At Trino Casino, we run trinoo https://trinoo.de/legal-and-affiliates/.de and we assume protecting the personal data of our German players conscientiously. As a licensed entertainment platform, we’ve established our operations to fulfill the strict standards of the General Data Protection Regulation (GDPR) and the German Federal Data Protection Act (BDSG). This document describes exactly how we gather, hold, handle, and protect your information when you use our website, engage in games, or engage with our affiliate systems. We hold transparency is essential for a trusting relationship. By presenting our data handling practices clearly, we aim you to remain confident that your sensitive financial details and personal identifiers are kept in a secure digital environment, managed by a responsible data controller that respects local laws and jurisdictional boundaries.
4. Data Retention Schedules and Data Masking Strategies
We do not retain your personal data forever. We follow a strict storage limitation principle. Active customer accounts hold data for the duration of the business relationship, from the moment you register until you formally close the account. After account closure, a holding period begins, driven mostly by German tax legislation and anti-money laundering rules. Transactional logs, identification documents collected under Know Your Customer protocols, and wagering history are securely archived for ten years from the end of the calendar year of the last transaction. Once that statutory retention window concludes, we permanently destroy or irreversibly anonymize the records so re-identification becomes technically impossible. Web server log data that contains IP addresses gets truncated after a strict thirty‑day cycle to reduce security risks. For accounts that go dormant—no activity but not closed—we send a proactive reminder before the dormancy threshold, so we can ask for renewed consent or start the deletion process, always in line with the storage limitation principle.
2. Categories of User Information Obtained During Registration and Playing
To provide a flawless entertainment experience that satisfies German regulations, we obtain a few certain categories of personal data, only what’s really needed. weiterführende Informationen During account creation, we ask for identification details: your legal first and last name, residential address with postal code, verified email address, and date of birth to make sure you fulfill the strict age minimum set by German regulators. When you start playing, we process financial transaction data—deposit amounts, withdrawal methods, partial payment card numbers encrypted with TLS, and e-wallet identifiers. Our systems capture technical device data like your IP address, which we geo-filter to confirm you’re in a permitted location, along with browser fingerprint hashes and operating system specs. We also monitor usage patterns and game session logs, documenting bet history and time spent playing, so we can fulfill our responsible gaming obligations. We do not obtain special categories of sensitive data unless you willingly give that information during a responsible gaming self-assessment or a support inquiry.
3. Detailed Processing Activities Pertaining to the Affiliate Programme
Our affiliate network, available on our legal and affiliates hub, functions as a separate data processing area. We act as a joint controller together with our marketing partners. When a German webmaster or content creator signs up for our partner program, we gather business details like tax identification numbers, bank account information for paying commissions, and traffic source analytics. Our tracking mechanism utilizes first‑party cookies dropped via a unique affiliate link, which enables us to attribute referred traffic to the correct partner account without capturing the browsing history of unregistered visitors. We process referred player data in a pseudonymized format for commission calculation, so the affiliate sees aggregated performance numbers rather than individual player identities. We review player activity logs against traffic sources to catch bonus abuse or fake incentivized traffic; this is grounded in our contractual and legitimate business interests. We have a strict affiliate code of conduct that prohibits partners from targeting self-excluded individuals or using unauthorized direct marketing that could jeopardize the privacy expectations of the German audience.
7. Cookie Administration and Monitoring Technologies for Regulatory Compliance
Our website employs different digital markers, and our consent management system ensures that no non-essential tracking tools https://www.ots.at/pressemappe/11739/evolaris-next-level-gmbh/seite/2 activate until a user in Germany gives active consent through our detailed preference center. Required session cookies, which don’t store private data but keep your game session and security keys working, are exempt from approval requirements under the ePrivacy Regulation as applied in German law. For continuous analytics and partner attribution cookies, we use backend tagging where practicable to minimize browser-side exposure. Our partner tracking pixel operates on a first-party data model to work around current browser restrictions, enabling accurate commissioning without intrusive fingerprinting scripts that are forbidden under German internet law. We’ve classified all tracking codes with thorough explanations of their intent, timeframe, and the third‑party vendors included, so you can change your settings at any time. Rejecting marketing cookies does not impair the performance of the gaming lobby or payment gateways. That reflects our data-protection approach: basic services are fully accessible irrespective of permission decisions you choose.
