At Trino Casino, we run trinoo.de and we assume protecting the personal data of our German players earnestly. As a licensed entertainment platform, we’ve developed our operations to meet the strict standards of the General Data Protection Regulation (GDPR) and the German Federal Data Protection Act (BDSG). This document explains exactly how we gather, retain, manage, and secure your information when you access our website, engage in games, or communicate with our affiliate systems. We hold transparency is crucial for a trusting relationship. By outlining our data handling practices clearly, we intend you to remain confident that your sensitive financial details and personal identifiers are kept in a secure digital environment, managed by a responsible data controller that complies with local laws and jurisdictional boundaries.
Our affiliate network, reachable via our legal and affiliates hub, functions as a separate data processing area. We act as a joint controller together with our marketing partners. When a German webmaster or content creator enrolls in our partner program, we collect business details like tax identification numbers, bank account information for paying commissions, and traffic source analytics. Our tracking mechanism utilizes first‑party cookies dropped via a unique affiliate link, which enables us to attribute referred traffic to the correct partner account without capturing the browsing history of unregistered visitors. We process referred player data in a pseudonymized format for commission calculation, so the affiliate observes aggregated performance numbers rather than individual player identities. We examine player activity logs against traffic sources to catch bonus abuse or fake incentivized traffic; this is founded on our contractual and legitimate business interests. We have a strict affiliate code of conduct that prevents partners from targeting self-excluded individuals or using unauthorized direct marketing that could jeopardize the privacy expectations of the German audience.
We do not retain your personal data permanently. We follow a strict storage limitation principle. Active customer accounts hold data for the duration of the business relationship, from the moment you register until you formally close the account. After account closure, a holding period kicks in, driven mostly by German tax legislation and anti-money laundering rules. Transactional logs, identification documents collected under Know Your Customer protocols, and wagering history are securely archived for ten years from the end of the calendar year of the last transaction. Once that statutory retention window ends, we permanently destroy or irreversibly anonymize the records so re-identification becomes technically impossible. Web server log data that contains IP addresses gets truncated after a strict thirty‑day cycle to reduce security risks. For accounts that go dormant—no activity but not closed—we send a proactive reminder before the dormancy threshold, so we can ask for renewed consent or start the deletion process, always in line with the storage limitation principle.
Our principal data processing systems reside in safe data centers within the European Union, but at times we require sub-processors in different countries. In these specific cases, we guarantee the same level of security by using Standard Contractual Clauses endorsed by the European Commission, together with a detailed Transfer Impact Assessment. To safeguard your financial data from unapproved access during communication, we enforce Transport Layer Security (TLS 1.3) encryption across all terminals, blocking outdated cipher suites. At rest, personal data inside our managed database clusters is secured by AES‑256 encryption, and access to decryption keys is restricted to a segregated privileged access management system. We conduct continuous vulnerability scans, mandatory penetration tests, and stringent logical access controls so exclusively the personnel who must have it can see your data. We employ a specialized Data Protection Officer you can contact through our platform, and we maintain an incident response plan that requires us to inform the appropriate German supervisory authority within 72 hours if a personal data breach could pose your rights at risk.
To deliver a flawless entertainment experience that meets German regulations, we obtain a few specific kinds of personal data, solely what is required. During account creation, we request identification details: your legal first and last name, residential address with postal code, verified email address, and date of birth to make sure you meet the strict age minimum set by German regulators. When you commence playing, we manage financial transaction data—deposit amounts, withdrawal methods, partial payment card numbers encrypted with TLS, and e-wallet identifiers. Our systems capture technical device data like your IP address, which we restrict by location to confirm you’re in a permitted location, along with browser fingerprint hashes and operating system specs. We also monitor usage patterns and game session logs, recording bet history and time spent playing, so we can satisfy our responsible gaming obligations. We do not obtain special categories of sensitive data unless you freely give that information during a responsible gaming self-assessment or a support inquiry.
