Neospin Privacy Policy
How Neospin collects, stores and protects player data, on what legal grounds, for how long, and what rights a Player has over their own information.
Who Controls the Data
Neospin.com is operated by Metlait SRL, registered at El Guayaval, Residencial La Campina Casa Numero Q-11, Cartago, El Guarco, Tejar, 30801, Costa Rica, under number 3-102-911867. Metlait SRL acts as Data Controller, which means the company decides how and why personal data is processed in the course of its relationship with a Player.
A Data Protection Officer is appointed and answers questions about personal data and about this policy at [email protected].
This policy explains data handling in line with applicable data protection law, including the Personal Information Protection and Electronic Documents Act (PIPEDA) and the General Data Protection Regulation (GDPR). It is reviewed periodically, and Players are encouraged to check this page from time to time.
Categories of Data Processed
Only data that is adequate, relevant and limited to the purpose is collected. The categories are:
- Identity data. Full name, username, date of birth, gender, nationality and official identification numbers such as a passport or ID card number;
- Contact data. Residential address, proof of address documentation, email address, telephone number and other contact details;
- Financial and transaction data. Bank account details, payment card details, documents evidencing source of funds or source of wealth, and records of deposits, withdrawals and other transactions on the platform;
- Gaming activity data. Games played, login and logout timestamps, wagering activity, bonus usage and any responsible gambling intervention;
- Technical data. IP address, location data, login credentials, browser type and version, operating system, time zone settings and other device information;
- Marketing and communication data. Marketing preferences and correspondence exchanged with support or through other channels;
- Voluntary data. Anything else a Player chooses to supply when using the services or contacting support.
Where the Data Comes From
Two sources feed the categories above. The first is the Player directly, at registration, during account use and in correspondence. The second is third parties, which includes verification providers, financial institutions and payment providers, AML and politically exposed person databases, regulators, responsible gambling databases, and marketing and affiliate partners.
Legal Grounds and Purposes
Every processing activity is limited to a specific and legitimate purpose with a valid legal ground behind it:
- Service delivery, on the ground of performance of a contract;
- Regulatory compliance, on the ground of legal obligation, which takes in anti money laundering rules, KYC checks, responsible gambling duties and statutory reporting;
- Fraud prevention and risk management, on the ground of legitimate interest in protecting the platform, its Players and the integrity of the business;
- Marketing and personalisation, on the ground of consent or of legitimate interest in delivering relevant offers and tailored advertising;
- Analytics and service improvement, on the ground of legitimate interest in monitoring performance, analysing usage, resolving technical faults and improving the experience;
- Security and system integrity, on the ground of legal obligation and legitimate interest in detecting threats and protecting the confidentiality, integrity and availability of data;
- Customer service automation through artificial intelligence, on the ground of legitimate interest. Third party conversational AI tools are integrated into the customer messaging platform to manage conversations, access tickets and profiles, analyse interaction patterns and generate support responses.
Who the Data Is Shared With
Delivering the service requires sharing data with trusted third parties. Each is contractually bound to use it only for a specified lawful purpose and under strict security obligations. The categories are:
- Companies within the corporate group;
- Game studios;
- Payment providers;
- Marketing partners;
- Regulators and supervisory authorities;
- Third party service providers;
- Conversational AI providers acting as data processors, which are granted limited access to the customer messaging workspace to support and automate service and marketing operations;
- AML and KYC verification tools;
- Professional advisers such as lawyers, accountants and notaries;
- Other trusted parties in the event of a merger, acquisition or sale, in which case Players are informed before the transfer takes place.
International Transfers
Where personal data is transferred across borders, for example for IT hosting, customer service or verification, appropriate safeguards apply. These include the European Commission’s Standard Contractual Clauses or transfers to countries covered by an adequacy decision. Comparable protection is applied to data processed by service providers in other jurisdictions, and accountability for their handling of that data remains with Metlait SRL.
How Long Data Is Kept
Personal data is retained only as long as the purpose requires or the law demands. Anti money laundering rules set a minimum of five years from the date an account is closed. Tax obligations and dispute resolution requirements may extend that period. Once the data is no longer needed it is securely deleted, anonymised or de-identified under established data protection standards.
Player Rights
A Player is entitled to:
- Access the personal data held about them;
- Correct data that is inaccurate or incomplete;
- Request deletion, subject to statutory retention requirements;
- Restrict processing in defined circumstances;
- Receive the data in a portable format or have it transferred to another provider;
- Object to processing based on legitimate interest, and to processing for marketing;
- Withdraw consent at any time where consent is the legal ground;
- Lodge a complaint with the local data protection authority.
Requests go to [email protected]. Fully automated decision making is not used in normal operations. Where an automated process is applied in a particular case, the Player is notified separately as the law requires.
Data Security
Unauthorised physical access to the facilities hosting processing systems is prevented, and those systems are located in data centres meeting recognised industry standards for physical and digital security. Access to personal data is limited to authorised staff.
Systems processing personal data are protected by passwords and authentication measures, with unique user identifiers issued for authentication. Access to files and programs follows a need to know principle, and controls prevent unauthorised installation or use of hardware and software. Secure and permanent deletion is applied to data that is no longer required.
Organisational measures prevent accidental mixing of personal data. A Data Protection Officer is appointed, and staff receive training in data privacy and data security.
Minors
Access to the Website is limited to individuals who have reached the legal gambling age in their jurisdiction, and never below 18. Personal data is not knowingly collected from anyone below that age. Where such data is identified, particularly through misuse of the platform, it is deleted and the matter is handled as the law requires.
Changes to This Policy
This policy may be adjusted over time to reflect changes in law, in technology or in the way the service operates. The date at the top of the page shows when it was last revised.