Last updated: January 2025. This Privacy Policy applies to all personal data processed by CrystalRoll Casino in connection with the services offered via crystalroll-casino.com. CrystalRoll Casino acts as a data controller within the meaning of the General Data Protection Regulation (GDPR). We process your personal data exclusively on the basis of a valid legal ground and in full compliance with applicable data protection legislation, including the GDPR and its national implementing acts.
1. What Personal Data Do We Collect?
We collect only the personal data that is necessary to provide our services and meet our legal obligations. This includes data you provide directly to us when registering or using our services, as well as data collected automatically through cookies and similar technologies. The categories of data we collect include:
- Identity data: first name, last name, date of birth, gender, and nationality;
- Contact data: email address, phone number, and residential address;
- Verification documents: copy of identity document, proof of address, and proof of payment method (for KYC procedures);
- Financial data: bank account details, payment history, and transaction records;
- Gaming data: gameplay activity, betting history, deposits, withdrawals, and player behaviour;
- Technical data: IP address, device type, browser information, operating system, and session duration;
- Communication data: messages via live chat, email, or other communication channels.
Please refer to our Cookie Policy for more information about data collected automatically via cookies and similar technologies.
2. Purposes and Legal Bases for Processing
CrystalRoll Casino always processes your personal data on the basis of a valid legal ground. The purposes and corresponding legal bases are as follows:
- Performance of a contract: creating and managing your player account, processing deposits and withdrawals, and providing customer support;
- Legal obligation: performing KYC and AML (Anti-Money Laundering) procedures in accordance with applicable anti-money laundering legislation and KSA requirements;
- Legitimate interest: fraud detection and prevention, system security, network and information security, and internal analytics to improve our services;
- Consent: sending commercial communications such as newsletters and promotional offers — you may withdraw your consent at any time;
- Responsible gambling compliance: monitoring player behaviour to protect vulnerable players and comply with KSA requirements on addiction prevention.
3. Sharing Data with Third Parties
CrystalRoll Casino does not share your personal data with third parties unless this is necessary for the provision of our services, required by law, or authorised by your explicit consent. We may share data with the following categories of recipients:
- Payment service providers: for the processing of deposits and withdrawals (e.g. iDEAL banks, e-wallet providers, credit card companies);
- Software suppliers: casino game providers that process personal data to ensure fair play and regulatory compliance;
- KYC/AML service providers: specialist parties for identity verification and screening against money laundering and terrorist financing;
- Dutch Gaming Authority (KSA) and other regulators: where we are legally required to do so or in the context of an official investigation;
- Legal advisors and law enforcement authorities: in cases of fraud, abuse, legal proceedings, or court orders;
- IT and hosting service providers: who support our technical infrastructure and are contractually bound to confidentiality via data processing agreements.
All third parties with whom we work are contractually required to protect your personal data in accordance with the GDPR. We never sell your data to third parties for commercial purposes.
4. International Data Transfers
In some cases, your personal data may be transferred to parties located outside the European Economic Area (EEA). In such cases, we ensure that an appropriate level of protection is guaranteed. We do this by, among other things, using Standard Contractual Clauses (SCCs) approved by the European Commission, or by doing business with parties certified under equivalent recognised privacy frameworks. Upon request, we will inform you of the specific safeguards applicable to any such transfer.
5. Retention Periods
We do not retain your personal data for longer than is necessary for the purposes for which it was collected, or as long as required by law. The retention periods we apply include:
- Account data and gaming history: for the duration of your account and up to 7 years after termination, in accordance with AML legislation and KSA requirements;
- Financial transaction data: 7 years from the transaction date in accordance with tax and AML regulations;
- KYC documents: 5 years after the end of the business relationship;
- Communication data: up to 2 years after last contact, unless longer retention is required for a complaint or legal proceedings;
- Marketing consent and data: until consent is withdrawn, after which it is immediately deleted.
After the applicable retention period has expired, your data will be securely destroyed or sufficiently anonymised so that it can no longer be linked to you as an individual.
