Slotoro Casino treats the protection and privacy of your personal data as a main focus. This Data Protection Policy explains, in plain language, how we gather, handle, store, and protect the data of members, with a concentration on those using our platform from Bulgaria. The policy adheres to international data protection norms, including the General Data Protection Regulation (GDPR). Every step we take is intended to give you a secure gaming experience while ensuring you in charge of your personal details. Slotoro Casino functions as a data controller, which means we determine why and how your data is handled. This policy covers all interactions with the Slotoro website, mobile apps, customer support lines, and any affiliated services. Transparency counts to us, so we urge every player to review this document before using the platform.
1. Scope and Purpose of the Data Protection Policy
Slotoro Casino’s data protection framework includes every point where we obtain personal information from registered users and visitors. This comprises account registration forms, identity verification submissions, payment processing interfaces, live chat transcripts, emails, and automated logs of technical parameters during browsing sessions. We collect personal data primarily to offer a fully functional, legally compliant, and personalized gaming experience. Without certain mandatory information, we cannot possibly establish a contractual relationship, process payments, or meet anti-money laundering requirements. We also employ aggregated and anonymized data for statistical analysis, platform improvements, and to strengthen responsible gambling tools. The framework also extends to data shared with carefully selected third-party providers who perform essential tasks like payment processing, game hosting, and customer relationship management. Each provider is bound by contracts that match the protections in this policy, so the same standard of care follows the data throughout its entire life.
6. Data Storage and Deletion Practices
We keep personal data for as long as necessary to accomplish the objectives it was collected for, or to meet statutory record-keeping regulations set by gaming regulators and tax authorities. Account information is maintained for the entire customer relationship, then is preserved for five years after account closure. That five-year period aligns with anti-money laundering directives and the time limit for potential legal claims. Financial transaction records are held a minimum of seven years for tax reporting. Identity verification documents are securely deleted once the verification outcome is logged, unless a law or a specific investigation requires us to keep them longer. Technical logs and security monitoring data are cycled on a rolling basis, normally retained for twelve months before automatic deletion. We use automated data lifecycle tools that identify records nearing their retention limit and then activate secure erasure. If we respect a deletion request under the right to erasure, we delete all personal data except for what we must keep for valid reasons, such as addressing legal claims or complying with a binding regulatory order.
2. Types of Personal Information Gathered
We collect several different categories of personal data, each for a particular reason. Identity information forms the core of your player profile: full legal name, date of birth, residential address, nationality, and a government-issued ID number. Contact information includes the email address and phone number you supply when registering, utilized for account notifications and security alerts. Payment details covers payment method details, transaction histories, deposit and withdrawal amounts, and partial card numbers (retained for fraud prevention). Technical data is automatically collected via cookies and similar tools, capturing IP addresses, device fingerprints, browser types, operating system versions, and session duration. Verification information includes documents provided for Know Your Customer checks, such as passport scans, utility bills, and proof of payment ownership. Lastly, activity data includes gaming preferences, betting patterns, bonus usage, and self-imposed limit settings. We gather each category only where a lawful basis exists, and retention periods are matched to the particular purpose for which the data was first obtained.
3. Legal Bases for Processing Player Information
We handle your personal data only when we have a proper legal reason to do so. The six lawful bases we rely on are those specified in data protection law. First, processing often happens because it’s necessary to fulfill our contract with you: handling your registration details, facilitating deposits and withdrawals, and delivering the gaming services you signed up for. Second, we handle some data to comply with legal obligations, including identity verification, anti-money laundering screening, and reporting suspicious transactions to authorities. Third, we base legitimate interests for things like network security monitoring, fraud detection, internal analytics, and direct marketing of similar products to existing customers, always after confirming your rights don’t surpass our interests. Consent is another basis, which we seek explicitly when you consent to non-essential cookies, promotional newsletters, or certain marketing campaigns. You can revoke consent at any time, but it won’t change the lawfulness of processing that occurred before. In very rare cases, processing might be required to secure someone’s vital interests or to execute a task in the public interest. We document the lawful basis for each processing activity and can provide that information if you ask.
7. Player Rights Pursuant to Data Protection Law
Bulgarian players have a complete range of rights pursuant to the GDPR, and we’ve set up internal processes to handle each one inside the one-month deadline. The right of access enables you to request whether we handle your data and get a copy of it accompanied by information about why and to whom we share it. The right to rectification means you can amend inaccurate or incomplete personal data, frequently through your account dashboard or by contacting support. The right to erasure (right to be forgotten) is applicable when, for example, your data is no longer needed or you revoke consent. You can exercise the right to restrict processing while a dispute about accuracy or lawfulness is under resolution. Data portability enables you to get your data in a structured, machine-readable format and move it to another controller. The right to object covers processing based on legitimate interests, such as profiling for direct marketing. And we won’t make decisions that have legal effects on you based solely on automated processing without human involvement. We never charge fee for exercising these rights save when a request is evidently unfounded or excessive.
