Privacy Policy
Privacy Policy
This Privacy Policy explains how GRP (casinogrp.uk) collects, uses, stores, and protects your personal data when you visit or use our website and services.
This Privacy Policy forms part of the legal documentation governing your use of casinogrp.uk, together with our Terms & Conditions and Responsible Gaming Policy. By accessing or using our website, you acknowledge that you have read, understood, and agree to the data practices described herein. If you do not agree, please discontinue your use of the site immediately.
📄 Table of Contents
1. Introduction
1.1. About Us
GRP operates the online gaming platform accessible at casinogrp.uk (the "Website"). In this Privacy Policy, references to "we", "us", or "our" refer to GRP and its associated operating entities. References to "you" or "your" refer to any individual accessing or using our Website.
1.2. Our Commitment to Your Privacy
We are committed to protecting and respecting the privacy of every person who visits or registers on our Website. We operate in full compliance with the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018 (DPA 2018). We act as the data controller in respect of all personal data we process about you.
1.3. Scope of This Policy
This Privacy Policy applies to:
- All visitors to casinogrp.uk, whether registered users or not;
- All individuals who register a player account with us;
- Individuals who contact us through any channel (email, live chat, telephone);
- Individuals whose personal data we receive through third-party partners, payment processors, or other legitimate sources.
This Policy should be read alongside our Terms & Conditions and Responsible Gaming Policy, which together form the complete legal framework governing your relationship with us.
1.4. Data Controller Details
For all matters relating to your personal data, you may contact our Data Protection Officer at [email protected] or our general support team at [email protected].
2. Data We Collect
2.1. Categories of Personal Data
We collect and process different categories of personal data depending on the nature of your interaction with our Website. The primary categories are set out below.
2.2. Identity & Registration Data
When you create a player account or complete identity verification, we collect:
- Full name (first name and surname);
- Date of birth (to verify you are aged 18 or over);
- Gender (where provided voluntarily);
- Username and account credentials;
- Government-issued identity documents (e.g. passport, driving licence) for Know Your Customer (KYC) verification;
- Proof of address documents (e.g. utility bill, bank statement);
- Selfie or biometric image where required for identity verification purposes.
2.3. Contact Data
- Email address;
- Telephone number;
- Residential address (including postcode);
- Country of residence.
2.4. Financial & Transaction Data
- Payment method details (e.g. partial card numbers, e-wallet identifiers);
- Deposit and withdrawal history;
- Transaction records and account balance information;
- Source of funds information requested for AML compliance purposes;
- Currency preference (British Pound Sterling – GBP).
We accept the following payment methods, the use of which may involve the processing of associated personal data:
- Visa and Mastercard (credit and debit cards)
- PayPal
- Skrill
- Neteller
- Paysafecard
- Apple Pay
- Google Pay
- Bank Transfer (BACS / Faster Payments)
- Trustly (Open Banking)
- Revolut
2.5. Gameplay & Behavioural Data
- Betting and gaming activity (game type, stake, frequency, session duration);
- Win/loss records;
- Responsible gaming indicators (deposit limits, self-exclusion requests, cooling-off periods);
- Bonus and promotional participation data.
2.6. Technical & Device Data
- IP address;
- Browser type and version;
- Device type and operating system;
- Geolocation data;
- Session timestamps and durations;
- Referring URLs and navigation paths within the Website.
2.7. Communications Data
- Records of correspondence with our customer support team;
- Live chat transcripts;
- Responses to surveys, feedback forms, and promotional offers;
- Marketing preferences and communication opt-in/opt-out status.
2.8. Data Collected from Third Parties
We may receive personal data about you from third-party sources, including:
- Identity verification providers (e.g. Jumio, Onfido, or equivalent KYC services);
- Payment processors and financial institutions;
- Fraud prevention and AML screening databases;
- Self-exclusion registers such as GAMSTOP;
- Credit reference agencies.
