Data Protection (UK/EU GDPR) – GlobalCasinoBonus
Last updated: 31 August 2025
At GlobalCasinoBonus we handle personal data with care and in line with the UK GDPR / EU GDPR. This page summarises our
data protection principles, technical and organisational measures, vendor controls, rights handling, and incident response.
1) GDPR Principles We Follow
- Lawfulness, fairness, transparency – clear purposes and notices.
- Purpose limitation – use data only for the stated purpose.
- Data minimisation – collect the least amount necessary.
- Accuracy – keep data accurate and up to date where relevant.
- Storage limitation – keep data no longer than needed.
- Integrity & confidentiality – protect with appropriate security.
- Accountability – document what we do and why.
2) Technical & Organisational Measures (TOMs)
- Transport security – HTTPS/TLS for all pages and forms.
- Perimeter protection – Cloudflare CDN, WAF, DDoS mitigation, bot management.
- Hosting security – patched servers, principle of least privilege, restricted admin access, activity logs.
- Access controls – MFA for admin accounts, role-based permissions, session timeouts, unique credentials.
- Data minimisation – we do not process payments or ID documents on our site; contact data is limited to what you send us.
- Backups & continuity – regular backups; tested restore procedures.
- Vulnerability management – timely updates to CMS/plugins; security monitoring and alerts.
- Encryption – encryption in transit (TLS); at-rest encryption provided by our hosting where available.
- Environment hygiene – staging/production separation; least-privilege API keys; secret rotation when needed.
- Staff & contractors – confidentiality obligations and need-to-know access.
3) Processors & Vendors
We use trusted service providers (“processors”) to operate the Website, including Cloudflare (DNS/CDN/WAF/DDoS), secure hosting,
web analytics (consent-based), anti-spam/security tools, email services, and affiliate networks (for click attribution).
We require appropriate contractual safeguards and process data only on documented instructions.
4) International Data Transfers
Where personal data is transferred outside the UK/EU/EEA by our processors (for example global network routing via Cloudflare),
we rely on recognised safeguards such as adequacy decisions, the UK IDTA, EU Standard Contractual Clauses (SCCs), or equivalent mechanisms.
5) Data Retention
- Contact enquiries: typically up to 12 months after resolution.
- Server & security logs (incl. Cloudflare): typically up to 90 days for security/troubleshooting.
- Analytics (if consented): typically 14–26 months in aggregated form.
- Cookie preferences: typically 6–12 months, or until cleared by you.
6) Data Subject Requests (Your Rights)
Depending on your jurisdiction, you may request access, rectification, deletion, restriction, objection, or portability, and withdraw consent for
consent-based processing. To exercise rights, email [email protected]. We may ask for information to verify identity.
7) DPIAs & High-Risk Processing
We assess new projects or tools for privacy risks. Where processing could be high-risk, we perform a Data Protection Impact Assessment (DPIA) and
apply additional safeguards before deployment.
8) Security Incidents & Breach Response
- Detection – monitoring via hosting/Cloudflare/security tools; triage alerts.
- Containment – isolate affected systems, rotate secrets, block malicious traffic.
- Assessment – determine scope, data categories, likelihood of risk to individuals.
- Notification – where legally required, notify the supervisory authority (e.g., UK ICO) and affected individuals within applicable timelines.
- Post-incident – root-cause analysis and remediation to prevent recurrence.
9) Children
Our Website is for adults aged 18+. We do not knowingly collect data from children. If you believe a minor has provided personal data,
contact us and we will delete it.
Questions about this Data Protection statement: [email protected].
UK supervisory authority: Information Commissioner’s Office (ICO).
This page provides general information and does not constitute legal advice. Your specific obligations may vary based on your stack and jurisdictions.