This online casino privacy notice explains how personal data is handled when players create or use an account, make payments, complete verification, use responsible-gambling controls or contact support. References to the controller mean the legal entity that determines how and why personal data is processed for the casino service.
Data controller / legal entity: Aurora North Ltd
Controller address / contact details: Level 2, The Hedge, Ir-Rampa ta’ San Ġiljan, St. Julian’s STJ 1062, Malta
Official website / domain: siirtocasino.com
Privacy contact / DPO: privacy@siirtocasino.com; DPO: dpo@siirtocasino.com
Cookie / analytics / adtech stack: Google Analytics 4, Hotjar, CookieYes (consent management), Facebook/Meta Pixel, Google Ads, affiliate tracking where deployed
Key processors / hosting / CDN providers: AWS (Frankfurt, Germany), Cloudflare, Sumsub (KYC), Trustly, Zimpler, Skrill, Neteller, Visa/Mastercard acquiring banks, SendGrid (email), tawk.to (live chat)
Retention periods by data category: Account data – 5 years after account closure; transactions – 5 years from transaction date; KYC/verification records – 5 years after account closure; support communications – 2 years after resolution; server and security logs – 12 months; marketing consent records – while consent is valid and for a reasonable period after withdrawal; cookie data – up to 12 months (session cookies expire when the browser closes).
International transfer destinations (if applicable): EEA (primary hosting in Germany); Malta (controller operations); limited transfers to UK/US where providers are located.
Transfer mechanism(s) / safeguards (if applicable): European Commission Standard Contractual Clauses (SCCs) for transfers outside the EEA; adequacy decisions where applicable (e.g., UK).
Effective date: 1 February 2026
Online casino account data is created through normal account use rather than one single form. Some information is supplied by the player, while other records are generated when the account is used for payments, games, bonuses, support or safer-gambling controls.
The main categories can include:
The table below shows the practical relationship between common account data and the functions it supports.
Data area | Examples | Main purpose |
|---|---|---|
Siirto Casino account access | Registered email, credentials and supplied profile data | Create and authenticate the account |
Verification | ID, address and payment-method evidence | KYC and payment-risk checks |
Payments | Amounts, method, status, timestamps and references | Process and reconcile deposits/withdrawals |
Gameplay & rewards | Sessions, stakes, results, bonus and loyalty activity | Balances, bonuses, cashback and player controls |
Support & RG | Messages, limits, time-out/self-exclusion status | Support cases and safer-gambling controls |
Siirto Casino account access | Examples Registered email, credentials and supplied profile data | Main purpose Create and authenticate the account |
|---|---|---|
Verification | Examples ID, address and payment-method evidence | Main purpose KYC and payment-risk checks |
Payments | Examples Amounts, method, status, timestamps and references | Main purpose Process and reconcile deposits/withdrawals |
Gameplay & rewards | Examples Sessions, stakes, results, bonus and loyalty activity | Main purpose Balances, bonuses, cashback and player controls |
Support & RG | Examples Messages, limits, time-out/self-exclusion status | Main purpose Support cases and safer-gambling controls |
Payment providers can process their own transaction information under their own privacy terms. The casino keeps the data needed to operate the account, reconcile transactions, investigate errors and meet applicable obligations.
Siirto Casino personal data may be used to run the account and the services connected to it.
Typical purposes include:
The legal basis depends on the purpose. Processing may be necessary to perform the service requested by the player, comply with legal obligations, protect legitimate interests such as security and fraud prevention, or rely on consent where consent is required.
Siirto Casino verification checks can be used to confirm that an account and payment method belong to the correct person. Verification may be requested before a withdrawal or when account and payment-risk checks require it.
Where third-party providers are used for payments, games, identity verification, hosting, communications, security or other technical functions, personal data is shared only to the extent needed for the relevant service or legal purpose. Personal data may also be disclosed to competent authorities where a valid legal obligation requires it.
Siirto Casino security measures are intended to protect account and personal information against unauthorised access, alteration, disclosure or loss. Players should also keep passwords private and treat unexpected authentication or payment requests cautiously.
Personal data is retained only for as long as needed for the purpose for which it was collected and for any additional period required by applicable legal, accounting, fraud-prevention, dispute or regulatory obligations. Different categories can therefore have different retention periods.
Siirto Casino players may have rights under the GDPR and other applicable data-protection law.
Depending on the circumstances, these can include the right to:
A request does not automatically override legal retention duties or other lawful reasons for continuing to process particular information.
Where the online casino website uses cookies or similar technologies, they can support login sessions, security, preferences and measurement of how the service is used. Non-essential analytics or marketing technologies are subject to the consent rules that apply to them.
Where consent controls are required, optional cookie choices can be managed through the website’s cookie controls or notice. Technologies that are strictly necessary for security, login or another essential service function can remain active independently of optional preferences.
Some service providers may process data outside the country where the player is located. Where personal data is transferred outside the European Economic Area, the transfer must use a lawful mechanism and appropriate safeguards where required by data-protection law.
For Siirto Casino data transfers, the safeguards depend on the provider, destination and transfer arrangement. More information about relevant transfer safeguards can be requested through the privacy or support contact provided for the service.
The casino is restricted to adults aged 18 and over. Age and identity checks may therefore form part of account verification. Responsible-gambling data is used to operate deposit limits, loss limits, session or time limits, reality checks, time-out and self-exclusion functions linked to the account.
Finnish players who need independent help with gambling can contact Peluuri at 0800 100 101. The helpline is free, confidential and open Monday to Friday from 12:00 to 18:00.
This Privacy Policy may be updated when account functions, payment methods, verification processes, service providers or applicable legal requirements change. The version published on the website applies from its stated effective date, and material changes are communicated where required.
Players can use the privacy or support contact provided on the website to ask questions about personal data, exercise privacy rights or request more information about how a particular category of data is handled.