Privacy Policy
Last updated: June 2025
This Privacy Policy explains how , operating the website corvellanhellspincasino.com (hereinafter referred to as the "Website", "we", "us", or "our"), collects, uses, stores, and protects personal data belonging to visitors, guests, and registered users (hereinafter "you" or "data subject"). This Policy is drafted in accordance with the requirements of the General Data Protection Regulation (EU) 2016/679 ("GDPR"), the Australian Privacy Act 1988, and other applicable data protection legislation.
By using our Website, booking accommodation or gaming services, or otherwise engaging with us, you acknowledge that you have read and understood this Privacy Policy. If you do not agree with any part of this Policy, please discontinue use of our Website and services.
1. Data Controller
The entity responsible for determining how and why your personal data is processed is:
| Legal Entity Name | |
|---|---|
| Trading Name | Corvellanhell Spincasino |
| Registered Address | |
| Website | corvellanhellspincasino.com |
| info@corvellanhellspincasino.com | |
| Country of Registration | Australia |
Where personal data of individuals located in the European Economic Area (EEA) or the United Kingdom is processed, acts as the Data Controller within the meaning of Article 4(7) of the GDPR.
2. Data Protection Officer (DPO)
We have appointed a Data Protection Officer who oversees compliance with applicable data protection law. You may contact our DPO at any time in relation to matters concerning the processing of your personal data:
| DPO Title | The Data Protection Officer |
|---|---|
| Organisation | |
| Postal Address | |
| info@corvellanhellspincasino.com |
3. Personal Data We Collect
We collect personal data that you provide directly to us, that is generated through your use of our services, or that we receive from third parties. The categories of personal data we process include, but are not limited to, the following:
3.1 Identity and Contact Data
- Full name (first name, surname)
- Date of birth
- Gender
- Nationality and country of residence
- Residential and billing address
- Email address
- Telephone and mobile number
- Copies of government-issued identity documents (passport, national ID, driver's licence) for identity verification and age verification purposes
3.2 Account and Registration Data
- Username and encrypted password
- Security questions and answers
- Account preferences and settings
- Date and time of account creation
3.3 Financial and Payment Data
- Credit and debit card details (card number partially masked, expiry date, cardholder name)
- Bank account information (IBAN, BSB, account number)
- E-wallet identifiers (e.g., PayPal email, Skrill or Neteller account ID)
- Transaction history, deposit and withdrawal records
- Source of funds documentation (where required by law)
3.4 Gaming and Hotel Activity Data
- Gaming history, bet records, wagers, wins, losses
- Bonus and promotional participation history
- Hotel reservation details (check-in and check-out dates, room type, special requests)
- Dining, spa, and ancillary service bookings
- On-site activity logs and access records
3.5 Technical and Usage Data
- IP address and geolocation data derived therefrom
- Browser type, version, and language settings
- Device type, operating system, and device identifiers
- Pages visited, time spent on pages, click-through data
- Referral URLs and search terms
- Cookie identifiers and similar tracking technology data
- Session logs and error reports
3.6 Communications Data
- Records of correspondence with us by email, live chat, telephone, or postal mail
- Customer support tickets and complaint records
- Survey responses and feedback forms
3.7 Marketing and Preference Data
- Marketing communication preferences (opt-in/opt-out status)
- Promotional offer redemption history
- Loyalty programme membership data
3.8 Special Categories of Personal Data
In limited circumstances, we may process special categories of personal data as defined in Article 9 of the GDPR, including:
- Health data — for example, where you notify us of an accessibility requirement or a self-exclusion linked to problem gambling and mental health
- Data relating to criminal convictions or offences — where required for anti-money laundering (AML) or enhanced due diligence checks
We process such data only where a specific legal basis under Article 9(2) GDPR applies, such as your explicit consent or compliance with a legal obligation, and only to the minimum extent necessary.
