Slotoro Casino manages the safety and secrecy of your personal data as a top priority https://slotoro.bg/legal-and-affiliates/. This Data Protection Policy describes, in clear wording, how we gather, manage, keep, and protect the data of users, with a emphasis on those accessing our platform from Bulgaria. The policy follows international data protection norms, including the General Data Protection Regulation (GDPR). Every step we take is intended to offer you a safe gaming experience while keeping you in control of your private information. Slotoro Casino serves as a data controller, which implies we choose why and how your data is processed. This policy covers all interactions with the Slotoro website, mobile apps, customer support platforms, and any affiliated services. Transparency matters to us, so we encourage every player to review this document before accessing the platform.
1. Scope and Purpose of the Data Protection Policy
Slotoro Casino’s data protection framework covers every point where we collect personal information from registered users and visitors. This includes account registration forms, identity verification submissions, payment processing interfaces, live chat transcripts, emails, and automated logs of technical parameters during browsing sessions. We gather personal data mainly to provide a fully functional, legally compliant, and personalized gaming experience. Without certain mandatory information, we are unable to establish a contractual relationship, process payments, or meet anti-money laundering requirements. We also employ aggregated and anonymized data for statistical analysis, platform improvements, and to improve responsible gambling tools. The framework also extends to data shared with carefully selected third-party providers who execute essential tasks like payment processing, game hosting, and customer relationship management. Each provider is bound by contracts that reflect the protections in this policy, so the same standard of care follows the data throughout its entire life.
6. Data Storage and Deletion Procedures
We retain personal data solely for the period necessary to accomplish the objectives it was gathered for, or to comply with statutory record-keeping regulations set by gaming regulators and tax authorities. Account information is maintained for the entire customer relationship, then is archived for five years after account closure. That five-year period aligns with anti-money laundering directives and the time limit for potential legal claims. Financial transaction records are held a minimum of seven years for tax reporting. Identity verification documents are safely removed once the verification outcome is logged, unless a law or a specific investigation requires us to keep them longer. Technical logs and security monitoring data are rotated on a rolling basis, typically kept for twelve months before automatic deletion. We use automated data lifecycle tools that identify records nearing their retention limit and then trigger secure erasure. If we fulfill a deletion request under the right to erasure, we delete all personal data except for what we must keep for strong reasons, such as defending legal claims or complying with a binding regulatory order.
2. Types of Personal Data Collected
We collect several various types of personal data, each for a specific reason. Identification data represents the core of your player profile: full legal name, date of birth, residential address, nationality, and a government-issued ID number. Contact information includes the email address and phone number you supply when registering, utilized for account notifications and security alerts. Financial data includes payment method details, transaction histories, deposit and withdrawal amounts, and partial card numbers (retained for fraud prevention). Technical data is automatically gathered via cookies and similar tools, capturing IP addresses, device fingerprints, browser types, operating system versions, and session duration. Verification information includes documents uploaded for Know Your Customer checks, such as passport scans, utility bills, and proof of payment ownership. Additionally, activity data covers gaming preferences, betting patterns, bonus usage, and self-imposed limit settings. We gather each category only where a lawful basis exists, and retention periods are matched to the specific purpose for which the data was originally obtained.

4. Data Distribution and Third-Party Disclosures
We collaborate with a set of vetted third-party service providers to operate the platform in a secure manner, and data sharing is restricted to what each partner needs to do their job. Payment processors get only the transaction details necessary to handle deposits and withdrawals; they work under Payment Card Industry Data Security Standard (PCI DSS) certifications. Game providers receive a unique player identifier and balance information, in no case your full personal profile. Identity verification agencies obtain the documents you upload for KYC checks and send back verification results through encrypted channels. Cloud hosting providers store data on infrastructure with enterprise-grade security controls, in server locations selected to maintain adequate protection. Marketing platforms handle email addresses and engagement metrics solely to run campaigns and assess performance. We also disclose personal data to regulators, law enforcement, and financial intelligence units when the law mandates it. Beyond these instances, we do not ever trade your data to external parties. Every third-party relationship is controlled by a written data processing agreement that specifies what data is used, for how long, and for what purpose, with strict confidentiality obligations.
8. Safety Measures Safeguarding Player Data
We use multiple layers of security to protect your confidential data from unauthorized access, change, exposure, or destruction. Encryption is the initial layer: Transport Layer Security (TLS) protects data in motion between your system and our platforms, and Advanced Encryption Standard (AES) secures data at rest in our databases. Access restrictions are strict: role-based authorizations, multi-factor authentication for admin accounts, and the concept of least authority, indicating staff can only see the data they certainly must have for their role. Our network protection features next-generation firewalls, intrusion identification and prevention mechanisms, and round-the-clock traffic surveillance by a specialized Security Operations Center. We keep our software protected through routine code inspections, vulnerability assessment, and penetration evaluations by third-party cybersecurity organizations. Data centers have biometric access controls, 24/7 monitoring, and duplicate power and environmental systems. We also have a thorough incident management plan that addresses prompt control, elimination, and reinstatement, plus a breach alert procedure that guarantees authorities and impacted individuals are notified within 72 hrs of us becoming aware about a relevant personal data breach.
