This Privacy Notice describes how Incaspin Casino gathers, handles, keeps, and secures personal data pertaining to players located in Germany https://incaspincasino.de.com/legal-and-affiliates/. The document works within the context of the European Union’s General Data Protection Regulation (GDPR) and the German Federal Data Protection Act (Bundesdatenschutzgesetz, BDSG-neu). Incaspin Casino acts as the data controller for personal information furnished through its website, mobile applications, and related services. German players have specific statutory rights concerning their data, and this notice specifies the lawful bases for processing, data retention periods, third-party sharing protocols, and the technical safeguards used to prevent unauthorised access. The document also explains the responsibilities of the Data Protection Officer and the supervisory authority contact procedures. Every section has been compiled to ensure transparency and compliance with Article 13 and Article 14 of the GDPR, providing German users with a complete overview of how their casino account data, payment details, identification documents, and behavioural analytics are managed throughout the entire customer lifecycle.
Kapitola 1. Identita správce údajů a podrobnosti o kontaktu
The data controller for all personal data processed through the Incaspin Casino platformy je právnická osoba působící pod názvem značky Incaspin Casino, registrovaná v jurisdikci recognised for its adherence to standardů ochrany údajů odpovídajících EU. The registered office address a registrační číslo are available upon verified request e-mailem na adresu pracovníkovi pro ochranu osobních údajů, nebo nahlédnutím do the imprint section hlavních webových stránek. German players may direct any privacy-related inquiries na jmenovanému pracovníkovi pro ochranu údajů, který působí nezávisle and reports directly to vrcholovému vedení. The DPO může být kontaktován prostřednictvím a dedicated encrypted email channel published within the full privacy policy text. Incaspin Casino udržuje právního zástupce na území Evropské unie z důvodu článku 27 GDPR, ensuring that německé dozorové úřady and data subjects disponují přímým kontaktem for regulatory matters. Správce determines účely a prostředky zpracovávání all personal data získaných při account registration, Know Your Customer verification, platebních transakcích vkladů a výběrů, a průběžné aktivitě při hraní. This includes informace generované pomocí cookies, device fingerprinting technologies, a serverových logů. German players should note, that the controller exercises full decision-making power over data processing operations while commissioning důkladně vybrané zpracovatele pro specifické technické služby jako je hosting, platební brány, and CRM platforms. Každý vztah se zpracovatelem je upravena právně závaznou dohodou o zpracování dat that meets the requirements of ustanovení čl. 28 GDPR, s vyhrazenými povinnými právy na audit by Incaspino Casino pro ověření průběžného souladu. Kontaktní údaje of the EU representative byly sděleny příslušnému německému úřadu pro ochranu osobních údajů as required by law.
9. Cookie Policy and Tracking Technologies
9.1 Core and Functional Cookies
The Incaspin Casino site and mobile platform deploy a set of cookies and similar tracking technologies to deliver core functionality. Strictly necessary cookies handle session state across page loads, preserve login authentication tokens, and preserve security context for CSRF protection. These first-party session cookies end when the browser is closed and do not require prior consent under German law transposing the ePrivacy Directive, as they are indispensable for the requested service delivery. Functional cookies store language preferences, preferred currency displays, and responsible gambling limit settings across visits, ensuring that returning players encounter a uniform customized environment without reconfiguring their preferences. The maximum lifespan of functional cookies is 365 days, after which they expire automatically if the player has not accessed the platform. Incaspin Casino does not use flash cookies, supercookies, or any regenerating techniques that evade browser deletion actions.
9.2 Metrics and Marketing Cookies
Analytics and marketing cookies are set only after German players provide explicit, freely given consent through the cookie consent management platform presented on first visit. The consent tool offers clear descriptions of each cookie category, the specific providers participating, the purposes of data collection, and the retention duration for each cookie type. Players may allow or deny consent for each category independently, and consent preferences are stored as documentary evidence in an encrypted consent log with timestamp and IP address. Analytics cookies from a privacy-focused measurement service monitor aggregated page interaction metrics without cross-site tracking or user-level profiling. Marketing cookies facilitate campaign attribution and frequency capping for promotional banners displayed within the logged-in casino environment. German players may adjust their consent choices at any time by accessing the cookie settings panel referenced in the website footer. Declining analytics or marketing cookies does not impact gameplay functionality or account standing in any manner. The consent tool asks again players annually to reaffirm or update their preferences.
