Privacy Policy
Last updated: August 14, 2025
1. Start with Who Is Responsible for Your Data
1.1. Identify the Website operator
The Website is operated by Carletta N.V., a company incorporated under the laws of Curaçao.
Carletta N.V. has its office at Dr. Henri Fergusonweg 1, Curaçao. The company is registered under number 142346.
The Company has been licensed by the Curaçao Gaming Control Board since 24/Jun/2025 to offer games of chance under license number OGL/2024/580/0570, in accordance with the National Ordinance on Games of Chance (LOK).
1.2. Understand the role of the controller
For data protection purposes, Carletta N.V. is the controller of your Personal Data.
This means that the Company decides the purposes for which Personal Data is processed and the methods used for that Processing when you use the Website and Services.
1.3. Check when this guide applies
This Privacy Policy applies when Personal Data is processed through:
- use of the Website;
- messages sent to or received from [email protected];
- phone conversations with us;
- support chat interactions.
This Policy explains how Personal Data is collected, used, retained, disclosed, transferred, protected, and deleted or anonymized where applicable.
2. Review the Main Terms Before Using the Services
2.1. Account
An Account is the unique account created for you so that you can access the Services or certain parts of them.
Identity verification and Regulatory Compliance checks may be required before or during Account use.
2.2. Company
Company, we, us, or our refers to Carletta N.V., registered in Curaçao under company registration number 142346, with registered address at Dr. Henri Fergusonweg 1, Curaçao.
2.3. Service
Service means the Website, its available functions, and the related online gaming and interactive services provided by the Company.
2.4. Website
Website means this website and may also include subdomains, associated platforms, and applications operated by the Company.
2.5. Personal Data
Personal Data means information connected to an identified or identifiable individual, as understood under the General Data Protection Regulation and the Curaçao Data Protection Framework.
2.6. Processing of Personal Data
Processing of Personal Data means any action performed with Personal Data, whether by automated or manual methods.
Such actions may include collecting, recording, organizing, structuring, storing, changing, retrieving, reviewing, using, disclosing, transferring, combining, restricting, erasing, or destroying Personal Data.
2.7. Regulatory Compliance
Regulatory Compliance refers to the Company’s obligation to process Personal Data in line with applicable legal requirements, including the National Ordinance on Games of Chance and Anti-Money Laundering regulations.
Processing for Regulatory Compliance is required by law and is not based on user consent.
3. Step One: Create and Access an Account
3.1. Why Account data is processed
When you create or use an Account, certain Personal Data is needed to register the Account, activate access, maintain security, and make the Services available.
3.2. Legal basis for Account processing
The legal basis is performance of a contract or steps taken before entering into a contract under GDPR Article 6(1)(b).
3.3. Personal Data used for Account access
For this step, the Company may process:
- email address and/or phone number;
- hashed password;
- selected currency;
- account identifiers;
- basic device or access logs used to activate and secure the Account.
4. Step Two: Complete Identity, Age, and Compliance Checks
4.1. Why verification may be required
The Company may need to verify your identity, confirm your age, complete KYC checks, and comply with AML/CFT, LOK, and NORUT obligations.
These checks help ensure that the Services are provided only where legal and regulatory requirements are met.
4.2. Legal basis for verification processing
The legal basis is compliance with legal obligations under GDPR Article 6(1)(c), including AML/CFT, LOK, and NORUT.
Where applicable, the Company may also rely on legitimate interests in maintaining platform integrity under GDPR Article 6(1)(f).
4.3. Personal Data used for verification
For identity, age, and compliance checks, the Company may process:
- passport;
- ID card;
- driver’s license;
- proof of address;
- date of birth or age attestation;
- selfies;
- liveness checks.
5. Step Three: Use Payment Functions
5.1. Why payment data is needed
When deposits, withdrawals, refunds, or other payment-related services are used, Personal Data may be required to process the transaction and maintain the relevant records.
5.2. Legal basis for payment processing
Payment-related Processing may rely on several legal bases:
- performance of a contract under GDPR Article 6(1)(b);
- compliance with legal obligations for financial record-keeping and AML under GDPR Article 6(1)(c);
- legitimate interests in fraud prevention under GDPR Article 6(1)(f).