3.9 Data Collected from Third Parties
We may also receive personal data about you from the following sources:
- Identity verification and Know Your Customer (KYC) service providers
- Credit reference and fraud prevention agencies
- Payment processors and financial institutions
- Regulatory bodies and law enforcement agencies
- Publicly available sources, including sanctions lists and politically exposed persons (PEP) databases
- Social media platforms (where you connect your social account to our services)
- Affiliate and referral partners
4. Legal Basis for Processing
We process your personal data only where we have a valid legal basis to do so. In accordance with Article 6 of the GDPR, we rely on the following legal bases:
4.1 Performance of a Contract (Article 6(1)(b) GDPR)
Processing is necessary to enter into and perform a contract with you. This includes:
- Creating and managing your online account
- Processing deposits, withdrawals, and transactions
- Processing hotel reservations and ancillary bookings
- Providing gaming services and verifying your eligibility to participate
- Delivering customer support
4.2 Compliance with a Legal Obligation (Article 6(1)(c) GDPR)
Processing is necessary to comply with legal and regulatory obligations imposed on us. This includes:
- Identity verification and age verification (KYC requirements)
- Anti-money laundering (AML) and counter-terrorist financing (CTF) obligations
- Responsible gambling and self-exclusion obligations under gambling legislation
- Tax reporting and record-keeping obligations
- Responding to lawful requests from courts, regulators, and law enforcement
- Sanctions screening against designated lists
4.3 Legitimate Interests (Article 6(1)(f) GDPR)
Processing is necessary for our legitimate interests or those of a third party, provided those interests are not overridden by your interests or fundamental rights. Our legitimate interests include:
- Fraud detection, prevention, and investigation
- Securing and improving our Website, systems, and services
- Analysing usage patterns to improve user experience
- Enforcing our Terms and Conditions and protecting our legal rights
- Conducting internal business analysis, auditing, and reporting
- Sending service-related communications and transactional messages
- Network and information security
4.4 Consent (Article 6(1)(a) GDPR)
Where we rely on your consent as the legal basis, we will inform you at the time of collection and give you a clear opportunity to consent or decline. You may withdraw your consent at any time without affecting the lawfulness of processing based on consent before its withdrawal. We rely on consent for:
- Sending direct marketing communications by email, SMS, or push notification
- Placing non-essential cookies and similar tracking technologies on your device
- Processing special category data where required (e.g., health-related responsible gambling data)
- Sharing your data with selected third-party marketing partners
4.5 Vital Interests (Article 6(1)(d) GDPR)
In rare and exceptional circumstances, we may process personal data where it is necessary to protect your vital interests or those of another person — for example, in a medical emergency on our premises.
4.6 Public Task (Article 6(1)(e) GDPR)
We may process personal data where necessary for the performance of a task carried out in the public interest or in the exercise of official authority vested in us, including cooperation with gambling regulators and government authorities in the public interest.
5. How We Use Your Personal Data
We use the personal data we collect for the following specific purposes:
5.1 Account Management and Service Delivery
- Registering and managing your user account on our platform
- Verifying your identity and age to ensure eligibility for gambling and hotel services
- Processing payments, deposits, and withdrawals
- Delivering the gaming and hotel accommodation services you have requested
- Communicating with you about your account, bookings, and transactions
5.2 Regulatory Compliance and Legal Obligations
- Conducting ongoing KYC, AML, and CTF checks as required by applicable law
- Verifying source of funds and source of wealth where required
- Maintaining mandatory records for tax and audit purposes
- Implementing responsible gambling tools such as self-exclusion, deposit limits, and cooling-off periods
- Reporting suspicious transactions to relevant authorities
5.3 Fraud Prevention and Security
- Detecting and preventing fraudulent, abusive, or unlawful activity
- Monitoring account activity for irregularities and security threats
- Protecting against unauthorised access to your account
- Investigating complaints, breaches, and disputes
5.4 Marketing and Personalisation
- Sending promotional emails, newsletters, and offers where you have consented or where we have a legitimate interest
- Personalising your experience on our Website based on your preferences and activity history
- Targeting relevant advertisements through our Website and third-party platforms
- Administering loyalty programmes, promotions, competitions, and bonuses
5.5 Analytics and Service Improvement
- Analysing usage data to understand how our Website and services are used
- Conducting research and statistical analysis to improve our offerings
- Testing and developing new features and services
- Generating anonymised or aggregated reports for internal and external stakeholders
