Golden Fish Tank Slot

Privacy & Security

Information Collection

The following categories of personal data are collected and processed by Yggdrasil Gaming, operating the platform accessible at golden-fishtank.com under license reference MGA/B2B/230/2012, issued by the Malta Gaming Authority:

  • Identification Data: Full legal name, date of birth, nationality, and government-issued identification document details are collected for the purposes of identity verification and regulatory compliance.
  • Contact Data: Electronic mail address, telephone number, and residential address are recorded to facilitate account administration and communication with registered users.
  • Financial Data: Payment instrument details, transaction histories, deposit and withdrawal records, and banking information are processed in accordance with applicable anti-money laundering obligations.
  • Technical Data: Internet Protocol addresses, browser type and version, device identifiers, operating system information, session timestamps, and cookie identifiers are automatically collected during user interaction with the platform.
  • Behavioral Data: Gaming activity records, wagering patterns, session durations, game preferences, and platform navigation data are retained for service optimization and responsible gambling monitoring purposes.
  • Verification Data: Documentation submitted in connection with Know Your Customer procedures, including copies of identity documents, proof of address, and source of funds declarations, are processed pursuant to regulatory requirements imposed by the Malta Gaming Authority.

Personal data is collected through multiple channels, including but not limited to account registration forms, identity verification procedures, transactional interactions, automated technical systems, and correspondence initiated by the data subject. The provision of certain categories of personal data constitutes a mandatory prerequisite for the delivery of services, and failure to supply such data may result in the inability to establish or maintain an account on the platform.

How We Use Data

Personal data collected through the platform is processed exclusively for the following defined and legitimate purposes, each grounded in an applicable legal basis under the General Data Protection Regulation (EU) 2016/679 and applicable Maltese data protection legislation:

  • Account Establishment and Administration: Personal data is processed to create, maintain, verify, and administer user accounts. Such processing is necessary for the performance of a contractual relationship between the data subject and the operator.
  • Regulatory and Legal Compliance: Data is processed to fulfill obligations imposed by the Malta Gaming Authority under license MGA/B2B/230/2012, as well as obligations arising under the Prevention of Money Laundering Act, the Gaming Act (Chapter 583 of the Laws of Malta), and applicable directives concerning anti-money laundering and counter-financing of terrorism. Such processing is mandated by legal obligation.
  • Transaction Processing and Financial Operations: Financial data is processed to execute deposits, withdrawals, bonus allocations, and other monetary transactions associated with the platform account. This processing is carried out pursuant to contractual necessity.
  • Fraud Prevention and Security: Technical and behavioral data are analyzed to detect, investigate, and prevent fraudulent activity, unauthorized access, and other security incidents. Such processing is justified on the grounds of legitimate interests pursued by the operator in maintaining platform integrity.
  • Responsible Gambling Oversight: Gaming behavior and usage data are monitored to identify indicators of problem gambling and to apply protective measures in accordance with responsible gambling obligations mandated by the Malta Gaming Authority.
  • Customer Support and Dispute Resolution: Correspondence records and account data are processed to respond to inquiries, resolve complaints, and manage any disputes arising from the use of the platform.
  • Service Analytics and Improvement: Aggregated and anonymized technical and behavioral data may be analyzed for the purpose of improving platform functionality, user experience, and service quality.
  • Direct Communications: Where consent has been obtained or legitimate interest applies, contact data may be used to transmit service-related notifications, security alerts, and, where separately consented to, marketing communications. Data subjects retain the right to withdraw consent for marketing communications at any time.

Personal data shall not be processed for purposes incompatible with those specified herein. No personal data shall be sold, rented, or otherwise transferred to third parties for independent commercial exploitation. Data may be disclosed to third-party processors, including payment service providers, identity verification agencies, and cloud infrastructure providers, solely to the extent necessary for the fulfillment of the above-stated purposes, and subject to appropriate contractual safeguards.

Security Measures

Yggdrasil Gaming has implemented a comprehensive set of technical and organizational measures designed to ensure the confidentiality, integrity, and availability of personal data processed through the golden-fishtank.com platform. These measures are maintained in accordance with Article 32 of the General Data Protection Regulation and applicable standards prescribed by the Malta Gaming Authority.

  • Encryption Protocols: All data transmitted between users and the platform is encrypted utilizing Transport Layer Security (TLS) protocols with a minimum standard of TLS 1.2. Sensitive data stored within internal systems is subject to encryption at rest using industry-standard cryptographic algorithms.
  • Access Control Mechanisms: Access to personal data is restricted to authorized personnel whose professional responsibilities necessitate such access. Role-based access control policies are enforced, and all access events are subject to logging and periodic audit review.
  • Authentication Systems: Multi-factor authentication is applied to administrative and privileged access accounts. User accounts are protected through secure password hashing mechanisms compliant with current cryptographic standards.
  • Network Security Infrastructure: Firewalls, intrusion detection systems, and intrusion prevention systems are deployed to monitor and filter network traffic. Vulnerability assessments and penetration testing are conducted on a periodic basis to identify and remediate potential security weaknesses.
  • Data Minimization and Retention Controls: Personal data is retained only for the period necessary to fulfill the purposes for which it was collected, subject to any extended retention obligations imposed by law or regulatory authority. Data minimization principles are applied at the point of collection.
  • Incident Response Procedures: Documented incident response procedures are maintained to ensure timely identification, containment, and notification of personal data breaches in accordance with the seventy-two-hour notification requirement established under Article 33 of the General Data Protection Regulation.
  • Third-Party Processor Oversight: All third-party data processors engaged by the operator are subject to data processing agreements containing mandatory security requirements. Periodic assessments of processor compliance are conducted to verify ongoing adherence to contractual and regulatory obligations.
  • Staff Training and Awareness: Personnel with access to personal data are required to undergo training on data protection obligations, security practices, and confidentiality requirements. Compliance with internal data protection policies is a condition of employment for all relevant staff.