5.3. Personal Data used for payment services
For payment-related purposes, the Company may process:
- payment instrument data;
- transaction history;
- currency;
- payout channel confirmations.
6. Step Four: Keep the Platform Secure
6.1. Why security monitoring is performed
The Company processes certain technical information to help detect fraud, monitor security risks, prevent unauthorized activity, and protect the integrity of the Services.
6.2. Legal basis for fraud prevention and security
The legal bases are:
- legitimate interests in securing the Service and protecting users under GDPR Article 6(1)(f);
- legal obligations under AML/CTF requirements under GDPR Article 6(1)(c).
6.3. Personal Data used for security purposes
Security and fraud prevention may involve Processing of:
- IP address;
- device type;
- browser data;
- device identifiers;
- technical identifiers.
7. Step Five: Apply Responsible Gaming and Player Protection Measures
7.1. Why player protection data is processed
Responsible gaming, player protection, cooling-off options, play limits, and self-exclusion tools may require the Processing of Personal Data connected with Account activity and risk indicators.
7.2. Legal basis for responsible gaming measures
The legal bases are:
- compliance with LOK / CGA Responsible Gaming requirements under GDPR Article 6(1)(c);
- legitimate interests in player welfare and Regulatory Compliance under GDPR Article 6(1)(f).
7.3. Personal Data used for player protection
For responsible gaming and self-exclusion management, the Company may process:
- self-exclusion status;
- self-exclusion duration;
- cooling-off selections;
- play limits;
- gameplay frequency;
- spend metrics indicative of risk;
- communications related to responsible gaming interventions.
8. Step Six: Contact Customer Support When Needed
8.1. Why support data is processed
When you contact support, Personal Data may be used to understand your request, respond to it, investigate the issue, and resolve Account or transaction-related matters.
8.2. Legal basis for support communications
The legal bases are:
- performance of a contract under GDPR Article 6(1)(b);
- legitimate interests in service quality and dispute resolution under GDPR Article 6(1)(f).
8.3. Personal Data used for support
Support-related Processing may include:
- support tickets;
- chat transcripts;
- email correspondence;
- call notes;
- account identifiers;
- transaction references connected to the inquiry.
9. Step Seven: Manage Marketing Communications
9.1. When marketing data may be processed
Where permitted by law, the Company may process contact and preference data for marketing communications.
Marketing activity is subject to opt-out rights and responsible gaming restrictions.
9.2. Legal basis for marketing
Electronic marketing is based on consent under GDPR Article 6(1)(a).
Where allowed by law, similar-product soft opt-in may be based on legitimate interests under GDPR Article 6(1)(f).
9.3. Personal Data used for marketing
For marketing communications, the Company may process:
- email address;
- phone number;
- push token;
- marketing preferences;
- engagement metrics;
- non-sensitive bonus eligibility status.
10. Step Eight: Understand Website Analytics and Cookies
10.1. Why Website data is processed
The Website may process technical and usage-related data to operate correctly, improve performance, measure interaction, and support cookie-based functionality.
10.2. Legal basis for analytics and cookies
The legal bases are:
- legitimate interests in operating and improving the Website under GDPR Article 6(1)(f);
- consent under GDPR Article 6(1)(a), where required for non-essential cookies.
10.3. Personal Data used for Website performance
Website performance and analytics may involve:
- usage logs;
- cookie identifiers;
- browser type and version;
- traffic data;
- on-site interaction metrics.
11. Step Nine: Understand Regulatory Records and Dispute Handling
11.1. Why records may be kept for official purposes
Some records may be required for regulatory reporting, audits, legal proceedings, dispute resolution, and cooperation with competent authorities.
11.2. Legal basis for regulatory and legal Processing
The legal bases are:
- legal obligation under GDPR Article 6(1)(c), including cooperation with the Curaçao Gaming Authority, FIU, tax authorities, and other authorities;
- legitimate interests in establishing, exercising, or defending legal claims under GDPR Article 6(1)(f).
