As a licensed operator in Italy, we gather and safeguard personal and transactional data under strict legal obligations. This policy spells out exactly how long we keep different categories of information, the legal reasons behind those periods, and the security measures that safeguard your data at every stage. We regularly balance our duty to retain records for fraud prevention and financial audits with the privacy rights you maintain under Italian data protection law and the GDPR. Our schedules get regular reviews so we keep fully compliant.
User Rights and Retention Interactions
When you send an erasure request, our system automatically checks each data category against its retention schedule. Everything beyond its mandatory window is erased without delay. For data still under a legal retention obligation, we lock it down right away so it’s excluded from active use and stored only for compliance storage; we advise you which specific law applies and the date deletion becomes possible. Access requests are responded to within thirty days and provide a breakdown of what we keep, why, and the scheduled deletion date. If you dispute accuracy, we add a note instead of altering the original record, so the audit trail remains intact. Portability requests are fulfilled in a structured, machine‑readable format even while data is still in its retention window.
Data Safeguarding During Preservation
Retained data is protected with AES‑256 encryption at rest, TLS 1.3 protocols in transit and isolated virtual private clouds. Access requires multi‑factor authentication plus just‑in‑time privilege elevation that ends on its own. Every access event is logged into an immutable audit trail. We run quarterly penetration tests through CREST‑certified firms and continuous vulnerability scans to maintain our storage tight. Backups are encrypted and spread across Italian data centres, with strict controls that block accidental restoration of data past its deletion date. A dedicated lifecycle dashboard marks every dataset as it nears expiration.
Permission Management and Workforce Training
Only employees whose roles demonstrably require access to retained personal data get permissions, and those permissions go through monthly recertification audits. Any access to dormant user records triggers a managerial review within one business day. Every staff member who handles personal data completes mandatory annual training on Italian data protection law and our internal retention policies, including hands‑on exercises on spotting valid erasure requests and telling the difference between data we must keep under a legal hold and data we can delete straight away.
Affiliate Program Data Retention
Partner relationship data, including contact information, payment information and commission payout records, is kept for the duration of the current agreement plus 10 years after the contract ends. That’s driven by tax obligations on commission payments, which require long‑term financial records. Affiliate performance statistics and aggregated player referral data get made anonymous after five years. We explicitly prohibit affiliates from autonomously collecting or retaining private data about referred players; they obtain only anonymised, consolidated summaries. Our affiliate agreements include inspection rights to check adherence, and any infringement is cause for prompt contract ending and payout forfeiture.
Data Types and Storage Durations
We sort all user data into distinct categories, each connected to a retention schedule that matches its function and legal context. That systematic approach stops us from holding on to things forever. Every year our Data Protection Officer assesses these groupings and adjusts the timelines whenever new guidance arrives from the Garante per la protezione dei dati personali. Below you’ll see how long each data type stays in our live systems before being securely anonymised or deleted. Archived backups operate on a ninety‑day cycle because of technical constraints.
Identity and Monetary Records
Identity documents you submit during Know Your Customer checks, like passport scans, utility bills and tax ID numbers, stay on file for ten years after you terminate your account, as anti‑money laundering law stipulates. Deposit and withdrawal logs, payment method tokens and wallet balance histories are retained for ten years from the date of each transaction, satisfying both AML requirements and Italian Civil Code limitation periods. We keep these records in encrypted, access‑restricted vaults and tamper‑proof ledgers. Once the retention deadline elapses, we strip away all personal identifiers permanently; statistical trends may still be utilized but never in a way that traces to any individual.
User Activity and Customer Support Interactions
In-depth reports of game sessions, bets placed, outcomes and session lengths are kept for five years after each gaming event, matching the statute of limitations for civil disputes. Customer service transcripts, email threads and call recordings stay for three years from your last interaction, covering the typical complaint‑handling window. After those periods, raw logs and case attachments get permanently deleted. Aggregated, anonymised datasets can be kept indefinitely for product improvement and service quality analysis. All of this data lives in case management systems with role‑based access restrictions.
Ethical Play and Self‑Exclusion Data
Upon activating self‑exclusion, your identity data must be stored permanently in a locked‑down register to stop you from opening new accounts, a measure Italian gambling regulations explicitly permit. Other safer‑gambling markers, like expired voluntary deposit limits, are deleted two years after the limit lifts. We never use self‑exclusion register data for anything other than enforcing the exclusion. The register is completely walled off from marketing and operational systems, so it serves only its protective purpose.
