Effective Date: 20th May 2024
1. Introduction & Our Commitment to Your Privacy
Welcome to GemTrio.uk, the official website for the "Gem Trio" slot game, provided by Pragmatic Play. This Privacy Policy outlines how GemTrio Digital Ltd. ("we," "us," or "our"), as the operator of https://gemtrio.uk/, collects, uses, stores, and protects your personal data.
As a licensed gambling operator, we understand that your trust is paramount. We are committed to safeguarding your privacy and ensuring transparency in our data practices. We operate at the intersection of general data protection laws (such as the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018) and specific gambling regulations (including those from the UK Gambling Commission (UKGC) and other relevant authorities).
This policy is designed not only to meet our legal obligations but also to build and maintain your trust by clearly explaining how your information is handled, especially given the sensitive nature of online gambling and its classification as a 'Your Money Your Life' (YMYL) category by Google. We strive to be transparent, demonstrate our expertise, and assure you of our trustworthiness and commitment to responsible operations.
2. Key Highlights: Your Privacy at a Glance
We know legal documents can be lengthy. Here are the most important points about your privacy with GemTrio.uk:
- We collect data to provide the "Gem Trio" game experience, manage your account, process payments, and ensure fair and responsible gambling. This includes details like your account information, game activity (e.g., bets placed, wins/losses, features used like "Buy Free Spins"), and payment data.
- Your financial security is a top priority. We employ robust security measures and adhere to industry standards like PCI DSS for payment processing.
- We share data only when necessary with trusted partners like payment providers, game developers (Pragmatic Play), and regulatory bodies (UKGC) to operate our services, comply with laws, and prevent fraud.
- We are transparent about our use of analytics. We use Yandex.Metrica for web analytics, and we explain the implications of this international data transfer in Section 8.
- You have strong rights over your data under UK GDPR, including the right to access, correct, or delete your information.
- Responsible gambling is fundamental. We collect and use data to identify and support players at risk and comply with our responsible gambling obligations.
- We do not target minors. Our services are strictly for individuals aged 18 and over.
- This policy is a dynamic document. We will update it as regulations and our services evolve, and we'll always notify you of significant changes.
3. Who We Are (Data Controller)
For the purposes of the UK GDPR and the Data Protection Act 2018, GemTrio Digital Ltd. is the data controller responsible for your personal data collected via https://gemtrio.uk/.
4. What Information We Collect About You
We collect various types of information, depending on how you interact with our site and services.
4.1. Information You Provide Directly
When you register an account, make deposits, or contact us, you may provide:
- Identity Data: Full name, date of birth, gender.
- Contact Data: Postal address, email address, telephone number.
- Financial Data: Payment card details (processed securely by third-party payment providers, we do not store full card numbers), bank account details for withdrawals.
- Verification Data (KYC & AML): Copies of identification documents (e.g., passport, driving licence), proof of address (e.g., utility bill), source of funds/wealth information, as required by anti-money laundering (AML) regulations and UKGC licensing conditions.
- Communication Data: Records of your correspondence with us, including customer support queries, chat transcripts, and feedback.
- Responsible Gambling Data: Information related to any self-exclusion requests, deposit limits, time-out periods, or other responsible gambling tools you utilise.
- Marketing Preferences: Your choices regarding receiving marketing communications from us.
4.2. Information We Collect Automatically
As you interact with our website and the "Gem Trio" game, we automatically collect:
- Technical Data: Internet Protocol (IP) address, your login data, browser type and version, time zone setting and location, browser plug-in types and versions, operating system and platform, and other technology on the devices you use to access this website.
- Usage Data: Information about how you use our website and the "Gem Trio" game, including:
- Gameplay Activity: Bets placed (e.g., min $0.10 to max $250.00), wins/losses, game rounds played, features activated (e.g., "Buy Free Spins" options for 1, 2, or 3 modifiers), symbols matched (e.g., "777", "BAR", "WILD"), Free Spins triggered by "emerald," "diamond," or "ruby" symbols, bonus prizes (e.g., MINI 20x, MAJOR 300x), and game session duration.
- Performance Data: Return to Player (RTP) rates observed (e.g., base game 96.50%), volatility interactions, and game outcomes.
