1.Who we are
- Clause 1.1. [JustPoker Operating Company Ltd.] (“JustPoker”, “we”, “us”) is the controller of the personal data described in this policy. We are registered in [Jurisdiction of Incorporation] under number [Company Registration No.], our registered office is at [Registered Address], and we hold a remote gaming licence issued by [Licensing Authority] (licence [License Number]).
- Clause 1.2. Our data protection contact can be reached at compliance@justpoker.example or by post at the address above. Please mark correspondence “Data protection”.
2.Scope of this policy
- Clause 2.1. This policy applies to everyone who visits our website, opens an account, plays our games, contacts our support team or otherwise interacts with us. It should be read together with our Terms of Service, Cookie Policy and AML & KYC Policy.
- Clause 2.2. “Personal data” means any information relating to an identified or identifiable person. “Processing” means anything we do with it, from collecting and storing to sharing and deleting.
3.Personal data we collect
We collect the following categories of personal data. We collect no more than we need for each purpose.
- Clause 3.1. Account data — email address, username, password (stored only as a salted bcrypt hash; we never see or store your plain-text password), display name, date of birth, country of residence, marketing preferences and the date you registered.
- Clause 3.2. Identity and verification data — the type of document you present (passport, national identity card or driving licence), the images or PDF files you upload, the file names and sizes, the outcome of the review, and, at Level 3, the source-of-funds or source-of-wealth evidence you provide (for example payslips, bank or exchange statements, or wallet ownership proofs). In the current demo build document files themselves are not retained; only the metadata and review status are stored.
- Clause 3.3. Financial and transaction data — the ledger of every credit and debit on your balance (deposits, withdrawals, stakes, payouts, bonuses and adjustments), the deposit addresses we issue to you, withdrawal addresses you supply, blockchain transaction identifiers, amounts, exchange rates applied, and the status of each request.
- Clause 3.4. Gameplay data — every hand you play, including stakes, decisions, cards, results, the server seed hash, client seed and nonce used to deal it, your seed pairs (including revealed server seeds), and derived statistics such as hands played and net result over time. At a live table we also record the table, round and seat you played, the cards you chose to show and the client seed you contributed to the round's combined seed.
- Clause 3.5. Responsible-gambling data — the limits you set, your reality-check interval, session length, self-exclusion periods and any interactions with us about your wellbeing.
- Clause 3.6. Device and usage data — IP address, approximate location derived from it, browser type and version, operating system, screen size, language, referring page, pages visited, time on site, and the user-agent string recorded against each sign-in session.
- Clause 3.7. Support and communications data — messages you send us through the contact form or by email, the topic you select, our replies, and notes we make about the case.
- Clause 3.8. Password-reset data — when you ask to reset your password, a one-way hash of the single-use link we email you (never the link itself), when it was requested, used or expired, and the IP address the request came from. The email is sent through our email-delivery provider.
- Clause 3.9. Audit events — a log of account-level events such as sign-ins, password changes and resets, limit changes, self-exclusions, seed rotations and verification submissions, with timestamps.
- Clause 3.10. We do not deliberately collect special-category data (such as health data). If you volunteer such information — for example when telling us about gambling harm — we process it only to support you and to meet our responsible-gambling obligations, and we restrict access to it.
4.Purposes and legal bases
We process personal data for the purposes and on the legal bases below.
| Purpose | Data used | Legal basis |
|---|---|---|
| Creating and operating your account, dealing hands, settling bets, showing history | Account, financial, gameplay | Performance of our contract with you |
| Verifying your age and identity; preventing underage gambling | Account, identity | Legal obligation (licence conditions, gambling law) |
| Anti-money-laundering, counter-terrorist-financing and sanctions compliance | Identity, financial, device, audit events | Legal obligation |
| Enforcing limits, reality checks and self-exclusion; identifying signs of harm | Responsible-gambling, gameplay, financial | Legal obligation; legitimate interest in player protection |
| Detecting fraud, multi-accounting, bots, collusion and bonus abuse | Device, gameplay, financial, audit events | Legitimate interests (integrity of the games; protecting other players); legal obligation |
| Securing the service and your account (including password-reset emails), investigating incidents | Account, device, password-reset data, audit events | Legitimate interests; legal obligation |
| Answering your questions and complaints | Support, account, relevant gameplay or financial records | Performance of our contract; legal obligation (complaint handling) |
| Sending promotional emails | Account (email, preferences) | Consent — you can withdraw it at any time in Settings |
| Service announcements (changes to terms, security notices, regulatory notices) | Account (email) | Performance of our contract; legal obligation |
| Aggregate analysis to improve the product | Gameplay and usage data, aggregated or pseudonymised | Legitimate interests |
Where we rely on legitimate interests we have balanced them against your rights and interests. You may object to processing on this basis (see section 9).
