Privacy Policy

Last updated: August 14, 2025

1. Start with Who Is Responsible for Your Data

1.1. Identify the Website operator

The Website is operated by Carletta N.V., a company incorporated under the laws of Curaçao.

Carletta N.V. has its office at Dr. Henri Fergusonweg 1, Curaçao. The company is registered under number 142346.

The Company has been licensed by the Curaçao Gaming Control Board since 24/Jun/2025 to offer games of chance under license number OGL/2024/580/0570, in accordance with the National Ordinance on Games of Chance (LOK).

1.2. Understand the role of the controller

For data protection purposes, Carletta N.V. is the controller of your Personal Data.

This means that the Company decides the purposes for which Personal Data is processed and the methods used for that Processing when you use the Website and Services.

1.3. Check when this guide applies

This Privacy Policy applies when Personal Data is processed through:

  • use of the Website;
  • messages sent to or received from [email protected];
  • phone conversations with us;
  • support chat interactions.

This Policy explains how Personal Data is collected, used, retained, disclosed, transferred, protected, and deleted or anonymized where applicable.

2. Review the Main Terms Before Using the Services

2.1. Account

An Account is the unique account created for you so that you can access the Services or certain parts of them.

Identity verification and Regulatory Compliance checks may be required before or during Account use.

2.2. Company

Company, we, us, or our refers to Carletta N.V., registered in Curaçao under company registration number 142346, with registered address at Dr. Henri Fergusonweg 1, Curaçao.

2.3. Service

Service means the Website, its available functions, and the related online gaming and interactive services provided by the Company.

2.4. Website

Website means this website and may also include subdomains, associated platforms, and applications operated by the Company.

2.5. Personal Data

Personal Data means information connected to an identified or identifiable individual, as understood under the General Data Protection Regulation and the Curaçao Data Protection Framework.

2.6. Processing of Personal Data

Processing of Personal Data means any action performed with Personal Data, whether by automated or manual methods.

Such actions may include collecting, recording, organizing, structuring, storing, changing, retrieving, reviewing, using, disclosing, transferring, combining, restricting, erasing, or destroying Personal Data.

2.7. Regulatory Compliance

Regulatory Compliance refers to the Company’s obligation to process Personal Data in line with applicable legal requirements, including the National Ordinance on Games of Chance and Anti-Money Laundering regulations.

Processing for Regulatory Compliance is required by law and is not based on user consent.

3. Step One: Create and Access an Account

3.1. Why Account data is processed

When you create or use an Account, certain Personal Data is needed to register the Account, activate access, maintain security, and make the Services available.

3.2. Legal basis for Account processing

The legal basis is performance of a contract or steps taken before entering into a contract under GDPR Article 6(1)(b).

3.3. Personal Data used for Account access

For this step, the Company may process:

  • email address and/or phone number;
  • hashed password;
  • selected currency;
  • account identifiers;
  • basic device or access logs used to activate and secure the Account.

4. Step Two: Complete Identity, Age, and Compliance Checks

4.1. Why verification may be required

The Company may need to verify your identity, confirm your age, complete KYC checks, and comply with AML/CFT, LOK, and NORUT obligations.

These checks help ensure that the Services are provided only where legal and regulatory requirements are met.

4.2. Legal basis for verification processing

The legal basis is compliance with legal obligations under GDPR Article 6(1)(c), including AML/CFT, LOK, and NORUT.

Where applicable, the Company may also rely on legitimate interests in maintaining platform integrity under GDPR Article 6(1)(f).

4.3. Personal Data used for verification

For identity, age, and compliance checks, the Company may process:

  • passport;
  • ID card;
  • driver’s license;
  • proof of address;
  • date of birth or age attestation;
  • selfies;
  • liveness checks.

5. Step Three: Use Payment Functions

5.1. Why payment data is needed

When deposits, withdrawals, refunds, or other payment-related services are used, Personal Data may be required to process the transaction and maintain the relevant records.

5.2. Legal basis for payment processing

Payment-related Processing may rely on several legal bases:

  • performance of a contract under GDPR Article 6(1)(b);
  • compliance with legal obligations for financial record-keeping and AML under GDPR Article 6(1)(c);
  • legitimate interests in fraud prevention under GDPR Article 6(1)(f).

