This personal data protection policy reflects the requirements of EU Regulation 2016/679 on the protection of individuals in regard to the processing of personal data and on the free movement of such data (“General Data Protection Regulation” or GDPR), with regard to the processing of personal data and the Personal Data Protection Act, as well as other special requirements of the applicable regulations for our activity, incl. but not only: the Gambling Act, the Anti-Money Laundering Act, their by-laws, as well as the mandatory gambling conditions, rules and requirements for organized gambling adopted by the National Revenue Agency by companies operating under the WINBET brand (referred to in current brevity policy “WINBET”).
What information do we collect and why?
We may collect personal information about you when you visit our gaming clubs. In most cases, we require your personal information for the purpose of providing services, to comply with a legal obligation or to protect our legitimate interest.
If you do not provide your credentials, we will not be able to provide you with the relevant service. Depending on the services you use, we may collect and process the following information about you:
When visiting a gaming club:
- Name and date of birth so that we can establish your identity and if you are at legal age to participate in games;
- email address for receiving marketing messages;
- telephone number for receiving marketing messages;
- UPN, permanent resident personal number or other identification number and ID card data, as well as citizenship – only when paying amounts earned over BGN 4,000
- Video recordings of your visit in order to ensure our and your security and / or fulfill a regulatory obligation.
The purpose of processing your data
In most cases, personal data is required in order to comply with a legal obligation, to perform a contract or on the basis of a legitimate interest. Of course, with some of our services, you provide us with this information by personal choice and by agreeing to it. The personal data we collect and process are most often for the following purposes:
- Gambling Act, Measures against Money Laundering Act, their by-laws, as well as the mandatory gambling conditions, rules and requirements for organized gambling adopted by the National Revenue Agency;
- Personal Income Tax Act;
- Accounting Act and the Tax-Insurance Procedure Code and other related acts, in connection with the keeping of correct and lawful accounting;
- obligations to provide information to all state commissions and regulatory bodies;
- obligations for video surveillance in our gaming clubs;
- obligations to provide information to the court and the law enforcement agencies.
Processing of data based on your consent
When we process your data for the purposes of direct marketing, as well asyou’re your participation in bonus games and raffles, we will need your explicit consent.
Data processing based on our legitimate interest
- video surveillance in our administrative sites;
- sound recordings of telephone conversation with the call center, in order to improve the quality of services provided, as well as for resolving disputes and protecting legitimate interests.
Who can we share your data with?
In some cases, we are obliged to provide your personal data to third parties in order to comply with our legal qobligations. Depending on the games organized by WINBET in which you take part, we may provide your data to the following categories of recipients:
- National Revenue Agency, State National Security Agency, in compliance with statutory requirements and obligations related to gambling. These bodies have the right to receive information about our registered users, the bets made, the winnings paid, as well as other data, in the cases and the form stipulated by law;
- Banks, payment institutions, postal money order companies, specifically identified in the relevant rules for organizing and conducting of the Games, in compliance with the requirements and obligations for making bets and paying out winnings;
- Providers of systems / services for providing games, managing and maintaining the activity and quality of services, incl. those related to the information technology with which we have a contract (e.g. IT providers, software suppliers, computer support providers, prizes providers, etc.), in compliance with the requirements and obligations to maintain the statutory system functionalities, identification of participants, placing bets, determining results and paying out winnings;
- State bodies / institutions, persons with public functions, regulators and supervisory bodies (including Ministry of Youth & Sports, NRA, SNSA, the courts, public prosecution and investigation bodies, Consumer Protection Commission, Competition Protection Commision, Personal data Protection Commission, etc.), if we have sufficient grounds to consider that the access, use, preservation or disclosure of them is necessary for: the implementation of applicable law or other normative act of binding nature; in response to an inquiry made by a supervisory body, regulator or other state institution in connection with or on the occasion of the performance of its statutory functions or initiated inspection, complaint, audit, etc .; detection, prevention or other actions related to fraud, money laundering, terrorist financing, technical or security issues.
WINBET uses third parties to support certain contract activities or in the performance of a legal obligation. We do not provide your personal data to third parties until we are sure that all technical and organizational measures have been taken to protect this data, and we strive to exercise strict control to achieve this goal. Some of these recipients of personal data may be:
- courier companies, external consultants and specialists, collection companies and law firms, banks, security companies, persons who on assignment maintain equipment, software and hardware used for processing personal data by WINBET, hosting companies and sales agents, etc.
Information about us
The personal data of the participants in the organized games can be processed by the following administrators: When you participate in games in our gaming clubs, the data are processed by Casino Solutions Ltd., UIC: 131496606, with registered office and address in Sofia, Mladost district, residential complex Mladost-2, Sveti Kyprian Str., Bl. 292, together with the companies operating under the WINBET brand, in their capacity as joint administrators.
