Privacy Policy

Last Updated: January 19, 2026

1. Introduction and Scope

This Privacy Policy describes how your Personal Data is collected, used, stored, disclosed, and protected when you access the Website and use its related services.

The Website is owned and operated by Carlitta N.V., with its registered office located at Zuikertuintjeweg Z/N (Zuikertuin Tower), Willemstad, Curacao. Company registration number: 162777. The Company is licensed by the Curaçao Gaming Control Board since 24/Jun/2025 to provide services under license OGL/2024/1516/0841 and the National Ordinance on Games of Chance (LOK).

This Policy applies to the collection, use, and processing of your Personal Data through:

  • our Website;
  • email communications: [email protected];
  • telephone calls and live chat support sessions.

We act as the controller of your Personal Data. The purpose of this Policy is to explain what data we process, for what purposes, on what legal grounds, how long it is stored, to whom it may be transferred, what rights you have regarding your data, and how you can exercise them.

2. Terms and Interpretation

Words beginning with a capital letter have the meanings defined in this Policy. These meanings apply regardless of whether the corresponding terms are used in the singular or plural.

2.1. Account

A unique account created to access our Services or specific parts thereof, subject to identity verification and Regulatory Compliance requirements.

2.2. Company

The Company, as well as the words “we”, “us”, or “our”, refers to Carlitta N.V., a company registered in accordance with the laws of Curaçao, with registration number 162777 and official address: Zuikertuintjeweg Z/N (Zuikertuin Tower), Willemstad, Curacao.

2.3. Service

The Website, its functionalities, as well as related online and interactive services provided by the Company.

2.4. Website

The Website, including any subdomains, associated platforms, or applications operated by the Company.

2.5. Personal Data

Any information relating to an identified or identifiable natural person, as defined in accordance with the General Data Protection Regulation (GDPR) and the applicable data protection framework of Curaçao.

2.6. Processing of Personal Data

Any operation or set of operations performed on Personal Data by automated or manual means, including, but not limited to: collection, recording, organization, structuring, storage, alteration, retrieval, viewing, use, disclosure by transmission, dissemination, alignment, restriction, erasure, or destruction.

2.7. Regulatory Compliance

The legal obligation of the Company to process Personal Data in accordance with applicable laws, including the National Ordinance on Games of Chance (LOK) and Anti-Money Laundering (AML) regulations. Such processing is carried out based on legal requirements and does not depend on user consent.

3. What Data We Process, for What Purposes, and on What Grounds

To ensure transparency, the main processing purposes, legal grounds, categories of Personal Data used, and applicable processing contexts are listed below.

3.1. Account Registration and Access to Services

  • Purpose of processing: creating an Account and providing access to the Services.
  • Legal basis: performance of a contract or steps taken prior to entering into a contract, in accordance with Article 6(1)(b) of the GDPR.
  • Data used: contact details, including email and/or phone; hashed password; selected currency; account identifiers; basic device data and access logs used to activate and protect the account.

3.2. Identity Verification, Age Verification, and AML / LOK Compliance

  • Purpose of processing: fulfillment of KYC requirements, age verification, compliance with AML/CFT, LOK, and NORUT.
  • Legal basis: compliance with legal obligations, including AML/CFT, LOK, NORUT (The National Ordinance on the Reporting of Unusual Transactions), in accordance with Article 6(1)(c) of the GDPR; legitimate interests in ensuring the integrity of the platform under Article 6(1)(f) of the GDPR, where applicable.
  • Data used: government-issued identification document, including a passport, ID card, or driver’s license; proof of address; date of birth or proof of age; selfie or liveness checks.

3.3. Payment Processing, Deposits, Withdrawals, and Refunds

  • Purpose of processing: executing payment operations, including deposits, withdrawals, and refunds.
  • Legal basis: performance of a contract under Article 6(1)(b) of the GDPR; legal obligation to maintain financial records and comply with AML under Article 6(1)(c) of the GDPR; legitimate interests in fraud prevention under Article 6(1)(f) of the GDPR.
  • Data used: payment instrument details; transaction history; currency; confirmation of payout channels.

3.4. Fraud Detection, Security Monitoring, and Abuse Prevention

  • Purpose of processing: protecting the Service, users, and infrastructure from fraudulent, unauthorized, or malicious activity.
  • Legal basis: legitimate interests in ensuring the security of the Service and users under Article 6(1)(f) of the GDPR; legal obligations within the AML/CTF framework under Article 6(1)(c) of the GDPR.
  • Data used: technical identifiers and device data, including IP address, device type, and browser data.

