Privacy Policy
Last updated: August 14, 2025
About This Privacy Overview
Who this information is for
This overview explains the privacy tools, data-related options, legal requirements, and protective measures that apply when you use the Website and the Services provided through it.
It is intended to help you understand what Personal Data may be required, which choices may be available to you, which Processing activities are mandatory, and how the Company handles requests, safeguards, cookies, retention, disclosures, and regulatory obligations.
Company responsible for the Website
The Website is owned and operated by Carletta N.V., a company registered in Curaçao.
Carletta N.V. has its office at Dr. Henri Fergusonweg 1, Curaçao and is registered under company registration number 142346.
Carletta N.V. has been licensed by the Curaçao Gaming Control Board since 24/Jun/2025 to offer games of chance under license number OGL/2024/580/0570 in accordance with the National Ordinance on Games of Chance (LOK).
Controller role
Carletta N.V. is the controller of your Personal Data.
This means that the Company determines the purposes of Personal Data Processing and the methods used for that Processing in connection with the Website and Services.
Where this overview applies
This Privacy Policy applies to Personal Data handled through:
- the Website;
- email communication via [email protected];
- phone calls with us;
- support chat sessions.
Terms That Explain Your Data Options
Account
An Account is the unique profile created for you to access the Services or selected parts of them.
Account access may depend on identity verification and Regulatory Compliance requirements.
Company
Company, we, us, or our means Carletta N.V., registered under Curaçao law with registration number 142346 and official address at Dr. Henri Fergusonweg 1, Curaçao.
Service
Service means the Website, the functions available through it, and the related online gaming and interactive services provided by the Company.
Website
Website means this website, together with any subdomains, related platforms, or applications operated by the Company.
Personal Data
Personal Data means information that relates to an identified or identifiable person, as defined under the General Data Protection Regulation and the Curaçao Data Protection Framework.
Processing of Personal Data
Processing of Personal Data means any manual or automated action performed with Personal Data.
This can include collecting, recording, organizing, structuring, storing, adapting, changing, retrieving, consulting, using, transmitting, disclosing, disseminating, aligning, combining, restricting, erasing, or destroying Personal Data.
Regulatory Compliance
Regulatory Compliance means the Company’s obligation to process Personal Data where required by applicable law, including the National Ordinance on Games of Chance and Anti-Money Laundering regulations.
Processing required for Regulatory Compliance is based on legal obligations and is not dependent on user consent.
Account and Access Options
Account creation
To make an Account available and allow access to the Services, the Company may need to process Personal Data connected with registration, activation, access control, and Account security.
The legal basis is performance of a contract or steps taken before entering into a contract under GDPR Article 6(1)(b).
Personal Data used for Account access may include:
- email address and/or phone number;
- hashed password;
- chosen currency;
- account identifiers;
- basic device or access logs used to activate and secure the Account.
Access limitations
Some Account functions may not be available unless required Personal Data is provided. Where information is needed for contract performance or compliance, the Company may be unable to create, maintain, or continue access to the Account without it.
Verification and Compliance Options
Identity verification
Identity checks may be required to confirm who you are, support KYC procedures, and meet legal or regulatory requirements.
The legal basis is compliance with legal obligations under GDPR Article 6(1)(c), including AML/CFT, LOK, and NORUT. Where applicable, the Company may also rely on legitimate interests in platform integrity under GDPR Article 6(1)(f).
Personal Data used for identity verification may include:
- passport;
- ID card;
- driver’s license;
- proof of address;
- selfies;
- liveness checks.
Age confirmation
Age confirmation is required because the Services are intended only for individuals who meet the applicable age threshold.
The Company may process date of birth, age attestation, and identity document information to confirm that a user is at least eighteen (18) years old or has reached the legal age required in their jurisdiction, whichever is higher.
AML, LOK, and NORUT compliance
Certain Personal Data must be processed to comply with AML/CFT, LOK, and NORUT obligations.
This Processing is legally required and does not rely on consent. If the required data is not provided, the Company may be unable to provide the Services or continue the contractual relationship.
Payment and Transaction Options
Deposits, withdrawals, and refunds
Payment-related Personal Data may be processed to complete deposits, withdrawals, refunds, payout confirmations, and other financial operations connected with the Services.
The legal bases are performance of a contract under GDPR Article 6(1)(b), compliance with financial record-keeping and AML obligations under GDPR Article 6(1)(c), and legitimate interests in fraud prevention under GDPR Article 6(1)(f).
Personal Data used for payment operations may include:
- payment instrument data;
- transaction history;
- currency;
- payout channel confirmations.
