data be shared with analytics and optimization platforms?

Yes. Third-party services may help analyze Website usage, conduct A/B testing, and improve user experience.

Where possible, this data is anonymized or pseudonymized.

7.8. Can Personal Data be shared with game content providers?

Yes. Licensed third-party game providers may receive the minimum data required to enable certain features of the platform.

This may include player identifiers and game session data.

7.9. Can Personal Data be shared with IT infrastructure providers?

Yes. Secure hosting, internal tools, and productivity solutions may be used to store and manage data necessary for the operation of the Services.

8. Cookies and Similar Technologies

8.1. Does the Website use cookies?

Yes. The Website may use cookies and similar technologies to enhance user experience, enable essential Website functions, and analyze site performance.

Cookies are small text files stored on your device when you visit the Website. They allow the Website to recognize your device and store certain information about your preferences or past actions.

8.2. What are strictly necessary cookies?

Strictly necessary cookies are essential for the functioning of the Website and cannot be switched off in our systems.

They enable core functionality such as page navigation, access to secure areas, and user authentication.

8.3. What are functional cookies?

Functional cookies support enhanced functionality and personalization.

For example, they may help remember language preferences or user settings. They may be set by us or by third-party providers whose services we use.

8.4. What are analytical or performance cookies?

Analytical or performance cookies collect aggregated and anonymized data about how visitors use the Website.

This may include page visits, click-through rates, traffic sources, and on-site interaction metrics. The purpose is to measure and improve Website performance.

8.5. What are advertising or targeting cookies?

Advertising or targeting cookies may be set by us or by advertising partners to build a profile of your interests and deliver relevant advertising on this Website or on other websites.

They may also help limit how often you see an advertisement and assess its effectiveness.

8.6. What is the difference between session and persistent cookies?

Session cookies expire when you close your browser.

Persistent cookies remain on your device for a predetermined period or until you delete them.

8.7. What is the difference between first-party and third-party cookies?

First-party cookies are set by us.

Third-party cookies are set by third-party service providers acting on our behalf. These may include providers of analytics, customer support tools, or advertising networks.

8.8. Can I manage cookies?

Yes. You may control and manage cookies through your browser settings.

Most browsers allow you to refuse or delete cookies. However, restricting certain cookies may affect the availability or functionality of some parts of the Website.

9. Protection of Minors

9.1. What age requirements apply?

The Services are strictly intended for individuals who are at least eighteen (18) years old or have reached the legal age as defined by their respective jurisdictions, whichever is higher.

By accessing or registering for the Services, you confirm that you meet this age requirement.

9.2. What measures are used to prevent underage access?

In alignment with the Curaçao Gaming Authority’s Responsible Gaming Policy introduced in February 2025, measures are implemented to prevent underage access to the Services.

These measures include document verification, automated monitoring, security reviews, and data purging where a user is identified as a minor.

9.3. What is document verification?

Document verification means that users may be required to provide valid government-issued identification documents during the registration process.

This supports age confirmation and compliance with applicable requirements.

9.4. What is automated monitoring?

Automated monitoring involves continuous monitoring of user activity to detect inconsistencies or signs of underage access attempts.

9.5. What happens if underage access is suspected?

If underage access is suspected, security reviews may be conducted.

These reviews may include verification of registration data and financial transactions.

9.6. What happens to data submitted by minors?

Personal Data submitted by individuals identified as minors is deleted immediately.

9.7. What role do parents and guardians have?

Parents and guardians are encouraged to use available parental control tools and educate minors about responsible online behavior to prevent unauthorized access to the Services.

9.8. How does responsible gaming relate to minors?

The Company’s commitment to responsible gaming includes adherence to Curaçao Gaming Authority guidelines on player protection and age verification.

Policies are reviewed and enhanced to ensure they meet or exceed regulatory standards.

10. Your Data Protection Rights

10.1. What rights do I have under the GDPR?

Under the GDPR, you have several rights regarding your Personal Data.

These include the right of access, right to rectification, right to erasure, right to restrict processing, right to data portability, and right to object.

10.2. What is the Right of Access?

Under Article 15 GDPR, you can request confirmation of whether we process your Personal Data and obtain a copy of such data, together with information about how it is used.

10.3. What is the Right to Rectification?

Under Article 16 GDPR, you can request correction of inaccurate or incomplete Personal Data without undue delay.

10.4. What is the Right to Erasure?

Under Article 17 GDPR, you can request deletion of your Personal Data where certain legal grounds apply.

For example, this may apply where data is no longer necessary for the purposes for which it was collected, or where you withdraw consent and no other lawful basis applies.

10.5. What is the Right to Restrict Processing?

Under Article 18 GDPR, you can request that we limit the processing of your Personal Data in specific situations.

