Privacy Policy
This Privacy Policy outlines how spinz-casino (operating via the domain spinz-nz.com) collects, uses, maintains, and discloses personal information collected from players and visitors. This policy applies to the website and all products and services offered by the operator. We are committed to protecting your privacy and ensuring that your personal data is handled in accordance with the New Zealand Privacy Act 2020, the European General Data Protection Regulation (GDPR), and the regulations established by the Malta Gaming Authority (MGA). This policy is effective as of November 2025.
Who We Are
The data controller responsible for your personal information on spinz-nz.com is Rootz Limited, a company incorporated under the laws of Malta.
- Company Registration Number: C83903
- Legal Address: Ewropa Business Centre, Level 3 - 701, Dun Karm Street, Birkirkara, BKR 9034, Malta
- Licensing Authority: Malta Gaming Authority (MGA) under license number MGA/B2C/599/2018 (Issued: 2019-04-30, Valid through 2025).
We have appointed a Data Protection Officer (DPO) responsible for overseeing questions in relation to this privacy policy. If you have any questions about this policy, including any requests to exercise your legal rights, please contact our DPO or customer support team via the contact methods provided on our website.
What Personal Data We Collect
To provide a secure and compliant gaming experience at spinz-casino, we must collect specific categories of personal data. We do not collect more information than is necessary for our operational and legal obligations.
Categories of Data
- Identity Data: Includes first name, maiden name, last name, username or similar identifier, marital status, title, date of birth, and gender. This is required for age verification under New Zealand and Maltese law.
- Contact Data: Includes billing address, residential address, email address, and telephone numbers.
- Financial & Transaction Data: Includes bank account and payment card details (processed via secure PCI-DSS compliant providers), details about payments to and from you, and other details of products and services you have purchased from us.
- Technical Data: Includes internet protocol (IP) address, your login data, browser type and version, time zone setting and location, browser plug-in types and versions, operating system and platform, and other technology on the devices you use to access spinz-nz.com.
- Profile & Usage Data: Includes your username and password, purchases or orders made by you, your interests, preferences, feedback, survey responses, and information about how you use our website, products, and services (betting history, game logs).
- AML/KYC Documentation: Copies of identification documents (passport, driver's license), proof of address (utility bills), and source of wealth/funds documentation as required by Anti-Money Laundering regulations.
Legal Basis for Processing
We process your personal data only when we have a lawful basis to do so. In compliance with the GDPR and the NZ Privacy Act, we rely on the following legal grounds:
- Performance of a Contract: Processing is necessary to register your account, process your bets, and facilitate withdrawals. Without this data, we cannot provide our services to you.
- Legal Obligation: We are required by the Malta Gaming Authority and international AML laws to verify your identity, monitor for fraud, and ensure responsible gambling.
- Legitimate Interests: We process data to improve our services, detect fraud, secure our network, and analyze customer behavior to enhance the spinz-casino experience, provided these interests do not override your fundamental rights.
- Consent: Generally, we do not rely on consent as a legal basis for processing your personal data other than in relation to sending third-party direct marketing communications to you via email or text message. You have the right to withdraw consent to marketing at any time.
Purpose of Processing
We use the data collected at spinz-nz.com for the following specific purposes:
- Service Provision: To register you as a new customer, manage your account, and process financial transactions (deposits and withdrawals).
- Regulatory Compliance: To carry out age verification, identity checks (KYC), and anti-money laundering (AML) checks as required by the MGA and New Zealand regulations.
- Customer Support: To manage our relationship with you, including notifying you about changes to our terms or privacy policy and troubleshooting issues via our 24/7 support channels.
- Responsible Gambling: To monitor gaming behavior to identify potential problem gambling patterns and intervene if necessary.
- Security & Fraud Prevention: To prevent, detect, and investigate fraud, cheating, money laundering, and other criminal activities.
- Marketing & Analytics: To deliver relevant website content and advertisements to you (where you have consented) and measure or understand the effectiveness of the advertising we serve to you.
Disclosure & Sharing
Your personal data is strictly confidential. However, to operate spinz-casino effectively and legally, we may share your data with the following categories of third parties:
- Service Providers: Third-party companies that provide services on our behalf, including payment processors, game providers (to launch game sessions), website hosting, and data analysis.
- Regulators & Authorities: The Malta Gaming Authority (MGA), the New Zealand Department of Internal Affairs, tax authorities, and law enforcement agencies where required by law or to report suspicious activity.
- Group Companies: Other companies within the Rootz Limited corporate group for internal administration and AML compliance purposes.
- Professional Advisers: Lawyers, bankers, auditors, and insurers who provide consultancy, banking, legal, insurance, and accounting services.
- Credit Reference & Fraud Prevention Agencies: For the purpose of assessing your credit score (where applicable) and verifying your identity and preventing fraud.
International Transfers
As Rootz Limited is located in Malta (European Economic Area), your data is primarily stored within the EEA. However, providing services to New Zealand players involves international data transfer. We ensure that your personal data is protected by requiring all our group companies and service providers to follow the same rules when processing your personal data.