5.6 Legal Proceedings and Enforcement
- Enforcing our Terms and Conditions, responsible gambling policies, and other agreements
- Establishing, exercising, or defending legal claims
- Responding to requests from regulatory and law enforcement authorities
7. Sharing Your Personal Data
We do not sell, rent, or trade your personal data to third parties for their own marketing purposes. We may share your personal data with the categories of recipients described below, and only to the extent necessary for the stated purpose:
7.1 Service Providers and Data Processors
We engage trusted third-party companies and individuals to perform services on our behalf. These processors act under our documented instructions and are contractually bound to protect your data. They include:
- Payment processors, banking partners, and financial institutions
- Identity verification and KYC/AML compliance providers
- Cloud hosting and IT infrastructure providers
- Customer relationship management (CRM) platform providers
- Email marketing and communications platforms
- Customer support and live chat software providers
- Analytics and data intelligence providers
- Fraud detection and cybersecurity service providers
- Responsible gambling solution providers
7.2 Regulatory Authorities and Law Enforcement
We may disclose your personal data to competent regulatory authorities, government agencies, and law enforcement bodies where we are legally required or permitted to do so. This includes:
- Gambling commissions and licensing authorities
- Financial intelligence units and AML regulators
- Tax authorities
- Courts and tribunals
- Police and other law enforcement agencies
7.3 Business Partners
With your consent, we may share your data with selected business partners, including affiliate networks and joint venture partners, for the purpose of delivering co-branded services or targeted marketing offers.
7.4 Group Companies
Where is part of a corporate group, we may share your data with our affiliated entities for internal administrative purposes, IT system management, and group-level reporting, subject to appropriate data sharing agreements.
7.5 Professional Advisers
We may share your data with lawyers, auditors, accountants, and insurers where necessary in the course of professional services they provide to us, subject to duties of confidentiality.
7.6 Business Transfers
In the event of a merger, acquisition, restructuring, sale of assets, or insolvency proceeding, your personal data may be transferred to the relevant successor or acquiring entity as part of the transaction. We will notify you via a prominent notice on our Website or by email if such a transfer materially affects your privacy rights.
8. International Transfers of Personal Data
As an Australian-based organisation serving an international audience, your personal data may be transferred to and processed in countries outside of Australia, the European Economic Area (EEA), or the United Kingdom. Some of these countries may not provide the same level of data protection as your country of residence.
Where we transfer personal data internationally, we ensure appropriate safeguards are in place, including:
- Adequacy decisions by the European Commission recognising the destination country as providing an adequate level of protection
- Standard Contractual Clauses (SCCs) approved by the European Commission (Module 1: Controller-to-Controller; Module 2: Controller-to-Processor) incorporated into contracts with recipients
- Binding Corporate Rules (BCRs) where applicable within our group structure
- Other appropriate safeguards permitted under Chapter V of the GDPR
You may request a copy of the safeguards we use for international transfers by contacting our DPO at the details provided in Section 2.
9. Data Retention
We retain your personal data only for as long as is necessary to fulfil the purposes for which it was collected, including satisfying any legal, regulatory, accounting, or reporting requirements. The following retention periods apply as a general guide:
| Category of Data | Retention Period | Basis |
|---|---|---|
| Account and identity data | Duration of account + 7 years after closure | Legal obligation (AML, tax), legitimate interests |
| Financial and transaction records | 7 years from date of transaction | Legal obligation (AML Act, tax law) |
| KYC and identity verification documents | 5–7 years from end of business relationship | Legal obligation (AML/CTF legislation) |
| Gaming activity logs | 5 years from date of activity | Legal obligation, legitimate interests |
| Hotel reservation records | 5 years from check-out date | Legal obligation, contract performance |
| Customer support communications | 3 years from date of communication | Legitimate interests, legal claims |
| Marketing consent records | Duration of consent + 3 years | Legal obligation (evidence of consent) |
| Technical and log data | Up to 12 months | Legitimate interests (security) |
| Responsible gambling records (self-exclusion) | Duration of exclusion + 7 years | Legal obligation, vital interests |
At the end of the applicable retention period, personal data is securely deleted, anonymised, or destroyed in accordance with our internal data destruction procedures and applicable law. Where data is anonymised, the resulting information is no longer personal data and may be retained indefinitely for statistical purposes.
