This Privacy Notice explains how cookie richtlinie Incaspin Casino collects, processes, stores, and secures personal data belonging to players located in Germany. The document operates within the scope of the European Union’s General Data Protection Regulation (GDPR) and the German Federal Data Protection Act (Bundesdatenschutzgesetz, BDSG-neu). Incaspin Casino acts as the data controller for personal information furnished through its website, mobile applications, and related services. German players possess specific statutory rights relating to their data, and this notice outlines the lawful bases for processing, data retention periods, third-party sharing protocols, and the technical safeguards deployed to prevent unauthorised access. The document also explains the responsibilities of the Data Protection Officer and the supervisory authority contact procedures. Every section has been drafted to ensure transparency and compliance with Article 13 and Article 14 of the GDPR, offering German users with a complete overview of how their casino account data, payment details, identification documents, and behavioural analytics are managed throughout the entire customer lifecycle.
První bod: Identita správce údajů a podrobnosti o kontaktu

Osobou odpovědnou za zpracování údajů pro všechny osobní údaje zpracovávané prostřednictvím the Incaspin Casino webové stránky is právnická osoba působící pod obchodní značkou Incaspin Casino, zapsaná v jurisdikci recognised for its adherence to EU data protection equivalence standards. The registered office address a identifikační číslo společnosti are available upon žádost s ověřením totožnosti e-mailem na adresu pracovníkovi pro ochranu osobních údajů, nebo nahlédnutím do části s právními informacemi webové prezentace. Hráči z Německa mohou směřovat veškeré dotazy ohledně ochrany soukromí k určenému pověřenci pro ochranu osobních údajů, who operates independently a je přímo podřízen senior management. The DPO je k zastižení via speciální šifrovanou e-mailovou adresu zveřejněnou v rámci úplného znění zásad ochrany soukromí. Incaspin Casino má právního zástupce within the European Union z důvodu Article 27 GDPR, aby bylo zaručeno, že German supervisory authorities i dotčené osoby mají přímé kontaktní místo for regulatory matters. Tento subjekt determines the purposes and means zpracování všech osobních údajů získaných při registraci účtu, Know Your Customer verification, platebních transakcích vkladů a výběrů, and ongoing gameplay activity. To zahrnuje informace generované pomocí souborů cookies, technologií pro identifikaci zařízení, a záznamů serveru. Hráči z Německa by si měli uvědomit, že tento subjekt uplatňuje absolutní moc nad rozhodováním nad operacemi zpracování údajů while commissioning důkladně vybrané zpracovatele for specific technical services např. hosting, platební brány, and CRM platforms. Each processor relationship se řídí a binding data processing agreement jež vyhovuje podmínkám článku 28 GDPR, s možností provádět povinné audity ze strany Incaspin Casino pro ověření průběžného souladu. The contact details na zástupce pro Evropskou unii byly sděleny kompetentnímu německému dozorovému orgánu pro ochranu dat v souladu s právními předpisy.
Two Groups of Individual Data Obtained
Two Point One Identity Verification and Player Data
German players must provide particular personal data to establish and keep an active Incaspin Casino account. This category contains entire legal name, home address, date of birth, birthplace, citizenship, and gender. For identification verification purposes mandatory under German anti-money laundering regulations, the casino gathers government-issued identity files such as passport copies, national identity card scans, and residence permit documentation. The program also logs the document number, issuing body, expiry date, and a biometrical comparison result produced during the automated verification process. Home validation is done through recent utility bills, bank statements, or authorized communication that evidently shows the player’s full name, registered location, and an issuing date inside the previous three months. Incaspin Casino uses these verification prerequisites uniformly to conform with the Fourth and Fifth Anti-Money Laundering Orders as implemented into Germany’s law, ensuring that all account fulfills the regulatory identity confidence level ahead of any withdrawals are permitted.
Two Point Two Financial and Payment Data

Financial data encompasses all deposit and withdrawal records, including payment instrument data, masked card numbers, e-wallet account email addresses, bank account IBAN numbers for SEPA transfers, and cryptocurrency wallet addresses where applicable. Incaspin Casino stores complete transaction histories showing timestamps, amounts in EUR or digital currency equivalents, processing statuses, and any intermediary payment processor references. Source of funds declarations and accompanying documents such as payslips, tax returns, or business financial statements are collected when players cross specific deposit thresholds or trigger enhanced due diligence procedures. This data is isolated in encrypted database tables with access restricted to compliance personnel and senior financial officers. German players using Sofort, Giropay, or other local payment methods should be aware that the chosen payment provider will also process transaction data according to its own privacy policy, with Incaspin Casino obtaining only the information necessary to credit the player account.
