PRIVACY POLICY

1. Scope
2. Definitions
3. Types of data processed by Grand Z
4. Purposes of collecting and processing information
5. Disclosing data subjects information
6. Data transfers
7. Marketing
8. Security
9. Data retention
10. Data subject rights under GDPR
11. Data subject requirements
12. Processing Data Through Consent
13. Privacy Policies of Linked Website and Advertisers
14. Surveys & Contests
15. Miscellaneous

 

1. SCOPE

Grand Z is completely committed in giving you a safe gaming experience that you can enjoy. We will always properly and purposely process the data provided to us according to the current legislation and with focus on your rights as a player. The scope of this privacy policy is to help you know your rights and also have access to all the information that will be processed by the data controller, Brightstar N.V. If you have any questions regarding this data policy or your rights as a data subject, please contact our Data Privacy Officer directly on: [email protected]

Please keep in mind that Grand Z is only open for Adult players (18+). We will use the data and documents you will provide in order to verify your age. Keep in mind that any use of any games or services shown on Grand Z is forbidden for anyone who is under 18 years old.

2. DEFINITIONS

This Policy is issued on behalf of Brightstar N.V., a company based at Kaya W.F.G, (Jombi) Mensing 24, Unit A, Curaçao, under gaming License number # 365/JAZ issued by Gaming Services Provider N.V., authorized and regulated by the Government of Curacao. The terms “Company”, “we”, “us”, “website” or “our” in this Privacy Policy refer to Brightstar N.V. or the relevant company in the group responsible for processing your data.

All references to “Player”, “end user”, “you”, “yours” and/or “your”, in this Privacy Policy refers to any user which accesses and plays on Grand Z.

Any reference to “Games” or “Game” in this Privacy Policy refers to the gaming products offered on Grand Z. “The data controller” is a person, company, or other body that determines the purpose and means of personal data processing (this can be determined alone, or jointly with another person/company/body).

“Data processor” is a natural or legal person, public authority, agency or other body which processes personal data on behalf of the controller.

“Personal Data” are any information which are related to an identified or identifiable natural person. “GDPR” or “the Regulation” – General Data Protection Regulation (2016/679)

3. TYPES OF DATA PROCESSED BY GRAND Z

Depending on your activity, Grand Z will request some or all the information mentioned below.

• Information that you will be requested to provide upon registration – identity data (Date of Birth, Place of Birth, Residential Address) and contact data (Username, Phone Number and Email Address) – this will allow us to create and maintain a business relationship with you, and it will allow you to enjoy the services offered on the website.

• In order to maintain this business relationship, as well as to comply with our legal obligations, we will also keep **activity logs ** (your playing history, login activity, game sessions, total bets, total wins, IP address), account balance information (total, real and bonus balance, bonuses, reserved bets, maximum balance, deposits, withdrawals, average deposit and bonus, income) as well as game analytics (free rounds, recently played games, favourite provider, most played, biggest win).

• To be able to provide you with the best customer experience possible, we will keep records of your customer support correspondence with Grand Z (both emails and chats).

• You have the right to set limits on your account, in order for us to help you in this process we will process your decision in regards to the self-imposed such limits (bet and loss limits, daily deposit limits) – what we call “limit data ”; you also have the right to self-exclude yourself or freeze the account for a set period of time or for an indetermined period of time (please know that you will not be able to access your account until the self-exclusion period has passed).

• We will request and process Know Your Customer (KYC) information in line with our legal requirements and our Terms & Conditions mentioned on the website. These are requested on a case to case basis, they include but are not limited to: Bank statements, Valid ID, Utility bill, PEP status, Source of wealth or source of funds.

• In order to provide you with the best gaming experience, we will collect and use technical data , including but not limited to: IP address (the address used to connect your computer to the internet) and device, your login information, browser type and version, time zone setting, browser plug-in types and versions, operating system and platform; Information about your visit including the full Uniform Resource Locators (URL), games you played and duration of each game and page, page interaction information (“Usage Data ”); Information received from cookies including details of your visits to this site for traffic overview, games you played, duration on each game and in general your behaviour on the website. This information is collected in line with our Cookie Policy (add link) (“Cookie Data ”) and your preferences as expressed in the in the cookie banner on our website.

