PRIVACY POLICY
Last Updated: January 19, 2026
Important Information on Personal Data Protection
This notice explains how Carlitta N.V. processes users’ Personal Data when accessing the Website, using the Services, undergoing verifications, performing payment transactions, and contacting customer support. The document also describes security measures, possible legal bases for processing, retention periods, data transfers to third parties, the use of cookies, and user rights.
The Website is owned and operated by Carlitta N.V., a company registered in Curaçao under registration number 162777. The official address of the Company is: Zuikertuintjeweg Z/N (Zuikertuin Tower), Willemstad, Curacao. Since June 24, 2025, the Company has been licensed by the Curaçao Gaming Control Board to provide services under license OGL/2024/1516/0841 in accordance with the National Ordinance on Games of Chance (LOK).
This notice applies to Personal Data processed through the Website, via email at [email protected], during telephone calls, and through support chat communications. Regarding such data, Carlitta N.V. acts as the controller, meaning it determines the purposes and means of processing within the scope of applicable law.
Terms Used in This Notice
For a proper understanding of this document, the following definitions are used:
Account — a personal account created to access the Services or specific features thereof. The use of an Account may require identity verification and compliance with regulatory requirements.
Company — Carlitta N.V., registered in Curaçao under number 162777. In this document, the words “we”, “us”, and “our” refer to this Company.
Service — the Website, its features, as well as related online and interactive services provided by the Company.
Website — the website, including subdomains, related platforms, or applications operated by the Company.
Personal Data — any information relating to an identified or identifiable natural person, as provided by the General Data Protection Regulation (GDPR) and the applicable data protection framework of Curaçao.
Processing of Personal Data — any operation or set of operations performed on data, whether or not by automated means. These include collection, recording, organization, structuring, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, dissemination or otherwise making available, alignment or combination, restriction, erasure, or destruction.
Regulatory Compliance — the obligation of the Company to process Personal Data in accordance with applicable laws, including the National Ordinance on Games of Chance (LOK) and Anti-Money Laundering (AML) requirements. Such processing is carried out on a legal basis and does not depend on the user’s consent.
Notice on Data for Accessing the Services
When creating an Account and subsequently accessing the Services, the Company may process information necessary for the registration, activation, and protection of the account.
Such information includes email and/or phone number, hashed password, chosen currency, Account identifiers, basic device data, and access logs. This data is used to provide access to the Services and maintain Account security.
The legal basis for such processing is the performance of a contract or steps taken prior to entering into a contract under Article 6(1)(b) of the GDPR.
Notice on Identity and Age Verification
In order to carry out KYC procedures, verify age, and comply with AML/CFT, LOK, and NORUT (The National Ordinance on the Reporting of Unusual Transactions) requirements, the Company may request and process documents and information necessary to identify the user.
This may include a passport, ID card, driver’s license, proof of address, date of birth or proof of age, as well as a selfie or liveness check results.
Such processing is carried out based on legal obligations under Article 6(1)(c) of the GDPR. Where applicable, the legitimate interest of the Company in maintaining the integrity of the platform under Article 6(1)(f) of the GDPR may also be taken into account.
Notice on Payment Data
When a user deposits funds, requests a withdrawal, or processes a refund, the Company may process data necessary to conduct and confirm the respective transaction.
Such data includes details of the payment instrument, transaction history, currency, and payout channel confirmations.
Processing may be necessary for the performance of a contract under Article 6(1)(b) of the GDPR, compliance with legal obligations for financial accounting and AML under Article 6(1)(c) of the GDPR, as well as fraud prevention based on legitimate interest under Article 6(1)(f) of the GDPR.
Notice on Security Monitoring
To protect the Website, Services, users, and technical infrastructure, the Company may process technical data that helps detect suspicious activity, prevent unauthorized access, and mitigate the risk of abuse.
Such data may include IP address, device type, browser information, and other technical identifiers.
Such processing is based on the legitimate interests of the Company in ensuring the security of the Service and users under Article 6(1)(f) of the GDPR. If the processing is related to AML/CFT requirements, a legal obligation under Article 6(1)(c) of the GDPR also applies.