10. Your Rights as a Data Subject
Subject to applicable law and certain exemptions, you have the following rights with respect to your personal data. We will respond to verified requests within one calendar month of receipt. In complex cases or where multiple requests are received, we may extend this period by a further two months, of which we will notify you.
10.1 Right of Access (Article 15 GDPR)
You have the right to obtain confirmation of whether we process your personal data and, where we do, to receive a copy of that data together with supplementary information about how it is processed. This is known as a Subject Access Request (SAR).
10.2 Right to Rectification (Article 16 GDPR)
You have the right to request correction of inaccurate personal data and completion of incomplete personal data that we hold about you, without undue delay.
10.3 Right to Erasure / 'Right to be Forgotten' (Article 17 GDPR)
You have the right to request the deletion of your personal data where:
- The data is no longer necessary for the purposes for which it was collected
- You withdraw consent and there is no other legal basis for processing
- You object to processing based on legitimate interests and there are no overriding legitimate grounds
- The data has been unlawfully processed
- Erasure is required by a legal obligation
Please note that this right is not absolute. We may be required to retain certain data to comply with legal obligations (e.g., AML and tax record-keeping requirements).
10.4 Right to Restriction of Processing (Article 18 GDPR)
You have the right to request that we restrict the processing of your personal data in the following circumstances:
- You contest the accuracy of the data (during the period we take to verify accuracy)
- The processing is unlawful but you prefer restriction to erasure
- We no longer need the data but you require it for the establishment, exercise, or defence of legal claims
- You have objected to processing pending verification of whether our legitimate grounds override yours
10.5 Right to Data Portability (Article 20 GDPR)
Where processing is based on your consent or on the performance of a contract, and is carried out by automated means, you have the right to receive your personal data in a structured, commonly used, and machine-readable format (e.g., CSV or JSON), and to transmit that data to another controller where technically feasible.
10.6 Right to Object (Article 21 GDPR)
You have the right to object at any time to:
- Processing based on legitimate interests or the public task — we will cease processing unless we can demonstrate compelling legitimate grounds that override your interests, rights, and freedoms, or for the establishment, exercise, or defence of legal claims
- Processing for direct marketing purposes — we will cease processing immediately upon receipt of your objection, without the need to provide any justification
- Processing for research, statistical, or scientific purposes, unless the processing is necessary for the performance of a task carried out in the public interest
10.7 Rights in Relation to Automated Decision-Making and Profiling (Article 22 GDPR)
You have the right not to be subject to a decision based solely on automated processing, including profiling, that produces legal or similarly significant effects on you. Where we engage in such processing, we will inform you, provide you with information about the logic involved, and offer you the ability to request human review of the decision, express your point of view, and contest the outcome.
10.8 Right to Withdraw Consent
Where processing is based on your consent, you have the right to withdraw that consent at any time. Withdrawal of consent does not affect the lawfulness of any processing carried out before the withdrawal. You may withdraw consent for marketing communications by clicking the "unsubscribe" link in any marketing email, by adjusting your account notification settings, or by contacting us directly.
10.9 Right to Lodge a Complaint
If you believe that we have processed your personal data in breach of applicable data protection law, you have the right to lodge a complaint with:
-
Office of the Australian Information Commissioner (OAIC)
Website: www.oaic.gov.au
GPO Box 5218, Sydney NSW 2001, Australia - A supervisory authority in your country of residence — if you are located in the EEA or the United Kingdom, you may contact the data protection supervisory authority of the EU member state or the UK Information Commissioner's Office (ICO) where you habitually reside or work, or where the alleged infringement occurred.
