Data Protection & Privacy
Information Collection
The following categories of personal data are collected and processed by RubyPlay in connection with the operation of the dragoness-slot.com platform, which is licensed and regulated by the Malta Gaming Authority under licence reference MGA/B2B/826/2020:
- Identification Data: Full legal name, date of birth, nationality, and government-issued identification document details are collected for the purposes of identity verification and compliance with applicable regulatory obligations.
- Contact Data: Electronic mail address, postal address, and telephone number are obtained at the time of account registration and may be updated upon request by the data subject.
- Financial Data: Payment instrument details, transaction records, deposit and withdrawal histories, and associated banking information are processed in accordance with anti-money laundering obligations and applicable financial regulations.
- Technical Data: Internet Protocol addresses, browser type and version, device identifiers, operating system information, session duration, and navigational data generated during interaction with the platform are recorded automatically through standard web technologies.
- Behavioural Data: Gaming activity records, wagering patterns, session histories, and preference data are accumulated in the course of platform usage and are retained in accordance with regulatory data retention requirements.
- Verification Data: Documentation submitted in support of Know Your Customer procedures, including copies of identity documents, proof of address, and source of funds declarations, are processed as mandated by applicable anti-money laundering legislation.
- Communication Data: Records of correspondence initiated by or directed to the data subject, including customer support interactions, are retained for quality assurance and compliance purposes.
Personal data is collected directly from the data subject at the point of registration and during the course of continued platform engagement. In certain circumstances, data may be obtained from third-party identity verification service providers, fraud prevention agencies, and regulatory bodies, where such collection is authorised or required by law.
How We Use Data
Personal data collected in connection with the operation of dragoness-slot.com is processed exclusively for specified, explicit, and legitimate purposes. The following descriptions set forth the lawful bases and operational purposes upon which data processing activities are founded:
- Account Administration: Personal data is processed for the purpose of establishing, maintaining, and managing user accounts on the platform. This includes authentication procedures, account security monitoring, and the administration of account-related communications.
- Contractual Obligations: Processing is carried out to the extent necessary for the performance of the contractual relationship between the platform operator and the registered user, including the provision of gaming services, processing of financial transactions, and fulfilment of associated service obligations.
- Regulatory Compliance: Data is processed to satisfy obligations imposed by the Malta Gaming Authority, applicable anti-money laundering directives, data protection legislation, and all other statutory or regulatory requirements to which the platform operator is subject by virtue of licence MGA/B2B/826/2020.
- Identity Verification and Fraud Prevention: Processing activities are conducted for the purposes of verifying user identity, preventing fraudulent activity, detecting and investigating suspected breaches of applicable terms and conditions, and mitigating financial crime risks.
- Responsible Gaming: Data relating to gaming behaviour and account activity is processed for the purpose of identifying indicators of problem gambling, implementing self-exclusion arrangements, and fulfilling duties of care obligations as prescribed by regulatory guidelines.
- Financial Processing: Transaction data is processed to facilitate deposits, withdrawals, and the accurate reconciliation of financial records in compliance with applicable accounting and regulatory requirements.
- Security and Platform Integrity: Technical and behavioural data is processed for the purpose of maintaining platform security, detecting unauthorised access attempts, preventing system abuse, and ensuring the integrity of gaming operations.
- Legal Claims: Personal data may be processed where necessary for the establishment, exercise, or defence of legal claims before judicial, administrative, or other competent authorities.
No personal data shall be processed for purposes incompatible with those specified above. Where processing is proposed for a new purpose, data subjects shall be informed in advance and, where required by applicable law, their consent shall be obtained prior to the commencement of such processing.
Data Security
RubyPlay implements comprehensive technical and organisational measures designed to ensure an appropriate level of security with respect to the personal data processed in connection with dragoness-slot.com. Such measures are reviewed and updated on a periodic basis to reflect the current state of technical capability and the nature of associated risks.
- Encryption Protocols: All data transmitted between user devices and platform infrastructure is protected through the application of Transport Layer Security protocols. Sensitive data stored within platform systems is subject to encryption at rest utilising industry-standard cryptographic mechanisms.
- Access Controls: Access to personal data is restricted on the basis of the principle of least privilege. Authorised personnel are granted access solely to the categories of data necessary for the performance of their designated functions. Access rights are subject to periodic review and are revoked upon cessation of the relevant operational requirement.
- Authentication Measures: Multi-factor authentication requirements are applied to administrative access to systems containing personal data. User account access is protected through secure authentication mechanisms, the specifications of which are maintained in accordance with current security standards.
- Infrastructure Security: Platform infrastructure is maintained within secured data centre environments subject to physical access controls, environmental monitoring, and continuous availability management. Network perimeter defences, including firewall configurations and intrusion detection systems, are maintained and monitored by qualified security personnel.
- Incident Response: Documented procedures for the detection, reporting, and management of personal data breaches are maintained and tested on a periodic basis. In the event of a breach presenting risk to the rights and freedoms of data subjects, notification shall be provided to the competent supervisory authority and, where required, to affected data subjects, within the timeframes prescribed by applicable data protection legislation.
- Processor Due Diligence: Third-party service providers engaged to process personal data on behalf of the platform operator are subject to appropriate contractual obligations, including the implementation of adequate technical and organisational security measures, prior to being granted access to any personal data.
- Staff Awareness: Personnel with access to personal data are subject to confidentiality obligations and receive appropriate training regarding data protection requirements and security practices applicable to their respective roles.
- Data Minimisation: Only such personal data as is strictly necessary for the specified processing purposes is collected and retained. Retention periods are established in accordance with regulatory requirements and legitimate operational necessity, and data is securely deleted or anonymised upon the expiry of the applicable retention period.
Your Rights
In accordance with applicable data protection legislation, including Regulation (EU) 2016/679 of the European Parliament and of the Council (the General Data Protection Regulation), data subjects whose personal data is processed in connection with dragoness-slot.com are vested with the following rights:
- Right of Access: Data subjects are entitled to obtain confirmation as to whether personal data concerning them is being processed and, where such processing is taking place, to receive a copy of the personal data together with supplementary information regarding the purposes of processing, the categories of data concerned, the recipients or categories of recipients to whom data has been or will be disclosed, the applicable retention periods, and the existence of any automated decision-making.
- Right to Rectification: Data subjects are entitled to require the correction of inaccurate personal data and, having regard to the purposes of processing, the completion of incomplete personal data without undue delay.
- Right to Erasure: Data subjects may request the deletion of personal data concerning them where such data is no longer necessary in relation to the purposes for which it was collected, where consent has been withdrawn and no other legal basis for processing exists, where a valid objection to processing has been lodged, or where applicable legal obligations require deletion. It is noted that erasure requests may be subject to limitations where continued retention is required for compliance with legal obligations or for the establishment, exercise, or defence of legal claims.
- Right to Restriction of Processing: Data subjects may request that the processing of their personal data be restricted in circumstances prescribed by applicable data protection legislation, including where the accuracy of data is contested, where processing is unlawful but erasure is not sought, or where an objection to processing has been lodged pending verification of legitimate grounds.
- Right to Data Portability: Where processing is based on consent or on a contractual basis and is carried out by automated means, data subjects are entitled to receive the personal data concerning them in a structured, commonly used, and machine-readable format and to have such data transmitted to another controller where technically feasible.