Privacy Policy
Last updated: August 14, 2025
How This Page Helps You
What you can use this page for
This page explains how Personal Data is handled when you use the Website, contact support, manage access to the Services, complete verification, make payments, adjust privacy-related choices, or submit a request concerning your data while using Pin Up bookmaker.
It is written to help users understand what information may be needed, why it may be processed, which parts of Processing are required by law, how support requests are handled, and how privacy rights may be exercised.
Who manages the Website
The Website is owned and operated by Carletta N.V., a company registered under the laws of Curaçao.
Carletta N.V. has its office at Dr. Henri Fergusonweg 1, Curaçao. The company registration number is 142346.
Carletta N.V. has been licensed by the Curaçao Gaming Control Board since 24/Jun/2025 to offer games of chance under license number OGL/2024/580/0570 in accordance with the National Ordinance on Games of Chance (LOK).
Who is responsible for data decisions
Carletta N.V. acts as the controller of your Personal Data.
As controller, the Company decides why Personal Data is processed and how Processing is carried out in relation to the Website and Services.
Where privacy support applies
This Privacy Policy applies to Personal Data processed through:
- the Website;
- email messages sent to or received from [email protected];
- phone calls with us;
- support chat sessions.
Terms Support May Refer To
Account
Account means the unique account created for you to access the Services or specific parts of the Services.
Support may need to refer to your Account when assisting with access, verification, payment inquiries, security reviews, or rights requests.
Company
Company, we, us, or our means Carletta N.V., registered in Curaçao under company registration number 142346, with official address at Dr. Henri Fergusonweg 1, Curaçao.
Service
Service means the Website, the Website functions, and the related online gaming and interactive services provided by the Company.
Website
Website means this website, including subdomains, associated platforms, and applications operated by the Company.
Personal Data
Personal Data means information connected with an identified or identifiable person, as defined under the General Data Protection Regulation and the Curaçao Data Protection Framework.
Processing of Personal Data
Processing of Personal Data means any manual or automated operation performed with Personal Data.
This may include collecting, recording, organizing, structuring, storing, changing, retrieving, reviewing, using, disclosing, transmitting, sharing, aligning, combining, restricting, deleting, or destroying Personal Data.
Regulatory Compliance
Regulatory Compliance means the Company’s duty to process Personal Data where applicable laws require it.
This includes obligations under the National Ordinance on Games of Chance and Anti-Money Laundering regulations. Processing required for Regulatory Compliance is based on legal obligations and does not depend on user consent.
Help With Account Access and Registration
Data needed to create or manage an Account
When an Account is created, activated, secured, or managed, the Company may process Personal Data required to provide access to the Services.
This may include:
- email address and/or phone number;
- hashed password;
- chosen currency;
- Account identifiers;
- basic device or access logs needed for activation and Account security.
Legal reason for Account-related Processing
The legal basis for this Processing is performance of a contract or steps taken before entering into a contract under GDPR Article 6(1)(b).
Why support may use Account data
Support may refer to Account-related data when helping with access issues, service availability, Account security, transaction references, or inquiries connected with the use of the Services.
Help With Identity and Age Verification
Why verification may be requested
The Company may need to verify identity, confirm age, complete KYC checks, and meet AML/CFT, LOK, and NORUT obligations.
These checks may be required before certain Services are made available or continued.
Data used for verification assistance
Verification-related Personal Data may include:
- passport;
- ID card;
- driver’s license;
- proof of address;
- date of birth or age attestation;
- selfies;
- liveness checks.
Legal reason for verification checks
The legal basis is compliance with legal obligations under GDPR Article 6(1)(c), including AML/CFT, LOK, and NORUT.
Where applicable, the Company may also rely on legitimate interests in platform integrity under GDPR Article 6(1)(f).
Help With Payments and Transaction Questions
Data used for payment-related support
If you contact support about deposits, withdrawals, refunds, payout confirmations, or other payment-related matters, the Company may process Personal Data connected with the relevant transaction.
This may include:
- payment instrument data;
- transaction history;
- currency;
- payout channel confirmations.
Legal reason for payment Processing
Payment Processing may be based on:
- performance of a contract under GDPR Article 6(1)(b);
- legal obligations for financial record-keeping and AML under GDPR Article 6(1)(c);
- legitimate interests in fraud prevention under GDPR Article 6(1)(f).
Why payment records may be retained
Payment-related records may be needed for transaction completion, AML checks, financial record-keeping, tax obligations, audit requirements, dispute resolution, or legal claims.
Help With Security and Fraud Prevention
Technical information used for protection
To protect the Website, users, and the Services, the Company may process technical and device-related information.
This may include:
- IP address;
- device type;
- browser data;
- device identifiers;
- technical identifiers.
