Rich Royal Gaming Data Retention Policy for Italy Users

As a licensed operator in Italy, Rich Royal Casino, we obtain and safeguard personal and transactional data under stringent legal obligations. This policy details exactly how long we retain different categories of information, the legal reasons behind those periods, and the security measures that safeguard your data at every stage. We constantly balance our duty to retain records for fraud prevention and financial audits with the privacy rights you hold under Italian data protection law and the GDPR. Our schedules get regular reviews so we keep fully compliant.

Legal Basis for Data Retention

Our retention approach rests on several legal obligations that govern gambling operators serving the Italian market. Anti‑money laundering rules from the Italian Financial Intelligence Unit require us to keep transaction logs, identity verification documents and suspicious activity reports for a specific duration after the business relationship ends. Meanwhile, tax rules administered by the Agenzia delle Entrate require we preserve financial records that back up taxable gaming revenue and player winnings. These obligations override any general right to erasure during the mandatory period. For operational data that doesn’t fall under a fixed legal window, we base our approach on legitimate interest assessments where a valid reason exists, and we offer an opt‑out unless a compelling legal obligation overrides it.

Retention Based on Consent

Marketing preferences, newsletter sign‑ups and the behavioural analytics employed for personalised offers stay only with your explicit consent. You can withdraw consent anytime through your account dashboard; once you do, we halt that processing immediately and delete the connected profiles within thirty days. Data processed lawfully before withdrawal is separated from active systems to block further use, but it is not removed retroactively. Consent records themselves are kept for six years as proof of compliance. We do not use this data for anything beyond the activity you agreed to.

Data Removal Procedures

When a information type hits the end of its planned retention period, our self-running lifecycle mechanism kicks off a secure deletion workflow. First, the data gets digitally detached from production databases. Next, physical storage blocks are overwritten with random data patterns to stop forensic recovery. Finally, a digitally signed log lands in a compliance ledger, giving verifiable evidence that purging happened on time. Backup copies rotate every ninety days, so any deleted data is removed from all media within three months. When a litigation hold applies, we pause the deletion workflow only for the affected records, document the hold reason, and restart once the hold lifts.

Affiliate Program Data Retention

Partner relationship data, including communication data, payout data and commission transaction history, remains for the life of the active partnership plus a decade after the partnership concludes. This is due to tax requirements on commission payouts, which require long‑term financial records. Affiliate performance statistics and combined referred-player data get anonymised after half a decade. We firmly disallow affiliates from independently collecting or storing personal data about referred users; they obtain only anonymised, aggregated statements. Our affiliate contracts include inspection rights to check adherence, and any breach is reason for instant agreement cancellation and payout forfeiture.

Information Protection In Preservation

Retained data is safeguarded with AES‑256 encryption at rest, TLS 1.3 protocols in transit and isolated virtual private clouds. Access demands multi‑factor authentication plus just‑in‑time privilege elevation that terminates on its own. Every access event is recorded into an immutable audit trail. We run quarterly penetration tests through CREST‑certified firms and continuous vulnerability scans to keep our storage tight. Backups are encrypted and spread across Italian data centres, with strict controls that block accidental restoration of data past its deletion date. A dedicated lifecycle dashboard flags every dataset as it nears expiration.

Access Governance and Employee Education

Only employees whose roles demonstrably require access to retained personal data get permissions, and those permissions go through monthly recertification audits. Any access to dormant user records triggers a managerial review within one business day. Every staff member who handles personal data completes mandatory annual training on Italian data protection law and our internal retention policies, including hands‑on exercises on spotting valid erasure requests and distinguishing the difference between data we must keep under a legal hold and data we can delete straight away.

Policy Changes and User Notification

We review this Data Retention Policy every six months and whenever a major legal change hits Italian gambling operations. Minor clarifications are published silently with a revised effective date. Material changes that alter retention periods, include new data categories or change the legal basis for processing are communicated directly to you by email at least thirty days before they take effect. You’ll also notice an in‑platform banner notification when you log in during the notice period. Historical versions are archived and available on request, each with a version number and a validity date range. If an earlier version provided a shorter retention period for certain data, we adhere to that promise for data collected under that version and apply new terms only going forward.

