PRIVACY POLICY

Last updated: August 14, 2025

1. Scope, Controller, and Website Operator

1.1. Confirm who operates the Website

This Website is owned and operated by Carletta N.V., a company registered under the laws of Curaçao.

Company details:

  • Company name: Carletta N.V.
  • Registered office: Dr. Henri Fergusonweg 1, Curaçao
  • Company registration number: 142346
  • Licensing authority: Curaçao Gaming Control Board
  • Licensed since: 24/Jun/2025
  • License number: OGL/2024/580/0570
  • Legal framework: National Ordinance on Games of Chance (LOK)

1.2. Confirm who controls Personal Data

Carletta N.V. acts as the controller of your Personal Data.

This means that the Pin-Up determines why and how Personal Data is collected, used, stored, disclosed, protected, and otherwise processed when you access or use the Website and Services.

1.3. Confirm where this Privacy Policy applies

This Privacy Policy applies to the collection, use, and Processing of Personal Data through:

  • the Website;
  • communications via [email protected];
  • phone calls with us;
  • support chat sessions with us.

1.4. Confirm what this Privacy Policy explains

This Privacy Policy explains:

  • what Personal Data we process;
  • why we process Personal Data;
  • what legal bases apply;
  • how long Personal Data is retained;
  • where Personal Data is stored;
  • when Personal Data may be transferred internationally;
  • who Personal Data may be shared with;
  • how cookies and similar technologies may be used;
  • how minors are protected;
  • what rights you have;
  • how you may exercise those rights;
  • what happens if required Personal Data is not provided.

2. Definitions Checklist

2.1. Account

Account means a unique account created for you to access the Services or specific parts of the Services.

Account access may be subject to:

  • identity verification;
  • Regulatory Compliance requirements.

2.2. Company

Company, we, us, or our means Carletta N.V.

Carletta N.V. is:

  • registered under the laws of Curaçao;
  • registered under company registration number 142346;
  • located at Dr. Henri Fergusonweg 1, Curaçao.

2.3. Service

Service means:

  • the Website;
  • Website functionalities;
  • related online gaming and interactive services provided by the Company.

2.4. Website

Website means this website, including:

  • subdomains;
  • associated platforms;
  • applications operated by the Company.

2.5. Personal Data

Personal Data means any information relating to an identified or identifiable individual.

This definition follows:

  • the General Data Protection Regulation;
  • the Curaçao Data Protection Framework.

2.6. Processing of Personal Data

Processing of Personal Data means any operation or set of operations performed on Personal Data, whether by automated or manual means.

Processing may include:

  • collection;
  • recording;
  • organization;
  • structuring;
  • storage;
  • adaptation;
  • alteration;
  • retrieval;
  • consultation;
  • use;
  • disclosure by transmission;
  • dissemination;
  • alignment;
  • combination;
  • restriction;
  • erasure;
  • destruction.

2.7. Regulatory Compliance

Regulatory Compliance means the Company’s legal obligation to process Personal Data in accordance with applicable laws.

This includes obligations under:

  • the National Ordinance on Games of Chance;
  • Anti-Money Laundering regulations.

Processing for Regulatory Compliance:

  • is based on legal requirements;
  • does not rely on user consent.

3. Personal Data Processing Checklist

3.1. Account registration and access to Services

Purpose checklist:

  • create your Account;
  • activate access to the Services;
  • secure the Account;
  • manage Account access;
  • enable use of specific parts of the Services.

Legal basis checklist:

  • performance of a contract under GDPR Article 6(1)(b);
  • steps prior to entering into a contract under GDPR Article 6(1)(b).

Personal Data checklist:

  • email address and/or phone number;
  • hashed password;
  • chosen currency;
  • account identifiers;
  • basic device or access logs used to activate and secure the Account.

3.2. Identity verification, age confirmation, and AML / LOK compliance

Purpose checklist:

  • verify customer identity;
  • confirm age;
  • complete KYC checks;
  • comply with AML/CFT obligations;
  • comply with LOK requirements;
  • comply with NORUT requirements;
  • support platform integrity where applicable.

Legal basis checklist:

  • compliance with legal obligations under GDPR Article 6(1)(c);
  • AML/CFT compliance;
  • LOK compliance;
  • NORUT compliance;
  • legitimate interests in platform integrity under GDPR Article 6(1)(f), where applicable.

Personal Data checklist:

  • passport;
  • ID card;
  • driver’s license;
  • proof of address;
  • date of birth;
  • age attestation;
  • selfies;
  • liveness checks.