11.3. Personal Data used for these purposes
The Company may process records required for:
- regulatory cooperation;
- compliance audits;
- legal proceedings;
- dispute resolution, as permitted by applicable laws.
12. Step Ten: Know Where Personal Data Comes From
12.1. Data provided by you
The Company primarily collects Personal Data directly from you.
This may happen when you:
- create an Account;
- complete verification;
- make a deposit;
- request a withdrawal;
- contact support.
12.2. Data generated through Service use
Some information is created through your use of the platform.
This may include:
- gameplay;
- transaction history;
- device information;
- log information;
- cookie data in accordance with the Cookie Policy.
12.3. Data from third-party services
Trusted third-party services may provide support for:
- compliance;
- security;
- payment-related functions;
- identity verification.
12.4. Data from public and legitimate sources
Where necessary, the Company may add information from publicly available and legitimate sources.
Such use is limited to:
- compliance;
- verification;
- risk management.
12.5. Data from authorities
In certain situations, Personal Data may be received from regulatory or law enforcement authorities in connection with legal and compliance obligations.
13. Step Eleven: Understand How Long Data Is Retained
13.1. General retention principle
The Company keeps Personal Data only for the period necessary to complete the purposes for which it was collected and processed, or for the period required by applicable legal or regulatory obligations.
13.2. Factors that affect retention
Retention periods are determined by considering:
- the purpose of Processing;
- provision of the Services;
- contractual obligations;
- protection of legitimate interests;
- statutory AML requirements;
- gaming requirements;
- tax requirements;
- legal claims;
- audit obligations;
- supervisory requirements.
13.3. What happens after retention ends
When the applicable retention period expires, Personal Data is securely deleted, anonymized, or archived so that it can no longer be linked to you.
Further retention may occur only if required by law.
14. Step Twelve: Review Storage and International Transfers
14.1. Where data may be stored
Personal Data is stored on secure servers operated by the Company and trusted service providers.
Depending on operational and regulatory requirements, these servers may be located:
- within the European Economic Area;
- outside the European Economic Area;
- in Curaçao.
14.2. How transfers outside the EEA are protected
If Personal Data is transferred outside the EEA, the Company applies safeguards required under applicable data protection laws.
14.3. Adequacy decisions
Where the European Commission recognizes a country as providing an adequate level of data protection, Personal Data may be transferred on that basis.
14.4. Standard Contractual Clauses
Where no adequacy decision applies, the Company uses Standard Contractual Clauses approved by the European Commission to help keep Personal Data protected.
15. Step Thirteen: See Who May Receive Personal Data
15.1. General rule for sharing
Personal Data is shared only when needed and only for purposes described in this Privacy Policy.
Sharing is carried out under applicable data protection laws, contractual obligations, and security measures.
15.2. Regulatory and supervisory authorities
Personal Data may be shared with:
- the Curaçao Gaming Authority;
- the Financial Intelligence Unit;
- tax authorities;
- governmental bodies;
- law enforcement bodies.
Such sharing may be necessary for legal or regulatory obligations, including AML and responsible gaming requirements.
15.3. Verification and compliance providers
Identity verification and compliance providers may receive Personal Data to help verify customer identity and meet AML and Know Your Customer obligations.
15.4. Payment processors and financial institutions
Payment processors and financial institutions may receive information needed for:
- deposits;
- withdrawals;
- refunds;
- other payment-related services.
This may include transaction details, payment method information, and account identifiers.
15.5. Support and communication providers
External providers may support email delivery, live chat, and other communication channels.
They may process:
- contact details;
- support messages.
15.6. Fraud prevention and security partners
Trusted providers may help protect platform security and integrity by detecting or preventing potentially fraudulent or unauthorized activity.
15.7. Analytics and optimization providers
Third-party services may assist with Website usage analysis, A/B testing, and user experience improvements.
Where possible, data used for these purposes is anonymized or pseudonymized.
15.8. Game content providers
Licensed third-party game providers may receive only the minimum data required to enable certain platform features.
This may include:
- player identifiers;
- game session data.