Data Removal Procedures
When a data class hits the end of its planned retention period, our self-running lifecycle mechanism kicks off a secure deletion workflow. First, the data gets logically removed from production databases. Next, physical storage blocks are replaced with random data patterns to prevent forensic recovery. Finally, a digitally signed log lands in a audit trail, giving traceable confirmation that erasure happened on time. Backup copies rotate every ninety days, so any deleted data is removed from all media within three months. When a litigation hold applies, we pause the deletion workflow only for the affected records, record the hold reason, and continue once the hold lifts.
Regulatory Foundation for Record Keeping
Our retention approach rests on several legal obligations that govern gambling operators operating in the Italian market. Anti‑money laundering rules from the Italian Financial Intelligence Unit force us to keep transaction logs, identity verification documents and suspicious activity reports for a fixed term after the business relationship ends. Meanwhile, tax rules imposed by the Agenzia delle Entrate require we preserve financial records that back up taxable gaming revenue and player winnings. These obligations override any general right to erasure during the mandatory period. For operational data that falls outside a fixed legal window, we use legitimate interest assessments where a valid reason exists, and we allow an opt‑out unless a compelling legal obligation prevents it.
Consent‑Based Retention
Marketing preferences, newsletter sign‑ups and the behavioural analytics employed for personalised offers remain only with your explicit consent. You can revoke consent anytime through your account dashboard; once you do, we stop that processing immediately and delete the connected profiles within thirty days. Data processed lawfully before withdrawal is separated from active systems to block further use, but it is not removed retroactively. Consent records themselves are kept for six years as proof of compliance. We never employ this data for anything beyond the activity you agreed to.
Common Questions
May I request data erasure before the retention period expires?
Yes, you can file an erasure request any time. We instantly examine each data category in relation to its legal retention duty. If there’s no legal hold, we delete it fast. Regarding items we must preserve, we confine them to storage‑only, explain the legal basis blocking instant erasure, and share the projected deletion date. You can also view all your data categories with their scheduled deletion dates through your account dashboard. Such a partial strategy respects your rights within the limits of Italian law.
What occurs with my data when I opt for permanent self‑exclusion?
If you sign up for permanent self‑exclusion, accordo utente richroyalcasinò, your personal data is shifted to a dedicated exclusion register that operates indefinitely with highly restricted access. This is a legal mandate designed to stop you from creating new accounts. Your gaming and transaction history, however, still complies with standard retention schedules and is removed after those periods conclude. The self‑exclusion record is separated from all marketing and operational platforms, so it only serves the safeguarding role it was intended for. No promotional communications will reach you.
How is data from dormant accounts managed?
An account is deemed inactive following twelve consecutive months without a login. At that stage, we automatically disable marketing communications and transition the account to a dormant status with limited processing. The underlying retention periods remain active according to the original data collection dates, not the date of inactivity. That means data from an inactive account is still held for the full statutory period that applies to its category and then deleted according to our standard procedures. If you come back after a long break, you might need to complete a fresh Know Your Customer check to reactivate. Your data dashboard shows the current status at all times.
International Data Transfers and Data Retention
Our primary infrastructure sits within Italy and the larger European Economic Area. Some secondary services, like fraud detection platforms and customer relationship tools, may send some personal data to countries beyond the EEA. In those cases, we ensure an adequacy decision exists or we put Standard Contractual Clauses in place together with a transfer impact assessment. The retention periods we apply to transferred data reflect those in this policy, and processors are contractually bound to remove or return data when the service ends. We maintain a public register of sub‑processors, updated within fourteen days of any change, and we favour vendors with Italian data centres. Geo‑fencing rules maintain Italian user data inside European boundaries, confirmed through yearly audits.
![]()
Policy Changes and Player Notification
We evaluate this Data Retention Policy every six months and whenever a major legal change affects Italian gambling operations. Minor clarifications are posted silently with a revised effective date. Material changes that modify retention periods, introduce new data categories or change the legal basis for processing are communicated directly to you by email at least thirty days before they come into force. You’ll also find an in‑platform banner notification when you log in during the notice period. Historical versions are stored and available on request, each with a version number and a validity date range. If an earlier version provided a shorter retention period for certain data, we adhere to that promise for data collected under that version and apply rainews.it new terms only going forward.