Privacy Policy

Version: 1.0  |  Last Updated: 31 August 2026

This Privacy Policy (“Policy”) describes how Fortunica, operating at casinofortunicaonline.uk (“we”, “us”, “our”), collects, uses, stores, and shares personal data relating to users of our Platform. This Policy should be read alongside our Terms & Conditions and our Responsible Gaming Policy.

We are committed to protecting your personal data and processing it in accordance with the UK General Data Protection Regulation (UK GDPR), the Data Protection Act 2018, and all other applicable data protection legislation.

1. Introduction

1.1 Who We Are

Fortunica operates the online casino platform accessible at casinofortunicaonline.uk. For all privacy-related enquiries, you can contact our Data Protection Officer (DPO) at [email protected].

1.2 Scope

This Policy applies to all personal data collected through your use of the Website, including data collected when you register an account, make deposits or withdrawals, participate in games or promotions, contact our support team, or browse our Website. It applies to all current, former, and prospective players.

1.3 Your Consent

Where we rely on consent as a legal basis for processing, you have the right to withdraw that consent at any time. Withdrawal of consent does not affect the lawfulness of any processing carried out before its withdrawal. Where consent is withdrawn, some features or services may no longer be available to you.

2. Data We Collect

2.1 Data You Provide Directly

When you register an account or interact with our services, we collect the following categories of personal data:

  • Identity Data: Full legal name, date of birth, gender, and nationality;
  • Contact Data: Email address, telephone number, and postal address;
  • Verification Data: Copies of identity documents (passport, driving licence, national ID card), proof of address, and source of funds documentation submitted during KYC;
  • Financial Data: Payment method details (card last four digits, e-wallet identifiers), transaction history, deposit and withdrawal records;
  • Account Data: Username, password (stored in encrypted form), account preferences, and communication preferences;
  • Responsible Gaming Data: Self-imposed limits, cooling-off periods, and self-exclusion records.

2.2 Data Collected Automatically

When you access and use our Platform, we automatically collect:

  • Technical Data: IP address, browser type and version, operating system, device type and identifiers;
  • Usage Data: Pages visited, games played, session duration, betting history, clicks and navigation patterns;
  • Log Data: Server logs, error reports, and access timestamps;
  • Cookie Data: Information collected through cookies and similar tracking technologies (see Section 6).

2.3 Data from Third Parties

We may receive personal data about you from:

  • Identity verification and KYC service providers;
  • Fraud prevention and anti-money laundering (AML) databases;
  • Payment processors and financial institutions;
  • Self-exclusion scheme operators (e.g., GAMSTOP);
  • Publicly available sources, such as electoral rolls and credit reference agencies.

3. How We Use Your Data

3.1 Primary Purposes

We use your personal data for the following primary purposes:

  • Account Management: Creating, verifying, and maintaining your player account;
  • Service Delivery: Enabling you to access games, make deposits and withdrawals, and participate in promotions;
  • Identity & Age Verification (KYC): Verifying that you are who you claim to be and that you meet the minimum age requirement of 18 years;
  • Transaction Processing: Processing deposits, withdrawals, and refunds;
  • Customer Support: Responding to enquiries, complaints, and support requests;
  • Responsible Gaming: Monitoring player behaviour for signs of problem gambling and administering protective tools and limits;
  • Legal & Regulatory Compliance: Meeting our obligations under anti-money laundering legislation, responsible gambling regulations, and other applicable laws.

3.2 Secondary Purposes

  • Marketing: Sending you personalised offers, promotions, and newsletters where you have given consent or where we have a legitimate interest and you have not opted out;
  • Platform Improvement: Analysing usage data to improve the Platform, fix bugs, and enhance the user experience;
  • Fraud Prevention: Detecting, investigating, and preventing fraudulent activity, cheating, and financial crime;
  • Security: Protecting the integrity of our Platform and the safety of our players.

3.3 Marketing Communications

We may send you marketing communications by email, SMS, or push notification where you have opted in to receive them or where we have a legitimate interest to do so. You may unsubscribe from marketing communications at any time by clicking the “unsubscribe” link in any email, adjusting your Account preferences, or contacting us at [email protected].

4. Legal Bases for Processing

We process your personal data on the following legal bases under UK GDPR:

Processing Purpose Legal Basis
Account registration & service deliveryPerformance of a contract (Art. 6(1)(b))
KYC / identity & age verificationLegal obligation (Art. 6(1)(c))
AML / fraud preventionLegal obligation & legitimate interests (Art. 6(1)(c) & (f))
Responsible gaming monitoringLegal obligation & legitimate interests (Art. 6(1)(c) & (f))
Payment processingPerformance of a contract (Art. 6(1)(b))
Marketing communicationsConsent or legitimate interests (Art. 6(1)(a) & (f))
Platform analytics & improvementLegitimate interests (Art. 6(1)(f))
Legal claims & regulatory obligationsLegal obligation (Art. 6(1)(c))

5. Data Sharing & Third Parties

5.1 Categories of Recipients

We may share your personal data with the following categories of third parties:

  • KYC & Identity Verification Providers: To verify your identity and age in compliance with legal requirements;
  • Payment Service Providers: To process deposits, withdrawals, and refunds securely;
  • Game Software Providers: Who may process limited technical data in the delivery of game content;
  • Fraud & AML Service Providers: To prevent money laundering, fraud, and other financial crime;
  • Self-Exclusion Databases: Including GAMSTOP, to fulfil self-exclusion obligations;
  • Customer Support Platforms: To manage and respond to player enquiries;
  • Marketing Technology Providers: Where you have consented to receive marketing communications;
  • Regulatory & Law Enforcement Authorities: Where required by law, court order, or regulatory obligation;
  • Professional Advisers: Including lawyers, auditors, and insurers, under obligations of confidentiality.