5.3. Personal Data used for payment services

For payment-related purposes, the Company may process:

  • payment instrument data;
  • transaction history;
  • currency;
  • payout channel confirmations.

6. Step Four: Keep the Platform Secure

6.1. Why security monitoring is performed

The Company processes certain technical information to help detect fraud, monitor security risks, prevent unauthorized activity, and protect the integrity of the Services.

6.2. Legal basis for fraud prevention and security

The legal bases are:

  • legitimate interests in securing the Service and protecting users under GDPR Article 6(1)(f);
  • legal obligations under AML/CTF requirements under GDPR Article 6(1)(c).

6.3. Personal Data used for security purposes

Security and fraud prevention may involve Processing of:

  • IP address;
  • device type;
  • browser data;
  • device identifiers;
  • technical identifiers.

7. Step Five: Apply Responsible Gaming and Player Protection Measures

7.1. Why player protection data is processed

Responsible gaming, player protection, cooling-off options, play limits, and self-exclusion tools may require the Processing of Personal Data connected with Account activity and risk indicators.

7.2. Legal basis for responsible gaming measures

The legal bases are:

  • compliance with LOK / CGA Responsible Gaming requirements under GDPR Article 6(1)(c);
  • legitimate interests in player welfare and Regulatory Compliance under GDPR Article 6(1)(f).

7.3. Personal Data used for player protection

For responsible gaming and self-exclusion management, the Company may process:

  • self-exclusion status;
  • self-exclusion duration;
  • cooling-off selections;
  • play limits;
  • gameplay frequency;
  • spend metrics indicative of risk;
  • communications related to responsible gaming interventions.

8. Step Six: Contact Customer Support When Needed

8.1. Why support data is processed

When you contact support, Personal Data may be used to understand your request, respond to it, investigate the issue, and resolve Account or transaction-related matters.

8.2. Legal basis for support communications

The legal bases are:

  • performance of a contract under GDPR Article 6(1)(b);
  • legitimate interests in service quality and dispute resolution under GDPR Article 6(1)(f).

8.3. Personal Data used for support

Support-related Processing may include:

  • support tickets;
  • chat transcripts;
  • email correspondence;
  • call notes;
  • account identifiers;
  • transaction references connected to the inquiry.

9. Step Seven: Manage Marketing Communications

9.1. When marketing data may be processed

Where permitted by law, the Company may process contact and preference data for marketing communications.

Marketing activity is subject to opt-out rights and responsible gaming restrictions.

9.2. Legal basis for marketing

Electronic marketing is based on consent under GDPR Article 6(1)(a).

Where allowed by law, similar-product soft opt-in may be based on legitimate interests under GDPR Article 6(1)(f).

9.3. Personal Data used for marketing

For marketing communications, the Company may process:

  • email address;
  • phone number;
  • push token;
  • marketing preferences;
  • engagement metrics;
  • non-sensitive bonus eligibility status.

10. Step Eight: Understand Website Analytics and Cookies

10.1. Why Website data is processed

The Website may process technical and usage-related data to operate correctly, improve performance, measure interaction, and support cookie-based functionality.

10.2. Legal basis for analytics and cookies

The legal bases are:

  • legitimate interests in operating and improving the Website under GDPR Article 6(1)(f);
  • consent under GDPR Article 6(1)(a), where required for non-essential cookies.

10.3. Personal Data used for Website performance

Website performance and analytics may involve:

  • usage logs;
  • cookie identifiers;
  • browser type and version;
  • traffic data;
  • on-site interaction metrics.

11. Step Nine: Understand Regulatory Records and Dispute Handling

11.1. Why records may be kept for official purposes

Some records may be required for regulatory reporting, audits, legal proceedings, dispute resolution, and cooperation with competent authorities.

11.2. Legal basis for regulatory and legal Processing

The legal bases are:

  • legal obligation under GDPR Article 6(1)(c), including cooperation with the Curaçao Gaming Authority, FIU, tax authorities, and other authorities;
  • legitimate interests in establishing, exercising, or defending legal claims under GDPR Article 6(1)(f).

