Customer Privacy Notice
The data controller is Olympic Entertainment Group AS (registry code 14437516, Pronksi 19 10124 Tallinn, hereinafter “OEG”, will process your personal data in compliance with the EU General Data Protection Regulation 2016/679 (GDPR).
OEG respects your privacy and is committed to protecting personally identifiable information you may provide us. OEG has adopted this privacy notice (“Privacy Notice“) to explain what information may be collected, how OEG uses this information, and under what circumstances OEG may disclose the information to third parties.
The Data Protection Officer can be reached by email at DataProtectionOfficerEstonia@oc.eu.
- Data processing principles
The data shall be processed and collected:
- lawfully, fairly and in a transparent manner;
- for specified, explicit and legitimate purposes;
- adequate, relevant and limited to what is necessary in relation to the purposes for which they are processed;
- accurate and, where necessary, kept up to date. OEG shall take every reasonable step to ensure that personal data that are inaccurate, having regard to the purposes for which they are processed, are erased or rectified without delay.
- kept in a form which permits identification for no longer than is necessary for the purposes for which the personal data are processed;
- processed in a manner that ensures appropriate security of the personal data, including protection against unauthorized or unlawful processing and against accidental loss, destruction or damage, using appropriate technical or organizational measures.
- Legal basis
OEG processes your personal data on the following legal basis:
- Fulfilling OEG’s legal obligations;
- Performance of a contract between you and OEG;
- Your consent;
- OEG’s legitimate interest.
Please note that if OEG is processing your personal data on the basis of legitimate interest then this means that OEG has determined that its legitimate interest for processing your personal data for certain purposes outweighs your interest and rights to protect your personal data.
- Processing purposes
OEG processes your personal data for the purposes of offering you our services and to comply with our legal obligations, as well as monitoring and improving the use of our services.
- Data subjects
The data subjects are all customers who visit and use the services of Olybet Bar&Grill.
- Data categories
OEG, collects, uses and stores the following customer data:
- Registration Data – first name, last name, personal identification code, title, date of birth, gender, PEP status, personal identity document data;
- Contact and Marketing Data – email address, telephone numbers, preferred language, residential address;
- Club Rewards Card data – first name, last name, occupation, preferred language, game, deposit amount, bet amount, payout amount, balance, tier level, rewards points balance, rewards point transactions, tier points balance, playing time;
- Payment data – first name, last name, bank account number, alimony debt data, SWIFT code, bank, date, transfer amount, description of transfer;
- Other data obtained by other processes during your use of our services, which can be used for the exercise, compiling and defence of legal claims and requested by the Law and Gaming Regulators.
Registration Data shall only be processed if you place bets using the betting machines.
Club Rewards Card data shall only be processed if you sign up for the Club Rewards card and use it to place bets. Club Rewards Card data is used to offer discounts to card holders.
Payment data shall only be processed if either the deposit or payment of winnings is done by bank transfer or credit card payment. If the deposit or payment of transfer is done in cash, then only data for payments which exceed 2000 euros shall be processed. Alimony debt data is only processed If you request payment of winnings in cash which exceeds 5000 euros.
Contact and Marketing data shall be used for marketing purposes if you have consented to receive direct marketing messages. Further information of processing such purposes shall be provided below under “Information about Processing Customers’ Personal Data for Direct Marketing and Analytics Purposes”.
If you refuse, even if on legitimate grounds, to provide us any data that we are legally obligated to collect about you, or that we require to perform our contract we cannot offer you our services or let you place bets.
We do not collect any Special Categories of Personal Data about you (this includes details about your race or ethnicity, religious or philosophical beliefs, sex life, sexual orientation, political opinions, trade union membership, information about your health, and genetic and biometric data).
- Methods of processing personal data
Processing shall be performed in an automated or semi-automated manner and includes the following operations: collection, recording, organization, profiling, retention, review, use, modification, selection, excerpting, comparison, disclosure, dissemination, erasure, blocking, or limitation. If you are using the Club Rewards card, then your personal data and gaming habits shall also be profiled in order for us to better understand our customers.
Processing shall be conducted using hard-copy or electronic instruments to ensure the security and privacy of such data.
- Data sharing, transfer and retention
In the course of data processing You data will be shared with third parties if this is necessary for the performance of obligations arising from legislation or contracts, and for the exercise of our legitimate interest in the fields of fraud prevention, provision of security as well as exercise of legal claims. If you use the Olybet Bar&Grill website, then your personal data may also be shared with Google Analytics to collect data on your use of our website so that we can improve our website.
The recipients of the data are governmental authorities and service providers, such as the mediator of the PEP check and the sanction control database, banks, legal advisors and consultants, insurance firms, national registries, archiving services, courts, bailiffs, trustees in bankruptcy, the provider of software for managing the poker tournament, the service provider for sending the e-mails and messages, the service provider for the registry of customer feedbacks, the online survey service provider, service provider for fraud prevention and detection, but only in the extent that they need the data for the provision of services to you and the Company and whilst complying with data protection laws.
In addition, OEG shares customer data with other Olympic Entertainment Group companies in the European Union. If we transfer customer data out of the EU or the EEA, then such transfer shall be subject to i) Adequacy Decision by the European Commission ii) Standard Contractual Clauses iii) other derogations as specified in the GDPR.
The data will be kept for a period of 5 years from your last visit After this period, your data will be anonymised by removing your personal data such as your name, personal code or date of birth and contact info from your user profile, so that your person is no longer identifiable in our systems.
