Privacy Policy

Privacy Policy · AU

We guard your data like a fortress.

At WinSpirit Casino Australia, privacy is not a legal formality — it is an active commitment. This document is written in plain language so every player understands exactly how their personal information is handled.

Effective
15 Feb 2026

Operator
Complete Technologies N.V.

Licence
Curaçao GCB

Jurisdiction
Australia

🛡️

256-BIT SSL · APP PRINCIPLES
GDPR ALIGNED · PCI DSS

01 — Data Collection

What information we collect from you

Every piece of data we hold exists for a defined reason. Each card below shows what the data is used for.

🪪
Identity Data

Full name, date of birth, nationality, government-issued photo ID. Used exclusively to verify you are 18+, confirm your identity at KYC, and prevent fraud.

📬
Contact Data

Email address, mobile number, residential address. Used for account notifications, password resets, withdrawal confirmations, and regulatory correspondence.

💳
Financial Data

Payment tokens (not raw card numbers), transaction history, source of funds declarations. Required to process deposits, withdrawals, and comply with Australian AML legislation.

🖥️
Technical Data

IP address, browser type, device ID, session timestamps, gameplay logs. Used for platform security, fraud detection, responsible gambling monitoring, and performance improvements.

📋
Behavioural Data

Game history, session duration, wagering patterns, bonus usage. Used to personalise your experience, identify responsible gambling risk signals, and improve our game offering.

💬
Communications

Live chat transcripts, support emails, complaint records. Retained for quality assurance, dispute resolution, and regulatory compliance for up to 3 years post-account closure.

We never collect sensitive special categories of data — including racial or ethnic origin, political opinions, religious beliefs, trade union membership, genetic data, biometric data, health data, or sexual orientation.

02 — Data Lifecycle

How your data flows through our systems

From the moment you register to the day an account is closed, your data follows a controlled, audited lifecycle.

STAGE 01
📝
Registration
You provide email, password, name and DOB via encrypted TLS 1.3 form submission

STAGE 02
🔍
KYC Verification
ID documents passed to accredited KYC partner, encrypted at rest, processed within 4hrs

STAGE 03
🎮
Active Play
Session data, game logs, and transactions collected with role-based access controls

STAGE 04
📊
Processing
Payments handled by PCI DSS L1 processors. WinSpirit stores only tokenised references

STAGE 05
🔒
Closure
Account closed; data retained per legal minimums then securely deleted or anonymised

03 — Legal Basis

Why we process your data and on what legal grounds

Australian Privacy Principles and international data protection frameworks require every use of personal data to have a documented lawful basis.

Processing Purpose
Legal Basis
Data Involved

Account registration & login management
Contract
Identity, contact, credentials

Processing deposits and withdrawals
Contract
Financial, identity

KYC identity verification (AML)
Legal Obligation
Identity docs, financial records

Age verification — 18+ only
Legal Obligation
Date of birth, photo ID

Fraud prevention & account security
Legitimate Interests
Technical, behavioural, financial

Responsible gambling monitoring
Legitimate / Legal
Gameplay patterns, session data

Customer support & dispute resolution
Legitimate Interests
Communications, account data

Promotional emails & bonus offers
Consent (opt-in)
Contact data, game history

Platform analytics & improvements
Legitimate Interests
Anonymised technical & behavioural data

Where we rely on legitimate interests, we have conducted a balancing test confirming that our interests do not override your fundamental rights or freedoms. You may request a copy of this assessment at any time.

04 — Data Sharing

Third parties who may receive your data

We share data only when operationally necessary or legally required — never for third-party advertising revenue.

Payment Processors
MiFinity, Neosurf, Flexepin, Crypto networks

Receive only the minimum necessary to complete your transaction. All are PCI DSS Level 1 certified. WinSpirit retains only tokenised payment references — never raw card data.

KYC / AML Providers
Accredited identity verification partners

Your identity documents are transmitted securely to verify you against official databases. Documents are not retained by the KYC provider beyond the verification period.

Game Providers
Pragmatic Play, Evolution, NetEnt, BGaming et al.

Anonymised session tokens only — not your name, address, or financial data. Used for RNG integrity, game logging, and progressive jackpot management.

Regulatory Bodies
Curaçao Gaming Control Board & law enforcement

Disclosed only when required by valid legal order or regulatory directive. Limited strictly to data specified in the request.

Our firm commitment

We never sell your personal data to marketers, data brokers, or any third party for commercial gain.

We never share data with social networks or advertising platforms without explicit consent.

Every third party has a signed Data Processing Agreement aligned with Australian Privacy Act requirements.

International transfers are protected by Standard Contractual Clauses or adequacy decisions.

05 — Cookies

Cookies & tracking: what’s on and what’s your choice

We use four categories of cookies. Essential cookies cannot be disabled — everything else is your choice.

Essential
Login session management, account security tokens, CSRF protection, geo-restriction enforcement, and platform integrity monitoring. These are required for the site to function at all.

Always on

Analytics
Anonymised data on pages visited, error rates, game loading times, and device performance. Helps us fix bugs faster and improve the experience for all AU players.

Optional

Functional
Remembers your preferred language, display theme, game sort order, and table limits. Without these cookies, you will need to set your preferences on every visit.

Optional

Marketing
Set in partnership with advertising networks to measure the effectiveness of our promotional campaigns and show relevant bonus offers. Full opt-out available at any time.

Off

Manage your actual cookie settings at any time via Account → Privacy Settings.

