Privacy policy and how we handle your data

This privacy policy explains what personal data GamStop Compass Casino collects when you visit the site, why we collect it, how long we keep it and what rights you have under the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018. It is written to be readable rather than exhaustive; if anything below is unclear, please contact us using the details at the end.

Understand the key definitions

Throughout this policy we use the following terms in the meanings given by Article 4 of the UK GDPR. Personal data means any information relating to an identified or identifiable natural person. Processing means any operation performed on personal data, including collection, storage, use and erasure. Controller means the party that determines the purposes and means of processing – on this site, that is GamStop Compass Casino acting as editorial publisher. Processor means a third party that processes personal data on the controller’s behalf, for example our hosting provider or web-analytics provider.

Identify the data we collect

We try to minimise the personal data we collect. The site is informational; we do not require registration to read any page and we do not operate gambling accounts. The categories of personal data we may process are limited to: contact information you actively provide via the form on the contact page (name, email address, subject and message body); technical log data automatically generated by our hosting provider when you load a page (IP address, user agent, referrer URL, timestamp); and cookie identifiers and analytics data described in the cookies page.

We do not collect special category data, we do not collect data from children under 13, and the site is restricted to readers aged 18 and over. If you believe a child has submitted data through the contact form, please contact us so we can erase it.

Understand the lawful basis we rely on

Under Article 6 of the UK GDPR we rely on the following lawful bases. Consent (Article 6(1)(a)) applies to any non-essential cookies and to receipt of editorial updates if you opt in. Legitimate interests (Article 6(1)(f)) apply to security logging, fraud prevention and audience-measurement analytics where these are configured to minimise individual identification. Compliance with a legal obligation (Article 6(1)(c)) applies when we are required to retain information for tax, fraud or regulatory purposes.

When you submit a message through the contact form, we process the data on the basis of your consent and our legitimate interest in operating an editorial publication. You can withdraw consent at any time by emailing us; this does not affect the lawfulness of processing prior to withdrawal.

Identify who we share data with

We do not sell personal data and we do not share it with advertising networks for behavioural targeting. We share limited categories of data with processors strictly to operate the site: our hosting and content-delivery provider (server logs); our analytics provider, if you have consented to non-essential cookies (anonymised page views, session duration, country-level geolocation); and our email service if you contact us (the contents of your message). Each processor is bound by a written processing agreement under Article 28 of the UK GDPR. We may also disclose data to law-enforcement authorities where we are legally compelled to do so.

Understand how long we keep your data

Retention periods are aligned to the purpose of the processing. Server access logs are kept for up to 90 days for security and abuse prevention. Cookie data follows the durations listed on the cookies page. Contact-form submissions are retained for up to 24 months after the last correspondence, then deleted unless a longer retention is necessary for legal claims. Editorial newsletter records (if any) are kept until you unsubscribe, after which we retain a minimal suppression record to honour your opt-out.

Exercise your rights as a data subject

Under the UK GDPR you have the right of access (request a copy of your data), the right to rectification (correct inaccurate data), the right to erasure (the “right to be forgotten” in defined circumstances), the right to restriction of processing, the right to data portability, the right to object to processing on legitimate-interests or direct-marketing grounds, and the right not to be subject to solely automated decision-making. We do not carry out automated decision-making or profiling that produces legal effects.

To exercise any of these rights, email us at privacy@{{SITE_DOMAIN}} (placeholder address; to be replaced at deployment) or write to the postal address on the contact page. We will respond within one calendar month. If you are not satisfied with our response, you have the right to lodge a complaint with the Information Commissioner’s Office (ICO) at ico.org.uk or by calling 0303 123 1113.

Contact the data protection lead

Data protection enquiries should be sent to: Data Protection Lead, GamStop Compass Casino, [editorial postal address placeholder], United Kingdom. Email: privacy@{{SITE_DOMAIN}} (placeholder). We are not a public authority and are not required to appoint a statutory Data Protection Officer; an internal data protection lead has nevertheless been designated.

Track changes to this policy

Material changes to this policy are recorded in the last-reviewed date shown above and, for significant changes, by a banner on the homepage for at least 30 days. Earlier versions of the policy are available on request through the contact details above.