At Trino Casino, we manage trinoo https://trinoo.de/legal-and-affiliates/.de and we take protecting the personal data of our German players seriously. As a licensed entertainment platform, we’ve developed our operations to satisfy the strict standards of the General Data Protection Regulation (GDPR) and the German Federal Data Protection Act (BDSG). This document clarifies exactly how we collect, retain, process, and secure your information when you use our website, engage in games, or interact with our affiliate systems. We believe transparency is crucial for a trusting relationship. By outlining our data handling practices clearly, we want you to remain confident that your sensitive financial details and personal identifiers remain in a secure digital environment, handled by a responsible data controller that adheres to local laws and jurisdictional boundaries.
1. Identifikace správce údajů a právní základ zpracování
We act as the data controller for all personal details collected through Trino Casino at trinoo.de, which is customized for German users. Our legal department is based in a registered office within the European Economic Area, so we are fully subject to GDPR enforcement. For processing your data, we depend on six specified lawful bases. Most of the time, we process your data to fulfill our contractual obligations—like taking bets, processing withdrawals, and keeping your account running. We also employ legitimate interest for analytics and security actions, including fraud detection algorithms and network integrity checks, as long as these do not outweigh your fundamental rights and freedoms. When required by law, particularly under anti-money laundering regulations and German gambling ordinances, processing occurs due to a legal obligation. Regarding marketing communications, such as our affiliate program, we rely on your explicit consent, which you can withdraw anytime without any effect on the essential services we deliver.
5. Global Transmissions and System Security Measures
Our principal data processing systems are located in safe data centers inside the European Union, but sometimes we must utilize sub-processors in other countries. In such limited cases, we assure the identical standard of protection by employing Standard Contractual Clauses authorized by the European Commission, along with a comprehensive Transfer Impact Assessment. To secure your financial data from illegitimate access during transmission, we implement Transport Layer Security (TLS 1.3) encryption across all endpoints, rejecting outdated cipher suites. At rest, personal data inside our managed database clusters is secured by AES‑256 encryption, and access to decryption keys is confined to a segregated privileged access management system. We perform ongoing vulnerability scans, required penetration tests, and rigorous logical access controls so exclusively the personnel who must have it can view your data. We employ a specialized Data Protection Officer you can reach through our platform, and we have an incident response plan that requires us to notify the pertinent German supervisory authority within 72 hours if a personal data breach could place your rights at risk.
2. Types of User Information Obtained at Sign-Up and Playing
To provide a flawless entertainment experience that meets German regulations, we obtain a few specific categories of personal data, only what’s really needed. During account creation, we request identification details: your legal first and last name, residential address with postal code, verified email address, and date of birth to ensure you fulfill the strict age minimum established by German regulators. When you commence playing, we process financial transaction data—deposit amounts, withdrawal methods, partial payment card numbers encrypted with TLS, and e-wallet identifiers. Our systems record technical device data like your IP address, which we geographically filter to verify you’re in a permitted location, along with browser fingerprint hashes and operating system specs. We also record usage patterns and game session logs, documenting bet history and time spent playing, so we can fulfill our responsible gaming obligations. We do not collect special categories of sensitive data except when you voluntarily give that information during a responsible gaming self-assessment or a support inquiry.
6. Using Your Prerogatives Pursuant to German and European Union Regulations
For residents of Germany, you have a set of rights that we keep simple to enforce. You may file a subject access request at any time. We are then required to verify whether we store your information and give you a copy in a structured, standard, machine‑readable format within 30 days. The right to amendment enables you to update outdated or incorrect profile details without hesitation, which is essential for seamless payment handling. In some cases, you are entitled to a restriction of processing, especially if you challenge the accuracy of data while we verify it. The right to erasure, frequently referred to as the “right to be forgotten,” is applicable when the data is no longer required for the primary objective, though mandatory storage requirements may temporarily overrule this demand. You additionally possess the right to data portability for information furnished under authorization or contract, so you are able to shift your transaction record to a alternative provider. You have an unconditional entitlement to object to direct marketing, and you are able to contest to data handling based on lawful interests, which we shall weigh against our own justifiable bases. Grievances can be submitted straight with the data oversight body of your German federal state if you suspect a breach has taken place.