3. How We Use Your Data
3.1. Purposes of Processing
We use the personal data we collect for the following specific and clearly defined purposes:
| Purpose | Description |
|---|---|
| Account creation & management | Registering and maintaining your player account, including authentication and account security. |
| Identity verification (KYC) | Verifying your identity and age (18+) to comply with anti-money laundering and regulatory obligations. |
| Service delivery | Providing gaming, promotional, and customer support services as described in our Terms & Conditions. |
| Payment processing | Facilitating deposits, withdrawals, and chargebacks securely. |
| Regulatory compliance | Meeting obligations under AML, counter-terrorist financing, and other applicable laws. |
| Fraud prevention & security | Detecting, investigating, and preventing fraudulent activity, account misuse, and suspicious transactions. |
| Responsible gaming | Monitoring gameplay patterns to identify and support players at risk, as detailed in our Responsible Gaming Policy. |
| Marketing & communications | Sending promotional offers, newsletters, and personalised content where you have provided consent. |
| Analytics & improvement | Analysing usage patterns to improve Website performance, user experience, and product offerings. |
| Legal proceedings | Establishing, exercising, or defending legal claims. |
3.2. Marketing Communications
We will only send you direct marketing communications (including promotional emails, SMS, and push notifications) where you have provided explicit consent to receive such communications. You may withdraw your consent at any time by:
- Clicking the "unsubscribe" link in any marketing email;
- Updating your communication preferences within your account settings;
- Contacting us directly at [email protected].
Please note that withdrawing consent for marketing will not affect the lawfulness of any processing carried out prior to such withdrawal, nor will it affect any processing carried out on other lawful bases.
4. Legal Bases for Processing
4.1. Overview
Under UK GDPR, every processing activity requires a valid lawful basis. We rely on the following legal bases in relation to different types of processing:
| Legal Basis | When We Rely on It |
|---|---|
| Article 6(1)(a) – Consent | For direct marketing communications and the use of non-essential cookies and tracking technologies. |
| Article 6(1)(b) – Contract | For processing necessary to perform the contract with you (account management, payment processing, service delivery). |
| Article 6(1)(c) – Legal Obligation | For KYC/AML checks, age verification, self-exclusion compliance, and regulatory record-keeping. |
| Article 6(1)(f) – Legitimate Interests | For fraud detection, Website security, responsible gaming monitoring, and internal analytics, where our interests do not override your fundamental rights. |
4.2. Legitimate Interests Assessment
Where we rely on legitimate interests as a legal basis, we have conducted a balancing test to ensure that our interests do not unduly override your rights and freedoms. You have the right to object to processing based on legitimate interests at any time (see Section 9).
4.3. Sensitive Data
Gambling activity may, in some circumstances, constitute data relating to health or lifestyle, which may be considered sensitive in nature. Where we process such data, we do so strictly to fulfil our legal and regulatory obligations relating to responsible gaming and player protection, or with your explicit consent.
5. Data Sharing & Third Parties
5.1. Categories of Recipients
We do not sell, rent, or trade your personal data to third parties for their own marketing purposes. However, we may share your personal data with the following categories of trusted recipients, strictly as necessary for the purposes outlined in this Policy:
- Identity verification & KYC providers – to confirm your identity and age;
- Payment service providers & processors – to handle deposits, withdrawals, and dispute resolution;
- Fraud prevention & AML screening services – to detect and prevent financial crime;
- Game software providers – to deliver gaming content and maintain fair play integrity;
- Customer support platforms – to facilitate live chat and ticketing services;
- Marketing & analytics platforms – to deliver and measure marketing campaigns (where you have consented);
- Self-exclusion scheme operators (e.g. GAMSTOP) – to uphold responsible gaming commitments as described in our Responsible Gaming Policy;
- Regulatory authorities and law enforcement – where required by law or court order;
- Legal advisers and auditors – in connection with legal proceedings or regulatory audits;
- Group companies and business successors – in the event of a corporate restructure, merger, or acquisition.
5.2. Data Processing Agreements
All third-party service providers that process personal data on our behalf are required to enter into a Data Processing Agreement (DPA) in accordance with UK GDPR Article 28. We carry out periodic due diligence to ensure that our processors maintain appropriate security standards and process data only in accordance with our documented instructions.
5.3. No Sale of Personal Data
We confirm that we do not and will not sell your personal data to any third party for commercial gain. Any sharing of data with advertising or analytics partners is governed by strict contractual terms and is limited to aggregated or pseudonymised data where possible.
6. Cookies & Tracking Technologies
6.1. What Are Cookies?
Cookies are small text files placed on your device by a website when you visit it. They are widely used to make websites function more efficiently, remember your preferences, and provide aggregate analytical information to website owners.