This may include cases where the accuracy of the data is contested or where processing is unlawful.

10.6. What is the Right to Data Portability?

Under Article 20 GDPR, you can request a copy of the Personal Data you provided to us in a structured, commonly used, and machine-readable format.

Where technically feasible, you may transfer that data to another controller.

10.7. What is the Right to Object?

Under Article 21 GDPR, you can object at any time to the processing of your Personal Data for reasons related to your particular situation, where processing is based on legitimate interests.

You can also object to processing for direct marketing purposes.

10.8. How can I exercise my rights?

To exercise your data protection rights, you may contact us through:

11. Consent and Withdrawal

11.1. Can I withdraw consent?

Yes. If we process your Personal Data based on your consent, you have the right to withdraw that consent at any time.

11.2. Does withdrawal affect earlier processing?

No. Withdrawal of consent does not affect the lawfulness of processing based on consent before its withdrawal.

11.3. How can I withdraw consent?

To withdraw consent, contact us using the contact channels specified in this Privacy Policy.

After receiving your request, we will stop processing your Personal Data unless retention or continued processing is required to comply with legal or regulatory obligations.

11.4. Can withdrawal affect access to Services?

Yes. If withdrawing consent affects our ability to provide certain Services, we will inform you of the consequences before completing the withdrawal process.

12. Complaints

12.1. Can I lodge a complaint?

Yes. Under Article 77 GDPR, if you believe that your Personal Data is being processed unlawfully or that your privacy rights have been violated, you have the right to lodge a complaint.

12.2. Where can I lodge a complaint?

You may lodge a complaint with:

  • the supervisory authority in the EU Member State where you reside, work, or where the alleged violation occurred;
  • the Curaçao Gaming Authority or any other relevant data protection authority in Curaçao.

12.3. Should I contact the Company first?

If you have concerns or unresolved questions about the Processing of your Personal Data, you are encouraged to contact us directly first.

We will make every reasonable effort to address your concerns in a timely and lawful manner.

13. Providing Personal Data

13.1. Is providing Personal Data mandatory?

Providing Personal Data may be a legal requirement, a contractual requirement, or a requirement necessary to access the Services.

13.2. When is Personal Data required by law?

Certain data must be provided to comply with applicable laws and regulations, including Anti-Money Laundering obligations and responsible gaming requirements.

13.3. When is Personal Data required for a contract?

Some data is necessary to enter into and perform a contract with you.

This includes data needed to enable access to the Services and process transactions.

13.4. What happens if I do not provide required Personal Data?

Failure to provide required Personal Data may result in:

  • inability to create or maintain an Account;
  • restrictions on the use of the Services;
  • termination of the contractual relationship;
  • failure to comply with regulatory obligations, which may prevent us from providing Services.

14. Legal Disclaimer

14.1. Are the Services guaranteed to be uninterrupted or error-free?

No. The Services operate on an “AS-IS” and “AS-AVAILABLE” basis without warranties or guarantees of uninterrupted or error-free performance.

14.2. Is absolute data security guaranteed?

No. While reasonable precautions are taken to protect Personal Data, absolute security cannot be guaranteed due to the complex nature of technology and evolving cybersecurity threats.

14.3. What limitations of liability apply?

To the maximum extent permitted by law, we are not liable for:

  • events beyond our direct control, including system failures, cyberattacks, or unauthorized access;
  • indirect, incidental, consequential, or punitive damages arising from data breaches, unauthorized disclosure, or misuse of Personal Data;
  • errors, inaccuracies, or security vulnerabilities on third-party websites linked from the platform.

14.4. Is the Company responsible for third-party websites?

By using the Services, you acknowledge and agree that the Company does not bear responsibility for external websites or services operated by third parties, even if they are linked from the platform.

15. Acceptance, Updates, and Language

15.1. What does continued use of the Services mean?

Your continued use of the Services signifies your explicit acceptance of this Privacy Policy.

This document serves as the entire and exclusive Privacy Policy and replaces any previous versions.

15.2. Should this Policy be read with other documents?

Yes. This Privacy Policy should be read together with the Terms and Conditions and any additional applicable notices posted on the platform.

15.3. Can this Privacy Policy be changed?

Yes. The Company reserves the right to modify this Privacy Policy at any time.

Any changes will be posted on the platform, and continued use of the Services after modifications constitutes acceptance of the revised Policy.

15.4. Should I review this Privacy Policy regularly?

Yes. You are strongly encouraged to review this Privacy Policy regularly to stay informed about updates.

15.5. Which language version prevails?

All versions of this Privacy Policy except the English version are provided for informational purposes only.

The English version prevails in case of any discrepancies or conflicts between different versions.