Privacy Policy

Effective Date: September 2026
Last Reviewed: September 2026

1. Introduction and Scope

This Privacy Policy (hereinafter “Policy”) explains how bonusbuycasino-uk.com (hereinafter “we,” “us,” “our,” or “the Operator”) collects, uses, processes, stores, and protects personal data obtained through the website located at bonusbuycasino-uk.com (hereinafter “the Website”). The Website provides informational content regarding bonus buy slot mechanics, the regulatory status of such features within the United Kingdom, and a directory of casinos offering this functionality in jurisdictions where it is permitted.

This Policy applies to all users of the Website (hereinafter “you” or “your”) and governs all data processing activities conducted by the Operator in connection with the Website. It is designed to inform you of your rights regarding your personal data and to comply with applicable data protection legislation, including the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018.

By accessing, browsing, or using the Website, you acknowledge that you have read, understood, and agree to the practices described in this Policy. If you do not agree with any provision of this Policy, you must immediately cease using the Website.

This Policy is incorporated into and forms part of the Website’s Terms and Conditions. Any capitalized terms not defined herein have the meaning ascribed to them in the Terms and Conditions.

2. Types of Personal Data Collected

2.1 Data You Provide Voluntarily

The Operator collects personal data only when you choose to provide it. This occurs in the following circumstances:

2.1.1 Subscription to Notifications
If you subscribe to receive notifications, updates, or newsletters, we collect:

  • Email address
  • Name (optional)
  • Date of subscription
  • IP address at time of subscription
  • User agent information

2.1.2 Participation in Surveys
If you voluntarily participate in surveys or feedback forms, we collect:

  • Responses to survey questions
  • Demographic information if provided
  • IP address at time of participation
  • Timestamps

2.1.3 Contact Forms
If you submit an enquiry through a contact form, we collect:

  • Name
  • Email address
  • Subject and content of your message
  • IP address at time of submission

2.1.4 Comments or Forum Participation
If the Website permits user comments or forum participation, we collect:

  • Username (if chosen)
  • Comment content
  • Timestamp
  • IP address
  • Browser information

2.2 Data Collected Automatically

When you access the Website, certain data is collected automatically through cookies, log files, and other tracking technologies:

2.2.1 Technical Data

  • IP address
  • Browser type and version
  • Operating system
  • Device type and screen resolution
  • Referring URL
  • Pages visited and time spent on each page
  • Clickstream data
  • Date and time of access
  • Geographic location (derived from IP address, city/region level only)

2.2.2 Usage Data

  • Frequency of visits
  • Features accessed
  • Search queries
  • Interactions with content
  • Navigation patterns

2.2.3 Cookie Data

  • Cookie preferences
  • Session identifiers
  • Analytics identifiers

2.3 Data from Third-Party Sources

The Operator does not purchase, rent, or otherwise acquire personal data from third-party sources. However, analytics and advertising partners may provide aggregated, anonymised data that does not directly identify you.

2.4 Special Category Data

The Operator does not intentionally collect special category data as defined by the UK GDPR, including:

  • Racial or ethnic origin
  • Political opinions
  • Religious or philosophical beliefs
  • Trade union membership
  • Genetic data
  • Biometric data for identification purposes
  • Health data
  • Sex life or sexual orientation data

Users are advised not to provide such information through any means on the Website.

2.5 Data Relating to Problem Gambling

The Operator does not collect data relating to your gambling activities, problem gambling status, or any related financial information. The Website does not facilitate gambling transactions and does not process any financial data.

3. Purposes of Processing and Legal Bases

3.1 Purpose: Website Operation and Improvement

Description: The collection of technical and usage data enables the Operator to:

  • Ensure the Website functions correctly across different devices and browsers
  • Monitor and maintain the security of the Website
  • Analyse usage patterns to improve content and structure
  • Identify and resolve technical issues
  • Generate statistical reports

Legal Basis: Legitimate interest (Article 6(1)(f) of UK GDPR). The Operator has a legitimate interest in maintaining, operating, and improving the Website for the benefit of all users. This processing is necessary and proportionate and does not override your fundamental rights and freedoms.

