Data Protection & Privacy
Information Collection
The following categories of personal data are subject to collection and processing by Booming Games Limited, operating under Malta Gaming Authority licence reference MGA B2B-402/2017, in connection with the provision of services accessible via the gunspinner.com platform:
- Identification Data: Full legal name, date of birth, nationality, and government-issued identification document details, as required for the fulfilment of statutory identity verification obligations.
- Contact Data: Electronic mail address, telephone number, and residential or correspondence address, collected for the purpose of account administration and service-related communications.
- Financial Data: Payment instrument details, transaction history, and related financial records, processed in accordance with applicable anti-money laundering and counter-terrorist financing regulatory requirements.
- Technical Data: Internet Protocol address, browser type and version, operating system, device identifiers, session duration, and navigational behaviour data, collected automatically upon interaction with the platform.
- Account Data: Username, account credentials in encrypted form, preferences, and interaction history pertaining to the use of services offered through the platform.
- Compliance Data: Records pertaining to responsible gambling assessments, self-exclusion declarations, and any documentation submitted in satisfaction of regulatory due diligence requirements.
Personal data is collected by means of direct submission by the data subject, automated technical collection mechanisms including cookies and similar tracking technologies, and, where permissible under applicable law, from authorised third-party verification and data enrichment providers. The collection of personal data is conducted solely to the extent necessary for the purposes specified herein, in accordance with the principle of data minimisation as established under Regulation (EU) 2016/679 of the European Parliament and of the Council (the General Data Protection Regulation).
Use of Information
Personal data collected in the manner described above is processed by Booming Games Limited exclusively for the following specified, explicit, and legitimate purposes:
- Contract Performance: The processing of identification, contact, and account data is carried out to the extent necessary for the establishment, administration, and termination of the contractual relationship between the data controller and the data subject, including the creation and maintenance of user accounts and the provision of platform services.
- Regulatory Compliance: Personal data, including identification and financial data, is processed in fulfilment of legal obligations imposed upon the data controller by the Malta Gaming Authority, applicable anti-money laundering legislation, and other mandatory statutory frameworks. Such processing constitutes a legal obligation within the meaning of Article 6(1)(c) of the General Data Protection Regulation.
- Fraud Prevention and Security: Technical and account data are processed for the purpose of detecting, investigating, and preventing fraudulent activity, unauthorised access, and other conduct that may constitute a breach of applicable laws or the terms and conditions governing use of the platform.
- Responsible Gambling: Compliance data pertaining to player behaviour and self-declared limitations is processed for the purpose of implementing responsible gambling measures and fulfilling associated obligations under the applicable gaming licence conditions.
- Platform Improvement and Analytics: Technical data and navigational behaviour records may be processed on the basis of the legitimate interests of the data controller for the purpose of analysing platform performance, identifying technical deficiencies, and improving the quality of services offered, provided that such interests are not overridden by the fundamental rights and freedoms of the data subject.
- Communications: Contact data is utilised for the delivery of transactional and service-related communications, including notifications relating to account status, security alerts, and regulatory disclosures. Direct marketing communications, where conducted, are subject to the prior, freely given, specific, informed, and unambiguous consent of the data subject.
Personal data shall not be processed for purposes incompatible with those specified at the time of collection. Data shall not be sold, rented, or otherwise transferred to third parties for their independent commercial purposes without the explicit consent of the data subject, except where such disclosure is required by law or by order of a competent regulatory or judicial authority.
Data Security
Booming Games Limited implements and maintains a comprehensive framework of technical and organisational measures designed to ensure a level of security appropriate to the risk presented by the processing activities carried out in connection with the gunspinner.com platform. Such measures are established in accordance with the requirements of Article 32 of the General Data Protection Regulation and the technical security standards mandated by the Malta Gaming Authority.
The technical measures implemented include, but are not limited to, the following:
- Encryption: Personal data is subject to encryption both in transit and at rest, utilising industry-standard cryptographic protocols including Transport Layer Security (TLS) for data transmitted over public networks and Advanced Encryption Standard (AES) protocols for stored data.
- Access Controls: Access to systems and databases containing personal data is restricted on a strictly need-to-know basis and is enforced through role-based access control mechanisms, multi-factor authentication requirements, and audit logging of all access events.
- Network Security: The platform infrastructure is protected by firewall systems, intrusion detection and prevention mechanisms, and regular penetration testing conducted by qualified independent security professionals.
- Data Pseudonymisation: Where appropriate and technically feasible, personal data is subject to pseudonymisation measures to reduce the risks associated with unauthorised access or accidental disclosure.
- Vulnerability Management: Software systems and infrastructure components are subject to regular security updates, patch management procedures, and scheduled vulnerability assessments.
The organisational measures implemented include the following:
- Staff Training: All personnel with access to personal data are required to undergo periodic data protection and information security training and are bound by contractual confidentiality obligations.