4. Information Disclosure and Third-Party Notifications
We partner with a set of vetted third-party service providers to manage the platform in a secure manner, and data sharing is limited to what each partner requires to fulfill their role. Payment processors get only the transaction details required to process deposits and withdrawals; they function under Payment Card Industry Data Security Standard (PCI DSS) certifications. Game providers receive a unique player identifier and balance information, never your full personal profile. Identity verification agencies obtain the documents you submit for KYC checks and send back verification results through encrypted channels. Cloud hosting providers store data on infrastructure with enterprise-grade security controls, in server locations selected to maintain adequate protection. Marketing platforms process email addresses and engagement metrics only to send campaigns and evaluate performance. We also reveal personal data to regulators, law enforcement, and financial intelligence units when the law mandates it. Apart from these situations, we never sell your data to external parties. Every third-party relationship is governed by a written data processing agreement that spells out what data is used, for how long, and for what purpose, with strict confidentiality obligations.
5. International Data Movements and Safeguards
As Slotoro Casino is available internationally, we could move your personal data to servers and service providers located outside your country of residence. When transfers occur from the European Economic Area to third countries, we place safeguards in place so that GDPR protection levels aren’t weakened. Standard Contractual Clauses endorsed by the European Commission are the main mechanism we use; they bind recipients to the same data protection duties. We also review the legal system of the destination country, examining things like government surveillance laws and if you’d have a way to pursue redress. If a service provider is certified under an approved framework or functions in a country with an adequacy decision, we verify that before any transfer begins. Bulgarian players can request the Data Protection Officer for a copy of the relevant safeguard documents. We stay accountable for your data even after it’s transferred, and we carry out regular audits and mandate any service provider to tell us immediately about any security incident impacting that data.
8. Protection Protocols Safeguarding Player Data
We utilize multiple levels of protection to secure your personal data from unapproved intrusion, change, revelation, or damage. Encryption is the first line: Transport Layer Security (TLS) secures data in transit between your system and our servers, and Advanced Encryption Standard (AES) safeguards data at standstill in our repositories. Access controls are strict: role-based authorizations, multi-factor verification for admin profiles, and the principle of least authority, implying staff can solely access the data they definitely need for their role. Our network defense includes next-generation security barriers, intrusion identification and blocking systems, and round-the-clock data flow surveillance by a committed Security Operations Center. We maintain our systems safe through regular code audits, vulnerability scanning, and penetration evaluations by third-party cybersecurity firms. Data facilities have biometric access controls, 24/7 surveillance, and duplicate power and environmental systems. We also have a comprehensive incident management strategy that addresses immediate isolation, removal, and restoration, plus a breach reporting procedure that assures supervisory bodies and involved users are notified within 72 hrs of us learning about a applicable personal data incident.
The 9th Affiliate Programme Data Handling Standards
Our affiliate programme adheres to the same strict data protection protocols as the main gaming platform. Affiliates who register provide us with business contact data, payment information for commission payouts, and marketing performance data generated through tracking links and unique identifiers. We process this data based on contract performance and legitimate grounds (monitoring campaign effectiveness and preventing fraud). Tracking technologies on affiliate landing pages collect referral source details, click records, and conversion actions; we pseudonymize this data wherever possible. Affiliates are contractually expected to have their own compliant privacy statements and to secure valid consent from users before tracking starts, in line with ePrivacy rules. Commission payment data is stored for the life of the affiliate relationship and then for the legally required fiscal duration. Affiliates have the same data subject entitlements as users, including viewing to their stored information and the ability to make corrections. We run periodic compliance checks on affiliate partners to make sure their data handling aligns with this framework, and we can end partnerships if we find breaches.
Frequently Asked Questions
What personal data does Slotoro Casino require to create an account?
For account setup, we require your full legal name, date of birth, home address, email address, and a username and password of your choice. Upon making a deposit, we will also request your phone number and payment method information. Subsequently, we will request identity bbc.co.uk verification documents to comply with regulatory standards.
What is the process for a player to request removal of their personal data?
You may request deletion by contacting our Data Protection Officer via email at the address specified in the site’s privacy area https://slotoro.bg/legal-and-affiliates/. Inform us of your identity and the specific data you wish to have removed. We’ll review your request against the legal requirements and reply within 30 calendar days.
Does Slotoro Casino disclose data to other gaming companies?
No, we don’t share your personal data with other gaming operators for marketing or cross-promotions. We may share data with regulators and law enforcement if the law demands it, and with service providers who help run our platform—under strict contracts.
What is the retention period for identity verification documents?
Your ID documents are kept only as long as required to complete verification and satisfy anti-money laundering requirements. Usually, they’re securely archived for five years after the last transaction on your account, then permanently deleted with certified erasure methods.
How is financial transaction data safeguarded?
Financial data is protected with end-to-end encryption, tokenization of card details, and compliance with PCI DSS. Payment processing runs on isolated networks, and only a small, background-checked team with confidentiality agreements can access financial records.
May a player challenge the use of their data for marketing?
Of course. Every marketing message we send has an unsubscribe link that lets you opt out immediately. You can also adjust your preferences in your account settings or contact customer support to refuse direct marketing.
What happens when Slotoro Casino handle data breaches?
We have a formal breach response plan: immediate containment, forensic investigation, and notification to bg.wikipedia.org the supervisory authority within 72 hours of discovery. If a breach puts your rights and freedoms at high risk, we’ll tell you without delay and give you clear steps to protect yourself.
Which is the lawful basis for processing affiliate data?
We process affiliate data mainly because it’s needed to perform the contract: manage the relationship, track referrals, and pay commissions. We also rely on legitimate interest for fraud prevention and programme analytics, always balanced against what affiliates reasonably expect.