Cross-border Data Transfers and Storage Periods

Our main systems resides within Italy and the wider European Economic Area. Some secondary services, like fraud detection platforms and customer relationship tools, may pass certain personal data to countries outside the EEA. In those cases, we guarantee an adequacy decision exists or we establish Standard Contractual Clauses in place together with a transfer impact assessment. The retention periods we assign to transferred data mirror those in this policy, and processors are contractually bound to remove or return data when the service ends. We keep a public register of sub‑processors, updated within fourteen days of any change, and we choose vendors with Italian data centres. Geo‑fencing rules keep Italian user data inside European boundaries, verified through yearly audits.

Individual Rights and Retention Handling

When you submit an erasure request, our system automatically reviews each data category against its retention schedule. All data past its mandatory window gets deleted without delay. For data still subject to a legal retention obligation, we restrict it right away so it’s taken out of active use and kept solely for compliance storage; we notify you which specific law applies and the date deletion becomes possible. Access requests are responded to within thirty days and include a breakdown of what we keep, why, and the scheduled deletion date. If you dispute accuracy, we attach a note instead of altering the original record, so the audit trail stays intact. Portability requests are fulfilled in a structured, machine‑readable format even while data is still in its retention window.

Data Categories and Retention Periods

We categorize all user data into clear categories, each connected to a retention whoscored.com schedule that matches its purpose and legal context. That organized approach keeps us from keeping things forever. Every year our Data Protection Officer examines these classifications and modifies the timelines whenever new guidance emerges from the Garante per la protezione dei dati personali. Below you’ll view how long each data type stays in our live systems before being securely anonymized or destroyed. Archived backups follow a ninety‑day cycle because of technical constraints.

Identity and Monetary Records

Identity documents you provide during Know Your Customer checks, like passport scans, utility bills and tax ID numbers, remain on file for ten years after you terminate your account, as anti‑money laundering law requires. Deposit and withdrawal logs, payment method tokens and wallet balance histories are retained for ten years from the date of each transaction, satisfying both AML requirements and Italian Civil Code limitation periods. We keep these records in encrypted, access‑restricted vaults and tamper‑proof ledgers. Once the retention deadline elapses, we remove all personal identifiers permanently; statistical trends may still be utilized but never in a way that traces to any individual.

User Activity and Support Communications

Comprehensive records of game sessions, bets placed, outcomes and session lengths are kept for five years after each gaming event, matching the statute of limitations for civil disputes. Customer service transcripts, email threads and call recordings stay for three years from your last interaction, covering the typical complaint‑handling window. After those periods, raw logs and case attachments get permanently deleted. Aggregated, anonymised datasets can be kept indefinitely for product improvement and service quality analysis. All of this data lives in case management systems with role‑based access restrictions.

Safe Gaming and Self‑Exclusion Data

Upon activating self‑exclusion, your identity data must be stored permanently in a locked‑down register to stop you from opening new accounts, a measure Italian gambling regulations explicitly permit. Other safer‑gambling markers, like expired voluntary deposit limits, are deleted two years after the limit lifts. We never use self‑exclusion register data for anything other than enforcing the exclusion. The register is completely walled off from marketing and operational systems, so it serves only its protective purpose.

Frequently Asked Questions

Can I request deletion of my data before the retention period ends?

Absolutely, you may lodge an erasure request whenever you wish. We instantly examine each data category in relation to its legal retention duty. If no legal obligation applies, we erase it promptly. For anything we must keep, we restrict it to storage‑only, tell you the legal basis stopping immediate deletion and give you the expected deletion date. You can also view all your data categories with their scheduled deletion dates through your account dashboard. This partial method honors your rights to the extent permitted by Italian regulations.

What occurs with my data when I opt for permanent self‑exclusion?

When you register for permanent self‑exclusion, your identity data moves to a dedicated exclusion register that stays live indefinitely with tightly controlled access. It is a legal obligation intended to block you from establishing new accounts. Conversely, your gameplay and transaction records continue to adhere to the usual retention timelines and are erased when those durations expire. The self‑exclusion record is separated from all marketing and operational platforms, so it only serves the safeguarding role it was intended for. No marketing communications will be sent to you.

How do you handle data belonging to inactive accounts?

An account is deemed inactive following twelve consecutive months without a login. Then, we automatically halt marketing messages and place the account into a dormant condition with minimized processing. The fundamental retention timelines continue based on the initial collection dates, not the inactivity date. Consequently, data from an inactive account is kept for the entire statutory duration applicable to its type and then removed in line with our usual processes. If you return following a lengthy hiatus, you might have to finish a fresh Know Your Customer assessment to re‑enable your account. Your data dashboard displays the current status continuously.

Leave a Reply

Your email address will not be published. Required fields are marked *