2.3 Technical and Behavioural Data
When German players log into the Incaspin Casino platform, the system automatically collects technical data points including IP addresses, device types, operating system versions, browser fingerprints, screen resolutions, language settings, and mobile carrier details. Session data includes login timestamps, page navigation paths, game launches, bet amounts, win and loss records, and in-game feature activations. This technical corpus allows the casino to provide optimised gaming experiences, identify fraudulent activity patterns, and uphold responsible gambling self-exclusion settings. Behavioural analytics monitor betting frequency, average stake sizes, session duration, and deposit velocity to feed the responsible gambling algorithms that generate personalised risk alerts. All technical logs are de-identified where possible and stored separately from core identity records, with re-identification possible only through a strictly regulated cryptographic lookup procedure accessible exclusively to the fraud and compliance teams under documented access justification.
5: International Data Transfers
The primary data storage infrastructure for Incaspin Casino resides within secure facilities located in the European Economic Area, specifically configured to serve the German market with latency-optimized connectivity while maintaining full GDPR jurisdictional coverage. Certain specialised processing activities may involve international data transfers beyond the EEA, including fraud detection services operating from certified facilities in third countries and customer support continuity arrangements during peak demand periods. For every such transfer, Incaspin Casino implements the safeguards mandated by Chapter V of the GDPR. Standard contractual clauses approved by the European Commission form the foundational transfer mechanism for processor relationships, with supplementary technical and organisational measures utilised where the recipient country lacks an adequacy decision from the European Commission. German players should understand that supplementary measures include complete encryption of data in transit and at rest using AES-256 standards, strict key management policies that prevent the foreign processor from accessing plaintext data, and contractual obligations requiring the processor to challenge any government access request and notify Incaspin Casino immediately when legally permitted. Transfer impact assessments are conducted prior to onboarding any non-EEA processor and are reviewed whenever the legal landscape of the recipient jurisdiction changes materially. The Data Protection Officer maintains a current register of all international transfers, which is made available to the competent German data protection authority upon request and can be summarised for data subjects who want to know the geographical flow of their information.
7. Security of Data Safeguards
Incaspin Casino deploys a tiered security architecture in accordance with the ISO 27001 control framework and the technical requirements specified in Article 32 of the GDPR. Network-level protections include enterprise-grade firewalls equipped with stateful packet inspection, intrusion detection and prevention systems that monitor traffic patterns for indicators of compromise, and distributed denial-of-service mitigation services that neutralize volumetric attacks before they arrive at the application layer. All data transferred between German player devices and casino servers is encrypted using Transport Layer Security version 1.3 with forward secrecy enabled, preventing retrospective decryption of captured traffic even if long-term private keys are later compromised. Internal administrative interfaces are isolated on a management network inaccessible from the public internet, with access permitted exclusively through multi-factor authenticated VPN tunnels coming from pre-registered static IP addresses owned by authorised personnel. At the application layer, the platform mandates strong password policies demanding minimum character lengths and complexity standards, with passwords hashed using bcrypt with per-user salts before storage. Account access anomalies activate step-up authentication challenges or temporary account locks awaiting manual review by the security team. Database-level encryption secures data at rest, with separate encryption keys for personal data columns, financial fields, and identity document stores, each controlled through a hardware security module that logs every key access operation. Regular vulnerability scanning and annual penetration testing by an independent CREST-accredited security firm confirm the effectiveness of these controls, with critical findings remediated within 48 hours. Security incident response procedures are tested through bi-annual tabletop exercises involving the Data Protection Officer, with a documented breach notification workflow ensuring German players and the supervisory authority receive notification within the 72-hour deadline stipulated by GDPR.
4. Data Sharing and Third-Party Recipients
4.1 In-House Data Access Model
In the Incaspin Casino operational system, personal data access utilizes a strict least-privilege model applied across four distinct personnel tiers. Customer support agents access basic account information and communication history but cannot view full financial records or identity documents. Compliance officers possess permissions to examine verification documents, transaction patterns, and risk scores. Financial department personnel manage withdrawal requests and view payment instrument details needed to execute transfers. IT security staff monitor system logs and security event data but do not regularly interact with player-identifiable records. Every access event is tracked with a timestamp, user identifier, and purpose code, creating an immutable audit trail that is reviewed quarterly by the Data Protection Officer. German players may request a copy of the access log entries pertaining to their orf.at account by submitting a subject access request through the designated privacy channel.