• We will not collect or process any kind of sensitive data , including but not limited to racial or ethnic origin, political opinions, religious or philosophical beliefs, trade union memberships, health data, data concerning an individual’s sex life or sexual orientation;

• Public sources data that is publicly available information from Third Parties or Publicly Available Sources, usually via Google searches, when required for us to use it to be in line with our legal requirements.

4. PURPOSES OF COLLECTING AND PROCESSING THE INFORMATION

TYPE OF DATALAWFUL BASIS FOR PROCESSINGPURPOSE FOR WHICH THE DATA WILL BE PROCESSED
- Identity Data
- Contact Data
- Public Sources Data
- Performance of a contract with you
- Complying with our legal obligations
- Registering you as a user to create your account and allow you to play games in order to provide you with gaming services in line with our contract with you (see Terms and Conditions) and performing our obligations arising from the Terms and Conditions including contacting you where contact is necessary to perform our obligations towards you, e.g. customer support matters.
- Complying with our legal obligations under Anti-Money Laundering and gaming laws.
- Financial Dataa
- Identity Data
- Contact Data
- Bank Account Data
Performance of a contract with youTo process your deposit/withdrawal of funds and payouts in relation to Games played on our website and in accordance with the Terms and Conditions.
- Identity Data
- Contact Data
- Technical Data
- Account Data
- Usage Data
- Cookie Data
Legitimate interestsOur legitimate interest for administering, protecting and developing our business and the website, provision of administration and IT services, network security, to prevent fraud, including through troubleshooting, data analysis, testing, system maintenance, and support.
- Identity Data
- Contact Data
- Technical Data
- Account Data
- Usage Data
- Cookie Data
Legitimate interestsOur legitimate interest to see how customers use our products in order to develop them and to grow our business and form our marketing strategy and to deliver relevant website content and advertisements to users.
- Technical Data
- Usage Data
- Cookie Data
Legitimate interestsOur legitimate interests to use data analytics to improve our website, products and services, customer relationships and marketing strategy and to define types of customers for our products, to keep our website updated and relevant, and to develop our business.
- Identity Data
- Contact Data
- Technical Data
- Account Data
- Usage Data
- Cookie Data
ConsentMarketing products or services which might be of interest to you Contacting you with bonuses schemes and promotional offers Contacting you with game updates.
- Account Data
- Usage Data
- Identity Data
ConsentCollecting information to help improve the use of our website, Games and customer experience through participation in surveys and/or contests.
- Identity Data
- Contact Data
Complying with our legal obligationsNotifying you of changes to this Privacy Policy in line with our obligations under GDPR.
- Account Data
- Usage Data
- Identity Data
Legitimate interestsOur legitimate interest to develop our products, grow our business and improve customer relationships by providing game leader boards and promote in-game player achievements
- Account Data
- Usage Data
- Identity Data
Legitimate interestsOur legitimate interests to solicit input and feedback in order to study how our customers use our products in order to develop and improve our Games and services and customise your user experience and customer relationship.
- Identity Data
- Contact Data
- Technical Data
- Account Data
- Usage Data
- Bank Account Data
Complying with our legal obligationsComplying with our legal obligations under money laundering and gaming laws to prevent money laundering, fraud and collusion by analysing and studying player behaviour, communications, depositing and player patterns.
- Limit Data
- Identity Data
- Contact Data
- Technical Data
- Account Data
- Usage Data
Complying with our legal obligationsComplying with our legal obligations under gaming laws for the allowance of the setting of player limits and processing of data to ensure that player and website do not exceed set limits.
- Self-Exclusion Data
- Identity Data
- Contact Data
- Technical Data
- Account Data
- Usage Data
Complying with our legal obligationsComplying with our legal obligations under gaming laws for the allowance of the setting of self-exclusions and processing of data to ensure that player and website abide by such exclusions.
- KYC Data
- Public Sources Data
- Bank Account Data
- PEP Data
Complying with our legal obligationsComplying with our legal obligations under anti-money laundering and gaming laws to verify your identity and establish source of wealth, source of funds and politically exposed person status.

Please know that Grand Z will use the information provided also for legal and regulatory compliance purposes, including as necessary: to respond to governmental or regulatory entities requests; to comply with our legal obligations under current Anti-Money Laundering laws and Regulations and any applicable current local and international Tax laws; to identify misuse of our systems and any fraud or other illegal or unlawful activity or any other activity which is or may be contrary to our legal and regulatory compliance obligations.

