This Privacy Notice outlines how Incaspin Casino gathers, processes, stores, and safeguards personal data belonging to players located in Germany. The document works within the framework of the European Union’s General Data Protection Regulation (GDPR) and the German Federal Data Protection Act (Bundesdatenschutzgesetz, BDSG-neu). Incaspin Casino serves as the data controller for personal information provided through its website, mobile applications, and related services. German players have specific statutory rights regarding their data, and this notice outlines the lawful bases for processing, data retention periods, third-party sharing protocols, and the technical safeguards deployed to prevent unauthorised access. The document also details the responsibilities of the Data Protection Officer and the supervisory authority contact procedures. Every section has been compiled to ensure transparency and compliance with Article 13 and Article 14 of the GDPR, offering German users with a complete overview of how their casino account data, payment details, identification documents, and behavioural analytics are managed during the entire customer lifecycle.
1. Identita správce údajů a podrobnosti o kontaktu
Správcem údajů za veškeré osobní údaje processed through the Incaspin Casino platform je the legal entity operating under the brand name Incaspin Casino, zapsaná v státě recognised for its adherence to EU data protection equivalence standards. The registered office address a registrační číslo jsou k dispozici na ověřenou žádost e-mailem na adresu pracovníkovi pro ochranu osobních údajů, nebo nahlédnutím do the imprint section of the main website. Hráči z Německa mohou směřovat any privacy-related inquiries na jmenovanému pracovníkovi pro ochranu údajů, který působí nezávisle a podává zprávy přímo senior management. Pověřenec je k zastižení via vyhrazeného šifrovaného e-mailového kanálu zveřejněnou v rámci kompletního textu politiky ochrany osobních údajů. Incaspin Casino udržuje a legal representative v Evropské unii for purposes of ustanovení čl. 27 GDPR, čímž zajišťuje, že německé dozorové úřady i dotčené osoby have a direct point of contact pro regulační záležitosti. The controller determines účely a prostředky of processing all personal data získaných při account registration, Know Your Customer verification, deposit and withdrawal transactions, and ongoing gameplay activity. This includes informace generované pomocí cookies, technologií otisku zařízení, a serverových logů. German players should note, že tento subjekt uplatňuje plnou rozhodovací pravomoc over data processing operations while commissioning carefully vetted processors for specific technical services např. hosting, platební brány, a platformy pro řízení vztahů se zákazníky. Each processor relationship is governed by závaznou smlouvou o zpracování údajů která splňuje požadavky článku 28 GDPR, s možností provádět povinné audity pro Incaspin Casino k ověření trvalého dodržování předpisů. Kontaktní údaje of the EU representative are provided to kompetentnímu německému dozorovému orgánu pro ochranu dat v souladu s právními předpisy.
8. Entitlements of Germany-based Data Subjects
German users hold the full suite of data subject prerogatives specified in Articles 15 through 21 of the GDPR, together with the entitlement to submit a appeal with a supervisory authority https://incaspincasino.de.com/legal-and-affiliates/. The right to access permits players to obtain verification of if Incaspin Casino processes their private data and to get a duplicate of that data including particulars about processing purposes, classes, addressees, retention periods, and the presence of automated decision-making. Access requests are completed within one month, without charge for the first request, with the reply delivered in a organized, generally used, machine-readable format. The right to rectification enables players to amend inaccurate personal data or fill in missing documents, a especially relevant entitlement for identity document updates following name alterations or address moves. Incaspin Casino processes rectification requests within ten business days and verifies rectifications to any third-party addressees to whom the inaccurate data was revealed. The right to erasure applies where the personal data is not anymore needed for the objectives for which it was collected, where consent is canceled, where the player opposes to processing and no prevailing legitimate grounds are present, or where processing is illegal. However, statutory retention requirements take precedence over erasure requests, and data required for legal compliance will be limited from further processing rather than deleted until the retention period lapses. The restriction right of processing functions as an option where the accuracy of data is contested, processing is illegal but the player opposes deletion, or the player requires the data for legal assertions despite the controller no longer demanding it. Data portability rights under Article 20 GDPR apply solely to data furnished by the player and handled by automated methods based on consent or agreement, meaning gameplay history and transaction logs are suitable for portability while fraud detection ratings derived from internal algorithms do not. Rights requests should be addressed to the Data Protection Officer email address, with legitimate proof of identity required before any data is disclosed.
