← Back to Homepage

GDPR Compliance Statement

Last Updated: January 1, 2025

kiwiislefortuneplay.com is committed to protecting the privacy and personal data of all our users, including those in the European Union (EU) and European Economic Area (EEA). This GDPR Compliance Statement explains how we comply with the General Data Protection Regulation (GDPR) and outlines your rights under this regulation.

1. Our Commitment to GDPR Compliance

The General Data Protection Regulation (GDPR) is a comprehensive data protection law that came into effect on May 25, 2018. It applies to organizations that process personal data of individuals in the EU/EEA, regardless of where the organization is located.

We take GDPR compliance seriously and have implemented appropriate technical and organizational measures to ensure the protection of your personal data in accordance with GDPR requirements.

2. Legal Basis for Processing Personal Data

Under GDPR, we must have a lawful basis for processing your personal data. We process your data based on the following legal grounds:

2.1 Consent (Article 6(1)(a))

We process certain data based on your explicit consent, including:

  • Cookie data (after you accept our cookie banner)
  • Marketing communications (if you opt-in to receive them)
  • Age verification consent

You have the right to withdraw your consent at any time without affecting the lawfulness of processing based on consent before its withdrawal.

2.2 Contractual Necessity (Article 6(1)(b))

We process data necessary to provide our service to you, including:

  • Account creation and management
  • Delivering gaming services
  • Maintaining gameplay progress and achievements
  • Providing customer support

2.3 Legal Obligation (Article 6(1)(c))

We process data when required by law, including:

  • Age verification to comply with age restriction regulations
  • Responding to lawful requests from authorities
  • Complying with tax and accounting regulations

2.4 Legitimate Interests (Article 6(1)(f))

We process data based on our legitimate interests, including:

  • Platform security and fraud prevention
  • Improving our services and user experience
  • Analytics and performance monitoring
  • Protecting our legal rights

We have conducted legitimate interest assessments to ensure our interests do not override your fundamental rights and freedoms.

3. Your Rights Under GDPR

If you are a resident of the EU/EEA, you have the following rights regarding your personal data:

3.1 Right of Access (Article 15)

You have the right to obtain:

  • Confirmation of whether we process your personal data
  • Access to your personal data
  • Information about how we process your data

How to exercise: Contact us at support@kiwiislefortuneplay.com to request a copy of your data.

3.2 Right to Rectification (Article 16)

You have the right to have inaccurate personal data corrected and incomplete data completed.

How to exercise: Update your information through your account settings or contact support@kiwiislefortuneplay.com.

3.3 Right to Erasure / "Right to be Forgotten" (Article 17)

You have the right to request deletion of your personal data when:

  • The data is no longer necessary for the purposes for which it was collected
  • You withdraw consent and there's no other legal basis for processing
  • You object to processing and there are no overriding legitimate grounds
  • The data was unlawfully processed
  • Erasure is required to comply with a legal obligation

How to exercise: Contact support@kiwiislefortuneplay.com to request account deletion.

3.4 Right to Restriction of Processing (Article 18)

You have the right to request restriction of processing when:

  • You contest the accuracy of your personal data
  • Processing is unlawful but you oppose erasure
  • We no longer need the data, but you need it for legal claims
  • You've objected to processing pending verification of legitimate grounds

How to exercise: Contact support@kiwiislefortuneplay.com with your restriction request.

3.5 Right to Data Portability (Article 20)

You have the right to receive your personal data in a structured, commonly used, and machine-readable format and to transmit that data to another controller.

How to exercise: Contact support@kiwiislefortuneplay.com to request a portable copy of your data.

3.6 Right to Object (Article 21)

You have the right to object to:

  • Processing based on legitimate interests or public interest
  • Direct marketing (including profiling for marketing purposes)
  • Processing for scientific, historical research, or statistical purposes

How to exercise: Contact support@kiwiislefortuneplay.com or use the unsubscribe link in marketing emails.

3.7 Rights Related to Automated Decision-Making (Article 22)

You have the right not to be subject to decisions based solely on automated processing, including profiling, which produces legal effects or similarly significantly affects you.

Note: We do not engage in automated decision-making that produces legal effects or similarly significantly affects you.

3.8 Right to Withdraw Consent

Where processing is based on consent, you have the right to withdraw your consent at any time. Withdrawal of consent does not affect the lawfulness of processing based on consent before its withdrawal.

3.9 Right to Lodge a Complaint

You have the right to lodge a complaint with a supervisory authority, particularly in the EU member state of your residence, place of work, or place of alleged infringement.

Exercising Your Rights: To exercise any of these rights, please contact us at support@kiwiislefortuneplay.com. We will respond to your request within one month, though this may be extended by two additional months for complex requests. We will inform you of any such extension within one month of receipt of your request.

4. Data Protection Principles

We adhere to the GDPR data protection principles and ensure that personal data is:

4.1 Processed Lawfully, Fairly, and Transparently

We provide clear information about our data processing activities through our Privacy Policy and this GDPR Statement. We process data only on lawful bases as outlined in Section 2.

