OLYBET.LT WEBSITE PRIVACY NOTICE

1 General

1.1 This website is operated by „Olympic Casino Group Baltija“, UAB, legal entity code 211733760, address Konstitucijos ave. 12 LT09308 Vilnius, Lithuania (“OLYBET” or “we”). OLYBET recognizes the importance of your privacy and is committed to protecting your personal data. This privacy notice (“Notice”) explains the principles on how OLYBET collects and uses information when you visit the website www.olybet.lt („Website“) and use any of the gaming services provided on the Website („Service“).   

1.2 OLYBET processes your personal data under this Notice and in accordance with applicable legislation, including the General Data Protection Regulation (2016/679) and the applicable national data protection laws of the Republic of Lithuania, as applicable towards the personal data controller stated in Section 2 of this Notice.

2 Personal data controller

2.1 For the personal data processing purposes brought out in Section 5 of this Notice, the controller of your personal data is:

Olympic Casino Group Baltija, UAB

Legal entity code: 211733760

Address: Konstitucijos ave. 12 LT09308 Vilnius, Lithuania

E-mail: [email protected]

3 Data protection officer

3.1 You shall have the right to communicate with OLYBET’s data protection officer in order to obtain information on the processing of your personal data. OLYBET’s data protection officer’s contact references are:

E-mail: [email protected]

 

4 Categories and sources of personal data OLYBET collects and processes

4.1 Personal data are information that can be used to directly or indirectly uniquely identify, contact, or locate you as a private individual (“Personal Data”). The source of the collected Personal Data depends on how you interact with us. 

4.1.1 Registration data. OLYBET processes the following Personal Data related to your registration to the Website: e-mail address, country of residence, phone number, etc („Registration Data“).

Source: Personal Data you directly provide to OLYBET upon registration.

4.1.2 Verification data. OLYBET processes the following Personal Data in order to complete your registration and verify your admissibility to use the Service: name, surname, date of birth, personal code, user name, user ID, document type, document number, document validity, document copy, country, which issued document, citizenship, address, language, currency, date, time, mobile sign, etc. („Verification Data“).

Source: Personal Data you directly provide to OLYBET upon registration and Personal Data made available to us by the verification service providers.

4.1.3 Anti-money laundering data. OLYBET processes the following Personal Data in order to designate whether you are, or you are related to a politically exposed person: name, surname, personal code or date of birth, information on political exposure, winning place time and date, etc („AML Data“).

Source: Personal Data you directly provide to OLYBET as necessary.

4.1.4 Gambling data. OLYBET processes the following data in order to provide you with the Service: self-exclusion data, gaming-exclusion data, user ID, bet ID, currency, bet amount, current balance, game ID, seller ID, bet type, bet status, expected max win amount, bet result date, win amount, payout amount, login data, IP-address, currency, date and time of entering and exiting the Service, etc („Gambling data“).

Source: Personal Data you provide us whilst using the Service and the Personal Data gathered from the databases available to OLYBET in relation to providing the Service (e.g. list of persons with restrictions on gambling (www.nelosti.ltp.lt).

4.1.5 Transfer data. OLYBET processes the following data to commence the money transfers related to the Service: name, surname, banking number, date, time, transaction amount, etc („Transfer Data“).

Source: Personal Data you provide us upon requesting monetary transfer and Personal Data received from the payment service providers.

4.1.6 Communications data. OLYBET processes the following Personal Data, if you interact with OLYBET via Website’s chatbot, e-mails or complaint reports: contents of your message, e-mail address or social media contacts, etc („Communication Data“).

Source: Personal Data you directly provide to OLYBET.

4.1.7 Technical data. OLYBET processes the following data when you visit the Website: IP address (including location based on the IP address), access-provider, referring URL, date, time, access tokens, session key, browser type and version, operating system, amount and state of transferred data, MAC-address (“Technical Data”).

Source: While you are browsing through the Website, the Website itself generates or collects the Technical Data from your device automatically.

4.1.8 Marketing data. OLYBET processes the following personal data for marketing purposes: e-mail address, phone number, your preferences. („Marketing Data“)

Source: Personal Data you directly or indirectly (e.g. via cookies) provide to OLYBET whilst using the Service.

