Privacy Policy
This policy explains how Bennycasino handles personal data when you use bennycasino.com. It is written to comply with the UK GDPR, the UK Data Protection Act 2018 and, because the controller is established in Sweden, the EU GDPR and the Swedish Dataskyddslagen (2018:218) in parallel. In plain language: we collect very little personal data, we never sell it, and you may ask us to delete what we hold at any time.
Data controller
- Controller: REV Studio AB
- Company no.: 559414-7919
- Address: Erik Dahlbergsgatan 20B, 411 26 Gothenburg, Sweden
- Email: hello@bennycasino.com
- Site: https://bennycasino.com
1. What we collect
We collect only what we need to run the site and understand our traffic. There is no account system, no login, and we store no personal user data beyond what is required for analytics and any email correspondence you choose to initiate.
- Server logs from our hosting provider (IP address, user agent, timestamp, requested URL, referrer). Retained for 30 days for security and operational diagnostics.
- Privacy-respecting analytics events (page views, country, device class, referrer), collected via a tool configured not to store IP addresses or cookies that identify individuals.
- Email correspondence you send to us via the contact channels (corrections, partnerships, press, general). Retained for as long as needed to handle the matter, then archived for record-keeping where legally relevant.
- Affiliate referral identifiers passed by your browser to operators when you click an outbound link. We do not see who registers; we only see aggregate, anonymised click counts.
2. What we do not collect
We do not run the site as a profiling operation. The following categories are expressly out of scope:
- No accounts, no sign-up, no stored login credentials.
- No payment data of any kind. We never process payments, operators do.
- No advertising cookies and no third-party tracking pixels.
- No data brokering, no resale of any user data to anyone, ever.
- No special-category data (health, biometric, political, religious, etc.). If a contact email contains such data, we delete it as soon as the matter is resolved.
3. Lawful basis for processing
Each category of processing relies on a specific lawful basis under Article 6 of the UK GDPR (and the EU GDPR where it applies in parallel):
- Server logs and analytics: legitimate interests (Art. 6(1)(f)) in operating and securing the site. The balancing test is documented internally; the data is minimal and is not used to identify individuals.
- Email correspondence: contractual necessity / legitimate interests in responding to enquiries (Art. 6(1)(b)/(f)). For partnership emails, the processing is necessary to enter into a contract.
- Affiliate click tracking: legitimate interests in earning commission on referred registrations. The processing takes place on the operator's side after the click; we do not see the user's personal data.
4. Who we share data with
We share the minimum necessary with the following service providers, all of whom are bound by data processing agreements:
- Hosting / CDN provider, required to serve the site.
- Analytics provider, privacy-respecting analytics tool, configured for anonymised data only.
- Email service provider, to receive incoming mail to the inboxes listed on the contact page.
- Operator partners, only when you click an affiliate link and visit the operator's site. We pass a referral identifier; the operator collects whatever data it collects on its own site under its own privacy policy.
5. International data transfers
Some of our service providers operate servers outside the UK and the EEA. Where this happens we rely on the UK International Data Transfer Agreement (or the UK Addendum to the EU SCCs) together with the European Commission's Standard Contractual Clauses (SCCs), and supplementary measures where applicable (encryption in transit, encryption at rest). We do not transfer personal data to providers in jurisdictions that do not offer an adequate level of protection.
6. Security measures
Concrete technical and organisational measures in place:
- TLS 1.2+ on every page (HSTS preload).
- Strict Content-Type, X-Frame-Options, Referrer-Policy and Permissions-Policy headers.
- No cookies that store personal identifiers.
- Inboxes and admin tools protected by 2FA.
- Access principle: each contact inbox can be read only by the editor. Forwards to other parties are logged.
Your rights under the UK GDPR
You have the rights listed below in respect of any personal data we hold about you. To exercise any of them, please email hello@bennycasino.com with the subject line "GDPR request". We will respond within 30 days.
- Access. Obtain a copy of the personal data we hold about you.
- Rectification. Have inaccurate data corrected.
- Erasure ("right to be forgotten"). Have your data deleted, subject to overriding legal obligations.
- Restriction of processing. Ask us to limit what we do with your data while a dispute is being resolved.
- Data portability. Receive your data in a structured, machine-readable format.
- Object to processing. Object to processing carried out on the basis of our legitimate interests.
- Lodge a complaint. UK residents may complain to the Information Commissioner's Office (ICO). EEA residents may also complain to the supervisory authority of their country of residence, and, since the controller is Swedish, to Integritetsskyddsmyndigheten (IMY).
How long we keep data
| Data | Period | Basis |
|---|---|---|
| Server logs (IP, user agent, URL) | 30 days | Operational / security |
| Aggregate analytics events | 12 months | Legitimate interests in product analytics |
| Contact correspondence | 24 months after the last interaction | Contractual / legitimate interests |
| Partnership records | 7 years | Swedish accounting law (Bokföringslagen 1999:1078) |
| Press correspondence | 12 months | Legitimate interests |
Cookies
Bennycasino uses very few cookies. There is no advertising cookie, no third-party tracking cookie and no behavioural-profiling cookie. See our dedicated Cookie Policy for the full inventory.
Strictly necessary
- Purpose: Page rendering and security headers; no personal data stored.
- Duration: Session
- Vendor: Bennycasino / hosting provider
Analytics (anonymous)
- Purpose: Aggregate page views and country distribution; IP not stored.
- Duration: Session
- Vendor: Privacy-respecting analytics tool
For privacy questions, GDPR requests or to challenge processing: hello@bennycasino.com. We respond within 30 days.
When we update this policy we change the "last updated" date at the top, and where the change is material we add a note in the Changelog.