As a regulated operator in Italy, we gather and look after personal and transactional data under strict legal obligations it-richroyal.it. This policy outlines exactly how long we hold different categories of information, the legal reasons behind those periods, and the security measures that safeguard your data at every stage. We constantly balance our duty to retain records for fraud prevention and financial audits with the privacy rights you maintain under Italian data protection law and the GDPR. Our schedules undergo regular reviews so we stay fully compliant.
Data Subject Rights and Retention Interactions
When you send an erasure request, our system automatically examines each data category against its retention schedule. Everything beyond its mandatory window is erased without delay. For data still subject to a legal retention obligation, we secure it right away so it’s removed from active use and held only for compliance storage; we notify you which specific law is relevant and the date deletion becomes possible. Access requests are answered within thirty days and include a breakdown of what we hold, why, and the scheduled deletion date. If you dispute accuracy, we append a note instead of altering the original record, so the audit trail is preserved. Portability requests are processed in a structured, machine‑readable format even while data is still in its retention window.
Data Transfers Abroad and Retention
Our primary infrastructure resides inside Italy and the wider European Economic Area. Some supporting services, like fraud detection platforms and customer relationship tools, may pass certain personal data to countries external to the EEA. In those cases, we make sure an adequacy decision is in place or we put Standard Contractual Clauses in place together with a transfer impact assessment. The retention periods we apply to transferred data reflect those in this policy, and processors are contractually bound to delete or return data when the service ends. We publish a public register of sub‑processors, updated within fourteen days of any change, and we prefer vendors with Italian data centres. Geo‑fencing rules maintain Italian user data inside European boundaries, verified through yearly audits.
Information Erasure Procedures
When a information type hits the end of its designated storage time, our automatic lifecycle system kicks off a safe removal process. First, the data gets digitally detached from production databases. Next, physical storage blocks are replaced with random data patterns to hinder forensic recovery. Finally, a cryptographically timestamped entry lands in a audit trail, giving traceable confirmation that purging happened on time. Backup copies refresh every ninety days, so any deleted data disappears from all media within three months. When a litigation hold applies, we suspend the deletion workflow only for the affected records, record the hold reason, and restart once the hold lifts.
Data Safeguarding During Preservation
Retained data is protected with AES‑256 encryption at rest, TLS 1.3 protocols in transit and isolated virtual private clouds. Access demands multi‑factor authentication plus just‑in‑time privilege elevation that ends on its own. Every access event is logged into an immutable audit trail. We run quarterly penetration tests through CREST‑certified firms and continuous vulnerability scans to maintain our storage tight. Backups are encrypted and spread across Italian data centres, with strict controls that block accidental restoration of data past its deletion date. A dedicated lifecycle dashboard flags every dataset as it nears expiration.
Permission Management and Staff Training
Only employees whose roles demonstrably necessitate access to retained personal data get permissions, and those permissions go through monthly recertification audits. Any access to dormant user records triggers a managerial review within one business day. Every staff member who handles personal data completes mandatory annual training on Italian data protection law and our internal retention policies, including hands‑on exercises on spotting valid erasure requests and differentiating the difference between data we must keep under a legal hold and data we can delete straight away.
Affiliate Program Data Retention
Affiliate partnership data, including contact details, payout data and commission payout records, is kept for the entirety of the active relationship plus ten years after the partnership concludes. That stems from tax requirements on commission transactions, which require long‑term financial archives. Affiliate performance statistics and aggregated player referral data get anonymized after five years. We firmly disallow affiliates from independently collecting or keeping personal information about referred users; they obtain only anonymised, consolidated summaries. Our affiliate agreements include audit rights to ensure compliance, and any infringement is cause for instant agreement cancellation and payout forfeiture.
Legal Grounds for Data Retention
Our data management policy relies on several regulatory requirements that affect gambling operators targeting the Italian market. Anti‑money laundering regulations from the Italian Financial Intelligence Unit force us to keep activity logs, identity verification documents and suspicious activity reports for a fixed term after the business relationship ends. Meanwhile, tax rules enforced by the Agenzia delle Entrate oblige us to preserve financial records that substantiate taxable gaming revenue and player winnings. These obligations override any general right to erasure during the mandatory period. For operational data that doesn’t fall under a fixed legal window, we rely on legitimate interest assessments where a valid reason exists, and https://www.fanpage.it/attualita/estrazioni-lotto-e-superenalotto-oggi-sabato-18-febbraio-2023-numeri-vincenti-e-quote/ we allow an opt‑out unless a compelling legal obligation overrides it.
