Privacy Policy

Last updated: August 14, 2025

How This Page Helps You

What you can use this page for

This page explains how Personal Data is handled when you use the Website, contact support, manage access to the Services, complete verification, make payments, adjust privacy-related choices, or submit a request concerning your data while using Pin Up bookmaker.

It is written to help users understand what information may be needed, why it may be processed, which parts of Processing are required by law, how support requests are handled, and how privacy rights may be exercised.

Who manages the Website

The Website is owned and operated by Carletta N.V., a company registered under the laws of Curaçao.

Carletta N.V. has its office at Dr. Henri Fergusonweg 1, Curaçao. The company registration number is 142346.

Carletta N.V. has been licensed by the Curaçao Gaming Control Board since 24/Jun/2025 to offer games of chance under license number OGL/2024/580/0570 in accordance with the National Ordinance on Games of Chance (LOK).

Who is responsible for data decisions

Carletta N.V. acts as the controller of your Personal Data.

As controller, the Company decides why Personal Data is processed and how Processing is carried out in relation to the Website and Services.

Where privacy support applies

This Privacy Policy applies to Personal Data processed through:

  • the Website;
  • email messages sent to or received from [email protected];
  • phone calls with us;
  • support chat sessions.

Terms Support May Refer To

Account

Account means the unique account created for you to access the Services or specific parts of the Services.

Support may need to refer to your Account when assisting with access, verification, payment inquiries, security reviews, or rights requests.

Company

Company, we, us, or our means Carletta N.V., registered in Curaçao under company registration number 142346, with official address at Dr. Henri Fergusonweg 1, Curaçao.

Service

Service means the Website, the Website functions, and the related online gaming and interactive services provided by the Company.

Website

Website means this website, including subdomains, associated platforms, and applications operated by the Company.

Personal Data

Personal Data means information connected with an identified or identifiable person, as defined under the General Data Protection Regulation and the Curaçao Data Protection Framework.

Processing of Personal Data

Processing of Personal Data means any manual or automated operation performed with Personal Data.

This may include collecting, recording, organizing, structuring, storing, changing, retrieving, reviewing, using, disclosing, transmitting, sharing, aligning, combining, restricting, deleting, or destroying Personal Data.

Regulatory Compliance

Regulatory Compliance means the Company’s duty to process Personal Data where applicable laws require it.

This includes obligations under the National Ordinance on Games of Chance and Anti-Money Laundering regulations. Processing required for Regulatory Compliance is based on legal obligations and does not depend on user consent.

Help With Account Access and Registration

Data needed to create or manage an Account

When an Account is created, activated, secured, or managed, the Company may process Personal Data required to provide access to the Services.

This may include:

  • email address and/or phone number;
  • hashed password;
  • chosen currency;
  • Account identifiers;
  • basic device or access logs needed for activation and Account security.

Legal reason for Account-related Processing

The legal basis for this Processing is performance of a contract or steps taken before entering into a contract under GDPR Article 6(1)(b).

Why support may use Account data

Support may refer to Account-related data when helping with access issues, service availability, Account security, transaction references, or inquiries connected with the use of the Services.

Help With Identity and Age Verification

Why verification may be requested

The Company may need to verify identity, confirm age, complete KYC checks, and meet AML/CFT, LOK, and NORUT obligations.

These checks may be required before certain Services are made available or continued.

Data used for verification assistance

Verification-related Personal Data may include:

  • passport;
  • ID card;
  • driver’s license;
  • proof of address;
  • date of birth or age attestation;
  • selfies;
  • liveness checks.

Legal reason for verification checks

The legal basis is compliance with legal obligations under GDPR Article 6(1)(c), including AML/CFT, LOK, and NORUT.

Where applicable, the Company may also rely on legitimate interests in platform integrity under GDPR Article 6(1)(f).

Help With Payments and Transaction Questions

Data used for payment-related support

If you contact support about deposits, withdrawals, refunds, payout confirmations, or other payment-related matters, the Company may process Personal Data connected with the relevant transaction.

This may include:

  • payment instrument data;
  • transaction history;
  • currency;
  • payout channel confirmations.

Legal reason for payment Processing

Payment Processing may be based on:

  • performance of a contract under GDPR Article 6(1)(b);
  • legal obligations for financial record-keeping and AML under GDPR Article 6(1)(c);
  • legitimate interests in fraud prevention under GDPR Article 6(1)(f).

Why payment records may be retained

Payment-related records may be needed for transaction completion, AML checks, financial record-keeping, tax obligations, audit requirements, dispute resolution, or legal claims.

Help With Security and Fraud Prevention

Technical information used for protection

To protect the Website, users, and the Services, the Company may process technical and device-related information.