Whenever we transfer your personal data out of the EEA or New Zealand, we ensure a similar degree of protection is afforded to it by ensuring at least one of the following safeguards is implemented:
- We will only transfer your personal data to countries that have been deemed to provide an adequate level of protection for personal data by the European Commission or New Zealand privacy laws.
- Where we use certain service providers, we may use specific contracts (Standard Contractual Clauses) approved for use which give personal data the same protection it has in Europe.
Data Retention
We will only retain your personal data for as long as necessary to fulfill the purposes we collected it for, including for the purposes of satisfying any legal, accounting, or reporting requirements.
Under Anti-Money Laundering laws applicable to our MGA license, we are required to keep basic information about our customers (including Contact, Identity, Financial, and Transaction Data) for a minimum of five (5) years after they cease being customers (account closure). After this statutory period, your data will be securely deleted or anonymized. Data processed solely for marketing purposes will be deleted immediately upon your withdrawal of consent.
Your Rights
Under the New Zealand Privacy Act 2020 and the GDPR, you have substantial rights regarding your personal data held by spinz-nz.com. You may exercise these rights free of charge.
- Right of Access: You can request a copy of the personal data we hold about you to verify that we are lawfully processing it.
- Right to Correction: You may request the correction of any incomplete or inaccurate data we hold about you.
- Right to Erasure (Right to be Forgotten): You can ask us to delete or remove personal data where there is no good reason for us continuing to process it. Note that we may not always be able to comply with your request of erasure for specific legal reasons (e.g., mandatory AML retention laws) which will be notified to you, if applicable, at the time of your request.
- Right to Object: You may object to the processing of your personal data where we are relying on a legitimate interest or for direct marketing purposes.
- Right to Restriction: You may ask us to suspend the processing of your personal data in specific scenarios, such as establishing its accuracy.
- Right to Withdraw Consent: Where we are relying on consent to process your personal data (e.g., marketing), you may withdraw this consent at any time.
To exercise any of these rights, please contact our customer support. We aim to respond to all legitimate requests within one month (30 days). Occasionally it may take us longer if your request is particularly complex.
Cookies & Tracking Technologies
spinz-casino uses cookies and similar tracking technologies to track the activity on our service and hold certain information. Cookies are files with a small amount of data which may include an anonymous unique identifier.
- Essential Cookies: Necessary for the website to function (e.g., remembering your login session). These cannot be switched off.
- Analytical/Performance Cookies: Allow us to recognize and count the number of visitors and see how visitors move around the site. This helps us improve the way our website works.
- Functionality Cookies: Used to recognize you when you return to our website, enabling us to personalize our content for you.
- Marketing Cookies: Record your visit to our website, the pages you have visited, and the links you have followed to make advertising more relevant to your interests.
You can instruct your browser to refuse all cookies or to indicate when a cookie is being sent. However, if you do not accept cookies, you may not be able to use some portions of our service (e.g., launching games).
Data Security
We have put in place appropriate security measures to prevent your personal data from being accidentally lost, used, or accessed in an unauthorized way, altered, or disclosed. spinz-nz.com utilizes industry-standard security protocols:
- Encryption: All sensitive data exchanges are encrypted using TLS 1.2 (Transport Layer Security) or higher protocols.
- Access Controls: Access to your personal data is limited to those employees, agents, contractors, and other third parties who have a business need to know. They will only process your personal data on our instructions and are subject to a duty of confidentiality.
- Monitoring: We employ advanced firewalls and intrusion detection systems to monitor traffic and prevent unauthorized access.
- Standards: Our operations align with international security standards (ISO 27001) and we engage with eCogra for alternative dispute resolution, ensuring high operational integrity.
We have put in place procedures to deal with any suspected personal data breach and will notify you and any applicable regulator of a breach where we are legally required to do so.
Complaints & Contacts
If you have any concerns or complaints about how we handle your data, we encourage you to contact us first so we can resolve the issue promptly.
Internal Contact Channels
- Author/Representative: Oliver Bennett
- Contact Methods: Live Chat (Available 24/7 on website) or Email Support (via website contact form).
External Escalation
If you feel that your concerns have not been adequately addressed by us, you have the right to lodge a complaint with the relevant supervisory authorities:
- Malta (Lead Authority): Information and Data Protection Commissioner (IDPC). Website: idpc.org.mt
- New Zealand: Office of the Privacy Commissioner. You can file a complaint online at privacy.org.nz if you believe we have breached the NZ Privacy Act 2020.
Updates
We keep our privacy policy under regular review. This version was last updated in November 2025.
We reserve the right to modify this privacy policy at any time. If we make material changes to how we treat our users' personal data, we will notify you through a notice on the spinz-nz.com website home page or via email approximately 30 days prior to the change becoming effective. You are responsible for periodically visiting our website and this privacy policy to check for any changes.