Data Controller and Statutory Scope

This Privacy Policy defines the technical, organizational, and regulatory standards applied to personal data processed across all digital properties operated by Aurora Gaming Ltd., including our wagering platforms and auxiliary services. Aurora Gaming Ltd. acts as the designated Data Controller under the General Data Protection Regulation (EU) 2016/679 and associated data privacy frameworks applicable to Canadian customers, including the Personal Information Protection and Electronic Documents Act (PIPEDA).

Aurora Gaming Ltd. operates as an incorporated entity in Malta under company registration number C 12345, maintaining its registered corporate address at 123 High Street, Sliema, SLM 1540, Malta. All real-money wagering, transaction settlement, and customer profile management operations function under regulatory licenses issued by the Malta Gaming Authority (MGA). Operational compliance ensures that data processing satisfies cross-jurisdictional accountability standards.

The scope of this policy covers personal information gathered through direct user registration, account verification, financial transactions, server telemetry, and customer support communications across our web portal and dedicated sports betting applications. Processing activities align directly with our service commitments and regulatory mandates, including player safety monitoring outlined in our dedicated responsible gambling guidelines. You are encouraged to review these governance rules to understand the retention schedules and access controls applied to your records.

Categories of Personal Data Processed

To establish player accounts, process sports wagers, fulfill mandatory anti-money laundering (AML) protocols, and maintain network integrity, we collect and process several distinct categories of personal information:

  • Identity and Verification Records: Legal first and last name, date of birth, residential citizenship, and government-issued identification numbers. These records satisfy age verification requirements (19+ in most Canadian provinces; 18+ in Alberta and Quebec) and mandatory Know Your Customer (KYC) identity validation checks.
  • Contact and Communication Points: Residential street address, verified email address, and active telephone numbers. These data points facilitate account status notifications, security alerts, settlement receipts, and mandatory service disclaimers.
  • Financial and Settlement Data: Masked payment card numbers (Primary Account Number truncated to PCI-DSS standards), bank transfer routing codes, and electronic wallet identifiers (including Interac e-Transfer, Skrill, and Neteller account emails). When settling accounts with digital currencies via our cryptocurrency betting platform, public wallet addresses and blockchain transaction hashes are logged.
  • Wagering and Transaction History: Comprehensive ledgers detailing deposits, withdrawals, promotional redemptions, single wagers, parlay bets, and in-play live event slips. These records maintain platform transparency and satisfy financial audit compliance.
  • Technical Telemetry and Device Logs: IPv4 and IPv6 addresses, operating system specifications, browser build numbers, device hardware fingerprints, location coordinates derived from geolocation validation tools, and network session time-stamps. This telemetry detects multi-accounting fraud, unauthorized access attempts, and automated scraping tools.

Legal Basis for Data Processing

Aurora Gaming processes your personal information in strict adherence to applicable Canadian statutory frameworks, including the Personal Information Protection and Electronic Documents Act (PIPEDA) and relevant provincial privacy legislation, alongside international regulatory benchmarks. Under these data protection laws, every operation involving your records must rely on a clearly established lawful ground. We systematically categorize all processing into four primary legal justifications: contractual necessity, statutory obligation, legitimate business interests, and express consent.

1. Performance of a Contract
When you register an account with our platform, an enforceable contractual relationship is established under our published terms. Processing your personal data is mandatory to deliver our core wagering and account management services. Under this basis, we process data to:

  • Authenticate user credentials and maintain secure account administration across active sessions.
  • Facilitate financial transactions, including processing deposits, settlement of wagers across live betting markets, and processing Canadian Dollar (CAD) withdrawals via verified payment processors.
  • Execute transaction histories, settle winning stakes accurately against verified event outcomes, and maintain an immutable ledger of all placed bets.
  • Deliver critical non-marketing operational notices, such as balance updates, security alerts, technical maintenance notifications, and amendments to service terms.