3.5. Responsible Gaming, User Protection, and Self-Exclusion Management

  • Purpose of processing: compliance with LOK / CGA Responsible Gaming requirements, user protection, and access restriction management.
  • Legal basis: compliance with LOK / CGA Responsible Gaming requirements under Article 6(1)(c) of the GDPR; legitimate interests in user well-being and Regulatory Compliance under Article 6(1)(f) of the GDPR.
  • Data used: self-exclusion status and duration; selected cool-off periods; limits; activity frequency; spending metrics indicating risk; communications related to responsible use of the Service.

3.6. Customer Support and Service Communications

  • Purpose of processing: processing user requests, providing answers, and resolving disputes.
  • Legal basis: performance of a contract when responding to service requests under Article 6(1)(b) of the GDPR; legitimate interests in quality of service and dispute resolution under Article 6(1)(f) of the GDPR.
  • Data used: support requests; chat transcripts; email correspondence; call notes; account identifiers; transaction links related to the request.

3.7. Marketing Communications, Where Permitted

  • Purpose of processing: sending legally permitted marketing messages and managing user preferences.
  • Legal basis: consent under Article 6(1)(a) of the GDPR for electronic marketing; legitimate interests under Article 6(1)(f) of the GDPR for soft opt-in regarding similar products, where permitted by law. Such processing is always subject to the right to opt-out and restrictions related to the responsible use of the Service.
  • Data used: contact details, including email, phone number, or push token; marketing preferences; interaction metrics; bonus eligibility status not related to sensitive data.

3.8. Website Performance, Analytics, and Cookies

  • Purpose of processing: ensuring the operation of the Website, improving its functionality, and analyzing usage.
  • Legal basis: legitimate interests in operating and improving the website under Article 6(1)(f) of the GDPR; consent under Article 6(1)(a) of the GDPR when required for non-essential cookies.
  • Data used: usage logs; cookie identifiers; browser type and version; traffic data; interaction metrics on the website.

3.9. Regulatory Reporting, Audits, and Dispute Resolution

  • Purpose of processing: cooperation with competent authorities, fulfillment of reporting obligations, audits, and legal protection.
  • Legal basis: legal obligation under Article 6(1)(c) of the GDPR within the framework of interaction with CGA, FIU, tax, and other authorities; legitimate interests in establishing, exercising, or defending legal claims under Article 6(1)(f) of the GDPR.
  • Data used: records necessary for regulatory interaction, compliance reviews, or judicial and other legal procedures, to the extent permitted by applicable law.

4. Data Retention Periods

We store your Personal Data only for the period necessary to achieve the purposes for which it was collected and processed, or for the duration required by applicable legal and regulatory obligations.

The retention period for each category of data is determined taking into account:

  • the purpose of processing, including the provision of Services, fulfillment of contractual obligations, or protection of our legitimate interests;
  • applicable mandatory retention periods, including AML requirements, regulations of the relevant services, and tax laws;
  • the need to establish, exercise, or defend legal claims, as well as to fulfill auditing and supervisory requirements.

Upon expiration of the relevant retention period, your Personal Data is securely deleted, anonymized, or archived in such a way that it can no longer be associated with you, unless further retention is required by law.

5. Sources of Personal Data

We obtain your Personal Data primarily from you when you interact with our Services, including registering an Account, passing identity verification, processing payments, and using the Website.

In addition, Personal Data may come from the following sources.

5.1. Directly from You

Information you provide when creating an Account, completing verification stages, making deposits or withdrawing funds, as well as when contacting support.

5.2. As a Result of Using the Services

Data generated during your activity on the platform, including activity history, transactions, technical logs, device data, and cookies in accordance with the cookies section of this Policy.

5.3. From Third-Party Verification and Compliance Services

We may use trusted third parties to support specific aspects of our operations, including compliance, security, and payment-related functions.

5.4. From Publicly Available and Legitimate Sources

When necessary, we may supplement the information provided by you with data from publicly available and legitimate sources solely for compliance, verification, or risk management purposes.

5.5. From Regulatory and Law Enforcement Authorities

In certain cases, we may receive data from competent authorities in connection with our legal and compliance obligations.

6. Data Storage and International Transfers

We store your Personal Data on secure servers operated by us and our trusted service providers. Such servers may be located both within the European Economic Area (EEA) and in jurisdictions outside the EEA, including Curaçao, depending on operational and regulatory requirements.

If Personal Data is transferred outside the EEA, we ensure that such transfers comply with applicable data protection legislation and apply appropriate safeguards, including:

  • Adequacy Decisions: transferring data to countries recognized by the European Commission as providing an adequate level of data protection;
  • Standard Contractual Clauses (SCCs): using standard contractual clauses approved by the European Commission if an adequacy decision is absent.

7. To Whom We May Transfer Your Personal Data

We may transfer your Personal Data only when necessary and consistent with the purposes specified in this Policy. Transfers are carried out in compliance with applicable data protection legislation, contractual obligations, and security measures.

