Legal

Privacy & cookies.

1. Introduction

iGains BV ("iGains", "we", "us" or "our") respects your privacy and is committed to handling personal data responsibly and in accordance with applicable data protection laws, including the General Data Protection Regulation (EU) 2016/679 ("GDPR") and applicable legislation.

This Privacy Policy explains how iGains processes personal data when you:

  • visit our website;
  • contact us;
  • interact with our games or demonstrations;
  • register for or use our User Console;
  • communicate with us; or
  • otherwise interact with our business.

iGains is a B2B casino game and technology provider.

Our website and User Console are intended primarily for professional users. iGains does not operate a consumer-facing casino through this website and does not provide real-money gambling services directly to consumers.

2. Data Controller

The controller responsible for personal data processed in connection with the website and iGains' own business activities is:

Company: iGains BV

General Contact:

support@igains.io

Privacy Contact:

privacy@igains.io

3. Personal Data We May Collect

The type of personal data we process depends on how you interact with iGains.

3.1 Website Visitors

We may process technical information such as:

  • IP address;
  • browser type and version;
  • operating system;
  • device information;
  • pages or resources requested;
  • date and time of access;
  • referring website;
  • technical logs;
  • security information; and
  • cookie or consent preferences.

3.2 Contact Enquiries

If you contact us, we may process:

  • name;
  • company name;
  • job title or role;
  • business email address;
  • telephone number, where provided;
  • country;
  • information contained in your enquiry; and
  • technical information associated with the communication.

3.3 User Console Accounts

If you register for or use the iGains User Console, we may process:

  • name;
  • business email address;
  • business telephone number;
  • job title or role;
  • company information;
  • account credentials;
  • authentication information;
  • account permissions;
  • login dates and times;
  • IP addresses;
  • device and security information;
  • activity and audit logs;
  • API and integration information;
  • support communications; and
  • information required to administer the business relationship.

3.4 Business and Compliance Information

Depending on the relationship, we may process information concerning:

  • company identity;
  • ownership or control;
  • regulatory status;
  • gambling licences;
  • business authorisations;
  • authorised representatives;
  • compliance communications; and
  • information reasonably required for due diligence, security, fraud prevention or regulatory compliance.

4. How We Use Personal Data

We may process personal data to:

  • operate and secure our website;
  • provide access to the User Console;
  • authenticate users;
  • manage accounts and permissions;
  • provide customer and technical support;
  • respond to enquiries;
  • communicate with business contacts;
  • provide demonstrations and testing environments;
  • maintain and improve our Services;
  • monitor and investigate security events;
  • prevent fraud, abuse and unauthorised access;
  • maintain technical and audit records;
  • manage business relationships;
  • comply with legal and regulatory obligations;
  • establish, exercise or defend legal claims; and
  • protect the rights, property and security of iGains, our customers and other persons.

We will not use personal data for purposes incompatible with the purpose for which it was collected, unless permitted by applicable law.

5. Legal Bases for Processing

Depending on the circumstances, iGains relies on one or more of the following legal bases.

5.1 Contract

We may process personal data where necessary to establish or perform a contract or take steps at your request before entering into a contract.

This may include account administration, customer support and provision of requested Services.

5.2 Legitimate Interests

We may process personal data where necessary for legitimate interests pursued by iGains or a third party, provided those interests are not overridden by applicable rights and freedoms.

Examples may include:

  • securing our systems;
  • preventing fraud and abuse;
  • maintaining business relationships;
  • improving Services;
  • protecting intellectual property;
  • responding to business enquiries; and
  • establishing or defending legal claims.

5.3 Legal Obligations

We may process personal data where necessary to comply with applicable legal or regulatory obligations.

5.4 Consent

Where required, we may process personal data based on your consent.

Where processing is based on consent, you may withdraw that consent at any time.

Withdrawal does not affect the lawfulness of processing carried out before withdrawal.

6. Your Acknowledgement of this Policy

By using the iGains website, you acknowledge that you have read this Privacy Policy.