2. Legal and Regulatory Obligations
As an operator compliant with strict licensing standards and anti-financial crime mandates, we must collect, verify, and retain specific user records to satisfy binding regulatory requirements. This includes:

  • Know Your Customer (KYC) Verifications: Validating government-issued identification, residential address documentation, and age verification to ensure players meet the Canadian legal age of majority (19+ in most provinces; 18+ in Alberta, Manitoba, and Quebec).
  • Anti-Money Laundering (AML) & Counter-Terrorist Financing (CTF): Monitoring transaction volumes, screening against domestic and international politically exposed persons (PEP) and sanctions registries, and filing mandatory reports on suspicious financial activities.
  • Player Protection Mandates: Monitoring activity metrics to identify markers of problematic gambling, enforcing self-exclusion registers, and executing loss limits consistent with our responsible gaming frameworks.
  • Statutory Auditing and Tax Compliance: Maintaining financial transaction logs and dispute resolution archives for mandated statutory retention windows (typically five to seven years post-account closure).

3. Legitimate Business Interests
We process personal data where necessary to pursue legitimate operational objectives, provided such activities do not override your fundamental individual privacy rights. Activities conducted under legitimate interests include:

  • Platform Integrity and Fraud Prevention: Implementing device fingerprinting, IP address monitoring, and algorithmic screening to detect syndicate betting, arbitrage abuse, bonus exploitation, and unauthorized multi-accounting.
  • Risk Assessment and Market Management: Analyzing aggregated turnover to calibrate sports betting odds and manage operational exposure.
  • Technical Infrastructure Security: Detecting and mitigating malicious traffic, brute-force attempts, DDoS vectors, and unauthorized network intrusions.
  • Service Optimization: Reviewing telemetry and aggregated navigational trends to improve interface performance, server stability, and feature responsiveness across desktop and mobile browsers.

4. Express Consent
Where processing falls outside contractual, statutory, or legitimate interest justifications, we obtain your clear and explicit consent prior to handling your data. Consent is specifically utilized for opt-in direct marketing, such as customized email bulletins and notifications regarding our latest sportsbook promos. You retain the absolute right to revoke this consent at any time via your account profile settings or through the unsubscribe mechanism included in every marketing communication, without impacting the lawfulness of any processing conducted prior to revocation.

Data Sharing, Third Parties, and Cookie Policy

Aurora Gaming does not sell, rent, or trade your personal information to third parties for commercial marketing purposes. Data transfers occur strictly to fulfill service contracts, satisfy anti-money laundering (AML) mandates, maintain network security, and execute operational tasks on our sportsbook platform. All third-party data processors are vetted for compliance with Canadian privacy standards under the Personal Information Protection and Electronic Documents Act (PIPEDA) and operate under binding Data Processing Agreements (DPAs).

Authorized Third-Party Service Providers and Data Categories:

  • Payment Gateways and Financial Institutions: When processing deposits or withdrawals in CAD or digital assets, transactional data (such as account identifiers, card tokenization references, transaction amounts, and billing postcodes) is transmitted to licensed payment clearing networks, Interac service partners, card networks (Visa, Mastercard), and custodial crypto gateway providers.
  • Identity Verification and Fraud Detection Vendors: Compliance with statutory Know Your Customer (KYC) obligations requires submitting submitted identity credentials, proof of address documentation, and device fingerprints to specialized verification databases to screen against global sanctions lists, politically exposed persons (PEP) registers, and fraud rings.
  • Sports Data Feeds and Odds Engine Providers: To calculate settlements and manage live wagering integrity, anonymized bet ticket metadata, session IDs, and market selections are processed by real-time infrastructure feeds (such as Sportradar and Betgenius) without disclosing direct personal identifiers.
  • Technical Infrastructure and Cloud Hosting: Platform data is hosted on encrypted cloud server networks and Content Delivery Networks (CDNs) providing DDoS mitigation, web application firewalls, and low-latency database replication.
  • Regulatory Bodies and Law Enforcement: Where mandated by Canadian federal or provincial law, court orders, or formal directives from financial intelligence units (such as FINTRAC) and sports integrity monitoring bodies, specific account audit logs and transaction histories are transferred under strict legal protocols.
  • Player Protection Platforms: User exclusion records and transaction limits configured under our responsible gambling protocols are synchronized with self-exclusion management registers to enforce betting restrictions.
  • Analytics and Marketing Attribution Partners: Aggregated session metrics, campaign identifiers, and device-level attribution tags are shared with analytics vendors and affiliate tracking networks to measure platform performance and referral accuracy. These vendors receive pseudonymized identifiers rather than direct account credentials.
  • Corporate Group and Support Contractors: Customer support platforms, ticketing systems, and internal audit contractors engaged by Aurora Gaming Ltd. may access account records strictly to resolve disputes, process refunds, or investigate reported irregularities, subject to internal confidentiality obligations.

