Policies

Privacy Policy

1. Identity and Contact Details of the Controller

The controller responsible for the processing of your personal data within the meaning of Art. 4 No. 7 GDPR is

Email: privacy@Stake.eu

As the controller is established outside the European Union, we have appointed an EU representative pursuant to Art. 27 GDPR:

Email: [EU representative email]

We have appointed a Data Protection Officer (DPO). You may contact our DPO at any time regarding any matter relating to the processing of your personal data or the exercise of your rights under the GDPR:

Email: [dpo@Stake.eu ]

2. Scope and Applicability

2.1 General

This Privacy Policy of Sweepstakes Services Limited (owner and operator of Stake.eu), Minmarge Limited (payment agent of Stake.eu) explains how Stake.eu (“Stake”, "we", "us", "our") collects, uses, discloses, and otherwise processes personal data of users of the Stake.eu website and services ("Services"), in compliance with the General Data Protection Regulation (EU) 2016/679 ("GDPR"), the German Telecommunications-Telemedia Data Protection Act (TTDSG), and other applicable data protection laws.

This Privacy Policy applies to all users accessing the Services located in the European Economic Area (EEA), including Germany, regardless of where our company is established. This policy governs our processing of personal data of individuals in the EEA where such processing relates to the offering of our Services to those individuals.

2.2 Relationship to Other Policies

Where this Privacy Policy refers to other policies (including our Terms and Conditions or Cookie Policy), those policies supplement but do not replace the rights and protections afforded to you under the GDPR. In the event of any conflict between this Privacy Policy and any other document, this Privacy Policy shall prevail with respect to data protection matters.

3. Categories of Personal Data We Collect

We collect the following information from you:

  • Full name

  • Date of Birth

  • Permanent address

  • E-mail

  • Phone number

  • Device information about your use of our website, such as the content you view, the time and duration of your visit on our website, how often you use our Services, how you first heard about our website, your preferences and information about your interaction with the content offered through our website, your hardware model, device type, other unique device identifiers, operating system version, browser type and IP address

  • Identification documents (may include ID, utility bills, bank statements, etc.)

  • Transaction information (linked to the purchases and redeems you make)

  • Communications exchange with our teams (support, live chat, complaints, etc.)

  • Information we obtain from a third-party, such as a site or platform provider

  • (including Facebook), about your use of or interest in our Services.

We collect and process the following categories of personal data, which are limited to what is necessary for the purposes described below (data minimization principle, Art. 5(1)(c) GDPR):

Personal Information CategoryExamplesCollected
IdentifiersA real name, alias, postal address, unique personal identifier, online identifier, Internet Protocol address, email address, account name, Social Security number or equivalent information under your country of residence’s laws, driver's license number, or other similar identifiers.YES
Personal informationIncluding but not limited to name, signature, social security number, physical characteristics or description, communications such e-mails or chat messages, address, telephone number, driver’s license or state identification card number, insurance policy number, education, employment, employment history, bank account number, credit card number, debit card number, or any other financial information. Some personal information included in this category may overlap with other categories.YES
Commercial informationRecords of personal property, products or services purchased, obtained, or considered, or other purchasing or consuming histories or tendencies.YES
Biometric informationAn individual’s physiological, biological or behavioral characteristics that can be used singly or in combination with each other or with other identifying data, to establish individual identity. Facial recognition technology collects information from your image capture, including biometric data, and shares this information with us, which assists us to verify your ID.YES
Internet or other similar network activityBrowsing history, search history, information on a consumer's interaction with a website, application, or advertisement.YES
Geolocation dataPhysical or IP address location or movements.YES
Sensory dataAudio, electronic, visual, or similar information.YES
Professional or employment-related informationCurrent or past job history.YES
Inferences drawn from other personal informationProfile reflecting a person's preferences, characteristics, predispositions, behaviour.YES

The afore-mentioned information encompasses personal data which belong to a special category of personal data as defined in Art. 9(1) GDPR (which requires your explicit consent for health data, racial or ethnic origin, political opinions, religious beliefs, biometric data, or data concerning sexual orientation). Profile photos processed with facial recognition or image analysis technology, game activity data and identity verification data may belong to such special category. We will only process and collect them upon you having expressed your explicit consent or another of the reasons mentioned in Art. 9(2) GDPR is fulfilled and the procedural requirements of Art. 9(3) GDPR are fulfilled. Where such data is collected incidentally (e.g., in support correspondence), it will be deleted without undue delay unless processing is required by applicable law.