Your use of the website is subject to the iGains Website & User Console Terms and Conditions.

This acknowledgement is not intended to constitute consent where applicable law requires a separate consent mechanism.

Where iGains relies on consent for a particular processing activity, including non-essential cookies, we will request that consent separately through an appropriate mechanism.

7. Business Communications

We may use business contact information to communicate with you concerning:

  • an existing business relationship;
  • requested Services;
  • technical matters;
  • security matters;
  • account administration;
  • product updates; or
  • relevant iGains business developments.

Where consent is required for particular marketing communications, we will obtain it.

You may opt out of marketing communications at any time through an available unsubscribe mechanism or by contacting us.

Operational, contractual, security and legally required communications may continue where necessary.

8. Cookies and Similar Technologies

Our website may use cookies, local storage and similar technologies.

We distinguish between technologies that are necessary for the operation of the website and optional technologies such as analytics.

8.1 Essential Technologies

We may use strictly necessary technologies for purposes such as:

  • maintaining security;
  • remembering cookie preferences;
  • providing requested website functionality;
  • maintaining sessions; and
  • supporting essential technical operations.

Where a technology is strictly necessary, applicable law may allow its use without prior consent.

8.2 Optional Analytics

Where we use non-essential analytics or similar technologies, these will only be activated where the visitor has provided the relevant consent through our cookie consent mechanism.

Our current website provides the visitor with the choice between:

"Accept All"

and

"Essential Only".

Selecting "Essential Only" prevents optional analytics technologies from being activated, subject to the operation of strictly necessary technologies.

8.3 Changing Cookie Preferences

Visitors can change their cookie preferences through the cookie preference mechanism provided on the website.

iGains will provide a "Cookie Preferences" option, or an equivalent mechanism, through which the consent window can be reopened.

9. Demonstration Games

iGains may provide playable demonstrations of its Games.

Demo environments may process technical information such as:

  • IP address;
  • session information;
  • timestamps;
  • technical events;
  • security information; and
  • information necessary to prevent abuse and maintain service stability.

Demo sessions may use technical controls such as rate limiting.

Unless expressly stated otherwise, demo functionality does not create a persistent consumer gambling account and does not provide access to real-money gambling.

10. Security and Fraud Prevention

We process technical and account information where reasonably necessary to protect our Services against:

  • unauthorised access;
  • credential compromise;
  • malicious activity;
  • fraud;
  • abuse;
  • attacks;
  • automated misuse; and
  • other security threats.

Security information may include IP addresses, timestamps, authentication events, device information and other technical information reasonably required to investigate and prevent security incidents.

11. Who May Receive Personal Data

We may disclose personal data to categories of recipients where reasonably necessary for the purposes described in this Privacy Policy.

These may include:

  • hosting and infrastructure providers;
  • cloud service providers;
  • authentication providers;
  • security providers;
  • analytics providers, where applicable;
  • email and communications providers;
  • customer support providers;
  • professional advisers;
  • accountants and auditors;
  • legal advisers;
  • regulators and supervisory authorities;
  • law enforcement authorities, where legally required; and
  • other service providers acting on our behalf.

Where a third party processes personal data on our behalf, we seek to ensure that appropriate contractual and security safeguards are in place.

We do not sell personal data to data brokers.

12. International Data Transfers

Some service providers used by iGains may process personal data outside the European Economic Area ("EEA").

Where personal data is transferred outside the EEA, iGains will use an appropriate legal transfer mechanism where required by applicable law.

Depending on the circumstances, this may include:

  • an adequacy decision;
  • European Commission Standard Contractual Clauses;
  • appropriate supplementary safeguards; or
  • another legally recognised mechanism.

Where required, further information concerning relevant transfers and safeguards may be obtained by contacting privacy@igains.io.

13. Retention of Personal Data

We retain personal data only for as long as reasonably necessary for the relevant purpose, taking into account legal, contractual, regulatory, security and legitimate business requirements.

Different categories of personal data may therefore have different retention periods.

Contact Enquiries:

Normally retained for as long as reasonably necessary to handle the enquiry and any resulting business relationship.