4.1.9 Cookie data. OLYBET implements cookies on the Website for optimising the Website and its functionalities. The cookies may collect your Personal Data. For further information, please see OLYBET’s cookie notice („Cookie Data“)

4.2 If you fail to provide necessary information, OLYBET is not able to register your user account, provide you with the Service or fulfill any other purposes provided in Section 5 of this Notice.

5 Legal basis and purposes for processing the personal data

5.1 OLYBET’s legal basis to process your Personal Data depends on the objective and context in which we collect the Personal Data. For easier understanding, we have grouped all purposes and data categories for processing the Personal Data with the following legal grounds: performance of a legal obligation, performance of a contract, OLYBET’s legitimate interest and your consent.

5.2 If the legal basis for processing the Personal Data is:

5.2.1 performance of a legal obligation, then this means first and foremost that OLYBET is required to process certain Personal Data by law. In this case we cannot decide which personal data are collected and processed, as it derives from applicable laws;

5.2.2 performance of a contract, then this means processing Personal Data for the performance of a contract to which you are a party, i.e. the terms and conditions and regulations, which you have accepted upon registration to the Service;  

5.2.3 OLYBET’s legitimate interest, this means first and foremost the objective of improving the Website and OLYBET’s business activities. However, specifics of the legitimate interests, as used in each separate case, are referred in the table below;

5.2.4 consent, this means first and foremost that Personal data shall only be processed, if your consent is granted, for example, ensuring an effective user experience by adjusting the Service is only possible upon your consent, without your consent it would not be possible to tailor the Service to meet your preferences.

5.3 The following depicts a non-exhaustive list of processing purposes that are linked to the specific data categories and legal basis for processing:

Processing purpose

Legal basis for the processing purpose

Categories of personal data used by us for the processing purpose

Sending marketing info to you via e-mail, SMS or phone; tailor the content of the marketing info based on your preferences

Your consent provided by ticking your preferences on the “Registration” page; your consent provided for the application of certain cookies

Marketing Data; Cookie Data

Registering your user account on the Website

Performance of the contract between you and OLYBET

Registration Data

Transfer of identification data from betting shop, casino and/or slot hall database to your online Service user account

Performance of the contract between you and OLYBET

Registration Data

Verification Data

Identity verification

Performance of a legal obligation under the Lithuanian Law on Prevention of Money

Laundering and Terrorist Financing

Registration Data

Verification Data

AML Data

 

 

 

Identification and registration of politically exposed persons

Performance of a legal obligation under the Lithuanian Law on Prevention of Money

Laundering and Terrorist Financing

AML Data

Record keeping about the bets made by you, funds transferred to us for making the bets, refunds made, and monetary transfers made to you

Performance of a legal obligation under the Lithuanian Gambling Law.

Verification Data, Gambling Data

 

Self-exclusion check from the Registry of the   Gaming Control Authority

Performance of a legal obligation under  Lithuanian Gambling Law.

Customer ban check from OLYBET’s ban registry

Performance of a legal obligation under the  Lithuanian Gambling Law and enforcing of the contract between you and OLYBET

Registering your entrance and exiting from the Service (log in to the Service’s environment)

Performance of a legal obligation under the  Lithuanian Gambling Law

Registering and displaying you the information about for how long you have been playing and the amounts of bets made and prizes won

Performance of a legal obligation under the  Lithuanian Gambling Law

Improvement, personalisation (preferences) and development of the Website and the Service

OLYBET’s legitimate interest in developing and enhancing the Website, the Services and the user experience in the course of its regular business activities

Technical Data, Cookie Data, Communication Data

Enabling customer support and communication between you and OLYBET; customer feedback registration and handling

OLYBET’s legitimate interest in providing effective user relations management

Communication Data

Transfer of funds from a payment service provider or from a bank to your online Service account

Performance of the contract between you and OLYBET

Gambling Data, Transfer Data

Transfer of the winning amount payment to your banking account

Performance of the contract between you and OLYBET

Verifying that your banking account data matches your Service’s account data

Performance of a legal obligation under the  Lithuanian Gambling Law

Verification Data, Transfer Data, Registration Data

Tracking and registration of customer transaction starting from 1000 € pursuant to the anti-money laundering requirements

Performance of a legal obligation under the Lithuanian Law on Prevention of Money Laundering and Terrorist Financing

 

Verification Data

 

Reporting to the Lithuanian Financial Crime Investigation Service and Gaming Control Authority about your monetary operations starting from 15 000 €

Performance of a legal obligation under the Lithuanian Law on Prevention of Money Laundering and Terrorist Financing

Verifying your identity and age

Performance of a legal obligation under Law on Prevention of Money Laundering and Terrorist Financing and Gambling Law.