4.2 Collected for Specified, Explicit, and Legitimate Purposes

We collect data only for the purposes explicitly stated in our Privacy Policy. We do not process data in a manner incompatible with those purposes.

4.3 Adequate, Relevant, and Limited to What is Necessary

We practice data minimization by collecting only the data necessary to provide our services. We do not collect financial information because our platform is completely free.

4.4 Accurate and Kept Up to Date

We provide mechanisms for you to update your information and take reasonable steps to ensure data accuracy. Inaccurate data is corrected or erased without delay.

4.5 Kept for No Longer Than Necessary

We retain personal data only as long as necessary for the purposes for which it was collected or as required by law. See our data retention policies in the Privacy Policy.

4.6 Processed Securely

We implement appropriate technical and organizational measures to ensure data security, including SSL-256 encryption, secure password storage, access controls, and regular security audits.

4.7 Accountability

We maintain documentation of our processing activities and can demonstrate compliance with GDPR principles.

5. International Data Transfers

If we transfer personal data from the EU/EEA to countries outside the EU/EEA (including New Zealand), we ensure appropriate safeguards are in place:

  • Standard Contractual Clauses: We may use EU-approved Standard Contractual Clauses for data transfers
  • Adequacy Decisions: We may transfer data to countries deemed adequate by the European Commission
  • Appropriate Safeguards: We implement appropriate technical and organizational measures to protect transferred data

6. Data Protection Officer (DPO)

While we are not legally required to appoint a Data Protection Officer, we have designated a privacy contact responsible for GDPR compliance:

Privacy Contact Email: support@kiwiislefortuneplay.com

For GDPR-related inquiries, please use the subject line "GDPR Request" to ensure prompt attention.

7. Data Breach Notification

In the unlikely event of a personal data breach that is likely to result in a risk to your rights and freedoms, we will:

  • Notify the relevant supervisory authority within 72 hours of becoming aware of the breach
  • Notify affected individuals without undue delay if the breach is likely to result in a high risk to their rights and freedoms
  • Provide clear information about the nature of the breach and steps being taken to address it

8. Children's Data Protection

Our Platform is not intended for children under 18 years of age. We do not knowingly process data of children under 18. If we discover that we have inadvertently collected data from a child under 18, we will delete it immediately.

Under GDPR Article 8, children under 16 (or lower age set by member states) require parental consent for information society services. Our 18+ age requirement exceeds this standard.

9. Profiling and Automated Decision-Making

We do not engage in profiling or automated decision-making that produces legal effects or similarly significantly affects individuals. Any use of algorithms or automated processing is limited to:

  • Game mechanics (Random Number Generation for game outcomes)
  • Personalized game recommendations based on play history
  • Basic analytics to improve platform performance

These activities do not create legal effects or significantly affect individuals in a GDPR context.

10. Third-Party Data Processors

We may engage third-party service providers to process data on our behalf. When we do:

  • We enter into written data processing agreements that comply with GDPR Article 28
  • We ensure processors provide sufficient guarantees regarding security and compliance
  • We conduct due diligence on processors' data protection practices
  • We monitor processor compliance through regular audits and reviews

11. Marketing Communications

We will only send you marketing communications if:

  • You have given explicit consent (opt-in), OR
  • We have a legitimate interest and you have not opted out (soft opt-in for existing users)

Every marketing email includes a clear unsubscribe mechanism. You can opt out at any time without affecting your account or access to our services.

12. Record of Processing Activities

In accordance with GDPR Article 30, we maintain records of our processing activities, including:

  • Purposes of processing
  • Categories of data subjects and personal data
  • Categories of recipients
  • International data transfers
  • Retention periods
  • Security measures

13. Privacy by Design and Default

We implement privacy by design and default principles:

  • Data minimization: We collect only necessary data
  • Purpose limitation: Data is used only for stated purposes
  • Privacy-friendly default settings
  • Security measures integrated into system design
  • Regular privacy impact assessments for new features

14. Updates to This GDPR Statement

We may update this GDPR Compliance Statement to reflect changes in our practices or legal requirements. Updates will be posted with a revised "Last Updated" date. Material changes will be communicated through prominent notices on our Platform.

15. Contact and Questions

For any questions about our GDPR compliance or to exercise your rights, please contact us:

Email: support@kiwiislefortuneplay.com

Subject Line for GDPR Requests: "GDPR Request"

We will respond to all GDPR-related inquiries within one month of receipt.

16. Supervisory Authority Contact

If you believe we have not adequately addressed your concerns, you have the right to lodge a complaint with a supervisory authority. For users in the EU/EEA, you can find your local supervisory authority through the European Data Protection Board website: https://edpb.europa.eu/about-edpb/board/members_en


kiwiislefortuneplay.com is committed to protecting your personal data and respecting your privacy rights under GDPR. We continuously review and improve our data protection practices to ensure compliance with this important regulation.

← Back to Homepage