Privacy Policy
Who We Are and How to Contact Us
We are Oreels, an online casino and betting operator providing services to players in the United Kingdom. For the purposes of applicable data protection laws, including the UK General Data Protection Regulation (UK GDPR), we act as the data controller of your personal data. This means we are responsible for how your information is collected, used, and protected when you use our website and services.
We have appointed a Data Protection Officer (DPO) to oversee compliance with data protection obligations. If you have any questions about this Privacy Policy or wish to exercise your rights, you can contact us at: [email protected]. You may also write to us via our registered business address, which is available on our website.
We are committed to handling your personal data transparently, securely, and in accordance with UK regulatory requirements, including those set by the UK Gambling Commission.
What Personal Data We Collect
When you use Oreels, we collect various types of personal data necessary to provide our services and comply with legal obligations. This includes identity data such as your full name, date of birth, and proof of identity documents. We also collect contact data, including your email address, phone number, and residential address.
We process financial and payment data, such as bank details, card information, and transaction history. Gameplay and transaction data, including betting activity, deposits, withdrawals, and account behaviour, are also recorded. Additionally, we collect technical data such as IP address, device information, browser type, and geolocation data to ensure compliance with licensing requirements.
We may also store your marketing preferences and communication choices. All data collected is relevant, limited, and necessary for the purposes outlined in this policy.
How and Why We Use Your Data
We process your personal data based on lawful grounds under UK GDPR. The primary basis is the performance of a contract, enabling us to create and manage your account, process transactions, and provide gaming services. We also process data to comply with legal obligations, particularly those related to gambling regulation, anti-money laundering (AML), and fraud prevention.
Where required, we rely on your consent, particularly for marketing communications and certain cookies. You may withdraw this consent at any time. In some cases, we rely on legitimate interests, such as improving our services, ensuring platform security, and preventing misuse, provided these interests do not override your rights.
We ensure that all processing activities are necessary, proportionate, and aligned with regulatory expectations in the UK iGaming sector.
KYC, AML and Regulatory Compliance
As a licensed operator, we are required to conduct Know Your Customer (KYC) and Anti-Money Laundering (AML) checks. This involves verifying your identity, age, location, and source of funds before allowing full access to our services. We may request official documentation such as passports, utility bills, or bank statements.
We also monitor gameplay and transaction activity to detect suspicious behaviour and ensure compliance with legal and licensing obligations. Geolocation data may be used to confirm that you are accessing our services from permitted jurisdictions.
This processing is carried out under legal obligation and is essential to maintaining a safe and regulated gambling environment. Failure to provide required information may result in restricted access or account suspension.
Cookies and Tracking Technologies
Oreels uses cookies and similar tracking technologies to enhance your experience, ensure platform functionality, and analyse performance. Cookies help us remember your preferences, manage sessions, and deliver relevant content. Some cookies are strictly necessary, while others require your consent.
We also use analytics tools and marketing cookies to understand user behaviour and improve our services. These technologies may collect information such as IP address, browsing patterns, and interaction data.
You can manage your cookie preferences through your browser settings or via our cookie consent tool. For more detailed information, please refer to our separate Cookie Policy, which explains the types of cookies used and their purposes.
Data Sharing and International Transfers
We may share your personal data with trusted third parties where necessary. These include payment providers, identity verification services, fraud prevention agencies, game providers, and marketing partners. We may also share data with regulators, law enforcement, and relevant authorities where legally required.
Some of our service providers may be located outside the United Kingdom. In such cases, we ensure that appropriate safeguards are in place, such as adequacy decisions or standard contractual clauses, to protect your data during international transfers.
We do not sell your personal data. All third parties are required to process your data securely and only for specified purposes in line with contractual obligations.
Data Retention and Security
We retain your personal data only for as long as necessary to fulfil the purposes outlined in this policy, including legal, regulatory, and operational requirements. Financial and AML-related records are typically retained for a minimum of five years, in accordance with UK regulations.
We implement robust security measures to protect your data, including encryption, secure servers, and strict access controls. Only authorised personnel have access to personal data, and all processing is conducted in a secure environment.
While we take all reasonable steps to protect your information, no system is entirely secure. We encourage you to use strong passwords and protect your account credentials.
Your Rights Under UK GDPR
As a user in the United Kingdom, you have several rights regarding your personal data. These include the right to access your data, request correction of inaccurate information, and request deletion where applicable. You also have the right to restrict processing, object to certain uses, and request data portability.
You may withdraw consent for marketing communications at any time. To exercise your rights, you can submit a Data Subject Access Request (DSAR) by contacting us via our DPO email. We will respond within the legally required timeframe.
If you are not satisfied with how we handle your data, you have the right to lodge a complaint with the Information Commissioner’s Office (ICO), the UK supervisory authority for data protection.