Data Protection & Privacy
Information Collection
This Privacy Policy governs the collection, processing, and storage of personal data by RubyPlay, operating the platform accessible at dragoness-slot.com, under the regulatory authority of the Malta Gaming Authority pursuant to licence reference MGA/B2B/826/2020. All data processing activities conducted by this organisation are carried out in strict accordance with applicable data protection legislation, including the General Data Protection Regulation (EU) 2016/679 and any supplementary national implementing measures.
The following categories of personal data are subject to collection and processing in connection with the provision of services offered through this platform:
- Identity Data: Full legal name, date of birth, gender, nationality, and government-issued identification document details, including passport numbers, national identity card references, and equivalent documentary evidence required for identity verification and Know Your Customer (KYC) compliance procedures.
- Contact Data: Electronic mail address, postal address, telephone number, and any other communication details provided by the data subject at the point of registration or subsequently updated within the account management interface.
- Financial Data: Payment instrument details, transaction histories, deposit and withdrawal records, banking institution references, and any financial information required to facilitate the execution of monetary transactions and to satisfy applicable anti-money laundering obligations.
- Technical Data: Internet Protocol (IP) address, browser type and version, device identifiers, operating system information, session timestamps, geolocation data derived from network infrastructure, and cookie-based tracking identifiers generated during platform interaction.
- Behavioural Data: Gaming activity records, wagering patterns, session duration metrics, game selection histories, responsible gambling self-assessment responses, and any other interaction data generated through the use of platform features and services.
- Communications Data: Records of correspondence initiated between the data subject and customer support personnel, including the content of electronic messages, complaint submissions, and responses issued by the organisation.
- Compliance Data: Documentation and records generated in the course of regulatory compliance assessments, including source of funds declarations, enhanced due diligence records, and outputs from mandatory screening processes conducted against sanctions lists and politically exposed persons registers.
Personal data is collected through direct submission by the data subject during the account registration process, through automated technical means during platform usage, and where lawfully permissible, from authorised third-party verification and screening service providers engaged by the organisation for compliance purposes.
Data Usage
Personal data collected and retained by the organisation is processed exclusively for specified, explicit, and legitimate purposes. Processing activities are conducted on the basis of one or more lawful grounds as defined under applicable data protection legislation, including the performance of a contractual obligation, compliance with legal requirements, the pursuit of legitimate organisational interests, and, where applicable, the freely given and informed consent of the data subject.
The primary purposes for which personal data is processed are enumerated as follows:
- Account Administration and Service Provision: The creation, maintenance, and administration of user accounts is facilitated through the processing of identity and contact data. This activity is necessary for the performance of the contractual relationship established between the organisation and the data subject upon successful registration.
- Identity Verification and KYC Compliance: Identity and financial data are processed for the purpose of verifying the identity of data subjects in accordance with obligations imposed by applicable anti-money laundering legislation and regulatory requirements imposed by the Malta Gaming Authority. Verification procedures may involve the engagement of authorised third-party service providers.
- Payment Processing and Financial Transaction Management: Financial data is processed to facilitate the execution of deposit and withdrawal transactions, to reconcile account balances, and to investigate and resolve any disputed or irregular financial activity associated with the data subject's account.
- Regulatory Compliance and Legal Obligations: Personal data across multiple categories is processed to fulfil mandatory obligations arising from applicable law, including anti-money laundering requirements, responsible gambling legislation, tax reporting obligations, and directives issued by competent regulatory authorities.
- Responsible Gambling and Player Protection: Behavioural and account data is analysed for the purpose of identifying indicators of problematic gambling behaviour, administering self-exclusion requests and deposit limitation mechanisms, and ensuring that the organisation discharges its player protection obligations in accordance with the conditions of its operating licence.
- Fraud Prevention and Platform Security: Technical and behavioural data is processed for the detection, investigation, and prevention of fraudulent activity, unauthorised account access, collusive behaviour, and any other activity that may compromise the integrity of the platform or cause harm to the organisation or other users.