Notice on User Protection and Self-Exclusion
To comply with LOK / CGA Responsible Gaming requirements, protect users, and manage self-exclusion, the Company may process information related to access restrictions and responsible use of the Service.
Such information may include self-exclusion status, duration of self-exclusion, chosen cooling-off periods, set limits, activity frequency, expenditure metrics that may indicate risk, and communications related to responsible gaming measures.
The legal bases are legal obligations under Article 6(1)(c) of the GDPR and the legitimate interests of the Company in protecting users and complying with regulatory requirements under Article 6(1)(f) of the GDPR.
Notice on Customer Support Data
If a user contacts support, the Company may process information necessary to review the inquiry, prepare a response, verify the circumstances, and resolve any potential dispute.
This category may include support tickets, email correspondence, chat transcripts, notes on phone calls, Account identifiers, and transaction references if they are linked to the request.
The basis is the performance of a contract when processing service inquiries under Article 6(1)(b) of the GDPR. Additionally, a legitimate interest in ensuring service quality and resolving disputes under Article 6(1)(f) of the GDPR may apply.
Notice on Marketing Communications
The Company may use Personal Data for marketing communications only when permitted by applicable law.
For such purposes, email, phone number, push token, marketing preferences, engagement metrics, and bonus eligibility status may be used, provided that such information does not constitute sensitive data.
Electronic marketing is carried out based on consent under Article 6(1)(a) of the GDPR. If legislation permits a soft opt-in for similar products, processing may be performed based on legitimate interest under Article 6(1)(f) of the GDPR. The user may opt out of such communications, and restrictions related to the responsible use of the Service always apply.
Notice on Website Operation, Analytics, and Cookies
To ensure the stable operation of the Website, analyze performance, and improve user experience, the Company may process usage logs, cookie identifiers, browser type and version, traffic data, and website interaction metrics.
The legal basis may be the legitimate interest of the Company in operating and improving the Website under Article 6(1)(f) of the GDPR. If consent is required for non-essential cookies, it is obtained under Article 6(1)(a) of the GDPR.
Cookies and similar technologies help ensure basic website functions, save specific user settings, analyze Website performance, and improve user experience. Cookies are small text files that are stored on the user’s device when visiting a website.
Strictly necessary cookies ensure the basic operation of the Website, including navigation, access to secure sections, and authentication. These cookies cannot be switched off in our systems, as the website cannot function properly without them.
Functional cookies help save user settings, such as language or other preferences. They may be set by the Company or by third-party providers whose services are used on the Website.
Analytical or performance cookies collect aggregated and anonymized information about visits, clicks, traffic sources, and website usage. This data is used to evaluate and improve the performance of the Website.
Advertising or targeting cookies may be placed by the Company or its advertising partners to build a profile of the user’s interests and show relevant adverts on the Website or other sites. They may also be used to limit the frequency of ad views and measure the effectiveness of advertising campaigns.
Session cookies are deleted after closing the browser. Persistent cookies remain on the device for a set period or until deleted by the user.
Cookies can be first-party, if they are set by the Website itself, or third-party, if they are placed by third-party providers acting on behalf of the Company. Such providers may include analytical services, support tools, or advertising networks.
Users can manage cookies through their browser settings. Most browsers allow blocking or deleting cookies. However, restricting certain cookies may affect the availability or correct operation of some features of the Website.
Notice on Regulatory Reporting and Disputes
The Company may process specific records to fulfill regulatory obligations, undergo audits, interact with competent authorities, and protect legal interests.
Such data may be required for cooperation with the CGA, FIU, tax authorities, and other state or supervisory bodies, as well as for legal procedures and dispute resolution.
The basis for processing is a legal obligation under Article 6(1)(c) of the GDPR and a legitimate interest in establishing, exercising, or defending legal claims under Article 6(1)(f) of the GDPR.
Sources of Personal Data
Personal Data may come from various sources. The primary source is the user themselves, when they create an Account, undergo verification, deposit funds, request a withdrawal or refund, or contact customer support.
