Privacy Policy

Version: 1.0  |  Last Updated: 30 July 2025

MidasLuck ("we," "us," or "our"), accessible at midasluck-play.com, is committed to protecting and respecting your privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard your personal data when you visit our Website, create an account, or use our services. It also describes your rights in relation to that data and how you can exercise them.

This Privacy Policy should be read alongside our Terms & Conditions and Responsible Gaming Policy. By using our Website and services, you acknowledge that you have read and understood this Privacy Policy. If you do not agree with our practices, please do not use our Website.

1. Introduction

1.1. Our Commitment to Privacy

We recognise the importance of privacy and personal data protection. We process personal data in accordance with the principles set out in the General Data Protection Regulation (EU) 2016/679 ("GDPR") and any applicable national data protection legislation. All personal data we collect is processed lawfully, fairly, and transparently.

1.2. Scope

This Privacy Policy applies to all personal data collected from users of midasluck-play.com, including registered Players, visitors who browse without registering, and individuals who contact us via any communication channel.

2. Data We Collect

2.1. Data You Provide Directly

We collect personal data that you provide to us voluntarily, including when you:

  • Register an Account: full name, date of birth, email address, residential address, phone number, username, and password;
  • Complete KYC verification: copies of identity documents (passport, national ID, driver's licence), proof of address, and payment method documentation;
  • Make a deposit or withdrawal: payment method details, transaction amounts;
  • Contact our support team: communication records, complaint details;
  • Respond to surveys or promotions: preference data, feedback.

2.2. Data Collected Automatically

When you use our Website, we automatically collect certain technical data, including:

  • Device and browser information: device type, operating system, browser type and version;
  • Network data: IP address, approximate geographic location derived from IP;
  • Usage data: pages visited, time spent on each page, navigation paths, links clicked;
  • Gaming data: game sessions, bets placed, results, timestamps, wagering history;
  • Cookie and tracking data: as described in Section 6 below.

2.3. Data From Third Parties

We may receive personal data from third parties in the following circumstances:

  • Identity verification agencies (for KYC and AML purposes);
  • Payment processors and financial institutions (for transaction verification);
  • Fraud prevention databases and screening services;
  • Analytics and marketing partners (aggregated or pseudonymised data).

3. How We Use Your Data

We use the personal data we collect for the following purposes:

  • Account management: to create, maintain, and administer your Account;
  • Service delivery: to provide and improve our Casino Games and related services;
  • Identity and age verification (KYC): to comply with our obligations to verify that players are of legal age and are who they claim to be;
  • Financial processing: to process deposits, withdrawals, and refunds;
  • Anti-money laundering (AML) and fraud prevention: to detect, prevent, and investigate fraudulent or suspicious activity;
  • Responsible gaming: to monitor for signs of problem gambling and apply protective measures where necessary;
  • Customer support: to respond to your enquiries, complaints, and requests;
  • Marketing communications: to send you promotional offers, newsletters, and updates, where you have consented to receive these;
  • Legal compliance: to fulfil our obligations under applicable law and respond to lawful requests from authorities;
  • Website improvement: to analyse usage patterns and improve the performance, design, and content of the Website.

4. Legal Bases for Processing

We process your personal data on the following legal bases under the GDPR:

  • Contractual necessity (Art. 6(1)(b) GDPR): Processing is necessary for the performance of the contract between you and us — i.e., to provide our gaming services, manage your Account, and process transactions;
  • Legal obligation (Art. 6(1)(c) GDPR): Processing is necessary for compliance with applicable laws, including AML regulations, KYC requirements, and data retention obligations;
  • Legitimate interests (Art. 6(1)(f) GDPR): Processing is necessary for our legitimate business interests, such as fraud detection, security, business analytics, and improving our services, provided such interests are not overridden by your rights and freedoms;
  • Consent (Art. 6(1)(a) GDPR): Where we process your data for marketing purposes or non-essential cookies, we do so on the basis of your explicit, freely given consent, which you may withdraw at any time.

5. Data Sharing & Third Parties

5.1. Service Providers

We may share your personal data with trusted third-party service providers who assist us in operating the Website and delivering our services. These include:

  • Payment processing and banking partners;
  • Identity and age verification providers;
  • Software and game providers;
  • Customer support platform providers;
  • Email and communication service providers;
  • IT infrastructure, hosting, and cloud service providers;
  • Analytics and performance monitoring tools.

All third-party processors are bound by data processing agreements requiring them to process data only as instructed and to implement appropriate security measures.

5.2. Legal Disclosures

We may disclose personal data to regulatory authorities, law enforcement agencies, or other government bodies where we are legally required to do so, or where we believe disclosure is necessary to:

  • Comply with a legal obligation or court order;
  • Enforce or apply our Terms and Conditions;
  • Protect the rights, property, or safety of MidasLuck, our players, or others.

5.3. Business Transfers

In the event of a merger, acquisition, or sale of assets involving MidasLuck, personal data may be transferred to the relevant parties as part of that transaction. We will notify you before your personal data is transferred and becomes subject to a different privacy policy.