6. Information Retention and Deletion Rules
Incaspin Casino implements a precise data retention policy designed to meet statutory record-keeping requirements while minimising the storage of personal data after its intended purpose. Player account data and complete transaction logs are stored for the complete duration of the current business relationship, described as the term from account creation till the account is terminated, plus an extra statutory retention duration stipulated by German anti-money laundering regulations and commercial law. Under the Geldwäschegesetz, identification records, transaction receipts, and due diligence papers must be preserved for at least five years from the end of the calendar year in which the business relationship terminated. Accounting records relevant to tax obligations are kept for ten years in accordance with the German Fiscal Code. Following the end of these mandatory terms, personal data is either permanently anonymised so that re-identification becomes impossible with all means reasonably likely to be applied, or safely deleted through cryptographic erasure and physical storage media wiping procedures. Technical logs and security event data observe a reduced retention period of twelve months, after which they are compiled into anonymised statistical summaries. Inactive accounts demonstrating no login activity for a continuous period of 24 months are flagged for dormancy review, and the connected personal data is limited to retain only the core identifier and transaction records needed for the remaining statutory retention clock. The casino deploys automated data lifecycle management processes that operate weekly to locate records beyond their retention deadlines, triggering deletion procedures without human involvement, with the results documented for compliance audit objectives.
7. Data Security Measures
Incaspin Casino utilizes a multi-layered security architecture in accordance with the ISO 27001 control framework and the technical requirements specified in Article 32 of the GDPR. Network-level protections encompass enterprise-grade firewalls configured with stateful packet inspection, intrusion detection and prevention systems that monitor traffic patterns for indicators of compromise, and distributed denial-of-service mitigation services that neutralize volumetric attacks before they hit the application layer. All data transferred between German player devices and casino servers is encrypted using Transport Layer Security version 1.3 with forward secrecy enabled, avoiding retrospective decryption of captured traffic even if long-term private keys are eventually leaked. Internal administrative interfaces are separated on a management network unreachable from the public internet, with access allowed solely through multi-factor authenticated VPN tunnels starting from pre-registered static IP addresses belonging to authorised personnel. At the application layer, the platform imposes strong password policies demanding minimum character lengths and complexity standards, with passwords hashed using bcrypt with per-user salts before storage. Account access anomalies activate step-up authentication challenges or temporary account locks until manual review by the security team. Database-level encryption protects data at rest, with separate encryption keys for personal data columns, financial fields, and identity document stores, each managed through a hardware security module that logs every key access operation. Regular vulnerability scanning and annual penetration testing by an independent CREST-accredited security firm validate the effectiveness of these controls, with critical findings resolved within 48 hours. Security incident response procedures are evaluated through bi-annual tabletop exercises engaging the Data Protection Officer, with a documented breach notification workflow guaranteeing German players and the supervisory authority receive notification within the 72-hour deadline required by GDPR.
2. Groups of Personal Data Gathered
2.1 Identification Confirmation and User Data
German users must provide certain personal data to establish and sustain an current Incaspin Casino account. This group includes full statutory full name, home location, DOB, place of birth, nationality, and gender. For identification validation aims mandatory under German anti-money laundering rules, the casino obtains government-issued ID documents such as passport scans, scans of national ID, and residence permit documentation. The system also stores the ID number, issuer, validity end, and a biometrical matching score created during the automated confirmation process. Address validation is done through current utility bills, bank statements, or official communication that clearly displays the user’s full name, recorded location, and an creation date inside the last three months. Incaspin Casino applies these verification requirements evenly to conform with the Fourth and Fifth Anti-Money Laundering Directives as transposed into Germany’s law, ensuring that every account meets the regulatory identification certainty level before any withdrawals are authorized.
2.2 Monetary and Payment Data
Payment information encompasses all deposit and withdrawal records, including payment method details, masked card numbers, e-wallet account email addresses, bank account IBAN details for SEPA transfers, and crypto wallet addresses where applicable. Incaspin Casino keeps complete transaction histories showing timestamps, amounts in EUR or cryptocurrency equivalents, processing statuses, and any intermediary payment processor references. Source of funds declarations and accompanying documents such as payslips, tax returns, or business financial statements are collected when players cross specific deposit thresholds or trigger enhanced due diligence procedures. This data is segregated in encrypted database tables with access limited to compliance personnel and senior financial officers. German players using Sofort, Giropay, or other local payment methods should be aware that the chosen payment provider will also process transaction data according to its own privacy policy, with Incaspin Casino obtaining only the information necessary to credit the player account.
