Logo grosvenor casino torquay q6trjt
Banner grosvenor casino torquay iwjax8

This document explains how Grosvenor Casino Torquay handles your personal data.

Privacy Policy Grosvenor Casino Torquay

1. Introduction

This Privacy Policy sets out how Grosvenor Casino Torquay (the “casino”) collects, processes, stores, and protects personal data relating to individuals who visit the premises, use services, or otherwise interact with the casino. This document constitutes a formal notice under the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018.

By using the services of the casino or providing personal data, you acknowledge that you have read and understood the terms of this Privacy Policy. This policy may be updated periodically to reflect changes in applicable law, regulatory guidance, or internal procedures. The version published here is the operative version.

2. Data Controller

Grosvenor Casino Torquay acts as the data controller in respect of personal data processed under this policy. As data controller, the casino determines the purposes and means by which personal data is processed.

Any queries regarding this policy or the exercise of data subject rights should be directed to the designated compliance contact using the details provided in Section 9 of this document.

3. Personal Data Collected

The casino collects and processes the following categories of personal data:

  • Identification data: full name, date of birth, residential address, nationality, and copies of identity documents such as passports or driving licences.
  • Account and transaction data: records of account registration, account activity, and financial transaction history where applicable.
  • Gaming and betting activity: records of gaming sessions, betting patterns, and participation in gaming activities on the premises.
  • Technical and device data: where applicable, IP address, browser type, and device identifiers when you interact with any digital services.
  • Communications data: records of correspondence, enquiries, and complaints submitted to the casino.
  • Special category data: in limited circumstances, special category data may be processed, including health-related information or indicators relevant to responsible gambling assessments. Such data is processed only where required by law or regulation, or where necessary to protect the well-being of an individual.

Personal data is processed for the following purposes and on the following legal bases:

  • Provision of services and account management
    • Legal basis: performance of a contract
  • Compliance with anti-money laundering obligations
    • Legal basis: legal obligation
  • Compliance with responsible gambling requirements
    • Legal basis: legal obligation / substantial public interest
  • Fraud detection and crime prevention
    • Legal basis: legal obligation / legitimate interests
  • Identity verification and age verification
    • Legal basis: legal obligation
  • Internal analytics and service improvement
    • Legal basis: legitimate interests
  • Direct marketing and customer profiling
    • Legal basis: legitimate interests (subject to your right to object)
  • Responding to regulatory or law enforcement requests
    • Legal basis: legal obligation

Consent is not relied upon as the sole legal basis for processing, except where explicitly indicated. Where consent is the applicable basis, you retain the right to withdraw it at any time. Withdrawal of consent does not affect the lawfulness of processing carried out prior to withdrawal, but may affect the ability to provide or continue to provide certain services.

5. Data Sharing and Third-Party Disclosure

Personal data may be shared with third parties in the following circumstances:

  • Regulatory and law enforcement authorities: disclosure may be made to the Gambling Commission, law enforcement agencies, and other competent authorities where required by law or where a valid statutory request is received, supported by appropriate legal authority such as a warrant or court order.
  • Fraud prevention and risk agencies: data may be shared with agencies responsible for detecting and preventing financial crime, money laundering, and fraud.
  • IT and operational service providers: third-party providers may be engaged for hosting, technical support, and operational functions. Such providers process data only on documented instructions and are bound by appropriate data processing agreements.
  • Responsible gambling organisations: where problem gambling behaviour is identified or suspected, relevant data may be shared with third-party organisations that assist in delivering safer gambling interventions.
  • Group companies: where applicable, personal data may be shared within the corporate group for compliance, operational, or administrative purposes.

Personal data is not sold to third parties. Any sharing of data is conducted on the basis of a lawful ground and is limited to what is necessary for the stated purpose.

6. Data Retention

Personal data is retained only for as long as is necessary to fulfil the purposes for which it was collected, or as required by applicable law or regulation. In particular:

  • Records required under the Money Laundering Regulations 2017 are retained for a minimum period of five years from the end of the business relationship or the date of the transaction.
  • Account and gaming records are retained for the period required to satisfy regulatory obligations and to resolve any disputes or legal claims.
  • Where no specific statutory retention period applies, a retention period proportionate to the purpose of processing is applied, and data is reviewed regularly for deletion or anonymisation.

7. Your Rights as a Data Subject

Under UK GDPR, individuals have the following rights in relation to their personal data:

  • Right to be informed: to receive clear information about how personal data is processed, as set out in this policy.
  • Right of access: to submit a Subject Access Request to obtain a copy of the personal data held, together with information about how it is used and with whom it is shared.
  • Right to rectification: to request correction of inaccurate or incomplete personal data.
  • Right to erasure: in certain circumstances, to request deletion of personal data. This right is subject to limitations where retention is required by law.
  • Right to restriction of processing: to request that processing of personal data is limited in specified circumstances.
  • Right to data portability: where processing is based on consent or contract and carried out by automated means, to request that personal data be provided in a structured, commonly used, machine-readable format.
  • Right to object: to object to processing based on legitimate interests, including direct marketing and profiling. Where an objection is made to direct marketing, such processing will cease without delay.
  • Rights related to automated decision-making: where decisions are made based solely on automated processing, including profiling, that produce legal or similarly significant effects, to request human review, to express a point of view, and to obtain an explanation of the decision.

To exercise any of these rights, contact details in Section 9 should be used. Verified requests will be responded to within one calendar month. In complex cases, this period may be extended by a further two months; in such cases, notification of the extension will be provided.

8. Security of Personal Data

Appropriate technical and organisational measures are implemented to protect personal data against unauthorised access, loss, destruction, alteration, or disclosure. These measures are reviewed and updated in line with developments in applicable standards and regulatory guidance. Access to personal data is restricted to personnel who require it for legitimate operational or compliance purposes.

9. Contact and Complaints

For queries relating to this Privacy Policy, to exercise data subject rights, or to raise a concern about how personal data is handled, contact the compliance team in writing at the address of Grosvenor Casino Torquay or by using the contact details available at the premises.

If a concern is not resolved satisfactorily, a complaint may be lodged with the Information Commissioner’s Office (ICO), the supervisory authority for data protection in the United Kingdom. The ICO can be contacted at ico.org.uk or by telephone on 0303 123 1113.

10. Changes to This Policy

This Privacy Policy may be amended at any time. Where changes are material, reasonable steps will be taken to bring them to your attention. Continued use of the services following notification of changes constitutes acceptance of the revised policy. Periodic review of this document is recommended in order to remain informed about the processing of personal data.