Grand Z will also keep a copy of your gambling history and to employ measures to detect and identify problem gaming using analytical tools and/or behaviour monitoring systems, and to take steps to prevent further harm as per our legal obligation. We will also use such data to initiate customer interaction where we have concerns that your behaviour may indicate problem gambling.

Grand Z will also use and study your Usage Data, Technical Data and Account Data to target marketing activities for persons of the same age as you, if marketing consent is provided. This activity includes the processing of your age. We consider this to be in our legitimate interests to develop our products, form our marketing strategy, deliver website content and advertisement to users, to keep our website updated and relevant and overall to provide a better customer experience to our players. You have a right to object to such processing (see section Rights and Data Subject Requests).

We will further process your IP address in order to confirm your location, in line with our verification requirements under anti-money laundering laws, and to ensure that you do not have multiple accounts on our website in line with our obligations under gaming laws.

Your personal data will be processed automatically with the aim of evaluating certain personal aspects (profiling). We use profiling for the purposes of complying with our anti-money laundering and funding of terrorism obligations. As a rule, Grand Z does not make any kind of decisions based solely on automated processing as defined in Article 22 of the GDPR to establish and implement the business relationship, as there is always an element of human involvement in such decisions. If we use these procedures in individual cases, we will inform you of this separately, provided this is allowed by law.

Please know that Grand Z is using payment gateway providers, so no credit card or bank account information (other than the one you provide us for KYC verification purposes, and that Grand Z will process in order to comply with legal obligations) will be processed on our side.

5. DISCLOSING DATA SUBJECTS INFORMATION

Grand Z will only disclose your personal data to the third parties set out below for the purposes listed in the table above. We shall only disclose your personal data to third parties where lawful to do so including where Grand Z:
• Needs to share the information in order to provide you with the service and the disclosure is necessary in the process or needs to share the information in order to obtain services from third parties in order to provide you with the service.

• Have a legal duty to do so e.g. assisting with detecting and preventing fraud and crime or regulatory reporting or in relation to problem gaming;

• Have a legitimate interest for the purposes of litigation or asserting and defending our legal rights and interests or if we are required to disclose the information in response to legal process (for example, a court order, search warrant or subpoena);

• Have a legitimate business interest to do so for managing risk;

• Have been instructed by you to do so;

• Believe that Grand Z and its content is being used in the commission of a crime, including to report such criminal activity or to exchange information with other companies and organizations for the purposes of fraud or money-laundering protection;

• Have a reasonable and good faith belief that there is an emergency that poses a threat to the health, life and/or safety of you, another person or the public generally; and

• In order to protect the rights or property of Brightstar N.V., including to enforce our Terms and Conditions.

Grand Z will disclose your personal data to third parties which include:

• Regulators and other authorities as may be required by law or by courts of law;

• Law enforcement, government, courts, dispute resolution bodies, regulators and any party appointed or requested by regulators to carry out investigations or audits of our activities;

• Еxternal service providers and third-party vendors. We shall only disclose the personal data which is necessary for such third parties to deliver the required service. These include: MaxMind (provides IP intelligence to locate visitors and show them relevant content and ads, perform analytics, enforce digital rights and efficiently route internet traffic); Customer.io (email newsletter platform); Payment IQ (payment getaway provider); Professional advisors including lawyers, compliance officers, auditors and insurers; Kallik Investments Limited – Player Payment Processor and subsidiary of Brightstar N.V.

Grand Z will always make sure that the third party data processors are taking all the necessary security measures in order to protect your personal data and that they are in full GDPR compliance; Grand Z will also make sure that the information provided to each data processor is proportional and in line to the purpose of processing.

Where you are disputing payments or losses charged on your account, we shall disclose your KYC Data, Bank Account Data, Usage and Account Data to your bank to settle the dispute. Relevant authorities, employees of Brightstar N.V., in particular Customer support agents and other employees with relevant roles shall also have access to your personal data for the purpose of executing their duties and providing you with assistance and the service.

6. DATA TRANSFERS

Grand Z will only transfer your data to the European Union or to countries that have been deemed to provide an adequate level of protection for personal data by the European Commission. If processors from outside the EU countries are used, Grand Z will make sure that all data processors used are audited and found to be compliant to the European Data Protection standards.

7. MARKETING

Grand Z will send you information about our services which may be of interest to you. If you have consented to receive marketing, but changed your mind and decide you want to stop receiving the information and withdraw your consent, you have the right to opt out at any time from receiving such marketing material.

