Privacy Policy
Last Updated: 17.06.2026
Version: 1.0
We may update this Privacy Policy periodically. We encourage you to review this page regularly to stay informed about how your personal data is collected, used, and protected.
This Privacy Policy explains how Neospin collects, processes, shares, and secures your personal data in compliance with applicable data protection legislation, including the General Data Protection Regulation (GDPR) and the Personal Information Protection and Electronic Documents Act (PIPEDA).
1. General Information & Data Controller
-
Operator: www.neospin.com (referred to as the "Casino", "we", or "us") is operated by Metlait S.R.L.
-
Registered Address: El Guayaval, Residencial La Campina Casa Numero Q-11, Cartago, El Guarco, Tejar, 30801 – Costa Rica.
-
Registration Number: 3-102-911867.
-
Role: Metlait S.R.L. acts as the Data Controller, determining the purposes and means of processing your personal data.
-
Data Protection Officer (DPO): For any inquiries or concerns regarding your personal data or this policy, contact our DPO directly at [email protected].
2. Personal Data We Collect
We collect only data that is necessary, relevant, and adequate for the purposes outlined below. The categories of data collected include:
-
Identity Data: Full name, username, date of birth, gender, nationality, and official government identification details (e.g., passport or driver's license).
-
Contact Data: Residential address, proof of address documents, email address, and phone number.
-
Financial & Transactional Data: Bank account numbers, payment card details, income declarations/bank statements (source of funds or wealth verification), and deposit/withdrawal history.
-
Gaming Activity Data: Game logs, login/logout timestamps, wagering history, bonus activity, and responsible gaming notes/interventions.
-
Technical Data: IP address, location data, login credentials, browser type/version, operating system, time zone settings, and device specifications.
-
Marketing & Communications: Direct communications with customer support, ticket histories, and marketing preferences.
-
Voluntary Data: Any additional information you choose to submit when reaching out to support or using our services.
3. Data Collection Sources & Retention
Data Sources
We gather personal data from two primary channels:
-
Directly from you: When you register an account, upload documents, communicate with support, or make transactions.
-
From third parties: Including identity and KYC verification providers, credit reference agencies, financial/payment institutions, AML/PEP databases, regulatory bodies, and marketing affiliates.
Data Retention
-
Personal data is retained only for as long as necessary to fulfill the original purpose of collection or to meet mandatory legal and regulatory obligations.
-
In accordance with Anti-Money Laundering (AML) regulations, core transactional, identity, and financial logs are kept for a minimum of five (5) years following account closure.
-
Once data is no longer required, it is securely erased, anonymized, or destroyed according to technical data protection standards.
4. Legal Bases & Purposes for Data Processing
We process your data strictly under valid legal bases:
| Processing Purpose | Legal Basis |
| Service Delivery | Performance of a Contract |
| Regulatory Compliance (KYC/AML checks, age verification, responsible gaming obligations) | Legal Obligation |
| Fraud Prevention & Risk Management | Legitimate Interest |
| System Security & Technical Integrity | Legal Obligation & Legitimate Interest |
| Analytics & Platform Improvement | Legitimate Interest |
| Customer Support Optimization (Integration of conversational AI tools like Anthropic, OpenAI, and Gemini) | Legitimate Interest |
| Marketing & Personalization | Consent or Legitimate Interest |
5. Sharing Data with Third Parties
To deliver our services effectively, we share your data with authorized third-party service providers under strict data processor contracts:
-
Corporate Group Entities: Internal administrative and operational teams.
-
Gaming & Software Providers: To facilitate game sessions and manage outcomes.
-
Payment Processors & Financial Institutions: To execute deposit and payout requests safely.
-
Identity Verification & AML Providers: For automated KYC, PEP, and sanctions checks.
-
Conversational AI Service Providers: (e.g., Anthropic, OpenAI, Gemini) To assist, manage, and automate customer support tickets and live messaging workflows.
-
Marketing & Affiliate Partners: To distribute promotional campaigns (where consent is provided).
-
Professional Advisors & Authorities: Legal counsel, auditors, accountants, or regulatory and law enforcement bodies when legally required.
-
Corporate Restructuring: In the event of a merger, acquisition, or sale of assets, users will be notified prior to data transfer.
6. International Data Transfers
When transferring data outside your home jurisdiction (e.g., for cloud hosting, remote support, or international verification services), we implement legal safeguards to protect your information. These safeguards include the European Commission's Standard Contractual Clauses (SCCs) or reliance on official adequacy decisions, ensuring your data receives equivalent protection globally.
7. Your Rights as a Data Subject
Subject to statutory conditions and exceptions, you hold the following rights regarding your personal data:
-
Access: Request a copy of the personal data we hold about you.
-
Rectification: Correct inaccurate, outdated, or incomplete data.
-
Erasure ("Right to be Forgotten"): Request deletion of your data (where retention is not mandated by AML or other laws).
-
Restriction: Request that we temporarily limit processing of your data in specific scenarios.
-
Data Portability: Request transfer of your data to another service provider in a structured format.
-
Objection: Object to processing based on legitimate interests or direct marketing.
-
Withdraw Consent: Revoke marketing or voluntary consent at any time.
-
Lodge a Complaint: Contact your local Data Protection Authority if you believe your privacy rights have been infringed.
Note on Automated Decision-Making: We do not rely on fully automated decision-making that produces legal effects without human intervention. If such tools are used, you will be notified separately.
8. Protection of Minors
Our platform is strictly restricted to individuals aged 18 and older (or the higher legal gambling age in their jurisdiction). We do not knowingly collect data from minors. If we discover that an underage user has submitted personal information, we will immediately close the account, delete the data, and notify relevant authorities where required.
9. Data Security & Technical Controls
We employ multi-layered technical and organizational security controls to prevent unauthorized access, loss, or disclosure:
-
Physical Access Controls: Server hardware is housed in secure, industry-standard data centers with restricted physical entry.
-
System Access Controls: Authenticated login systems utilizing unique User IDs, strong password policies, and multi-factor authentication for internal systems.
-
Data Access & Segregation Controls: Strict "need-to-know" access rules for employees, encrypted data transfers, and practices preventing accidental mixing of user data.
-
Organizational Measures: Regular staff training on privacy protocols and oversight by a designated Data Protection Officer (DPO).