- Data Processing Agreements: All third-party processors engaged by Booming Games Limited are required to execute data processing agreements that impose equivalent security obligations and restrict the use of personal data to those purposes specified by the data controller.
- Incident Response: A formal data breach response procedure is maintained, providing for the timely identification, containment, assessment, and notification of personal data breaches in accordance with the obligations established under Article 33 and Article 34 of the General Data Protection Regulation.
- Data Retention: Personal data is retained only for the period necessary to fulfil the purposes for which it was collected, or for such longer period as is required by applicable law or regulatory obligation. Upon expiry of the applicable retention period, personal data is securely deleted or anonymised in accordance with established internal procedures.
Notwithstanding the measures described herein, the data subject is advised that no method of electronic transmission or digital storage can be guaranteed to be unconditionally secure. Booming Games Limited is committed to the continuous review and enhancement of its security framework in response to evolving technological and regulatory developments.
User Rights
Data subjects whose personal data is processed by Booming Games Limited in connection with the gunspinner.com platform are vested with the following rights under the General Data Protection Regulation, subject to the conditions, limitations, and exemptions prescribed therein:
- Right of Access (Article 15 GDPR): The data subject is entitled to obtain confirmation as to whether personal data relating to them is being processed, and, where such is the case, to obtain access to that personal data together with information regarding the purposes of processing, the categories of data concerned, the recipients or categories of recipients to whom the data has been disclosed, the envisaged retention period, and such other information as is prescribed by applicable law.
- Right to Rectification (Article 16 GDPR): The data subject is entitled to require the correction of inaccurate personal data relating to them without undue delay. Having regard to the purposes of the processing, the data subject is further entitled to have incomplete personal data completed, including by means of a supplementary statement.
- Right to Erasure (Article 17 GDPR): The data subject is entitled to require the deletion of personal data relating to them in circumstances where such data is no longer necessary in relation to the purposes for which it was collected, where consent upon which processing was based has been withdrawn and no other legal ground for processing exists, or where the data has been unlawfully processed, subject to applicable legal retention obligations that may override this right.
- Right to Restriction of Processing (Article 18 GDPR): The data subject is entitled to require that the processing of their personal data be restricted in circumstances specified under applicable law, including where the accuracy of the data is contested, where processing is unlawful but erasure is not requested, or where the data is required for the establishment, exercise, or defence of legal claims.
- Right to Data Portability (Article 20 GDPR): Where processing is carried out on the basis of consent or for the performance of a contract, and where processing is carried out by automated means, the data subject is entitled to receive personal data relating to them in a structured, commonly used, and machine-readable format, and to transmit such data to another controller without hindrance from Booming Games Limited.
- Right to Object (Article 21 GDPR): The data subject is entitled to object, on grounds relating to their particular situation, to the processing of personal data relating to them which is carried out on the basis of the legitimate interests of the data controller. Where personal data is processed for direct marketing purposes, the data subject is entitled to object to such processing at any time without the requirement to provide justification.
- Rights in Relation to Automated Decision-Making (Article 22 GDPR): The data subject is entitled not to be subject to a decision based solely on automated processing, including profiling, which produces legal effects concerning them or similarly significantly affects them, except where such processing is necessary for the entry into or performance of a contract, is authorised by applicable law, or is based on the data subject's explicit consent.
- Right to Withdraw Consent: Where processing is based upon the consent of the data subject, such consent may be withdrawn at any time without affecting the lawfulness of processing carried out prior to its withdrawal.
- Right to Lodge a Complaint: The data subject is entitled to lodge a complaint with the competent supervisory authority in the Member State of their habitual residence, place of work, or place of the alleged infringement. In Malta, the competent supervisory authority is the Office of the Information and Data Protection Commissioner (IDPC).
Requests pertaining to the exercise of any of the rights described above shall be submitted in writing to the contact address specified below. Booming Games Limited undertakes to respond to all verified requests within the timeframes prescribed by applicable data protection legislation. The data controller reserves the right to verify the identity of the requesting party prior to processing any such request. Where requests are manifestly unfounded or excessive, a reasonable administrative fee may be charged or the request may be declined, in accordance with the provisions of Article 12(5) of the General Data Protection Regulation.
Contact
All enquiries, requests, and formal correspondence relating to the processing of personal data by Booming Games Limited, including requests for the exercise of data subject rights and notifications of potential data protection concerns, shall be directed to the data controller at the following electronic mail address:
Electronic correspondence: [email protected]
Booming Games Limited, as the data controller responsible for the processing of personal data in connection with the gunspinner.com platform, is a company incorporated and operating under the laws of Malta, holding gaming licence reference MGA B2B-402/2017 issued by the Malta Gaming Authority. All formal correspondence submitted to the data controller shall be treated in confidence and in accordance with the obligations imposed upon the data controller under applicable data protection legislation.