- Site Interaction: Pages viewed, time spent on pages, navigation paths, search queries, and interactions with buttons (e.g., "spin", "autoplay", "bet increase/decrease").
- Cookie Data: Information collected through cookies and similar tracking technologies (see Section 9).
- Affiliate Data: If you arrived at our site via an affiliate link, we may collect information about the referring source to track and attribute your referral for commission purposes. This typically involves non-personally identifiable unique identifiers.
4.3. Information from Third Parties
We may receive personal data about you from various third parties, including:
- Identity and Contact Data from publicly available sources (e.g., electoral roll) and identity verification services for KYC and AML checks.
- Financial and Transaction Data from payment service providers to process your deposits and withdrawals.
- Technical and Usage Data from analytics providers (like Yandex.Metrica), advertising networks, and search information providers.
- Game Provider Data: Data from Pragmatic Play (the "Gem Trio" provider) regarding your gameplay to ensure accurate record-keeping and game functionality.
5. How We Use Your Information (Purposes & Legal Bases)
We use your personal data only when we have a valid legal basis to do so. Most commonly, we will use your personal data in the following circumstances:
- To Perform Our Contract with You: This is necessary to provide you with access to the "Gem Trio" game and its features, manage your account, process your bets, wins, and withdrawals.
- To Comply with a Legal or Regulatory Obligation: This includes fulfilling our UKGC licensing conditions, AML obligations, responsible gambling duties, fraud prevention, and reporting to authorities.
- For Our Legitimate Interests: We rely on our legitimate interests (or those of a third party) where your interests and fundamental rights do not override those interests. This includes improving our services, ensuring network and information security, preventing fraud, and conducting business analysis.
- With Your Consent: Where you have given us explicit consent for a specific purpose, such as for certain marketing communications or non-essential cookies. You have the right to withdraw consent at any time.
Specific Use Cases:
- To provide and manage your account: We use your name, contact details, and account data to set up and maintain your account, verify your identity, and communicate with you about your account.
- To operate the "Gem Trio" game: We use your gameplay data (bets, wins, losses, features used) to run the game, calculate outcomes, and ensure fair play.
- To process transactions: We use your financial data to process deposits and withdrawals securely.
- To provide customer support: We use your communication data to respond to your inquiries and resolve any issues you may have.
- To comply with legal and regulatory obligations: We use your identity, contact, financial, and verification data to comply with AML laws, UKGC licensing conditions, and responsible gambling regulations. This includes monitoring for suspicious activity and reporting to relevant authorities.
- To ensure network and information security: We use technical data to protect our systems from cyber threats and fraud.
- To improve our website and services: We use technical, usage, and aggregated data to understand how users interact with our site and game, identify areas for improvement, and enhance the user experience.
- For marketing and promotional purposes: With your consent, we may use your contact and communication data to send you updates, offers, and promotions related to "Gem Trio" or other games.
- To manage our affiliate programs: We use affiliate data to track referrals and process commissions, ensuring transparency and compliance with advertising standards.
6. Sharing Your Information
We may share your personal data with the following categories of recipients for the purposes outlined above:
- Game Providers: We share necessary gameplay data with our game provider, Pragmatic Play, to ensure the smooth operation of the "Gem Trio" game, verify game outcomes, and facilitate any necessary technical support.
- Payment Processors: Your financial data is shared with trusted third-party payment service providers to securely process your deposits and withdrawals. These providers are PCI DSS compliant.
- Regulatory and Law Enforcement Authorities: We are legally obliged to share your data with the UK Gambling Commission (UKGC), the Information Commissioner's Office (ICO), and other relevant regulatory bodies, as well as law enforcement agencies, courts, and other governmental authorities, when required by law or to investigate potential illegal activities.
- Identity Verification and AML Service Providers: We share identity and verification data with third-party providers to perform Know Your Customer (KYC) and Anti-Money Laundering (AML) checks, as legally required.
- Responsible Gambling Organisations: In cases of self-exclusion or concerns about problem gambling, we may share relevant data with organisations dedicated to responsible gambling support, such as GamCare or GAMSTOP, to protect vulnerable players.
- IT and Technical Service Providers: We use third-party providers for hosting, maintenance, data analytics (e.g., Yandex.Metrica), and other technical services necessary to operate our website and game.