This may include:

  • IP address;
  • device type;
  • browser data;
  • device identifiers;
  • technical identifiers.

Why security Processing is carried out

Security-related Processing helps detect suspicious activity, prevent unauthorized access, reduce platform abuse, protect users, and maintain the integrity of the Services.

Legal basis for security measures

The legal bases are legitimate interests in securing the Service and users under GDPR Article 6(1)(f), and legal obligations under AML/CTF requirements under GDPR Article 6(1)(c).

Help With Responsible Gaming Measures

Support for player protection tools

The Company may process Personal Data to support responsible gaming, self-exclusion, cooling-off selections, play limits, player protection measures, and related interventions.

This Processing may involve:

  • self-exclusion status;
  • self-exclusion duration;
  • cooling-off selections;
  • play limits;
  • gameplay frequency;
  • spend metrics indicative of risk;
  • communications related to responsible gaming interventions.

Legal reason for responsible gaming Processing

The legal bases are compliance with LOK / CGA Responsible Gaming requirements under GDPR Article 6(1)(c), and legitimate interests in player welfare and Regulatory Compliance under GDPR Article 6(1)(f).

How support may assist

Support may process relevant communications and Account information when handling requests or issues connected with self-exclusion, cooling-off selections, limits, or responsible gaming interventions.

Help With Customer Support Communications

Information processed when you contact support

When you contact support, the Company may process the information needed to understand your request, respond to it, check relevant Account or transaction details, and resolve the matter.

Support-related Personal Data may include:

  • support tickets;
  • chat transcripts;
  • email correspondence;
  • call notes;
  • Account identifiers;
  • transaction references tied to the inquiry.

Legal basis for support Processing

The legal bases are performance of a contract under GDPR Article 6(1)(b), and legitimate interests in service quality and dispute resolution under GDPR Article 6(1)(f).

Contact channel for support

Support may be contacted at:

Help With Marketing Preferences

When marketing data may be processed

Where permitted by law, the Company may process Personal Data for marketing communications.

This Processing is always subject to opt-out options and responsible gaming restrictions.

Data connected with marketing preferences

Marketing-related Personal Data may include:

  • email address;
  • phone number;
  • push token;
  • marketing preferences;
  • engagement metrics;
  • non-sensitive bonus eligibility status.

Legal basis for marketing

Electronic marketing is based on consent under GDPR Article 6(1)(a).

Where permitted by law, similar-product soft opt-in may rely on legitimate interests under GDPR Article 6(1)(f).

Help With Website Analytics and Cookies

Data used to operate and improve the Website

The Company may process Website usage and technical information to operate the Website, improve functionality, analyze performance, and understand how visitors interact with the Website.

This may include:

  • usage logs;
  • cookie identifiers;
  • browser type and version;
  • traffic data;
  • on-site interaction metrics.

Legal basis for Website-related Processing

The legal bases are legitimate interests in operating and improving the Website under GDPR Article 6(1)(f), and consent under GDPR Article 6(1)(a) where non-essential cookies require consent.

Cookie support information

Cookies and similar technologies may be used to support essential functions, remember preferences, measure performance, and, where permitted, support advertising or targeting activities.

Cookies are small text files stored on your device when you visit the Website. They allow the Website to recognize the device and store certain information about preferences or previous actions.

Cookie Categories and Controls

Strictly necessary cookies

Strictly necessary cookies are required for core Website operation.

They may support:

  • page navigation;
  • access to secure areas;
  • user authentication.

These cookies cannot be switched off in the Company’s systems.

Functional cookies

Functional cookies help provide enhanced functionality and personalization.

They may remember language preferences or user settings and may be placed by the Company or by third-party providers whose services are used.

Analytical or performance cookies

Analytical or performance cookies collect aggregated and anonymized information about Website use.

This may include page visits, click-through rates, traffic sources, and on-site interaction metrics.

These cookies are used to measure and improve Website performance.

Advertising or targeting cookies

Advertising or targeting cookies may be placed by the Company or advertising partners.

They may help build a profile of interests, deliver relevant advertising on this Website or other websites, limit how often an advertisement appears, and assess advertising effectiveness.

Session and persistent cookies

Session cookies expire when your browser is closed.

Persistent cookies remain on your device for a predetermined period or until you delete them.

First-party and third-party cookies

First-party cookies are placed by the Company.

Third-party cookies are placed by service providers acting on the Company’s behalf, including analytics providers, customer support tools, or advertising networks.

Managing cookies in your browser

Most browsers allow you to refuse or delete cookies.

If certain cookies are restricted, some Website features may become unavailable or may not function as intended.

Help With Data Sources

Information received from you

The Company primarily obtains Personal Data directly from you.

This may happen when you create an Account, complete verification steps, make deposits, request withdrawals, or contact support.

