This policy explains how personal data is collected, processed and protected for anyone registering or playing on the platform, in line with the General Data Protection Regulation (GDPR) and Italian data protection law. Using the Postepay online casino platform means accepting the practices described below, alongside the data protection principles set by the Garante per la Protezione dei Dati Personali. Where a specific provision of Italian law sets a higher standard of protection, that provision applies over general terms stated here.
The operator acts as the data controller for all personal information collected through registration, gameplay and payment processing. This policy covers data gathered directly from players, data generated through platform activity, and data received from third parties such as payment providers or identity verification services. It applies to every account, regardless of which payment channel is used to fund it, including accounts set up through a casino that accept Postepay as their primary funding method.
The following types of information get collected and processed during normal use of the platform:
Financial data tied to an account funded through an online Postepay casino payment channel is retained under the same rules as any other method, without additional data sharing beyond what's needed for transaction processing.
Personal data gets processed under several legal bases recognized by GDPR, and each purpose is tied to a specific justification.
Purpose | Legal Basis | Data Involved |
|---|---|---|
Account registration and login | Contract performance | Identity, contact data |
Identity verification (KYC/AML) | Legal obligation | Identity, financial data |
Processing deposits and withdrawals | Contract performance | Financial data |
Fraud prevention and security monitoring | Legitimate interest | Technical, behavioral data |
Marketing communications | Consent | Contact data |
Regulatory reporting to gambling authorities | Legal obligation | Identity, financial, behavioral data |
| Legal Basis | Contract performance |
|---|---|
| Data Involved | Identity, contact data |
| Legal Basis | Legal obligation |
|---|---|
| Data Involved | Identity, financial data |
| Legal Basis | Contract performance |
|---|---|
| Data Involved | Financial data |
| Legal Basis | Legitimate interest |
|---|---|
| Data Involved | Technical, behavioral data |
| Legal Basis | Consent |
|---|---|
| Data Involved | Contact data |
| Legal Basis | Legal obligation |
|---|---|
| Data Involved | Identity, financial, behavioral data |
Consent-based processing, such as promotional emails, can be withdrawn at any time without affecting the ability to use core account functions.
Data tied to a verified account is kept for as long as the account remains active, plus an additional period required by Italian anti-money laundering regulation, typically ten years from account closure. Transaction records associated with a Postepay online casino payment method follow the same retention schedule as any other funding channel, since regulatory reporting requirements apply uniformly across all payment types. Technical logs used for security monitoring are generally retained for a shorter period, unless they're relevant to an active investigation or dispute.
Personal data is shared only where necessary to operate the platform or meet a legal obligation. Recipients typically include:
No personal data is sold to third parties for their own marketing purposes.
Where data is transferred outside the European Economic Area, such as to a cloud hosting provider located in a third country, the transfer relies on Standard Contractual Clauses approved by the European Commission or an equivalent adequacy mechanism. Players can request details of the specific safeguards applied to their data by contacting the data protection team listed below.
Postepay online casino applies encryption to data in transit and at rest, restricts internal access to personal data on a need-to-know basis, and monitors systems for unauthorized access attempts. Payment data is processed in line with PCI DSS standards where applicable, regardless of whether the transaction runs through a card, an e-wallet or the platform's own transfer system. Any confirmed data breach affecting personal information is reported to the Garante and, where required, to affected users, within the timeframe set by GDPR.
Anyone with an account has the following rights regarding their personal data:
At online Postepay casino, requests can be submitted through the account settings page or directly to the data protection contact, and are typically processed within 30 days.
The platform uses cookies to maintain login sessions, remember account preferences and analyze site performance. Essential cookies required for core functionality don't require separate consent, while analytics and marketing cookies are only activated after explicit opt-in through the cookie banner. Cookie preferences can be changed at any time from the account or browser settings.
Any concern about how personal data is handled can be raised directly with the data protection team through the contact details listed in the account dashboard. If a concern isn't resolved satisfactorily, a complaint can be filed with the Garante per la Protezione dei Dati Personali, the competent authority for data protection matters in Italy. This right exists independently of any internal complaint process offered by the operator.
This policy may be updated periodically to reflect changes in applicable law or Postepay online casino functionality. Material changes are communicated through the registered email address on file, with a notice period before the revised policy takes effect. Continued use of the account after that notice period counts as acceptance of the updated terms.