5.How long we keep your data
- Clause 5.1. We keep personal data only for as long as it is needed for the purpose it was collected, and then for as long as the law requires us to keep it. Anti-money-laundering law obliges us to retain customer due diligence records and transaction records for at least five years after the end of the business relationship or the date of the transaction, whichever is later. This period may be extended where a regulator or law-enforcement agency requires it, or where a dispute or investigation is open.
- Clause 5.2. Indicative retention periods:
- Identity and verification records, ledger and transaction records, hand history: five years after account closure (AML retention), then deleted or irreversibly anonymised.
- Self-exclusion records: for the duration of the exclusion plus a further period required to prevent re-registration (permanent exclusions are kept indefinitely in a minimal form).
- Sign-in sessions: 30 days from creation, or until you sign out or end all sessions. Resetting your password ends every session at once.
- Password-reset links: a link works once and for 60 minutes; the stored record of it is deleted 24 hours after it expires or is used.
- Support correspondence: three years from the closure of the case, or five years if it relates to a complaint or a financial transaction.
- Server logs containing IP addresses: 12 months, unless retained as part of a security investigation.
- Marketing preferences: for as long as you have an account, and a suppression record of your opt-out afterwards so that we do not contact you again.
- Clause 5.3. When a retention period ends we delete the data securely or anonymise it so that it can no longer be linked to you. Anonymised, aggregated statistics (for example total hands dealt) may be kept indefinitely.
6.Who we share data with
- Clause 6.1. We do not sell personal data. We share it only with the following categories of recipient, and only what each needs:
- Identity-verification and screening providers, who check your documents, verify your age and address, and screen against sanctions and politically-exposed-persons lists on our behalf.
- Payment and blockchain-analytics providers, who process cryptocurrency deposits and withdrawals, quote exchange rates, and assess the risk of the wallets you transact with.
- Hosting, infrastructure, email-delivery and security providers that run the service under contract with us and act only on our instructions.
- Professional advisers and auditors, including — once appointed — the independent testing laboratory that will evaluate our games and random-number generation before real-money launch, under confidentiality obligations.
- Regulators and authorities — [Licensing Authority], financial-intelligence units, tax authorities, courts and law-enforcement agencies — where the law requires or permits it, including when we file a suspicious-activity report. We are legally prohibited from telling you when such a report has been made.
- Other operators and industry bodies, through recognised schemes for self-exclusion and fraud prevention, to the extent permitted by law.
- A successor operator, if we transfer the business or the licence, on notice to you and subject to this policy continuing to apply.
- Clause 6.2. Other players at a live table. A live table is shared, so every signed-in player viewing it can see, while you are seated: your username and seat; your bets and decisions; any hole cards you choose to show; at the showdown, the hole cards of every seat dealt into the round, yours included; and your result. The round record — each dealt-in seat's username, seat and shown cards, and the client seed you contributed to the round's combined seed — is kept in the hand history of every other player dealt into that round, so it remains visible to them after you leave. Your email address, balance and other account data are never shown. If you do not want this, play the single-player games instead.
- Clause 6.3. Each processor acting on our behalf is bound by a written contract that requires it to protect your data, use it only for our purposes and delete it when the contract ends.
7.International transfers
- Clause 7.1. Some recipients listed above are located outside [Jurisdiction of Incorporation], and outside the European Economic Area and the United Kingdom. Where we transfer personal data to a country that has not been recognised as providing adequate protection, we rely on appropriate safeguards — normally the European Commission's Standard Contractual Clauses or the UK International Data Transfer Addendum — together with an assessment of the laws of the destination country and supplementary technical measures such as encryption.