Information created through use of the Services

Some Personal Data is generated through activity on the platform.

This may include gameplay, transaction history, device information, log information, and cookie data in accordance with the Cookie Policy.

Information received from service providers

Trusted third parties may support identity verification, compliance, security, and payment-related functions.

Where these services are used, Personal Data may be processed to support verification, risk management, compliance, or operational requirements.

Information from public sources and authorities

Where necessary, the Company may supplement user-provided information with data from publicly available and legitimate sources.

This is limited to compliance, verification, and risk management purposes.

In some cases, Personal Data may also be received from regulatory or law enforcement authorities in connection with legal or compliance obligations.

Help With Data Retention

How long Personal Data may be kept

Personal Data is retained only for as long as needed for the purposes for which it was collected and processed, or for as long as legal and regulatory obligations require.

What affects retention periods

Retention periods may depend on:

  • the purpose of Processing;
  • provision of the Services;
  • contractual obligations;
  • legitimate interests;
  • Anti-Money Laundering requirements;
  • gaming regulations;
  • tax regulations;
  • legal claims;
  • audit requirements;
  • supervisory requirements.

What happens when retention ends

When the applicable retention period expires, Personal Data is securely deleted, anonymized, or archived so that it can no longer be associated with you.

Further retention may continue only where required by law.

Help With Storage and International Transfers

Where Personal Data may be stored

Personal Data is stored on secure servers operated by the Company and trusted service providers.

Depending on operational and regulatory requirements, these servers may be located:

  • within the European Economic Area;
  • outside the European Economic Area;
  • in Curaçao.

Transfers outside the EEA

Where Personal Data is transferred outside the EEA, the Company applies safeguards required by applicable data protection laws.

Adequacy decisions

Transfers may take place to countries that the European Commission recognizes as providing an adequate level of data protection.

Standard Contractual Clauses

Where no adequacy decision applies, the Company uses Standard Contractual Clauses approved by the European Commission to help protect Personal Data transferred outside the EEA.

Help With Data Sharing

General sharing rule

Personal Data may be shared only where necessary and only for the purposes described in this Privacy Policy.

Sharing is handled in compliance with applicable data protection laws, contractual obligations, and security measures.

Authorities and official bodies

Personal Data may be shared with regulatory and supervisory authorities where required by law or regulatory obligations.

Such recipients may include:

  • Curaçao Gaming Authority;
  • Financial Intelligence Unit;
  • tax authorities;
  • governmental bodies;
  • law enforcement bodies.

These disclosures may relate to AML, responsible gaming, reporting, audits, or legal requirements.

Verification and compliance providers

Identity verification and compliance service providers may receive Personal Data to help verify customer identity and comply with AML and Know Your Customer obligations.

Payment processors and financial institutions

Payment processors and financial institutions may receive Personal Data needed to enable deposits, withdrawals, refunds, and other payment-related services.

This may include transaction details, payment method information, and Account identifiers.

Support and communication tools

External service providers may process Personal Data to support email delivery, live chat, or other communication channels.

This may include contact details and support messages.

Security and fraud prevention partners

Trusted providers may process Personal Data to help protect platform security and detect or prevent potentially fraudulent or unauthorized activity.

Analytics and optimization platforms

Third-party services may support Website usage analysis, A/B testing, and user experience improvements.

Where possible, information used for these purposes is anonymized or pseudonymized.

Game content providers

Licensed third-party game providers may receive only the minimum Personal Data required to enable certain platform features.

This may include player identifiers and game session data.

Internal tools and IT infrastructure

Secure hosting, productivity solutions, and internal tools may be used to store and manage data necessary for operation of the Services.

Help With Minor Protection

Age requirement for the Services

The Services are intended only for individuals who are at least eighteen (18) years old or who have reached the legal age in their jurisdiction, whichever is higher.

By accessing or registering for the Services, you confirm that you meet the applicable age requirement.

Measures against underage access

In alignment with the Curaçao Gaming Authority’s Responsible Gaming Policy introduced in February 2025, the Company applies measures intended to prevent underage access to the Services.

Verification and monitoring

Users may be required to provide valid government-issued identification documents during registration.

The Company may also use automated monitoring to detect inconsistencies or signs of attempted underage access.

If underage access is suspected, security reviews may be carried out, including verification of registration data and financial transactions.

Data submitted by minors

Personal Data submitted by individuals identified as minors is deleted immediately.

Guidance for parents and guardians

Parents and guardians are encouraged to use available parental control tools and educate minors about responsible online behavior to help prevent unauthorized access to the Services.

Responsible gaming safeguards

The Company’s responsible gaming approach includes adherence to CGA guidance on player protection and age verification.