In strict compliance with European and local legislation in the field of personal data and in order to guarantee the rights of data subjects, the companies operating under the WINBET brand, as joint administrators, have agreed:
- The right to information of each subject to be provided by the company with which he has made initial contact;
- Where the basis for data processing is consent, it shall be provided to the company to which it is provided, and shall be considered a valid basis for processing in respect of other companies;
- The Personal Data Protection Officer for companies operating under the WINBET brand as joint administrators can be found at the following e-mail address: [email protected];
- Each of the companies is obliged in due time, but not later than 1 month from the request, to provide information about the actions taken on the rights / claims stated by the data subject on the grounds of art. 15 – 22 of the General Regulation for Personal Data Protection and LPPD;
- Inquiries from data subjects made electronically will be answered electronically, unless otherwise requested by them;
- Each of the companies is responsible for the execution of requests for exercising the rights of data subjects, regardless of which of the companies the specific request is addressed to;
- The companies jointly apply rules, policies, organizational and technical measures to ensure the security of personal data, their lawful processing, respect for the rights of data subjects, as well as the engagement of processors to guarantee the same or adequate level of protection and manner. of data processing;
- In the event of a breach of security of data processing, the companies shall cooperate to ensure that all necessary measures are taken to limit the data security / data subjects’ rights and to notify (no later than 72 hours after learning) the Commission for the protection of personal data and, if necessary, the data subject;
- Notwithstanding the agreements between the companies, the data subject may address his requests to any of them. The latter are jointly liable for the exercise of the data subject’s rights.
Technical and organizational security measures
In order to ensure the maximum level of protection of personal data, the companies operating under the WINBET brand jointly apply the following technical and organizational security measures, such as:
- Protection of the collected personal data from unjustified use and monitors their processing;
- Maintenance of secure computer systems through which personal data is processed. Adequate control mechanisms for data sharing and management are applied to our systems;
- Adopt strict policies and procedures applicable to its staff to minimize the risks of personal data processing;
- WINBET employees are familiar with the applicable rules and are trained to process personal data with the utmost care and in full compliance with established good practices;
- In carrying out its activities, WINBET works only with established organizations and avoids working with companies that it believes may endanger the security of personal data of individuals;
- Adopted good practices in the implementation and administration of security systems and monitoring of technological developments in relation to possible risks to the security of information in the company;
- Observance of the security of the computer systems and the personal data contained in them, including the possibilities for access to certain types of personal data by its employees;
- Providing access only to the personal data that is necessary for the performance of the work of the employee.
WINBET companies have adopted procedures to effectively identify, report and investigate personal data breaches. In the event of a breach of personal data security, each of the companies will take immediate action to limit the effect of the breach, as well as to inform the data subjects concerned and the data protection supervisory authority.
What are your rights and how can you exercise them?
You have the right to information, access and receiving a copy of your personal data that is processed by WINBET. If you believe that information about you that WINBET has is inaccurate or incomplete, you may request that your personal data to be edited. You can also exercise the right to correct or update the personal data provided by you by accessing your user profile on the WINBET website. In addition, you have the right to:
- Place an objection to the processing of your personal data;
- request restrictions on the processing of your personal data; and / or
- withdraw your consent when WINBET processes your personal data on the basis of consent (without such withdrawal affecting the lawfulness of the processing carried out before the withdrawal);
- complain with the supervisory body – CPDP (Sofia 1592, Blvd. “Prof. Tsvetan Lazarov” or at cpdp.bg ).
WINBET will process and satisfy requests, consent withdrawals or objections in accordance with the requirements of the applicable data protection rules, but these rules are not absolute: they are not always applicable and there may be exceptions. In response to a request, you will need to verify your identity and / or provide additional information to help us better understand your request. When you have re-exercised your right to access information or copy machine-readable data, WINBET may charge a reasonable fee based on the administrative costs required to provide it.
How to exercise your rights?
Each of the rights provided by law may be exercised by submitting a request, as follows:
- Electronically to the following email address: [email protected].
- In the central office of WINBET at the address: Sofia, Mladost district, residential complex Mladost-2, Sveti Kyprian Str., Bl. 292
The request for the exercise of personal data rights should contain the following information:
- Identification of the person – names and PIN;
- Contacts for feedback – address, phone, e-mail;
- Request – description of the request.
WINBET provides information on the actions taken in connection with a request to exercise your rights within one month of receiving the request. If necessary, this period may be extended by a further two months, taking into account the complexity and number of requests from a particular person. WINBET shall inform the person of any such extension within one month of receipt of the request, stating the reasons for the delay.
The information provided to the subject and any communication and action to exercise the data subject’s rights shall be provided free of charge (except in the case of abuse of the rights granted).
We may request the provision of additional information necessary to verify your identity when there are concerns about the identity of the requesting individual. WINBET is not obliged to respond to a request if it is unable to identify the data subject. Where the request is made by electronic means, the information shall, where possible, be provided by electronic means, unless you have specifically requested otherwise.
Data Protection Officer
The Data Protection Officer of all companies that use the WINBET brand is a lawyer. Desislava Dimitrova, e-mail: [email protected]
Update of the personal data protection policy
This policy is subject to change by WINBET, as last updated on September 1, 2019. Any future changes or additions to this policy will be duly noted.