User Accounts:

Retained while the account remains active and for a reasonable period afterwards where necessary for contractual, legal, security or dispute-related purposes.

Security and Audit Logs:

Retained for a period appropriate to the relevant security and operational purpose and the risks involved.

Business and Contractual Records:

Retained for periods required by applicable accounting, tax, legal or regulatory obligations.

Marketing Preferences:

Retained as necessary to respect communication preferences and demonstrate compliance.

When personal data is no longer required, it will be deleted, anonymised or securely disposed of, where appropriate.

14. Your Rights

Subject to applicable legal conditions and limitations, you may have the right to:

  • obtain confirmation as to whether we process your personal data;
  • request access to your personal data;
  • request correction of inaccurate or incomplete personal data;
  • request deletion of personal data;
  • request restriction of processing;
  • object to certain processing;
  • receive personal data you provided to us in a portable format, where applicable;
  • withdraw consent where processing is based on consent; and
  • object to direct marketing.

These rights are subject to the conditions and exceptions provided by applicable law.

15. How to Exercise Your Rights

Privacy requests can be submitted to:

privacy@igains.io

We may request additional information where reasonably necessary to verify your identity before responding to a request.

This is intended to prevent personal data from being disclosed to an unauthorised person.

We will respond within the period required by applicable law.

16. Right to Complain

You have the right to lodge a complaint with the competent data protection supervisory authority.

We nevertheless encourage you to contact iGains first where you have a question or concern so that we can attempt to resolve it.

17. Automated Decision-making

Unless expressly stated otherwise, iGains does not make decisions producing legal or similarly significant effects concerning individuals solely through automated processing.

Technical systems may automatically detect or flag events such as:

  • suspicious login activity;
  • unusual API activity;
  • security threats;
  • excessive requests; or
  • potential abuse.

These controls are primarily intended to protect the Services.

Where legally required, additional information concerning automated decision-making will be provided.

18. Data Security

iGains uses technical and organisational measures designed to protect personal data against unauthorised access, alteration, disclosure, loss or destruction.

Depending on the nature and risks of the processing, these measures may include:

  • access controls;
  • authentication;
  • encryption;
  • logging and monitoring;
  • backups;
  • network and application security;
  • credential management;
  • personnel access restrictions;
  • security procedures; and
  • incident response processes.

No internet-based service can guarantee absolute security.

19. Personal Data Breaches

Where iGains identifies a personal data breach for which notification is required under applicable law, we will take the measures required by the GDPR and other applicable legislation.

Where iGains processes personal data on behalf of a customer as a processor, notification and cooperation obligations will be handled in accordance with the applicable data processing agreement and applicable law.

20. Children

Our Services are intended for professional users and are not directed at children.

We do not knowingly collect personal data from children through the public website for consumer purposes.

If you believe that a child has unnecessarily provided personal data to us, please contact privacy@igains.io.

21. Third-party Websites

Our website may contain links to third-party websites.

This Privacy Policy does not govern those websites.

We recommend reviewing the privacy policies of third parties before providing personal data to them.

22. Controller or Processor

Depending on the nature of a particular processing activity, iGains may act as:

  • a data controller, where iGains determines the purposes and means of processing; or
  • a data processor, where iGains processes personal data on behalf of a customer under that customer's documented instructions.

Where iGains acts as a processor, the customer's instructions and any applicable data processing agreement govern the relevant processing, subject to applicable law.

Nothing in this Privacy Policy changes the allocation of responsibilities established by an applicable data processing agreement.

23. Changes to this Privacy Policy

We may update this Privacy Policy when our Services, technology, legal obligations or processing activities change.

The current version will be published on our website together with its effective date.

Where a change materially affects how we process personal data and notification is required, we will take appropriate steps to inform affected individuals.

24. Contact

For privacy questions, requests or concerns:

Company: iGains BV

Privacy:

privacy@igains.io

Security:

security@igains.io

Website:

https://igains.io

Effective date: 25 August 2026 · iGains BV