Notwithstanding the foregoing measures, it is acknowledged that no technical or organizational safeguard can guarantee absolute protection against all potential security threats. Users are encouraged to adopt appropriate security practices in connection with their use of the platform, including the selection of strong, unique passwords and the prompt reporting of any suspected unauthorized account activity.

User Rights

Data subjects whose personal data is processed by Yggdrasil Gaming in connection with the golden-fishtank.com platform are entitled to exercise the following rights in accordance with Chapter III of the General Data Protection Regulation (EU) 2016/679 and applicable national implementing legislation:

  • Right of Access (Article 15 GDPR): Data subjects are entitled to obtain confirmation as to whether personal data concerning them is being processed and, where such processing occurs, to receive a copy of the personal data together with information regarding the purposes of processing, the categories of data concerned, the recipients or categories of recipients, the envisaged retention period, and the existence of automated decision-making.
  • Right to Rectification (Article 16 GDPR): Data subjects are entitled to request the correction of inaccurate personal data and the completion of incomplete personal data without undue delay. Requests for rectification will be assessed and, where substantiated, acted upon within the statutory timeframe.
  • Right to Erasure (Article 17 GDPR): Data subjects may request the deletion of personal data where it is no longer necessary for the purposes for which it was collected, where consent has been withdrawn and no alternative legal basis exists, where an objection has been lodged and no overriding legitimate grounds persist, or where the data has been unlawfully processed. It is noted that certain data may be exempt from erasure where retention is required by applicable regulatory or legal obligations, including those imposed by the Malta Gaming Authority under license MGA/B2B/230/2012.
  • Right to Restriction of Processing (Article 18 GDPR): Data subjects are entitled to request the restriction of processing in circumstances where the accuracy of personal data is contested, where processing is unlawful but erasure is opposed, where the data is no longer required by the operator but is needed by the data subject for the establishment or defense of legal claims, or where an objection to processing has been lodged pending verification of overriding grounds.
  • Right to Data Portability (Article 20 GDPR): Where processing is based on consent or contractual necessity and is carried out by automated means, data subjects are entitled to receive personal data concerning them in a structured, commonly used, and machine-readable format, and to transmit such data to another controller without hindrance.
  • Right to Object (Article 21 GDPR): Data subjects are entitled to object to the processing of personal data where such processing is based on legitimate interests or performed for direct marketing purposes. Upon receipt of an objection to direct marketing, processing for such purposes shall cease without exception.
  • Rights Related to Automated Decision-Making (Article 22 GDPR): Data subjects are entitled not to be subject to decisions based solely on automated processing, including profiling, which produce legal effects or similarly significant effects, except where such processing is necessary for the performance of a contract, authorized by applicable law, or based on explicit consent.
  • Right to Lodge a Complaint: Where a data subject considers that the processing of personal data infringes applicable data protection law, the right to lodge a complaint with the competent supervisory authority is available. In Malta, the relevant authority is the Information and Data Protection Commissioner (IDPC), accessible at idpc.org.mt.

Requests for the exercise of any of the above-enumerated rights shall be submitted in writing to the contact address specified herein. The operator is obligated to respond to such requests within one calendar month of receipt, with the possibility of extension by a further two months where requests are complex or numerous in volume, subject to notification of the data subject within the initial one-month period. Identity verification may be required prior to the processing of any data subject request.

Contact Us

All inquiries, requests, or correspondence pertaining to the processing of personal data, the exercise of data subject rights, or any matter relating to this privacy documentation shall be directed to the data protection contact point of Yggdrasil Gaming as follows:

Electronic correspondence: [email protected]

Requests submitted via electronic mail shall be acknowledged upon receipt, and a substantive response shall be provided within the timeframe prescribed by applicable data protection legislation. Data subjects are advised to clearly specify the nature of their request and to include sufficient information to enable verification of identity where required. The operator is committed to addressing all data protection inquiries in a diligent, impartial, and timely manner consistent with its obligations under the General Data Protection Regulation and the regulatory framework administered by the Malta Gaming Authority under license MGA/B2B/230/2012.

🍪 This site uses cookies to improve your experience. Read more in our Privacy Policy.
Necessary
Required for the website to function properly
Analytics
Help us understand how visitors use the site
Marketing
Used for personalized advertising
Preferences
Remember your site preferences