We encourage you to contact us in the first instance to resolve any concerns before escalating to a supervisory authority.
10.10 How to Exercise Your Rights
To exercise any of your data subject rights, please submit a written request to our Data Protection Officer:
- Email: info@corvellanhellspincasino.com
- Post: The Data Protection Officer, ,
To protect your privacy and security, we may ask you to verify your identity before we process your request. We will not charge a fee for handling your request unless it is manifestly unfounded, excessive, or repetitive, in which case we may charge a reasonable administrative fee or decline to respond.
11. Data Security
We are committed to protecting your personal data against accidental or unlawful destruction, loss, alteration, unauthorised disclosure, and unauthorised access. We implement appropriate technical and organisational security measures, including:
- Industry-standard Secure Socket Layer (SSL) / Transport Layer Security (TLS) encryption for data in transit
- Encryption of sensitive data at rest, including financial and identity documents
- Role-based access controls and the principle of least privilege
- Multi-factor authentication for system access
- Regular vulnerability assessments, penetration testing, and security audits
- Firewalls, intrusion detection systems, and antivirus software
- Staff training on data protection and information security
- Documented data breach response and notification procedures
In the event of a personal data breach that is likely to result in a risk to your rights and freedoms, we will notify the relevant supervisory authority within 72 hours of becoming aware, and will notify you without undue delay where the breach is likely to result in a high risk to your rights and freedoms, as required by Articles 33 and 34 of the GDPR.
12. Children and Minors
Our Website and gambling services are strictly intended for adults aged 18 years or over. We do not knowingly collect personal data from persons under the age of 18. We conduct age verification checks as part of our registration and KYC process to prevent access by minors.
If you are a parent or guardian and believe that a minor has provided personal data to us, please contact us immediately at info@corvellanhellspincasino.com. We will take prompt steps to delete such data and close any associated account.
13. Responsible Gambling and Data Processing
We are committed to promoting responsible gambling. As part of our responsible gambling programme, we may collect and process data relating to your gambling behaviour, including spend patterns, session duration, and self-reported concerns. This data may be used to:
- Implement voluntary and mandatory self-exclusion programmes
- Apply deposit limits, loss limits, session time limits, and cooling-off periods
- Identify signs of problem gambling and intervene appropriately
- Fulfil obligations imposed by gambling regulatory authorities
Where self-exclusion data involves health-related information, we process it on the basis of your explicit consent (Article 9(2)(a) GDPR) and/or compliance with a legal obligation (Article 9(2)(b) GDPR). This data is treated with the highest level of confidentiality.
14. Third-Party Websites and Links
Our Website may contain links to third-party websites, plug-ins, and applications. Clicking on those links or enabling those connections may allow third parties to collect or share data about you. We do not control these third-party websites and are not responsible for their privacy practices. We encourage you to review the privacy policy of each third-party website you visit.
15. Changes to This Privacy Policy
We may update this Privacy Policy from time to time to reflect changes in our processing activities, applicable law, or regulatory guidance. The updated version will be published on this page with an updated "Last updated" date at the top. Where changes are material, we will notify you by email or by a prominent notice on our Website prior to the changes taking effect.
We encourage you to review this Privacy Policy periodically to stay informed about how we protect your personal data.
16. Contact Us
If you have any questions, concerns, or requests relating to this Privacy Policy or the way we process your personal data, please do not hesitate to contact us:
| Controller | |
|---|---|
| Data Protection Officer | The Data Protection Officer |
| Postal Address | |
| info@corvellanhellspincasino.com | |
| Website | corvellanhellspincasino.com |
We aim to respond to all legitimate requests within 30 days. Occasionally, it may take us longer if your request is particularly complex or you have made multiple requests. In that case, we will notify you and keep you updated.