This Privacy Policy is for users in Greece who use sugarrushdemo.com.gr. It explains how we handle personal data on an online gambling website, what we use it for, and what choices you have. We follow the GDPR and process data with a practical mindset: only what’s needed, for clear purposes, with reasonable protection. If you want to know what we collect, how it’s used, and when it can be shared, the sections below cover that in plain language.
The Data Controller is the party operating sugarrushdemo.com.gr and deciding how and why personal data is processed. For privacy questions or GDPR requests, email [email protected]. To keep accounts safe, we may ask for reasonable identity verification before completing a request—especially if it involves access to data, deletion, or portability. We only use verification to confirm you’re the right person and to prevent unauthorised disclosure.
This policy applies to visitors, registered users, and customers in Greece using sugarrushdemo.com.gr, on desktop or mobile. It also covers messages sent to customer support and other service communications. The site is intended for adults, and we do not knowingly collect personal data from minors. If we learn that a minor has provided personal information, we will take appropriate steps to limit processing and remove the data where suitable.
We may process account and identity details, verification and compliance information (including responsible gaming settings), and records linked to activity and transactions. Technical data may also be collected, such as IP address, device identifiers, browser details, timestamps, and security logs. Cookies and similar technologies can support essential functions and, where permitted, analytics. If you contact support, we may keep your messages and the details needed to handle the request.
We use personal data to run the service, manage accounts, and provide customer support. Processing can also be needed for eligibility checks, security, and fraud prevention. Some data handling supports legal and regulatory compliance, including responsible gaming protections. We use service-level insights to fix problems, improve performance, and make the site easier to use. Marketing may be used where permitted and, where required, based on your preferences.
Depending on the purpose, processing may rely on contract performance (providing the service), legal obligation (compliance duties), or legitimate interests (security, preventing abuse, improving reliability). Where required, we rely on consent—commonly for non-essential cookies and certain marketing preferences. Vital interests apply only rarely, when processing is needed to protect someone’s life. We match each activity to an appropriate legal basis and keep processing limited to what the purpose requires.
Cookies help the site function and remember key settings. Essential cookies support core operations like security and stability. Non-essential cookies (for example analytics or personalisation) require consent under EU/Greece rules. You can change your choices and withdraw consent at any time via the cookie settings available on the site, with effect going forward. Declining non-essential cookies should not break core functions, but it may reduce optional features.
We may share data with trusted providers who support the service, such as hosting, analytics, support tools, verification services, and security partners. Where relevant, data may also be shared with payment providers and professional advisers (for example legal or audit). If group companies are involved, sharing may occur under consistent protection standards. We may disclose data to authorities or regulators where required by law. Personal data is not sold.
If data is transferred outside the EEA, we use GDPR safeguards to protect it. This can include Standard Contractual Clauses and extra measures where needed. Transfers are limited to genuine operational needs and assessed with security in mind. You can request more information about the safeguards that apply to your situation by contacting [email protected].
We keep personal data only as long as needed for the purposes described in this policy and for applicable legal or compliance obligations. Retention depends on the data type and the context in which it was collected. When information is no longer required, we delete it or anonymise it so it can no longer be linked to you. We aim to avoid keeping data “just in case.”
If you believe your data has been handled in a way that conflicts with GDPR, you can complain to the Hellenic Data Protection Authority (HDPA). You can also contact us first, since many issues can be resolved quickly with a direct review—especially when the question relates to account details, technical records, or how a feature works. We aim to respond clearly and handle concerns in a fair way.
We use technical and organisational measures designed to protect personal data, such as access controls, monitoring, and incident response procedures. Where appropriate, we use encryption in transit. We also review key suppliers and tools with security expectations in mind. Even strong protections cannot guarantee perfect security, so we focus on layered controls and fast action if something looks unusual.
Automated systems may be used for fraud prevention, platform security, and responsible gaming protections. For example, unusual activity can trigger checks intended to reduce misuse and protect users. Where required by law, you can request human review of an automated decision that significantly affects you. To request review, contact [email protected] and describe what happened and how it affected you.
We may update this Privacy Policy when services, processes, or legal requirements change. The latest version will be posted on the site with a new “Last updated” date. If changes are significant, we may provide notice through appropriate channels within the service experience. Continued use of sugarrushdemo.com.gr means you had the opportunity to review the current version.