4.2 External Providers and Regulatory Bodies
Incaspin Casino engages specialist external processors including cloud hosting providers operating ISO 27001-certified data centres within the European Economic Area, payment processors licensed by the German Federal Financial Supervisory Authority, identity verification services that check submitted documents against authoritative databases, email delivery platforms for transactional communications, and CRM software vendors for customer engagement analytics. Each processor undergoes a rigorous vendor assessment addressing technical security measures, sub-processor transparency, international transfer safeguards, and business continuity capabilities. Contracts require data processing solely on documented instructions from Incaspin Casino, with no authority for the processor to repurpose data for its own objectives. Regulatory disclosures to German law enforcement agencies, tax authorities, or gambling regulators occur only when legally mandated, and unless prohibited by law, the casino will alert affected players of such disclosures. The following key principles regulate all third-party data sharing arrangements:
- Processors get only the minimum personal data necessary to perform their contracted function, with field-level data minimisation implemented to every integration.
- Sub-processor engagements require prior written approval from Incaspin Casino, and any unlicensed subcontracting constitutes a material breach of the data processing agreement.
- All processors must hold ISO 27001 certification or comparable independently audited security standards, with current records filed with Incaspin Casino before data flows start.
- No personal data is sold to advertising technology platforms, data brokers, or any entity whose primary business focuses on monetising personal information.
Six. Data Archiving and Removal Guidelines
Incaspin Casino runs a precise data retention policy designed to meet statutory record-keeping obligations while reducing the storage of personal data past its necessary purpose. Player account data and entire transaction records are retained for the full length of the active business relationship, defined as the period from account creation up to the account is terminated, plus an extra statutory retention duration mandated by German anti-money laundering legislation and commercial law. Under the Geldwäschegesetz, identification files, transaction vouchers, and due diligence materials must be kept for at least five years after the end of the calendar year in which the business relationship ended. mehr Informationen erhalten Accounting records pertinent to tax duties are retained for ten years in conformity with the German Fiscal Code. Following the end of these mandatory intervals, personal data is either irrevocably anonymised so that re-identification becomes impossible with all ways reasonably expected to be applied, or securely removed through cryptographic erasure and physical storage media cleaning methods. Technical logs and security event data follow a reduced retention period of twelve months, after which they are combined into anonymised statistical summaries. Inactive accounts showing no login activity for a consecutive period of 24 months are designated for dormancy assessment, and the associated personal data is limited to keep only the core name and transaction records required for the leftover statutory retention timeline. The casino deploys automated data lifecycle management processes that operate weekly to find records past their retention thresholds, initiating deletion procedures without human input, with the results recorded for compliance audit reasons.
3. bod Účely a právní základy zpracování
Incaspin Casino processes osobních údajů na základě několika různých GDPR právních důvodů, zvolených according to dané činnosti zpracování. The performance of a contract pursuant to Article 6(1)(b) GDPR covers all data processing potřebné to create and manage the player account, zpracování vkladů a výběrů, a poskytování služeb interaktivního hraní jež German players aktivně požadují při registraci. This includes zasílání platebních pokynů zúčtovacím bankám a kontrolu that players meet požadavek minimálního věku 18 let dle německé legislativy. Zpracování na základě právní povinnosti podle Article 6(1)(c) GDPR encompasses anti-money laundering customer due diligence, oznamování podezřelých obchodů příslušným finančním zpravodajským jednotkám, retence záznamů pro splnění obchodně-právních a daňových požadavků, a soulad s německými herními předpisy concerning player protection standards. The applicable legal frameworks obsahují the Geldwäschegesetz a ustanovení státní smlouvy o hazardu pokud je to relevantní to data retention mandates.
Legitimní zájmy pursued by Incaspin Casino dle Article 6(1)(f) GDPR obsahují network and information security monitoring, fraud prevention and detection, direct marketing of similar products to existing customers pokud je to povoleno podle Section 7 of the German Act Against Unfair Competition, and business analytics for service improvement. German players mají absolutní právo vznášet námitky proti zpracování na základě oprávněných zájmů, včetně profilování pro účely přímého marketingu, a tyto námitky will be honoured without undue delay. Consent dle Article 6(1)(a) GDPR je spoléháno for optional marketing communications e-mailem a SMS where hráč se aktivně přihlásil, pro nasazení neesenciálních cookies a sledovacích technologií, a pro zpracování citlivých údajů v konkrétních případech. Mechanismy pro odvolání souhlasu are prominently placed v rámci nastavení účtu a v zápatí každé marketingové komunikace, with withdrawal taking effect bez retroaktivních následků pro dříve legální zpracování. German players kteří ještě nedosáhli osmácti let nesmějí otevírat účty, a jakákoli neúmyslně shromážděná data nezletilých jsou okamžitě po zjištění smazána.