5.2 No Sale of Personal Data

We do not sell, rent, or trade your personal data to third parties for their own marketing purposes.

5.3 Third-Party Data Processors

All third-party service providers who process personal data on our behalf are required to do so under a written data processing agreement ensuring that your data is handled with the same level of protection as we apply.

6. Cookies & Tracking Technologies

6.1 What Are Cookies?

Cookies are small text files placed on your device when you visit a website. They allow the website to recognise your device on subsequent visits and to collect information about your browsing behaviour.

6.2 Types of Cookies We Use

Cookie Type Purpose
Strictly NecessaryEssential for the operation of the Website (e.g., session management, login authentication). Cannot be disabled.
FunctionalRemember your preferences and settings (e.g., language, currency) to improve your experience.
AnalyticsCollect aggregated data on how users interact with the Website to help us improve performance.
MarketingTrack your browsing behaviour to deliver personalised advertisements. Only used with your consent.

6.3 Managing Cookies

You can manage your cookie preferences through our cookie consent banner when you first visit the Website. You may also adjust cookie settings in your browser at any time. Please note that disabling certain cookies may impair the functionality of the Website.

7. Data Security

7.1 Security Measures

We implement appropriate technical and organisational measures to protect your personal data against unauthorised access, loss, destruction, or disclosure. These measures include:

  • SSL/TLS encryption for all data transmitted between your device and our servers;
  • Encryption of sensitive data at rest (including passwords, using industry-standard hashing);
  • Access controls restricting access to personal data to authorised personnel only;
  • Regular security assessments and penetration testing;
  • Incident response procedures to address data breaches promptly.

7.2 Data Breach Notification

In the event of a personal data breach that poses a risk to your rights and freedoms, we will notify the UK Information Commissioner’s Office (ICO) within 72 hours of becoming aware of the breach, and will notify you directly where the breach is likely to result in a high risk to your rights, in accordance with our obligations under UK GDPR.

8. Data Retention

8.1 Retention Periods

We retain your personal data for as long as necessary to fulfil the purposes for which it was collected, subject to our legal and regulatory obligations. Indicative retention periods are as follows:

  • Account data & transaction records: Retained for a minimum of 5 years following account closure, in accordance with anti-money laundering legislation;
  • KYC documentation: Retained for a minimum of 5 years following the end of the customer relationship;
  • Marketing data: Retained until you withdraw consent or opt out;
  • Support correspondence: Retained for 3 years from the date of the last communication;
  • Technical & log data: Retained for up to 12 months from the date of collection.

8.2 Deletion

Upon expiry of the applicable retention period, personal data will be securely deleted or anonymised in accordance with our internal data disposal procedures.

9. Your Rights

9.1 Rights Under UK GDPR

As a data subject under UK GDPR, you have the following rights:

  • Right of Access: You may request a copy of the personal data we hold about you (a “Subject Access Request”);
  • Right to Rectification: You may request correction of inaccurate or incomplete personal data;
  • Right to Erasure (“Right to be Forgotten”): You may request deletion of your personal data, subject to legal retention obligations;
  • Right to Restrict Processing: You may request that we limit the processing of your data in certain circumstances;
  • Right to Data Portability: You may request a structured, machine-readable copy of data you have provided to us, where processing is based on consent or contract;
  • Right to Object: You may object to processing based on legitimate interests or for direct marketing purposes;
  • Rights Related to Automated Decision-Making: You have the right not to be subject to solely automated decisions that produce legal or similarly significant effects, without human review.

9.2 How to Exercise Your Rights

To exercise any of the above rights, please contact our Data Protection Officer at [email protected]. We will respond to your request within one (1) calendar month. We may need to verify your identity before processing your request.

9.3 Right to Complain

If you are dissatisfied with how we handle your personal data, you have the right to lodge a complaint with the UK Information Commissioner’s Office (ICO) at ico.org.uk or by calling 0303 123 1113.

10. International Data Transfers

10.1 Transfers Outside the UK

In the course of providing our services, your personal data may be transferred to, stored in, or processed in countries outside the United Kingdom. Where such transfers occur, we ensure that appropriate safeguards are in place, such as:

  • Transfers to countries recognised by the UK government as providing an adequate level of data protection;
  • Use of UK International Data Transfer Agreements (IDTAs) or equivalent approved standard contractual clauses;
  • Binding corporate rules where applicable.

10.2 Your Rights in Respect of Transfers

You may request further information about the specific safeguards applied to transfers of your data by contacting us at [email protected].

11. Minors

Our Platform is strictly intended for individuals who are 18 years of age or older. We do not knowingly collect personal data from persons under the age of 18. If we become aware that personal data of a minor has been collected, we will take immediate steps to delete such data and close the associated account. If you believe a minor has registered an account or shared data with us, please contact us at [email protected] immediately. For further information on how we protect minors, please refer to our Responsible Gaming Policy.

12. Changes to This Policy

We may update this Privacy Policy from time to time to reflect changes in our practices, technology, legal requirements, or other factors. When we make material changes, we will notify you by email or by posting a prominent notice on the Website, and update the “Last Updated” date at the top of this Policy. We encourage you to review this Policy periodically. Your continued use of the Platform following any update constitutes your acceptance of the revised Policy.

13. Contact Information

For any questions, requests, or concerns relating to this Privacy Policy or our data processing practices, please contact us using the details below: