As a authorized operator in Italy, richroyalcasino programma partner, we obtain and manage personal and transactional data under stringent legal obligations. This policy outlines exactly how long we hold different categories of information, the legal reasons behind those periods, and the security measures that protect your data at every stage. We regularly balance our duty to retain records for fraud prevention and financial audits with the privacy rights you maintain under Italian data protection law and the GDPR. Our schedules undergo regular reviews so we stay fully compliant.
Cross-border Data Transfers and Retention
Our main systems sits in Italy and the wider European Economic Area. Some secondary services, like fraud detection platforms and customer relationship tools, may pass limited personal data to countries outside the EEA. In those cases, we make sure an adequacy decision is in place or we establish Standard Contractual Clauses in place together with a transfer impact assessment. The retention periods we apply to transferred data reflect those in this policy, and processors are contractually bound to delete or return data when the service ends. We maintain a public register of sub‑processors, updated within fourteen days of any change, and we choose vendors with Italian data centres. Geo‑fencing rules keep Italian user data inside European boundaries, confirmed through yearly audits.
Data Safeguarding In Retention
Stored information is safeguarded with AES‑256 encryption at rest, TLS 1.3 protocols in transit and isolated virtual private clouds. Access requires multi‑factor authentication plus just‑in‑time privilege elevation that terminates on its own. Every access event is written into an immutable audit trail. We run quarterly penetration tests through CREST‑certified firms and continuous vulnerability scans to maintain our storage tight. Backups are encrypted and spread across Italian data centres, with strict controls that block accidental restoration of data past its deletion date. A dedicated lifecycle dashboard flags every dataset as it nears expiration.
Permission Management and Staff Training
Only employees whose roles demonstrably require access to retained personal data get permissions, and those permissions go through monthly recertification audits. Any access to dormant user records initiates a managerial review within one business day. Every staff member who handles personal data completes mandatory annual training on Italian data protection law and our internal retention policies, including hands‑on exercises on spotting valid erasure requests and differentiating the difference between data we must keep under a legal hold and data we can delete straight away.
Policy Revisions and User Notifications
We review this Data Retention Policy every six months and whenever a major legal change impacts Italian gambling operations. Minor clarifications are posted silently with a revised effective date. Material changes that alter retention periods, include new data categories or alter the legal basis for processing are communicated directly to you by email at least thirty days before they take effect. You’ll also see an in‑platform banner notification when you log in during the notice period. Historical versions are stored and available on request, each with a version number and a validity date range. If an earlier version gave a shorter retention period for certain data, we follow that promise for data collected under that version and apply new terms only going forward.
Legal Basis for Data Retention
Our storage strategy relies on several legal obligations that govern gambling operators targeting the Italian market. Anti‑money laundering rules from the Italian Financial Intelligence Unit force us to keep transaction logs, identity verification documents and suspicious activity reports for a specific duration after the business relationship ends. Meanwhile, tax rules imposed by the Agenzia delle Entrate require we preserve financial records that substantiate taxable gaming revenue and player winnings. These duties override any general right to erasure during the mandatory period. For operational data that falls outside a fixed legal window, we base our approach on legitimate interest assessments where a valid reason exists, and we offer an opt‑out unless a compelling legal obligation stops us.
Consent‑Based Retention
Marketing preferences, newsletter sign‑ups and the behavioural analytics utilised for personalised offers stay only with your explicit consent. You can retract consent anytime through your account dashboard; once you do, we stop that processing immediately and delete the connected profiles within thirty days. Data processed lawfully before withdrawal is removed from active systems to block further use, but it is not deleted retroactively. Consent records themselves are kept for six years as proof of compliance. We never employ this data for anything beyond the activity you agreed to.
Affiliate Program Data Retention
Partner relationship data, including contact details, payout data and commission payment history, remains for the duration of the current agreement plus 10 years after the partnership concludes. This is due to tax duties on commission payouts, which demand long‑term financial records. Affiliate performance statistics and aggregated referred‑player statistics get anonymised after five years. We firmly disallow affiliates from autonomously collecting or retaining personal data about referred players; they receive only anonymised, aggregated summaries. Our affiliate agreements include inspection rights to check adherence, and any violation is reason for prompt contract ending and payout forfeiture.
Data Types and Retention Periods
We sort all user data into distinct categories, each tied to a retention schedule that matches its purpose and legal context. That structured approach prevents us from keeping things forever. Every year our Data Protection Officer examines these categories and adjusts the timelines whenever new guidance comes from the Garante per la protezione dei dati personali. Below you’ll view how long each data type stays in our live systems before being securely anonymised or destroyed. Archived backups roll on a ninety‑day cycle because of technical restrictions.
Identity and Fiscal Records
Identity documents you upload during Know Your Customer checks, like passport scans, utility bills and tax ID numbers, are kept on file for ten years after you close your account, as anti‑money laundering law requires. Deposit and withdrawal logs, payment method tokens and wallet balance histories are kept for ten years from the date of each transaction, satisfying both AML requirements and Italian Civil Code limitation periods. We keep these records in encrypted, access‑restricted vaults and tamper‑proof ledgers. Once the retention deadline elapses, we strip away all personal identifiers permanently; statistical trends may still be applied but never in a way that traces to any individual.
User Activity and Customer Support Interactions
Detailed logs of game sessions, bets placed, outcomes and session lengths are kept for five years after each gaming event, matching the statute of limitations for civil disputes. Customer service transcripts, email threads and call recordings stay for three years from your last interaction, covering the typical complaint‑handling window. After those periods, raw logs and case attachments get permanently deleted. Aggregated, anonymised datasets can be kept indefinitely for product improvement and service quality analysis. All of this data lives in case management systems with role‑based access restrictions.
Safe Gaming and Self‑Exclusion Data
Once you enable self‑exclusion, your identity data must be stored permanently in a locked‑down register to stop you from opening new accounts, a measure Italian gambling regulations explicitly permit. Other safer‑gambling markers, like expired voluntary deposit limits, are deleted two years after the limit lifts. We never use self‑exclusion register data for anything other than enforcing the exclusion. The register is completely walled off from marketing and operational systems, so it serves only its protective purpose.
User Rights and Retention Handling
When you submit an erasure request, our system automatically checks each data category against its retention schedule. Everything beyond its mandatory window is erased without delay. For data still under a legal retention obligation, we lock it down right away so it’s excluded from active use and held only for compliance storage; we advise you which specific law is in effect and the date deletion becomes possible. Access requests are responded to within thirty days and come with a breakdown of what we hold, why, and the scheduled deletion date. If you dispute accuracy, we attach a note instead of changing the original record, so the audit trail is preserved. Portability requests are honoured in a structured, machine‑readable format even while data is still in its retention window.
Common Questions
Can I request deletion of my data before the retention period ends?
Yes, you can file an erasure request any time. We promptly review every data category against its mandatory retention requirement. If no legal obligation applies, we erase it promptly. For anything we must keep, we restrict it to storage‑only, tell you the legal basis stopping immediate deletion and give you the expected deletion date. Additionally, you can see all your data categories along with their planned deletion dates via your account dashboard. That partial approach respects your rights as far as Italian regulations allow.
What happens to my data if I self‑exclude permanently?
When you register for permanent self‑exclusion, your identity data moves to a dedicated exclusion register that stays live indefinitely with tightly controlled access. That’s a legal requirement built to prevent you from opening new accounts. Conversely, your gameplay and transaction records continue to adhere to the usual retention timelines and are erased when those durations expire. The self‑exclusion entry is isolated from all marketing and operational systems, thus it fulfills solely the protective purpose for which it was gathered. You will not receive any promotional messages.
How do you handle data belonging to inactive accounts?
An account becomes inactive after twelve straight months with no login. At that point, we automatically switch off marketing communications and move the account to a dormant state with reduced processing. The underlying retention periods remain active according to the original data collection dates, not the date of inactivity. This implies that data from a dormant account is still retained for the complete legal period relevant to its category and subsequently erased following our standard protocols. Should you return after an extended absence, you may be required to undergo a new Know Your Customer verification to reactivate. Your data dashboard shows the current status at all times.
Data Deletion Procedures
When a data category hits the end of its designated storage time, our self-running lifecycle mechanism kicks off a secure deletion workflow. First, the data gets virtually eliminated from production databases. Next, physical storage blocks are rewritten with random data patterns to hinder forensic recovery. Finally, a crypto-stamped record lands in a regulatory record, giving traceable confirmation that purging happened on time. Backup copies rotate every ninety days, so any deleted data disappears from all media within three months. When a litigation hold applies, we halt the deletion workflow only for the affected records, record the hold reason, and resume once the hold lifts.