Privacy Policy
Welcome to SpiniMax Casino (spinimax.me). Protecting your personal data is of the utmost importance to us. Below, we inform you in detail about how we collect, process, and protect your data when you use our website and our online gambling services. This privacy policy has been drawn up in accordance with the UK General Data Protection Regulation (UK GDPR), the Data Protection Act 2018 (DPA 2018), and the specific regulatory requirements set by the Gambling Commission for players resident or ordinarily resident in the United Kingdom.
Data Controller
The data controller responsible for the processing of personal data on this website within the meaning of the UK GDPR and other national data protection laws is:
- SpiniMax Casino.
- Domain: spinimax.me.
- Email Address: [email protected].
If you have any questions, suggestions, or wish to exercise your data subject rights, you can contact our Data Protection Officer at any time via the email address provided.
Principles of Data Processing
We process personal data of our users only to the extent necessary to provide a functional website as well as our content and services (in particular secure online gambling, payment transactions, and player protection). The processing of personal data is regularly carried out only with the user's consent or if processing is permitted by statutory provisions.
Collection and Processing of Personal Data
3.1 Registration and Account Opening
When you register at SpiniMax Casino, we collect various data that are strictly necessary for the opening and management of your user account. These include:
- First and last name.
- Date of birth and place of birth;.
- Residential address (street, house number, postcode, city, country).
- Email.
- Telephone.
- Proof of identity and age (e.g, identity documents as part of the KYC โ Know Your Customer process).
Licence and supervision
This site operates under an Anjouan licence and is not regulated by the UK Gambling Commission.
- Identity and Age Verification: To prevent underage gambling and protect against fraud, we cross-reference your data with external credit reference agencies and verification services.
- Integration with Self-Exclusion Systems and Limits: To protect against problem gambling and comply with regulatory requirements (such as deposit limits and central self-exclusion schemes like GAMSTOP), we process and transmit data to corresponding central registries and monitoring systems within the legally mandated framework. Note that this scheme does not cover this site: registering with it does not block an account here.
3.3 Payment Data and Transactions
For deposits and withdrawals, we collect and process transaction-related data. Secure payment methods common in the United Kingdom (such as debit cards, bank transfers, PayPal, Apple Pay, or other verified payment service providers) require the processing of payment details. In accordance with anti-money laundering regulations, payments may generally only be processed via accounts and payment services held in your own name.
3.4 Automatically Collected Data (Log Files)
With every visit to our website spinimax.me, our system automatically collects data and information from the computer system of the accessing device. This includes:
- IP address of the accessing.
- Date and time of access.
- Name and URL of the retrieved file.
- Website from which access is made (referrer URL).
- Browser used and operating system of your device, as well as the name of your access.
The temporary storage of the IP address by the system is necessary to enable the delivery of the website to the user's computer. Storage in log files is carried out to ensure the functionality of the website and to protect against attacks on our IT systems.
Legal Bases for Processing (UK GDPR)
The processing of your personal data is based on the following legal grounds under the UK GDPR:
- Consent (Article 6(1)(a) UK GDPR): When you have given us voluntary consent to process your data (e.g, to receive promotional newsletters or optional marketing cookies).
- Performance of a Contract and Pre-contractual Measures (Article 6(1)(b) UK GDPR): Processing is necessary for the performance of the gambling contract, account maintenance, processing of stakes and winnings, and the handling of payments.
- Legal Obligation (Article 6(1)(c) UK GDPR): We are subject to numerous legal obligations (e.g, anti-money laundering laws, tax laws, Gambling Act regulations) that make the storage and verification of your data mandatory.
- Legitimate Interests (Article 6(1)(f) UK GDPR): Processing may be necessary to protect our legitimate interests or the interests of a third party, provided that your fundamental rights and freedoms do not override those interests (e.g, fraud prevention, ensuring IT security, enforcement of legal claims).
Use of Cookies and Tracking Technologies
Our website spinimax.me uses cookies and similar tracking technologies to improve the user experience, ensure the functionality of the platform, and analyze traffic.
5.1 Types of Cookies
- Strictly Necessary Cookies: These are essential for the technical operation of the website and the casino account (e.g, for storing login sessions or security tokens). The platform cannot function properly without these cookies.
- Functional Cookies: These allow us to remember your preferences and settings (such as language or region) to provide you with a more convenient service.
- Analytical and Performance Cookies: These help us understand how visitors interact with our website by collecting and reporting information anonymously. This serves the continuous optimization of our offerings.
- Marketing and Advertising Cookies: These are used to display relevant advertising tailored to your interests. They are only set with your explicit consent.
