Data Protection & Privacy
Data We Collect
In the course of operating the platform accessible at golden-fishtank.com, which is licensed and regulated under Malta Gaming Authority licence reference MGA/B2B/230/2012, certain categories of personal data are collected, stored, and processed in accordance with applicable data protection legislation, including the General Data Protection Regulation (EU) 2016/679 (hereinafter referred to as "GDPR") and all relevant national implementing measures.
The following categories of personal data are subject to collection and processing by Yggdrasil Gaming:
- Identification Data: Full legal name, date of birth, nationality, and government-issued identification numbers, where required for identity verification and regulatory compliance purposes.
- Contact Data: Electronic mail address, postal address, telephone number, and any other contact details submitted voluntarily by the data subject or required for the fulfilment of contractual obligations.
- Technical Data: Internet Protocol (IP) addresses, browser type and version, operating system specifications, device identifiers, session identifiers, and access timestamps, collected automatically upon interaction with the platform.
- Behavioural Data: Navigation patterns, interaction logs, game session data, frequency of platform usage, and related analytical metrics gathered during the data subject's engagement with services.
- Financial Data: Payment instrument details, transaction histories, deposit and withdrawal records, and any information necessary for the processing of financial transactions and the fulfilment of anti-money laundering obligations.
- Communication Data: Records of correspondence initiated by or directed to the data subject, including support requests, complaints, and any written or electronic communications exchanged with company representatives.
- Compliance and Verification Data: Documentation and information collected for the purposes of Know Your Customer (KYC) procedures, responsible gambling assessments, and adherence to applicable regulatory requirements imposed by the Malta Gaming Authority.
Personal data is collected directly from the data subject at the point of registration, during account management, and throughout ongoing platform interactions. Certain technical data may be collected automatically through the use of cookies and similar tracking technologies deployed on the platform. The data subject is directed to the applicable Cookie Policy for further information regarding the use of such technologies.
Data Usage
Personal data collected through the platform is processed exclusively for specified, explicit, and legitimate purposes in accordance with the principle of purpose limitation as established under Article 5 of the GDPR. Processing activities are conducted on the basis of one or more lawful grounds as defined under Article 6 of the GDPR, including the performance of a contract, compliance with a legal obligation, and the pursuit of legitimate interests of the data controller.
The purposes for which personal data is processed are detailed as follows:
- Contractual Performance: Personal data is processed to the extent necessary for the establishment, management, and termination of contractual relationships with business partners and end users, including the provision of gaming content, platform functionality, and associated services.
- Regulatory Compliance: Data is processed in fulfilment of legal and regulatory obligations imposed upon the data controller by the Malta Gaming Authority and other competent authorities, including obligations pertaining to anti-money laundering, counter-terrorism financing, responsible gambling, and player protection requirements.
- Identity Verification: Processing is undertaken for the purpose of verifying the identity and age of individuals interacting with the platform, in accordance with applicable legislative requirements and licensing conditions under MGA/B2B/230/2012.
- Security and Fraud Prevention: Personal data is processed for the detection, investigation, and prevention of fraudulent activity, unauthorised access, and other threats to the integrity and security of the platform and its users.
- Platform Optimisation: Technical and behavioural data is analysed for the purpose of improving the functionality, performance, and user experience of the platform, including the identification and resolution of technical deficiencies.
- Customer Support: Communication data is processed to facilitate the management and resolution of support requests, complaints, and enquiries submitted by data subjects.
- Legal Claims: Personal data may be retained and processed where necessary for the establishment, exercise, or defence of legal claims before judicial, administrative, or regulatory bodies.
- Legitimate Interests: Where processing is based upon legitimate interests, such interests have been assessed and determined to be proportionate and not overridden by the fundamental rights and freedoms of the data subject.
Personal data shall not be processed for purposes incompatible with those originally specified at the time of collection, unless the data subject has provided explicit consent or processing is otherwise permitted under applicable law. Data shall be retained only for as long as is necessary to fulfil the purposes for which it was collected, or as required by applicable legal or regulatory retention obligations.
Data Protection
Yggdrasil Gaming has implemented comprehensive technical and organisational measures designed to ensure a level of security appropriate to the risks associated with the processing of personal data, in accordance with Article 32 of the GDPR. Such measures are reviewed and updated on a periodic basis to reflect developments in technology and the evolving threat landscape.
The technical and organisational safeguards currently in place include, but are not limited to, the following:
- Encryption: Personal data transmitted between the data subject and the platform is protected through the application of industry-standard Transport Layer Security (TLS) encryption protocols. Stored personal data is subjected to encryption measures commensurate with the sensitivity of the data concerned.
- Access Controls: Access to personal data is restricted on a strict need-to-know basis. Role-based access control mechanisms are employed to ensure that only authorised personnel are permitted to access, modify, or process personal data in connection with their designated responsibilities.
- Pseudonymisation: Where technically feasible and appropriate, personal data is pseudonymised to reduce the risk of identification in the event of unauthorised access or data breach incidents.
- Infrastructure Security: The platform infrastructure is maintained within secure environments subject to physical and logical access controls, including firewalls, intrusion detection systems, and continuous monitoring mechanisms.
- Incident Response: Documented procedures for the detection, reporting, and remediation of personal data breaches are maintained in accordance with the notification obligations set forth under Articles 33 and 34 of the GDPR. In the event of a breach likely to result in a risk to the rights and freedoms of natural persons, notification shall be made to the competent supervisory authority within the prescribed statutory timeframe.
- Processor Obligations: Where personal data is processed by third-party processors on behalf of Yggdrasil Gaming, such processors are required to provide sufficient guarantees regarding their technical and organisational measures, and processing activities are governed by data processing agreements concluded in accordance with Article 28 of the GDPR.
- Staff Training: Personnel engaged in the processing of personal data are subject to mandatory data protection training and are bound by obligations of confidentiality in relation to the personal data to which they are afforded access.
- Data Minimisation: Personal data is collected and retained only to the minimum extent necessary for the fulfilment of specified processing purposes, in accordance with the principle of data minimisation as established under Article 5(1)(c) of the GDPR.
Notwithstanding the measures described herein, the absolute security of data transmitted over the internet cannot be guaranteed. The data controller shall, however, take all reasonable steps to protect personal data against unauthorised or unlawful processing, accidental loss, destruction, or damage.
Your Rights
Data subjects whose personal data is processed by Yggdrasil Gaming in connection with the platform at golden-fishtank.com are afforded a comprehensive set of rights under applicable data protection legislation, including the GDPR. These rights may be exercised subject to the conditions, limitations, and exemptions provided for under applicable law.
The rights to which data subjects are entitled are set out as follows:
- Right of Access (Article 15 GDPR): The data subject is entitled to obtain confirmation as to whether personal data concerning them is being processed, and, where such processing is occurring, to receive a copy of the personal data together with supplementary information regarding the purposes, categories, recipients, and retention periods applicable to such processing.
- Right to Rectification (Article 16 GDPR): The data subject is entitled to request the correction of inaccurate personal data concerning them without undue delay. Taking into account the purposes of processing, the data subject is further entitled to request the completion of incomplete personal data.