3.3. Payment processing

Purpose checklist:

  • process deposits;
  • process withdrawals;
  • process refunds;
  • enable payment-related services;
  • maintain financial records;
  • support AML-related checks;
  • help prevent fraud.

Legal basis checklist:

  • performance of a contract under GDPR Article 6(1)(b);
  • legal obligation for financial record-keeping under GDPR Article 6(1)(c);
  • legal obligation for AML compliance under GDPR Article 6(1)(c);
  • legitimate interests in fraud prevention under GDPR Article 6(1)(f).

Personal Data checklist:

  • payment instrument data;
  • transaction history;
  • currency;
  • payout channel confirmations.

3.4. Fraud detection, security monitoring, and abuse prevention

Purpose checklist:

  • secure the Service;
  • protect users;
  • monitor for security risks;
  • detect potentially fraudulent activity;
  • prevent unauthorized activity;
  • prevent platform abuse.

Legal basis checklist:

  • legitimate interests in securing the Service and users under GDPR Article 6(1)(f);
  • legal obligations under AML/CTF under GDPR Article 6(1)(c).

Personal Data checklist:

  • IP address;
  • device type;
  • browser data;
  • device identifiers;
  • technical identifiers.

3.5. Responsible gaming, player protection, and self-exclusion

Purpose checklist:

  • manage self-exclusion;
  • record self-exclusion duration;
  • manage cooling-off selections;
  • apply play limits;
  • support player protection;
  • monitor risk indicators;
  • support responsible gaming interventions;
  • comply with Regulatory Compliance requirements.

Legal basis checklist:

  • compliance with LOK / CGA Responsible Gaming requirements under GDPR Article 6(1)(c);
  • legitimate interests in player welfare under GDPR Article 6(1)(f);
  • legitimate interests in Regulatory Compliance under GDPR Article 6(1)(f).

Personal Data checklist:

  • self-exclusion status;
  • self-exclusion duration;
  • cooling-off selections;
  • play limits;
  • gameplay frequency;
  • spend metrics indicative of risk;
  • communications related to responsible gaming interventions.

3.6. Customer support and service communications

Purpose checklist:

  • respond to service requests;
  • provide support;
  • resolve Account inquiries;
  • resolve transaction inquiries;
  • maintain service quality;
  • support dispute resolution.

Legal basis checklist:

  • performance of a contract under GDPR Article 6(1)(b);
  • legitimate interests in service quality under GDPR Article 6(1)(f);
  • legitimate interests in dispute resolution under GDPR Article 6(1)(f).

Personal Data checklist:

  • support tickets;
  • chat transcripts;
  • email correspondence;
  • call notes;
  • account identifiers;
  • transaction references tied to the inquiry.

3.7. Marketing communications where permitted

Purpose checklist:

  • send marketing communications where permitted;
  • manage marketing preferences;
  • measure engagement;
  • apply opt-out choices;
  • observe responsible gaming restrictions.

Legal basis checklist:

  • consent under GDPR Article 6(1)(a) for electronic marketing;
  • legitimate interests under GDPR Article 6(1)(f) for similar-product soft opt-in where allowed by law.

Personal Data checklist:

  • email address;
  • phone number;
  • push token;
  • marketing preferences;
  • engagement metrics;
  • non-sensitive bonus eligibility status.

3.8. Website performance, analytics, and cookies

Purpose checklist:

  • operate the Website;
  • improve Website performance;
  • measure Website use;
  • support essential Website functions;
  • use non-essential cookies where permitted.

Legal basis checklist:

  • legitimate interests in operating and improving the Website under GDPR Article 6(1)(f);
  • consent under GDPR Article 6(1)(a), where required for non-essential cookies.

Personal Data checklist:

  • usage logs;
  • cookie identifiers;
  • browser type and version;
  • traffic data;
  • on-site interaction metrics.

3.9. Regulatory reporting, audits, and dispute resolution

Purpose checklist:

  • cooperate with regulatory authorities;
  • cooperate with supervisory authorities;
  • comply with audits;
  • support legal proceedings;
  • resolve disputes;
  • establish legal claims;
  • exercise legal claims;
  • defend legal claims.

Legal basis checklist:

  • legal obligation under GDPR Article 6(1)(c);
  • cooperation with the Curaçao Gaming Authority;
  • cooperation with the FIU;
  • cooperation with tax authorities;
  • cooperation with other authorities;
  • legitimate interests in establishing, exercising, or defending legal claims under GDPR Article 6(1)(f).

