Aztec Bonanza Slot

Privacy & Security

Information Gathering

This Privacy Policy governs the collection, processing, and storage of personal data by Pragmatic Play Ltd in connection with the operation of aztec-bonanza.com. Personal data is collected in strict accordance with applicable data protection legislation and the regulatory requirements imposed by the recognised gaming authority under whose licence this platform operates.

The following categories of personal data are subject to collection and processing:

  • Identity Data: Full legal name, date of birth, gender, and government-issued identification details, as required for the purposes of age verification and identity authentication.
  • Contact Data: Electronic mail address, telephone number, and residential address, collected for the purpose of account administration and regulatory correspondence.
  • Financial Data: Payment instrument details, transaction records, deposit and withdrawal histories, and banking information, processed exclusively for the purposes of facilitating financial transactions and fulfilling anti-money laundering obligations.
  • Technical Data: Internet Protocol (IP) addresses, browser type and version, device identifiers, operating system information, session data, and cookie-derived information, gathered automatically upon interaction with the platform.
  • Usage Data: Behavioural and navigational data pertaining to platform interaction, including gaming activity records, session durations, wagering patterns, and preference data.
  • Compliance Data: Documentation and information gathered in fulfilment of Know Your Customer (KYC) obligations, source of funds declarations, and responsible gambling assessments, as mandated by the applicable licensing authority.
  • Communication Data: Records of correspondence initiated by or directed to the data subject, including support requests, complaint submissions, and responses thereto.

Personal data is obtained directly from the data subject at the time of account registration, during the verification process, through ongoing platform usage, and via automated technical collection mechanisms. Data may additionally be received from third-party verification service providers, payment processors, and fraud prevention agencies, where such receipt is legally permissible and operationally necessary.

Use of Information

All personal data collected through the operation of this platform is processed exclusively for defined, legitimate, and specified purposes. Processing is conducted on the basis of one or more of the following legal grounds: the performance of a contract to which the data subject is a party, compliance with legal obligations to which the data controller is subject, the pursuit of legitimate interests of the data controller or a third party, or, where applicable, the explicit consent of the data subject.

The specific purposes for which personal data is processed are as follows:

  • Account Establishment and Administration: Personal data is processed to create, maintain, and administer user accounts, including the verification of eligibility to participate in gaming services and the authentication of user identity at the point of access.
  • Service Delivery: Data pertaining to user activity and preferences is utilised to facilitate the provision of gaming services, process transactions, manage balances, and ensure the continuous and uninterrupted operation of platform functionality.
  • Regulatory Compliance: Personal data is processed as required by the licensing authority and applicable law, including for the purposes of age verification, identity verification, anti-money laundering screening, transaction monitoring, and the maintenance of statutory records.
  • Fraud Prevention and Security: Usage data, technical data, and financial data are processed to detect, investigate, and prevent fraudulent activity, unauthorised access, and other unlawful conduct that may compromise the integrity of the platform or the interests of its users.
  • Responsible Gambling: Gaming activity and behavioural data are processed to monitor usage patterns, identify indicators of problem gambling behaviour, enforce self-exclusion requests, and fulfil obligations imposed by the licensing authority in respect of player protection.
  • Financial Processing: Financial data is processed to execute deposits, withdrawals, and other monetary transactions, to reconcile accounts, and to comply with applicable financial regulation and taxation requirements.
  • Customer Support: Communication data and account-related information are processed to address enquiries, resolve disputes, manage complaints, and deliver user assistance services.
  • Legal Proceedings: Where necessary, personal data may be processed for the establishment, exercise, or defence of legal claims, and for cooperation with competent regulatory or law enforcement authorities.

Personal data shall not be processed for purposes incompatible with those for which it was originally collected, save where such processing is authorised by applicable law or where the explicit consent of the data subject has been obtained.

Data Security

Pragmatic Play Ltd is committed to the implementation and maintenance of appropriate technical and organisational measures designed to ensure a level of security commensurate with the risks presented by the processing of personal data. Such measures are regularly reviewed and updated in response to evolving technological standards and identified threats.

