Legal

Privacy Policy

How Mad Casino collects, processes and protects personal data of United Kingdom residents under the UK General Data Protection Regulation, the Privacy and Electronic Communications Regulations and applicable anti-money-laundering law.

Last updated

1. Data we collect

Mad Casino collects three categories of personal data:

  • Account data submitted at signup, including name, date of birth, address, email and contact telephone number.
  • Transaction data generated by deposits and withdrawals, including payment method details and counterparty bank identifiers.
  • Gameplay data generated automatically by use of the platform, including session timestamps, wagering history, device identifiers and IP-derived geolocation.

2. Lawful basis for processing

We process personal data on four lawful bases under Article 6 of the UK GDPR:

  • Contract. Providing the gaming service you have signed up for.
  • Legal obligation. Anti-money-laundering checks, age verification and tax reporting.
  • Legitimate interest. Fraud prevention, security, responsible-gambling monitoring and product improvement.
  • Consent. Direct marketing communications, which you can withdraw at any time from account settings.

3. How we use your data

  • Verifying identity at signup and before withdrawal under know-your-customer rules.
  • Processing deposits, withdrawals and refunds.
  • Operating the responsible-gambling tools and matching activity against self-exclusion records.
  • Detecting and preventing fraud, bonus abuse and money laundering.
  • Responding to player support enquiries and complaints.
  • Sending marketing communications where you have given consent.
  • Reporting to regulators and tax authorities where required by law.

4. Third-party processors

We share personal data with a defined set of processors that operate on our behalf, each bound by a data processing agreement that limits use to the agreed purpose. These include payment service providers (card scheme acquirers, Skrill, Neteller, MuchBetter, PayPal, bank rails), identity-verification providers, customer-support platform providers, fraud-detection providers and game studios for the purpose of fulfilling RTP-audit obligations.

5. Retention

Account and transaction data is retained for five years after account closure under anti-money-laundering and tax record-keeping rules. Gameplay logs are retained for two years for fraud and dispute resolution purposes. Marketing consent records are retained until consent is withdrawn or for two years after the last interaction, whichever is shorter.

6. Your rights under UK GDPR

As a UK data subject you have eight rights:

  • The right to be informed.
  • The right of access.
  • The right to rectification.
  • The right to erasure.
  • The right to restrict processing.
  • The right to data portability.
  • The right to object.
  • Rights related to automated decision-making and profiling.

To exercise any of these rights, email privacy@madcasino-official.org. We respond within one calendar month under UK GDPR. You also have the right to lodge a complaint with the Information Commissioners Office if you believe your data has been mishandled.

7. International data transfers

Some of our processors operate outside the United Kingdom. Where this is the case, we use the UK International Data Transfer Agreement or equivalent safeguards to ensure data continues to be protected to UK GDPR standards.

8. Cookies

Cookies are covered separately in the cookie policy. We use cookies for account session management, fraud detection and, where you consent, marketing analytics.