4. Data Preservation Plans and Data Masking Strategies
We don’t keep your personal data forever. We follow a strict storage limitation principle. Active customer accounts store data for the duration of the business relationship, from the moment you register until you formally close the account. After account closure, a holding period begins, driven mostly by German tax legislation and anti-money laundering rules. Transactional logs, identification documents collected under Know Your Customer protocols, and wagering history are securely archived for ten years from the end of the calendar year of the last transaction. Once that statutory retention window expires, we permanently destroy or irreversibly anonymize the records so re-identification becomes technically impossible. Web server log data that contains IP addresses gets truncated after a strict thirty‑day cycle to reduce security risks. For accounts that go dormant—no activity but not closed—we send a proactive reminder before the dormancy threshold, so we can ask for renewed consent or start the deletion process, always in line with the storage limitation principle.
3. Specific Processing Activities Connected with the Affiliate Programme
Our affiliate network, reachable via our legal and affiliates hub, functions as a separate data processing area. We function as a joint controller together with our marketing partners. When a German webmaster or content creator registers for our partner program, we gather business details like tax identification numbers, bank account information for paying commissions, and traffic source analytics. Our tracking mechanism uses first‑party cookies dropped via a unique affiliate link, which lets us attribute referred traffic to the correct partner account without capturing the browsing history of unregistered visitors. We process referred player data in a pseudonymized format for commission calculation, so the affiliate sees aggregated performance numbers rather than individual player identities. We examine player activity logs against traffic sources to catch bonus abuse or fake incentivized traffic; this is based on our contractual and legitimate business interests. We have a strict affiliate code of conduct that prohibits partners from targeting self-excluded individuals or using unauthorized direct marketing that could compromise the privacy expectations of the German audience.
7. Cookie Management and Tracking Tools for Compliance with Laws
Our website employs multiple tracking markers, and our consent management system makes sure that no non-essential trackers fire until a German user gives active consent through our detailed settings panel. Essential session cookies, which do not save private data but keep your gaming session and security credentials operational, are excluded from permission requirements under the Electronic Privacy Directive as applied in German law. For persistent analytics and affiliate attribution cookies, we employ backend tagging where practicable to limit browser-side exposure. Our affiliate tracking code runs on a first-party data model to circumvent current browser restrictions, permitting precise attribution without invasive fingerprinting scripts that are forbidden under German digital regulations. We’ve categorized all programs with comprehensive descriptions of their function, duration, and the third‑party vendors involved, so you can change your preferences at any time. Refusing marketing cookies does not affect the operation of the casino lobby or payment systems. That shows our privacy-first approach: essential services are fully accessible regardless of consent choices you make.
Common Questions
How does Trino Casino confirm my age under German regulations?
We utilize a multi-tiered system: automatic checks against national databases and manual document review. When you sign up, you must submit your national ID card or passport through an encrypted portal. Our compliance team cross‑references this with the Schufa identity service to verify legal age. If something is inconsistent, we provisionally restrict the account until a video identification call with a certified agent can clear things up, all in line with the German Interstate Treaty on Gambling.
Can my personal data be disclosed with the affiliate who recommended me?
No. Our affiliate programme employs a strict aggregation firewall. We never share your name, contact details, or payment records with the referring affiliate. The partner only sees a pseudonymized dashboard with confirmed registration counts and a statistical summary of net gaming revenue. Our affiliate agreements expressly prohibit them from seeking to identify individual players. This maintains your gameplay completely separate from the marketing channel that directed you to Trino Casino.
In what way can I permanently revoke my marketing consent?
Go to “Communication Settings” in your account dashboard and turn off promotional channels. Every marketing email we send has a one‑click unsubscribe link at the bottom that works right away. To withdraw consent for postal mail or SMS, contact our Data Protection Officer through the support ticket system. We’ll stop direct marketing within at most 48 hours after receiving your request.
What transpires to my data if Trino Casino ceases operations?
If business ever stops, we are legally required to notify the competent German data protection authority and all active users in advance. Mandatory transactional logs and identification records will be securely transferred to a certified archival service or handed over to the responsible regulatory body for as long as the law demands. Any data that isn’t mandatory gets securely destroyed using cryptographic wiping techniques before the closure of our servers is finalized.
Is Trino Casino use automated decision-making for payments?
We use a limited automated profiling system to flag possible fraud or bonus abuse. If the system blocks a withdrawal, we’re required by law to involve a human. Our financial risk team manually checks every flagged transaction before we tell you the final decision. You can challenge that decision, give your side, and ask for a full manual review by our risk management specialists.
How do I obtain a complete record of my stored data?
Contact us from the address associated with your account to our Data Protection Officer, place “SAR” in the subject line. We’ll confirm your identity with a two‑factor step. Subsequently, we collect your data from all systems—chat logs, game history, identity documents—and create a digitally signed PDF and a machine‑readable JSON file, which will be sent to you within one calendar month.