8. Rights of German Data Subjects
German gamblers possess the complete suite of data subject rights listed in Articles 15 through 21 of the GDPR, along with the entitlement to lodge a appeal with a supervisory authority. The right to access enables players to acquire verification of if Incaspin Casino processes their individual data and to receive a duplicate of that data along with information about processing aims, types, receivers, holding terms, and the presence of automated decision-making. Access requests are fulfilled within one month, free of charge for the first request, with the reply provided in a organized, generally used, machine-readable layout. The rectification right permits players to amend incorrect personal data or complete missing files, a particularly pertinent right for identity document updates following name modifications or address relocations. Incaspin Casino handles rectification inquiries within ten business days and confirms corrections to any third-party addressees to whom the inaccurate data was revealed. The erasure right is applicable where the personal data is no longer necessary for the purposes for which it was obtained, where consent is withdrawn, where the player opposes to processing and no overriding legitimate grounds are present, or where processing is not permitted. Nonetheless, statutory retention requirements take precedence over erasure applications, and data needed for legal compliance will be restricted from further processing rather than removed until the retention period ends. The right to restriction of processing serves as an substitute where the precision of data is challenged, processing is unlawful but the player objects to deletion, or the player requires the data for legal assertions despite the controller no longer demanding it. Data portability rights under Article 20 GDPR extend only to data provided by the player and processed by automated means based on authorization or contract, signifying gameplay history and transaction logs qualify for portability while fraud detection ratings obtained from internal systems do not. Rights applications should be addressed to the Data Protection Officer email address, with valid proof of identity needed before any data is released.

7. Information Security Measures
Incaspin Casino deploys a multilevel security architecture in accordance with the ISO 27001 control framework and the technical requirements set forth in Article 32 of the GDPR. Network-level protections include enterprise-grade firewalls equipped with stateful packet inspection, intrusion detection and prevention systems that watch traffic patterns for indicators of compromise, and distributed denial-of-service mitigation services that withstand volumetric attacks before they hit the application layer. All data sent between German player devices and casino servers is encrypted using Transport Layer Security version 1.3 with forward secrecy enabled, blocking retrospective decryption of captured traffic even if long-term private keys are eventually leaked. Internal administrative interfaces are separated on a management network unreachable from the public internet, with access permitted exclusively through multi-factor authenticated VPN tunnels originating from pre-registered static IP addresses owned by authorised personnel. At the application layer, the platform mandates strong password policies demanding minimum character lengths and complexity standards, with passwords hashed using bcrypt with per-user salts before storage. Account access anomalies trigger step-up authentication challenges or temporary account locks until manual review by the security team. Database-level encryption secures data at rest, with separate encryption keys for personal data columns, financial fields, and identity document stores, each administered through a hardware security module that tracks every key access operation. Regular vulnerability scanning and annual penetration testing by an independent CREST-accredited security firm confirm the effectiveness of these controls, with critical findings remediated within 48 hours. Security incident response procedures are practiced through bi-annual tabletop exercises engaging the Data Protection Officer, with a documented breach notification workflow guaranteeing German players and the supervisory authority receive notification within the 72-hour deadline mandated by GDPR.
Třetím Důvody a právní základy pro zpracování
Incaspin Casino zpracovává personal data na základě několika různých GDPR právních základů, selected v závislosti na dané činnosti zpracování. Plnění smlouvy pursuant to Article 6(1)(b) GDPR covers veškeré zpracování údajů necessary pro vytvoření a správu účtu hráče, process deposits and withdrawals, a doručení the interactive gaming services které German players aktivně požadují během registrace. This zahrnuje zasílání platebních pokynů akvizičním bankám a kontrolu že players splňují the minimum age requirement osmácti let podle německého práva. Zpracování na základě právní povinnosti podle Article 6(1)(c) GDPR pokrývá anti-money laundering customer due diligence, suspicious transaction reporting příslušným finančním zpravodajským jednotkám, record retention k uspokojení požadavků obchodního a daňového práva, and compliance s německými herními předpisy ohledně norem ochrany hráčů. Relevantní právní rámce obsahují the Geldwäschegesetz a ustanovení of the Glücksspielstaatsvertrag pokud je to relevantní k mandátům uchovávání údajů.