Data Retention: Technical logs are retained for a limited period necessary for security and operational purposes. Anonymised analytics data may be retained indefinitely.

3.2 Purpose: Communication and Notifications

Description: Processing of your email address and name enables the Operator to:

  • Send requested notifications and updates
  • Respond to enquiries submitted through contact forms
  • Provide information about changes to the Website or this Policy
  • Deliver requested content or resources

Legal Basis: Consent (Article 6(1)(a) of UK GDPR) for marketing-related communications. For direct responses to enquiries, the legal basis is legitimate interest (Article 6(1)(f)) or, where applicable, the performance of a request made by you prior to entering into any agreement.

Data Retention: Subscription data is retained until you unsubscribe or request deletion, or until a period of inactivity, whichever occurs first. Contact form submissions are retained for a reasonable period from the date of last correspondence.

3.3 Purpose: Compliance with Legal Obligations

Description: Processing may be necessary to:

  • Comply with applicable laws and regulations
  • Respond to lawful requests from public authorities
  • Detect and prevent fraud or misuse of the Website
  • Enforce the Terms and Conditions

Legal Basis: Legal obligation (Article 6(1)(c) of UK GDPR) and legitimate interest (Article 6(1)(f)).

Data Retention: Data processed for legal compliance purposes is retained as required by applicable law or until the relevant matter is resolved.

3.4 Purpose: Analytics and Performance Monitoring

Description: Processing of usage data enables the Operator to:

  • Measure the effectiveness of the Website
  • Understand user behaviour and preferences
  • Test and optimise features
  • Plan future development

Legal Basis: Consent for non-essential cookies through our cookie consent mechanism. For essential analytics that do not require consent, the legal basis is legitimate interest.

Data Retention: Analytics data is retained for a defined period, after which it is aggregated or deleted.

4. Cookies and Similar Technologies

4.1 Definition

Cookies are small text files stored on your device when you visit a website. They serve various functions, including remembering preferences and enabling the website to function correctly.

4.2 Types of Cookies Used

Cookie CategoryPurposeDurationConsent Required
Strictly NecessaryEnable core functionality, security, and basic features. Cannot be disabled.Session to limited periodNo
Performance/AnalyticsCollect anonymised usage data to improve the Website.Limited periodYes
FunctionalRemember preferences and settings for a better experience.Limited periodYes
Targeting/AdvertisingNot used on this Website. The Operator does not serve targeted advertisements.N/AN/A

4.3 Third-Party Cookies

The Website may use third-party services that set their own cookies. These include:

  • Analytics services used to collect anonymised usage statistics. Their respective privacy policies apply to these cookies.
  • Social media plugins, if present, may set cookies when you interact with their content.

4.4 Cookie Management

You can manage your cookie preferences through:

  • Our cookie consent banner displayed upon first visit
  • Your browser settings (most browsers allow you to block or delete cookies)
  • Opt-out tools provided by analytics services

Please note that disabling certain cookies may affect the functionality of the Website.

5. Data Sharing and Disclosure

5.1 Third-Party Service Providers

The Operator engages third-party service providers to perform certain functions. These providers have access to personal data only to the extent necessary to perform their services and are contractually obligated to:

  • Process data only on documented instructions
  • Implement appropriate security measures
  • Not use data for their own purposes
  • Sub-process only with prior consent
  • Assist with data subject requests

Categories of Service Providers:

  • Hosting and Infrastructure: Website hosting, cloud storage, and server management
  • Email Service Providers: Delivery of notifications and newsletters
  • Analytics Providers: Performance monitoring and usage analysis
  • Security Providers: Protection against threats and monitoring

A full list of sub-processors is available upon request.