Financial record handling
Payment information may also be retained where needed for financial record-keeping, AML checks, dispute handling, audits, tax obligations, or legal claims.
Security and Fraud Prevention Tools
Technical safeguards
The Company may process technical information to keep the Services secure, identify suspicious patterns, prevent misuse, and protect platform integrity.
The legal bases are legitimate interests in securing the Service and users under GDPR Article 6(1)(f), and legal obligations under AML/CTF rules under GDPR Article 6(1)(c).
Personal Data used for security purposes may include:
- IP address;
- device type;
- browser data;
- device identifiers;
- technical identifiers.
Abuse prevention
Security-related Processing may be used to detect potentially fraudulent activity, unauthorized access, or platform abuse. These measures support both user protection and compliance obligations.
Responsible Gaming and Protection Tools
Self-exclusion and cooling-off tools
The Company may process Personal Data to manage self-exclusion, cooling-off selections, and other responsible gaming measures.
The legal bases are compliance with LOK / CGA Responsible Gaming requirements under GDPR Article 6(1)(c), and legitimate interests in player welfare and Regulatory Compliance under GDPR Article 6(1)(f).
Personal Data used for these tools may include:
- self-exclusion status;
- self-exclusion duration;
- cooling-off selections;
- play limits;
- communications related to responsible gaming interventions.
Risk indicators and protection measures
To support player protection, the Company may process gameplay frequency and spend metrics indicative of risk.
This Processing helps meet responsible gaming obligations and allows the Company to apply interventions where required or appropriate under the applicable framework.
Communication and Support Options
Support requests
When you contact support, the Company may process Personal Data necessary to understand the inquiry, verify relevant details, respond to the request, and resolve the issue.
The legal bases are performance of a contract under GDPR Article 6(1)(b), and legitimate interests in service quality and dispute resolution under GDPR Article 6(1)(f).
Personal Data used for support may include:
- support tickets;
- chat transcripts;
- email correspondence;
- call notes;
- account identifiers;
- transaction references tied to the inquiry.
Contact channel
Support and rights-related requests may be sent by email to:
Requests may also be sent by post to:
- Dr. Henri Fergusonweg 1, Curaçao.
Marketing Preference Options
Marketing where permitted
The Company may process Personal Data for marketing communications only where this is permitted by law.
Electronic marketing is based on consent under GDPR Article 6(1)(a). Where allowed by law, similar-product soft opt-in may rely on legitimate interests under GDPR Article 6(1)(f).
Marketing is always subject to opt-out options and responsible gaming restrictions.
Data used for marketing preferences
Marketing-related Personal Data may include:
- email address;
- phone number;
- push token;
- marketing preferences;
- engagement metrics;
- non-sensitive bonus eligibility status.
Opt-out availability
Where marketing communications are provided, opt-out rights apply. If you object to direct marketing, the Company will handle the request in accordance with applicable data protection rules.
Website Performance and Cookie Options
Website functionality
The Website may use cookies and similar technologies to support core functions, improve user experience, measure performance, and understand Website interactions.
The legal bases are legitimate interests in operating and improving the Website under GDPR Article 6(1)(f), and consent under GDPR Article 6(1)(a) where non-essential cookies require consent.
Personal Data used for Website performance may include:
- usage logs;
- cookie identifiers;
- browser type and version;
- traffic data;
- on-site interaction metrics.
Strictly necessary cookies
Strictly necessary cookies support essential Website functions.
They may enable:
- page navigation;
- access to secure areas;
- user authentication.
These cookies cannot be switched off in the Company’s systems.
Functional cookies
Functional cookies allow the Website to provide additional functionality and personalization.
They may remember:
- language preferences;
- user settings.
They may be placed by the Company or by third-party providers whose services are used.
Analytical or performance cookies
Analytical or performance cookies collect aggregated and anonymized information about Website use.
This information may relate to:
- page visits;
- click-through rates;
- traffic sources;
- on-site interaction metrics.
These cookies help measure and improve Website performance.
Advertising or targeting cookies
Advertising or targeting cookies may be set by the Company or advertising partners.
They may be used to:
- build a profile of interests;
- show relevant advertising on this Website or on other websites;
- limit how often an advertisement is shown;
- assess advertising effectiveness.
Session and persistent cookies
Session cookies expire when the browser is closed.
Persistent cookies remain on the device for a predetermined period or until they are deleted by you.
First-party and third-party cookies
First-party cookies are placed by the Company.
Third-party cookies are placed by service providers acting on behalf of the Company. These providers may include analytics services, customer support tools, or advertising networks.
Browser controls
You may manage cookies through your browser settings.