Why security Processing is carried out
Security-related Processing helps detect suspicious activity, prevent unauthorized access, reduce platform abuse, protect users, and maintain the integrity of the Services.
Legal basis for security measures
The legal bases are legitimate interests in securing the Service and users under GDPR Article 6(1)(f), and legal obligations under AML/CTF requirements under GDPR Article 6(1)(c).
Help With Responsible Gaming Measures
Support for player protection tools
The Company may process Personal Data to support responsible gaming, self-exclusion, cooling-off selections, play limits, player protection measures, and related interventions.
This Processing may involve:
- self-exclusion status;
- self-exclusion duration;
- cooling-off selections;
- play limits;
- gameplay frequency;
- spend metrics indicative of risk;
- communications related to responsible gaming interventions.
Legal reason for responsible gaming Processing
The legal bases are compliance with LOK / CGA Responsible Gaming requirements under GDPR Article 6(1)(c), and legitimate interests in player welfare and Regulatory Compliance under GDPR Article 6(1)(f).
How support may assist
Support may process relevant communications and Account information when handling requests or issues connected with self-exclusion, cooling-off selections, limits, or responsible gaming interventions.
Help With Customer Support Communications
Information processed when you contact support
When you contact support, the Company may process the information needed to understand your request, respond to it, check relevant Account or transaction details, and resolve the matter.
Support-related Personal Data may include:
- support tickets;
- chat transcripts;
- email correspondence;
- call notes;
- Account identifiers;
- transaction references tied to the inquiry.
Legal basis for support Processing
The legal bases are performance of a contract under GDPR Article 6(1)(b), and legitimate interests in service quality and dispute resolution under GDPR Article 6(1)(f).
Contact channel for support
Support may be contacted at:
Help With Marketing Preferences
When marketing data may be processed
Where permitted by law, the Company may process Personal Data for marketing communications.
This Processing is always subject to opt-out options and responsible gaming restrictions.
Data connected with marketing preferences
Marketing-related Personal Data may include:
- email address;
- phone number;
- push token;
- marketing preferences;
- engagement metrics;
- non-sensitive bonus eligibility status.
Legal basis for marketing
Electronic marketing is based on consent under GDPR Article 6(1)(a).
Where permitted by law, similar-product soft opt-in may rely on legitimate interests under GDPR Article 6(1)(f).
Help With Website Analytics and Cookies
Data used to operate and improve the Website
The Company may process Website usage and technical information to operate the Website, improve functionality, analyze performance, and understand how visitors interact with the Website.
This may include:
- usage logs;
- cookie identifiers;
- browser type and version;
- traffic data;
- on-site interaction metrics.
Legal basis for Website-related Processing
The legal bases are legitimate interests in operating and improving the Website under GDPR Article 6(1)(f), and consent under GDPR Article 6(1)(a) where non-essential cookies require consent.
Cookie support information
Cookies and similar technologies may be used to support essential functions, remember preferences, measure performance, and, where permitted, support advertising or targeting activities.
Cookies are small text files stored on your device when you visit the Website. They allow the Website to recognize the device and store certain information about preferences or previous actions.
Cookie Categories and Controls
Strictly necessary cookies
Strictly necessary cookies are required for core Website operation.
They may support:
- page navigation;
- access to secure areas;
- user authentication.
These cookies cannot be switched off in the Company’s systems.
Functional cookies
Functional cookies help provide enhanced functionality and personalization.
They may remember language preferences or user settings and may be placed by the Company or by third-party providers whose services are used.
Analytical or performance cookies
Analytical or performance cookies collect aggregated and anonymized information about Website use.
This may include page visits, click-through rates, traffic sources, and on-site interaction metrics.
These cookies are used to measure and improve Website performance.
Advertising or targeting cookies
Advertising or targeting cookies may be placed by the Company or advertising partners.
They may help build a profile of interests, deliver relevant advertising on this Website or other websites, limit how often an advertisement appears, and assess advertising effectiveness.
Session and persistent cookies
Session cookies expire when your browser is closed.
Persistent cookies remain on your device for a predetermined period or until you delete them.
First-party and third-party cookies
First-party cookies are placed by the Company.
Third-party cookies are placed by service providers acting on the Company’s behalf, including analytics providers, customer support tools, or advertising networks.
Managing cookies in your browser
Most browsers allow you to refuse or delete cookies.
If certain cookies are restricted, some Website features may become unavailable or may not function as intended.
Help With Data Sources
Information received from you
The Company primarily obtains Personal Data directly from you.
This may happen when you create an Account, complete verification steps, make deposits, request withdrawals, or contact support.
Information created through use of the Services
Some Personal Data is generated through activity on the platform.