International Data Transfers

Aurora Gaming Ltd. operates from Malta and engages processors located across the European Economic Area, the United Kingdom, and Canada. Where personal data moves across these borders, transfers rely on adequacy frameworks recognized under GDPR or on contractual safeguards agreed with each processor, including confidentiality clauses and audit rights consistent with PIPEDA principles. Canadian account holders should understand that certain processing occurs outside Canada, subject to the safeguards described in this section.

Processors outside these jurisdictions are engaged only where equivalent contractual protections are in place. Aurora Gaming Ltd. retains the right to suspend a transfer arrangement if a processor fails to maintain agreed security or confidentiality standards.

Cookie Classifications and Technical Tracking Technologies

Our web infrastructure and mobile betting applications use HTTP cookies, local storage, and tracking scripts to ensure core functionality, authenticate user accounts, and evaluate traffic performance:

  • Strictly Necessary Cookies: Essential for platform security, user session authentication, CSRF token validation, and load balancing. These cookies cannot be disabled without preventing login and transaction execution. Retention ranges from single-session memory to 30 days for continuous security authentication.
  • Analytical and Performance Cookies: Used to measure page load speeds, interface interaction bottlenecks, and navigation flows. Analytical tools capture aggregated data such as browser type, operating system, network latency, and route errors without identifying specific individuals. Retention standardly spans 90 to 365 days.
  • Functionality and Preference Cookies: Store selected user preferences across repeat visits, including Canadian region settings, default odds formats (decimal, American, fractional), language selections, and dashboard layout configurations.
  • Attribution and Marketing Cookies: Monitor affiliate referral identifiers, campaign source tags, and conversion parameters to ensure accurate tracking across marketing networks. These scripts operate on 30-day attribution windows.

Managing and Disabling Cookie Settings

You can adjust, block, or delete cookies at any time through the configuration settings of your browser (such as Chrome, Safari, Firefox, or Edge). If you choose to reject strictly necessary cookies, key components of the betting interface, cashier modules, and secure account management areas may fail to function correctly. Detailed disclosures on organizational governance can be verified via our company background overview.

User Rights, Data Security, and Retention Standards

Under applicable data privacy regulations, including the Personal Information Protection and Electronic Documents Act (PIPEDA) in Canada and international standards such as the GDPR, registered account holders retain specific statutory rights regarding the collection, processing, and storage of their personal information. Aurora Gaming maintains strict compliance workflows to ensure user requests are verified and processed within the required statutory timeframe of 30 calendar days.