Fraud detection/AML compliance

 

Performance of a legal obligation under Law on Prevention of Money Laundering and Terrorist Financing and Gambling Law.

Diagnose and repair problems with the Website and the Service

OLYBET’s legitimate interest in providing data security and preventing fraudulent actions related to the Website and the Service, also, ensure the functioning of the Website and the Service

Technical Data, Gaming Data, AML Data, Verification Data

Analysing statistical data regarding the usage of the Website and Service

OLYBET’s legitimate interest in analysing the functioning of the Website and Service for its business development

Technical Data, Cookie Data, Gaming Data

Data transfers to separate data controllers for receiving verification, payment and fraud prevention services

OLYBET’s legitimate interest in detecting and deterring suspicious and fraudulent actions related to the Website and the Service

Technical Data, Cookie Data, Gaming Data, Verification Data, Transfer Data

Providing the online gaming environment as a Service for casino, poker or sports betting

Performance of the contract between you and OLYBET

Registration Data, Verification Data, AML Data, Gambling Data, Transfer Data, Communication Data, Technical Data, Marketing Data, Cookie Data

Ensuring the safety of the Website and the Service by detecting and preventing the use of interfering software, devices and techniques

OLYBET’s legitimate interest in ensuring the safety of data processing, the Website and the Service

Data transfers within the OLYBET group

OLYBET’s legitimate interest in utilising shared administrative infrastructure and optimising costs (including data storage)

Storing materials containing Personal Data in OLYBET’s backup systems

OLYBET’s legitimate interest in ensuring the security of data processing operations

 

5.4 We may process your Personal Data for other purposes, provided that OLYBET discloses the purposes and use to you at the relevant time, and that you either consent to the proposed use of the Personal Data, other legal grounds exist for the new processing purposes or the new purpose is compatible with the original purpose brought out above.

6 Automated decision making and profiling

6.1 In the course of you browsing the Website and using the Service, OLYBET may sometimes apply automated processing to your Personal Data and make automated decisions based on your Personal Data. These automated decisions can affect the content and access to the Service or its features.

6.2 In the following situations we may apply automated decision making as authorised by applicable laws or is necessary for the performance of the contract between you and OLYBET:

6.2.1 Verifying your identity and allowance of providing access to the Service upon registration of the user account on the Website: upon registering to the Service on the Website, we verify via partially automated decision whether you meet the criteria for registering the user account and accessing the Service. The decision making process entails analysing your Personal Data, such as date of birth (age), personal identification number, nationality, self-exclusion data and gaming-exclusion data against the statutory allowance requirements. These data are usually directly made available by you or gathered from the databases available to OLYBET in relation to providing the Service (e.g. list of persons with restrictions on gambling). As a result of the partially automated decision your registration and access to the Service is completed or declined;

6.2.2 User payment verification: according to applicable laws, OLYBET is obliged to check whether your payment account details match the user account details you have provided for the use of the Service. Personal Data subject to such automated decision are the banking account details (name, banking account number). These data are collected directly from you and received from the payment service provider. As a result of the automated decision any money transfer to your user account or to you is completed or declined;

6.2.3 Risk assessment and compliance with the sports rules and other Service’s rules: pursuant to the regulations, OLYBET does not allow cooperation between customers and thus applies active measures to avoid the use of scripts, bots and other devices and techniques interfering the fair play. To combat any interferences of fair play and non-compliances of the binding Service’s rules, we analyse your activities on the Website and in the Service. For such analysis we mainly rely on the Technical Data and Gambling Data as defined in Sections 4.1.4. and 4.1.7. above.  We compare such data against data previously collected by us or received from third party service providers about you or your device. As a result of the automated decision, OLYBET and/or the engaged gaming service provider (who processes such data in aggregated manner based merely on User ID) may restrict the access to the Service’s functions (e.g. cancel repeated bets from the same IP address or shared address, limit maximum bet amounts, etc.) if the activity is non-compliant;