- Customer Support and Dispute Resolution: Communications data and account information are processed to facilitate the provision of customer support services, to investigate complaints, and to resolve disputes in a fair and timely manner.
- Service Improvement and Analytics: Aggregated and, where applicable, pseudonymised technical and behavioural data may be processed for the purpose of evaluating platform performance, identifying technical deficiencies, and informing decisions relating to the development and enhancement of services. Such processing is conducted on the basis of legitimate interests and does not result in decisions with legal or equivalent significant effects upon individual data subjects.
- Marketing Communications: Where explicit consent has been obtained from the data subject, contact data may be processed for the purpose of transmitting promotional communications, service updates, and offers relevant to the data subject's use of the platform. Consent for marketing communications may be withdrawn at any time through the account settings interface or by contacting the organisation directly.
Personal data shall not be processed for purposes incompatible with those specified herein without the prior notification of affected data subjects and, where required, the obtaining of additional consent or other appropriate legal basis.
Data Security
The organisation is committed to ensuring that personal data is protected against unauthorised access, accidental loss, destruction, alteration, or disclosure through the implementation of appropriate technical and organisational security measures. Such measures are reviewed and updated on a periodic basis to reflect evolving technological standards, identified risk factors, and the nature of the data processed.
The technical and organisational measures implemented by the organisation include, without limitation, the following:
- Encryption: Personal data transmitted between data subjects and the platform infrastructure is encrypted using industry-standard Transport Layer Security (TLS) protocols. Sensitive data retained within organisational systems, including financial information and authentication credentials, is subject to encryption at rest using appropriate cryptographic mechanisms.
- Access Control: Access to personal data held within organisational systems is restricted on the basis of role-based access control principles. Personnel are granted access to personal data only to the extent strictly necessary for the performance of their designated responsibilities. Access rights are reviewed on a regular basis and revoked upon termination of employment or change of role.
- Authentication Mechanisms: Organisational systems processing personal data are protected by multi-factor authentication requirements for personnel accessing sensitive infrastructure and administrative interfaces. Data subjects are provided with guidance on maintaining the security of their individual account credentials.
- Pseudonymisation and Data Minimisation: Where technically feasible and operationally appropriate, personal data is pseudonymised or anonymised prior to use in analytics and performance assessment activities. Data collection practices are subject to a principle of minimisation, whereby only data strictly necessary for specified processing purposes is collected and retained.
- Third-Party Processor Management: Where personal data is transferred to or processed by third-party service providers engaged by the organisation, such processors are required to demonstrate compliance with applicable data protection standards. Data processing agreements incorporating appropriate contractual safeguards are executed with all third-party processors prior to the commencement of data processing activities.
- Incident Response and Breach Notification: The organisation maintains documented procedures for the identification, assessment, and response to personal data security incidents. In the event of a personal data breach meeting the threshold for notification under applicable legislation, the relevant supervisory authority shall be notified within seventy-two hours of the organisation becoming aware of the breach. Where a breach is likely to result in a high risk to the rights and freedoms of affected data subjects, those data subjects shall also be notified without undue delay.
- Staff Training and Awareness: Personnel with access to personal data are required to undergo training on data protection obligations, security practices, and the organisation's internal policies governing the handling of personal information. Training is conducted upon commencement of employment and repeated at appropriate intervals thereafter.
- Data Retention: Personal data is retained for no longer than is necessary for the purposes for which it was collected, subject to any overriding retention obligations imposed by applicable law. Upon expiry of the applicable retention period, personal data is securely deleted or irreversibly anonymised in accordance with documented disposal procedures.
Notwithstanding the measures described herein, no data transmission or storage system can be guaranteed to be entirely secure. The organisation undertakes to employ all reasonable and proportionate measures to protect personal data but cannot warrant absolute security in all circumstances.