Part of the data is generated when using the Services. This may include activity information, transaction history, technical logs, device details, and cookie data.
The Company may also receive data from trusted third-party providers who assist in performing identity verification, compliance procedures, security functions, and payment operations.
If necessary for verification, risk management, or compliance with legal requirements, information may be supplemented with data from legitimate and publicly available sources.
In certain cases, data may be obtained from regulatory or law enforcement authorities in connection with the legal and compliance obligations of the Company.
Data Retention and Erasure Periods
The Company retains Personal Data only for the period necessary to fulfill the purposes of processing, or for the duration established by applicable laws and regulatory requirements.
When determining the retention period, the purpose of processing, the provision of Services, the fulfillment of contractual obligations, the protection of legitimate interests, AML requirements, applicable tax and regulatory rules, and the need to establish, exercise, or defend legal claims are taken into account.
After the expiration of the applicable period, data is securely deleted, anonymized, or archived in such a way that it can no longer be associated with the user, unless further retention is required by law.
Data Storage and International Transfers
Personal Data is stored on secure servers used by the Company and trusted service providers. Such servers may be located both within the European Economic Area (EEA) and in other jurisdictions, including Curaçao, if necessitated by operational or regulatory requirements.
If Personal Data is transferred outside the EEA, the Company ensures compliance with applicable data protection laws and implements appropriate safeguards.
Such safeguards include Adequacy Decisions, when transfers are made to countries recognized by the European Commission as providing an adequate level of data protection, as well as Standard Contractual Clauses (SCCs) if no adequacy decision is in place for the respective country.
To Whom Personal Data May Be Disclosed
The Company may transfer Personal Data only when necessary and within the scope of the purposes specified in this notice. Any transfer is carried out in compliance with applicable data protection laws, contractual obligations, and security measures.
Data may be disclosed to regulatory and supervisory authorities, including the Curaçao Gaming Authority (CGA), the Financial Intelligence Unit (FIU), tax authorities, government bodies, and law enforcement agencies, if required by law, AML obligations, or responsible gaming requirements.
Identity verification and compliance providers may process data necessary to confirm the user’s identity and fulfill AML and Know Your Customer (KYC) requirements.
Payment processors and financial institutions may receive details about transactions, payment methods, and Account identifiers if required for deposits, withdrawals, or other payment operations.
Support and communication services, including email delivery, live chat, and other communication channels, may process contact details and user messages to provide customer support.
Security partners may assist the Company in protecting the platform, detecting suspicious activity, preventing fraud, and mitigating the risk of unauthorized access.
Analytics and optimization platforms may be used to analyze Website performance, conduct A/B testing, and improve user experience. Wherever possible, data is used in an anonymized or pseudonymized form.
Licensed third-party content providers may receive only the minimum amount of data necessary for the operation of specific platform features, such as user identifiers and session data.
IT infrastructure providers and internal tools may be used for secure data storage, management, and technical maintenance.
Notice on the Protection of Minors
The Company takes measures to prevent minors from accessing the Services. These measures comply with the Responsible Gaming Policy of the Curaçao Gaming Authority, introduced in February 2025.
The Services are intended solely for individuals who are at least 18 years of age, or a higher legal age if established in the user’s jurisdiction.
By accessing the Services or registering, the user confirms that they meet the applicable age requirement.
A valid government-issued identity document may be required for age verification. Such verification may be conducted as part of the registration process.
The Company also employs automated activity monitoring to detect inconsistencies or signs of minor access attempts. If such access is suspected, security checks may be carried out, including the analysis of registration data and financial transactions.
If an individual is identified as a minor, the Personal Data provided by them will be deleted immediately.
Parents and legal guardians are advised to use parental control tools and explain online safety rules to minors to prevent unauthorized access to the Services.
The Company adheres to the CGA guidelines regarding user protection and age verification. Policies and procedures are regularly reviewed and improved to meet or exceed regulatory standards.
User Rights Regarding Data
In accordance with the General Data Protection Regulation (GDPR), the user has several rights related to their Personal Data.
The user may request access to their data under Article 15 of the GDPR. Such a request may include confirmation of processing, obtaining a copy of the data, and information on how it is used.