Legitimní zájmy pursued by Incaspin Casino podle Article 6(1)(f) GDPR obsahují network and information security monitoring, fraud prevention and detection, direct marketing of similar products to existing customers tam, kde je to dovoleno podle Section 7 of the German Act Against Unfair Competition, a obchodní analýzy za účelem zlepšení služeb. German players mají nezpochybnitelné právo odmítnout zpracování na základě oprávněných zájmů, včetně vytváření profilů pro účely přímého marketingu, a tyto námitky budou ctěny bez zbytečného odkladu. Povolení podle Article 6(1)(a) GDPR is relied upon pro volitelné marketingové komunikace via email and SMS where the player has actively opted in, pro nasazení neesenciálních cookies a sledovacích technologií, a pro zpracování citlivých údajů za specifických okolností. Způsoby zrušení souhlasu jsou nápadně umístěny v nastavení účtu a v patičce každého marketingového sdělení, with withdrawal taking effect bez zpětných důsledků for previously lawful processing. German players kteří ještě nedosáhli osmácti let nesmějí otevírat účty, a veškerá omylem sebraná data nezletilých je ihned po odhalení odstraněna.
Pátý bod: International Data Transfers
The core data storage infrastructure for Incaspin Casino resides within secure facilities located in the European Economic Area, specifically configured to serve the German market with latency-optimised connectivity while maintaining full GDPR jurisdictional coverage. Some specialised processing activities may involve international data transfers to countries outside the EEA, including fraud detection services operating from certified facilities in third countries and customer support continuity arrangements during peak demand periods. For every such transfer, Incaspin Casino implements the safeguards mandated by Chapter V of the GDPR. Standard contractual clauses approved by the European Commission form the foundational transfer mechanism for processor relationships, with supplementary technical and organisational measures implemented where the recipient country lacks an adequacy decision from the European Commission. German players should understand that supplementary measures include complete encryption of data in transit and at rest using AES-256 standards, strict key management policies that prevent the foreign processor from accessing plaintext data, and contractual obligations requiring the processor to challenge any government access request and notify Incaspin Casino immediately when legally permitted. Transfer impact assessments are conducted prior to onboarding any non-EEA processor and are reviewed whenever the legal landscape of the recipient jurisdiction changes materially. The Data Protection Officer maintains a current register of all international transfers, which is made available to the competent German data protection authority upon request and can be summarised for data subjects who want to know the geographical flow of their information.
4. Data Sharing and Third-Party Recipients
4.1 In-House Data Access Model
Inside the Incaspin Casino operational framework, personal data access follows a strict least-privilege model applied across four distinct personnel tiers. Customer support agents view basic account information and communication history but cannot view full financial records or identity documents. Compliance officers possess permissions to inspect verification documents, transaction patterns, and risk scores. Financial department personnel manage withdrawal requests and view payment instrument details needed to execute transfers. IT security staff monitor system logs and security event data but do not typically interact with player-identifiable records. Every access event is logged with a timestamp, user identifier, and purpose code, creating an immutable audit trail that is examined quarterly by the Data Protection Officer. German players are able to request a copy of the access log entries pertaining to their account by submitting a subject access request through the designated privacy channel.
4.2 External Service Providers and Authorities
Incaspin Casino utilizes specialist external processors such as cloud hosting providers managing ISO 27001-certified data centres in the European Economic Area, payment processors authorised by the German Federal Financial Supervisory Authority, identity verification services that compare submitted documents against authoritative databases, email delivery platforms for transactional communications, and CRM software vendors for customer engagement analytics. Each processor passes through a rigorous vendor assessment addressing technical security measures, sub-processor transparency, international transfer safeguards, and business continuity capabilities. Contracts stipulate data processing solely on documented instructions from Incaspin Casino, with no right for the processor to repurpose data for its own objectives. Regulatory disclosures to German law enforcement agencies, tax authorities, or gambling regulators occur only when legally mandated, and unless prohibited by law, the casino will inform affected players of such disclosures. The following key principles control all third-party data sharing arrangements:
- Processors get only the least personal data required to perform their specified function, with field-level data minimisation implemented to every integration.
- Sub-processor engagements demand prior written authorisation from Incaspin Casino, and any unapproved subcontracting forms a material breach of the data processing agreement.
- All processors must hold ISO 27001 certification or equivalent independently audited security credentials, with current records filed with Incaspin Casino before data flows commence.
- No personal data is disclosed to advertising technology platforms, data brokers, or any entity whose primary business focuses on monetising personal information.