- Your rights
- You have the right to receive information about whether the company processes their personal data and, if the company does, to obtain a copy of the data.
- You have the right to demand the amendment of inaccurate personal data.
- You have the right to withdraw your consent at any time if the data processing is based on consent. The withdrawal of consent does not affect the lawfulness of data processing prior to the withdrawal.
- You have the right to withdraw from the direct marketing data processing at any time. The withdrawal of consent does not affect the lawfulness of data processing prior to the withdrawal.
- You have the right to request the deletion of your personal data. However, the company has no absolute obligation to delete the data. The company can delete data that is processed based on consent or legitimate interest, unless the interest of the Company is outweighed by your interest. The right to erase does not apply to data processed due to legal obligations or under contract when they are in force.
- You have the right to object to the processing of your personal data, particularly if it is in your legitimate interest, and to restrict the processing of your personal data if this is justified.
- You have the right to receive your personal data, which you have provided yourself in a structured and machine-readable form (where technically possible) for the transmission to another service provider.
- You have the right to submit a complaint about the use of data to the Data Protection Inspectorate of the Republic of Estonia by sending an e-mail to firstname.lastname@example.org or by going in-person to visit Tatari 39, 10134, Tallinn
Please note that although you have the right to request certain processing activities do be done with your personal data, all such requests are subject to OEG’s legal obligations regarding the appropriate data. This means, for example, that if you request erasure of your personal data within 5 years of your last visit, OEG cannot satisfy the request as OEG has a legal obligation to retain the data for 5 years after your last visit.
OEG will respond to customer`s request and, if applicable and appropriate, make the requested change in its active databases as soon as reasonably practicable, but within 30 days from the receipt of the request.
Information about Processing Customers’ Personal Data for Direct Marketing and Analytics Purposes
The joint controllers of your personal data are Olympic Entertainment Group AS (registry code 14437516, address Pronksi tn 19, 10124 Tallinn, Estonia), who is the operator of Olympic Casino and Olybet Bar&Grill, and OB Holding 1 OÜ (registry code 14975047, address Pronksi tn 19, 10124 Tallinn, Estonia), who is the operator of OlyBet (together – we).
We use the electronic contact details provided by you to send you information and special offers on the subjects chosen by you to promote the businesses of Olympic Casino, Olybet Bar&Grill and OlyBet. The legal basis for processing your personal data is your consent (Art 6(1)(a) of the GDPR).
If you agree, the information and special offers will be personalised, i.e., sent to you based on our best understanding of your interests and behaviour. In making these offers, we may contact you based on, for example, your use of Olympic Casino and OlyBet services (e.g., if you prefer certain games in Olympic Casino, we may notify you if such games become available in OlyBet; if you have participated in certain events or offers before, offer them to you again; provide special offers to players who have staked a certain amount, etc.). The purpose is to know you better in order to incentivize you to use our services. In doing so, we use both profiling and automated decision-making. The automated decisions usually take place without human intervention. However, they do not bring about any legal effects to you or otherwise similarly significantly affect you. At worst, we may send you offers you are not interested in. The personalised offers may somewhat increase the addiction of compulsive gamblers; however, we have taken the necessary safeguards and never target any such player knowingly and strongly encourage responsible gaming. You have the right to obtain human intervention regarding the decision making, express your point of view regarding such decisions, and contest the decisions. The legal basis for processing your personal data is your consent (Art 6(1)(a) of the GDPR).
We will process your personal data for the above-mentioned purposes until you withdraw your relevant consent(s), asking you to update your preferences from time to time.
We also provide you information and special offers via phone or when you visit Olympic Casino, OlyBet or Olybet Bar&Grill. These offers are usually personalised, i.e., based on our best understanding of your interests and behaviour as explained above. The legal basis for processing your personal data is our legitimate interest to promote the businesses of Olympic Casino and OlyBet (Art 6(1)(f) of the GDPR). In such case, we have concluded that, considering the circumstances, our legitimate interest is not overridden by your interests or fundamental rights and freedoms which require protection of personal data. You have the right to object at any time to such processing by contacting us on the contact details below. In such case, your personal data will no longer be processed for direct marketing purposes.
We use the personal data you have provided us or that has been created based on your use of Olympic Casino and OlyBet services on an aggregated level for analytics, i.e., to understand our customers, their needs, and behaviour better in order to make better marketing and business decisions. For example, to understand which Olympic Casino games are popular and should also be available in OlyBet to increase its use; in which order the games should be listed to increase their popularity; which OlyBet sports events are popular and should be streamed in Olympic Casino; what are the characteristics of customers who are active either only or both online and offline; etc. Although such analytics may initially be based on some of your personal data, the data is aggregated, and no personal data is used in any reports. The legal basis for processing your personal data is our legitimate interest to make better marketing and business decisions and to promote the businesses of Olympic Casino and OlyBet (Art 6(1)(f) of the GDPR). In such case, we have concluded that, considering the circumstances, our legitimate interest is not overridden by your interests or fundamental rights and freedoms which require protection of personal data. You have the right to object, on grounds relating to your situation, at any time to such processing by contacting us on the contact details below. In that case, we will no longer process your personal data for analytics purposes unless we demonstrate compelling legitimate grounds for the processing which override your interests, rights and freedoms.
We will process your personal data for the above-mentioned purposes until you object to it and we do not have the right to continue processing or until you have an active agreement with either of us.