Your primary data subject entitlements include the following operational rights:

  • Right of Access and Portability: You can request a comprehensive digital extract of all personal data held about you, including account registration logs, transaction records, verification records, and activity histories across our desktop platform and sports betting apps. This data is delivered in a structured, commonly used, machine-readable format (CSV or JSON).
  • Right to Rectification: If profile information, residential address, banking data, or contact numbers become outdated or inaccurate, you may update them directly within your account profile or request administrative correction through customer support. Proof of address or updated documentation may be required to verify modified identity records.
  • Right to Erasure (Right to be Forgotten): You may request the permanent deletion of your account and associated personal data. Erasure requests are processed subject to mandatory legal and financial obligations, including anti-money laundering (AML) legislation, anti-fraud auditing rules, and responsible gambling self-exclusion registry requirements.
  • Right to Restrict or Object to Processing: You hold the right to limit the processing of your personal information where data accuracy is contested, or to object entirely to automated decision-making and direct promotional communications. Opting out of promotional messaging can be completed via marketing preference toggles without impacting transactional account notices.
  • Right to Lodge a Complaint: You may raise a concern directly with our compliance office at any stage. Where a resolution is unsatisfactory, you retain the right to escalate the matter to the applicable privacy regulator without prejudice to any other legal remedy available to you.

To exercise any of the rights above, submit a written request through your account support channel or directly to our compliance office. Requests must include sufficient information to confirm your identity, since Aurora Gaming will not disclose or amend account records without verifying the requester is the account holder. Where a request is manifestly unfounded or repetitive, a reasonable administrative response may apply, or the request may be declined with reasons given in writing.

Data Minimization Practices: Fields not required for account verification, settlement, or statutory reporting are not requested. Optional profile fields, such as marketing preferences, remain blank unless voluntarily completed. Historical fields no longer required for an active purpose are flagged for scheduled removal once the applicable retention period lapses.

Children and Underage Access: Our services are restricted to individuals who have reached the legal age of majority in their province of residence. Aurora Gaming does not knowingly collect personal data from minors. Any account identified as belonging to an underage individual is suspended immediately, associated funds are returned where permitted by law, and the account record is closed subject to the retention obligations described below.

Security Protocols and Infrastructure Protection: All data transmitted to and from livelinebetting.com is protected using 256-bit TLS (Transport Layer Security) encryption protocols, authenticated by verified cryptographic certificates. Stored data is partitioned on isolated servers with active perimeter firewalls, regular vulnerability assessments, and strict multi-factor authentication (MFA) access controls restricted strictly to authorized operational staff.

Mandatory Retention Periods: In accordance with financial compliance rules, counter-terrorist financing guidelines, and Canadian federal reporting frameworks, essential customer identity records, deposits, payouts, and transactional betting logs must be retained for a mandatory minimum period of five (5) full calendar years following account closure. Upon the expiration of the statutory retention mandate, personal identifiers are permanently scrubbed from our database systems.

Support correspondence and dispute records are retained for the duration needed to resolve the matter and to demonstrate compliance with any subsequent regulatory inquiry, after which they follow the same scheduled removal process as other closed-account records. Technical telemetry logs used for fraud detection are held for a shorter operational window before being aggregated or discarded, reflecting their narrower security purpose. Marketing preference records are retained only while an active consent remains in place and are removed promptly once consent is withdrawn.

Data Breach Notification Procedures: Aurora Gaming maintains internal protocols to detect, contain, and assess any incident affecting the confidentiality, integrity, or availability of personal data. Where an incident poses a genuine risk to affected individuals, notification is issued to the relevant regulator and to affected account holders without undue delay, consistent with obligations under PIPEDA and applicable GDPR provisions. Notifications describe the nature of the incident, the categories of data involved, and the steps taken to contain and remediate it. Internal incident logs are preserved to support regulatory review and continuous improvement of security controls.

Contacting the Data Protection Officer (DPO): For formal privacy inquiries, subject access requests, or regulatory questions regarding data processing, contact our dedicated compliance office directly by email at [email protected] or via postal mail addressed to Data Protection Office, Aurora Gaming Operations, 123 High Street, Sliema, SLM 1540, Malta. If you believe your privacy concerns have not been adequately resolved, you maintain the right to submit a formal complaint to the Office of the Privacy Commissioner of Canada (OPC) or your provincial privacy oversight commissioner.