How Mafia Protects Your Personal Data
Eight registration data points, from email to date of birth, are collected the moment an account is opened. We explain what Mafia Casino online holds, why, and how long it is kept.
Read Our Privacy NoticePrivacy Policy at Mafia Casino
When players register with Mafia Casino online, we collect a defined set of registration data: email address, date of birth, country, phone number, gender, full name, social security number, zip code and username, along with the IP address and location data captured automatically at sign-up. We also gather device information, usage logs and general location data during ongoing play, and we may supplement this with information from public and government databases, credit and fraud prevention agencies, and data the player has made public, for example through linked social accounts.
Why we process this data
We rely on four lawful bases: performance of our contract with the player, compliance with legal obligations, our legitimate interests, and consent. Legitimate interest covers things such as fraud detection, IT security, responsible gaming segmentation and analysing gaming behaviour to recommend games and features. Consent is required for direct marketing, customised offers and targeted advertising.
Access to games is offered only through a protected network using technology for encrypting sensitive data, and administrative, technical and physical safeguards are applied throughout, though absolute security is not guaranteed.
What Data We Collect and Where It Comes From
Personal data reaches us through three channels: what the player provides directly, what is captured automatically, and what we obtain from outside sources.
| Category | Examples |
|---|---|
| Registration data | Email, date of birth, country, phone number, full name, username |
| Automatically collected | IP address, device identifiers, operating system, usage logs |
| Third-party sourced | Public and government databases, credit and fraud prevention agencies |
| International transfers | Standard Contractual Clauses or other recognised safeguards |
This spread means identity, financial and behavioural data all pass through the same privacy framework, which is why KYC checks and marketing consent are handled under separate lawful bases.
Your Data Protection Rights
As a registered player, a number of specific rights are available to you regarding the personal data we hold:
- Access — request confirmation of what personal data we hold about you
- Rectification — ask us to correct inaccurate or incomplete data
- Erasure — request deletion of your data where no legal basis requires us to keep it
- Restriction of processing — limit how your data is used while a dispute is resolved
- Data portability — receive your data in a format you can transfer elsewhere
- Objection — object to processing based on legitimate interest or direct marketing
- Withdrawal of consent — withdraw consent previously given for marketing or personalisation
- Complaint — lodge a complaint with a supervisory authority in your EU member state of residence, place of work, or place of alleged infringement
Any of these rights can be exercised by contacting our Data Protection Officer directly through the address provided on our site.
Data Retention and Sharing
We retain personal data for the duration of the account and for as long as needed to fulfil the purposes described in our notice, with longer retention required where anti-money-laundering or other regulatory obligations apply. Once an account is closed and no further legal or business need remains, data is deleted or anonymised.
Personal data may be shared with internal authorised employees and group subsidiaries, payment providers and financial institutions for their own compliance checks, customer support and technology providers, fraud prevention agencies, marketing partners, game providers, and law enforcement or regulatory authorities where required. If a complaint or query is raised on a third-party platform such as a casino review site or dispute resolution body, we may respond directly to that platform and disclose only the personal data necessary to identify the account and resolve the matter.
Where data is transferred outside the EU/EEA, we rely on adequacy decisions, Standard Contractual Clauses or other legally recognised safeguards to keep the same level of protection in place.