This may include gameplay, transaction history, device information, log information, and cookie data in accordance with the Cookie Policy.
Information received from service providers
Trusted third parties may support identity verification, compliance, security, and payment-related functions.
Where these services are used, Personal Data may be processed to support verification, risk management, compliance, or operational requirements.
Information from public sources and authorities
Where necessary, the Company may supplement user-provided information with data from publicly available and legitimate sources.
This is limited to compliance, verification, and risk management purposes.
In some cases, Personal Data may also be received from regulatory or law enforcement authorities in connection with legal or compliance obligations.
Help With Data Retention
How long Personal Data may be kept
Personal Data is retained only for as long as needed for the purposes for which it was collected and processed, or for as long as legal and regulatory obligations require.
What affects retention periods
Retention periods may depend on:
- the purpose of Processing;
- provision of the Services;
- contractual obligations;
- legitimate interests;
- Anti-Money Laundering requirements;
- gaming regulations;
- tax regulations;
- legal claims;
- audit requirements;
- supervisory requirements.
What happens when retention ends
When the applicable retention period expires, Personal Data is securely deleted, anonymized, or archived so that it can no longer be associated with you.
Further retention may continue only where required by law.
Help With Storage and International Transfers
Where Personal Data may be stored
Personal Data is stored on secure servers operated by the Company and trusted service providers.
Depending on operational and regulatory requirements, these servers may be located:
- within the European Economic Area;
- outside the European Economic Area;
- in Curaçao.
Transfers outside the EEA
Where Personal Data is transferred outside the EEA, the Company applies safeguards required by applicable data protection laws.
Adequacy decisions
Transfers may take place to countries that the European Commission recognizes as providing an adequate level of data protection.
Standard Contractual Clauses
Where no adequacy decision applies, the Company uses Standard Contractual Clauses approved by the European Commission to help protect Personal Data transferred outside the EEA.
Help With Data Sharing
General sharing rule
Personal Data may be shared only where necessary and only for the purposes described in this Privacy Policy.
Sharing is handled in compliance with applicable data protection laws, contractual obligations, and security measures.
Authorities and official bodies
Personal Data may be shared with regulatory and supervisory authorities where required by law or regulatory obligations.
Such recipients may include:
- Curaçao Gaming Authority;
- Financial Intelligence Unit;
- tax authorities;
- governmental bodies;
- law enforcement bodies.
These disclosures may relate to AML, responsible gaming, reporting, audits, or legal requirements.
Verification and compliance providers
Identity verification and compliance service providers may receive Personal Data to help verify customer identity and comply with AML and Know Your Customer obligations.
Payment processors and financial institutions
Payment processors and financial institutions may receive Personal Data needed to enable deposits, withdrawals, refunds, and other payment-related services.
This may include transaction details, payment method information, and Account identifiers.
Support and communication tools
External service providers may process Personal Data to support email delivery, live chat, or other communication channels.
This may include contact details and support messages.
Security and fraud prevention partners
Trusted providers may process Personal Data to help protect platform security and detect or prevent potentially fraudulent or unauthorized activity.
Analytics and optimization platforms
Third-party services may support Website usage analysis, A/B testing, and user experience improvements.
Where possible, information used for these purposes is anonymized or pseudonymized.
Game content providers
Licensed third-party game providers may receive only the minimum Personal Data required to enable certain platform features.
This may include player identifiers and game session data.
Internal tools and IT infrastructure
Secure hosting, productivity solutions, and internal tools may be used to store and manage data necessary for operation of the Services.
Help With Minor Protection
Age requirement for the Services
The Services are intended only for individuals who are at least eighteen (18) years old or who have reached the legal age in their jurisdiction, whichever is higher.
By accessing or registering for the Services, you confirm that you meet the applicable age requirement.
Measures against underage access
In alignment with the Curaçao Gaming Authority’s Responsible Gaming Policy introduced in February 2025, the Company applies measures intended to prevent underage access to the Services.
Verification and monitoring
Users may be required to provide valid government-issued identification documents during registration.
The Company may also use automated monitoring to detect inconsistencies or signs of attempted underage access.
If underage access is suspected, security reviews may be carried out, including verification of registration data and financial transactions.
Data submitted by minors
Personal Data submitted by individuals identified as minors is deleted immediately.
Guidance for parents and guardians
Parents and guardians are encouraged to use available parental control tools and educate minors about responsible online behavior to help prevent unauthorized access to the Services.
Responsible gaming safeguards
The Company’s responsible gaming approach includes adherence to CGA guidance on player protection and age verification.
Policies are reviewed and enhanced to meet or exceed applicable regulatory standards.