11.3. Personal Data used for these purposes

The Company may process records required for:

  • regulatory cooperation;
  • compliance audits;
  • legal proceedings;
  • dispute resolution, as permitted by applicable laws.

12. Step Ten: Know Where Personal Data Comes From

12.1. Data provided by you

The Company primarily collects Personal Data directly from you.

This may happen when you:

  • create an Account;
  • complete verification;
  • make a deposit;
  • request a withdrawal;
  • contact support.

12.2. Data generated through Service use

Some information is created through your use of the platform.

This may include:

  • gameplay;
  • transaction history;
  • device information;
  • log information;
  • cookie data in accordance with the Cookie Policy.

12.3. Data from third-party services

Trusted third-party services may provide support for:

  • compliance;
  • security;
  • payment-related functions;
  • identity verification.

12.4. Data from public and legitimate sources

Where necessary, the Company may add information from publicly available and legitimate sources.

Such use is limited to:

  • compliance;
  • verification;
  • risk management.

12.5. Data from authorities

In certain situations, Personal Data may be received from regulatory or law enforcement authorities in connection with legal and compliance obligations.

13. Step Eleven: Understand How Long Data Is Retained

13.1. General retention principle

The Company keeps Personal Data only for the period necessary to complete the purposes for which it was collected and processed, or for the period required by applicable legal or regulatory obligations.

13.2. Factors that affect retention

Retention periods are determined by considering:

  • the purpose of Processing;
  • provision of the Services;
  • contractual obligations;
  • protection of legitimate interests;
  • statutory AML requirements;
  • gaming requirements;
  • tax requirements;
  • legal claims;
  • audit obligations;
  • supervisory requirements.

13.3. What happens after retention ends

When the applicable retention period expires, Personal Data is securely deleted, anonymized, or archived so that it can no longer be linked to you.

Further retention may occur only if required by law.

14. Step Twelve: Review Storage and International Transfers

14.1. Where data may be stored

Personal Data is stored on secure servers operated by the Company and trusted service providers.

Depending on operational and regulatory requirements, these servers may be located:

  • within the European Economic Area;
  • outside the European Economic Area;
  • in Curaçao.

14.2. How transfers outside the EEA are protected

If Personal Data is transferred outside the EEA, the Company applies safeguards required under applicable data protection laws.

14.3. Adequacy decisions

Where the European Commission recognizes a country as providing an adequate level of data protection, Personal Data may be transferred on that basis.

14.4. Standard Contractual Clauses

Where no adequacy decision applies, the Company uses Standard Contractual Clauses approved by the European Commission to help keep Personal Data protected.

15. Step Thirteen: See Who May Receive Personal Data

15.1. General rule for sharing

Personal Data is shared only when needed and only for purposes described in this Privacy Policy.

Sharing is carried out under applicable data protection laws, contractual obligations, and security measures.

15.2. Regulatory and supervisory authorities

Personal Data may be shared with:

  • the Curaçao Gaming Authority;
  • the Financial Intelligence Unit;
  • tax authorities;
  • governmental bodies;
  • law enforcement bodies.

Such sharing may be necessary for legal or regulatory obligations, including AML and responsible gaming requirements.

15.3. Verification and compliance providers

Identity verification and compliance providers may receive Personal Data to help verify customer identity and meet AML and Know Your Customer obligations.

15.4. Payment processors and financial institutions

Payment processors and financial institutions may receive information needed for:

  • deposits;
  • withdrawals;
  • refunds;
  • other payment-related services.

This may include transaction details, payment method information, and account identifiers.

15.5. Support and communication providers

External providers may support email delivery, live chat, and other communication channels.

They may process:

  • contact details;
  • support messages.

15.6. Fraud prevention and security partners

Trusted providers may help protect platform security and integrity by detecting or preventing potentially fraudulent or unauthorized activity.

15.7. Analytics and optimization providers

Third-party services may assist with Website usage analysis, A/B testing, and user experience improvements.

Where possible, data used for these purposes is anonymized or pseudonymized.

