Rolletto Privacy Policy
Rolletto is committed to handling your personal data with transparency and care. This privacy policy describes what information we collect from you, why we collect it, how we use it, and what control you have over it. We operate in full compliance with UK GDPR and the Data Protection Act 2018.
What Personal Information We Collect
When you register an account with Rolletto, you provide us with basic personal information: your name, date of birth, email address, postal address, and phone number. This is needed to set up your account, verify your identity, and communicate with you about your account and our services.
We collect identity verification documents — such as a passport, driving licence, or utility bill — when required by UK Gambling Commission regulations. These are used solely to confirm your age, identity, and address, and are stored securely in encrypted form.
Financial information is collected when you make deposits or request withdrawals. This includes your payment method details, transaction amounts, and timing. We use this to process your payments accurately and to comply with anti-money laundering obligations.
We also collect technical data automatically — your IP address, device type, browser, and behaviour on our platform. This information helps us keep the platform secure and improve the user experience.
Legal Bases for Processing
Rolletto processes your personal data under several legal bases depending on the purpose: the performance of a contract (providing the gaming service you've registered for), compliance with legal obligations (regulatory requirements under our UK Gambling Commission licence), legitimate interests (fraud prevention and platform security), and consent (marketing communications, which you may withdraw at any time).
How We Share Your Information
Rolletto does not sell your personal data. We share information only where necessary: with payment processors to handle your transactions, with identity verification providers to fulfil our KYC obligations, and with regulatory authorities and law enforcement agencies where required by law. All third parties who receive your data are required by contract to protect it and use it only for the purposes we specify.
International Transfers
Some of our service providers operate outside the UK. Where your data is transferred internationally, we ensure that appropriate safeguards are in place, such as Standard Contractual Clauses approved by the UK Information Commissioner's Office, to maintain the same level of protection as applies in Great Britain.
Retention of Your Data
We retain your account data for a minimum of five years following closure of your account, as required by UK anti-money laundering legislation. Gaming records and financial transaction data may be retained for longer periods where required for regulatory compliance. When data is no longer needed, it is securely and permanently deleted.
Your Rights
Under UK GDPR, you have the right to access the personal data we hold about you, correct any inaccuracies, request deletion (where no legal obligation requires us to retain it), object to processing based on legitimate interests, and request portability of your data. To exercise these rights, contact us at [email protected].
You have the right to lodge a complaint with the Information Commissioner's Office (ICO) if you believe your data has not been handled appropriately. The ICO can be contacted at ico.org.uk or by calling 0303 123 1113.
We review this privacy policy periodically and will update it as our practices evolve. Changes will be published on this page and, where significant, communicated to you directly.
