At Trino Casino, we manage trinoo.de and we accept protecting the personal data of our German players conscientiously. As a licensed entertainment platform, we’ve established our operations to meet the strict standards of the General Data Protection Regulation (GDPR) and the German Federal Data Protection Act (BDSG). This document explains exactly how we collect, retain, process, and secure your information when you access our website, participate in games, or communicate with our affiliate systems. We hold transparency is essential for a trusting relationship. By laying out our data handling practices clearly, we aim you to remain confident that your sensitive financial details and personal identifiers remain in a secure digital environment, managed by a responsible data controller that respects local laws and jurisdictional boundaries.

1. Určení správce údajů a právní důvod zpracování

We serve as the data controller for all personal data gathered via Trino Casino at trinoo.de, designed specifically for users in Germany. Our legal team operates from a registered office inside the European Economic Area, making us fully bound by GDPR enforcement. When we process your data, we rely on six defined lawful bases. In most cases, we process your data to meet our contractual duties—such as accepting bets, handling withdrawals, and maintaining your account. We also employ legitimate interest for analytics and security actions, including fraud detection algorithms and network integrity checks, as long as these do not outweigh your fundamental rights and freedoms. When required by law, particularly under anti-money laundering regulations and German gambling ordinances, processing occurs due to a legal obligation. Regarding marketing communications, such as our affiliate program, we rely on your explicit consent, which you can withdraw anytime without any effect on the essential services we deliver.

7. Cookie Handling and Monitoring Technologies for Compliance with Laws

Our website employs various digital markers, and our consent management system ensures that no unnecessary trackers fire until a German visitor gives explicit consent through our comprehensive preference center. Required session cookies, which do not save personal data but maintain your play session and security tokens operational, are free from permission requirements under the Electronic Privacy Directive as implemented in German law. For ongoing analytics and affiliate tracking cookies, we implement server‑side tagging where practicable to minimize frontend exposure. Our affiliate tracking code runs on a first-party data model to circumvent contemporary browser limitations, allowing correct tracking without aggressive tracking scripts that are forbidden under German internet law. We’ve grouped all scripts with detailed descriptions of their purpose, length, and the outside providers involved, so you can modify your preferences at any time. Refusing marketing cookies doesn’t harm the functionality of the casino lobby or payment systems. That shows our privacy-first approach: essential services stay entirely usable regardless of approval selections you choose.

2. Groups of Player Details Collected During Registration and Gaming

To offer a seamless entertainment experience that complies with German regulations, we obtain a few specific categories of personal data, solely what is required. During account creation, we ask for identification details: your legal first and last name, residential address with postal code, verified email address, and date of birth to ensure you fulfill the strict age minimum imposed by German regulators. When you start playing, we handle financial transaction data—deposit amounts, withdrawal methods, partial payment card numbers encrypted with TLS, and e-wallet identifiers. Our systems automatically log technical device data like your IP address, which we geographically filter to ensure you’re in a permitted location, along with browser fingerprint hashes and operating system specs. We also track usage patterns and game session logs, logging bet history and time spent playing, so we can fulfill our responsible gaming obligations. We do not collect special categories of sensitive data except when you voluntarily give that information during a responsible gaming self-assessment or a support inquiry.

4. Data Preservation Plans and Data Masking Strategies

We do not retain your personal data indefinitely. We follow a strict storage limitation principle. Active customer accounts hold data for the duration of the business relationship, from the moment you register until you formally close the account. After account closure, a holding period kicks in, driven mostly by German tax legislation and anti-money laundering rules. Transactional logs, identification documents collected under Know Your Customer protocols, and wagering history are securely archived for ten years from the end of the calendar year of the last transaction. Once that statutory retention window concludes, we permanently destroy or irreversibly anonymize the records so re-identification becomes technically impossible. Web server log data that contains IP addresses gets truncated after a strict thirty‑day cycle to reduce security risks. For accounts that go dormant—no activity but not closed—we send a proactive reminder before the dormancy threshold, so we can ask for renewed consent or start the deletion process, always in line with the storage limitation principle.

3. Detailed Processing Activities Related to the Affiliate Programme

Our affiliate network, available on our legal and affiliates hub, operates as a separate data processing area. We act as a joint controller together with our marketing partners. When a German webmaster or content creator enrolls in our partner program, we obtain business details like tax identification numbers, bank account information for paying commissions, and traffic source analytics. Our tracking mechanism employs first‑party cookies dropped via a unique affiliate link, which enables us to attribute referred traffic to the correct partner account without capturing the browsing history of unregistered visitors. We manage referred player data in a pseudonymized format for commission calculation, so the affiliate sees aggregated performance numbers rather than individual player identities. We examine player activity logs against traffic sources to catch bonus abuse or fake incentivized traffic; this is based on our contractual and legitimate business interests. We have a strict affiliate code of conduct that prevents partners from targeting self-excluded individuals or using unauthorized direct marketing that could jeopardize the privacy expectations of the German audience.

