Privacy Policy
Last Updated: January 2024.
1. Introduction and Scope
Koru Casino ("we," "us," "our," or "Company") is committed to protecting your privacy and ensuring you have a positive experience on our platform. This Privacy Policy explains how we collect, use, disclose, and otherwise process personal information in connection with our gaming services, website, and related applications.
This Privacy Policy applies to all users of the Koru Casino website, mobile applications, and any other digital services we provide (collectively, the "Services"). We are committed to complying with applicable privacy laws, including the Privacy Act 1988 (Cth) in Australia and the General Data Protection Regulation (GDPR) where applicable to our European users.
By accessing and using Koru Casino, you acknowledge that you have read, understood, and agree to be bound by this Privacy Policy. If you do not agree with our privacy practices, please do not use our Services.
2. Information We Collect
2.1 Information You Provide Directly
Account Registration Information: When you create an account with Koru Casino, we collect information necessary to establish and maintain your account, including your full name, date of birth, email address, physical address, telephone number, username, password, and country of residence.
Identity Verification Information: In accordance with anti-money laundering regulations and responsible gaming compliance, we collect and verify identity documents. This may include copies of your driver's license, passport, national identity card, or other government-issued identification. We may also collect proof of address documents such as utility bills, bank statements, or official correspondence.
Payment Information: When you make deposits or withdrawals, we collect payment method details including credit card numbers, bank account information, e-wallet identifiers, and transaction history. Payment processing is handled through secure third-party payment processors; however, we maintain records of transaction amounts and dates.
Customer Service Communications: If you contact our customer support team via email, live chat, or telephone, we collect and retain records of your communications, including the content of your messages and any personal information disclosed during these interactions.
Marketing Preferences: We collect information about your marketing preferences, including whether you wish to receive promotional emails, SMS messages, and notifications about special offers and new features.
Account Activity Data: We maintain detailed records of your gaming activity, including games played, amounts wagered, winnings, losses, deposits, withdrawals, and account balance history.
2.2 Information Collected Automatically
Technical Information: Our servers automatically collect technical data about your device and usage, including your IP address, browser type and version, operating system, device identifier, and the pages you visit within our Services.
Cookies and Similar Technologies: We use cookies, web beacons, pixels, and similar tracking technologies to enhance your user experience, understand how you interact with our Services, and for analytical purposes. This includes session cookies (which expire when you close your browser) and persistent cookies (which remain on your device).
Location Data: Depending on your device settings and applicable law, we may collect information about your geographic location to ensure compliance with regional restrictions, prevent unauthorized access from restricted jurisdictions, and personalize your experience.
Log Files: Our servers maintain log files containing information about your interactions with the platform, including access times, pages visited, referring URLs, and error reports.
Device Information: We collect information about your device hardware, including device model, operating system, unique device identifiers, mobile network information, and installed applications.
3. Purposes of Data Processing
3.1 Legitimate Business Purposes
Service Delivery and Account Management: We process your personal information to provide, maintain, and improve our gaming Services, process your transactions, manage your account, and respond to your requests and inquiries.
Regulatory Compliance and Legal Obligations: We process personal information to comply with applicable gaming regulations, anti-money laundering laws, know-your-customer requirements, tax obligations, and other legal requirements imposed by Australian authorities and relevant gaming commissions.
Fraud Prevention and Security: We use your information to detect, prevent, and address fraud, abuse, and security incidents. This includes analyzing patterns of behavior to identify suspicious activities and protect the integrity of our platform.
Responsible Gaming: We process information to implement responsible gaming measures, monitor for signs of problem gambling, and enforce betting limits and self-exclusion requests you may have established.
Customer Support: We use your information to provide customer service, respond to inquiries, resolve disputes, and maintain quality assurance.
Marketing and Promotional Communications: With your consent, we send you information about new games, promotions, special offers, tournament invitations, and other information about our Services.
Analytical and Statistical Purposes: We analyze aggregated and anonymized data to understand user behavior, improve our Services, develop new features, and conduct market research.
Legal Claims and Disputes: We may process your information as necessary to establish, exercise, or defend legal claims and resolve disputes.
3.2 Legitimate Interests
We rely on legitimate interests as a lawful basis for processing your information, including improving user experience, ensuring platform security, conducting business operations, and protecting our legal rights and interests.
4. Legal Basis for Processing
4.1 Under Australian Law
Under the Privacy Act 1988 (Cth) and the Australian Privacy Principles, we process personal information where:
- Processing is necessary to provide our Services and fulfill our contractual obligations to you.
- You have provided explicit consent for specific processing.
- We have a legal obligation to process the.
- It is necessary to protect your vital interests or those of.
- We have a legitimate interest in processing, and that interest is not overridden by your interests or fundamental.
4.2 Under GDPR (for European Users)
For users subject to GDPR, we process personal information based on the following lawful bases:
- Contractual Necessity: Processing necessary to perform our contract with you and provide our.