We are the data controller for all personal information collected through Trino Casino at trinoo https://trinoo.de/legal-and-affiliates/.de, which is tailored for users in Germany. Our legal team operates from a registered office inside the European Economic Area, making us fully bound by GDPR enforcement. When handling your data, we rely on six established lawful bases. Most of the time, we process your data to fulfill our contractual obligations—like taking bets, processing withdrawals, and keeping your account running. We also use legitimate interest for analytics and security measures, such as fraud detection algorithms and network integrity checks, as long as these don’t override your fundamental rights and freedoms. When required by law, particularly under anti-money laundering regulations and German gambling ordinances, processing occurs due to a legal obligation. Regarding marketing communications, such as our affiliate program, we rely on your explicit consent, which you can withdraw anytime without any effect on the essential services we deliver.
For residents of Germany, you are entitled to a set of rights that we’ve made simple to enforce. You can submit a subject access request at any moment. We are then required to verify whether we store your data and give you a version in a organized, standard, machine‑readable format within 30 days. The right to amendment lets you update obsolete or erroneous profile data without delay, which is crucial for efficient payment processing. Under certain circumstances, you may request a limitation of processing, especially if you contest the precision of data while we verify it. The right to deletion, commonly known as the “right to be forgotten,” is applicable when the data has become unnecessary for the primary goal, though statutory retention duties may momentarily override this request. You are also granted the right to data portability for information furnished under consent or contractual terms, so you are able to shift your usage history to a different provider. You have an absolute entitlement to oppose direct marketing, and you can object to data handling based on lawful interests, which we will assess against our own compelling grounds. Appeals can be lodged straight with the data protection authority of your German state if you suspect a infringement has happened.
We use a multi-tiered system: automatic checks against national databases and human document review. When you create an account, you must provide your national ID card or passport through an encrypted portal. Our compliance team verifies this with the Schufa identity service to verify legal age. If something does not align, we briefly restrict the account until a video identification call with a certified agent can clarify the situation, all in line with the German Interstate Treaty on Gambling.
No. Our affiliate programme employs a strict aggregation firewall. We never share your name, contact details, or payment records with the referring affiliate. The partner only accesses a pseudonymized dashboard with confirmed registration counts and a statistical summary of net gaming revenue. Our affiliate agreements explicitly prohibit them from attempting to identify individual players. This maintains your gameplay completely separate from the marketing channel that led you to Trino Casino.
Go to “Communication Settings” in your account dashboard and turn off promotional channels. Every marketing email we send has a one‑click unsubscribe link at the bottom that works right away. To withdraw consent for postal mail or SMS, contact our Data Protection Officer through the support ticket system. We’ll stop direct marketing within at most 48 hours after receiving your request.
If business ever stops, we are legally required to notify the competent German data protection authority and all active users in advance. Mandatory transactional logs and identification records will be securely transferred to a certified archival service or handed over to the responsible regulatory body for as long as the law demands. Any data that isn’t mandatory gets securely destroyed using cryptographic wiping techniques before the closure of our servers is finalized.
We use a limited automated profiling system to flag possible fraud or bonus abuse. If the system blocks a withdrawal, we’re required by law to involve a human. Our financial risk team manually checks every flagged transaction before we tell you the final decision. You can challenge that decision, give your side, and ask for a full manual review by our risk management specialists.
Contact us from the address associated with your account to our Data Protection Officer, include “SAR” in the subject line. We’ll verify your identity with a two‑factor verification. Following that, we gather your data from all systems—chat logs, game history, identity documents—and generate a digitally signed PDF and a machine‑readable JSON file, which you’ll receive within one calendar month.
Our website employs various digital markers, and our consent management system guarantees that no unnecessary trackers fire until a German visitor gives affirmative consent through our detailed settings panel. Necessary session cookies, which do not store personal information but maintain your game session and security credentials functioning, are excluded from approval requirements under the Electronic Privacy Directive as applied in German legislation. For ongoing analytics and affiliate attribution cookies, we implement server-side tracking where possible to minimize client‑side exposure. Our partner tracking pixel operates on a direct context model to bypass contemporary browser limitations, enabling precise attribution without invasive fingerprinting scripts that are forbidden under German internet law. We’ve grouped all tracking codes with thorough explanations of their function, timeframe, and the outside providers involved, so you can change your preferences at any time. Rejecting promotional cookies does not impair the performance of the game lobby or payment gateways. That demonstrates our privacy-first approach: core services are completely available irrespective of consent choices you choose.