
At Trino Casino, we operate trinoo.de and we assume protecting the personal data of our German players conscientiously. As a licensed entertainment platform, we’ve developed our operations to meet the strict standards of the General Data Protection Regulation (GDPR) and the German Federal Data Protection Act (BDSG). This document describes exactly how we collect, hold, process, and protect your information when you visit our website, participate in games, or communicate with our affiliate systems. We hold transparency is essential for a trusting relationship. By outlining our data handling practices clearly, we want you to remain confident that your sensitive financial details and personal identifiers are kept in a secure digital environment, controlled by a responsible data controller that respects local laws and jurisdictional boundaries.
2. Categories of User Information Gathered When Creating an Account and Gameplay
To provide a seamless entertainment experience that complies with German regulations, we obtain a few certain types of personal data, solely what is required. During account creation, we ask for identification details: your legal first and last name, residential address with postal code, verified email address, and date of birth to make sure you satisfy the strict age minimum established by German regulators. When you begin gaming, we manage financial transaction data—deposit amounts, withdrawal methods, partial payment card numbers encrypted with TLS, and e-wallet identifiers. Our systems automatically log technical device data like your IP address, which we restrict by location to ensure you’re in a permitted deutschlandfunk.de location, along with browser fingerprint hashes and operating system specs. We also track usage patterns and game session logs, recording bet history and time spent playing, so we can satisfy our responsible gaming obligations. We do not gather special categories of sensitive data except when you voluntarily give that information during a responsible gaming self-assessment or a support inquiry.
4. Data Storage Timelines and Data Masking Strategies
We do not retain your personal data permanently. We adhere to a strict storage limitation principle. Active customer accounts store data for the duration of the business relationship, from the moment you register until you formally close the account. After account closure, a holding period kicks in, driven mostly by German tax legislation and anti-money laundering rules. Transactional logs, identification documents collected under Know Your Customer protocols, and wagering history are securely archived for ten years from the end of the calendar year of the last transaction. Once that statutory retention window ends, we permanently destroy or irreversibly anonymize the records so re-identification becomes technically impossible. Web server log data that contains IP addresses gets truncated after a strict thirty‑day cycle to reduce security risks. For accounts that go dormant—no activity but not closed—we send a proactive reminder before the dormancy threshold, so we can ask for renewed consent or start the deletion process, always in line with the storage limitation principle.
3. Specific Processing Activities Connected with the Affiliate Programme
Our affiliate network, accessible through our legal and affiliates hub, serves as a separate data processing area. We act as a joint controller together with our marketing partners. When a German webmaster or content creator registers for our partner program, we gather business details like tax identification numbers, bank account information for paying commissions, and traffic source analytics. Our tracking mechanism utilizes first‑party cookies dropped via a unique affiliate link, which lets us attribute referred traffic to the correct partner account without capturing the browsing history of unregistered visitors. We process referred player data in a pseudonymized format for commission calculation, so the affiliate sees aggregated performance numbers rather than individual player identities. We check player activity logs against traffic sources to catch bonus abuse or fake incentivized traffic; this is grounded in our contractual and legitimate business interests. We have a strict affiliate code of conduct that prohibits partners from targeting self-excluded individuals or using unauthorized direct marketing that could compromise the privacy expectations of the German audience.
1. Určení správce údajů a právní důvod zpracování
We act as the data controller for all personal details collected through Trino Casino at trinoo.de, which is customized for German users. Our legal team operates from a registered office inside the European Economic Area, making us fully bound by GDPR enforcement. For processing your data, we depend on six specified lawful bases. Typically, we process your data to satisfy our contractual commitments—including placing bets, processing withdrawals, and keeping your account active. We also employ legitimate interest for analytics and security actions, including fraud detection algorithms and network integrity checks, as long as these do not outweigh your fundamental rights and freedoms. Where legislation requires it, especially under anti-money laundering laws and German gambling ordinances, processing is carried out due to a legal duty. Regarding marketing communications, such as our affiliate program, we rely on your explicit consent, which you can withdraw anytime without any effect on the essential services we deliver.
6. Applying Your own Rights Pursuant to German and EU Regulations
For residents of Germany, you have a collection of prerogatives that we’ve made easy to enforce. You may file a personal data inquiry at any time. We must to ascertain whether we hold your data and provide you with a copy in a structured, widely adopted, machine‑readable format within 30 days. The right to amendment lets you correct obsolete or erroneous profile details without hesitation, which is vital for seamless payment handling. Under certain circumstances, you can demand a suspension of data handling, notably if you challenge the correctness of data while we verify it. The right to erasure, often called the “right to be forgotten,” applies when the data has become unnecessary for the original purpose, though mandatory storage requirements may momentarily overrule this request. You additionally possess the right to data transfer for information furnished under authorization or contract, so you can move your activity log to a different provider. You enjoy an absolute prerogative to refuse direct marketing, and you are able to contest to operations based on justified grounds, which we’ll evaluate against our justifiable bases. Grievances can be lodged directly with the privacy regulator of your German region if you think a breach has occurred.