You may opt-out at any time as set out below:

1.Email [email protected] and say that you would like to opt-out

2.Tick the ‘opt-out’ option on your profile;

3.Press ‘unsubscribe’ on any marketing material received.

• Withdrawing your consent will not lead to any detriment to you or the relationship with Grand Z and you can choose to opt in or pot out anytime.

8. SECURITY

Grand Z is committed to ensuring that your information is secure. We have implemented measures and procedures to prevent unauthorised access or disclosure of your information. Likewise, we seek to keep confidential all information you send to us.

This site uses Secure Sockets Layer (SSL) to ensure secure transmission of your personal data. You should be able to see the padlock symbol in the status bar on the bottom right hand corner of the browser window. The URL address will also start with https:// depicting a secure webpage. SSL applies encryption between two points such as your PC and the connecting server.

In addition, we limit access to your personal data to those employees, agents, contractors and other third parties who have a business need to know. They will only process your personal data on our instructions and they are subject to a duty of confidentiality.

We have put in place procedures to deal with any personal data breach and will notify you and the relevant regulator of a breach where we are legally required to do so.

9. DATA RETENTION

Grand Z is committed to respecting the purpose limitation, data minimisation and storage limitation principles as defined under GDPR. As such, all data will be maintained for the duration of your relationship with us. Following termination of the relationship, the following data will be retained in the following manner:

Data TypeRetention PeriodRetention Basis
Identity Data, Contact Data, Technical Data, Usage Data, Account Data, KYC Data, Public Sources Data, Self-Exclusion Data and Financial DataFive yearsLegal obligation
Personal data may be held longer where required for a legal investigation or litigation or where there is a reasonable suspicion that a player has been involved in criminal activity by virtue of his/her gaming activities.
The five years’ retention period for self-excluded players shall begin to run from the lapse of the self-exclusion period.
Contact DataFive yearsLegitimate interest where needed for the establishment, exercise or defence of legal claims, disputes, and judicial investigations.
Account DataNine yearsAs required by the income tax laws to abide with our obligations thereunder
Record of Player Interactions in relation to Problem GamingUp to five years unless required further to fulfil other obligations/retention periodsAs required by gaming laws
Records of indefinite self-excluded Players confirming Problem gamingIndefiniteAs required by gaming laws
 

10. DATA SUBJECT RIGHTS UNDER GDPR

Grand Z will always keep GDPR in mind whenever working with personal data, and such, it is very important for us that you are familiar with your rights as a data subject.

Right to Transparent Information – We will always make sure to inform you in a clear manner on any personal data pertaining to you that may be processed by us. Such information is being provided to you in this Privacy Policy. Any additional questions can be sent to [email protected] and our data privacy team will answer as soon as possible.

Right of Access to Information – you have the right to request confirmation from us whether personal data relating to you is being processed and if so to access such personal data.

Right to lodge a request – you can always contact our DPO on [email protected]. If you would only like to receive information on a specific category of data, please indicate such category.

Right to Rectification – you have the right to request from us the rectification, without delay, of any inaccurate personal data pertaining to you.

You may change your data in the following manner:

  • Through your Profile: by accessing the ‘Account Details’ page on the platform;

  • By email: by emailing: [email protected]

Please note that your username may not be changed.

Right to Be Forgotten – you have the right to request from us the erasure of all personal data pertaining to you without delay, where the data has been processed with your consent as the basis for processing and/or where the processing is no longer lawful.

Right to Restrict Processing – you have the right to request from us the restriction of processing if: processing is unlawful; you are contesting the accuracy of data; the data is no longer required by the controller but you require us to keep it in order to establish, exercise, or defend a legal claim; or if you have previously objected to the processing. Once data is restricted, we cannot process it in any way other than to store it unless: we have your consent; or if it is required for the establishment, exercise, or defence of legal claims; or if it is for the protection of the rights of other persons; or if it is for reasons of important public interest.

Please note that this does not extend to personal data which is inferred or derived by us.

Right to Data Portability – you have the right to receive from us personal data which you have provided to us and to transmit that data to another controller without hindrance from us. This right applies where the data is being processed with your consent, or for the performance of a contract, and when processing is carried out by automated means.