6. Data Security
CrystalRoll Casino takes the security of your personal data extremely seriously. We implement appropriate technical and organisational measures to protect your data against unauthorised access, loss, destruction, alteration, or unlawful disclosure. Our security measures include:
- 256-bit SSL/TLS encryption for all data transfers between your browser and our servers;
- Encrypted storage of all sensitive and personally identifiable data;
- Strict access controls based on the need-to-know principle — only authorised personnel have access to your data;
- Regular security audits, vulnerability scans, and penetration tests by independent experts;
- Two-factor authentication (2FA) for access to internal systems;
- Mandatory annual privacy training for all staff who process personal data.
In the event of a data breach that poses a risk to your rights and freedoms, we will notify you and the relevant supervisory authority in accordance with the applicable mandatory data breach notification requirements (within 72 hours of discovery).
7. Your Rights under the GDPR
Under the General Data Protection Regulation, you have the following rights in relation to your personal data. You may exercise these rights at any time by contacting our customer service team:
- Right of access (Art. 15 GDPR): you may request an overview of all personal data we process about you, including the purposes and legal bases;
- Right to rectification (Art. 16 GDPR): you may request the correction or completion of inaccurate or incomplete data;
- Right to erasure / 'right to be forgotten' (Art. 17 GDPR): you may request the deletion of your personal data, unless we have a legal obligation to retain it;
- Right to restriction of processing (Art. 18 GDPR): you may request that the processing of your data be restricted in certain circumstances, for example during an objection or correction request;
- Right to data portability (Art. 20 GDPR): you may request your data in a structured, commonly used and machine-readable format and transfer it to another controller;
- Right to object (Art. 21 GDPR): you may object to the processing of your data on the basis of legitimate interest or for direct marketing purposes;
- Right to withdraw consent: you may withdraw your consent for marketing communications at any time without affecting the lawfulness of processing carried out prior to withdrawal.
We will respond to your request within 30 days, as required by the GDPR. In the case of a particularly complex request, this period may be extended by 60 days, of which we will notify you. We may request identity verification before fulfilling your request in order to protect your privacy.
8. Cookies and Similar Technologies
CrystalRoll Casino uses cookies and similar technologies to improve the functioning of our website, personalise your experience, and gain insight into how our website is used. We distinguish the following types of cookies:
- Strictly necessary cookies: essential for the basic operation of the website, such as maintaining your login session. These cookies cannot be disabled;
- Analytical cookies: for anonymous website statistics, allowing us to measure and improve the performance and usage of our site;
- Functional cookies: for remembering your preferences, such as language settings and currency choice;
- Marketing cookies: for displaying personalised advertisements and measuring the effectiveness of our marketing campaigns.
You can adjust your cookie preferences at any time via our cookie management centre. Please refer to our comprehensive Cookie Policy for a full description of all cookies and management options.
9. Automated Decision-Making and Profiling
CrystalRoll Casino uses automated systems for fraud detection and to protect the security of our platform. As part of our responsible gambling policy, we automatically monitor player behaviour to detect signs of problematic gambling. If automated decision-making has a significant impact on you — such as the temporary restriction of your account — you may always request human intervention and object to the decision. Please contact our customer service team for this purpose.
10. Minors
CrystalRoll Casino's services are exclusively intended for persons aged 18 and over. We do not knowingly collect personal data from minors. All registrations are verified through age verification in accordance with KSA requirements. If you suspect that a minor has created an account or provided personal data to us, please report this immediately to our customer service team so that we can take the necessary measures and remove the data without delay.
11. Changes to This Privacy Policy
CrystalRoll Casino may update this Privacy Policy from time to time to comply with changed legislation, new services, or improved processing practices. The most current version is always available on this page, with the date of the last amendment. For material changes that substantially affect your privacy rights, we will notify you by email or via a prominent notice on the website. We recommend reviewing this policy periodically to stay informed of any changes.
12. Contact and Complaints
Do you have questions about this Privacy Policy, about the processing of your personal data, or would you like to exercise one of your privacy rights? Please contact our Privacy Officer via live chat or email. We aim to handle your request as quickly as possible and no later than within the statutory 30-day period.
You also have the right to lodge a complaint with the national data protection supervisory authority. In the Netherlands, this is:
- Autoriteit Persoonsgegevens (AP) — Dutch Data Protection Authority
- Website: www.autoriteitpersoonsgegevens.nl
- Phone: +31 (0)70 888 85 00
- P.O. Box 93374, 2509 AJ The Hague, Netherlands
We do, however, appreciate it if you contact us first so that we can work together towards an appropriate solution before you file a formal complaint.