- Clause 7.2. You may request a copy of the safeguards we use by contacting compliance@justpoker.example.
8.How we protect your data
- Clause 8.1. We protect personal data with technical and organisational measures appropriate to the risk, including: encryption of data in transit (TLS) and at rest; passwords stored only as salted bcrypt hashes; session cookies that are HTTP-only, same-site and marked secure in production; least-privilege access controls and logging of staff access; segregated environments; regular dependency and vulnerability reviews; and an incident-response plan.
- Clause 8.2. Server seeds used for provably fair dealing are secret until revealed and are never transmitted to any client before the hands dealt with them are complete. The dealer's hole cards are never sent to your device before a hand resolves.
- Clause 8.3. If a personal-data breach is likely to result in a risk to you we will notify the competent supervisory authority within 72 hours of becoming aware of it and, where the risk is high, notify you directly without undue delay.
- Clause 8.4. No system is perfectly secure. You can help by using a unique password, enabling two-factor authentication where available, keeping your device updated and signing out on shared devices.
9.Your rights
- Clause 9.1. Subject to the law that applies to you, you have the right to:
- Access — obtain confirmation that we process your data and a copy of it, together with the information in this policy.
- Rectification — have inaccurate data corrected and incomplete data completed. Some fields (for example your name or date of birth) can only be changed with supporting documents, because they are part of your verified identity.
- Erasure — ask us to delete your data. Important limitation: we cannot delete identity, transaction, gameplay or self-exclusion records that we are legally required to keep (see section 5). In those cases we will restrict the data so that it is used only to meet the legal obligation, and delete it when the retention period ends.
- Restriction — ask us to pause processing while a dispute about accuracy or lawfulness is resolved.
- Portability — receive the data you provided to us in a structured, commonly used, machine-readable format. Your transaction ledger can be exported as a CSV file from your account; your hand history is shown hand by hand in your account and we will provide it as a file on request.
- Objection — object to processing based on legitimate interests, and at any time to direct marketing. Marketing stops immediately when you opt out in Settings or use the unsubscribe link.
- Withdraw consent — where processing relies on consent, without affecting processing that took place before withdrawal.
- Complain — to a supervisory authority (see section 14).
- Clause 9.2. To exercise a right, email compliance@justpoker.example from your registered address or use the contact form while signed in. We may ask you to verify your identity before acting. We respond within one month; for complex or multiple requests we may extend this by up to two further months and will tell you if so. Requests are free unless they are manifestly unfounded or excessive.
10.Automated decisions and profiling
- Clause 10.1. We use automated rules to flag activity for human review — for example deposits above a threshold, rapid changes in play, or device signals shared between accounts. Decisions with a significant effect on you, such as closing an account, refusing a withdrawal or rejecting a verification submission, are always reviewed by a trained member of staff before they are final.
- Clause 10.2. Our games are not personalised. The outcome of every hand is determined solely by the provably fair algorithm described on the Provably Fair page; no personal data influences the shuffle.
- Clause 10.3. You may ask for a human review of any automated flag that affects you and express your point of view by contacting support.
11.Cookies and local storage
- Clause 11.1. We use one essential session cookie and a small number of browser local-storage entries. We do not currently use third-party analytics or advertising cookies. The full list, with durations and purposes, is in our Cookie Policy.
12.Children
- Clause 12.1. The service is strictly for adults aged 18 or over. We do not knowingly collect data from anyone younger. If we learn that an account belongs to a minor we close it and delete the data, except for the minimal record we must keep to prevent re-registration and to comply with the law. If you believe a minor has used our service, contact compliance@justpoker.example.
13.Changes to this policy
- Clause 13.1. We review this policy at least annually and whenever our processing changes. The current version, with its “last updated” date, is always published at /legal/privacy. If a change materially affects how we use your data we will notify you by email or by a notice when you next sign in before it takes effect.
14.Contact and complaints
- Clause 14.1. Data protection queries and rights requests: compliance@justpoker.example. General support: support@justpoker.example or the contact form.
- Clause 14.2. If you are unhappy with how we have handled your data you have the right to lodge a complaint with the data protection supervisory authority in [Jurisdiction of Incorporation] or in the country where you live or work. We would appreciate the chance to address your concern first, but you are not required to contact us before complaining to an authority.