As a authorized operator in Italy, visita il sito, we gather and look after personal and transactional data under rigorous legal obligations. This policy outlines exactly how long we hold different categories of information, the legal reasons behind those periods, and the security measures that protect your data at every stage. We regularly balance our duty to retain records for fraud prevention and financial audits with the privacy rights you hold under Italian data protection law and the GDPR. Our schedules receive regular reviews so we keep fully compliant.
Data Transfers Abroad and Retention
Our core infrastructure sits in Italy and the broader European Economic Area. Some ancillary services, like fraud detection platforms and customer relationship tools, may send limited personal data to countries beyond the EEA. In those cases, we ensure an adequacy decision exists or we implement Standard Contractual Clauses in place together with a transfer impact assessment. The retention periods we use to transferred data mirror those in this policy, and processors are contractually bound to remove or return data when the service ends. We keep a public register of sub‑processors, updated within fourteen days of any change, and we prefer vendors with Italian data centres. Geo‑fencing rules keep Italian user data inside European boundaries, validated through yearly audits.
Partner Program Data Retention
Partner relationship data, including communication data, payment details and commission transaction history, stays for the entirety of the active relationship plus ten years after the partnership concludes. This is due to tax obligations on commission payments, which necessitate long‑term financial archives. Affiliate performance metrics and combined referred-player data get anonymized after half a decade. We explicitly prohibit affiliates from separately gathering or storing personal information about referred customers; they obtain only anonymous, aggregated statements. Our affiliate agreements include audit rights to ensure compliance, and any infringement is reason for immediate contract termination and commission loss.
Individual Rights and Retention Management
When you submit an erasure request, our system automatically examines each data category against its retention schedule. Anything past its mandatory window gets deleted without delay. For data still governed by a legal retention obligation, we secure it right away so it’s excluded from active use and stored only for compliance storage; we advise you which specific law is in effect and the date deletion becomes possible. Access requests are responded to within thirty days and include a breakdown of what we store, why, and the scheduled deletion date. If you question accuracy, we append a note instead of modifying the original record, so the audit trail is preserved. Portability requests are honoured in a structured, machine‑readable format even while data is still in its retention window.
Data Security In Preservation
Held data is secured with AES‑256 encryption at rest, TLS 1.3 protocols in transit and isolated virtual private clouds. Access necessitates multi‑factor authentication plus just‑in‑time privilege elevation that ends on its own. Every access event is recorded into an immutable audit trail. We run quarterly penetration tests through CREST‑certified firms and continuous vulnerability scans to ensure our storage tight. Backups are encrypted and spread across Italian data centres, with strict controls that block accidental restoration of data past its deletion date. A dedicated lifecycle dashboard flags every dataset as it nears expiration.

Permission Management and Workforce Training
Only employees whose roles demonstrably need access to retained personal data get permissions, and those permissions go through monthly recertification audits. Any access to dormant user records triggers a managerial review within one business day. Every staff member who handles personal data completes mandatory annual training on Italian data protection law and our internal retention policies, including hands‑on exercises on spotting valid erasure requests and distinguishing the difference between data we must keep under a legal hold and data we can delete straight away.
Legal Basis for Data Retention
Our storage strategy rests on several legal obligations that apply to gambling operators serving the Italian market. Anti‑money laundering directives from the Italian Financial Intelligence Unit force us to keep transaction logs, identity verification documents and suspicious activity reports for a fixed term after the business relationship ends. Meanwhile, tax rules imposed by the Agenzia delle Entrate demand we preserve financial records that back up taxable gaming revenue and player winnings. These duties override any general right to erasure during the mandatory period. For operational data that isn’t covered by a fixed legal window, we base our approach on legitimate interest assessments where a valid reason exists, and we offer an opt‑out unless a compelling legal obligation overrides it.
Consent‑Based Retention
Marketing preferences, newsletter sign‑ups and the behavioural analytics employed for personalised offers are kept only with your explicit consent. You can revoke consent anytime through your account dashboard; once you do, we cease that processing immediately and delete the connected profiles within thirty days. Data processed lawfully before withdrawal is removed from active systems to block further use, but it is not removed retroactively. Consent records themselves are kept for six years as proof of compliance. We do not use this data for anything beyond the activity you agreed to.