4. Purposes and Legal Bases for Processing

We process personal data only where a valid legal basis exists under Art. 6(1) GDPR. The following table sets out each purpose for which we process personal data and the corresponding legal basis:

PurposeLegal Basis (Art. 6(1) GDPR)Details
Account registration and managementArt. 6(1)(b) — Performance of contractProcessing is necessary to create and maintain your account and provide our Services
Processing transactions and managing virtual currency (Gold Coins, Stake Cash)Art. 6(1)(b) — Performance of contractProcessing is necessary for the execution of purchases and transactions within the Services
Customer support and responding to enquiriesArt. 6(1)(b) — Performance of contract; Art. 6(1)(f) — Legitimate interestsProviding assistance and resolving issues is an integral part of our Service and a legitimate interest of both parties
Age verification and identity verificationArt. 6(1)(c) — Legal obligation; Art. 6(1)(b) — Performance of contractWe are required to verify user age to comply with applicable laws and our Terms
Prevention of fraud, cheating, and other prohibited conductArt. 6(1)(f) — Legitimate interestsOur legitimate interest in maintaining the integrity and security of our platform, provided this interest is not overridden by your fundamental rights
Compliance with legal obligations (e.g., AML, tax, regulatory reporting)Art. 6(1)(c) — Legal obligationProcessing is necessary to comply with applicable legal requirements
Sending service-related communicationsArt. 6(1)(b) — Performance of contractNecessary communications about your account, transactions, and service updates
Sending marketing communicationsArt. 6(1)(a) — ConsentOnly where you have given your specific, informed, and freely given consent in accordance with Art. 7 GDPR C-61/19
Analytics and improvement of ServicesArt. 6(1)(f) — Legitimate interestsOur legitimate interest in understanding how our Services are used and improving them, balanced against your rights
Security of our systems and ServicesArt. 6(1)(c) — Legal obligation; Art. 6(1)(f) — Legitimate interestsEnsuring data security under Art. 32 GDPR and our interest in protecting our systems and users
Responsible gaming / player protectionArt. 6(1)(c) — Legal obligation; Art. 6(1)(f) — Legitimate interestsCompliance with responsible gaming requirements and our interest in user welfare

Where we rely on our legitimate interests as the legal basis for processing (Art. 6(1)(f) GDPR), we have carried out a balancing test to ensure that our interests are not overridden by your interests or fundamental rights and freedoms. You may request details of this balancing test by contacting us at the details set out in Section 1 above. You also have the right to object to such processing at any time pursuant to Art. 21 GDPR (see Section 10 below).

5. Consent and Right to Withdraw

Where we rely on your consent as the legal basis for processing (Art. 6(1)(a) GDPR), the following applies:

5.1 Right to Withdraw Consent

You have the right to withdraw your consent at any time, with effect for the future. Withdrawal of consent does not affect the lawfulness of processing carried out prior to withdrawal. To withdraw consent, please:

  • Use the preference settings in your account dashboard; or

  • Contact us at [privacy@ stake.eu ].

We will action your withdrawal request without undue delay and no later than within one month of receipt.

5.2 No Coupling

We do not make the provision of our core Services conditional upon your consent to the processing of personal data that is not necessary for the performance of the relevant contract. Where consent is requested for optional processing (such as marketing communications), refusal will have no adverse consequences for your use of the Services.

6. Information We Collect Automatically

6.1 Technical and Usage Data

When you use our Services, we automatically collect technical data including your IP address, browser type and version, device identifiers, operating system, referring URLs, and information about your interactions with our website. This data is collected to ensure the technical functioning and security of our Services and is processed on the basis of Art. 6(1)(b) and/or Art. 6(1)(f) GDPR.

6.2 Cookies and Similar Technologies

We use cookies and similar tracking technologies. Information about the types of cookies we use, their purposes, their duration, and the legal basis for their use (including which cookies require your prior consent under § 25(1) TTDSG and which are strictly necessary under § 25(2) TTDSG) is set out in our Cookie Policy, which is set forth in a separate document available to you inter alia via a link on our website.

