Privacy Policy
Written as the questions people actually send to the Data Protection Officer, in the order they send them.
Last updated: August 2026
Who holds my data?
Data control on this website sits with the operator. There may also be a joint controller, a business group and a parent company in the picture. The Data Protection Officer answers at dpo@lizaro.com, and that address is the right one for everything on this page.
What exactly is held?
Account details — name, date of birth, email, telephone, country, currency, username and password. Due diligence records — identity card, driving licence or passport number, proof of address, social security number, source of wealth and funds, bank ID, financial statements. Transactions, with the routes used and their references. Play data — games opened, stakes, bonuses received, wagering progress. Technical data — IP address, device, browser and how pages here are used. And correspondence, including chat transcripts and anything attached to an email.
Why is it held?
To run the account and settle bets. To meet due diligence and know-your-customer duties. To verify age and identity. To satisfy anti-money-laundering obligations. To answer support requests. To prevent fraud. To comply with licence conditions and other legal requirements.
Marketing is separate: it goes out only where you have agreed to receive it, and that agreement can be withdrawn whenever you like without affecting anything already done.
Where else does it come from?
Public and government databases, the internet and social media, commercially available databases, financial and credit institutions, fraud prevention agencies and public authorities. Not everything held about an account was supplied by the account holder.
Who else sees it?
Authorised employees. Brands inside the same operator or entity. Contractors, agents, joint controllers, affiliates and subsidiaries. Third-party service providers. Law enforcement, regulatory and licensing authorities.
There is one further case, and it is unusual enough to state rather than bury. Send a complaint or a review about the account to a third-party platform — a casino review site, a gambling forum, a dispute resolution body — and that platform may be given personal data, no more than what identifies the account, under a legitimate interest in protecting business reputation.
How long is it kept?
As long as the account lives, and after that deleted or anonymised once nothing legal or commercial still needs it. Where anti-money-laundering rules and other regulation bite, that period stretches.
What can I ask for?
Access to your data, correction of anything wrong, erasure, restriction of processing, portability, or an objection to processing. Consent, wherever the processing leans on it, can be taken back.
A complaint can also go to the supervisory authority in your EU member state of residence, your place of work, or the place where you believe an infringement happened.
Send requests to dpo@lizaro.com from the address the account is registered under — from anywhere else, identity has to be established first and that adds days.
What about cookies?
Four categories: essential, functional, performance and targeting. The first makes the site work at all. Consent gates the last two, and every page carries a cookie panel offering accept all, decline all and save. Browser settings clear or block cookies independently of that, though refusing the essential ones breaks parts of the site.
What if somebody else gets into my account?
Tell support the same day. Traffic between your browser and this site is encrypted in transit and access to account records is limited to staff who need it, but a shared or reused password defeats both. Use a password that exists nowhere else, and turn on biometric unlock where your phone offers it.