6.2.4 Fraud detection: pursuant to the applicable laws, OLYBET is obligated to detect and deter activities relating to money laundering and fraud. For this purpose, OLYBET or a fraud prevention service provider compares your device’s online identifiers (e.g. Technical Data and Cookie Data as defined in Sections 4.1.7. and 4.1.9. above) and Gambling Data (see 4.1.4 above) against similar type of data previously collected about you or your device used to access the Website. If it is detected that your account or device has fraudulent pattern or is connected to money laundering, as a result of the automated decision, OLYBET may restrict your access to the Service (e.g. block or freeze your user account).

6.3 The automated decisions described in Section 6.2 above usually take place without human intervention. You have the right to obtain human intervention in regard to the decision making defined in Sections 6.2.3 and 6.2.4; express your point of view in regard to such decision and contest the decision.

7 Personal data retention period

7.1 Your Personal Data (all data categories mentioned in Section 4.1.9, except for Cookie Data) shall be stored insofar as reasonably necessary to attain the objectives stated in Section 5 of this Notice, or until the legal obligation stipulates that we do so. The following is a non-exhaustive summary with examples on storing your Personal Data:

7.1.1 Registration Data, Verification Data, AML Data and Gambling Data will be retained up to 7 years as of the last log-in to your user account;

7.1.2 Transfer Data will be retained for 7 years as of the end of the financial year the transaction was recorded in the accounting documents. Please note that the data about transactions starting from 1000 € will be retained for 7 years as of the last log-in to your user account. The reports to the Gaming Control Authority and Financial Crime Investigation Service about the transactions starting from 15 000 € will be retained for the period of 5 years;

7.1.3 Marketing Data will be retained for 1 year as of the collection of such data;

7.1.4 Communication Data will be retained for 3 months as of the collection of such data;

7.1.5 Technical Data will be retained for 30 days as of the collection of such data.

7.2 After the retention period mentioned in Section 7.1 of this Privacy Notice, we might either retain your Personal Data for longer period, if it is necessary to comply with our legal obligations, meet regulatory requirements, resolve disputes and enforce the contract between you and OLYBET or anonymize your Personal Data and retain this anonymized information indefinitely.

7.3 After the expiry of the retention period referred to in Section 7.1. of this Privacy Notice or the termination of the legal basis for processing purpose, OLYBET shall retain the materials containing the Personal Data in the backup systems, from which the corresponding materials will be deleted after the end of the backup cycle. OLYBET ensures that during the backup period, appropriate safeguards are applied to the materials in the backup. The backed-up materials are put beyond the use, i.e. are not processed for any other purpose, and the materials are deleted by OLYBET as soon as possible, i.e. after the end of the OLYBET’s backup cycle, the Personal Data will be destroyed. 

8 Your rights as a data subject

8.1 We have a legal obligation to ensure that your Personal Data is kept accurate and up to date. We kindly ask you to assist us to comply with this obligation by ensuring that you inform us of any changes that have to be made to any of your Personal Data that we are processing.

8.2 You may, at any time, exercise the following rights with respect to our processing of your Personal Data by contacting us via contact information referred to in this Notice:

8.2.1 Right to access: you have the right to request access to any data that can be considered your Personal Data. This includes the right to be informed on whether we process your Personal data, what Personal Data categories are being processed by us, and the purpose of our data processing;

8.2.2 Right to rectification: you have the right to request that we correct any of your Personal Data if you believe that it is inaccurate or incomplete;

8.2.3 Right to object: you are entitled to object to certain processing of Personal Data, including for example, making automated decisions based on your Personal Data or when we otherwise base the processing of your Personal Data on our legitimate interest;

8.2.4 Right to restrict Personal Data processing: you have the right to request that we restrict the processing of your Personal Data if you wish to: (i) object the lawfulness of the processing; (ii) fix unlawful processing of Personal Data; (iii) receive or avoid deletion of Personal Data for establishing or defending against legal claims; or (iv) demand restriction of the processing until assessing the plausibility of OLYBET’s legitimate interest in the specific processing activity;