You may withdraw your consent to non-essential cookies at any time through our cookie preference centre, accessible via the [Cookie Settings] link in the footer of our website.

7. How We Share Your Personal Data

7.1 Categories of Recipients

We may share your personal data with the following categories of recipients:

Recipient CategoryPurposeLegal Basis
IT service providers and cloud hosting providersHosting, storage, and technical infrastructureArt. 6(1)(b)/(f) GDPR; Art. 28 GDPR (data processing agreement)
Payment processorsProcessing transactionsArt. 6(1)(b) GDPR
Identity verification and KYC service providersAge and identity verificationArt. 6(1)(b)/(c) GDPR
Analytics providers (e.g., website analytics tools)Service improvement and analyticsArt. 6(1)(f) GDPR or Art. 6(1)(a) GDPR (where consent required)
Customer support platform providersManaging support requestsArt. 6(1)(b) GDPR
Fraud prevention and security providersPlatform integrity and fraud preventionArt. 6(1)(f) GDPR
Legal and compliance advisorsLegal compliance and dispute resolutionArt. 6(1)(c)/(f) GDPR
Regulatory and law enforcement authoritiesCompliance with legal obligationsArt. 6(1)(c) GDPR
Group companies / affiliatesInternal administrative purposesArt. 6(1)(f) GDPR

7.2 Data Processing Agreements

Where we engage third parties to process personal data on our behalf (processors), we ensure that such processing is governed by a written data processing agreement pursuant to Art. 28 GDPR, which requires the processor to process personal data only on our documented instructions and to implement appropriate technical and organisational security measures.

7.3 No Sale of Personal Data

We do not sell your personal data to third parties for their own marketing or commercial purposes.

8. International Transfers of Personal Data

8.1 Transfers to Third Countries

Some of our service providers are located outside the European Economic Area (EEA), including in the United States of America (USA). Such transfers of personal data are subject to the requirements of Chapter V GDPR (Arts. 44–49 GDPR). We do not transfer personal data to a third country unless one of the following safeguards is in place:

(a) Adequacy Decision (Art. 45 GDPR)

Where the European Commission has adopted an adequacy decision in respect of the recipient country (Art. 45 GDPR), data may be transferred without further safeguards. In respect of transfers to the USA:

The European Commission adopted the EU-US Data Privacy Framework (DPF) adequacy decision on 10 July 2023 (Commission Implementing Decision EU 2023/1795 of 10 July 2023, Document C(2023) 4745 final). Transfers to US organizations certified under the DPF may take place on the basis of this adequacy decision. Where we transfer data to a DPF-certified organization, we will identify this in our records of processing activities. You may verify DPF certification at: www.dataprivacyframework.gov .

(b) Standard Contractual Clauses (Art. 46(2)(c) GDPR)

Where a DPF certification is not in place or where transfers are made to other third countries without an adequacy decision, we rely on the Standard Contractual Clauses (SCCs) adopted by the European Commission pursuant to Art. 46(2)(c) GDPR. In accordance with the ECJ judgment in Schrems II (C-311/18), we supplement SCCs with a Transfer Impact Assessment (TIA) to ensure that the level of protection guaranteed by the GDPR is not undermined. Where a TIA identifies that the SCCs alone are insufficient, we implement supplementary technical and organizational measures.

(c) Other Appropriate Safeguards (Art. 46 GDPR)

We may also rely on other appropriate safeguards pursuant to Art. 46 GDPR, including binding corporate rules (Art. 47 GDPR) or approved codes of conduct (Art. 40 GDPR).

8.2 Transfers to the USA: Specific Disclosure

You are informed that the USA has surveillance laws (including Section 702 of the Foreign Intelligence Surveillance Act (FISA) and Executive Order 12333) that may permit US government authorities to access personal data transferred from the EU to the USA. The EU-US Data Privacy Framework provides, in principle, for redress mechanisms for EEA residents regarding such access. To the extent that we transfer data to US recipients who are not DPF-certified, we implement the safeguards described in Section 8.1(b) above and carry out a Transfer Impact Assessment.