Personal Data checklist:

  • records required for regulatory cooperation;
  • records required for compliance audits;
  • records required for legal proceedings;
  • records required for dispute resolution, as permitted by applicable laws.

4. Sources of Personal Data Checklist

4.1. Data collected directly from you

We may collect Personal Data directly from you when you:

  • create an Account;
  • complete verification steps;
  • make deposits;
  • make withdrawals;
  • communicate with our support team.

4.2. Data generated through your use of the Services

We may collect data generated through activity on the platform, including:

  • gameplay;
  • transaction history;
  • device information;
  • log information;
  • cookie data in accordance with the Cookie Policy.

4.3. Data received from third-party verification and compliance services

We may use trusted third parties to support:

  • compliance functions;
  • security functions;
  • payment-related functions;
  • identity verification.

4.4. Data obtained from publicly available and legitimate sources

Where necessary, we may supplement information you provide with data from publicly available and legitimate sources.

This is done solely for:

  • compliance;
  • verification;
  • risk management.

4.5. Data received from regulatory and law enforcement authorities

In some cases, we may receive data from competent authorities in connection with:

  • legal obligations;
  • compliance obligations;
  • regulatory requirements.

5. Data Retention Checklist

5.1. General retention rule

We retain Personal Data only for as long as necessary to fulfill the purposes for which it was collected and processed.

We may also retain Personal Data where required under applicable legal and regulatory obligations.

5.2. Factors used to determine retention periods

Retention periods are determined based on:

  • the purpose of Processing;
  • provision of the Services;
  • contractual obligations;
  • protection of legitimate interests;
  • statutory AML retention requirements;
  • gaming regulations;
  • tax regulations;
  • legal claims;
  • audits;
  • supervisory requirements.

5.3. Actions after the retention period expires

Once the relevant retention period expires, Personal Data is:

  • securely deleted;
  • anonymized;
  • archived in a way that ensures it can no longer be associated with you.

Further retention may apply only where required by law.

6. Storage and International Transfers Checklist

6.1. Storage locations

Personal Data is stored on secure servers operated by:

  • the Company;
  • trusted service providers.

These servers may be located:

  • within the European Economic Area;
  • outside the European Economic Area;
  • in Curaçao, depending on operational and regulatory requirements.

6.2. Transfers outside the EEA

When Personal Data is transferred outside the EEA, such transfers comply with applicable data protection laws.

6.3. Adequacy decisions

Transfers may rely on adequacy decisions where the European Commission has recognized a country as providing an adequate level of data protection.

6.4. Standard Contractual Clauses

Where no adequacy decision exists, we use Standard Contractual Clauses approved by the European Commission.

These clauses help ensure that Personal Data remains protected when transferred outside the EEA.

7. Personal Data Sharing Checklist

7.1. General sharing rule

Personal Data may be shared only when necessary and for the purposes described in this Privacy Policy.

Sharing is carried out in compliance with:

  • applicable data protection laws;
  • contractual obligations;
  • security measures.

7.2. Regulatory and supervisory authorities

Personal Data may be shared with:

  • the Curaçao Gaming Authority;
  • the Financial Intelligence Unit;
  • tax authorities;
  • governmental bodies;
  • law enforcement bodies.

Such sharing may be required by law and regulatory obligations, including AML and responsible gaming requirements.

7.3. Identity verification and compliance providers

Personal Data may be shared with providers that help us:

  • verify customer identity;
  • comply with AML obligations;
  • comply with Know Your Customer obligations.

7.4. Payment processors and financial institutions

Personal Data may be shared to enable:

  • deposits;
  • withdrawals;
  • refunds;
  • other payment-related services.

Shared data may include:

  • transaction details;
  • payment method information;
  • account identifiers.

7.5. Customer support and communication tools

External providers may process Personal Data to support:

  • email delivery;
  • live chat;
  • other communication channels;
  • customer service operations.

Personal Data processed for these purposes may include:

  • contact details;
  • support messages.

7.6. Fraud prevention and security partners

Trusted service providers may assist with:

  • protecting platform security;
  • protecting platform integrity;
  • detecting potentially fraudulent activity;
  • preventing unauthorized activity.

7.7. Analytics and optimization platforms

Third-party services may help us:

  • analyze Website usage;
  • conduct A/B testing;
  • improve user experience.

Where possible, data used for these purposes is:

  • anonymized;
  • pseudonymized.

7.8. Game content providers

Licensed third-party game providers may receive only the minimum data required to enable certain features of the platform.

This may include:

  • player identifiers;
  • game session data.

