Privacy policy
Legal
Version [x.x] · Last updated [date] · Effective [date]
This policy explains how Darminor Studios Ltd. collects, uses, shares and protects personal data when you browse this website, contact our commercial team, apply for a role with us, or interact with a game we have licensed to a regulated operator.
We have written it to be read, not to be survived. If anything here is unclear, ask us at [privacy@darminor.com] and we will explain it in plain terms.
1. Who we are
Darminor Studios Ltd. (“Darminor”, “we”, “us”, “our”) is a business-to-business game studio. We design, build, certify and license slots, scratchcards and instant win games, together with the remote game server that delivers them, to licensed gaming operators. We do not operate a casino and we do not hold player accounts or player funds.
- Legal entity — Darminor Studios Ltd., a company incorporated in Malta under company registration number [company registration number].
- Registered office — [registered address].
- Licensing — licensed and regulated by the Malta Gaming Authority under licence number [MGA licence number], and by [additional regulators and licence numbers].
- Data protection contact — [Data Protection Officer or privacy lead], reachable at [privacy@darminor.com].
- Representative — [UK / EU Article 27 representative, if appointed].
2. Scope of this policy
This policy applies to personal data we handle as a controller: this website, our sales and partner communications, supplier management, events, and recruitment. It also describes, in section 3.4, the limited player data we handle as a processor on behalf of operators.
It does not apply to the websites, apps or lobbies operated by the companies that license our games. When you play one of our titles inside an operator’s site, that operator is the controller of your account data and their own privacy notice governs it. Links from this website to third-party sites are provided for convenience and we are not responsible for their privacy practices.
3. What data we collect
3.1 Website visitors
- Technical data: IP address (truncated where technically possible), device type, operating system, browser and language settings.
- Usage data: pages viewed, time on page, referring URL, outbound clicks, and which game demos you launched.
- Identifiers set by cookies and similar technologies, described in our cookie policy.
3.2 Commercial contacts and enquiries
- Identity and contact data: name, employer, job title, business email address and telephone number.
- Correspondence: the content of your enquiry, meeting and demonstration notes, integration tickets and support requests.
- Relationship records: contracts, purchase orders, billing details and revenue-share statements.
- Due-diligence data required by our licences: [beneficial ownership, licence status, sanctions and PEP screening results].
3.3 Job applicants
- CV, cover letter, employment history, education, portfolio, code or maths samples.
- Interview notes, assessment scores, references and right-to-work documentation.
- Optional diversity monitoring data, provided voluntarily and held separately from your application in aggregated form.
3.4 Player data handled for operators
When an operator licenses our games, our remote game server receives a pseudonymous player identifier issued by the operator, together with session identifiers, wager and win records, game state and the outcome of each round. We use this data solely to run the game, settle the round, maintain the regulatory audit trail and investigate disputes.
- The operator is the controller; Darminor acts as a processor on the operator’s documented instructions under a written agreement meeting Article 28 UK GDPR / EU GDPR.
- We do not receive player names, postal addresses, payment card details or identity documents.
- Requests from players about this data should be raised with the operator first; see section 10.
3.5 Children
Our games and materials are intended for licensed operators and for adults only. We do not knowingly collect personal data from anyone under 18. If you believe a minor has provided us with personal data, contact [privacy@darminor.com] and we will delete it.
4. Our lawful bases
We rely on one of the following bases for every processing activity described above.
- Legitimate interests — operating and securing this website, understanding how our catalogue is browsed, responding to business enquiries, managing operator and supplier relationships, and defending legal claims. We have completed a balancing assessment for each; a summary is available on request.
- Contract — taking steps at your request before entering into a licensing agreement, and performing that agreement once signed.
- Legal obligation — regulatory reporting and record-keeping imposed by our gaming licences, plus anti-money-laundering, accounting and tax law in [applicable jurisdictions].
- Consent — non-essential cookies, marketing communications, and holding your details in our talent pool after a recruitment process ends. You may withdraw consent at any time without affecting processing carried out before withdrawal.
5. How we use personal data
- To publish, maintain and secure this website, and to keep the game catalogue accurate.
- To respond to enquiries, arrange demonstrations and negotiate licensing terms.
- To deliver, integrate, certify and support our games and remote game server.
- To produce aggregated performance reporting for operators, from which individuals cannot be identified.
- To detect and investigate fraud, collusion, malfunctioning game rounds and misuse of our systems.
- To assess applications, run interviews and manage offers.
- To send product and release updates where you have asked for them, with an unsubscribe link in every message.
- To meet licence conditions, respond to regulators and test houses, and comply with lawful requests.
We do not sell personal data, and we do not use it to build advertising profiles or to make solely automated decisions that produce legal or similarly significant effects.
