Your data, explained
A practical guide to our use of personal data
This policy explains what happens to personal data when you browse this website, register or use an account, make a payment, play, contact support or use safer-gambling tools. Read it with our Cookie Policy, Terms & Conditions and Responsible Gambling guide. Personal data means information that identifies you or can reasonably be linked to you.
- Controller
- Rivo Interactive Ltd
- Privacy contact
- privacy@rivocasino.org.uk
- Trading name
- Rivo Casino
- Version
- 1.0
- Version
- 1.0
- Effective date
- 20 July 2026
- Last reviewed
- 20 July 2026
1. Scope, controller and contact details
This policy covers personal data handled in connection with the Rivo Casino website, account and related customer services. The controller is Rivo Interactive Ltd, trading as Rivo Casino. Its registered address is Hamchako, Mutsamudu, Anjouan, Union of the Comoros and company number is ALSI-182947. The controller determines why and how personal data is processed.
Send privacy questions or rights requests to privacy@rivocasino.org.uk. For ordinary account support, use support@rivocasino.org.uk. Do not send identity documents, passwords or payment credentials through an unrequested or insecure channel. We may need to verify your identity before discussing an account or completing a request.
2. Personal data we collect and its sources
The information processed depends on whether you browse, create an account, verify your identity, deposit or withdraw, play, contact support or use player-protection tools. Relevant categories may include:
- Identity and eligibility: name, birth date, age, nationality, signature, photograph, identity-document details, proof of address, and identity, sanctions or politically exposed person check results.
- Contact and account: address, email, telephone number, username, identifiers, registration details, preferences and account status.
- Financial and transaction: payment method details, masked payment identifiers, deposits, withdrawals, refunds, bonuses, chargebacks and source-of-funds or source-of-wealth evidence where required. Full card details may be handled by a payment provider rather than stored by us.
- Gameplay and safer gambling: games, stakes, wins and losses, sessions, limits, time-outs, self-exclusion, interactions, affordability or vulnerability indicators and review records.
- Technical and usage: IP address, device, browser, language, approximate network-derived location, login events, cookie identifiers, page journeys, clicks, crash logs and security telemetry.
- Communications and preferences: emails, chats, recorded calls where applicable, complaints, surveys, support notes, marketing choices, campaign engagement and suppression records.
Where data comes from
Most information comes from you during registration, verification, payments and support conversations. Other data is generated through use of the service or received from payment providers, identity and age-verification services, fraud and device-intelligence providers, public records, sanctions databases, self-exclusion services, regulators, law enforcement, dispute-resolution bodies and, where lawful, affordability or credit-reference providers. When another person supplies information about you, we assess whether it can lawfully be used and provide notice where required.
3. Purposes and lawful bases
Data-protection law requires a lawful basis for each purpose. More than one basis can apply because the same record may be needed for different reasons. The precise basis depends on the activity and applicable law.
| Purpose | Typical data | Lawful basis |
|---|---|---|
| Provide and secure accounts, games, payments, bonuses and support | Identity, contact, account, financial, gameplay and communications | Contract; legitimate interests in reliable service and security |
| Verify age and identity; meet licensing, anti-money-laundering, sanctions, tax and record duties | Identity, verification, transaction and source-of-funds information | Legal obligation; legitimate interests where checks support compliance |
| Prevent fraud, collusion, payment abuse, cyberattacks and rule breaches | Device, transaction, gameplay, account and risk information | Legitimate interests in protecting customers and the service; legal obligation where applicable |
| Monitor gambling behaviour, offer controls and intervene where harm may be indicated | Gameplay, transaction, account, communications and safer-gambling information | Legal obligation; legitimate interests in player protection; an additional lawful condition for special-category data |
| Send marketing, personalise permitted offers and measure campaigns | Contact, preference, account and engagement information | Consent where required; otherwise legitimate interests, subject to marketing law and objection rights |
| Improve services; handle complaints, audits, regulatory enquiries and claims | Usage, technical, feedback, account and complaint records | Legitimate interests; legal obligation; consent for non-essential technology where required |
Where we rely on legitimate interests, we consider necessity and the effect on your rights. We do not use that basis where your interests or fundamental rights override ours. You may withdraw consent at any time without affecting earlier lawful use. Some data is required by law or contract; without it, we may be unable to open an account, process a transaction or provide a requested feature.
4. KYC, fraud prevention and safer gambling
Identity and financial-crime checks
Know-your-customer checks help confirm identity, age and eligibility. We may compare details with documents, databases or specialist providers and request updated evidence. Transactions and account links may be reviewed for money laundering, sanctions exposure, fraud, bonus abuse, chargebacks, multiple accounts or collusion. A withdrawal or feature may be delayed or restricted while a required review is completed, subject to the Terms & Conditions and applicable law.
Player-protection monitoring
Gameplay, payments, sessions, behavioural changes, limits, communications and other indicators may be assessed for possible gambling harm. This can lead to a message, review, recommendation to set controls, limit, time-out, restriction or self-exclusion. These actions support player-protection duties; they are not medical diagnoses. Information about health or vulnerability is used only where an additional legal condition is available. Our Responsible Gambling page explains practical controls and support.
5. Marketing, preferences and cookies
Account security, verification, payment and material terms messages are service communications, not promotions. Marketing by email, SMS, push notification or telephone is sent only where applicable rules allow. Change eligible preferences in available account settings, use a message’s unsubscribe instruction or contact privacy@rivocasino.org.uk. A minimal suppression record may remain after opt-out so the choice can be honoured.
Account activity and broad audience characteristics may help select permitted offers, but safer-gambling indicators should not be used to encourage increased play. You can object to direct marketing at any time. Cookies and similar technologies support sign-in, security, preferences, measurement and advertising. Essential technologies operate where necessary; non-essential ones are used according to legally required consent choices. Categories, providers, purposes, durations and controls are explained in the Cookie Policy.
