At Trino Casino, we operate trinoo trinoo.de.de and we take protecting the personal data of our German players seriously. As a licensed entertainment platform, we’ve built our operations to satisfy the strict standards of the General Data Protection Regulation (GDPR) and the German Federal Data Protection Act (BDSG). This document clarifies exactly how we obtain, retain, manage, and safeguard your information when you use our website, play games, or interact with our affiliate systems. We consider transparency is vital for a trusting relationship. By outlining our data handling practices clearly, we want you to feel confident that your sensitive financial details and personal identifiers remain in a secure digital environment, managed by a responsible data controller that adheres to local laws and jurisdictional boundaries.
1. Identifikace správce údajů a právní základ zpracování
We act as the data controller for all personal details collected through Trino Casino at trinoo.de, which is customized for German users. Our legal team operates from a registered office inside the European Economic Area, making us fully bound by GDPR enforcement. For processing your data, we depend on six specified lawful bases. In most cases, we process your data to meet our contractual duties—such as accepting bets, handling withdrawals, and maintaining your account. We also rely on legitimate interest for analytics and security purposes, like fraud detection algorithms and network integrity checks, provided these do not override your fundamental rights and freedoms. Where legislation requires it, especially under anti-money laundering laws and German gambling ordinances, processing is carried out due to a legal duty. For marketing communications, including our affiliate programme, we rely on your explicit consent, which you can withdraw at any time without any impact on the core services we provide.
6. Applying Your personal Prerogatives Under German and European Union Regulations
If you live in Germany, you are entitled to a collection of prerogatives that we’ve made straightforward to enforce. You are able to lodge a subject access request at your convenience. We are then required to ascertain whether we hold your data and supply you with a copy in a structured, widely adopted, machine‑readable form within 30 days. The right to amendment enables you to correct stale or erroneous profile details without delay, which is vital for efficient payment operations. In some cases, you are entitled to a suspension of processing, notably if you dispute the precision of data while we check it. The right to erasure, commonly known as the “right to be forgotten,” applies when the data has become unnecessary for the primary goal, though legal retention obligations may temporarily override this request. You also have the right to data portability for data furnished under consent or agreement, so you may transfer your activity log to a new service. You have an total right to object to direct marketing, and you may oppose to data handling based on lawful interests, which we’ll evaluate against our legitimate justifiable bases. Grievances can be lodged directly with the privacy regulator of your German federal state if you believe a infringement has happened.
5. International Movements and Technical Security Controls
Our primary data processing systems are located in safe data centers inside the European Union, but sometimes we must utilize sub-processors in other countries. In those rare cases, we assure the equivalent degree of security by using Standard Contractual Clauses authorized by the European Commission, combined with a comprehensive Transfer Impact Assessment. To safeguard your financial data from unapproved access during communication, we apply Transport Layer Security (TLS 1.3) encryption across all endpoints, rejecting obsolete cipher suites. At rest, personal data stored in our managed database clusters is shielded by AES‑256 encryption, and access to decryption keys is restricted to a separate privileged access management system. We perform continuous vulnerability scans, compulsory penetration tests, and strict logical access controls so solely the personnel who must have it can access your data. We have a dedicated Data Protection Officer you can contact through our platform, and we keep an incident response plan that obligates us to inform the pertinent German supervisory authority within 72 hours if a personal data breach could place your rights at risk.
7. Cookie Administration and Monitoring Technologies for Regulatory Compliance
Our website employs multiple tracking markers, and our consent management system guarantees that no non-essential tracking tools activate until a German user gives explicit consent through our comprehensive preference center. Essential session cookies, which do not store private data but keep your gaming session and security tokens working, are exempt from approval requirements under the Electronic Privacy Directive as applied in German law. For persistent analytics and affiliate attribution cookies, we implement backend tagging where possible to limit browser-side exposure. Our affiliate tracking pixel functions on a first-party data model to work around current browser restrictions, enabling precise attribution without aggressive tracking scripts that are banned under German digital regulations. We’ve classified all programs with detailed descriptions of their function, length, and the external vendors included, so you can modify your settings whenever you like. Rejecting promotional cookies does not affect the operation of the game lobby or payment portals. That reflects our privacy‑by‑design approach: essential services remain completely available irrespective of approval selections you select.