Data Removal Procedures
When a information type hits the end of its designated storage time, our self-running lifecycle mechanism kicks off a safe removal process. First, the data gets logically removed from production databases. Next, physical storage blocks are rewritten with random data patterns to stop forensic recovery. Finally, a cryptographically timestamped entry lands in a compliance ledger, giving verifiable evidence that purging happened on time. Backup copies refresh every ninety days, so any deleted data disappears from all media within three months. When a litigation hold applies, we halt the deletion workflow only for the affected records, document the hold reason, and resume once the hold lifts.
Policy Updates and User Notification
We assess this Data Retention Policy every six months and whenever a major legal change hits Italian gambling operations. Minor clarifications are published silently with a revised effective date. Material changes that alter retention periods, add new data categories or change the legal basis for processing are communicated directly to you by email at least thirty days before they take effect. You’ll also see an in‑platform banner notification when you log in during the notice period. Historical versions are archived and available on request, each with a version number and a validity date range. If an earlier version provided a shorter retention period for certain data, we stick to that promise for data collected under that version and apply new terms only going forward.
Information Categories and Retention Periods
We categorize all user data into clear categories, each linked to a retention schedule that corresponds to its purpose and legal context. That organized approach keeps us from keeping things forever. Every year our Data Protection Officer examines these groupings and updates the timelines whenever new guidance emerges from the Garante per la protezione dei dati personali. Below you’ll find how long each data type stays in our live systems before being securely anonymised or deleted. Archived backups operate on a ninety‑day cycle because of technical limitations.
Identity and Monetary Records
Identity documents you submit during Know Your Customer checks, like passport scans, utility bills and tax ID numbers, stay on file for ten years after you end your account, as anti‑money laundering law stipulates. Deposit and withdrawal logs, payment method tokens and wallet balance histories are kept for ten years from the date of each transaction, meeting both AML requirements and Italian Civil Code limitation periods. We hold these records in encrypted, access‑restricted vaults and tamper‑proof ledgers. Once the retention deadline expires, we remove all personal identifiers permanently; statistical trends may still be utilized but never in a way that links back to any individual.
User Activity and Customer Support Interactions
Comprehensive records of game sessions, bets placed, outcomes and session lengths are kept for five years after each gaming event, matching the statute of limitations for civil disputes. Customer service transcripts, email threads and call recordings stay for three years from your last interaction, covering the typical complaint‑handling window. After those periods, raw logs and case attachments get permanently deleted. Aggregated, anonymised datasets can be kept indefinitely for product improvement and service quality analysis. All of this data lives in case management systems with role‑based access restrictions.
Ethical Play and Self‑Exclusion Data
Upon activating self‑exclusion, your identity data must be stored permanently in a locked‑down register to stop you from opening new accounts, a measure Italian gambling regulations explicitly permit. Other safer‑gambling markers, like expired voluntary deposit limits, are deleted two years after the repubblica.it limit lifts. We never use self‑exclusion register data for anything other than enforcing the exclusion. The register is completely walled off from marketing and operational systems, so it serves only its protective purpose.
Popular Queries
May I request data erasure before the retention period expires?
Certainly, you can submit a deletion request at any moment. We instantly examine each data category in relation to its legal retention duty. When no legal hold exists, we remove it quickly. For anything we must keep, we restrict it to storage‑only, tell you the legal basis stopping immediate deletion and give you the expected deletion date. Additionally, you can see all your data categories along with their planned deletion dates via your account dashboard. This partial method honors your rights to the extent permitted by Italian regulations.
What occurs with my data when I opt for permanent self‑exclusion?
If you sign up for permanent self‑exclusion, your personal data is shifted to a dedicated exclusion register that operates indefinitely with highly restricted access. That’s a legal requirement built to prevent you from opening new accounts. Your gameplay and transaction history, on the other hand, still follow the standard retention schedules and get deleted once those periods run out. The self‑exclusion record is separated from all marketing and operational platforms, so it only serves the safeguarding role it was intended for. You will not receive any promotional messages.
What is your approach to data from inactive accounts?
After twelve uninterrupted months of no login, an account is considered inactive. At that point, we automatically switch off marketing communications and move the account to a dormant state with reduced processing. The fundamental retention timelines continue based on the initial collection dates, not the inactivity date. This implies that data from a dormant account is still retained for the complete legal period relevant to its category and subsequently erased following our standard protocols. If you come back after a long break, you might need to complete a fresh Know Your Customer check to reactivate. The current status is always visible on your data dashboard.

