Retention Based on Consent
Marketing preferences, newsletter sign‑ups and the behavioural analytics utilised for personalised offers are kept only with your explicit consent. You can revoke consent anytime through your account dashboard; once you do, we stop that processing immediately and delete the connected profiles within thirty days. Data processed lawfully before withdrawal gets isolated from active systems to block further use, but it isn’t retroactively deleted. Consent records themselves are kept for six years as proof of compliance. We never use this data for anything beyond the activity you agreed to.
Information Categories and Retention Periods
We organize all user data into distinct categories, each linked to a retention schedule that corresponds to its purpose and legal context. That organized approach keeps us from keeping things forever. Every year our Data Protection Officer reviews these categories and adjusts the timelines whenever new guidance arrives from the Garante per la protezione dei dati personali. Below you’ll view how long each data type remains in our live systems before being securely anonymized or deleted. Archived backups roll on a ninety‑day cycle because of technical constraints.
Personal and Financial Records
Identity documents you submit during Know Your Customer checks, like passport scans, utility bills and tax ID numbers, stay on file for ten years after you end your account, as anti‑money laundering law stipulates. Deposit and withdrawal logs, payment method tokens and wallet balance histories are retained for ten years from the date of each transaction, fulfilling both AML requirements and Italian Civil Code limitation periods. We store these records in encrypted, access‑restricted vaults and tamper‑proof ledgers. Once the retention deadline elapses, we remove all personal identifiers permanently; statistical trends may still be used but never in a way that traces to any individual.
Account Actions and Support Communications
In-depth reports of game sessions, bets placed, outcomes and session lengths are kept for five years after each gaming event, matching the statute of limitations for civil disputes. Customer service transcripts, email threads and call recordings stay for three years from your last interaction, covering the typical complaint‑handling window. After those periods, raw logs and case attachments get permanently deleted. Aggregated, anonymised datasets can be kept indefinitely for product improvement and service quality analysis. All of this data lives in case management systems with role‑based access restrictions.
Safe Gaming and Self‑Exclusion Data
Once you enable self‑exclusion, your identity data must be stored permanently in a locked‑down register to stop you from opening new accounts, a measure Italian gambling regulations explicitly permit. Other safer‑gambling markers, like expired voluntary deposit limits, are deleted two years after the limit lifts. We never use self‑exclusion register data for anything other than enforcing the exclusion. The register is completely walled off from marketing and operational systems, so it serves only its protective purpose.
Policy Updates and Player Notification
We review this Data Retention Policy every six months and whenever a major legal change hits Italian gambling operations. Minor clarifications are published silently with a revised effective date. Material changes that modify retention periods, introduce new data categories or alter the legal basis for processing are communicated directly to you by email at least thirty days before they come into force. You’ll also see an in‑platform banner notification when you log in during the notice period. Historical versions are kept and available on request, each with a version number and a validity date range. If an earlier version provided a shorter retention period for certain data, we follow that promise for data collected under that version and apply new terms only going forward.
Popular Queries
Can I request deletion of my data before the retention period ends?
Certainly, you can submit a deletion request at any moment. We promptly review every data category against its mandatory retention requirement. When no legal hold exists, we remove it quickly. For anything we must keep, we restrict it to storage‑only, tell you the legal basis stopping immediate deletion and give you the expected deletion date. You can also view all your data categories with their scheduled deletion dates through your account dashboard. This partial method honors your rights to the extent permitted by Italian regulations.
How is my data handled if I choose permanent self‑exclusion?
Upon enrolling in permanent self‑exclusion, your identity information is transferred to a specialized exclusion register that remains active indefinitely under strictly controlled access. This is a legal mandate designed to stop you from creating new accounts. Conversely, your gameplay and transaction records continue to adhere to the usual retention timelines and are erased when those durations expire. The self‑exclusion entry is isolated from all marketing and operational systems, thus it fulfills solely the protective purpose for which it was gathered. You will not receive any promotional messages.
How do you handle data belonging to inactive accounts?
An account becomes inactive after twelve straight months with no login. At that point, we automatically switch off marketing communications and move the account to a dormant state with reduced processing. The fundamental retention timelines continue based on the initial collection dates, not the inactivity date. Consequently, data from an inactive account is kept for the entire statutory duration applicable to its type and then removed in line with our usual processes. If you come back after a long break, you might need to complete a fresh Know Your Customer check to reactivate. Your data dashboard displays the current status continuously.