6.2. Types of Cookies We Use
| Cookie Type | Purpose | Consent Required? |
|---|---|---|
| Strictly Necessary | Essential for core website functionality (login sessions, security, navigation). Cannot be disabled. | No |
| Functional | Remember your preferences such as language, currency, and display settings. | Yes |
| Performance / Analytics | Collect anonymised data on how visitors interact with the Website (e.g. Google Analytics). | Yes |
| Marketing / Targeting | Track browsing across websites to deliver relevant advertisements and measure campaign effectiveness. | Yes |
6.3. Other Tracking Technologies
In addition to cookies, we may use the following tracking technologies:
- Web beacons (pixel tags) – used in HTML emails to confirm whether an email has been opened;
- Local storage & session storage – to retain browser-level preferences;
- Software Development Kits (SDKs) – embedded within mobile applications to collect device and usage data.
6.4. Managing Cookies
When you first visit the Website, you will be presented with a cookie consent banner through which you can accept or reject non-essential cookies. You may change your preferences at any time by accessing the Cookie Settings link in the footer of our Website. You may also control cookies through your browser settings; however, please note that restricting cookies may impair certain features of the Website.
7. Data Security
7.1. Technical & Organisational Measures
We implement a comprehensive range of technical and organisational security measures to protect your personal data against unauthorised access, accidental loss, destruction, or alteration. These measures include, but are not limited to:
- SSL/TLS encryption for all data transmitted between your browser and our servers;
- AES-256 encryption for data stored at rest;
- Multi-factor authentication (MFA) for access to internal systems containing personal data;
- Role-based access controls (RBAC) limiting data access to authorised personnel only;
- Regular security penetration testing and vulnerability assessments;
- Secure data centres with physical access controls;
- Firewalls, intrusion detection systems, and ongoing security monitoring;
- Staff training on data protection and information security obligations.
7.2. Data Breach Response
In the event of a personal data breach that is likely to result in a risk to your rights and freedoms, we will:
- Notify the Information Commissioner's Office (ICO) within 72 hours of becoming aware of the breach, in accordance with UK GDPR Article 33;
- Notify you directly without undue delay if the breach is likely to result in a high risk to your rights and freedoms;
- Document the breach, its effects, and all remedial actions taken.
7.3. Your Responsibility
While we take every reasonable precaution to protect your personal data, you are also responsible for maintaining the confidentiality of your account credentials. You should never share your password with any third party. If you believe your account has been compromised, please contact us immediately at [email protected].
8. Data Retention
8.1. General Retention Principles
We retain your personal data only for as long as is necessary to fulfil the purposes for which it was collected, or as required by applicable law. Our retention decisions take into account the nature of the data, the purposes of processing, and any applicable legal or regulatory obligations.
8.2. Specific Retention Periods
| Data Category | Retention Period | Basis |
|---|---|---|
| Account & identity records | 5 years after account closure | AML / Proceeds of Crime Act 2002 |
| Transaction & financial records | 5 years after account closure | AML / HMRC requirements |
| KYC documents | 5 years after the end of the business relationship | Money Laundering Regulations 2017 |
| Customer support communications | 3 years after the last interaction | Legitimate interests / contractual basis |
| Marketing data | Until consent is withdrawn or 2 years of inactivity | Consent |
| Responsible gaming records | 5 years after account closure | Legal obligation / legitimate interests |
| Technical / log data | 12 months | Legitimate interests (security) |
8.3. Post-Retention Disposal
Upon expiry of the applicable retention period, personal data will be securely deleted or anonymised in accordance with our internal data disposal procedures. Where anonymisation is not possible, data will be archived and restricted from active processing pending secure deletion.
9. Your Rights
9.1. Rights Under UK GDPR
Under the UK GDPR and the Data Protection Act 2018, you have the following rights in relation to your personal data:
You may request a copy of all personal data we hold about you, along with information about how it is being used.
You may request that we correct any inaccurate or incomplete personal data held about you.
You may request deletion of your personal data where it is no longer necessary for the purposes for which it was collected, subject to legal retention obligations.
You may request that we limit the processing of your data in certain circumstances (e.g. while accuracy is contested).
Where processing is based on consent or contract, you may request your data in a structured, machine-readable format.
You may object to processing based on legitimate interests or for direct marketing purposes at any time.
You have the right not to be subject to solely automated decisions that produce significant legal or similarly significant effects, unless you have given consent.
Where processing is based on consent, you may withdraw that consent at any time without affecting prior lawful processing.