7. Cookie Handling and Tracking Tools for Regulatory Compliance
Our website employs different digital markers, and our consent management platform guarantees that no non-essential trackers trigger until a German user gives active consent through our comprehensive preference center. Required session cookies, which do not store personal information but preserve your game session and security keys functioning, are free from consent requirements under the Electronic Privacy Directive as enforced in German law. For ongoing analytics and partner attribution cookies, we employ server-side tracking where possible to reduce browser-side exposure. Our affiliate tracking code operates on a direct context model to bypass current browser restrictions, enabling correct tracking without invasive fingerprinting scripts that are banned under German digital law. We’ve grouped all scripts with comprehensive descriptions of their function, duration, and the external vendors engaged, so you can modify your settings whenever you wish. Declining promotional cookies doesn’t harm the performance of the game lobby or payment gateways. That reflects our privacy-first approach: basic services are entirely usable irrespective of consent choices you make.
5. Global Movements and Technical Safety Safeguards
Our primary data processing systems reside in secure data centers within the European Union, but occasionally we need to use sub-processors in various countries. In those specific cases, we ensure the equivalent degree of safeguarding by employing Standard Contractual Clauses endorsed by the European Commission, together with a thorough Transfer Impact Assessment. To safeguard your financial data from illegitimate access during transfer, we enforce Transport Layer Security (TLS 1.3) encryption across all connection points, rejecting old cipher suites. At rest, personal data stored in our managed database clusters is secured by AES‑256 encryption, and access to decryption keys is restricted to a isolated privileged access management system. We run ongoing vulnerability scans, compulsory penetration tests, and strict logical access controls so exclusively the individuals who need it can access your data. We have a appointed Data Protection Officer you can reach through our platform, and we maintain an incident response plan that mandates us to inform the relevant German supervisory authority within 72 hours if a personal data breach could put your rights at risk.
Common Questions
In what way does Trino Casino verify my age under German regulations?
We employ a multi-tiered system: computerized checks against national databases and human document review. When you create an account, you must upload your national ID card or passport through an encrypted portal. Our compliance team cross‑references this with the Schufa identity service to verify legal age. If something doesn’t match, we briefly restrict the account until a video identification call with a certified agent can clear things up, all in line with the German Interstate Treaty on Gambling.
Is it possible that my personal data be disclosed with the affiliate who recommended me?
No. Our affiliate programme employs a strict aggregation firewall. We never disclose your name, contact details, or payment records with the referring affiliate. The partner only sees a pseudonymized dashboard with confirmed registration counts and a statistical summary of net gaming revenue. Our affiliate agreements expressly prohibit them from trying to identify individual players. This maintains your gameplay completely separate from the marketing channel that directed you to Trino Casino.
How can permanently revoke my marketing consent?
Go to “Communication Settings” in your account dashboard and turn off promotional channels. Every marketing email we send has a one‑click unsubscribe link at the bottom that works right away. To withdraw consent for postal mail or SMS, contact our Data Protection Officer through the support ticket system. We’ll stop direct marketing within at most 48 hours after receiving your request.
What transpires to my data if Trino Casino ceases operations?
If business ever stops, we are legally required to notify the competent German data protection authority and all active users in advance trinoo.de. Mandatory transactional logs and identification records will be securely transferred to a certified archival service or handed over to the responsible regulatory body for as long as the law demands. Any data that isn’t mandatory gets securely destroyed using cryptographic wiping techniques before the closure of our servers is finalized.
Will Trino Casino use automated decision-making for payments?
We use a limited automated profiling system to flag possible fraud or bonus abuse. If the system blocks a withdrawal, we’re required by law to involve a human. Our financial risk team manually checks every flagged transaction before we tell you the final decision. You can challenge that decision, give your side, and ask for a full manual review by our risk management specialists.
What is the process to receive a complete record of my stored data?
Send an email from the address tied to your account to our Data Protection Officer, place “SAR” in the subject line. We’ll authenticate your identity with a two‑factor step. After that, we compile your data from all systems—chat logs, game history, identity documents—and generate a digitally signed PDF and a machine‑readable JSON file, which you’ll receive within one calendar month.