- Legal Obligation: Compliance with gaming regulations, anti-money laundering laws, and other legal.
- Legitimate Interests: Our business interests in maintaining and improving our platform, fraud prevention, and security, provided these interests do not override your fundamental.
- Consent: Where you have explicitly consented to specific processing activities, particularly for marketing communications and.
- Protection of Vital Interests: Protecting the safety and wellbeing of our.
5. Data Sharing and Disclosure
5.1 Service Providers and Processors
We engage third-party service providers to assist in operating our Services, including payment processors, identity verification providers, hosting providers, analytics companies, and customer support platforms. These processors are contractually obligated to protect your information and use it only for purposes necessary to provide services to us.
5.2 Legal and Regulatory Authorities
We may disclose personal information when required by law or when we have a good faith belief that disclosure is necessary to:
- Comply with legal obligations, court orders, or government.
- Enforce our Terms of Service and other.
- Protect the security and integrity of our.
- Protect the rights, privacy, safety, or property of Koru Casino, our users, or the.
5.3 Business Transfers
If Koru Casino is involved in a merger, acquisition, bankruptcy, dissolution, reorganization, or similar transaction or proceeding, your personal information may be transferred as part of that transaction. We will provide notice before your information becomes subject to a different privacy policy.
5.4 Aggregated and Anonymized Information
We may share aggregated, anonymized information that does not identify you with third parties for research, marketing, analytics, and other purposes without restriction.
5.5 Other Users
Certain information may be visible to other users of the Services, including your username, gaming activity statistics, and tournament rankings, depending on privacy settings and feature configurations.
6. International Data Transfers
6.1 Transfer Mechanisms
Koru Casino operates from Australia and processes data within Australian servers and systems. However, some of our service providers may be located in other countries. When we transfer personal information internationally, we implement appropriate safeguards in accordance with applicable law.
6.2 GDPR Compliance for International Transfers
For European users, we ensure that international transfers of personal information are made only where appropriate safeguards are in place, including Standard Contractual Clauses, adequacy decisions, or explicit consent. We conduct transfer impact assessments to ensure your data remains adequately protected.
6.3 Australian Privacy Principles
We ensure that any transfer of personal information outside Australia complies with the Privacy Act and our obligations as an Australian data controller.
7. Data Retention
7.1 Retention Periods
We retain personal information for the duration of your relationship with us and for as long as necessary to fulfill the purposes for which it was collected, including legal, accounting, and reporting requirements.
Account Information: Retained throughout your active account status and for seven years following account closure for regulatory compliance.
Transaction Records: Retained for a minimum of seven years in accordance with Australian tax and anti-money laundering regulations.
Identity Verification Documents: Retained for the duration of account activity plus seven years for compliance purposes.
Marketing Communications: Retained until you unsubscribe or request removal from our mailing lists.
Customer Service Records: Retained for a minimum of three years or as required by applicable regulations.
7.2 Secure Deletion
Upon expiration of required retention periods, we securely delete or anonymize personal information through industry-standard methods, unless legal obligations or legitimate interests require continued retention.
8. Your Rights and Choices
8.1 Australian Privacy Rights
Under the Privacy Act, you have the right to:
- Access your personal information held by us.
- Request correction of inaccurate or incomplete.
- Complain to the Office of the Australian Information Commissioner about privacy.
- Request that we not use your information for direct.
- Understand how and why we use your.
8.2 GDPR Rights (European Users)
Under GDPR, European users have the following rights:
Right of Access: You may request confirmation of whether we process your information and obtain a copy of your personal data.
Right to Rectification: You may request correction of inaccurate or incomplete information.
Right to Erasure: You may request deletion of your personal information in certain circumstances (the "right to be forgotten"), subject to our legal retention obligations.
Right to Restrict Processing: You may request that we limit how we use your information in certain situations.
Right to Data Portability: You may request your information in a structured, commonly used format and transmit it to another controller.
Right to Object: You may object to our processing of your information on grounds relating to your particular situation.
Right to Withdraw Consent: If we process information based on your consent, you may withdraw that consent at any time.
Rights Related to Automated Decision-Making: You have rights regarding automated decision-making and profiling that significantly affects you.
8.3 Exercise Your Rights
To exercise any of these rights, please contact us at [email protected] with a clear description of your request. We will respond within the timeframes required by applicable law (generally 30 days for Australian requests and up to 30 calendar days for GDPR requests, extendable to 60 days where necessary).
8.4 Marketing Preferences
You may opt out of promotional communications by:
- Clicking the unsubscribe link in any marketing.
- Updating your notification preferences in your account.
- Contacting our support team at [email protected].
- Replying STOP to SMS promotional.
Please note that even if you unsubscribe from marketing communications, we will continue to send you transactional messages related to your account and legal notices.
9. Security Measures
9.1 Technical Safeguards
We implement comprehensive security measures to protect your personal information from unauthorized access, disclosure, alteration, and destruction. These measures include:
- SSL/TLS encryption for data.