User Rights
In accordance with applicable data protection legislation, data subjects whose personal data is processed by the organisation are entitled to exercise the rights enumerated below. Requests for the exercise of any such right may be submitted to the organisation using the contact details provided in the relevant section of this document. The organisation shall respond to all verified requests within the timeframes prescribed by applicable law, and in any event within thirty calendar days of receipt of a valid request, subject to any lawful extension in cases of complexity or volume.
The rights available to data subjects are as follows:
- Right of Access: A data subject is entitled to obtain confirmation as to whether personal data concerning them is being processed by the organisation, and where such processing is occurring, to receive a copy of the personal data held, together with information relating to the purposes of processing, the categories of data processed, the recipients to whom data has been or may be disclosed, the intended retention period, and the existence of any automated decision-making activities.
- Right to Rectification: A data subject is entitled to request the correction of inaccurate personal data held by the organisation without undue delay. Where personal data held is incomplete, the data subject is entitled to have such data completed, taking into account the purposes of processing.
- Right to Erasure: A data subject is entitled to request the deletion of personal data concerning them where the data is no longer necessary for the purposes for which it was collected, where consent upon which processing was based has been withdrawn and no alternative legal basis exists, or where the data has been unlawfully processed. This right is subject to applicable exemptions, including obligations requiring the retention of data for compliance with legal requirements.
- Right to Restriction of Processing: A data subject is entitled to request that the processing of their personal data be restricted in specified circumstances, including where the accuracy of the data is contested, where processing is unlawful but the data subject opposes erasure, or where the organisation no longer requires the data but the data subject requires it for the establishment, exercise, or defence of legal claims.
- Right to Data Portability: Where processing is based on consent or the performance of a contract, and is carried out by automated means, a data subject is entitled to receive personal data concerning them in a structured, commonly used, and machine-readable format, and to transmit that data to another controller without hindrance from the organisation. Where technically feasible, the data subject may request that the data be transmitted directly from the organisation to another controller.
- Right to Object: A data subject is entitled to object at any time to the processing of personal data concerning them where such processing is based on the legitimate interests of the organisation or is conducted for direct marketing purposes. Where an objection is raised to processing for direct marketing purposes, the processing of personal data for such purposes shall cease without delay.
- Rights Related to Automated Decision-Making: A data subject is entitled not to be subject to a decision based solely on automated processing, including profiling, which produces legal effects concerning them or similarly significantly affects them, unless such processing is necessary for the performance of a contract, authorised by applicable law, or based on explicit consent. Where automated decision-making of this nature is conducted, the data subject is entitled to obtain human review of the decision, to express their point of view, and to contest the decision.
- Right to Withdraw Consent: Where processing is based on the consent of the data subject, such consent may be withdrawn at any time. Withdrawal of consent does not affect the lawfulness of processing carried out on the basis of consent prior to its withdrawal.
- Right to Lodge a Complaint: A data subject who considers that the processing of their personal data infringes applicable data protection legislation is entitled to lodge a complaint with the relevant supervisory authority. The competent supervisory authority in Malta is the Office of the Information and Data Protection Commissioner (IDPC).
The organisation reserves the right to verify the identity of any individual submitting a data subject rights request prior to the fulfilment of such request, in order to ensure that personal data is not disclosed to or acted upon at the direction of unauthorised parties. Where a request is determined to be manifestly unfounded or excessive, the organisation may charge a reasonable administrative fee or decline to act upon the request, providing written reasons for such a decision.
Contact Us
All enquiries, requests, and correspondence relating to the processing of personal data by the organisation, including the exercise of data subject rights as described in this document, shall be directed to the designated point of contact using the details provided below. Responses to all substantive enquiries will be issued within the timeframes required by applicable data protection legislation.
Electronic correspondence: [email protected]
All communications should clearly identify the nature of the enquiry or request, provide sufficient information to enable the organisation to verify the identity of the data subject where applicable, and specify any particular data processing activities to which the request relates. The organisation shall acknowledge receipt of all correspondence and shall provide a substantive response within the applicable statutory timeframe.