2.3 Technical and Behavioral Records
As German players log into the Incaspin Casino platform, the system automatically collects technical data points including IP addresses, device types, operating system versions, browser fingerprints, screen resolutions, language settings, and mobile carrier details. Session data encompasses login timestamps, page navigation paths, game launches, bet amounts, win and loss records, and in-game feature activations. This technical corpus enables the casino to offer optimised gaming experiences, detect fraudulent activity patterns, and respect responsible gambling self-exclusion settings. Behavioural analytics monitor betting frequency, average stake sizes, session duration, and deposit velocity to feed the responsible gambling algorithms that produce personalised risk alerts. All technical logs are pseudonymised where possible and stored independently from core identity records, with re-identification possible only through a strictly regulated cryptographic lookup procedure accessible exclusively to the fraud and compliance teams under documented access justification.
3. Účely a právní základy zpracování
Incaspin Casino zpracovává osobní data na základě několika různých GDPR právních základů, vybraných according to the specific processing activity. Plnění smlouvy ve smyslu Article 6(1)(b) GDPR covers veškeré zpracování údajů potřebné pro vytvoření a správu účtu hráče, process deposits and withdrawals, a poskytování the interactive gaming services které German players aktivně vyžadují during registration. This zahrnuje transmitting payment instructions zúčtovacím bankám a ověřování that players dosahují požadavek minimálního věku osmácti let under German law. Povinné zpracování dle Article 6(1)(c) GDPR zahrnuje anti-money laundering customer due diligence, hlášení podezřelých transakcí relevantním jednotkám finančního zpravodajství, record retention to satisfy obchodně-právních a daňových požadavků, and compliance s německými herními předpisy ohledně norem ochrany hráčů. Relevantní právní rámce zahrnují zákon o praní špinavých peněz a ustanovení státní smlouvy o hazardu kde je to relevantní to data retention mandates.
Oprávněné zájmy sledované Incaspin Casino podle Article 6(1)(f) GDPR zahrnují network and information security monitoring, fraud prevention and detection, direct marketing of similar products to existing customers tam, kde je to dovoleno dle Section 7 of the German Act Against Unfair Competition, a analýzy podnikání za účelem zlepšení služeb. German players retain the absolute right odmítnout zpracování založeném na oprávněných zájmech, včetně vytváření profilů k přímým marketingovým účelům, a tyto námitky budou ctěny bez zbytečné prodlevy. Povolení under Article 6(1)(a) GDPR je využíván for optional marketing communications via email and SMS where hráč aktivně souhlasil, for the placement of non-essential cookies and tracking technologies, and for sensitive data processing za specifických okolností. Consent withdrawal mechanisms jsou výrazně umístěny v rámci nastavení účtu a v zápatí každé marketingové komunikace, with withdrawal taking effect bez zpětných důsledků for previously lawful processing. German players who have not yet reached osmácti let nesmějí otevírat účty, and any inadvertently collected minor data is deleted immediately upon discovery.
5: International Data Transfers
The main data storage infrastructure for Incaspin Casino operates from secure facilities located in the European Economic Area, specifically engineered to serve the German market with latency-optimized connectivity while maintaining full GDPR jurisdictional coverage. Some specialised processing activities may involve international data transfers to countries outside the EEA, including fraud detection services operating from certified facilities in third countries and customer support continuity arrangements during peak demand periods. For each such transfer, Incaspin Casino applies the safeguards mandated by Chapter V of the GDPR. Standard contractual clauses approved by the European Commission form the foundational transfer mechanism for processor relationships, with supplementary technical and organisational measures applied where the recipient country lacks an adequacy decision from the European Commission. German players should understand that supplementary measures include end-to-end encryption of data in transit and at rest using AES-256 standards, strict key management policies that prevent the foreign processor from accessing plaintext data, and contractual obligations requiring the processor to challenge any government access request and notify Incaspin Casino immediately when legally permitted. Transfer impact assessments are conducted prior to onboarding any non-EEA processor and are reviewed whenever the legal landscape of the recipient jurisdiction changes materially. The Data Protection Officer maintains a current register of all international transfers, which is made available to the competent German data protection authority upon request and can be summarised for data subjects who seek to grasp the geographical flow of their information.