Most browsers allow cookies to be refused or deleted. Some Website features may not be available or may not work correctly if certain cookies are restricted.
Data Source Options
Information provided directly
The Company usually collects Personal Data directly from you.
This may happen when you:
- create an Account;
- complete verification;
- make a deposit;
- request a withdrawal;
- contact support.
Information created through use of the Services
Some Personal Data is generated while you use the platform.
This may include:
- gameplay;
- transaction history;
- device information;
- log information;
- cookie data in accordance with the Cookie Policy.
Information from verification, compliance, and payment providers
Trusted third parties may support identity verification, compliance, security, and payment-related functions.
Where these providers are used, they may assist with confirming information, preventing risk, or enabling required operational processes.
Information from public sources and authorities
Where necessary, Personal Data may be supplemented with data from publicly available and legitimate sources, solely for compliance, verification, or risk management.
In some cases, Personal Data may also be received from regulatory or law enforcement authorities in connection with legal and compliance obligations.
Storage and Transfer Options
Storage environment
Personal Data is stored on secure servers operated by the Company and trusted service providers.
Depending on operational and regulatory requirements, these servers may be located:
- within the European Economic Area;
- outside the European Economic Area;
- in Curaçao.
Transfers outside the EEA
If Personal Data is transferred outside the EEA, the Company applies appropriate safeguards required by applicable data protection laws.
Adequacy decisions
Personal Data may be transferred to a country recognized by the European Commission as providing an adequate level of data protection.
Standard Contractual Clauses
Where no adequacy decision applies, the Company uses Standard Contractual Clauses approved by the European Commission to support the protection of Personal Data transferred outside the EEA.
Retention and Deletion Options
Retention period
Personal Data is kept only for as long as needed for the purposes for which it was collected and processed, or for as long as applicable legal and regulatory obligations require.
Retention factors
The length of retention may depend on:
- the purpose of Processing;
- provision of the Services;
- contractual obligations;
- legitimate interests;
- AML requirements;
- gaming regulations;
- tax regulations;
- legal claims;
- audits;
- supervisory requirements.
End of retention
When the applicable retention period ends, Personal Data is securely deleted, anonymized, or archived so that it can no longer be associated with you, unless continued retention is required by law.
Sharing and Recipient Options
General disclosure standard
Personal Data may be shared only where necessary and only for the purposes described in this Privacy Policy.
Disclosure is carried out in compliance with applicable data protection laws, contractual obligations, and security measures.
Authorities and official bodies
Personal Data may be shared with regulatory and supervisory authorities where required by law or regulatory obligations.
Recipients may include:
- Curaçao Gaming Authority;
- Financial Intelligence Unit;
- tax authorities;
- governmental bodies;
- law enforcement bodies.
Verification and compliance providers
Identity verification and compliance service providers may receive Personal Data to help verify customer identity and comply with AML and Know Your Customer obligations.
Payment processors and financial institutions
Payment processors and financial institutions may receive Personal Data needed to enable deposits, withdrawals, refunds, and other payment-related services.
This may include:
- transaction details;
- payment method information;
- account identifiers.
Support and communication tools
External service providers may support email delivery, live chat, and other communication channels.
They may process contact details and support messages to assist with customer service.
Security and fraud prevention partners
Trusted providers may process Personal Data to protect platform security and integrity, including detection and prevention of potentially fraudulent or unauthorized activity.
Analytics and optimization platforms
Third-party tools may help analyze Website usage, conduct A/B testing, and improve user experience.
Where possible, data used in this context is anonymized or pseudonymized.
Game content providers
Licensed third-party game providers may receive only the minimum Personal Data needed to enable certain platform features.
This may include player identifiers and game session data.
Internal tools and IT infrastructure
Secure hosting, internal tools, and productivity solutions may be used to store and manage data necessary for operation of the Services.
Minor Protection Options
Age restriction
The Services are intended only for individuals who are at least eighteen (18) years old or who have reached the legal age in their jurisdiction, whichever is higher.
By accessing or registering for the Services, you confirm that the applicable age requirement is met.
Prevention of underage access
In alignment with the Curaçao Gaming Authority’s Responsible Gaming Policy introduced in February 2025, the Company applies measures intended to prevent minors from accessing the Services.
Verification and monitoring
Users may be asked to provide valid government-issued identification documents during registration.
The Company may also use automated monitoring to identify inconsistencies or signs of attempted underage access.
If underage access is suspected, security reviews may be carried out, including checks of registration data and financial transactions.
Data submitted by minors
Personal Data submitted by individuals identified as minors is deleted immediately.
Parental controls
Parents and guardians are encouraged to use available parental control tools and educate minors about responsible online behavior to help prevent unauthorized access to the Services.
