Privacy & Security
Information Collection
Play'n GO Malta Limited, operating the platform accessible at dragon-maiden.com under Malta Gaming Authority licence reference MGA/B2B/225/2012, acts as the data controller with respect to personal data processed in connection with the provision of its services. The following categories of personal data are subject to collection and processing:
- Identification data, including full legal name, date of birth, and government-issued identification document details, collected for the purpose of identity verification and regulatory compliance;
- Contact information, comprising residential address, electronic mail address, and telephone number, obtained in the course of account registration and ongoing correspondence;
- Financial data, including payment instrument details, transaction records, and account balance information, processed in connection with deposit, withdrawal, and gaming activity;
- Technical data, encompassing Internet Protocol address, browser type and version, device identifiers, operating system specifications, and session activity logs, automatically collected upon interaction with the platform;
- Usage and behavioural data, including gaming history, wagering patterns, session duration, and platform navigation data, recorded throughout the provision of services;
- Communications data, comprising the content and metadata of correspondence submitted by the data subject through any available communication channel;
- Verification and due diligence data, including documentation submitted in fulfilment of Know Your Customer obligations and anti-money laundering screening outcomes.
Personal data is collected directly from the data subject at the point of registration, through subsequent use of the platform, and where required by applicable law, from authorised third-party sources including identity verification service providers and regulatory databases. The provision of certain categories of personal data constitutes a contractual and regulatory requirement, and failure to supply such data may render the Company unable to establish or maintain an account on behalf of the data subject.
Use of Information
Personal data collected by Play'n GO Malta Limited is processed exclusively for specified, explicit, and legitimate purposes in accordance with the General Data Protection Regulation (EU) 2016/679 and applicable Maltese data protection legislation. The purposes for which personal data is processed are enumerated as follows:
- The establishment, maintenance, and administration of user accounts, including the execution of contractual obligations arising from the Terms and Conditions governing use of the platform;
- The fulfilment of legal and regulatory obligations imposed upon the Company as a licensee of the Malta Gaming Authority, including identity verification, age verification, responsible gaming compliance, anti-money laundering screening, and the reporting of suspicious transactions to competent authorities;
- The processing and settlement of financial transactions, including deposits and withdrawals, and the maintenance of accurate accounting records;
- The detection, investigation, and prevention of fraudulent activity, unauthorised account access, and any other conduct constituting a breach of applicable law or the Company's terms of service;
- The provision of customer support services and the management of queries, complaints, and dispute resolution procedures;
- The improvement and optimisation of platform functionality, user experience, and service delivery, on the basis of aggregated and individual usage analysis;
- The transmission of service-related communications, including account notifications, security alerts, and updates to applicable terms and policies, which are processed on the basis of contractual necessity and legal obligation;
- The transmission of direct marketing communications, where the data subject has provided express consent, and subject to the data subject's right to withdraw such consent at any time without detriment.
Personal data shall not be processed for purposes incompatible with those stated herein, nor shall it be sold, rented, or otherwise transferred to third parties for commercial purposes unrelated to the provision of services. Disclosure of personal data to third parties is limited to circumstances in which such disclosure is required by law, necessary for the performance of a contract, or carried out with the express consent of the data subject.
Data Security
Play'n GO Malta Limited has implemented a comprehensive framework of technical and organisational measures designed to ensure a level of security appropriate to the risk presented by the processing of personal data. Such measures are maintained in accordance with the requirements of Article 32 of the General Data Protection Regulation and are subject to periodic review and enhancement.
The technical measures implemented by the Company include, but are not limited to, the following:
- Encryption of personal data in transit through the application of Transport Layer Security (TLS) protocols, ensuring that data transmitted between the data subject's device and the Company's servers is rendered unintelligible to unauthorised third parties;
- Encryption of personal data at rest, applied to sensitive data categories stored within the Company's systems and databases;
- Implementation of access control mechanisms, including role-based access restrictions, multi-factor authentication requirements, and the application of the principle of least privilege, ensuring that personal data is accessible only to authorised personnel whose functions necessitate such access;
- Deployment of firewalls, intrusion detection and prevention systems, and continuous network monitoring to detect and respond to potential security incidents in a timely manner;
- Regular security assessments, penetration testing, and vulnerability scanning conducted by qualified internal and external parties;
- Maintenance of data backup and recovery procedures to ensure the continued availability and integrity of personal data.
The organisational measures maintained by the Company include the implementation of internal data protection policies, the designation of a Data Protection Officer responsible for overseeing compliance with applicable data protection legislation, mandatory data protection training for all personnel engaged in the processing of personal data, and the maintenance of records of processing activities as required by Article 30 of the General Data Protection Regulation. Contractual arrangements with third-party processors are governed by data processing agreements incorporating appropriate security obligations. Notwithstanding the foregoing measures, the Company acknowledges that no system of transmission or storage over the Internet can be guaranteed to be entirely secure, and data subjects are encouraged to exercise appropriate caution in the protection of their account credentials.
Your Rights
In accordance with the provisions of the General Data Protection Regulation and applicable national data protection legislation, data subjects whose personal data is processed by Play'n GO Malta Limited are afforded the following rights, each of which may be exercised by submitting a written request to the contact details specified below:
- Right of Access: The data subject is entitled to obtain confirmation as to whether personal data relating to them is being processed, and where such processing is confirmed, to receive a copy of the personal data concerned together with information regarding the purposes, categories, recipients, retention periods, and applicable safeguards associated with such processing, in accordance with Article 15 of the General Data Protection Regulation;
- Right to Rectification: The data subject is entitled to require the correction of inaccurate personal data and the completion of incomplete personal data relating to them, without undue delay, in accordance with Article 16 of the General Data Protection Regulation;
- Right to Erasure: The data subject is entitled, in circumstances prescribed by Article 17 of the General Data Protection Regulation, to require the deletion of personal data relating to them, including where such data is no longer necessary for the purposes for which it was collected, where consent has been withdrawn and no other legal basis exists, or where the data has been unlawfully processed. This right is subject to applicable legal obligations requiring the retention of certain data for specified periods;
- Right to Restriction of Processing: The data subject is entitled, in circumstances prescribed by Article 18 of the General Data Protection Regulation, to require that the processing of their personal data be restricted, including where the accuracy of the data is contested or where an objection to processing has been submitted pending verification of the applicable legal basis;
- Right to Data Portability: Where processing is carried out on the basis of consent or contractual necessity and by automated means, the data subject is entitled to receive personal data relating to them in a structured, commonly used, and machine-readable format, and to request that such data be transmitted directly to another controller where technically feasible, in accordance with Article 20 of the General Data Protection Regulation;
- Right to Object: The data subject is entitled to object, on grounds relating to their particular situation, to the processing of personal data relating to them where such processing is based on the legitimate interests of the controller or carried out for direct marketing purposes, in accordance with Article 21 of the General Data Protection Regulation;
- Right to Withdraw Consent: Where processing is based upon the consent of the data subject, such consent may be withdrawn at any time without affecting the lawfulness of processing carried out prior to withdrawal.
Requests submitted in exercise of the foregoing rights will be responded to within one calendar month of receipt, subject to extension by a further two months where the complexity or volume of requests so requires, in which case the data subject will be notified accordingly. The Company reserves the right to verify the identity of the requesting party prior to processing any such request. Data subjects who consider that the processing of their personal data infringes applicable data protection legislation