15.8. Game content providers

Licensed third-party game providers may receive only the minimum data required to enable certain platform features.

This may include:

  • player identifiers;
  • game session data.

15.9. Internal tools and IT infrastructure providers

Secure hosting and productivity solutions may be used to store and manage data necessary for the operation of the Services.

16. Step Fourteen: Manage Cookies and Similar Technologies

16.1. What cookies do

The Website may use cookies and similar technologies to improve user experience, enable essential Website functions, and analyze site performance.

Cookies are small text files stored on your device. They allow the Website to recognize your device and remember certain preferences or previous actions.

16.2. Strictly necessary cookies

Strictly necessary cookies are required for the Website to operate.

They support:

  • page navigation;
  • access to secure areas;
  • user authentication.

These cookies cannot be switched off in the Company’s systems.

16.3. Functional cookies

Functional cookies enable enhanced functionality and personalization.

They may remember:

  • language preferences;
  • user settings.

They may be set by the Company or by third-party providers whose services are used.

16.4. Analytical or performance cookies

Analytical or performance cookies collect aggregated and anonymized information about Website use.

This may include:

  • page visits;
  • click-through rates;
  • traffic sources;
  • interaction metrics.

The purpose is to measure and improve Website performance.

16.5. Advertising or targeting cookies

Advertising or targeting cookies may be set by the Company or advertising partners.

They may help:

  • build a profile of interests;
  • deliver relevant advertising on this Website or other websites;
  • limit how often an advertisement appears;
  • measure advertising effectiveness.

16.6. Session and persistent cookies

Session cookies end when you close your browser.

Persistent cookies remain on your device for a predetermined period or until you delete them.

16.7. First-party and third-party cookies

First-party cookies are set by the Company.

Third-party cookies are placed by service providers acting on the Company’s behalf, including analytics providers, customer support tools, or advertising networks.

16.8. Cookie controls

Cookies can be controlled through your browser settings.

Most browsers allow cookies to be refused or deleted. Restricting some cookies may reduce the availability or functionality of certain parts of the Website.

17. Step Fifteen: Confirm Minor Protection Measures

17.1. Age requirement

The Services are intended only for individuals who are at least eighteen (18) years old or have reached the legal age in their jurisdiction, whichever is higher.

By accessing or registering for the Services, you confirm that you meet this requirement.

17.2. Regulatory alignment

In line with the Curaçao Gaming Authority’s Responsible Gaming Policy introduced in February 2025, the Company applies measures intended to prevent underage access.

17.3. Age verification

Users may be required to provide valid government-issued identification documents during registration.

This helps enforce age restrictions and confirm eligibility to use the Services.

17.4. Monitoring and reviews

The Company may use automated monitoring to detect inconsistencies or signs of attempted underage access.

Where underage access is suspected, security reviews may be conducted, including checks of registration data and financial transactions.

17.5. Data submitted by minors

Personal Data submitted by individuals identified as minors is deleted immediately.

17.6. Parental controls

Parents and guardians are encouraged to use available parental control tools and educate minors about responsible online behavior to prevent unauthorized access to the Services.

17.7. Responsible gaming commitment

The Company follows CGA guidance on player protection and age verification and continually reviews its policies to ensure that they meet or exceed regulatory standards.

18. Step Sixteen: Exercise Your Data Protection Rights

18.1. Right of Access

Under Article 15 GDPR, you may ask whether your Personal Data is processed and request a copy of such data together with information about how it is used.

18.2. Right to Rectification

Under Article 16 GDPR, you may request correction of inaccurate or incomplete Personal Data without undue delay.

18.3. Right to Erasure

Under Article 17 GDPR, you may request deletion of Personal Data where legal grounds apply.

This may include situations where the data is no longer required for the purposes collected, or where consent is withdrawn and no other lawful basis applies.

18.4. Right to Restrict Processing

Under Article 18 GDPR, you may request a limitation on Processing in specific situations, including where data accuracy is contested or Processing is unlawful.

18.5. Right to Data Portability

Under Article 20 GDPR, you may request Personal Data you provided to the Company in a structured, commonly used, and machine-readable format.

Where technically feasible, that data may be transferred to another controller.