Help With Data Protection Rights
Access
Under Article 15 GDPR, you may request confirmation of whether your Personal Data is processed and may receive a copy of that data together with information about how it is used.
Rectification
Under Article 16 GDPR, you may request correction of inaccurate or incomplete Personal Data without undue delay.
Erasure
Under Article 17 GDPR, you may request deletion of Personal Data where applicable legal grounds exist.
This may apply where data is no longer needed for the purposes collected, or where consent is withdrawn and no other lawful basis applies.
Restriction
Under Article 18 GDPR, you may request limitation of Personal Data Processing in specific situations, including where data accuracy is contested or Processing is unlawful.
Portability
Under Article 20 GDPR, you may request the Personal Data you provided to the Company in a structured, commonly used, and machine-readable format.
Where technically feasible, the data may be transferred to another controller.
Objection
Under Article 21 GDPR, you may object to Processing based on legitimate interests for reasons related to your particular situation.
You may also object to Processing for direct marketing purposes.
How to submit a rights request
To exercise your data protection rights, contact the Company through:
- email: [email protected];
- postal address: Dr. Henri Fergusonweg 1, Curaçao.
Help With Consent Withdrawal
When consent can be withdrawn
Where Personal Data is processed based on consent, you may withdraw that consent at any time.
Effect of withdrawal
Withdrawal does not affect the lawfulness of Processing based on consent before the withdrawal.
How withdrawal requests are handled
To withdraw consent, use the contact channels specified in this Privacy Policy.
After receiving the request, the Company will stop the relevant Processing unless continued retention or Processing is required to comply with legal or regulatory obligations.
Possible impact on Services
If consent withdrawal affects the Company’s ability to provide certain Services, the Company will explain the consequences before completing the withdrawal process.
Help With Complaints
Right to complain
Under Article 77 GDPR, you may lodge a complaint if you believe that your Personal Data is being processed unlawfully or that your privacy rights have been violated.
Where a complaint may be submitted
A complaint may be lodged with:
- the supervisory authority in the EU Member State where you reside;
- the supervisory authority in the EU Member State where you work;
- the supervisory authority in the EU Member State where the alleged violation occurred;
- the Curaçao Gaming Authority;
- any other relevant data protection authority in Curaçao.
Contacting the Company first
If you have concerns or unresolved questions about Personal Data Processing, you are encouraged to contact the Company directly before escalating the matter.
The Company will make every reasonable effort to address concerns in a timely and lawful manner.
Help With Required Personal Data
Legal requirement
Certain Personal Data must be provided so that the Company can comply with applicable laws and regulations.
This includes Anti-Money Laundering obligations and responsible gaming requirements.
Contractual requirement
Some Personal Data is necessary to enter into and perform a contract with you.
This includes data required to enable access to the Services and process transactions.
Service access requirement
Certain Services may not be available unless required Personal Data is provided.
Without required data, the Company may be unable to fulfill contractual or legal obligations.
Consequences of not providing required data
Failure to provide required Personal Data may result in:
- inability to create or maintain an Account;
- restrictions on use of the Services;
- termination of the contractual relationship;
- failure to comply with regulatory obligations, which may prevent the Company from providing Services.
Legal Information and Policy Status
Service availability
The Services are provided on an “AS-IS” and “AS-AVAILABLE” basis.
The Company does not provide warranties or guarantees that performance will be uninterrupted or error-free.
Security limitation
The Company takes reasonable precautions to protect Personal Data.
However, absolute security cannot be guaranteed because technology is complex and cybersecurity threats continue to change.
Limitation of liability
To the maximum extent permitted by law, the Company is not liable for:
- events beyond its direct control, including system failures, cyberattacks, or unauthorized access;
- indirect, incidental, consequential, or punitive damages arising from data breaches, unauthorized disclosure, or misuse of Personal Data;
- errors, inaccuracies, or security vulnerabilities on third-party websites linked from the platform.
External websites and services
The Company is not responsible for external websites or services operated by third parties, even where those websites or services are linked from the platform.
By using the Services, you acknowledge and agree to this limitation.
Policy acceptance
Continued use of the Services signifies explicit acceptance of this Privacy Policy.
This document is the entire and exclusive Privacy Policy and replaces previous versions.
Related documents
This Privacy Policy should be read together with the Terms and Conditions and any additional applicable notices posted on the platform.
Policy updates
The Company reserves the right to modify this Privacy Policy at any time.
Changes will be posted on the platform. Continued use of the Services after modifications constitutes acceptance of the revised Policy.
You are strongly encouraged to review this Privacy Policy regularly to stay informed about updates.
Language priority
All versions of this Privacy Policy other than the English version are provided for informational purposes only.
The English version prevails in case of discrepancies or conflicts between different versions.
