This Privacy Notice outlines how Incaspin Casino gathers, manages, stores, and safeguards personal data pertaining to players located in Germany https://incaspincasino.de.com/legal-and-affiliates/. The document operates within the scope of the European Union’s General Data Protection Regulation (GDPR) and the German Federal Data Protection Act (Bundesdatenschutzgesetz, BDSG-neu). Incaspin Casino acts as the data controller for personal information provided through its website, mobile applications, and related services. German players enjoy specific statutory rights concerning their data, and this notice details the lawful bases for processing, data retention periods, third-party sharing protocols, and the technical safeguards implemented to prevent unauthorised access. The document also describes the responsibilities of the Data Protection Officer and the supervisory authority contact procedures. Every section has been compiled to ensure transparency and compliance with Article 13 and Article 14 of the GDPR, offering German users with a complete overview of how their casino account data, payment details, identification documents, and behavioural analytics are managed across the entire customer lifecycle.
2. Groups of Private Data Obtained
2.1 Identity Confirmation and User Data
German users must provide specific personal data to create and keep an living Incaspin Casino account. This class includes complete statutory full name, residential address, DOB, place of birth, nationality, and gender. For identity validation purposes mandatory under German anti-money laundering rules, the casino collects government-issued identity papers such as passport copies, national ID copies, and residence permit documentation. The program also stores the ID number, issuing body, validity end, and a biometrical matching result generated during the automatic confirmation process. Address verification is finished through latest utility bills, bank statements, or formal communication that clearly displays the player’s full name, on-file location, and an creation date inside of the previous three months. Incaspin Casino implements these verification requirements evenly to conform with the Fourth and Fifth Anti-Money Laundering Orders as incorporated into German law, ensuring that all account satisfies the statutory identification assurance level before any withdrawals are authorized.
2.2 Monetary and Payment Data
Financial data encompasses all deposit and withdrawal records, including payment method details, masked card numbers, e-wallet account email addresses, bank account IBAN details for SEPA transfers, and crypto wallet addresses where applicable. Incaspin Casino keeps complete transaction histories showing timestamps, amounts in EUR or equivalent cryptocurrency, processing statuses, and any intermediary payment processor references. Source of funds declarations and accompanying documents such as payslips, tax returns, or business financial statements are collected when players reach specific deposit thresholds or trigger enhanced due diligence procedures. This data is isolated in encrypted database tables with access limited to compliance personnel and senior financial officers. German players using Sofort, Giropay, or other local payment methods should be aware that the chosen payment provider will also process transaction data according to its own privacy policy, with Incaspin Casino obtaining only the information necessary to credit the player account.
2.3 Technical and Behavioral Records
While German players visit the Incaspin Casino platform, the system automatically collects technical identifiers including IP addresses, device types, operating system versions, browser fingerprints, screen resolutions, language settings, and mobile carrier details. Session data covers login timestamps, page navigation paths, game launches, bet amounts, win and loss records, and in-game feature activations. This technical corpus permits the casino to offer optimised gaming experiences, spot fraudulent activity patterns, and uphold responsible gambling self-exclusion settings. Behavioural analytics measure betting frequency, average stake sizes, session duration, and deposit velocity to supply the responsible gambling algorithms that generate personalised risk alerts. All technical logs are anonymised where possible and stored separately from core identity records, with re-identification possible only through a tightly controlled cryptographic lookup procedure accessible exclusively to the fraud and compliance teams under documented access justification.
7. Information Security Controls
Incaspin Casino utilizes a multilevel security architecture conforming to the ISO 27001 control framework and the technical requirements specified in Article 32 of the GDPR. Network-level protections encompass enterprise-grade firewalls set up with stateful packet inspection, intrusion detection and prevention systems that monitor traffic patterns for indicators of compromise, and distributed denial-of-service mitigation services that absorb volumetric attacks before they reach the application layer. All data transmitted between German player devices and casino servers is encrypted using Transport Layer Security version 1.3 with forward secrecy enabled, blocking retrospective decryption of captured traffic even if long-term private keys are subsequently exposed. Internal administrative interfaces are segmented on a management network not accessible from the public internet, with access allowed solely through multi-factor authenticated VPN tunnels coming from pre-registered static IP addresses assigned to authorised personnel. At the application layer, the platform mandates strong password policies necessitating minimum character lengths and complexity standards, with passwords hashed using bcrypt with per-user salts before storage. Account access anomalies trigger step-up authentication challenges or temporary account locks until manual review by the security team. Database-level encryption safeguards data at rest, with separate encryption keys for personal data columns, financial fields, and identity document stores, each controlled through a hardware security module that logs every key access operation. Regular vulnerability scanning and annual penetration testing by an independent CREST-accredited security firm confirm the effectiveness of these controls, with critical findings resolved within 48 hours. Security incident response procedures are evaluated through bi-annual tabletop exercises engaging the Data Protection Officer, with a documented breach notification workflow ensuring German players and the supervisory authority receive notification within the 72-hour deadline stipulated by GDPR.