6. Recipients, processors and international transfers
Data is shared only where there is a business or legal reason, and should be limited to what is needed. Recipients may include:
- hosting, cloud, analytics, monitoring and cybersecurity providers;
- banks, payment processors, card schemes, fraud and chargeback services;
- identity, age, sanctions, affordability, funds and document-check providers;
- game studios, platform suppliers and account-service providers;
- support, communications, marketing and professional advisers;
- Anjouan Gaming Commission, other regulators, law enforcement, courts, tax bodies and competent authorities;
- player-protection services, including Account self-exclusion via Rivo Casino customer support; and
- parties and advisers involved in a proposed corporate transaction.
Processors must act under documented instructions and appropriate contractual duties. Banks, regulators and some verification services may be independent controllers for their own legal purposes. A recipient may process data in another country. If the destination is not recognised as adequate, a lawful mechanism such as approved standard contractual clauses or another recognised safeguard is required, with supplementary measures where appropriate. Contact privacy@rivocasino.org.uk for information about relevant safeguards; commercially sensitive details may be redacted.
7. Retention and security
How long data is kept
Data is retained only as long as reasonably necessary for account administration, legal and licensing duties, financial-crime controls, safer gambling, disputes and claims. A period may run from account closure, transaction completion or complaint resolution and may be extended by a legal hold, regulatory request or investigation. At the end, data is deleted, anonymised or put beyond operational use as appropriate.
| Record category | Reason | Period |
|---|---|---|
| Account, identity and KYC | Administration, licensing and financial-crime compliance | 5 years after account closure, or longer if required by law |
| Payments, transactions and gameplay | Reporting, disputes, fraud prevention and regulatory records | 7 years from the date of the transaction or event |
| Safer gambling and self-exclusion | Player protection and enforcement of exclusions | For the exclusion period plus up to 7 years thereafter |
| Support, complaints and claims | Resolve issues, evidence decisions and defend claims | 6 years from resolution, or longer if a claim is pending |
| Marketing choices and technical logs | Respect opt-outs, security, diagnostics and consent records | Consent records for up to 3 years; security logs typically up to 12 months |
Periods may be extended where required by licensing, anti-money-laundering, tax, limitation or data-protection law. Shorter deletion may apply where data is no longer needed and no legal hold applies.
Security measures
We use proportionate technical and organisational measures intended to protect data from accidental or unlawful loss, alteration, destruction, disclosure or access. Depending on risk, these may include access controls, authentication, encryption, logging, monitoring, backups, staff training, supplier due diligence, vulnerability management and incident response. No online service can be guaranteed completely secure. Use a unique password, keep credentials private and report suspected misuse to support@rivocasino.org.uk.
8. Profiling and automated decision-making
Automated tools may assess identity, device, transaction, gameplay and behavioural signals to rank risk, detect fraud, support KYC, personalise permitted content or identify possible gambling harm. A tool may flag an account, request verification, limit a transaction or prompt a safer-gambling interaction. Rules and scores can be imperfect, so relevant decisions should have suitable testing, oversight and challenge routes.
A solely automated decision producing legal or similarly significant effects is used only where law permits and with required safeguards. Depending on the basis, these may include requesting human intervention, expressing your view and contesting the decision. Contact privacy@rivocasino.org.uk if you believe such a decision affected you. Details may be withheld where disclosure would undermine security, fraud prevention or another person’s rights.
9. Your data-protection rights
Rights depend on applicable law and may be subject to exemptions. They commonly include:
- access to your data and information about its use;
- rectification of inaccurate or incomplete information;
- erasure where no overriding reason requires retention;
- restriction while certain accuracy, objection or lawfulness issues are considered;
- objection to legitimate-interest processing and to direct marketing at any time;
- portability for certain data processed automatically on consent or contract;
- withdrawal of consent without affecting earlier lawful processing; and
- challenge to qualifying automated decisions.
Email privacy@rivocasino.org.uk and describe the request. We may reasonably verify identity. We respond within the period set by applicable law, subject to permitted extensions. Requests are normally free, although a lawful fee or refusal may apply to manifestly unfounded or excessive requests. We will explain any exemption or refusal and the complaint route.
Erasure is not absolute. Licensing, anti-money-laundering, tax, safer-gambling, self-exclusion, fraud-prevention and legal-claim duties may require records to remain. Closing an account does not automatically require immediate deletion of every record.
10. Complaints, supervisory authority and children
Privacy complaints
Contact privacy@rivocasino.org.uk so we can investigate, or send a formal complaint to complaints@rivocasino.org.uk. You may also complain to Anjouan Gaming Commission or another competent authority where permitted. Contacting us first does not remove that right.
Children
Gambling services are not intended for children or anyone below the legal gambling age. Age checks support account eligibility, but no process is infallible. If you believe a child supplied data or uses an account, contact support@rivocasino.org.uk. We will investigate, restrict access where appropriate and handle the data under legal and regulatory duties. Some records may need to remain to prevent repeated underage access or document action taken.
11. Policy changes and contact
This policy may change with the service, law, regulatory guidance, suppliers or processing practices. Its version, effective date and review date appear above. Material changes will be highlighted or communicated through an appropriate channel where required. Previous text may be retained for audit or legal purposes.
For privacy questions and rights requests, contact privacy@rivocasino.org.uk. For account help, use support@rivocasino.org.uk. Written correspondence may be addressed to Rivo Interactive Ltd at Hamchako, Mutsamudu, Anjouan, Union of the Comoros. Include enough detail to identify the issue, but never send passwords or full payment credentials.