7.9. Internal tools and IT infrastructure providers

We use secure hosting and productivity solutions to store and manage data necessary for the operation of the Services.

8. Cookies and Similar Technologies Checklist

8.1. General cookie use

The Website may use cookies and similar technologies to:

  • enhance user experience;
  • enable essential Website functions;
  • analyze site performance.

Cookies are small text files stored on your device when you visit the Website.

They allow the Website to:

  • recognize your device;
  • store certain information about preferences;
  • store certain information about past actions.

8.2. Strictly necessary cookies

Strictly necessary cookies:

  • are essential for the Website to function;
  • cannot be switched off in our systems;
  • enable page navigation;
  • enable access to secure areas;
  • support user authentication.

8.3. Functional cookies

Functional cookies:

  • support enhanced functionality;
  • support personalization;
  • may remember language preferences;
  • may remember user settings;
  • may be set by us;
  • may be set by third-party providers whose services we use.

8.4. Analytical or performance cookies

Analytical or performance cookies collect aggregated and anonymized data about Website use.

This may include:

  • page visits;
  • click-through rates;
  • traffic sources;
  • on-site interaction metrics.

These cookies are used to:

  • measure Website performance;
  • improve Website performance.

8.5. Advertising or targeting cookies

Advertising or targeting cookies may be set by us or by advertising partners.

They may be used to:

  • build a profile of your interests;
  • deliver relevant advertising on this Website;
  • deliver relevant advertising on other websites;
  • limit how often you see an advertisement;
  • assess advertising effectiveness.

8.6. Session cookies and persistent cookies

Session cookies:

  • expire when you close your browser.

Persistent cookies:

  • remain on your device for a predetermined period;
  • remain until deleted by you.

8.7. First-party cookies and third-party cookies

First-party cookies are set by us.

Third-party cookies are set by third-party service providers acting on our behalf.

Such providers may include:

  • analytics providers;
  • customer support tool providers;
  • advertising networks.

8.8. Managing cookies

You may control and manage cookies through your browser settings.

Most browsers allow you to:

  • refuse cookies;
  • delete cookies.

Restricting certain cookies may affect the availability or functionality of some parts of the Website.

9. Minor Protection Checklist

9.1. Age requirement

The Services are intended only for individuals who are:

  • at least eighteen (18) years old; or
  • the legal age defined by their respective jurisdiction, whichever is higher.

By accessing or registering for the Services, you confirm that you meet this age requirement.

9.2. Responsible Gaming Policy alignment

In alignment with the Curaçao Gaming Authority’s Responsible Gaming Policy introduced in February 2025, we have implemented measures to prevent underage access to the Services.

9.3. Document verification

Users may be required to provide valid government-issued identification documents during registration.

This supports:

  • age verification;
  • identity verification;
  • compliance with age restrictions.

9.4. Automated monitoring

Automated monitoring may be used to detect:

  • inconsistencies in user activity;
  • signs of underage access attempts.

9.5. Security reviews

Where underage access is suspected, security reviews may include verification of:

  • registration data;
  • financial transactions.

9.6. Data purging

Personal Data submitted by individuals identified as minors is deleted immediately.

9.7. Parental controls and education

Parents and guardians are encouraged to:

  • use available parental control tools;
  • educate minors about responsible online behavior;
  • help prevent unauthorized access to the Services.

9.8. Responsible gaming commitment

Our responsible gaming commitment includes adherence to CGA guidelines on:

  • player protection;
  • age verification.

We continually review and enhance our policies to ensure that they meet or exceed regulatory standards.

10. Data Protection Rights Checklist

10.1. Right of Access

Under Article 15 GDPR, you can request:

  • confirmation of whether we process your Personal Data;
  • a copy of such Personal Data;
  • information about how your Personal Data is used.

10.2. Right to Rectification

Under Article 16 GDPR, you can request correction of:

  • inaccurate Personal Data;
  • incomplete Personal Data.

Correction may be requested without undue delay.

10.3. Right to Erasure

Under Article 17 GDPR, you can request deletion of your Personal Data where legal grounds apply.

This may apply where:

  • data is no longer necessary for the purposes collected;
  • you withdraw consent where applicable;
  • no other lawful basis applies.

10.4. Right to Restrict Processing

Under Article 18 GDPR, you can request that we limit Processing of your Personal Data in specific situations.

This may apply where:

  • the accuracy of Personal Data is contested;
  • Processing is unlawful.

10.5. Right to Data Portability

Under Article 20 GDPR, you can request a copy of the Personal Data you provided to us.

The copy may be provided in a:

  • structured format;
  • commonly used format;
  • machine-readable format.