5.2 Legal Disclosure

The Operator may disclose personal data if required to do so by law or if such action is necessary to:

  • Comply with a legal obligation
  • Protect and defend the rights or property of the Operator
  • Prevent or investigate possible wrongdoing in connection with the Website
  • Protect the personal safety of users or the public

5.3 Business Transfers

In the event of a merger, acquisition, restructuring, or sale of assets, personal data may be transferred to the successor entity. Users will be notified of such a transfer and any change in data processing practices.

5.4 No Sale of Data

The Operator does not sell, rent, or trade your personal data to third parties for marketing or commercial purposes.

6. International Data Transfers

The Operator is based in the United Kingdom. However, some third-party service providers may be located outside the UK or the European Economic Area (EEA).

6.1 Transfer Mechanisms

When personal data is transferred to countries not deemed adequate by UK data protection standards, the Operator ensures appropriate safeguards are in place, including:

  • Standard Contractual Clauses approved by the Information Commissioner’s Office
  • UK International Data Transfer Addendum to the EU Standard Contractual Clauses
  • Data Processing Agreements incorporating UK GDPR requirements

6.2 Countries of Processing

Service providers may process data in:

  • United Kingdom
  • European Economic Area member states
  • Other jurisdictions with adequacy decisions or appropriate safeguards

6.3 Third-Party Privacy Policies

Data transferred to third-party providers is subject to their respective privacy policies. Users are advised to review these policies independently.

7. Data Security

7.1 Technical Measures

The Operator implements appropriate technical measures to protect personal data against unauthorised access, alteration, disclosure, or destruction:

  • Encryption: Data in transit is protected using TLS (Transport Layer Security) protocols. Data at rest is encrypted where practicable.
  • Access Controls: Access to personal data is restricted to authorised personnel on a need-to-know basis.
  • Firewall and Intrusion Detection: Network security measures are in place to prevent unauthorised access.
  • Regular Audits: Security practices are reviewed periodically.
  • Backup and Recovery: Regular backups with appropriate restoration procedures.

7.2 Organisational Measures

  • Staff Training: Personnel receive training on data protection and security practices.
  • Policies and Procedures: Internal policies govern data handling and breach response.
  • Contractual Controls: Service providers are bound by contractual data protection obligations.
  • Incident Response: A documented procedure for responding to data breaches.

7.3 Security Limitations

No method of transmission over the internet or electronic storage is completely secure. While the Operator strives to protect your data, absolute security cannot be guaranteed. Users are responsible for maintaining the confidentiality of any credentials they may create.

8. Data Retention

8.1 Retention Principles

Personal data is retained only for as long as necessary to fulfill the purposes for which it was collected, or as required by law. Retention periods are determined based on:

  • The purpose and nature of the data
  • Legal and regulatory requirements
  • Business operational needs
  • User requests and preferences

8.2 Specific Retention Periods

Data CategoryRetention PeriodJustification
Subscription emailsUntil unsubscription or period of inactivityConsent-based communication
Contact form submissionsReasonable period from last correspondenceResponse to enquiries and record of interactions
Server logs (technical)Limited periodSecurity and troubleshooting
Analytics dataDefined period (aggregated thereafter)Performance improvement
Survey responsesDefined period (anonymised thereafter)Research and improvement
Cookie preferencesLimited periodCompliance with consent requirements

8.3 Deletion Process

When data is no longer required, it is deleted securely or anonymised so that it can no longer be associated with you. Data stored in backups is deleted in accordance with the backup rotation schedule.

9. Your Rights

Under the UK GDPR, you have certain rights regarding your personal data. These rights are subject to certain conditions and exceptions.

9.1 Right of Access

You have the right to request confirmation of whether we process your personal data and, if so, to obtain a copy of that data. This includes information about:

  • The purposes of processing
  • The categories of data concerned
  • The recipients to whom data has been or will be disclosed
  • The retention period or criteria for determining it
  • Your rights in relation to the data
  • The source of the data if not collected from you

Response Time: Within a reasonable period following verification.