2. Categories of User Information Gathered When Creating an Account and Gameplay
To deliver a smooth entertainment experience that meets German regulations, we gather a few particular types of personal data, just what is necessary. During account creation, we require identification details: your legal first and last name, residential address with postal code, verified email address, and date of birth to guarantee you meet the strict age minimum established by German regulators. When you start playing, we process financial transaction data—deposit amounts, withdrawal methods, partial payment card numbers encrypted with TLS, and e-wallet identifiers. Our systems automatically log technical device data like your IP address, which we restrict by location to verify you’re in a permitted location, along with browser fingerprint hashes and operating system specs. We also track usage patterns and game session logs, recording bet history and time spent playing, so we can fulfill our responsible gaming obligations. We do not collect special categories of sensitive data except when you willingly give that information during a responsible gaming self-assessment or a support inquiry.
4. Data Preservation Plans and De-identification Methods
We don’t keep your personal data permanently. We adhere to a strict storage limitation principle. Active customer accounts hold data for the duration of the business relationship, from the moment you register until you formally close the account. After account closure, a holding period kicks in, driven mostly by German tax legislation and anti-money laundering rules. Transactional logs, identification documents collected under Know Your Customer protocols, and wagering history are securely archived for ten years from the end of the calendar year of the last transaction. Once that statutory retention window ends, we permanently destroy or irreversibly anonymize the records so re-identification becomes technically impossible. Web server log data that contains IP addresses gets truncated after a strict thirty‑day cycle to reduce security risks. For accounts that go dormant—no activity but not closed—we send a proactive reminder before the dormancy threshold, so we can ask for renewed consent or start the deletion process, always in line with the storage limitation principle.
3. Detailed Processing Activities Pertaining to the Affiliate Programme
Our affiliate network, reachable via our legal and affiliates hub, serves as a separate data processing area. We act as a joint controller together with our marketing partners. When a German webmaster or content creator enrolls in our partner program, we gather business details like tax identification numbers, bank account information for paying commissions, and traffic source analytics. Our tracking mechanism employs first‑party cookies dropped via a unique affiliate link, which allows us attribute referred traffic to the correct partner account without capturing the browsing history of unregistered visitors. We handle referred player data in a pseudonymized format for commission calculation, so the affiliate sees aggregated performance numbers rather than individual player identities. We review player activity logs against traffic sources to catch bonus abuse or fake incentivized traffic; this is grounded in our contractual and legitimate business interests. We have a strict affiliate code of conduct that prevents partners from targeting self-excluded individuals or using unauthorized direct marketing that could undermine the privacy expectations of the German audience.
Common Questions
How does Trino Casino verify my age in line with German regulations?
We employ a multi-layered system: computerized checks against national databases and hands-on document review. When you create an account, you must upload your national ID card or passport through an encrypted portal. Our compliance team cross‑references this with the Schufa identity service to confirm legal age. die Seite öffnen If something is inconsistent, we provisionally restrict the account until a video identification call with a certified agent can clarify the situation, all in line with the German Interstate Treaty on Gambling.
Will my personal data be disclosed with the affiliate who referred me?
No. Our affiliate programme employs a strict aggregation firewall. We never disclose your name, contact details, or payment records with the referring affiliate. The partner only accesses a pseudonymized dashboard with confirmed registration counts and a statistical summary of net gaming revenue. Our affiliate agreements clearly prohibit them from trying to identify individual players. This ensures your gameplay completely separate from the marketing channel that brought you to Trino Casino.
In what way can I permanently cancel my marketing consent?
Go to “Communication Settings” in your account dashboard and turn off promotional channels. Every marketing email we send has a one‑click unsubscribe link at the bottom that works right away. To withdraw consent for postal mail or SMS, contact our Data Protection Officer through the support ticket system. die Schlussfolgerung We’ll stop direct marketing within at most 48 hours after receiving your request.
What happens to my data if Trino Casino ceases operations?
If business ever stops, we are legally required to notify the competent German data protection authority and all active users in advance. Mandatory transactional logs and identification records will be securely transferred to a certified archival service or handed over to the responsible regulatory body for as long as the law demands. Any data that isn’t mandatory gets securely destroyed using cryptographic wiping techniques before the closure of our servers is finalized.
Will Trino Casino use automated decision-making for payments?
We use a limited automated profiling system to flag possible fraud or bonus abuse. If the system blocks a withdrawal, we’re required by law to involve a human. Our financial risk team manually checks every flagged transaction before we tell you the final decision. You can challenge that decision, give your side, and ask for a full manual review by our risk management specialists.
What is the process to receive a complete record of my stored data?
Email us from the address linked to your account to our Data Protection Officer, include “SAR” in the subject line. We’ll authenticate your identity with a two‑factor process. After that, we compile your data from all systems—chat logs, game history, identity documents—and prepare a digitally signed PDF and a machine‑readable JSON file, which will be sent to you within one calendar month.