- Professional Advisors: Our lawyers, auditors, and insurers may need access to relevant data in the course of providing their services to us.
- Affiliate Partners: If you were referred to us through an affiliate program, we may share anonymised or pseudonymised data with our affiliate partners to track the effectiveness of their referrals and calculate commissions. This data does not directly identify you.
We ensure that all third parties with whom we share your data are contractually obligated to protect your data to the same standards as set out in this Privacy Policy and in compliance with UK GDPR.
7. International Data Transfers
Some of our third-party service providers may be based outside the UK or the European Economic Area (EEA), meaning your personal data may be transferred to and stored in countries with different data protection laws.
Specific Disclosure: Yandex.Metrica (Russia)
We use Yandex.Metrica for web analytics services. Yandex.Metrica is provided by Yandex LLC, a company based in Russia.
Important Note on Data Transfers to Russia: The UK government has not issued an adequacy decision for Russia, meaning it does not currently consider Russia to provide an equivalent level of data protection to the UK. This implies that the legal protections for your personal data in Russia may not be as robust as those under UK GDPR.
Our Approach & Safeguards:
- Consent: We rely on your explicit consent for the use of Yandex.Metrica. You can manage your cookie preferences and withdraw consent at any time through our cookie consent tool.
- Anonymisation/Pseudonymisation: Where possible, we configure Yandex.Metrica to collect data in an aggregated and anonymised or pseudonymised form to minimise the risk to your individual privacy. This data is primarily used for statistical analysis of website traffic and user behaviour, rather than tracking individual users.
- Data Minimisation: We only collect the data strictly necessary for our analytics purposes.
By consenting to the use of Yandex.Metrica, you acknowledge and accept the potential risks associated with this international data transfer.
For other international transfers (e.g., to our game provider Pragmatic Play if they process data outside the UK/EEA), we implement appropriate safeguards, such as the UK International Data Transfer Agreement (IDTA) or UK Addendum to the EU Standard Contractual Clauses (SCCs), to ensure your data receives an adequate level of protection.
8. Cookies and Similar Technologies
Our website uses cookies and similar technologies (e.g., pixels, web beacons) to enhance your user experience, analyse site usage, and support our marketing efforts.
- What are cookies? Cookies are small text files placed on your device (computer, tablet, mobile) when you visit a website. They help the website remember information about your visit.
- How we use cookies:
- Strictly Necessary Cookies: Essential for the website to function (e.g., enabling secure login, remembering your game session). These cannot be switched off.
- Analytical/Performance Cookies: Allow us to recognise and count the number of visitors and see how visitors move around our website. This helps us improve how the website works (e.g., via Yandex.Metrica).
- Functionality Cookies: Used to recognise you when you return to our website, allowing us to personalise content for you and remember your preferences.
- Targeting/Advertising Cookies: Record your visit to our website, the pages you have visited, and the links you have followed. We will use this information to make our website and the advertising displayed on it more relevant to your interests.
You have the right to accept or decline non-essential cookies. You can manage your cookie preferences through our dedicated cookie consent tool available on our website. Most web browsers also allow you to control cookies through their settings. Please note that disabling strictly necessary cookies may impact the functionality of our website.
9. Data Security
We take the security of your personal data very seriously. We have implemented appropriate technical and organisational measures to prevent your personal data from being accidentally lost, used, altered, disclosed, or accessed in an unauthorised way. These measures include:
- Encryption: Using Transport Layer Security (TLS) encryption for all data transmitted between your browser and our servers.
- Access Controls: Restricting access to your personal data to employees, agents, contractors, and other third parties on a strict "need-to-know" basis, and only for specific, legitimate business purposes.
- Pseudonymisation/Anonymisation: Where appropriate, we apply these techniques to reduce the identifiability of personal data.
- Regular Security Audits: Conducting regular vulnerability assessments and penetration testing to identify and address potential weaknesses.
- Incident Response Plan: Having a robust plan in place to detect, respond to, and mitigate the effects of any data breach.
While we strive to protect your personal data, no method of transmission over the internet or method of electronic storage is 100% secure. We cannot guarantee absolute security.