Policies are reviewed and enhanced to meet or exceed applicable regulatory standards.

Help With Data Protection Rights

Access

Under Article 15 GDPR, you may request confirmation of whether your Personal Data is processed and may receive a copy of that data together with information about how it is used.

Rectification

Under Article 16 GDPR, you may request correction of inaccurate or incomplete Personal Data without undue delay.

Erasure

Under Article 17 GDPR, you may request deletion of Personal Data where applicable legal grounds exist.

This may apply where data is no longer needed for the purposes collected, or where consent is withdrawn and no other lawful basis applies.

Restriction

Under Article 18 GDPR, you may request limitation of Personal Data Processing in specific situations, including where data accuracy is contested or Processing is unlawful.

Portability

Under Article 20 GDPR, you may request the Personal Data you provided to the Company in a structured, commonly used, and machine-readable format.

Where technically feasible, the data may be transferred to another controller.

Objection

Under Article 21 GDPR, you may object to Processing based on legitimate interests for reasons related to your particular situation.

You may also object to Processing for direct marketing purposes.

How to submit a rights request

To exercise your data protection rights, contact the Company through:

Help With Consent Withdrawal

When consent can be withdrawn

Where Personal Data is processed based on consent, you may withdraw that consent at any time.

Effect of withdrawal

Withdrawal does not affect the lawfulness of Processing based on consent before the withdrawal.

How withdrawal requests are handled

To withdraw consent, use the contact channels specified in this Privacy Policy.

After receiving the request, the Company will stop the relevant Processing unless continued retention or Processing is required to comply with legal or regulatory obligations.

Possible impact on Services

If consent withdrawal affects the Company’s ability to provide certain Services, the Company will explain the consequences before completing the withdrawal process.

Help With Complaints

Right to complain

Under Article 77 GDPR, you may lodge a complaint if you believe that your Personal Data is being processed unlawfully or that your privacy rights have been violated.

Where a complaint may be submitted

A complaint may be lodged with:

  • the supervisory authority in the EU Member State where you reside;
  • the supervisory authority in the EU Member State where you work;
  • the supervisory authority in the EU Member State where the alleged violation occurred;
  • the Curaçao Gaming Authority;
  • any other relevant data protection authority in Curaçao.

Contacting the Company first

If you have concerns or unresolved questions about Personal Data Processing, you are encouraged to contact the Company directly before escalating the matter.

The Company will make every reasonable effort to address concerns in a timely and lawful manner.

Help With Required Personal Data

Legal requirement

Certain Personal Data must be provided so that the Company can comply with applicable laws and regulations.

This includes Anti-Money Laundering obligations and responsible gaming requirements.

Contractual requirement

Some Personal Data is necessary to enter into and perform a contract with you.

This includes data required to enable access to the Services and process transactions.

Service access requirement

Certain Services may not be available unless required Personal Data is provided.

Without required data, the Company may be unable to fulfill contractual or legal obligations.

Consequences of not providing required data

Failure to provide required Personal Data may result in:

  • inability to create or maintain an Account;
  • restrictions on use of the Services;
  • termination of the contractual relationship;
  • failure to comply with regulatory obligations, which may prevent the Company from providing Services.

Legal Information and Policy Status

Service availability

The Services are provided on an “AS-IS” and “AS-AVAILABLE” basis.

The Company does not provide warranties or guarantees that performance will be uninterrupted or error-free.

Security limitation

The Company takes reasonable precautions to protect Personal Data.

However, absolute security cannot be guaranteed because technology is complex and cybersecurity threats continue to change.

Limitation of liability

To the maximum extent permitted by law, the Company is not liable for:

  • events beyond its direct control, including system failures, cyberattacks, or unauthorized access;
  • indirect, incidental, consequential, or punitive damages arising from data breaches, unauthorized disclosure, or misuse of Personal Data;
  • errors, inaccuracies, or security vulnerabilities on third-party websites linked from the platform.

External websites and services

The Company is not responsible for external websites or services operated by third parties, even where those websites or services are linked from the platform.

By using the Services, you acknowledge and agree to this limitation.

Policy acceptance

Continued use of the Services signifies explicit acceptance of this Privacy Policy.

This document is the entire and exclusive Privacy Policy and replaces previous versions.

Related documents

This Privacy Policy should be read together with the Terms and Conditions and any additional applicable notices posted on the platform.

Policy updates

The Company reserves the right to modify this Privacy Policy at any time.

Changes will be posted on the platform. Continued use of the Services after modifications constitutes acceptance of the revised Policy.

You are strongly encouraged to review this Privacy Policy regularly to stay informed about updates.

Language priority

All versions of this Privacy Policy other than the English version are provided for informational purposes only.

The English version prevails in case of discrepancies or conflicts between different versions.