9.2 Right to Rectification

You have the right to request correction of inaccurate personal data and to have incomplete data completed. This right applies to any data you have provided.

Response Time: Within a reasonable period following verification.

9.3 Right to Erasure – “Right to be Forgotten”

You have the right to request deletion of your personal data where:

  • The data is no longer necessary for the purposes for which it was collected
  • You withdraw consent and no other lawful basis exists
  • You object to processing and no overriding legitimate grounds exist
  • The data has been unlawfully processed
  • Deletion is required by law

Limitations: The right to erasure does not apply where processing is necessary for compliance with a legal obligation, for the establishment or defence of legal claims, or for other specified purposes.

9.4 Right to Restrict Processing

You have the right to request restriction of processing where:

  • You contest the accuracy of the data
  • Processing is unlawful but you oppose deletion
  • Data is no longer needed but is required for legal claims
  • You have objected to processing pending verification

9.5 Right to Data Portability

You have the right to receive your data in a structured, commonly used, machine-readable format and to transmit it to another controller where processing is based on consent or contract and is carried out by automated means.

9.6 Right to Object

You have the right to object to processing based on legitimate interests, including profiling. On objection, the Operator will cease processing unless compelling legitimate grounds exist that override your interests, or the processing is for legal claims.

9.7 Rights in Relation to Automated Decision-Making

The Website does not engage in automated decision-making, including profiling, that produces legal or similarly significant effects.

9.8 Right to Withdraw Consent

Where processing is based on consent, you have the right to withdraw consent at any time. Withdrawal does not affect the lawfulness of processing based on consent before withdrawal.

9.9 Exercise of Rights

To exercise any of these rights, please contact us using the details in Section 16. We may require verification of your identity before responding. You will not be charged for exercising your rights, except in cases of manifestly unfounded or excessive requests.

10. Children’s Data

The Website is not intended for individuals under the age of 18. The Operator does not knowingly collect personal data from minors. If you are under 18, you are prohibited from using the Website.

If you believe that a minor has provided personal data to the Operator, please contact us immediately. We will take prompt steps to delete such data.

11. Changes to This Privacy Policy

The Operator reserves the right to modify this Policy at any time. Changes are effective upon posting on the Website. Users are advised to review this Policy periodically.

Notification of Significant Changes:

  • Minor updates (e.g., typographical corrections): Posted without individual notification
  • Significant changes (e.g., new processing purposes, new data categories, changes in third-party sharing): Prompt notification will be provided through the Website or via email where we hold your contact details

The date of the most recent revision appears at the top of this document.

12. Do Not Track Signals

The Website does not respond to Do Not Track (DNT) signals from browsers, as there is no standardised protocol for handling these signals. However, you can control tracking through your browser settings and our cookie consent mechanism.

13. Links to Third-Party Websites

The Website contains links to external sites, including online casinos, game providers, and regulatory authorities. This Policy does not apply to those third-party websites. The Operator is not responsible for the privacy practices or content of such sites.

Users are strongly advised to review the privacy policies of any third-party websites they visit. The Operator provides links for convenience only and does not endorse or accept responsibility for third-party data practices.

14. Data Breach Notification

14.1 Breach Response Plan

The Operator maintains a documented data breach response plan. In the event of a personal data breach that poses a risk to your rights and freedoms, we will notify the Information Commissioner’s Office (ICO) within the legally required timeframe of becoming aware of the breach, where feasible.

14.2 Notification to Affected Individuals

Where a breach is likely to result in a high risk to your rights and freedoms, we will notify you without undue delay. Such notification will describe:

  • The nature of the breach
  • The likely consequences
  • The measures taken or proposed to address the breach
  • Recommendations for mitigation

14.3 Reporting to ICO

The ICO can be contacted at: Information Commissioner’s Office, Wycliffe House, Water Lane, Wilmslow, Cheshire, SK9 5AF, or via their website at www.ico.org.uk.