06 — Security

Six layers of protection around your data

Security is not a single measure. WinSpirit deploys a layered defence architecture designed so that failure at any single layer does not expose your personal data.

🔐
TLS 1.3 + AES-256 Encryption

All data in transit is protected by TLS 1.3 — the current gold standard. Sensitive data stored at rest is encrypted with AES-256, including all KYC documents and financial records.

👤
Role-Based Access Control

Only authorised personnel with a documented business need can access personal data. Access is logged, time-limited, and reviewed quarterly by our security team.

👁️
24/7 Real-Time Monitoring

Automated anomaly detection scans account activity around the clock. Unusual login locations, rapid balance changes, or device switching trigger immediate security review.

💳
PCI DSS Level 1 Payments

No raw payment card data is ever stored on WinSpirit servers. All payment processing is delegated to PCI DSS Level 1 certified processors who maintain their own audit programmes.

🧪
Penetration Testing

Independent security audits and penetration tests are conducted on a regular schedule. Critical findings must be remediated within 72 hours under our security SLA.

📣
Breach Notification Protocol

In the event of a data breach, you will be notified without undue delay. We follow OAIC notification requirements and will clearly explain what happened and what to do.

07 — Retention Periods

How long we hold each type of data

Data is held only as long as legally required or operationally necessary. After expiry, it is securely deleted or irreversibly anonymised.

Financial & AML records
7 years

KYC documents
5 years

Account & identity data
5 years

Support communications
3 years

Marketing consent logs
Until withdrawn

Analytics & log data
13 months

Session cookies
Session end

Retention periods for financial records are fixed by Australian anti-money laundering regulations and cannot be shortened even upon your request. All other data beyond these minimums is deleted at account closure.

08 — Your Rights

Privacy rights you can exercise at any time

Under Australian Privacy Principles, you have the following rights. Contact our Privacy Officer to submit any request.

Right to Access

Request a complete copy of all personal data we hold about you. We provide this in a structured, readable format within 30 calendar days at no cost for the first request each year.

Right to Correction

Have inaccurate or out-of-date personal data corrected. Changes to KYC-verified fields such as name or date of birth require fresh supporting documentation.

Right to Erasure

Request deletion of your personal data where we have no remaining legal obligation to retain it. AML law requires retention of financial records for up to 7 years regardless.

Right to Data Portability

Where we process your data by automated means on the basis of consent or contract, request it in a machine-readable format for transfer to another service.

Right to Restrict Processing

Ask us to pause or limit processing of your data — for example while you contest its accuracy or object to the purpose for which it is being used.

Right to Object

Object to processing based on legitimate interests — including profiling for personalised recommendations. We will cease unless we can demonstrate compelling grounds.

Right to Withdraw Consent

Withdraw marketing consent at any time via Account → Communication Preferences, or by emailing [email protected]. Does not affect core account functionality.

Right to Lodge a Complaint

If you believe we have mishandled your personal data, you may lodge a complaint with the Office of the Australian Information Commissioner (OAIC) at oaic.gov.au.

All rights requests are responded to within 30 calendar days. Requests are free of charge for the first instance per calendar year. We verify your identity before processing any request.

09 — Child Protection

Protecting minors

WinSpirit is strictly for players aged 18 and over. We do not knowingly collect data from anyone under 18. Age is verified at registration and confirmed by government photo ID prior to any withdrawal.

If a minor’s account is discovered, the account is closed immediately. All associated funds are forfeited, and all personal data is permanently deleted from our systems.

Suspect a minor has registered? Email [email protected] immediately. We investigate all such reports within 24 hours.

10 — International Transfers

Cross-border data flows

Complete Technologies N.V. is incorporated in Curaçao. Our service providers operate across multiple jurisdictions, including the EU, UK, and US. Your data may be transferred internationally as part of normal operations.

Every international transfer is protected by one of the following safeguards:

EU Standard Contractual Clauses (SCCs)
European Commission adequacy decisions
Equivalent data protection frameworks

11 — Policy Updates

How we notify you when this Policy changes

We review this Privacy Policy at least annually, and whenever there is a material change to how we process personal data.

Minor Changes
Formatting & contact updates

Updated silently. The effective date on this page is revised. No advance notice required.

Material Changes
New purposes or new third parties

Email notification to your registered address at least 14 days before the change takes effect.

Consent-Required Changes
New consent-based processing

Explicit re-consent required before the new processing begins. You retain full ability to decline.

12 — Contact

Reach our privacy team

For any privacy concern, rights request, or data question — contact us. We aim to respond within 5 business days and are required to resolve all requests within 30 calendar days.

General Privacy Enquiries
Response within 5 business days

Data Protection Officer
For formal rights requests & OAIC matters

Registered Operator
Complete Technologies N.V.
Licensed by Curaçao Gaming Control Board

External Regulator
Office of the Australian Information Commissioner (OAIC)

If you are not satisfied with our response to a privacy complaint, you have the right to escalate to the OAIC free of charge at oaic.gov.au or by calling 1300 363 992.

Responsible Gambling

Gambling Help Online
1800 858 858
gamblinghelponline.org.au

© 2026 winspirit-casino-australlia.com · Privacy Policy · Last updated 15 February 2026. WinSpirit is operated by Complete Technologies N.V. and licensed by the Curaçao Gaming Control Board. This site is intended for Australian players aged 18 and over. Gambling involves financial risk — only gamble with money you can afford to lose.

18+ ONLY
AU Players

Baixar App