4. Data Sharing and External Recipients
4.1 Internal Data Access Structure
Inside the Incaspin Casino operational framework, personal data access adheres to a strict least-privilege model applied across four distinct personnel tiers. Customer support agents retrieve basic account information and communication history but are unable to view full financial records or identity documents. Compliance officers have permissions to inspect verification documents, transaction patterns, and risk scores. Financial department personnel process withdrawal requests and view payment instrument details needed to execute transfers. IT security staff review system logs and security event data but do not regularly interact with player-identifiable records. Every access event is logged with a timestamp, user identifier, and purpose code, creating an immutable audit trail that is reviewed quarterly by the Data Protection Officer. German players may request a copy of the access log entries pertaining to their account by submitting a subject access request through the designated privacy channel.
4.2 External Providers and Regulatory Bodies
Incaspin Casino employs specialist external processors comprising cloud hosting providers managing ISO 27001-certified data centres inside the European Economic Area, payment processors licensed by the German Federal Financial Supervisory Authority, identity verification services that compare submitted documents against authoritative databases, email delivery platforms for transactional communications, and CRM software vendors for customer engagement analytics. Each processor undergoes a rigorous vendor assessment covering technical security measures, sub-processor transparency, international transfer safeguards, and business continuity capabilities. Contracts require data processing solely on documented instructions from Incaspin Casino, with no authority for the processor to repurpose data for its own objectives. Regulatory disclosures to German law enforcement agencies, tax authorities, or gambling regulators take place only when legally mandated, and unless prohibited by law, the casino will alert affected players of such disclosures. The following key principles govern all third-party data sharing arrangements:
- Processors get only the minimum personal data necessary to perform their specified function, with field-level data minimisation implemented to every integration.
- Sub-processor engagements require prior written approval from Incaspin Casino, and any unapproved subcontracting constitutes a material breach of the data processing agreement.
- All processors must hold ISO 27001 certification or equivalent independently audited security qualifications, with current certificates filed with Incaspin Casino before data flows start.
- No personal data is transferred to advertising technology platforms, data brokers, or any entity whose primary business focuses on monetising personal information.
9. Cookie Policy and Tracking Technologies
9.1 Essential and Functional Cookies
The Incaspin Casino website and mobile platform utilize a range of cookies and similar tracking technologies to provide core functionality. Strictly necessary cookies handle session state across page loads, maintain login authentication tokens, and maintain security context for CSRF protection. These first-party session cookies end when the browser is closed and do not require prior consent under German law implementing the ePrivacy Directive, as they are necessary for the desired service delivery. Functional cookies store language preferences, preferred currency displays, and responsible gambling limit settings across visits, making sure that returning players find a consistent personalized environment without reconfiguring their preferences. The maximum lifespan of functional cookies is 365 days, after which they are deleted automatically if the player has not accessed the platform. Incaspin Casino does not use flash cookies, supercookies, or any regenerating techniques that circumvent browser deletion actions.
9.2 Metrics and Marketing Cookies
Analytics and marketing cookies are set only after German players grant explicit, freely given consent through the cookie consent management platform displayed on first visit. The consent tool presents clear descriptions of each cookie category, the specific providers participating, the purposes of data collection, and the retention duration for each cookie type. Players may allow or deny consent for each category independently, and consent preferences are logged as documentary evidence in an encrypted consent log with timestamp and IP address. Analytics cookies from a privacy-focused measurement service track aggregated page interaction metrics without cross-site tracking or user-level profiling. Marketing cookies enable campaign attribution and frequency capping for promotional banners displayed within the logged-in casino environment. German players may adjust their consent choices at any time by visiting the cookie settings panel located in the website footer. Rejecting analytics or marketing cookies does not influence gameplay functionality or account standing in any manner. The consent tool solicits players annually to reconfirm or update their preferences.
Conclusion
Incaspin Casino has arranged its data protection structure to satisfy the high standards expected by German players and mandated by the GDPR and the BDSG-neu. From the preliminary collection of identity and contact information through to the ultimate deletion or anonymisation of records years after account closure, every personal data life cycle stage works under recorded policies, contractual safeguards, and technical controls that are regularly audited and improved. The casino preserves transparent communication channels for rights requests, provides granular cookie consent options, and limits data sharing to vetted processors and legally mandated disclosures. German players are encouraged to read this Privacy Notice alongside the general Terms and Conditions and the Responsible Gambling Policy available on the Incaspin Casino website, and to contact the Data Protection Officer with any questions about how their personal information is handled.