Where technically feasible, you may transfer the data to another controller.

10.6. Right to Object

Under Article 21 GDPR, you can object to Processing of your Personal Data:

  • for reasons related to your particular situation;
  • where Processing is based on legitimate interests;
  • where Processing is for direct marketing purposes.

10.7. Exercising your rights

To exercise your data protection rights, you may contact us through:

11. Consent Withdrawal Checklist

11.1. Right to withdraw consent

If we process Personal Data based on your consent, you have the right to withdraw that consent at any time.

11.2. Effect of withdrawal

Withdrawal of consent does not affect the lawfulness of Processing based on consent before its withdrawal.

11.3. How to withdraw consent

To withdraw consent, contact us using the channels specified in this Privacy Policy.

After receiving your request, we will stop Processing the relevant Personal Data unless retention or continued Processing is required to comply with legal or regulatory obligations.

11.4. Possible consequences of withdrawal

If withdrawing consent affects our ability to provide certain Services, we will inform you of the consequences before completing the withdrawal process.

12. Complaint Checklist

12.1. Right to lodge a complaint

Under Article 77 GDPR, you have the right to lodge a complaint if you believe that:

  • your Personal Data is being processed unlawfully;
  • your privacy rights have been violated.

12.2. Complaint authorities

You may lodge a complaint with:

  • the supervisory authority in the EU Member State where you reside;
  • the supervisory authority in the EU Member State where you work;
  • the supervisory authority in the EU Member State where the alleged violation occurred;
  • the Curaçao Gaming Authority;
  • any other relevant data protection authority in Curaçao.

12.3. Contacting us before lodging a complaint

If you have concerns or unresolved questions about the Processing of your Personal Data, we encourage you to contact us directly.

We will make every reasonable effort to address your concerns in a timely and lawful manner.

13. Required Personal Data Checklist

13.1. Legal requirement

Providing Personal Data may be a legal requirement.

Certain data must be provided to comply with applicable laws and regulations, including:

  • Anti-Money Laundering obligations;
  • responsible gaming requirements.

13.2. Contractual requirement

Providing Personal Data may be a contractual requirement.

Some data is necessary to:

  • enter into a contract with you;
  • perform a contract with you;
  • enable access to the Services;
  • process transactions.

13.3. Service access requirement

Providing Personal Data may be required to access the Services.

Without required Personal Data, we may be unable to:

  • offer certain Services;
  • fulfill contractual obligations;
  • fulfill legal obligations.

13.4. Consequences of not providing required data

Failure to provide required Personal Data may result in:

  • inability to create or maintain an Account;
  • restrictions on use of the Services;
  • termination of the contractual relationship;
  • inability to comply with regulatory obligations;
  • prevention from providing Services.

14. Legal Disclaimer Checklist

14.1. Service basis

The Services operate on an “AS-IS” and “AS-AVAILABLE” basis.

No warranties or guarantees are provided for:

  • uninterrupted performance;
  • error-free performance.

14.2. Security limitation

We take reasonable precautions to protect Personal Data.

However, absolute security cannot be guaranteed due to:

  • the complex nature of technology;
  • evolving cybersecurity threats.

14.3. Limitation of liability

To the maximum extent permitted by law, we are not liable for:

  • events beyond our direct control, including system failures, cyberattacks, or unauthorized access;
  • indirect, incidental, consequential, or punitive damages arising from data breaches, unauthorized disclosure, or misuse of Personal Data;
  • errors, inaccuracies, or security vulnerabilities on third-party websites linked from the platform.

14.4. Third-party websites and services

By using the Services, you acknowledge and agree that we do not bear responsibility for external websites or services operated by third parties, even if they are linked from the platform.

15. Acceptance, Updates, and Language Checklist

15.1. Acceptance of this Privacy Policy

Your continued use of the Services signifies your explicit acceptance of this Privacy Policy.

This document serves as the entire and exclusive Privacy Policy and replaces any previous versions.

15.2. Related documents

This Privacy Policy should be read together with:

  • the Terms and Conditions;
  • any additional applicable notices posted on the platform.

15.3. Policy modifications

We reserve the right to modify this Privacy Policy at any time.

Any changes will be posted on the platform.

Continued use of the Services after modifications constitutes acceptance of the revised Policy.

15.4. Regular review

You are strongly encouraged to review this Privacy Policy regularly to stay informed about updates.

15.5. English version priority

All versions of this Policy, except for the English version, are provided for informational purposes only.

The English version prevails in case of discrepancies or conflicts between different versions.