Your Personal Data may be transferred to the following categories of recipients.

7.1. Regulatory and Supervisory Authorities

Such authorities include the Curaçao Gaming Authority (CGA), the Financial Intelligence Unit (FIU), tax authorities, as well as other government or law enforcement agencies, if required by law and regulatory obligations, including AML and responsible gaming requirements.

7.2. Identity Verification and Compliance Service Providers

Such providers help us verify user identity and fulfill AML and Know Your Customer (KYC) obligations.

7.3. Payment Processors and Financial Institutions

To facilitate deposits, withdrawals, and other payment services, we may transfer Personal Data, including transaction details, payment method details, and account identifiers.

7.4. Customer Support and Communication Tools

External service providers that ensure the delivery of emails, live chat, or other communication channels may process Personal Data, such as contact details and support messages, to facilitate customer service delivery.

7.5. Fraud Prevention and Security Partners

We may engage trusted providers to help protect the security and integrity of the platform, including detecting and preventing potentially fraudulent or unauthorized activity.

7.6. Analytics and Optimization Platforms

Third-party services may help us analyze Website usage, conduct A/B testing, and improve user experience. Where possible, such data is anonymized or pseudonymized.

7.7. Content Providers

Licensed third-party content providers may provide specific platform features. We transfer only the minimum amount of data required for the respective session, such as user identifiers and session data.

7.8. Internal Tools and IT Infrastructure Providers

We use secure hosting and production solutions to store and manage data necessary for the operation of the Services.

8. Cookies and Similar Technologies

The Website may use cookies and similar technologies to improve user experience, ensure basic site functions, and analyze performance.

Cookies are small text files that are saved on your device when you visit the Website. They allow the Website to recognize the device and store certain information about your preferences or past actions.

8.1. Strictly Necessary Cookies

These cookies are necessary for the Website to function and cannot be switched off in our systems. They provide basic functionality, including page navigation, access to secure areas, and user authentication.

8.2. Functional Cookies

These cookies support enhanced functions and personalization, such as remembering language preferences or user settings. They may be set by us or by third-party providers whose services we use.

8.3. Analytical or Performance Cookies

These cookies collect aggregated and anonymized data on how visitors use the Website, such as page visits, click rates, and traffic sources. Their purpose is to measure and improve Website performance.

8.4. Advertising or Targeting Cookies

These cookies may be set through our site by us or our advertising partners to build a profile of your interests and show you relevant adverts on our Website or other sites. They may also help limit the frequency of showing an advertisement and evaluate its effectiveness.

8.5. Session and Persistent Cookies

Some cookies are session cookies and are deleted after closing the browser. Others are persistent cookies and remain on the device for a predetermined period or until you delete them.

8.6. First-Party and Third-Party Cookies

Cookies on the Website may be set by us as first-party cookies or by third-party service providers acting on our behalf as third-party cookies. These may include providers of analytics, support tools, or advertising networks.

8.7. Managing Cookies

You can control and manage cookies through your browser settings. Most browsers allow you to refuse or delete cookies. However, restricting certain cookies may affect the availability or functionality of some parts of the Website.

9. Protection of Minors

In accordance with the Responsible Gaming Policy of the Curaçao Gaming Authority, introduced in February 2025, we have implemented strict measures aimed at preventing minors from accessing our Services.

9.1. Age Restrictions and Confirmation

Our Services are intended exclusively for individuals who are at least 18 years old, or the legal age established in the respective jurisdiction of the user, if such age is higher.

By accessing or registering for the Services, you confirm that you meet this age requirement.

9.2. Age Verification Mechanisms

To effectively enforce age restrictions, we apply verification mechanisms, including:

  • document verification: users are required to provide valid, government-issued identification documents as part of the registration process.

9.3. Preventative Measures and Security Checks

In addition to age verification, we apply measures aimed at enforcing the age policy:

  • automated monitoring: continuous monitoring of user activity to identify discrepancies or signs of minor access attempts;
  • security checks: conducting thorough checks when minor access is suspected, including verification of registration data and financial transactions;
  • data deletion: immediate deletion of Personal Data provided by individuals identified as minors.

9.4. Parental Control and Awareness

We recommend that parents and legal guardians use available parental control tools and inform minors about responsible online behavior to prevent unauthorized access to our Services.

9.5. Responsible Gaming Obligations

Our approach includes compliance with CGA guidelines regarding user protection and age verification. We regularly review and improve our policies to meet or exceed regulatory standards.

By using our Services, you acknowledge agreement with these terms, confirm compliance with legal age requirements, and understand our approach to responsible use of the Service.

10. Your Rights Regarding Personal Data

In accordance with the General Data Protection Regulation (GDPR), you possess the following rights regarding your Personal Data.