18.6. Right to Object

Under Article 21 GDPR, you may object to Processing based on legitimate interests for reasons related to your particular situation.

You may also object to Processing for direct marketing purposes.

18.7. Contact channels for rights requests

To exercise your rights, contact the Company through:

19. Step Seventeen: Withdraw Consent Where Applicable

19.1. When consent can be withdrawn

If the Company processes Personal Data based on your consent, you may withdraw that consent at any time.

19.2. Effect of withdrawal

Withdrawing consent does not affect the lawfulness of Processing carried out before consent was withdrawn.

19.3. How to withdraw consent

To withdraw consent, use the contact channels listed in this Privacy Policy.

Once the request is received, the Company will stop Processing the relevant Personal Data unless retention or continued Processing is required by legal or regulatory obligations.

19.4. Possible impact on Services

If consent withdrawal affects the Company’s ability to provide certain Services, you will be informed of the consequences before the withdrawal process is completed.

20. Step Eighteen: Raise a Complaint If Needed

20.1. Complaint right

Under Article 77 GDPR, you have the right to lodge a complaint if you believe your Personal Data is being processed unlawfully or your privacy rights have been violated.

20.2. Where complaints may be lodged

A complaint may be submitted to:

  • the supervisory authority in the EU Member State where you reside;
  • the supervisory authority in the EU Member State where you work;
  • the supervisory authority in the EU Member State where the alleged violation occurred;
  • the Curaçao Gaming Authority;
  • any other relevant data protection authority in Curaçao.

20.3. Contacting the Company first

If you have unresolved concerns about the Processing of your Personal Data, you are encouraged to contact the Company directly.

The Company will make every reasonable effort to respond to concerns in a timely and lawful manner.

21. Step Nineteen: Provide Required Personal Data

21.1. Legal requirement

Some Personal Data must be provided to comply with laws and regulations, including Anti-Money Laundering obligations and responsible gaming requirements.

21.2. Contractual requirement

Certain Personal Data is needed to enter into and perform a contract with you.

This includes data required to provide access to the Services and process transactions.

21.3. Service access requirement

Some Personal Data is necessary to access the Services.

Without required data, the Company may be unable to provide certain Services or meet contractual or legal obligations.

21.4. Consequences of non-disclosure

Failure to provide required Personal Data may result in:

  • inability to create or maintain an Account;
  • restrictions on the use of the Services;
  • termination of the contractual relationship;
  • inability to comply with regulatory obligations, which may prevent the Company from providing Services.

22. Step Twenty: Read the Legal Disclaimer and Policy Terms

22.1. Service basis

The Services are provided on an “AS-IS” and “AS-AVAILABLE” basis.

The Company does not provide warranties or guarantees of uninterrupted or error-free performance.

22.2. Security statement

The Company takes reasonable precautions to protect Personal Data.

However, absolute security cannot be guaranteed because technology is complex and cybersecurity threats continue to evolve.

22.3. Limitations of liability

To the maximum extent permitted by law, the Company is not liable for:

  • events beyond its direct control, including system failures, cyberattacks, or unauthorized access;
  • indirect, incidental, consequential, or punitive damages arising from data breaches, unauthorized disclosure, or misuse of Personal Data;
  • errors, inaccuracies, or security vulnerabilities on third-party websites linked from the platform.

22.4. Third-party websites

By using the Services, you acknowledge that the Company is not responsible for external websites or services operated by third parties, even where links to them appear on the platform.

22.5. Acceptance of the Privacy Policy

Your continued use of the Services means that you explicitly accept this Privacy Policy.

This document is the complete and exclusive Privacy Policy and replaces earlier versions.

22.6. Related documents and updates

This Privacy Policy should be read together with the Terms and Conditions and any additional applicable notices posted on the platform.

The Company may modify this Privacy Policy at any time. Changes will be posted on the platform. Continued use of the Services after modifications means acceptance of the revised Policy.

You are strongly encouraged to review this Privacy Policy regularly to stay informed about updates.

22.7. Language priority

All versions of this Privacy Policy other than the English version are provided for informational purposes only.

If any discrepancy or conflict exists between versions, the English version prevails.