15.9. Internal tools and IT infrastructure providers
Secure hosting and productivity solutions may be used to store and manage data necessary for the operation of the Services.
16. Step Fourteen: Manage Cookies and Similar Technologies
16.1. What cookies do
The Website may use cookies and similar technologies to improve user experience, enable essential Website functions, and analyze site performance.
Cookies are small text files stored on your device. They allow the Website to recognize your device and remember certain preferences or previous actions.
16.2. Strictly necessary cookies
Strictly necessary cookies are required for the Website to operate.
They support:
- page navigation;
- access to secure areas;
- user authentication.
These cookies cannot be switched off in the Company’s systems.
16.3. Functional cookies
Functional cookies enable enhanced functionality and personalization.
They may remember:
- language preferences;
- user settings.
They may be set by the Company or by third-party providers whose services are used.
16.4. Analytical or performance cookies
Analytical or performance cookies collect aggregated and anonymized information about Website use.
This may include:
- page visits;
- click-through rates;
- traffic sources;
- interaction metrics.
The purpose is to measure and improve Website performance.
16.5. Advertising or targeting cookies
Advertising or targeting cookies may be set by the Company or advertising partners.
They may help:
- build a profile of interests;
- deliver relevant advertising on this Website or other websites;
- limit how often an advertisement appears;
- measure advertising effectiveness.
16.6. Session and persistent cookies
Session cookies end when you close your browser.
Persistent cookies remain on your device for a predetermined period or until you delete them.
16.7. First-party and third-party cookies
First-party cookies are set by the Company.
Third-party cookies are placed by service providers acting on the Company’s behalf, including analytics providers, customer support tools, or advertising networks.
16.8. Cookie controls
Cookies can be controlled through your browser settings.
Most browsers allow cookies to be refused or deleted. Restricting some cookies may reduce the availability or functionality of certain parts of the Website.
17. Step Fifteen: Confirm Minor Protection Measures
17.1. Age requirement
The Services are intended only for individuals who are at least eighteen (18) years old or have reached the legal age in their jurisdiction, whichever is higher.
By accessing or registering for the Services, you confirm that you meet this requirement.
17.2. Regulatory alignment
In line with the Curaçao Gaming Authority’s Responsible Gaming Policy introduced in February 2025, the Company applies measures intended to prevent underage access.
17.3. Age verification
Users may be required to provide valid government-issued identification documents during registration.
This helps enforce age restrictions and confirm eligibility to use the Services.
17.4. Monitoring and reviews
The Company may use automated monitoring to detect inconsistencies or signs of attempted underage access.
Where underage access is suspected, security reviews may be conducted, including checks of registration data and financial transactions.
17.5. Data submitted by minors
Personal Data submitted by individuals identified as minors is deleted immediately.
17.6. Parental controls
Parents and guardians are encouraged to use available parental control tools and educate minors about responsible online behavior to prevent unauthorized access to the Services.
17.7. Responsible gaming commitment
The Company follows CGA guidance on player protection and age verification and continually reviews its policies to ensure that they meet or exceed regulatory standards.
18. Step Sixteen: Exercise Your Data Protection Rights
18.1. Right of Access
Under Article 15 GDPR, you may ask whether your Personal Data is processed and request a copy of such data together with information about how it is used.
18.2. Right to Rectification
Under Article 16 GDPR, you may request correction of inaccurate or incomplete Personal Data without undue delay.
18.3. Right to Erasure
Under Article 17 GDPR, you may request deletion of Personal Data where legal grounds apply.
This may include situations where the data is no longer required for the purposes collected, or where consent is withdrawn and no other lawful basis applies.
18.4. Right to Restrict Processing
Under Article 18 GDPR, you may request a limitation on Processing in specific situations, including where data accuracy is contested or Processing is unlawful.
18.5. Right to Data Portability
Under Article 20 GDPR, you may request Personal Data you provided to the Company in a structured, commonly used, and machine-readable format.
Where technically feasible, that data may be transferred to another controller.
18.6. Right to Object
Under Article 21 GDPR, you may object to Processing based on legitimate interests for reasons related to your particular situation.