8. Entitlements of German Data Subjects
German gamblers hold the complete range of data subject prerogatives listed in Articles 15 through 21 of the GDPR, along with the option to file a complaint with a supervisory authority. The right to access allows players to receive verification of if Incaspin Casino processes their individual data and to receive a version of that data along with particulars about processing purposes, categories, receivers, holding periods, and the presence of automated decision-making. Access inquiries are fulfilled within one month, at no cost for the initial request, with the reply provided in a organized, generally used, machine-readable layout. The right to rectification allows players to rectify wrong personal data or supplement missing files, a notably applicable entitlement for identity document changes following name alterations or address moves. Incaspin Casino deals with rectification applications within ten business days and confirms rectifications to any third-party addressees to whom the inaccurate data was shared. The right of deletion applies where the personal data is not anymore necessary for the purposes for which it was gathered, where consent is withdrawn, where the player opposes to processing and no overriding legitimate grounds are present, or where processing is unlawful. However, statutory retention requirements override erasure requests, and data necessary for legal compliance will be restricted from further processing rather than removed until the retention period expires. The right to restriction of processing functions as an option where the precision of data is disputed, processing is unlawful but the player objects to deletion, or the player necessitates the data for legal claims despite the controller no longer needing it. Data portability prerogatives under Article 20 GDPR are limited to data supplied by the player and handled by automated ways based on permission or agreement, implying gameplay history and transaction logs are suitable for portability while fraud detection assessments obtained from internal models do not. Rights inquiries should be sent to the Data Protection Officer email address, with proper proof of identity needed before any data is released.
4. Data Sharing and External Recipients
4.1 Internal Data Access Architecture
In the Incaspin Casino operational system, personal data access adheres to a strict least-privilege model used for four distinct personnel tiers. Customer support agents retrieve basic account information and communication history but are unable to view full financial records or identity documents. Compliance officers have permissions to inspect verification documents, transaction patterns, and risk scores. Financial department personnel process withdrawal requests and view payment instrument details needed to execute transfers. IT security staff review system logs and security event data but do not regularly interact with player-identifiable records. Every access event is tracked with a timestamp, user identifier, and purpose code, creating an immutable audit trail that is reviewed quarterly by the Data Protection Officer. German players can request a copy of the access log entries pertaining to their account by submitting a subject access request through the designated privacy channel.
4.2 External Service Providers and Authorities
Incaspin Casino utilizes specialist external processors such as cloud hosting providers running ISO 27001-certified data centres inside the European Economic Area, payment processors authorised by the German Federal Financial Supervisory Authority, identity verification services that match submitted documents against authoritative databases, email delivery platforms for transactional communications, and CRM software vendors for customer engagement analytics. Each processor passes through a rigorous vendor assessment covering technical security measures, sub-processor transparency, international transfer safeguards, and business continuity capabilities. Contracts require data processing solely on documented instructions from Incaspin Casino, with no entitlement for the processor to repurpose data for its own objectives. Regulatory disclosures to German law enforcement agencies, tax authorities, or gambling regulators happen only when legally mandated, and unless prohibited by law, the casino will notify affected players of such disclosures. The following key principles regulate all third-party data sharing arrangements:
- Processors receive only the least personal data necessary to carry out their contracted function, with field-level data minimisation enforced to every integration.
- Sub-processor engagements need prior written approval from Incaspin Casino, and any unapproved subcontracting forms a material breach of the data processing agreement.
- All processors must hold ISO 27001 certification or comparable independently audited security qualifications, with current documentation filed with Incaspin Casino before data flows commence.
- No personal data is disclosed to advertising technology platforms, data brokers, or any entity whose primary business involves monetising personal information.
