Privacy Policy
This notice describes the categories of personal information Cosmobet Casino handles, the purposes it serves, and the choices open to you as the person that information concerns. It applies to our website, our mobile interface and any correspondence with our support desk.
Information we hold
When you register, we record identifying details such as your full name, date of birth, residential address, email address and telephone number. Verification documents — a passport, driving licence or national identity card together with a recent utility bill or bank statement — are collected to satisfy anti-money-laundering and age-assurance obligations attached to licence OGL/2025/4887/5353.
Transactional records cover deposits, withdrawals, stakes placed, bonus credits applied and the payment instruments used. These records are generated automatically as you use the platform and are necessary for us to operate your balance accurately.
Technical information reaching our servers includes your IP address, browser identifier, operating system, device type, screen configuration and timestamps of each visit. Correspondence with support, including live chat transcripts and email threads, is retained alongside your account file.
Why we process it
The primary basis for processing is the performance of our contract with you: without account data we cannot credit deposits, settle bets, or release withdrawals. Refusing to supply mandatory fields will prevent an account from being opened or maintained.
A separate body of processing rests on legal obligation. Regulatory reporting, sanctions screening, transaction monitoring and the retention of verification records are all required of licensed operators, and consent is not the basis for these activities.
We rely on legitimate interests for fraud detection, bonus-abuse investigation, platform security and the analysis of aggregate usage patterns that guide product decisions. Direct marketing is sent on the basis of consent, which you may withdraw at any time without affecting your ability to play.
Disclosure to third parties
Payment processors, card acquirers and cryptocurrency gateways receive the minimum data set required to move funds. Game studios supplying content to Cosmobet Casino receive a pseudonymous session identifier rather than your name or contact details.
Identity verification bureaux, credit reference agencies and sanctions-list providers are engaged to confirm the information you supply. Where a regulator, court order or law enforcement authority makes a lawful request, we disclose what is compelled and no more.
We do not sell personal information, and we do not pass contact details to unrelated advertisers. Every processor engaged on our behalf works under a written agreement restricting them to our documented instructions and requiring appropriate security measures.
Storage periods and safeguards
Account and transaction records are kept for the duration of the relationship and for a further period after closure, ordinarily not less than five years, in line with anti-money-laundering record-keeping rules. Self-exclusion registers are held for as long as needed to give the exclusion effect.
Data is encrypted in transit using current TLS protocols and at rest on servers held in access-controlled facilities. Administrative access is granted on a least-privilege basis, logged, and reviewed periodically; payment card details are tokenised and never stored in full on our systems.
Where information is transferred outside your home jurisdiction, we put contractual protections in place, including standard contractual clauses where the receiving country lacks an adequacy determination.
Your rights and how to use them
You may request a copy of the personal information we hold, ask for inaccuracies to be corrected, object to processing based on legitimate interests, request restriction of processing, or ask for a portable export of the data you supplied to us. Requests are answered within one month, extendable where a request is complex.
The right to erasure is qualified: we cannot delete records we are legally obliged to keep, nor those needed to enforce an active self-exclusion. Where deletion is refused, we explain the specific ground relied on.
Cookies and similar identifiers are managed through the preference panel available on every page. Essential cookies supporting login and fraud prevention cannot be disabled, but analytics and marketing categories are opt-in and can be revoked at any time. If you are dissatisfied with our response, you may complain to your national data protection authority — in the United Kingdom, the Information Commissioner's Office.
Questions about this document go to [email protected].
This notice is provided in English for clarity and may be updated as our practices or legal obligations change. Material revisions are announced on the site and, where required, communicated directly to registered account holders.