Responsible gaming safeguards
The Company’s responsible gaming approach includes adherence to CGA guidance on player protection and age verification.
Policies are reviewed and enhanced to meet or exceed regulatory standards.
Your Rights and Request Options
Access
Under Article 15 GDPR, you may request confirmation of whether your Personal Data is processed and may obtain a copy of that data together with information about its use.
Rectification
Under Article 16 GDPR, you may request correction of inaccurate or incomplete Personal Data without undue delay.
Erasure
Under Article 17 GDPR, you may request deletion of Personal Data where applicable legal grounds exist.
This may apply where the data is no longer needed for the purposes collected, or where consent is withdrawn and no other lawful basis applies.
Restriction
Under Article 18 GDPR, you may request limitation of Personal Data Processing in specific situations, including where data accuracy is contested or Processing is unlawful.
Portability
Under Article 20 GDPR, you may request the Personal Data you provided to the Company in a structured, commonly used, and machine-readable format.
Where technically feasible, that data may be transferred to another controller.
Objection
Under Article 21 GDPR, you may object to Processing based on legitimate interests for reasons related to your particular situation.
You may also object to Processing for direct marketing purposes.
Submitting a rights request
To exercise data protection rights, contact the Company through:
- email: [email protected];
- postal address: Dr. Henri Fergusonweg 1, Curaçao.
Consent and Complaint Options
Withdrawal of consent
Where Processing is based on consent, you may withdraw consent at any time.
Withdrawal does not affect the lawfulness of consent-based Processing carried out before the withdrawal.
After a withdrawal request is received, the Company will stop the relevant Processing unless continued retention or Processing is required for legal or regulatory obligations.
If withdrawal affects the ability to provide certain Services, the Company will explain the consequences before completing the request.
Complaint submission
Under Article 77 GDPR, you may lodge a complaint if you believe your Personal Data is processed unlawfully or your privacy rights have been violated.
Complaints may be lodged with:
- the supervisory authority in the EU Member State where you reside;
- the supervisory authority in the EU Member State where you work;
- the supervisory authority in the EU Member State where the alleged violation occurred;
- the Curaçao Gaming Authority;
- any other relevant data protection authority in Curaçao.
Direct contact
If you have unresolved questions or concerns about Personal Data Processing, you are encouraged to contact the Company directly first.
The Company will make every reasonable effort to address concerns in a timely and lawful manner.
Required Data and Service Availability
Legal requirements
Certain Personal Data must be provided so that the Company can comply with laws and regulations, including Anti-Money Laundering obligations and responsible gaming requirements.
Contractual requirements
Some Personal Data is necessary to enter into or perform a contract with you.
This includes information required to provide access to the Services and process transactions.
Access requirements
Some Services may not be available unless required Personal Data is provided.
Without required data, the Company may be unable to fulfill contractual or legal obligations.
Consequences of non-disclosure
Failure to provide required Personal Data may result in:
- inability to create or maintain an Account;
- restrictions on use of the Services;
- termination of the contractual relationship;
- inability to comply with regulatory obligations, which may prevent the Company from providing Services.
Legal Notices and Policy Controls
Service basis
The Services are provided on an “AS-IS” and “AS-AVAILABLE” basis.
The Company does not provide warranties or guarantees of uninterrupted or error-free performance.
Security limitation
The Company takes reasonable precautions to protect Personal Data.
Absolute security cannot be guaranteed because technology is complex and cybersecurity threats continue to evolve.
Liability limitation
To the maximum extent permitted by law, the Company is not liable for:
- events beyond its direct control, including system failures, cyberattacks, or unauthorized access;
- indirect, incidental, consequential, or punitive damages arising from data breaches, unauthorized disclosure, or misuse of Personal Data;
- errors, inaccuracies, or security vulnerabilities on third-party websites linked from the platform.
Third-party websites
The Company is not responsible for external websites or services operated by third parties, even where they are linked from the platform.
By using the Services, you acknowledge and accept this limitation.
Acceptance and updates
Continued use of the Services means explicit acceptance of this Privacy Policy.
This document is the entire and exclusive Privacy Policy and replaces prior versions.
The Privacy Policy should be read together with the Terms and Conditions and any additional applicable notices posted on the platform.
The Company may modify this Privacy Policy at any time. Changes will be posted on the platform, and continued use of the Services after changes are made means acceptance of the revised Policy.
You are strongly encouraged to review this Privacy Policy regularly to stay informed about updates.
Language priority
All versions of this Privacy Policy other than the English version are provided for informational purposes only.
The English version prevails in case of discrepancies or conflicts between different versions.