8.2.5 Right to erasure: you may also request your Personal Data to be erased if the Personal Data is no longer necessary for the purposes for which it was collected, or if you consider that the processing is unlawful, or if you consider that the Personal Data has to be erased to enable us to comply with a legal requirement;

8.2.6 Right to data portability: if your Personal Data is being automatically processed with your consent or on the basis of a mutual contractual relationship, you may request that we provide you that Personal Data in a structured, commonly used and machine-readable format. Moreover, you may request that the Personal Data is transmitted to another controller. Bear in mind that the latter can only be done if that is technically feasible;

8.2.7 Right to withdraw your consent: in cases where the processing is based on your consent, you have the right to withdraw your consent to such processing at any time without any adverse effect;

8.2.8 Right to submit your claim with the supervisory authority: if you are not satisfied with our response to your request in relation to Personal Data or you believe we are processing your Personal Data not in accordance with the law, you can submit your claim with the Lithuanian Data Protection Inspectorate () at www.ada.lt.

8.3  Please note that you will need to provide sufficient information for us to handle your request regarding your rights brought out in Section 8.2 of the Notice. Prior to answering your request, we may ask you to provide additional information for the purposes of authenticating you and evaluating your request.

9 Sharing your personal data and data transfers

9.1 OLYBET discloses your Personal Data to third parties only in accordance with this Privacy Policy and to persons authorised to process Personal Data, who have undertaken to observe confidentiality or are subject to appropriate statutory confidentiality. In specific cases, OLYBET will only share your Personal Data with a third party if you have given consent to such disclosure.

9.2 Only if necessary for fulfilling its statutory or contractual obligations, OLYBET may disclose your Personal Data to the following recipients (including data processors) in its data processing activities (as necessary):

Type of the recipient

Purpose of disclosure

Location of the recipient

Online game service providers

Providing you with the online gaming environment (note that the Personal Data is mainly disclosed in aggregated format, which does not identify you specifically)

Mainly European Union, but also Isle of Man, Guernsey, and Canada

Verification and authentication service providers

Providing verification and authentication services to provide you access to the Service; and deter and detect fraud

European Union and USA

Payment service providers (including payment institutions, e.g. banks) and other money transfer service providers

Transfer of funds from a payment service provider or from a bank to your online Service account and transfer of the winning amount payment to your banking account

Mainly European Union, but also Guernsey

Law enforcement and data protection authorities

OLYBET discloses your Personal Data to law enforcement and data protection authorities only if we are under a duty to disclose or share these data in order to comply with any legal obligation (for example, if required to do so under applicable law, by a court order or for the purposes of prevention of fraud or other crime)

European Union

Operational service providers (legal advisors, accounting etc. bound to confidentiality)

Legitimate interests in ensuring the functioning of the Website and the Service; conducting of regular business activities

European Union

IT-services providers

Providing IT solutions necessary for operating the Website and the Service

Mainly European Union and USA

Third party service providers

Providing you with the possibility to connect your user account with your social media accounts.

Mainly European Union and USA

OLYBET group entities

For the purposes utilising the shared administrative infrastructure

European Union

 

9.3 In some cases, we may transfer your Personal Data outside the European Union or European Economic Area, if the respective operational services are provided outside the European Union or European Economic Area. We shall opt to use special Personal Data protection safeguards, in order to ensure the safety of your Personal Data. You have the right to get acquainted with or obtain information on the comprehensive list of data processors, transferring of your Personal Data outside the European Union or European Economic Area and the safeguards implied thereof by contacting us using the contact information specified in this Notice.


10. Information about Processing Olympic Casino and OlyBet Customers’ Personal Data for Direct Marketing and Analytics Purposes

10.1. The joint controllers of your personal data are Olympic Entertainment Group AS, who is the operator of Olympic Casino in Estonia, OB Holding 1 OÜ, who is the operator of OlyBet in Estonia, and Olympic Casino Group Baltija UAB, who is the operator of Olympic Casino and OlyBet in Lithuania.

The contact details of these data controllers are as follows:

Olympic Entertainment Group AS

Registry code 14437516,

address Pronksi tn 19, 10124 Tallinn, Estonia

E-mail [email protected]

 

OB Holding 1 OÜ

Registry code 14975047

address Pronksi tn 19, 10124 Tallinn, Estonia

E-mail [email protected]

 

Olympic Casino Group Baltija UAB

Registry code 211733760

Address Konstitucijos pr. 12, LT-09308 Vilnius, Lithuania

Email [email protected]

10.2. We use the electronic contact details provided by you to send you information and special offers on the subjects chosen by you to promote the businesses of Olympic Casino and OlyBet. The legal basis for processing your personal data is your consent (Art 6(1)(a) of the GDPR).

