Logo grosvenor casino bournemouth u8nxjc
Banner grosvenor casino bournemouth 1faklr

This document explains how Grosvenor Casino Bournemouth handles your personal data.

Grosvenor Casino Bournemouth Privacy Policy

1. Introduction

This Privacy Policy describes how Grosvenor Casino Bournemouth collects, processes, stores, and shares personal data in connection with the use of its services. The policy applies to all individuals who interact with the company, including registered customers, visitors to the premises, and users of any associated digital services.

Personal data is handled in accordance with the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018. By using the services, users acknowledge that their personal data will be processed as described in this policy.

This policy may be updated from time to time. Any material changes will be communicated through appropriate channels. Users are encouraged to review this document periodically to stay informed about the handling of personal data.

2. Data Controller

Grosvenor Casino Bournemouth is the data controller in respect of personal data collected through its services and premises. As data controller, the company determines the purposes and means of processing personal data.

Queries relating to this Privacy Policy or the handling of personal data can be submitted using the contact details set out in Section 9.

3. Personal Data Collected

The following categories of personal data are collected and processed:

3.1 Identity and Contact Data

This includes full name, date of birth, residential address, email address, telephone number, and government-issued identification documents such as a passport or driving licence. Collection of this data is necessary to verify identity, confirm eligibility to use the services, and comply with legal and regulatory obligations.

3.2 Account and Transaction Data

This includes records of account activity, transaction history, and any financial information provided in connection with the use of the services. This data is processed to deliver services under the contractual relationship with the user and to comply with anti-money laundering regulations.

3.3 Responsible Gambling Data

This includes records of any self-exclusion requests, deposit limits, time-out periods, affordability assessments, and other responsible gambling measures applied to an account. Processing of this data is required to meet obligations under gambling regulation and to protect customers who may be at risk of harm.

3.4 Special Category Data

In limited circumstances, special category data such as nationality or ethnicity may be collected where required to satisfy legal or regulatory requirements. Such data is not used for any other purpose without explicit consent.

3.5 Technical and Usage Data

This includes information about the use of digital services, such as device identifiers, IP addresses, browser type, and session data. This data is used for security, fraud prevention, and service improvement purposes.

Personal data is processed only where there is a lawful basis for doing so. The legal bases relied upon are:

  • Performance of a contract: Providing services requested by the user and managing the user’s account.
  • Legal obligation: Compliance with anti-money laundering, age verification, and gambling regulation requirements.
  • Legitimate interests: Fraud prevention, security, business analytics, and responsible gambling monitoring, where such interests do not override the fundamental rights and freedoms of the data subject.
  • Consent: Direct marketing communications where the user has provided explicit consent.

Where legitimate interests are relied upon, an assessment is carried out to ensure that these interests do not override the rights and freedoms of the individual.

5. Use of Personal Data

Personal data is used for the following purposes:

  • To verify identity and confirm eligibility to use the services in accordance with UK gambling law, including confirmation that the user is aged 18 or over.
  • To fulfil contractual obligations, including processing account registrations and managing the relationship with the account holder.
  • To comply with legal and regulatory requirements, including anti-money laundering checks, know-your-customer procedures, and reporting obligations to the UK Gambling Commission.
  • To monitor gambling activity and identify patterns that may indicate problem gambling or at-risk behaviour, and to apply responsible gambling interventions where appropriate.
  • To prevent and detect fraud, financial crime, and other unlawful activity.
  • To communicate with users regarding matters that require attention in connection with an account or the company’s legal and regulatory obligations.
  • To send direct marketing communications where consent has been provided or where otherwise permitted under applicable law. Consent may be withdrawn or an objection to such communications may be raised at any time.

6. Data Sharing

Personal data is not sold. Personal data may be shared with third parties only where there is a lawful basis to do so. Recipients of personal data may include:

  • Fraud prevention agencies and identity verification services, for the purpose of preventing financial crime and verifying identity.
  • Regulatory and statutory authorities, including the UK Gambling Commission, where disclosure is required by law. Requests from statutory bodies are fulfilled only where accompanied by a valid warrant, court order, or other recognised legal authority.
  • Third-party service providers who support operations, including IT infrastructure providers, data processors, and compliance service providers. These parties are required to process data only on documented instructions and under appropriate confidentiality obligations.
  • National self-exclusion schemes and responsible gambling organisations, where sharing is necessary to give effect to a self-exclusion request or to protect a customer identified as at risk.
  • Other entities within the same corporate group, where processing is necessary for internal administrative or compliance purposes.

7. Data Retention

Personal data is retained only for as long as necessary for the purposes for which it was collected, or as required by applicable law or regulation. In general, records relating to customer accounts and transactions are retained for a minimum period following the closure of an account or the end of the customer relationship, in accordance with anti-money laundering and gambling regulatory requirements.

When data is no longer required, secure deletion or anonymisation procedures are applied.

8. Your Rights

Under UK GDPR, individuals have the following rights in relation to their personal data:

  • Right to be informed: To receive clear information about how personal data is used, as set out in this policy.
  • Right of access: To submit a Subject Access Request and obtain a copy of the personal data held. A response will be provided within one calendar month of receiving a valid request.
  • Right to rectification: To request correction of any inaccurate or incomplete personal data.
  • Right to erasure: To request deletion of personal data in certain circumstances. This right is subject to limitations where retention is required by law or regulation.
  • Right to restriction: To request restriction of the processing of personal data in specific circumstances.
  • Right to object: To object to processing carried out on the basis of legitimate interests, including profiling for marketing purposes. Such processing will cease upon receipt of a valid objection unless compelling legitimate grounds for the processing can be demonstrated.
  • Right to data portability: Where processing is based on consent or contract and carried out by automated means, to request that data be provided in a structured, commonly used, and machine-readable format.
  • Right to withdraw consent: Where processing is based on consent, to withdraw that consent at any time. Withdrawal of consent does not affect the lawfulness of processing carried out before withdrawal. Withdrawal of consent in certain areas may affect the ability of the company to provide specific services.

To exercise any of these rights, contact details in Section 9 should be used. If a satisfactory response is not received, a complaint may be lodged with the Information Commissioner’s Office (ICO), the UK supervisory authority for data protection matters.

9. Contact

Questions or concerns relating to this Privacy Policy or the processing of personal data should be directed to Grosvenor Casino Bournemouth using the contact details available on the official website or by writing to the registered premises address.

Subject Access Requests or other data subject rights requests should be directed to the designated data protection contact point indicated on the website.