Six. Information Archiving and Deletion Guidelines
Incaspin Casino implements a precise data retention schedule intended to satisfy statutory record-keeping requirements while minimising the storage of personal data beyond its useful purpose. Player account data and entire transaction logs are stored for the complete length of the active business relationship, defined as the time from account creation until the account is closed, plus an extra statutory retention term required by German anti-money laundering legislation and commercial law. Under the Geldwäschegesetz, identification records, transaction confirmations, and due diligence papers must be maintained for at least five years from the end of the calendar year in which the business relationship concluded. Accounting records applicable to tax obligations are stored for ten years in compliance with the German Fiscal Code. Following the conclusion of these mandatory terms, personal data is either irrevocably anonymised so that re-identification becomes impracticable with all means reasonably expected to be used, or reliably erased through cryptographic erasure and physical storage media sanitisation processes. Technical logs and security event data adhere to a shorter retention cycle of twelve months, after which they are combined into anonymised statistical summaries. Inactive accounts demonstrating no login activity for a unbroken period of 24 months are designated for dormancy assessment, and the connected personal data is minimised to store only the core name and transaction records necessary for the leftover statutory retention clock. The casino deploys automated data lifecycle management processes that execute weekly to locate records beyond their retention thresholds, initiating deletion procedures without human input, with the results recorded for compliance audit reasons.
Two Groups of Individual Data Gathered
2.1 Identity Verification and Account Data
German players must supply specific private data to create and sustain an living Incaspin Casino account. This class includes full statutory name, residential location, birth date, birthplace, nationality, and gender. For identity validation aims required under Germany’s anti-money laundering regulations, the casino collects government-issued identification papers such as copy of passport, national identity card scans, and residence permit papers. The program also records the document number, issuing body, expiry date, and a biometrical matching rating produced during the automated validation process. Home confirmation is done through recent utility bills, bank statements, or official communication that evidently presents the member’s full name, on-file location, and an creation day inside the previous three months. Incaspin Casino applies these validation prerequisites consistently to comply with the 4th and Fifth Anti-Money Laundering Directives as transposed into German law, making sure that each account satisfies the legal identification confidence level before any withdrawals are allowed.
Two Point Two Financial and Deal Data
Financial data encompasses all deposit records, including payment instrument data, masked card numbers, e-wallet account email addresses, bank account IBAN details for SEPA transfers, and cryptocurrency wallet addresses where applicable. Incaspin Casino retains complete transaction histories showing timestamps, amounts in EUR or equivalent cryptocurrency, processing statuses, and any intermediary payment processor references. Source of funds declarations and supporting documents such as payslips, tax returns, or business financial statements are collected when players exceed specific deposit thresholds or trigger enhanced due diligence procedures. This data is segregated in encrypted database tables with access confined to compliance personnel and senior financial officers. German players using Sofort, Giropay, or other local payment methods should be aware that the chosen payment provider will also process transaction data according to its own privacy policy, with Incaspin Casino receiving only the information necessary to credit the player account.
2.3 Technical and Behavioral Records

When German players log into the Incaspin Casino platform, the system captures technical identifiers including IP addresses, device types, operating system versions, browser fingerprints, screen resolutions, language settings, and mobile carrier details. Session data encompasses login timestamps, page navigation paths, game launches, bet amounts, win and loss records, and in-game feature activations. This technical corpus allows the casino to offer optimised gaming experiences, identify fraudulent activity patterns, and honour responsible gambling self-exclusion settings. Behavioural analytics measure betting frequency, average stake sizes, session duration, and deposit velocity to supply the responsible gambling algorithms that produce personalised risk alerts. All technical logs are anonymised where possible and stored separately from core identity records, with re-identification possible only through a carefully managed cryptographic lookup procedure available exclusively to the fraud and compliance teams under documented access justification.
Conclusion
Incaspin Casino has arranged its data protection system to fulfill the high standards demanded by German players and mandated by the GDPR and the BDSG-neu. From the initial collection of identity and contact details through to the conclusive deletion or anonymisation of records years after account closure, every personal data life cycle stage functions under recorded policies, contractual safeguards, and technical controls that are regularly audited and improved. The casino preserves transparent communication channels for rights requests, supplies granular cookie consent options, and limits data sharing to vetted processors and legally mandated disclosures. German players are urged to read this Privacy Notice alongside the general Terms and Conditions and the Responsible Gambling Policy available on the Incaspin Casino website, and to contact the Data Protection Officer with any questions about how their personal information is handled.