Třetím Důvody a právní základy pro zpracování
Incaspin Casino zpracovává personal data podle několika odlišných GDPR právních základů, selected v závislosti na the specific processing activity. The performance of a contract pursuant to Article 6(1)(b) GDPR covers všechna zpracování dat potřebné to create and manage hráčského účtu, provádění vkladů a výběrů, a doručení interaktivních herních služeb that German players aktivně vyžadují during registration. This includes zasílání platebních pokynů zúčtovacím bankám a ověřování toho, že players meet požadavek minimálního věku 18 let dle německé legislativy. Zpracování na základě právní povinnosti dle Article 6(1)(c) GDPR pokrývá anti-money laundering customer due diligence, suspicious transaction reporting relevantním jednotkám finančního zpravodajství, record retention k uspokojení commercial and tax law requirements, and compliance s německou regulací hazardu týkajících se standardů ochrany hráčů. Použitelné právní rámce zahrnují Geldwäschegesetz and the stipulations státní smlouvy o hazardu pokud je to relevantní to data retention mandates.
Oprávněné zájmy sledované Incaspin Casino dle Article 6(1)(f) GDPR obsahují network and information security monitoring, fraud prevention and detection, direct marketing of similar products to existing customers where permitted dle Section 7 of the German Act Against Unfair Competition, a obchodní analýzy za účelem zlepšení služeb. German players retain the absolute right to object to processing založeném na oprávněných zájmech, včetně profilování k přímým marketingovým účelům, a tyto námitky budou respektovány without undue delay. Povolení under Article 6(1)(a) GDPR je spoléháno for optional marketing communications via email and SMS pokud the player has actively opted in, pro nasazení neesenciálních cookies a sledovacích technologií, a pro zpracování citlivých dat za specifických okolností. Consent withdrawal mechanisms are prominently placed v rámci nastavení účtu a v patičce každého marketingového sdělení, s tím, že odvolání má účinek bez zpětných důsledků pro dříve legální zpracování. German players kteří dosud nedosáhli the age of 18 nesmějí otevírat účty, a veškerá omylem sebraná data nezletilých is deleted immediately upon discovery.
9. Cookie Policy and Tracking Technologies
9.1 Core and Technical Cookies
The Incaspin Casino website and mobile platform deploy a range of cookies and similar tracking technologies to ensure core functionality. Strictly necessary cookies handle session state across page loads, maintain login authentication tokens, and preserve security context for CSRF protection. These first-party session cookies terminate when the browser is closed and do not require prior consent under German law transposing the ePrivacy Directive, as they are indispensable for the desired service delivery. Functional cookies keep language preferences, preferred currency displays, and responsible gambling limit settings across visits, guaranteeing that returning players experience a consistent personalised environment without reconfiguring their preferences. The maximum lifespan of functional cookies is 365 days, after which they are deleted automatically if the player has not returned to the platform. Incaspin Casino does not use flash cookies, supercookies, or any recreating techniques that circumvent browser deletion actions.
9.2 Metrics and Marketing Cookies
Analytics and marketing cookies are set only after German players grant explicit, freely given consent through the cookie consent management platform presented on first visit. The consent tool offers clear descriptions of each cookie category, the specific providers participating, the purposes of data collection, and the retention duration for each cookie type. Players may allow or deny consent for each category independently, and consent preferences are recorded as documentary evidence in an encrypted consent log with timestamp and IP address. Analytics cookies from a privacy-focused measurement service track aggregated page interaction metrics without cross-site tracking or user-level profiling. Marketing cookies facilitate campaign attribution and frequency capping for promotional banners presented within the logged-in casino environment. German players may change their consent choices at any time by accessing the cookie settings panel referenced in the website footer. Declining analytics or marketing cookies does not affect gameplay functionality or account standing in any manner. The consent tool asks again players annually to reaffirm or update their preferences.
Summary
Incaspin Casino has organized its data protection system to meet the high standards demanded by German players and mandated by the GDPR and the BDSG-neu. From the first collection of identity and contact details through to the ultimate deletion or anonymisation of records years after account closure, every personal data life cycle stage operates under documented policies, contractual safeguards, and technical controls that are regularly audited and improved. The casino preserves transparent communication channels for rights requests, offers granular cookie consent options, and limits data sharing to vetted processors and legally mandated disclosures. German players are urged to read this Privacy Notice alongside the general Terms and Conditions and the Responsible Gambling Policy available on the Incaspin Casino website, and to contact the Data Protection Officer with any questions about how their personal information is handled.