6. Applying Your personal Entitlements Pursuant to German legal and European Union Law
For residents of Germany, you possess a collection of prerogatives that we keep simple to exercise. You are able to lodge a personal data inquiry at any moment. We then have to confirm whether we process your information and supply you with a version in a organized, widely adopted, machine‑readable layout within 30 days. The right to rectification lets you update obsolete or incorrect profile details without delay, which is vital for seamless payment operations. Under certain circumstances, you can demand a limitation of operations, notably if you challenge the correctness of data while we confirm it. The right to erasure, often called the “right to be forgotten,” applies when the data is no longer required for the original objective, though legal retention obligations may momentarily supersede this demand. You additionally possess the right to information portability for details provided under consent or contract, so you are able to shift your activity log to a different provider. You have an absolute right to object to direct marketing, and you can object to operations based on lawful interests, which we’ll evaluate against our legitimate compelling grounds. Appeals can be lodged straight with the data oversight body of your German state if you think a infringement has happened.
1. Určení správce údajů a právní důvod zpracování
We act as the data controller for all personal details collected through Trino Casino at trinoo.de, which is customized for German users. Our legal team operates from a registered office inside the European Economic Area, making us fully bound by GDPR enforcement. When handling your data, we rely on six established lawful bases. In most cases, we process your data to meet our contractual duties—such as accepting bets, handling withdrawals, and maintaining your account. We also employ legitimate interest for analytics and security actions, including fraud detection algorithms and network integrity checks, as long as these do not outweigh your fundamental rights and freedoms. Where legislation requires it, especially under anti-money laundering laws and German gambling ordinances, processing is carried out due to a legal duty. For marketing communications, including our affiliate program, we depend on your explicit consent, which you can revoke at any time without affecting the core services we offer.
Common Questions
How does Trino Casino confirm my age under German regulations?
We employ a comprehensive system: automated checks against national databases and manual document review. When you sign up, you must provide your national ID card or passport through an encrypted portal. Our compliance team checks this with the Schufa identity service to confirm legal age. If something does not align, we briefly restrict the account until a video identification call with a certified agent can clear things up, all in line with the German Interstate Treaty on Gambling.
Will my personal data be disclosed with the affiliate who recommended me?
No. Our affiliate programme operates with a strict aggregation firewall. We do not share your name, contact details, or payment records with the referring affiliate. The partner only views a pseudonymized dashboard with confirmed registration counts and a statistical summary of net gaming revenue. Our affiliate agreements expressly prohibit them from attempting to identify individual players. This maintains your gameplay completely separate from the marketing channel that brought you to Trino Casino.
How can permanently revoke my marketing consent?
Go to “Communication Settings” in your account dashboard and turn off promotional channels. Every marketing email we send has a one‑click unsubscribe link at the bottom that works right away. To withdraw consent for postal mail or SMS, contact our Data Protection Officer through the support ticket system. We’ll stop direct marketing within at most 48 hours after receiving your request.
What transpires to my data if Trino Casino ceases operations?
If business ever stops, we are legally required to notify the competent German data protection authority and all active users in advance. Mandatory transactional logs and identification records will be securely transferred to a certified archival service or handed over to the responsible regulatory body for as long as the law demands. Any data that isn’t mandatory gets securely destroyed using cryptographic wiping techniques before the closure of our servers is finalized.
Will Trino Casino use automated decision-making for payments?
We use a limited automated profiling system to flag possible fraud or bonus abuse. If the system blocks a withdrawal, we’re required by law to involve a human. Our financial risk team manually checks every flagged transaction before we tell you the final decision. You can challenge that decision, give your side, and ask for a full manual review by our risk management specialists.
How can I get a complete record of my stored data?
Email us from the address linked to your account to our Data Protection Officer, include “SAR” in the subject line. We’ll confirm your identity with a two‑factor verification. Subsequently, we collect your data from all systems—chat logs, game history, identity documents—and generate a digitally signed PDF and a machine‑readable JSON file, which you’ll receive within one calendar month.
5. Global Transfers and System Protection Measures
Our principal data processing systems reside in protected data centers in the European Union, but sometimes we must utilize sub-processors in different countries. In these rare cases, we guarantee the equivalent degree of protection by implementing Standard Contractual Clauses endorsed by the European Commission, combined with a thorough Transfer Impact Assessment. To safeguard your financial data from unauthorized access during transfer, we enforce Transport Layer Security (TLS 1.3) encryption across all terminals, rejecting old cipher suites. At rest, personal data inside our managed database clusters is protected by AES‑256 encryption, and access to decryption keys is confined to a separate privileged access management system. We run ongoing vulnerability scans, mandatory penetration tests, and strict logical access controls so exclusively the individuals who need it can see your data. We maintain a appointed Data Protection Officer you can contact through our platform, and we maintain an incident response plan that requires us to notify the relevant German supervisory authority within 72 hours if a personal data breach could place your rights at risk.