9.2. Exercising Your Rights
To exercise any of the rights listed above, please submit a written request to our Data Protection Officer at [email protected]. We will respond to all valid requests within one calendar month of receipt. In cases of complexity or multiple simultaneous requests, we may extend this period by a further two months, and we will notify you accordingly.
We may need to verify your identity before processing your request. We will not charge a fee for exercising your rights unless your request is manifestly unfounded, excessive, or repetitive.
9.3. Right to Lodge a Complaint
If you are dissatisfied with how we have handled your personal data or with our response to a rights request, you have the right to lodge a complaint with the Information Commissioner's Office (ICO), the UK's supervisory authority for data protection matters:
- Website: ico.org.uk
- Telephone: 0303 123 1113
- Post: Information Commissioner's Office, Wycliffe House, Water Lane, Wilmslow, Cheshire, SK9 5AF
10. International Data Transfers
10.1. Transfers Outside the UK
In some circumstances, your personal data may be transferred to, stored in, or processed in countries outside the United Kingdom. This may occur when our service providers, sub-processors, or technology partners operate data centres or infrastructure in non-UK jurisdictions.
10.2. Safeguards
Whenever we transfer personal data outside the UK, we ensure that appropriate safeguards are in place to protect your data to a standard equivalent to that required within the UK. These safeguards may include:
- UK Adequacy Regulations – transfers to countries designated by the UK Secretary of State as providing adequate data protection;
- International Data Transfer Agreements (IDTAs) – the UK-specific standard contractual clauses approved by the ICO for use in international transfers;
- UK Addendum to EU Standard Contractual Clauses;
- Binding Corporate Rules (BCRs) where applicable within corporate group structures.
10.3. Further Information
You may request further information about the specific safeguards applicable to any international transfer of your personal data by contacting our Data Protection Officer at [email protected].
11. Minors
11.1. Age Restriction
Our Website and services are strictly intended for individuals who are 18 years of age or older. We do not knowingly collect, process, or retain personal data from any person under the age of 18. As part of our registration process, we require all users to confirm that they are of legal gambling age and to submit to identity and age verification checks.
11.2. Discovery of Underage Use
If we discover or have reasonable grounds to believe that a person under the age of 18 has provided us with personal data or has registered an account, we will:
- Immediately suspend and close the account in question;
- Refund any deposited funds in accordance with our Terms & Conditions;
- Securely delete all personal data associated with the underage individual without undue delay;
- Take all other steps required by applicable law and regulatory guidance.
11.3. Parental Controls
We strongly encourage parents and guardians to make use of available parental control tools to restrict access to gambling websites. We also support and participate in the GAMSTOP national self-exclusion scheme, as further described in our Responsible Gaming Policy. If you believe a minor has accessed our services, please contact us immediately at [email protected].
12. Changes to This Policy
12.1. Right to Amend
We reserve the right to update, modify, or replace this Privacy Policy at any time. Changes may be required to reflect updates in applicable law, regulatory guidance, our business operations, or changes in technology. We will always post the most current version of this Privacy Policy on this page, together with the version number and effective date.
12.2. Material Changes
Where we make material changes to this Privacy Policy that significantly affect how we use your personal data, we will provide you with prominent notice through one or more of the following methods:
- A notification displayed on the Website homepage or within your account dashboard;
- An email notification sent to the address registered on your account;
- A notification via our in-app messaging system (if applicable).
12.3. Continued Use
Your continued use of the Website following the effective date of any updated Privacy Policy constitutes your acknowledgement of the changes. If you do not agree with any changes, you should cease using our Website and contact us to discuss the deletion of your account and personal data.
12.4. Policy Archive
Upon request, we can provide you with previous versions of this Privacy Policy for review. Please contact our Data Protection Officer at [email protected] to request archived versions.
13. Contact Information
If you have any questions, concerns, or requests relating to this Privacy Policy or the processing of your personal data, please do not hesitate to contact us using the details below:
General Support & Account Enquiries:
📧 [email protected]
Data Protection Officer (Privacy & DPO Matters):
📧 [email protected]
Website:
🌎 casinogrp.uk
This Privacy Policy is governed by and construed in accordance with the laws of England and Wales. For further information about your rights, you may visit the ICO website at ico.org.uk.
Privacy Policy • Version 1.0 • Last Updated: 8 September 2025 • casinogrp.uk • Terms & Conditions • Responsible Gaming