The following technical and organisational safeguards are applied to personal data processed in connection with this platform:

  • Encryption: All personal data transmitted between the data subject's device and the platform's servers is encrypted using industry-standard Transport Layer Security (TLS) protocols. Sensitive data at rest, including financial credentials and identification documentation, is subject to encryption using advanced cryptographic standards.
  • Access Controls: Access to personal data is restricted on a strictly need-to-know basis. Role-based access control mechanisms are implemented to ensure that only authorised personnel whose functions necessitate access to specific categories of data are permitted such access.
  • Authentication Systems: Multi-factor authentication and secure credential management protocols are applied to systems through which personal data is accessible, in order to prevent unauthorised access by internal or external parties.
  • System Security: Firewalls, intrusion detection systems, and continuous network monitoring are maintained to protect information systems against unauthorised access, cyber threats, and denial-of-service attacks.
  • Data Minimisation: Personal data is collected and retained only to the extent necessary for the fulfilment of the purposes for which it was obtained. Data that is no longer required is securely deleted or anonymised in accordance with established retention schedules.
  • Vendor Management: Third-party data processors engaged to support platform operations are subject to contractual data protection obligations and are assessed for compliance with applicable data protection standards prior to engagement and on an ongoing basis.
  • Incident Response: Documented procedures are maintained for the detection, assessment, containment, and notification of personal data breaches, in accordance with the requirements of applicable data protection law and the relevant licensing authority.
  • Staff Training: All personnel with access to personal data are required to undergo data protection training and are subject to binding confidentiality obligations as a condition of their engagement.

Notwithstanding the implementation of the foregoing measures, no data transmission over the internet or electronic storage system can be guaranteed to be unconditionally secure. Users are advised to maintain the confidentiality of their account credentials and to notify the platform immediately upon suspicion of any unauthorised use of their account.

User Rights

Data subjects whose personal data is processed in connection with this platform are entitled to exercise a range of rights in relation to such data, as provided under applicable data protection legislation. The exercise of these rights is subject to verification of the identity of the data subject and to any limitations or exemptions prescribed by law, including those arising from regulatory or legal obligations to which the data controller is subject.

The following rights are available to data subjects:

  • Right of Access: Data subjects are entitled to request confirmation as to whether personal data concerning them is being processed and, where such processing is taking place, to obtain a copy of the personal data concerned together with supplementary information regarding the nature and purposes of such processing.
  • Right to Rectification: Where personal data held by the platform is found to be inaccurate or incomplete, data subjects are entitled to request the correction or completion of such data without undue delay.
  • Right to Erasure: Data subjects may request the deletion of personal data concerning them where such data is no longer necessary for the purposes for which it was collected, where consent upon which processing was based has been withdrawn, or where processing is found to be unlawful, subject to any overriding legal obligations requiring retention.
  • Right to Restriction of Processing: Data subjects are entitled to request the restriction of processing of their personal data in specified circumstances, including where the accuracy of the data is contested or where an objection to processing has been lodged and is pending determination.
  • Right to Data Portability: Where processing is carried out by automated means on the basis of consent or contractual necessity, data subjects are entitled to receive personal data concerning them in a structured, commonly used, and machine-readable format, and to have such data transmitted to another controller where technically feasible.
  • Right to Object: Data subjects are entitled to object to the processing of personal data concerning them where such processing is based on legitimate interests, including profiling based on those grounds, unless compelling legitimate grounds for processing can be demonstrated that override the interests, rights, and freedoms of the data subject.
  • Rights in Relation to Automated Decision-Making: Data subjects are entitled not to be subject to decisions based solely on automated processing, including profiling, which produce legal or similarly significant effects, save where such processing is permitted by applicable law or where explicit consent has been provided.
  • Right to Withdraw Consent: Where processing is based on the consent of the data subject, such consent may be withdrawn at any time without prejudice to the lawfulness of processing carried out prior to withdrawal.
  • Right to Lodge a Complaint: Data subjects are entitled to lodge a complaint with the competent supervisory authority responsible for data protection matters in the relevant jurisdiction where it is considered that the processing of personal data infringes applicable data protection legislation.

Requests for the exercise of any of the foregoing rights shall be submitted to the data controller in writing. Upon receipt of a valid request, a response shall be provided within the timeframes prescribed by applicable data protection law. The data controller reserves the right to decline requests that are manifestly unfounded, excessive, or incompatible with applicable legal obligations.

Reach Out

All enquiries, requests, and correspondence relating to the processing of personal data by Pragmatic Play Ltd in connection with this platform, including requests for the exercise of data subject rights, questions regarding this Privacy Policy, or concerns relating to data protection practices, shall be directed to the designated contact point by electronic correspondence.

Electronic correspondence may be addressed to the following: [email protected]

All communications shall be acknowledged and responded to in accordance with the applicable statutory response periods. Data subjects submitting formal requests are advised to provide sufficient information to enable the identification and verification of their identity, in order to facilitate the efficient and accurate processing of their request. The data controller shall not be liable for delays resulting from the failure of a data subject to provide adequate identifying information.

🍪 This site uses cookies to improve your experience. Read more in our Privacy Policy.
Necessary
Required for the website to function properly
Analytics
Help us understand how visitors use the site
Marketing
Used for personalized advertising
Preferences
Remember your site preferences