The user may require the rectification of inaccurate or incomplete data under Article 16 of the GDPR without undue delay.
The user may request the erasure of data under Article 17 of the GDPR if there are legal grounds for doing so. For example, when the data is no longer necessary for the purposes of processing or when the user withdraws consent where processing is based on consent.
The user may require the restriction of processing under Article 18 of the GDPR in certain situations, including cases where the accuracy of the data is contested or the processing is unlawful.
The user may request data portability under Article 20 of the GDPR. This allows obtaining the data provided to the Company in a structured, commonly used, and machine-readable format and transmitting it to another controller, if technically feasible.
The user may object to processing under Article 21 of the GDPR if the processing is based on the legitimate interests of the Company and there are grounds relating to the user’s particular situation. The user may also object to processing for direct marketing purposes.
To exercise their rights, the user may send a request via email to [email protected] or by post to the address: Zuikertuintjeweg Z/N (Zuikertuin Tower), Willemstad, Curacao.
Withdrawal of Consent
If Personal Data is processed on the basis of consent, the user may withdraw such consent at any time.
The withdrawal of consent does not affect the lawfulness of processing carried out before its withdrawal. Upon receiving the request, the Company shall cease the respective processing, unless further retention or use of the data is required to fulfill legal or regulatory obligations.
If the withdrawal of consent may affect the ability to provide specific Services, the Company will inform the user of the consequences before completing the process.
Complaints and Privacy Inquiries
In accordance with Article 77 of the GDPR, the user may lodge a complaint if they believe that their Personal Data is being processed unlawfully or that their privacy rights have been infringed.
The complaint may be directed to a supervisory authority in the EU Member State where the user resides, works, or where the alleged infringement occurred. The user may also contact the Curaçao Gaming Authority (CGA) or another relevant data protection authority in Curaçao.
If the user has questions or unresolved concerns regarding the processing of Personal Data, it is recommended to first contact the Company directly. We will make reasonable efforts to address the inquiry in a timely manner and in accordance with the law.
When the Provision of Data is Necessary
In certain cases, the provision of Personal Data is mandatory. This may be due to statutory or contractual requirements, or necessary to access the Services.
Data may be required to comply with applicable laws and regulations, including AML obligations and responsible gaming requirements. Certain data is necessary for entering into and performing a contract, including providing access to the Services and processing transactions.
If the user fails to provide the data required by law or necessary for the performance of a contract, it may result in the inability to create or maintain an Account, restrictions on the use of the Services, termination of contractual relations, or the inability to fulfill regulatory obligations, which may prevent the provision of the Services.
Legal Disclaimer
The Services are provided on an “AS-IS” and “AS-AVAILABLE” basis. The Company does not guarantee that the Services will always function without interruptions or errors.
Although the Company takes reasonable measures to protect Personal Data, absolute security cannot be guaranteed due to the complexity of technology and constantly evolving cyber threats.
To the maximum extent permitted by law, the Company is not liable for events beyond its direct control, including system failures, cyberattacks, or unauthorized access.
The Company is also not liable for indirect, incidental, consequential, or punitive damages related to data leaks, unauthorized disclosure, or misuse of Personal Data.
Furthermore, the Company is not responsible for errors, inaccuracies, or security vulnerabilities on third-party websites, links to which may be provided on the platform.
By using the Services, the user acknowledges that external sites and third-party services are not controlled by the Company, even if links to them are placed on the platform.
Acceptance of the Notice and Updates
Continued use of the Services signifies acceptance of this Privacy Policy.
This Policy is the complete and exclusive statement of the privacy rules and supersedes all previous versions. It should be read in conjunction with the Terms and Conditions and other applicable notices published on the platform.
The Company may amend this Policy at any time. Updates are posted on the platform, and continued use of the Services following the publication of changes constitutes acceptance of the updated version.
The user is advised to periodically review the Policy to remain informed about the current terms of Personal Data processing.
All versions of the Policy, other than the English version, are provided solely for informational purposes. In the event of any discrepancies or contradictions between language versions, the English version shall prevail.