8.3 Right to Obtain a Copy of Safeguards

You have the right to obtain a copy of the appropriate safeguards we have put in place for international transfers. Please contact us at [privacy@stake.eu ].

9. Retention of Personal Data

We retain personal data only for as long as is necessary for the purposes for which it was collected and processed, or as required by applicable law (storage limitation principle, Art. 5(1)(e) GDPR). The following retention periods apply:

Category of DataRetention PeriodBasis
Account and identity dataDuration of the contractual relationship + 5 years after account closureContractual; legal obligation (limitation periods)
Transaction and payment data7 years from the date of transactionLegal obligation (commercial and tax law)
Communication and support data3 years from the date of last interactionLegitimate interests (legal claims defence)
Marketing preference dataUntil consent is withdrawn; reviewed every 2 yearsConsent
Technical and log data90 days (rolling)Legitimate interests (security)
Verification / KYC documentsDuration of account + 5 years after closureLegal obligation

Upon expiry of the applicable retention period, personal data will be securely deleted or anonymized, unless further retention is required to comply with a legal obligation or to establish, exercise, or defend legal claims.

10. Your Rights Under the GDPR

Subject to applicable exceptions and limitations, you have the following rights under the GDPR in respect of your personal data:

10.1 Right of Access (Art. 15 GDPR)

You have the right to obtain confirmation of whether we process personal data concerning you and, if so, to receive a copy of that data together with information about the purposes, categories, recipients, retention periods, and the existence of automated decision-making.

10.2 Right to Rectification (Art. 16 GDPR)

You have the right to obtain the rectification of inaccurate personal data concerning you and to have incomplete personal data completed.

10.3 Right to Erasure / Right to Be Forgotten (Art. 17 GDPR)

You have the right to obtain the erasure of your personal data where:

  • the data is no longer necessary for the purposes for which it was collected;

  • you withdraw your consent and there is no other legal basis for the processing;

  • you object to processing under Art. 21 GDPR and there are no overriding legitimate grounds;

  • the personal data has been unlawfully processed;

  • erasure is required to comply with a legal obligation.This right is subject to exceptions, including where processing is necessary for compliance with a legal obligation or for the establishment, exercise, or defence of legal claims.

10.4 Right to Restriction of Processing (Art. 18 GDPR)

You have the right to obtain restriction of processing where:

  • you contest the accuracy of the data (restriction during the period of verification);

  • the processing is unlawful but you oppose erasure;

  • we no longer need the data but you require it for legal claims;

  • you have objected to processing pending verification of our legitimate grounds.

10.5 Right to Data Portability (Art. 20 GDPR)

You have the right to receive your personal data in a structured, commonly used, and machine-readable format and to transmit that data to another controller, where processing is based on your consent or on a contract and is carried out by automated means.

10.6 Right to Object (Art. 21 GDPR)

You have the right to object at any time, on grounds relating to your particular situation, to processing of your personal data that is based on our legitimate interests (Art. 6(1)(f) GDPR) or on a task carried out in the public interest (Art. 6(1)(e) GDPR). We will cease processing unless we demonstrate compelling legitimate grounds which override your interests, rights, and freedoms, or unless processing is necessary for legal claims.

Where personal data is processed for direct marketing purposes, you have the absolute right to object at any time to such processing, including profiling to the extent it relates to direct marketing. Upon receipt of your objection, we will immediately cease processing for direct marketing purposes (Art. 21(2) GDPR).

10.7 Rights in Relation to Automated Decision-Making and Profiling (Art. 22 GDPR)

You have the right not to be subject to a decision based solely on automated processing, including profiling, which produces legal effects concerning you or similarly significantly affects you. We [do / do not] carry out such automated decision-making. [Where we do, insert: the logic involved, the significance and the envisaged consequences for you, and how you may request human review of the decision.]

10.8 Right to Withdraw Consent (Art. 7(3) GDPR)

See Section 5.1 above.

10.9 How to Exercise Your Rights

To exercise any of the above rights, please contact us:

  • By email: [privacy@Stake.eu ]

  • By post: [Full address of controller or EU representative]

We will respond to your request without undue delay and in any event within one month of receipt of your request (Art. 12(3) GDPR). This period may be extended by a further two months where necessary, having regard to the complexity and number of requests. We will inform you of any such extension within one month of receipt of your request, together with the reasons for the delay. We will not charge a fee for responding to your request unless it is manifestly unfounded or excessive.