10.1. Right of Access — Article 15 GDPR

You can request confirmation as to whether we are processing your Personal Data, obtain a copy of such data, as well as information on how it is used.

10.2. Right to Rectification — Article 16 GDPR

You can request the correction of inaccurate or incomplete Personal Data without undue delay.

10.3. Right to Erasure — Right to be Forgotten, Article 17 GDPR

You can request the deletion of your Personal Data if there are appropriate legal grounds, for example, if the data is no longer necessary for the purposes for which it was collected, or if you withdraw consent where the processing is based on consent.

10.4. Right to Restriction of Processing — Article 18 GDPR

You can request the restriction of processing of your Personal Data in certain situations, for example, if the accuracy of the data is contested or the processing is unlawful.

10.5. Right to Data Portability — Article 20 GDPR

You can request a copy of the Personal Data you provided to us in a structured, commonly used, and machine-readable format and transmit such data to another controller, where technically feasible.

10.6. Right to Object — Article 21 GDPR

You can object at any time to the processing of your Personal Data for reasons related to your particular situation, if the processing is based on our legitimate interests or is carried out for direct marketing purposes.

11. How to Exercise Your Rights

If you wish to realize any of your data protection rights, you can contact us:

  • by email: [email protected];
  • by postal address: Zuikertuintjeweg Z/N (Zuikertuin Tower), Willemstad, Curacao.

12. Withdrawal of Consent

If we process your Personal Data based on your consent, you have the right to withdraw such consent at any time.

The withdrawal of consent does not affect the lawfulness of processing carried out based on consent before its withdrawal.

To withdraw consent, please contact us through the channels specified in this Policy. Upon receiving your request, we will stop processing your Personal Data unless further retention is required to comply with legal or regulatory obligations.

If the withdrawal of consent affects our ability to provide specific Services, we will inform you of the consequences before the withdrawal process is completed.

13. Complaints

In accordance with Article 77 of the GDPR, if you believe that your Personal Data is being processed unlawfully or your privacy rights have been violated, you have the right to lodge a complaint:

  • with a supervisory authority of the EU member state where you reside, work, or where the alleged infringement occurred;
  • with the Curaçao Gaming Authority (CGA) or another relevant data protection authority in Curaçao.

If you have questions or unresolved concerns regarding the processing of your Personal Data, we recommend contacting us directly first. We will make all reasonable efforts to address your requests in a timely manner and in accordance with the law.

14. Provision of Personal Data and Consequences of Failure to Provide It

The provision of Personal Data can be:

  • a legal requirement: certain data must be provided to comply with applicable laws and regulations, including AML obligations and responsible gaming requirements;
  • a contractual requirement: some data is necessary to enter into and perform a contract with you, including providing access to the Services and processing transactions;
  • a condition for access to the Services: without providing the necessary Personal Data, we may be unable to provide specific Services or fulfill contractual or legal obligations.

14.1. Obligation to Provide Data

You are obliged to provide Personal Data if required by law or necessary for the performance of a contract. Failure to provide such data may lead to:

  • the inability to create or maintain an Account;
  • restrictions on using the Services;
  • termination of contractual relations;
  • the inability to fulfill regulatory obligations, which may prevent the provision of the Services.

15. Legal Notice

Our Services are provided on an “AS-IS” and “AS-AVAILABLE” basis, without any warranties of uninterrupted or error-free operation.

While we take reasonable precautions to protect your Personal Data, we cannot guarantee absolute security due to the complexity of technology and constantly evolving cyber threats.

15.1. Limitation of Liability

To the maximum extent permitted by law, we are not liable for:

  • events beyond our direct control, including, but not limited to, system failures, cyberattacks, or unauthorized access;
  • indirect, incidental, consequential, or punitive damages arising in connection with data breaches, unauthorized disclosure, or misuse of Personal Data;
  • errors, inaccuracies, or security vulnerabilities on third-party websites, links to which may be posted on our platform.

By using our Services, you acknowledge and agree that we are not responsible for external websites or services operated by third parties, even if links to them are posted on our platform.

16. Acceptance of the Privacy Policy

Continued use of our Services signifies your explicit acceptance of this Privacy Policy.

This document constitutes the entire and exclusive Privacy Policy and supersedes any previous versions.

The Privacy Policy should be read in conjunction with our Terms and Conditions and any additional applicable notices posted on the platform.

We reserve the right to modify this Policy at any time. Any changes will be posted on the platform, and continued use of the Services after changes are made signifies acceptance of the updated Policy.

We strongly recommend regularly reviewing this Policy to stay informed of updates.

17. Miscellaneous

All versions of this Policy other than the English version are provided solely for informational purposes.

In the event of any discrepancies or contradictions between different versions, the English version shall prevail.