10.3. If you agree, the information and special offers will be personalised, i.e., sent to you based on our best understanding of your interests and behaviour. In making these offers, we may contact you based on, for example, your use of Olympic Casino and OlyBet services (e.g., if you prefer certain games in Olympic Casino, we may notify you if such games become available in OlyBet; if you have participated in certain events or offers before, offer them to you again; provide special offers to players who have staked a certain amount, etc.). The purpose is to know you better in order to incentivize you to use our services. In doing so, we use both profiling and automated decision-making. The automated decisions usually take place without human intervention. However, they do not bring about any legal effects to you or otherwise similarly significantly affect you. At worst, we may send you offers you are not interested in. The personalised offers may somewhat increase the addiction of compulsive gamblers; however, we have taken the necessary safeguards and never target any such player knowingly and strongly encourage responsible gaming. You have the right to obtain human intervention regarding the decision making, express your point of view regarding such decisions, and contest the decisions. The legal basis for processing your personal data is your consent (Art 6(1)(a) of the GDPR).

10.4. We will process your personal data for the above-mentioned purposes until you withdraw your relevant consent(s), asking you to update your preferences from time to time.

10.5. We also provide you information and special offers via phone or when you visit Olympic Casino or OlyBet. These offers are usually personalised, i.e., based on our best understanding of your interests and behaviour as explained above. The legal basis for processing your personal data is our legitimate interest to promote the businesses of Olympic Casino and OlyBet (Art 6(1)(f) of the GDPR). In such case, we have concluded that, considering the circumstances, our legitimate interest is not overridden by your interests or fundamental rights and freedoms which require protection of personal data. You have the right to object at any time to such processing by contacting us on the contact details below. In such case, your personal data will no longer be processed for direct marketing purposes.

10.6. We use the personal data you have provided us or that has been created based on your use of Olympic Casino and OlyBet services on an aggregated level for analytics, i.e., to understand our customers, their needs, and behaviour better in order to make better marketing and business decisions. Your personal data is sent to Estonia and analytics is performed by joint controllers Olympic Entertainment Group AS and OB Holding 1 OÜ. We analyse your data for example to understand which Olympic Casino games are popular and should also be available in OlyBet to increase its use; in which order the games should be listed to increase their popularity; which OlyBet sports events are popular and should be streamed in Olympic Casino; what are the characteristics of customers who are active either only or both online and offline; etc. Although such analytics may initially be based on some of your personal data, the data is aggregated, and no personal data is used in any reports.

The legal basis for processing your personal data is our legitimate interest to make better marketing and business decisions and to promote the businesses of Olympic Casino and OlyBet (Art 6(1)(f) of the GDPR). In such case, we have concluded that, considering the circumstances, our legitimate interest is not overridden by your interests or fundamental rights and freedoms which require protection of personal data. You have the right to object, on grounds relating to your situation, at any time to such processing by contacting us on the contact details above. In that case, we will no longer process your personal data for analytics purposes unless we demonstrate compelling legitimate grounds for the processing which override your interests, rights, and freedoms.

10.7. We will process your personal data for the above-mentioned purposes until you object to it and we do not have the right to continue processing or until you have an active agreement with us.

10.8. Note that our other personal data processing practices are described in our respective Privacy Policies, available on our respective websites (www.olympic-casino.lt for Olympic Casino and www.olybet.lt for OlyBet). Olympic Casino’s Privacy Policy is also available at the Olympic Casino reception. Also note that the withdrawal of consent(s) for or opting out from the marketing and analytics purposes does not preclude us from processing your personal data for other purposes described in the Privacy Policies.

11 Amendments to this notice

11.1 This Notice may be amended or modified from time to time to reflect changes in the way we process Personal Data and, in such case, the most recent version of the Notice will appear on this page. We will alert you about the essential amendments. Please check back periodically, and especially before you provide any new personally identifiable information.

Last updated on 09.04.2020