We may require you to verify your identity before acting on your request.

11. Right to Lodge a Complaint With a Supervisory Authority

You have the right to lodge a complaint with a competent data protection supervisory authority if you consider that the processing of your personal data infringes the GDPR (Art. 77 GDPR).

You may lodge a complaint with:

(a) The supervisory authority in the EU Member State of your habitual residence, place of work, or place of the alleged infringement. In Germany, the competent supervisory authorities are the Landesbeauftragte für Datenschutz of the relevant Federal State. A full list is available at: https://www.bfdi.bund.de/DE/Service/Anschriften/Laender/Laender-node.html .

(b) The lead supervisory authority for the controller, which is [identify the lead supervisory authority if applicable].

(c) The Federal Commissioner for Data Protection and Freedom of Information (BfDI):Graurheindorfer Str. 153, 53117 Bonn, GermanyTel.: +49 (0)228 997799-0Email: poststelle@bfdi.bund.de

This right does not prejudice any other administrative or judicial remedy available to you.

12. Security of Personal Data

We implement appropriate technical and organizational measures to ensure a level of security appropriate to the risk posed by the processing of your personal data, in accordance with Art. 32 GDPR. These measures include:

  • Encryption of personal data in transit (TLS/SSL) and at rest;

  • Pseudonymisation of personal data where appropriate;

  • Ongoing confidentiality, integrity, availability, and resilience of processing systems and services;

  • Regular testing, assessment, and evaluation of the effectiveness of technical and organisational measures;

  • Access controls limiting access to personal data to authorised personnel on a need-to-know basis;

  • Staff training on data protection.

In the event of a personal data breach that is likely to result in a risk to your rights and freedoms, we will notify the competent supervisory authority without undue delay and, where feasible, within 72 hours of becoming aware of the breach (Art. 33 GDPR). Where the breach is likely to result in a high risk to your rights and freedoms, we will also notify you directly without undue delay (Art. 34 GDPR).

13. Data Protection by Design and by Default

We implement data protection by design and by default in accordance with Art. 25 GDPR. This means that:

  • We only process personal data that is necessary for each specific purpose of processing (data minimization);

  • By default, personal data is not made accessible to an indefinite number of persons without your active involvement;

  • Privacy-protective settings are the default settings for our Services (privacy by default).

14. Profiling and Automated Decision-Making

[Where applicable, insert:] We carry out the following automated processing activities which may constitute profiling within the meaning of Art. 4(4) GDPR:

  • [Description of profiling activity, e.g., analysis of user gameplay patterns for responsible gaming monitoring]: Legal basis: Art. 6(1)(c)/(f) GDPR. This profiling [does / does not] produce legal effects or similarly significantly affect you. [If it does: describe the logic and envisaged consequences, and the right to request human review.]

Where profiling is used to make decisions that significantly affect you and is based on your consent, you may withdraw that consent at any time in accordance with Section 5.2 above.

15. Changes to this Privacy Policy

We may update this Privacy Policy from time to time to reflect changes in our practices, services, or legal requirements. Where we make material changes to this Privacy Policy that affect the processing of your personal data in a manner not previously disclosed to you, we will:

  • Notify you by email to the address associated with your account; and/or

  • Display a prominent notice on our website,

at least 30 days before the changes take effect, to give you the opportunity to review the changes and exercise any applicable rights (including the right to withdraw consent or to object to processing). Continued use of our Services after the effective date of the amended Privacy Policy does not constitute consent to the amended terms unless we have obtained your explicit consent where required.

16. Third-Party Services and Links

Where our Services contain links to third-party websites or services, this Privacy Policy does not apply to those third parties. We recommend that you review the privacy policies of any third-party services you access. We are not responsible for the privacy practices of third-party services.

17. Contact Us

For any questions, concerns, or requests relating to this Privacy Policy or the processing of your personal data, please contact:

Data Protection Contact:[privacy@Stake.eu ]

EU Representative (Art. 27 GDPR)

Data Protection Officer:[dpo@Stake.eu ]