As a regulated operator in Italy, we collect and manage personal and transactional data under strict legal obligations https://it-richroyal.it/legal-and-affiliates/. This policy spells out exactly how long we hold different categories of information, the legal reasons behind those periods, and the security measures that protect your data at every stage. We continuously balance our duty to retain records for fraud prevention and financial audits with the privacy rights you hold under Italian data protection law and the GDPR. Our schedules undergo regular reviews so we stay fully compliant.
Cross-border Data Transfers and Retention
Our core infrastructure sits documenti.camera.it in Italy and the larger European Economic Area. Some ancillary services, like fraud detection platforms and customer relationship tools, may send limited personal data to countries external to the EEA. In those cases, we ensure an adequacy decision is available or we implement Standard Contractual Clauses in place together with a transfer impact assessment. The retention periods we assign to transferred data reflect those in this policy, and processors are contractually bound to erase or return data when the service ends. We publish a public register of sub‑processors, updated within fourteen days of any change, and we prefer vendors with Italian data centres. Geo‑fencing rules keep Italian user data inside European boundaries, validated through yearly audits.
Information Protection In Preservation
Held data is secured with AES‑256 encryption at rest, TLS 1.3 protocols in transit and isolated virtual private clouds. Access necessitates multi‑factor authentication plus just‑in‑time privilege elevation that expires on its own. Every access event is logged into an immutable audit trail. We run quarterly penetration tests through CREST‑certified firms and continuous vulnerability scans to maintain our storage tight. Backups are encrypted and spread across Italian data centres, with strict controls that block accidental restoration of data past its deletion date. A dedicated lifecycle dashboard identifies every dataset as it nears expiration.
Access Governance and Employee Education
Only employees whose roles demonstrably require access to retained personal data get permissions, and those permissions go through monthly recertification audits. Any access to dormant user records prompts a managerial review within one business day. Every staff member who handles personal data completes mandatory annual training on Italian data protection law and our internal retention policies, including hands‑on exercises on spotting valid erasure requests and differentiating the difference between data we must keep under a legal hold and data we can delete straight away.
Data Deletion Procedures
When a data class hits the end of its planned retention period, our automatic lifecycle system kicks off a protected erasure procedure. First, the data gets logically removed from production databases. Next, physical storage blocks are overwritten with random data patterns to stop forensic recovery. Finally, a cryptographically timestamped entry lands in a audit trail, giving verifiable evidence that deletion happened on time. Backup copies cycle every ninety days, so any deleted data vanishes from all media within three months. When a litigation hold applies, we halt the deletion workflow only for the affected records, note the hold reason, and restart once the hold lifts.
Affiliate Program Data Retention
Partner relationship data, including communication data, payment details and commission transaction history, is kept for the entirety of the active partnership plus a decade after the contract ends. That stems from tax obligations on commission payments, which require long‑term financial records. Partner performance data and aggregated player referral data get made anonymous after five years. We firmly disallow affiliates from autonomously collecting or keeping personal information about referred players; they get only anonymous, consolidated reports. Our partner contracts include inspection rights to check adherence, and any violation is cause for prompt contract ending and payout forfeiture.
User Rights and Retention Handling
When you send an erasure request, our system automatically checks each data category against its retention schedule. Everything beyond its mandatory window is erased without delay. For data still under a legal retention obligation, we secure it right away so it’s taken out of active use and kept solely for compliance storage; we inform you which specific law is in effect and the date deletion becomes possible. Access requests are responded to within thirty days and come with a breakdown of what we keep, why, and the scheduled deletion date. If you dispute accuracy, we add a note instead of modifying the original record, so the audit trail stays intact. Portability requests are fulfilled in a structured, machine‑readable format even while data is still in its retention window.
Policy Revisions and User Notifications
We evaluate this Data Retention Policy every six months and whenever a major legal change hits Italian gambling operations. Minor clarifications go up silently with a revised effective date. Material changes that alter retention periods, introduce new data categories or change the legal basis for processing are communicated directly to you by email at least thirty days before they come into force. You’ll also see an in‑platform banner notification when you log in during the notice period. Historical versions are stored and available on request, each with a version number and a validity date range. If an earlier version offered a shorter retention period for certain data, we follow that promise for data collected under that version and apply new terms only going forward.