You may also object to Processing for direct marketing purposes.
18.7. Contact channels for rights requests
To exercise your rights, contact the Company through:
- email: [email protected];
- postal address: Dr. Henri Fergusonweg 1, Curaçao.
19. Step Seventeen: Withdraw Consent Where Applicable
19.1. When consent can be withdrawn
If the Company processes Personal Data based on your consent, you may withdraw that consent at any time.
19.2. Effect of withdrawal
Withdrawing consent does not affect the lawfulness of Processing carried out before consent was withdrawn.
19.3. How to withdraw consent
To withdraw consent, use the contact channels listed in this Privacy Policy.
Once the request is received, the Company will stop Processing the relevant Personal Data unless retention or continued Processing is required by legal or regulatory obligations.
19.4. Possible impact on Services
If consent withdrawal affects the Company’s ability to provide certain Services, you will be informed of the consequences before the withdrawal process is completed.
20. Step Eighteen: Raise a Complaint If Needed
20.1. Complaint right
Under Article 77 GDPR, you have the right to lodge a complaint if you believe your Personal Data is being processed unlawfully or your privacy rights have been violated.
20.2. Where complaints may be lodged
A complaint may be submitted to:
- the supervisory authority in the EU Member State where you reside;
- the supervisory authority in the EU Member State where you work;
- the supervisory authority in the EU Member State where the alleged violation occurred;
- the Curaçao Gaming Authority;
- any other relevant data protection authority in Curaçao.
20.3. Contacting the Company first
If you have unresolved concerns about the Processing of your Personal Data, you are encouraged to contact the Company directly.
The Company will make every reasonable effort to respond to concerns in a timely and lawful manner.
21. Step Nineteen: Provide Required Personal Data
21.1. Legal requirement
Some Personal Data must be provided to comply with laws and regulations, including Anti-Money Laundering obligations and responsible gaming requirements.
21.2. Contractual requirement
Certain Personal Data is needed to enter into and perform a contract with you.
This includes data required to provide access to the Services and process transactions.
21.3. Service access requirement
Some Personal Data is necessary to access the Services.
Without required data, the Company may be unable to provide certain Services or meet contractual or legal obligations.
21.4. Consequences of non-disclosure
Failure to provide required Personal Data may result in:
- inability to create or maintain an Account;
- restrictions on the use of the Services;
- termination of the contractual relationship;
- inability to comply with regulatory obligations, which may prevent the Company from providing Services.
22. Step Twenty: Read the Legal Disclaimer and Policy Terms
22.1. Service basis
The Services are provided on an “AS-IS” and “AS-AVAILABLE” basis.
The Company does not provide warranties or guarantees of uninterrupted or error-free performance.
22.2. Security statement
The Company takes reasonable precautions to protect Personal Data.
However, absolute security cannot be guaranteed because technology is complex and cybersecurity threats continue to evolve.
22.3. Limitations of liability
To the maximum extent permitted by law, the Company is not liable for:
- events beyond its direct control, including system failures, cyberattacks, or unauthorized access;
- indirect, incidental, consequential, or punitive damages arising from data breaches, unauthorized disclosure, or misuse of Personal Data;
- errors, inaccuracies, or security vulnerabilities on third-party websites linked from the platform.
22.4. Third-party websites
By using the Services, you acknowledge that the Company is not responsible for external websites or services operated by third parties, even where links to them appear on the platform.
22.5. Acceptance of the Privacy Policy
Your continued use of the Services means that you explicitly accept this Privacy Policy.
This document is the complete and exclusive Privacy Policy and replaces earlier versions.
22.6. Related documents and updates
This Privacy Policy should be read together with the Terms and Conditions and any additional applicable notices posted on the platform.
The Company may modify this Privacy Policy at any time. Changes will be posted on the platform. Continued use of the Services after modifications means acceptance of the revised Policy.
You are strongly encouraged to review this Privacy Policy regularly to stay informed about updates.
22.7. Language priority
All versions of this Privacy Policy other than the English version are provided for informational purposes only.
If any discrepancy or conflict exists between versions, the English version prevails.