Right to Object – you have the right to object at any time to the processing of personal data pertaining to you where the processing is based: on our legitimate interest; or the performance of a task in the public interest/exercise of official authority; or on direct marketing (including profiling); or on processing for purposes of scientific/historical research and statistics.

You also have the right to object to profiling based on our legitimate interests or on the performance of a task in the public interest/exercise of official authority.

You also have the right to object to automated decision making, including profiling, and therefore to not be subject to a decision which is based solely on automated processing, including profiling, which produces legal effects or significantly affects you.

11. DATA SUBJECT REQUIREMENTS

In order to protect the safety and security of your account Grand Z might need to request specific information from you upon receiving a request in line with the above rights to help us confirm your identity and ensure your right to access your personal data (or exercise any of your other rights). This is a security measures to ensure that personal data is not disclosed to any person who has no right to receive it.

Grand Z has an obligation to keep your data updated, and for this reason you may be asked about changes to your personal data at various intervals. You may help us in this process by informing us whenever your data has changed. You are entitled to ask us to modify your personal data if you ascertain that the personal data which we hold is not accurate or updated.

Since we require your data for the purposes of accepting and carrying out a relationship with you and fulfilling our contractual and legal obligations, should you choose not to provide Grand Z with such data, we might not be in a position to enter into a business relationship with you and fulfil the Terms and Conditions applicable between us and our obligations thereunder. Anti-money laundering obligations require us to verify your identity at certain intervals, for example, by means of your passport and to record your personal details. In order for us to be able to comply with this statutory obligation, we will ask you to provide us with the necessary information and documents and notify us without undue delay of any changes that may arise during the course of the business relationship. Should you choose not to provide us with such data, we might not be in a position to enter into or continue our business relationship and fulfil the Terms and Conditions applicable between us and our obligations thereunder as we would be in breach of our anti-money laundering and funding of terrorism obligations.

Reference is made to the Terms and Conditions whereby you have undertaken to provide us with certain personal data, including documentation, and to inform us of any changes to such data. In these circumstances, the provision of personal data is a contractual requirement.

You are never obliged to provide us with any data which we request on the basis of your consent, and your decision to not opt in or not to provide us with the consent will not influence the relation you have with Grand Z.

12. PROCESSING DATA THROUGH CONSENT

The processing of data highlighted above, with the exception of processing for marketing purposes does not require your consent as it relies on another legal basis.

We may however also request to process additional personal data on the basis of your consent. You are not obliged to give us your consent. Once you have granted us consent to the processing of personal data for an identified specific purpose, the processing becomes lawful on the basis of such consent. You can withdraw your consent at any time. Withdrawal of consent does not affect the legality of data processed prior to withdrawal.

You can withdraw your consent at any time by emailing [email protected] At the time of withdrawal of consent, we may determine that there is another legal ground allowing us to process your data; if this is the case, we shall inform you accordingly.

13. PRIVACY POLICIES OF LINKED WEBSITE AND ADVERTISERS

Grand Z may contain, from time to time, reference and linked third party Websites and advertisers. We are not responsible for the privacy practices or the content of such Websites. By clicking on those links you may be directed to those Websites which are not under the control of Brightstar N.V. and will need to comply with those respective third party privacy policies. If you have any questions about how these other Websites use your information, you should review their policies and contact them directly.

14. SURVEYS & CONTESTS

From time-to-time we collect information via surveys or for participation of any contests organized by us on the Site. Participation in these surveys and/or contests is completely voluntary, and any information provided to us will be provided based on your consent. You may choose whether to participate and thereby disclose any information about you. There will be no detriment towards you for not participating in such survey and contests. You may wish to revoke your consent at any time. By agreeing to participate in the survey, you agree to provide us with any such required information. Survey information will be used only for purposes of improving the use and customer satisfaction of the Site.

15. MISCELLANEOUS

**Changes to Privacy Policy ** - This policy was updated on 12/02/2024.

We retain the right to change our Privacy Policy at any time in case update is needed. Any new change shall apply from the date we publish them.

Any further updates will be listed on this web page, so please check back periodically.

If you are unhappy with the way in which we have processed your personal data, or you have any additional questions, you may contact our Data Protection Officer/Data Protection Representative by sending an email to [email protected]

You also have a right to lodge a complaint with the Office of the Information and Data Protection Commissioner, or other supervisory authority of your habitual residence, place of work or place of alleged infringement, and the right to seek an effective judicial remedy before courts.

Support