5.4. No Sale of Data

MidasLuck does not sell, rent, or lease your personal data to any third party for their own independent marketing purposes.

6. Cookies & Tracking Technologies

6.1. What Are Cookies?

Cookies are small text files placed on your device by the Website when you visit. They enable us to recognise your device, remember your preferences, and analyse how you interact with our Website. In addition to cookies, we may use web beacons, pixel tags, and local storage technologies for similar purposes.

6.2. Categories of Cookies We Use

  • Strictly Necessary Cookies: Essential for the Website to function correctly. They include session management, authentication, and security cookies. These cannot be disabled.
  • Functional Cookies: Enable enhanced features such as remembering your language preference or login status.
  • Analytics Cookies: Help us understand how players use the Website by collecting aggregated usage statistics (e.g., via Google Analytics or similar tools).
  • Marketing / Targeting Cookies: Used to deliver relevant promotional content. These are placed only with your consent.

6.3. Managing Cookies

You can control or disable cookies through your browser settings or via our cookie consent banner when you first visit the Website. Please note that disabling certain cookies may impair the functionality of the Website. For more information on how to manage cookies, visit www.allaboutcookies.org.

7. Data Security

7.1. Security Measures

MidasLuck implements appropriate technical and organisational security measures to protect your personal data against accidental loss, unauthorised access, disclosure, alteration, or destruction. These measures include:

  • SSL/TLS encryption for all data transmitted between your device and our servers;
  • Encryption at rest for sensitive data stored on our servers;
  • Access controls limiting internal access to personal data on a need-to-know basis;
  • Regular security audits and vulnerability assessments;
  • PCI-DSS compliance for payment card data handling.

7.2. Data Breach Notification

In the unlikely event of a personal data breach that is likely to result in a risk to your rights and freedoms, we will notify you and the relevant supervisory authority without undue delay and in any case within 72 hours of becoming aware of the breach, in accordance with our obligations under the GDPR.

8. Data Retention

8.1. Retention Periods

We retain personal data only for as long as is necessary to fulfil the purposes for which it was collected, or as required by applicable law. Our standard retention periods are as follows:

Category of Data Retention Period
Account and registration data5 years after Account closure
Financial transaction records7 years (AML compliance)
KYC documents5 years after business relationship ends
Customer support communications3 years after resolution
Marketing consent recordsUntil consent is withdrawn + 1 year
Analytics data (anonymised)26 months (rolling)

After the relevant retention period expires, personal data is securely deleted or anonymised.

9. Your Rights

Under the GDPR, you have the following rights in relation to your personal data:

  • Right of Access (Art. 15): You have the right to request a copy of the personal data we hold about you;
  • Right to Rectification (Art. 16): You have the right to request correction of inaccurate or incomplete personal data;
  • Right to Erasure (Art. 17): You have the right to request deletion of your personal data, subject to certain exceptions (e.g., legal retention obligations);
  • Right to Restriction of Processing (Art. 18): You have the right to request that we limit the processing of your data in certain circumstances;
  • Right to Data Portability (Art. 20): You have the right to receive a structured, machine-readable copy of the data you provided to us;
  • Right to Object (Art. 21): You have the right to object to processing based on legitimate interests, including direct marketing;
  • Rights Related to Automated Decision-Making (Art. 22): You have the right not to be subject to decisions based solely on automated processing that significantly affect you, unless you have given explicit consent.

To exercise any of the above rights, please contact our Data Protection Officer (DPO) at [email protected]. We will respond to all verifiable requests within thirty (30) days. In complex or multiple requests, this period may be extended by a further two months, with notice to you.

10. International Data Transfers

Your personal data may be transferred to and processed in countries outside the European Economic Area (EEA). Where we transfer data outside the EEA, we ensure appropriate safeguards are in place, such as:

  • Standard Contractual Clauses (SCCs) approved by the European Commission;
  • Transfers to countries with an adequacy decision by the European Commission;
  • Other appropriate safeguards as recognised under the GDPR.

You may request details of the specific safeguards in place by contacting [email protected].

11. Minors

Our services are not directed at, nor intended for use by, individuals under the age of 21. We do not knowingly collect personal data from anyone under this age. If we become aware that we have inadvertently collected data from a minor, we will promptly delete such data and close any associated Account. If you believe a minor has registered on our Website, please notify us immediately at [email protected].

12. Changes to This Policy

We may update this Privacy Policy from time to time to reflect changes in our data practices, legal requirements, or service offerings. When we make material changes, we will update the "Last Updated" date and version number at the top of this page and, where appropriate, notify you via email or a Website notice. We encourage you to review this page periodically. Your continued use of the Website after any change constitutes your acceptance of the updated Privacy Policy.

13. Contact Information

If you have any questions, concerns, or requests regarding this Privacy Policy or the processing of your personal data, please contact our Data Protection Officer:

If you are not satisfied with our response, you have the right to lodge a complaint with the relevant data protection supervisory authority in your country of residence. In Greece, the competent authority is the Hellenic Data Protection Authority (HDPA)Αρχή Προστασίας Δεδομένων Προσωπικού Χαρακτήρα (www.dpa.gr).

Coin