6. Exercising Your Prerogatives Under Germany’s and European Union Regulations

If you are a resident of Germany, you have a collection of prerogatives that we keep easy to use. You are able to lodge a subject access request at your convenience. We then have to confirm whether we store your data and give you a copy in a organized, widely adopted, machine‑readable layout within 30 days. The right to rectification lets you update obsolete or inaccurate profile data without waiting, which is crucial for smooth payment processing. In some cases, you are entitled to a limitation of operations, particularly if you dispute the accuracy of data while we confirm it. The right to removal, commonly known as the “right to be forgotten,” applies when the data is no longer needed for the original goal, though statutory retention duties may temporarily override this petition. You are also granted the right to information portability for information furnished under consent or contractual terms, so you are able to shift your transaction record to a alternative provider. You possess an total right to oppose direct marketing, and you are able to contest to processing based on legitimate interests, which we shall weigh against our own justifiable bases. Appeals can be filed straight with the privacy regulator of your German state if you suspect a breach has happened.

5. International Movements and Technical Protection Measures

Our main data processing systems reside in secure data centers within the European Union, but sometimes we require sub-processors in other countries. In these limited cases, we guarantee the equivalent standard of safeguarding by using Standard Contractual Clauses endorsed by the European Commission, along with a thorough Transfer Impact Assessment. To protect your financial data from unauthorized access during communication, we implement Transport Layer Security (TLS 1.3) encryption across all endpoints, refusing old cipher suites. At rest, personal data inside our managed database clusters is secured by AES‑256 encryption, and access to decryption keys is confined to a isolated privileged access management system. We run regular vulnerability scans, required penetration tests, and strict logical access controls so exclusively the personnel who need it can see your data. We employ a dedicated Data Protection Officer you can access through our platform, and we keep an incident response plan that mandates us to alert the relevant German supervisory authority within 72 hours if a personal data breach could put your rights at risk.

Frequently Asked Questions

How does Trino Casino check my age in line with German regulations?

We use a multi-tiered system: computerized checks against national databases and manual document review. When you create an account, you must submit your national ID card or passport through an encrypted portal. Our compliance team checks this with the Schufa identity service to verify legal age. If something does not align, we temporarily restrict the account until a video identification call with a certified agent can clear things up, all in line with the German Interstate Treaty on Gambling.

Is it possible that my personal data be disclosed with the affiliate who recommended me?

No. Our affiliate programme operates with a strict aggregation firewall. We never share your name, contact details, or payment records with the referring affiliate. The partner only sees a pseudonymized dashboard with confirmed registration counts and a statistical summary of net gaming revenue. Our affiliate agreements explicitly prohibit them from attempting to identify individual players. This maintains your gameplay completely separate from the marketing channel that brought you to Trino Casino.

In what way can I permanently withdraw my marketing consent?

Go to “Communication Settings” in your account dashboard and turn off promotional channels. Every marketing email we bild.de send has a one‑click unsubscribe link at the bottom that works right away. To withdraw consent for postal mail or SMS, contact our Data Protection Officer through the support ticket system. We’ll stop direct marketing within at most 48 hours after receiving your request.

What occurs to my data if Trino Casino ceases operations?

If business ever stops, we are legally required to notify the competent German data protection authority and all active users in advance. Mandatory transactional logs and identification records will be securely transferred to a certified archival service or handed over to the responsible regulatory body for as long as the law demands. Any data that isn’t mandatory gets securely destroyed using cryptographic wiping techniques before the closure of our servers is finalized.

Does Trino Casino use automated decision-making for payments?

We use a limited automated profiling system to flag possible fraud or bonus abuse. If the system blocks a withdrawal, we’re required by law to involve a human. Our financial risk team manually checks every flagged transaction before we tell you the final decision. You can challenge that decision, give your side, and ask for a full manual review by our risk management specialists.

What is the process to receive a complete record of my stored data?

Email us from the address linked to your account to our Data Protection Officer, place “SAR” in the subject line. We’ll confirm your identity with a two‑factor verification. Following that, we compile your data from all systems—chat logs, game history, identity documents—and prepare a digitally signed PDF and a machine‑readable JSON file, that you will get within one calendar month.

2

2