6. Sharing and processors
We disclose personal data only where there is a lawful basis and, for processors, only under a written contract that restricts them to our documented instructions and requires appropriate security. Our current categories of recipient are:
- Licensed operators who have contracted with us, in respect of the integration and the data described in section 3.4.
- Infrastructure and hosting providers — [hosting provider], [content delivery network].
- Product analytics and error monitoring — [analytics provider], [error monitoring provider].
- Business systems — [CRM provider], [email provider], [applicant tracking system].
- Independent test houses and certification laboratories — [accredited test house].
- Regulators and authorities — the Malta Gaming Authority and [other competent authorities], where required by law or licence condition.
- Professional advisers: auditors, insurers and lawyers, bound by confidentiality.
- An acquirer or investor in connection with a merger, acquisition or financing, subject to confidentiality undertakings.
A current list of processors, with their locations and safeguards, is available on request from [privacy@darminor.com].
7. International transfers
Our primary infrastructure is located in [hosting region, e.g. the EEA]. Where personal data is transferred outside the EEA or the UK, we rely on one of the following safeguards and document it before the transfer begins:
- An adequacy decision of the European Commission or the UK Secretary of State covering the destination country.
- The European Commission’s standard contractual clauses, together with the UK International Data Transfer Addendum where the transfer is subject to UK law.
- A documented transfer risk assessment and, where the assessment requires it, supplementary technical measures such as encryption and pseudonymisation.
You may request a copy of the relevant safeguard, with commercial terms redacted, from [privacy@darminor.com].
8. Retention
We keep personal data only as long as we need it for the purpose it was collected, plus any period required by law or licence condition. Our current schedule is:
- Enquiries and unconverted leads — [24 months] from the last meaningful contact.
- Contracts, invoices and accounting records — [10 years] from the end of the relationship.
- Game session and transaction logs held for operators — the period specified by the controlling operator and by [applicable licence conditions, currently 5 years].
- Unsuccessful applicants — [12 months]; talent pool records with consent — [24 months].
- Website analytics — [14 months], then aggregated.
- Consent and preference records — [the duration of the consent plus 24 months], as evidence of compliance.
At the end of the applicable period we delete the data or irreversibly anonymise it so that it can no longer be associated with an individual.
9. Security
- Encryption of personal data in transit and at rest, with key management held by [key management service].
- Role-based access control, least privilege, mandatory multi-factor authentication and quarterly access reviews.
- Strict separation of production, staging and development environments; no production personal data in test systems.
- Centralised logging, monitoring and alerting, with tamper-evident audit trails for regulated game events.
- Independent penetration testing [annually] and remediation tracked to closure.
- Security and privacy training for all staff at induction and [annually] thereafter.
- A documented incident response plan. Where a personal data breach is likely to result in a risk to individuals, we notify the competent supervisory authority within 72 hours of becoming aware, and affected individuals or controllers without undue delay.
10. Your rights
Subject to the conditions in applicable data protection law, you have the right to:
- Be informed about how we use your personal data — this policy.
- Request access to the personal data we hold about you, and a copy of it.
- Have inaccurate or incomplete data corrected.
- Request erasure where we no longer have a lawful reason to keep the data.
- Request restriction of processing while an issue is investigated.
- Receive data you provided to us in a portable, machine-readable format, and have it transmitted to another controller where technically feasible.
- Object to processing based on our legitimate interests, and to object to direct marketing at any time.
- Withdraw consent where consent is the basis for processing.
- Not be subject to a decision based solely on automated processing that produces legal or similarly significant effects.
To exercise a right, email [privacy@darminor.com] or write to us at the address in section 13. We respond within one month, and will tell you if we need a further two months because the request is complex. We may ask for information to verify your identity. Requests are free unless they are manifestly unfounded or excessive, in which case we may charge a reasonable fee or decline, with reasons.
If your request concerns data we process on behalf of an operator, we will pass it to that operator without undue delay and support them in responding, as our processing agreement requires.
11. Complaints
Please raise any concern with us first — we would rather fix it directly. You also have the right to complain to a supervisory authority, in particular in the country where you live, work, or where the issue arose.
- Malta — [Office of the Information and Data Protection Commissioner, address, telephone, email].
- United Kingdom — [Information Commissioner’s Office, address, helpline].
- Elsewhere in the EEA — [your local supervisory authority].
12. Changes to this policy
We review this policy at least [annually] and whenever our processing changes materially. The version number and dates at the top of the page record the current release. Where a change materially affects how we use your personal data, we will give notice by [email to registered contacts and a notice on this page] before it takes effect. Superseded versions are available on request.
13. Contact us
Darminor Studios Ltd. — Data protection
[Data Protection Officer or privacy lead]
[registered address]
[privacy@darminor.com] · [telephone number]
For commercial enquiries, use our contact page instead — it reaches the right team faster.