5.2 Consent and Management
Upon your first visit to our website, you will be prompted via a cookie banner to set your preferences regarding non-essential cookies. You can revoke or adjust your consent at any time with effect for the future via the cookie settings on our website.
Disclosure of Data to Third Parties
Your personal data will not be transmitted to third parties for purposes other than those listed below. We only share your data if:
- You have given your explicit consent to do so (Article 6(1)(a) UK GDPR).
- Disclosure is necessary for the establishment, exercise, or defense of legal claims, and there is no reason to assume that you have an overriding legitimate interest in the non-disclosure of your data (Article 6(1)(f) UK GDPR).
- There is a legal obligation to disclose data (Article 6(1)(c) UK GDPR), in particular to competent regulatory authorities, HM Revenue & Customs (HMRC), or law enforcement agencies, or.
- This is legally permissible and necessary for the execution of contractual relationships with you (Article 6(1)(b) UK GDPR), for example to payment service providers, identity verification service providers, IT service providers, or fraud prevention agencies.
If service providers act on our behalf (data processors), they are contractually bound under strict terms pursuant to Article 28 UK GDPR to process your data exclusively in accordance with our instructions and applicable data protection laws.
International Data Transfers
Should we transfer data to countries outside the United Kingdom or the European Economic Area (EEA) โ so-called third countries โ we ensure that an adequate level of protection is guaranteed. This is achieved either through adequacy regulations issued by the UK government, the use of standard contractual clauses, or other appropriate and legally recognized safeguards.
Retention Period and Deletion of Data
We store your personal data for as long as necessary to fulfill the purposes set out in this privacy policy or as required by statutory retention periods.
- Contract and Gaming Data: Following the closure of your player account, your data will be blocked for the duration of statutory retention periods (in particular under company and tax laws, as well as anti-money laundering regulations, which stipulate retention periods of up to 5 to 10 years) and deleted irrevocably once these periods have expired.
- Player Protection and Exclusion Data: Data relating to player protection and voluntary or regulatory self-exclusions are retained in accordance with gambling regulations for the legally mandated duration to ensure the protection of vulnerable players.
Your Rights as a Data Subject
As a data subject, you have comprehensive rights under the UK GDPR, which you can assert against SpiniMax Casino at any time. An informal notification by email to our support address: [email protected] is sufficient to exercise your rights.
- Right of Access (Article 15 UK GDPR): You have the right to request confirmation as to whether we are processing personal data concerning you, and access to that data, along with further information (e.g, processing purposes, categories of processed data, recipients).
- Right to Rectification (Article 16 UK GDPR): You have the right to request the immediate correction of inaccurate or completion of incomplete personal data stored by us.
- Right to Erasure / "Right to be Forgotten" (Article 17 UK GDPR): You can request the deletion of your personal data provided that the statutory requirements are met (e.g, if the data is no longer necessary for the purposes for which it was collected). Please note that this right may be restricted if statutory retention obligations (e.g, under anti-money laundering or gambling legislation) prevent immediate deletion.
- Right to Restriction of Processing (Article 18 UK GDPR): Under certain conditions, you have the right to request the restriction of the processing of your personal data.
- Right to Data Portability (Article 20 UK GDPR): You have the right to receive your personal data that you have provided to us in a structured, commonly used, and machine-readable format, or to request transmission to another controller.
- Right to Object (Article 21 UK GDPR): You have the right to object, on grounds relating to your particular situation, at any time to the processing of personal data concerning you which is based on Article 6(1)(e) or (f) UK GDPR.
- Right to Withdraw Consent (Article 7(3) UK GDPR): You can withdraw consent you have once given to process your data at any time with effect for the future.
- Right to Lodge a Complaint with a Supervisory Authority (Article 77 UK GDPR): If you believe that the processing of your personal data infringes the UK GDPR, you have the right to lodge a complaint with a data protection supervisory authority, in particular in the UK member state of your habitual residence, place of work, or place of the alleged infringement.
Data Security
We implement appropriate technical and organizational security measures in accordance with Article 32 UK GDPR to protect your personal data against accidental or intentional manipulation, loss, destruction, or unauthorized access by third parties. Our security measures, such as the use of modern SSL/TLS encryption technologies, are continuously improved in line with technological developments.
Currency and Amendments to This Privacy Policy
This privacy policy is currently valid and has the status of July 2026. Due to the further development of our website and services, or due to changed statutory or regulatory requirements, it may become necessary to amend this privacy policy. The most current version can be viewed at any time on our website at spinimax.me.