3. Lawful Bases for Handling Player Information
We use your personal data only when we have a valid legal reason to do so. The six lawful bases we rely on are those specified in data protection law. First, processing often happens because it’s necessary to perform our contract with you: handling your registration details, facilitating deposits and withdrawals, and offering the gaming services you signed up for. Second, we process some data to meet legal obligations, including identity verification, anti-money laundering screening, and reporting suspicious transactions to authorities. Third, we rely on legitimate interests for things like network security monitoring, fraud detection, internal analytics, and direct marketing of similar products to existing customers, always after confirming your rights don’t outweigh our interests. Consent is another basis, which we request explicitly when you consent to non-essential cookies, promotional newsletters, or certain marketing campaigns. You can withdraw consent at any time, but it won’t affect the lawfulness of processing that happened before. In very rare cases, processing might be required to secure someone’s vital interests or to execute a task in the public interest. We note the lawful basis for each processing activity and can share that information if you ask.
7. Player Entitlements In Accordance with Data Protection Legislation
Bulgarian players possess a complete range of rights pursuant to the GDPR, and we have implemented internal processes to handle each one within the one-month deadline. The right of access enables you to request whether we handle your data and receive a copy of it accompanied by information about why and with which parties we share it. The right to rectification signifies you can rectify inaccurate or incomplete personal data, usually through your account dashboard or by reaching out to support. The right to erasure (right to be forgotten) holds when, for example, your data is no longer required or you rescind consent. You can call upon the right to restrict processing while a dispute about accuracy or lawfulness is being settled. Data portability enables you to get your data in a structured, machine-readable format and transmit it to another controller. The right to object pertains to processing based on legitimate interests, encompassing profiling for direct marketing. And we will not make decisions that have legal effects on you based solely on automated processing without human involvement. We charge no fee for exercising these rights save when a request is obviously unfounded or excessive.
5. Cross-border Data Movements and Measures
Because Slotoro Casino is reachable internationally, we could transmit your personal data to servers and service providers based outside your country of residence. When transfers occur from the European Economic Area to third countries, we put safeguards in place so that GDPR protection levels are not weakened. Standard Contractual Clauses sanctioned by the European Commission are the main mechanism we use; they bind recipients to the same data protection duties. We also evaluate the legal system of the destination country, considering things like government surveillance laws and if you’d have a way to obtain redress. If a service provider is certified under an approved framework or works in a country with an adequacy decision, we verify that before any transfer begins. Bulgarian players can contact the Data Protection Officer for a copy of the relevant safeguard documents. We remain accountable for your data even after it’s transferred, and we carry out regular audits and demand any service provider to notify us immediately about any security incident influencing that data.
The 9th Affiliate Programme Data Handling Standards
This affiliate programme follows the same strict data protection practices as the main gaming platform. Affiliates who register provide us with business contact information, payment information for commission payouts, and marketing performance data produced through tracking links and unique identifiers. We process this data based on contract performance and legitimate basis (monitoring campaign effectiveness and preventing fraud). Tracking technologies on affiliate landing pages collect referral source details, click timestamps, and conversion events; we pseudonymize this data wherever possible. Affiliates are contractually obligated to have their own compliant privacy policies and to obtain valid consent from users before tracking commences, in line with ePrivacy regulations. Commission payment data is stored for the life of the affiliate relationship and then for the legally required fiscal term. Affiliates have the same data subject entitlements as users, including retrieval to their stored information and the ability to request corrections. We run periodic compliance audits on affiliate partners to make sure their data handling conforms with this policy, and we can end partnerships if we identify breaches.
Popular Questions
What personal data does Slotoro Casino require to create an account?
To create an account, we ask for your complete legal name, birth date, residential address, email address, and a username and password you select. For deposits, we additionally require your phone number and payment details. Subsequently, we will request identity verification documents to comply with regulatory standards.
How does a player go about requesting deletion of their personal information?
You can request deletion by emailing our Data Protection Officer at the address listed in the website’s privacy section. Inform us of your identity and the specific data you wish to have removed. Your request will be evaluated against legal standards, and we will reply within 30 days.
Is player data shared by Slotoro Casino with other gaming operators?
No, we don’t share your personal data with other gaming operators for marketing or cross-promotions. We may share data with regulators and law enforcement if the law demands it, and with service providers who help run our platform—under strict contracts.
For how long are identity verification documents kept?
We keep your ID documents only as long as needed to complete verification and meet anti-money laundering rules. Typically, they are securely archived for five years following the last transaction on your account, then permanently removed using certified erasure techniques.
What protections are in place for financial transaction data?
Financial data is protected with end-to-end encryption, tokenization of card details, and compliance with PCI DSS. Payment processing runs on isolated networks, and only a small, background-checked team with confidentiality agreements can access financial records.
May a player contest the use of their data for marketing?

Absolutely. Every marketing message we send has an unsubscribe link that lets you opt out immediately. You can also modify your preferences in your account settings or contact customer support to refuse direct marketing.
What happens when Slotoro Casino handle data breaches?
We have a formal breach response plan: immediate containment, forensic investigation, and notification to the supervisory authority within 72 hours of discovery. If a breach puts your rights and freedoms at high risk, we’ll tell you without delay and give you clear steps to protect yourself.
Which is the lawful basis for processing affiliate data?
We process affiliate data mainly because it’s needed to perform the contract: manage the relationship, track referrals, and pay commissions. We also rely on legitimate interest for fraud prevention and programme analytics, always balanced against what affiliates reasonably expect.