10. Data Retention
We will only retain your personal data for as long as necessary to fulfil the purposes for which we collected it, including for the purposes of satisfying any legal, accounting, or reporting requirements.
To determine the appropriate retention period for personal data, we consider the amount, nature, and sensitivity of the personal data, the potential risk of harm from unauthorised use or disclosure of your personal data, the purposes for which we process your personal data and whether we can achieve those purposes through other means, and the applicable legal requirements (e.g., AML regulations often require retaining data for 5 years after the end of a business relationship).
Upon expiry of the retention period, your personal data will be securely deleted or anonymised.
11. Your Rights Over Your Data
Under the UK GDPR, you have the following rights in relation to your personal data:
- Right to be Informed: To be informed about how your personal data is processed (which this Privacy Policy aims to do).
- Right of Access: To request access to your personal data (commonly known as a "data subject access request"). This enables you to receive a copy of the personal data we hold about you.
- Right to Rectification: To request correction of the personal data that we hold about you.
- Right to Erasure ("Right to be Forgotten"): To request the deletion or removal of your personal data where there is no good reason for us to continue processing it.
- Right to Restrict Processing: To request the suspension of the processing of your personal data in certain circumstances (e.g., if you want us to establish its accuracy or the reason for processing it).
- Right to Data Portability: To request the transfer of your personal data to you or to a third party in a structured, commonly used, machine-readable format.
- Right to Object: To object to the processing of your personal data where we are relying on a legitimate interest (or those of a third party) and there is something about your particular situation which makes you want to object to processing on this ground. You also have the right to object where we are processing your personal data for direct marketing purposes.
- Rights in Relation to Automated Decision Making and Profiling: You have the right not to be subject to a decision based solely on automated processing, including profiling, which produces legal effects concerning you or similarly significantly affects you, except in certain circumstances. We use automated processes for fraud prevention and responsible gambling monitoring.
- Right to Withdraw Consent: Where we are relying on consent to process your personal data, you have the right to withdraw that consent at any time.
To exercise any of these rights, please contact our Data Protection Officer (DPO) using the details provided in Section 16. We may need to request specific information from you to help us confirm your identity and ensure your right to access your personal data (or to exercise any of your other rights). This is a security measure to ensure that personal data is not disclosed to any person who has no right to receive it.
12. Responsible Gambling & Player Protection
We are deeply committed to promoting responsible gambling and protecting our players. We use certain data to fulfil these obligations:
- Identifying At-Risk Behaviour: We analyse gameplay patterns and account activity to identify potential indicators of problem gambling.
- Responsible Gambling Tools: We process data related to your use of responsible gambling tools such as deposit limits, session limits, reality checks, and self-exclusion periods. This data is crucial for us to enforce these limits and exclusions effectively.
- Communication: We may use your contact details to provide information about responsible gambling resources or to intervene if we identify concerning behaviour.
We work in cooperation with organisations such as GamCare and GAMSTOP. If you opt for self-exclusion, relevant data will be shared with these services to ensure your exclusion is applied across multiple operators.
For more information and support, please visit our Responsible Gambling page or contact organisations like GamCare (www.gamcare.org.uk) or use the GAMSTOP service (www.gamstop.co.uk).
13. Children's Privacy
Our services are not intended for individuals under the age of 18. We do not knowingly collect personal data from anyone under 18. If we become aware that we have collected personal data from a child under 18, we will take steps to delete that information as quickly as possible and close the account. If you believe we might have any information from or about a child under 18, please contact us immediately.
14. Changes to This Privacy Policy
We may update this Privacy Policy from time to time to reflect changes in our practices, legal requirements, or regulatory guidance. Any changes will be posted on this page, and the "Effective Date" at the top will be updated. For significant changes, we will notify you through a prominent notice on our website or directly via email. We encourage you to review this policy periodically to stay informed about how we are protecting your information.
15. How to Contact Us & Make a Complaint
If you have any questions, concerns, or requests regarding this Privacy Policy or our data practices, please do not hesitate to contact us.
Making a Complaint:
You have the right to make a complaint at any time to the Information Commissioner's Office (ICO), the UK supervisory authority for data protection issues. Their website is www.ico.org.uk. We would, however, appreciate the chance to deal with your concerns before you approach the ICO, so please contact us in the first instance.