8. Rights of German-resident Data Subjects
German players hold the entire range of data subject rights specified in Articles 15 through 21 of the GDPR, as well as the right to submit a appeal with a supervisory authority. The right to access enables players to receive confirmation of if Incaspin Casino processes their private data and to obtain a version of that data including details about processing purposes, classes, addressees, holding periods, and the presence of automated decision-making. Access requests are fulfilled within one month, free of charge for the initial request, with the answer delivered in a structured, generally used, machine-readable layout. The right to rectification allows players to rectify incorrect personal data or complete missing files, a particularly relevant right for identity document updates following name alterations or address moves. Incaspin Casino handles rectification inquiries within ten business days and verifies amendments to any third-party addressees to whom the incorrect data was disclosed. The erasure right holds true where the personal data is no more necessary for the aims for which it was gathered, where consent is withdrawn, where the player objects to processing and no overriding legitimate grounds exist, or where processing is unlawful. However, statutory retention duties take precedence over erasure applications, and data necessary for legal compliance will be restricted from further processing rather than erased until the retention period ends. The right to restriction of processing serves as an alternative where the accuracy of data is disputed, processing is illegal but the player is against deletion, or the player needs the data for legal assertions despite the controller no longer needing it. Data portability rights under Article 20 GDPR apply solely to data furnished by the player and processed by automated methods based on permission or agreement, signifying gameplay history and transaction logs qualify for portability while fraud detection assessments coming from internal models do not. Rights inquiries should be sent to the Data Protection Officer email address, with valid proof of identity required before any data is shared.
9. Cookie Policy and Tracking Technologies
9.1 Core and Functional Cookies
The Incaspin Casino platform and mobile platform implement a variety of cookies and similar tracking technologies to ensure core functionality. Strictly necessary cookies handle session state across page loads, preserve login authentication tokens, and preserve security context for CSRF protection. These first-party session cookies expire when the browser is closed and do not require prior consent under German law transposing the ePrivacy Directive, as they are necessary for the required service delivery. Functional cookies keep language preferences, preferred currency displays, and responsible gambling limit settings across visits, guaranteeing that returning players find a consistent personalised environment without reconfiguring their preferences. The maximum lifespan of functional cookies is 365 days, after which they expire automatically if the player has not accessed the platform. Incaspin Casino does not use flash cookies, supercookies, or any regenerating techniques that evade browser deletion actions.
9.2 Analytics and Marketing Cookies
Analytics and marketing cookies are set only after German players give explicit, freely given consent through the cookie consent management platform shown on first visit. The consent tool offers clear descriptions of each cookie category, the specific providers engaged, the purposes of data collection, and the retention duration for each cookie type. Players may allow or withhold consent for each category independently, and consent preferences are stored as documentary evidence in an encrypted consent log with timestamp and IP address. Analytics cookies from a privacy-focused measurement service monitor aggregated page interaction metrics without cross-site tracking or user-level profiling. Marketing cookies enable campaign attribution and frequency capping for promotional banners shown within the logged-in casino environment. German players may modify their consent choices at any time by using the cookie settings panel referenced in the website footer. Refusing analytics or marketing cookies does not influence gameplay functionality or account standing in any manner. The consent tool solicits players annually to update or update their preferences.
Conclusion
Incaspin Casino has structured its data protection structure to meet the high standards expected by German players and mandated by the GDPR and the BDSG-neu. From the preliminary collection of identity and contact details through to the final deletion or anonymisation of records years after account closure, every personal data life cycle stage operates under recorded policies, contractual safeguards, and technical controls that are regularly audited and improved. The casino preserves transparent communication channels for rights requests, provides granular cookie consent options, and limits data sharing to vetted processors and legally mandated disclosures. German players are encouraged to read this Privacy Notice alongside the general Terms and Conditions and the Responsible Gambling Policy available on the Incaspin Casino website, and to contact the Data Protection Officer with any questions about how their personal information is handled.