Pátý bod: International Data Transfers
The core data storage infrastructure for Incaspin Casino resides within secure facilities located in the European Economic Area, specifically engineered to serve the German market with low-latency connectivity while maintaining full GDPR jurisdictional coverage. Some specialised processing activities may involve international data transfers to countries outside the EEA, including fraud detection services operating from certified facilities in third countries and customer support continuity arrangements during peak demand periods. For any such transfer, Incaspin Casino applies the safeguards mandated by Chapter V of the GDPR. Standard contractual clauses approved by the European Commission form the foundational transfer mechanism for processor relationships, with supplementary technical and organisational measures applied where the recipient country lacks an adequacy decision from the European Commission. German players should understand that supplementary measures include end-to-end encryption of data in transit and at rest using AES-256 standards, strict key management policies that prevent the foreign processor from accessing plaintext data, and contractual obligations requiring the processor to challenge any government access request and notify Incaspin Casino immediately when legally permitted. Transfer impact assessments are conducted prior to onboarding any non-EEA processor and are reviewed whenever the legal landscape of the recipient jurisdiction changes materially. The Data Protection Officer maintains a current register of all international transfers, which is made available to the competent German data protection authority upon request and can be summarised for data subjects who want to know the geographical flow of their information.
Six. Information Archiving and Removal Policies
Incaspin Casino runs a precise data retention policy aimed to fulfill statutory record-keeping duties while reducing the storage of personal data after its intended purpose. Player account data and full transaction histories are kept for the full length of the ongoing business relationship, described as the term from account creation till the account is closed, plus an extra statutory retention duration stipulated by German anti-money laundering legislation and commercial law. Under the Geldwäschegesetz, identification records, transaction confirmations, and due diligence materials must be preserved for at least five years after the end of the calendar year in which the business relationship concluded. Accounting records applicable to tax duties are retained for ten years in compliance with the German Fiscal Code. Following the end of these mandatory terms, personal data is either irrevocably anonymised so that re-identification becomes impossible with all means reasonably expected to be used, or safely deleted through cryptographic erasure and physical storage media cleaning processes. Technical logs and security event data follow a reduced retention period of twelve months, after which they are combined into anonymised statistical summaries. Inactive accounts exhibiting no login activity for a unbroken period of 24 months are flagged for dormancy assessment, and the associated personal data is minimised to keep only the core ID and transaction records needed for the remaining statutory retention timeline. The casino uses automated data lifecycle management processes that operate weekly to find records beyond their retention deadlines, initiating deletion processes without human involvement, with the results recorded for compliance audit purposes.
První bod: Identita správce údajů a kontaktní údaje
The data controller for all personal data zpracovávané prostřednictvím the Incaspin Casino platform představuje subjekt působící pod názvem značky Incaspin Casino, zapsaná v státě známé svým dodržováním EU data protection equivalence standards. The registered office address and company registration number jsou k dispozici na ověřenou žádost e-mailem na adresu pracovníkovi pro ochranu osobních údajů, or by consulting the imprint section hlavních webových stránek. Hráči z Německa may direct jakékoli dotazy týkající se soukromí na jmenovanému pracovníkovi pro ochranu údajů, který působí nezávisle and reports directly to vrcholovému vedení. Tento pracovník can be reached přes speciální šifrovanou e-mailovou adresu uvedenou v kompletního textu politiky ochrany osobních údajů. Incaspin Casino má oprávněného zástupce na území Evropské unie for purposes of článku 27 GDPR, ensuring that německé kontrolní orgány a subjekty údajů disponují přímým kontaktem ohledně regulačních otázek. Tento subjekt determines účely a prostředky zpracování all personal data získaných při registraci účtu, ověřování Know Your Customer, platebních transakcích vkladů a výběrů, and ongoing gameplay activity. Sem patří informace generované pomocí cookies, device fingerprinting technologies, and server logs. Hráči z Německa by si měli uvědomit, že správce vykonává absolutní moc nad rozhodováním over data processing operations a zároveň zadává pečlivě prověřené zpracovatele for specific technical services jako je hosting, platební brány, a platformy pro řízení vztahů se zákazníky. Každá smluvní dohoda se zpracovatelem je upravena a binding data processing agreement která splňuje požadavky Article 28 GDPR, s vyhrazenými povinnými právy na audit by Incaspino Casino to verify ongoing compliance. The contact details of the EU representative jsou poskytnuty the competent German data protection authority jak vyžaduje zákon.
