Gecko Play Casino

Data Protection & Privacy

Information Gathering

Skill On Net Limited, operating the digital platform accessible at geckoplay-casino.co.uk, collects and processes personal data in strict accordance with applicable data protection legislation, including the United Kingdom General Data Protection Regulation (UK GDPR), the Data Protection Act 2018, and relevant regulatory requirements imposed by the United Kingdom Gambling Commission (licence reference: 039326-R-319358-059) and the Malta Gaming Authority (licence reference: MGA-C50024). The following categories of personal data are subject to collection and processing by this establishment:

  • Identity Data: Full legal name, date of birth, gender, nationality, and government-issued identification documentation, including passport numbers, driving licence references, and national identity card details, are collected for the purposes of identity verification and regulatory compliance.
  • Contact Data: Postal address, electronic mail address, and telephone number are recorded to facilitate account management and service-related correspondence.
  • Financial Data: Banking account details, payment card information, transaction histories, and records of deposits and withdrawals are retained in compliance with anti-money laundering obligations and financial regulatory requirements.
  • Technical Data: Internet Protocol (IP) addresses, browser type and version, device identifiers, operating system specifications, session duration data, and login timestamps are automatically collected upon access to the platform.
  • Usage Data: Records of gaming activity, wagering patterns, session frequency, and platform navigation behaviour are compiled and retained for regulatory and operational purposes.
  • Verification Data: Source of funds documentation, proof of address materials, and self-exclusion history records are collected in fulfilment of responsible gambling obligations and anti-money laundering screening requirements.
  • Communications Data: Records of correspondence submitted via electronic mail, live chat, and other designated communication channels are retained for quality assurance, dispute resolution, and regulatory record-keeping purposes.
  • Preference Data: Marketing communication preferences, account settings, and declared responsible gambling limits are recorded and maintained throughout the duration of the account relationship.

Personal data is obtained directly from the data subject at the point of account registration, during the continuation of the service relationship, and through automated technical processes associated with platform usage. Data may additionally be obtained from third-party identity verification providers, credit reference agencies, fraud prevention organisations, and publicly accessible databases where such acquisition is required for regulatory compliance or legitimate operational purposes.

Data Usage

Personal data collected by Skill On Net Limited is processed exclusively for defined, legitimate, and documented purposes. The processing activities conducted in relation to data subject information encompass the following:

  • Account Registration and Administration: Personal data is processed to establish, maintain, and administer registered user accounts, to verify the identity of account holders, and to ensure the continued accuracy of account records throughout the service relationship.
  • Regulatory Compliance: Processing is conducted in fulfilment of statutory and regulatory obligations imposed by the United Kingdom Gambling Commission and the Malta Gaming Authority, including obligations pertaining to age verification, identity confirmation, anti-money laundering screening, counter-terrorism financing measures, and responsible gambling requirements.
  • Financial Transaction Processing: Payment data and financial records are processed to facilitate the execution, reconciliation, and auditing of deposit and withdrawal transactions conducted through the platform.
  • Responsible Gambling Obligations: Usage data, wagering patterns, and account activity records are analysed to identify indicators of potentially harmful gambling behaviour, to implement self-exclusion requests, and to enforce account restrictions where required under applicable regulatory frameworks.
  • Fraud Prevention and Security: Technical and behavioural data are processed to detect, investigate, and prevent fraudulent activity, unauthorised account access, and other conduct constituting a breach of platform terms or applicable law.
  • Customer Support Services: Communications data and account information are processed to respond to enquiries, to investigate complaints, and to resolve disputes submitted through designated support channels.
  • Legal Obligations and Dispute Resolution: Personal data is retained and processed where necessary to establish, exercise, or defend legal claims, to comply with court orders or regulatory directives, and to fulfil obligations arising under applicable law.
  • Platform Improvement and Analytics: Aggregated and anonymised usage data is processed for the purposes of improving platform functionality, analysing service performance, and developing enhancements to the user experience, subject to applicable legal bases for such processing.
  • Direct Marketing Communications: Where explicit consent has been obtained, or where a legitimate interest basis has been established and documented, contact data may be processed for the purpose of transmitting promotional communications. Data subjects retain the right to withdraw consent or to object to such processing at any time.

All processing activities are conducted in accordance with an identified lawful basis under Article 6 of the UK GDPR, which may include the performance of a contract to which the data subject is party, compliance with a legal obligation, the protection of vital interests, the pursuit of legitimate interests of the data controller, or the explicit consent of the data subject.

Security Measures

Skill On Net Limited implements a comprehensive framework of technical and organisational measures designed to ensure an appropriate level of security in relation to the risks presented by the processing of personal data. The security infrastructure maintained by this organisation encompasses the following provisions:

  • Encryption Protocols: All data transmissions between data subjects and the platform are secured through industry-standard Transport Layer Security (TLS) encryption. Sensitive data stored within organisational systems is subject to encryption at rest utilising accepted cryptographic standards.
  • Access Control Mechanisms: Access to personal data is restricted on a strict need-to-know basis. Role-based access controls are implemented to ensure that personal data is accessible only to authorised personnel whose job functions require such access. Multi-factor authentication is applied to administrative system interfaces.
  • Network Security Infrastructure: Firewalls, intrusion detection systems, and intrusion prevention mechanisms are deployed to protect organisational networks and data processing environments from unauthorised external access and malicious activity.
  • Vulnerability Management: Regular security assessments, penetration testing exercises, and vulnerability scanning procedures are conducted to identify and remediate potential weaknesses within the technical infrastructure.
  • Data Minimisation and Retention Controls: Personal data is retained only for the period necessary to fulfil the purposes for which it was collected, subject to any applicable legal or regulatory retention obligations. Data that is no longer required for processing purposes is subject to secure deletion or anonymisation procedures.
  • Staff Training and Awareness: All personnel engaged in the processing of personal data are required to complete data protection training and to adhere to documented internal policies and procedures governing the handling of personal information.
  • Third-Party Processor Oversight: Contractual arrangements with third-party data processors are established in accordance with Article 28 of the UK GDPR. Due diligence assessments are conducted prior to engagement with external processors, and ongoing compliance monitoring is maintained throughout the duration of processing relationships.
  • Incident Response Procedures: Documented procedures for the identification, assessment, reporting, and remediation of personal data breaches are maintained. Where a breach is assessed as presenting a risk to the rights and freedoms of data subjects, notification to the Information Commissioner's Office and, where applicable, to affected data subjects, shall be conducted within the timeframes prescribed by applicable law.
  • Business Continuity and Data Recovery: Backup systems and data recovery procedures are maintained to ensure the availability and resilience of personal data processing systems in the event of a technical incident or operational disruption.

Notwithstanding the measures described above, it is acknowledged that no system of electronic transmission or data storage can be represented as entirely impenetrable. The organisation remains committed to the continuous review and improvement of its security posture in response to evolving threats and technological developments.

Your Rights

Data subjects whose personal information is processed by Skill On Net Limited are entitled to exercise the following rights in accordance with the provisions of the UK GDPR and the Data Protection Act 2018. The exercise of these rights is subject to applicable legal conditions, exemptions, and limitations as provided under the relevant legislation:

  • Right of Access: Data subjects are entitled to request confirmation as to whether personal data relating to them is being processed, and, where such processing is confirmed, to obtain a copy of the personal data held, together with supplementary information regarding the purposes and conditions of such processing. Such requests shall be responded to within one calendar month of receipt, subject to extension in cases of complexity or volume as permitted under applicable law.
  • Right to Rectification: Where personal data held by the organisation is established to be inaccurate or incomplete, data subjects are entitled to request the correction or completion of such data without undue delay. Documentation may be required in support of rectification requests where the accuracy of the data is disputed.
  • Right to Erasure: Data subjects may request the deletion of personal data where the grounds specified under Article 17 of the UK GDPR are applicable, including where the data is no longer necessary for the purposes for which it was collected, where consent upon which processing was based has been withdrawn, or where the processing has been determined to be unlawful. This right is subject to overriding legal obligations, including statutory and regulatory retention requirements applicable to licensed gambling operators.
  • Right to Restriction of Processing: Data subjects are entitled to request the restriction of processing activities in circumstances defined under Article 18 of the UK GDPR, including where the accuracy of the data is contested, where processing has been objected to pending verification of legitimate grounds, or where the data is required for the establishment, exercise, or defence of legal claims.
  • Right to Data Portability: Where processing is based on consent or on the performance of a contract, and is carried out by automated means, data subjects are entitled to receive personal data provided by them in a structured, commonly used, and machine-readable format, and to request the transmission of such data to another data controller where technically feasible.
  • Right to Object: Data subjects retain the right to object to the processing of personal data where such processing is based on legitimate interests or is conducted for direct marketing purposes. Objections to direct marketing processing shall be honoured without requirement to demonstrate grounds. Objections to other processing activities shall be assessed in light of any compelling legitimate grounds that may override the interests, rights, and freedoms of the data subject.
  • Rights in Relation to Automated Decision-Making: Data subjects are entitled not to be subject to decisions based solely on automated processing, including profiling, where such decisions produce legal effects or otherwise significantly affect them, except where permitted under applicable law or where explicit consent has been obtained.
  • Right to Withdraw Consent: Where processing is conducted on the basis of consent, data subjects are entitled to withdraw such consent at any time without detriment. Withdrawal of consent shall not affect the lawfulness of processing conducted prior to the point of withdrawal.
  • Right to Lodge a Complaint: Data subjects who consider that the processing of their personal data is not conducted in accordance with applicable data protection legislation are entitled to lodge a complaint with the Information Commissioner's Office (ICO), the supervisory authority for data protection matters in the United Kingdom, accessible at ico.org.uk.

Requests for the exercise of data subject rights should be submitted in writing to the contact details specified below. The identity of the requesting party may be required to be verified prior to the processing of any such request. No charge is levied for the exercise of data subject rights in standard circumstances; however, reasonable administrative fees may be applied where requests are assessed as manifestly unfounded or excessive.

Get in Touch

All formal correspondence relating to data protection matters, enquiries concerning the processing of personal data, and requests for the exercise of data subject rights should be directed to Skill On Net Limited through the following designated electronic communication channel:

Electronic Mail: [email protected]

Written correspondence submitted via the above address will be acknowledged and processed in accordance with the timeframes prescribed under applicable data protection legislation. Data subjects are requested to provide sufficient detail within their communications to enable the accurate identification of the relevant account and the precise nature of the request or enquiry. Skill On Net Limited is committed to responding to all data protection correspondence in a thorough, timely, and legally compliant manner.

🍪 This site uses cookies to improve your experience. Read more in our Privacy Policy.
Necessary
Required for the website to function properly
Analytics
Help us understand how visitors use the site
Marketing
Used for personalized advertising
Preferences
Remember your site preferences