- Secure socket technology for all financial.
- Firewall protection and intrusion detection.
- Regular security audits and vulnerability.
- Secure password storage using industry-standard hashing.
- Multi-factor authentication options for account.
9.2 Organizational Safeguards
- Limited access to personal information restricted to authorized.
- Comprehensive employee privacy and security.
- Confidentiality agreements with all staff and.
- Regular security awareness.
- Incident response procedures and breach notification.
9.3 Limitations
While we implement robust security measures, no method of transmission over the internet or electronic storage is completely secure. We cannot guarantee absolute security of your information. You are responsible for maintaining the confidentiality of your account credentials.
10. Cookies and Tracking Technologies
10.1 Types of Cookies
Essential Cookies: Necessary for platform functionality, account management, and security features.
Analytical Cookies: Enable us to understand how users interact with our Services, identify user preferences, and improve functionality.
Preference Cookies: Remember your choices and settings to enhance your experience.
Marketing Cookies: Track your activity to deliver personalized promotional content and advertisements.
10.2 Cookie Management
Most web browsers allow you to control cookies through your browser settings. You can refuse cookies or receive alerts when cookies are placed. However, disabling certain cookies may affect the functionality of our Services. For GDPR compliance, we obtain explicit consent before placing non-essential cookies on your device.
10.3 Third-Party Tracking
Third-party services and analytics providers may also place cookies and tracking technologies on your device to measure advertising effectiveness and understand user behavior.
11. Children and Minors
11.1 Age Restrictions
Our Services are intended for individuals aged 18 years or older in Australia and in compliance with all jurisdictional age restrictions. We do not knowingly collect personal information from individuals under the legal gaming age in their jurisdiction.
11.2 Parental Controls
Parents and guardians concerned about their children's online activities are encouraged to use filtering software and parental control tools to prevent access to our Services.
12. Third-Party Links and Services
Our Services may contain links to third-party websites, applications, and services not operated by Koru Casino. This Privacy Policy applies only to information collected through our Services. We are not responsible for the privacy practices of third-party websites and applications, and we encourage you to review their privacy policies before providing personal information.
13. Your Responsible Gaming Rights
13.1 Self-Exclusion
We support your right to restrict your own gaming by offering self-exclusion options. If you wish to self-exclude, you may request this through your account settings or by contacting [email protected]. Once activated, your account will be restricted from further gaming activity for the requested period.
13.2 Account Limits
You may set deposit limits, loss limits, and time limits on your account to support responsible gaming practices. These limits help you manage your gaming expenditure.
13.3 Support Resources
We provide information and links to problem gambling support organizations, including Gambling Help Online and Lifeline Australia.
14. Complaint Resolution and Contact Information
14.1 Privacy Inquiries
If you have questions about this Privacy Policy, our privacy practices, or wish to exercise your privacy rights, please contact us:
Email: [email protected].
We will acknowledge your inquiry and respond within 30 days of receipt.
14.2 Complaints Under Australian Law
If you believe we have breached the Privacy Act or Australian Privacy Principles, you may lodge a complaint with the Office of the Australian Information Commissioner (OAIC). The OAIC investigates privacy complaints and can authorize remedies for privacy breaches.
14.3 Complaints Under GDPR
European users who believe we have violated GDPR rights may lodge a complaint with their national supervisory authority. You also have the right to seek judicial remedy through the courts.
15. Policy Updates and Changes
15.1 Amendments
We may update this Privacy Policy periodically to reflect changes in our practices, technology, legal requirements, and other factors. We will notify you of material changes by posting the updated policy on our website and updating the "Last Updated" date.
15.2 Continued Use
Your continued use of our Services following notification of changes constitutes your acceptance of the revised Privacy Policy. We encourage you to review this policy regularly to stay informed about how we protect your information.
16. Specific Provisions for Australian Users
16.1 Privacy Act Compliance
Koru Casino complies fully with the Privacy Act 1988 (Cth) and the Australian Privacy Principles. We have implemented appropriate practices and systems to ensure compliance with information handling obligations.
16.2 Direct Marketing
In accordance with the Privacy Act, we will not use your personal information for direct marketing purposes unless:
- You have consented to such use.
- We have a reasonable belief that you would welcome the.
- We provide a simple way for you to.
16.3 Government Agency Requests
We may be required by law enforcement or government agencies to disclose personal information. Where lawful, we will attempt to notify you of such requests.
17. Definitions
Personal Information: Information about an identified individual or an individual who is reasonably identifiable.
Processing: Any operation performed on information, including collection, recording, organization, structuring, storage, adaptation, retrieval, consultation, use, disclosure, transmission, or deletion.
Data Controller: The entity determining purposes and means of processing personal information (Koru Casino).
Data Processor: An entity processing personal information on behalf of the controller.
Data Subject: The individual to whom personal information relates.
Koru Casino.
Support: [email protected].
Effective Date: January 2024.