Privacy Policy
Data We Collect
Booming Games Limited, operating the platform accessible at gunspinner.com and holding licence MGA B2B-402/2017 issued by the Malta Gaming Authority, acts as the data controller in respect of personal data processed in connection with the use of this website and its associated services. The following categories of personal data are subject to collection and processing:
- Identification data: full legal name, date of birth, nationality, and government-issued identification document details, where required for verification and compliance purposes.
- Contact data: electronic mail address, telephone number, and postal address as provided during registration or subsequent account management procedures.
- Account credentials: username, encrypted password, and authentication-related information necessary for secure access to user accounts.
- Financial data: payment instrument details, transaction records, deposit and withdrawal history, and associated financial identifiers required for the processing of monetary transactions.
- Technical data: Internet Protocol address, browser type and version, operating system, device identifiers, session duration, pages accessed, referral sources, and other automatically collected technical parameters generated during interaction with the platform.
- Behavioural data: gameplay history, wagering patterns, preferences, and interaction logs recorded in the course of platform usage.
- Compliance data: information collected pursuant to obligations arising under applicable anti-money laundering legislation, know-your-customer requirements, and responsible gaming frameworks, including source of funds documentation and self-exclusion records.
- Communication data: records of correspondence exchanged between the data subject and the company via electronic mail, live chat, or other supported communication channels.
Personal data is collected directly from the data subject at the point of registration, through subsequent interactions with the platform, and, where lawfully permitted, from third-party verification and fraud prevention service providers.
Data Usage
Personal data collected by Booming Games Limited is processed exclusively for specified, explicit, and legitimate purposes in accordance with Regulation (EU) 2016/679 of the European Parliament and of the Council (General Data Protection Regulation) and applicable Maltese data protection legislation. The purposes for which data processing is carried out are enumerated as follows:
- Account administration and service provision: personal data is processed to enable the creation, maintenance, and administration of user accounts, to facilitate access to platform services, and to ensure the proper delivery of gaming and entertainment content.
- Identity verification and regulatory compliance: data is processed to fulfil obligations imposed under MGA licence conditions, anti-money laundering directives, know-your-customer requirements, and other applicable regulatory frameworks. Such processing is mandatory and constitutes a legal obligation of the data controller.
- Financial transaction processing: financial and identification data is processed to facilitate the execution of deposits, withdrawals, and other monetary transactions in a secure and accurate manner.
- Fraud prevention and platform security: technical and behavioural data is analysed to detect, investigate, and prevent fraudulent activity, unauthorised access, abuse of the platform, and other security incidents.
- Responsible gaming obligations: data is processed to monitor user behaviour in accordance with responsible gaming requirements, including the administration of self-exclusion measures, spending limit controls, and referrals to problem gambling support services where applicable.
- Customer support: communication data is processed to respond to enquiries, resolve disputes, and provide technical assistance to data subjects in an effective and timely manner.
- Legal proceedings and dispute resolution: personal data may be retained and processed to the extent necessary for the establishment, exercise, or defence of legal claims, including cooperation with competent regulatory and law enforcement authorities.
- Statistical analysis and service improvement: aggregated and, where feasible, anonymised data is processed for analytical purposes to assess platform performance, identify technical issues, and inform the development and improvement of services offered.
- Electronic communications: where express consent has been obtained or a legitimate interest has been established in accordance with applicable law, personal data may be processed for the purpose of transmitting service-related notifications, account updates, and, where applicable, promotional communications.
The legal bases upon which processing activities are conducted include the performance of a contract to which the data subject is party, compliance with a legal obligation, the legitimate interests of the data controller, and, where applicable, the explicit consent of the data subject. Processing carried out on the basis of consent may be withdrawn at any time without prejudice to the lawfulness of processing conducted prior to such withdrawal.
Security Measures
Booming Games Limited has implemented a comprehensive framework of technical and organisational measures designed to ensure a level of security appropriate to the risks associated with the processing of personal data. These measures are reviewed and updated on a periodic basis to reflect evolving technological standards and regulatory expectations.
- Encryption protocols: all data transmitted between the data subject and the platform is protected through the application of Transport Layer Security (TLS) encryption. Sensitive data stored within company systems is subject to encryption at rest utilising industry-standard cryptographic algorithms.
- Access controls: access to personal data is restricted on a strict need-to-know basis. Role-based access control mechanisms are enforced to ensure that only authorised personnel are permitted to access data relevant to their designated functions. Administrative access is subject to multi-factor authentication requirements.
- Pseudonymisation: where operationally appropriate, personal data is pseudonymised to reduce the risk of harm in the event of unauthorised access or data breach.
- Audit logging: access to and processing of personal data is subject to systematic logging. Audit trails are maintained and reviewed periodically to detect and investigate anomalous activity.
- Data minimisation: personal data is collected and retained only to the extent necessary for the fulfilment of the purposes for which it was collected. Retention periods are established in accordance with applicable legal requirements and the operational needs of the data controller.
- Third-party processor assessments: prior to engagement, third-party service providers with access to personal data are subject to due diligence assessments to verify the adequacy of their data protection practices. Data processing agreements are established with all such processors in accordance with Article 28 of the GDPR.
- Incident response procedures: documented procedures for the detection, assessment, containment, and notification of personal data breaches are maintained and tested on a regular basis. Where a breach is determined to present a risk to the rights and freedoms of data subjects, notification shall be made to the competent supervisory authority within the timeframe prescribed by applicable law.
- Staff training and awareness: all personnel engaged in the processing of personal data are required to complete mandatory data protection training. Contractual confidentiality obligations are imposed on all staff members and contractors with access to personal data.
- Infrastructure security: server infrastructure is hosted within secure data centre facilities equipped with physical access controls, environmental protections, and continuous availability monitoring. Network perimeters are protected through firewall systems, intrusion detection mechanisms, and regular vulnerability assessments.
Notwithstanding the measures described above, no method of data transmission or storage can be guaranteed to be entirely free from the risk of unauthorised access. Data subjects are advised to take appropriate precautions in the protection of their account credentials and to notify the data controller promptly upon becoming aware of any suspected unauthorised access to their account.
Your Rights
Data subjects whose personal data is processed by Booming Games Limited are entitled to exercise the following rights in accordance with the General Data Protection Regulation and applicable national data protection legislation. Requests for the exercise of any of the rights enumerated below shall be submitted in writing to the contact details specified herein and shall be responded to within the periods prescribed by applicable law.
- Right of access (Article 15 GDPR): data subjects are entitled to obtain confirmation as to whether personal data concerning them is being processed and, where such processing is confirmed, to receive a copy of the personal data undergoing processing together with supplementary information regarding the purposes, categories, recipients, retention periods, and safeguards applicable to such processing.
- Right to rectification (Article 16 GDPR): data subjects are entitled to request the correction of inaccurate personal data and the completion of incomplete personal data without undue delay. Upon receipt of a valid rectification request, the data controller shall take reasonable steps to verify the accuracy of the information provided before effecting any amendment.
- Right to erasure (Article 17 GDPR): data subjects are entitled to request the deletion of personal data concerning them where such data is no longer necessary for the purposes for which it was collected, where consent has been