Information Categories and Holding Times
We sort all user data into clear categories, each connected to a retention schedule that corresponds to its purpose and legal context. That systematic approach prevents us from keeping things forever. Every year our Data Protection Officer reviews these classifications and modifies the timelines whenever new guidance comes from the Garante per https://www.gazzetta.it/scommesse/schedine/25-05-2024/schedina-vincente-serie-a-38a-giornata-38402.shtml la protezione dei dati personali. Below you’ll view how long each data type stays in our live systems before being securely anonymised or erased. Archived backups follow a ninety‑day cycle because of technical constraints.
Identity and Fiscal Records
Identity documents you upload during Know Your Customer checks, like passport scans, utility bills and tax ID numbers, remain on file for ten years after you terminate your account, as anti‑money laundering law requires. Deposit and withdrawal logs, payment method tokens and wallet balance histories are held for ten years from the date of each transaction, fulfilling both AML requirements and Italian Civil Code limitation periods. We store these records in encrypted, access‑restricted vaults and tamper‑proof ledgers. Once the retention deadline passes, we remove all personal identifiers permanently; statistical trends may still be applied but never in a way that traces to any individual.
Account Activity and Customer Support Interactions
Comprehensive records of game sessions, bets placed, outcomes and session lengths are kept for five years after each gaming event, matching the statute of limitations for civil disputes. Customer service transcripts, email threads and call recordings stay for three years from your last interaction, covering the typical complaint‑handling window. After those periods, raw logs and case attachments get permanently deleted. Aggregated, anonymised datasets can be kept indefinitely for product improvement and service quality analysis. All of this data lives in case management systems with role‑based access restrictions.
Safe Gaming and Self‑Exclusion Data
Once you enable self‑exclusion, your identity data must be stored permanently in a locked‑down register to stop you from opening new accounts, a measure Italian gambling regulations explicitly permit. Other safer‑gambling markers, like expired voluntary deposit limits, are deleted two years after the limit lifts. We never use self‑exclusion register data for anything other than enforcing the exclusion. The register is completely walled off from marketing and operational systems, so it serves only its protective purpose.
Frequently Asked Questions
May I request data erasure before the retention period expires?
Absolutely, you may lodge an erasure request whenever you wish. We promptly review every data category against its mandatory retention requirement. If there’s no legal hold, we delete it fast. For any data we are required to retain, we limit it to storage‑only, inform you of the legal reason preventing immediate removal, and provide the anticipated deletion date. You can also view all your data categories with their scheduled deletion dates through your account dashboard. This partial method honors your rights to the extent permitted by Italian regulations.
What occurs with my data when I opt for permanent self‑exclusion?
When you register for permanent self‑exclusion, your identity data moves to a dedicated exclusion register that stays live indefinitely with tightly controlled access. It is a legal obligation intended to block you from establishing new accounts. Your gameplay and transaction history, on the other hand, still follow the standard retention schedules and get deleted once those periods run out. The self‑exclusion entry is isolated from all marketing and operational systems, thus it fulfills solely the protective purpose for which it was gathered. You will not receive any promotional messages.
How is data from dormant accounts managed?
An account is deemed inactive following twelve consecutive months without a login. At that point, we automatically switch off marketing communications and move the account to a dormant state with reduced processing. The underlying retention clocks keep ticking based on the original collection dates, not the inactivity date. This implies that data from a dormant account is still retained for the complete legal period relevant to its category and subsequently erased following our standard protocols. Should you return after an extended absence, you may be required to undergo a new Know Your Customer verification to reactivate. Your data dashboard displays the current status continuously.
Legal Basis for Information Storage
Our data management policy relies on several legal duties that apply to gambling operators targeting the Italian market. Anti‑money laundering regulations from the Italian Financial Intelligence Unit force us to keep activity logs, identity verification documents and suspicious activity reports for a set period after the business relationship ends. Meanwhile, tax rules imposed by the Agenzia delle Entrate demand we preserve financial records that back up taxable gaming revenue and player winnings. These duties override any general right to erasure during the mandatory period. For operational data that falls outside a fixed legal window, we base our approach on legitimate interest assessments where a valid reason exists, and we offer an opt‑out unless a compelling legal obligation overrides it.
Retention Based on Consent
Marketing preferences, newsletter sign‑ups and the behavioural analytics employed for personalised offers are kept only with your explicit consent. You can withdraw consent anytime through your account dashboard; once you do, we halt that processing immediately and delete the connected profiles within thirty days. Data processed lawfully before withdrawal gets isolated from active systems to block further use, but it is not removed retroactively. Consent records themselves are kept for six years as proof of compliance. We do not use this data for anything beyond the activity you agreed to.