Privacy Policy
This document covers ezzcasino.info alone, an editorial notebook. It does not cover the operator Ezz or any other destination reached from here, each of which publishes its own policy under its own responsibility. The distinction matters more than it looks: this domain has no accounts, no log-in, no cashier, and no card number, IBAN or identity document ever passes through it.
Controller
The controller for the processing described on this page is the editorial team behind ezzcasino.info, reachable at the contact address on the domain. There are no forms, no ticketing systems and no case numbers — a written message arrives and is answered.
Categories of data processed
Two, and only two. The first is ordinary server log data, generated automatically whenever a page is served: IP address, device and browser type, operating system, page requested, referring page, and the timestamp of the request. The second is analytics cookies, which produce aggregate statistics about pages read, time spent and how the site performs over mobile connections.
A third, voluntary category exists: anyone writing to the domain address inevitably sends their own address and the contents of their message. Name, home address, NIF, mobile number and identity documents are never requested and exist in no system controlled by this notebook.
Purposes and lawful basis
Under the General Data Protection Regulation, server logs rest on the legitimate interest in keeping the service available, stable and protected against abuse. Audience measurement rests on consent collected through the cookie notice and is entirely dispensable — refusing it closes no doors, because the pages behave identically without it. Replying to messages rests on the legitimate interest in communicating with people who write in.
None of the processing described here serves behavioural advertising, individual profiling or the transfer of data to third parties for commercial purposes. That last practice is excluded absolutely and does not depend on any setting.
Retention
Hosting logs are short-lived and rotate, being deleted automatically by the infrastructure cycle. Statistics follow the retention window configured in the measurement tool and are erased at the end of it. Correspondence is kept while the matter is live, plus a reasonable period in case it reopens. Nothing here is held indefinitely, for the obvious reason that there would be no use in it.
Recipients and transfers
Aggregate statistics are processed by the provider of the measurement tool acting as a processor, which can involve transfers outside the European Economic Area under the mechanisms the GDPR provides for. Affiliate links carry a referral identifier to the operator — a marker recording where a visit came from, containing no personal data. There are no social media widgets, advertising pixels or additional trackers on this domain.
Rights of the data subject
The GDPR grants rights of access, rectification, erasure, restriction of processing, portability and objection, together with the right to withdraw consent at any moment without retroactive effect on processing already carried out. In practice, and because this notebook keeps no identifiable data, most requests belong with the parties that actually process personal data: the measurement tool provider for statistics, and the operator for anything touching a gaming account, its documents or its movements. Any request concerning this site can still be sent to the domain contact address and will receive an answer.
Supervisory authority
In Portugal the supervisory authority for data protection is the CNPD, the Comissão Nacional de Proteção de Dados. Any data subject who considers that the processing of their data breaches the GDPR may lodge a complaint with the CNPD, whether or not they contacted the controller first.
Minors, security and changes
The content is intended for adults aged 18 and over and is not directed at minors; since no identifiable data is collected from any visitor, none is collected from minors either. Pages are served over an encrypted connection, and because there are no accounts and no payments on this side there is no sensitive store that could be exposed — the strongest protection remains not collecting anything. Changes to this policy are published here with a date, and substantial ones are flagged at the top for a reasonable period. If the measurement tool is replaced, this page is updated before the change takes effect: consent requested after the fact is not consent.
Cookies in practice
A privacy policy states what is processed and why; cookies are the mechanism through which most of it happens on a website. Necessary ones keep pages functioning and remember basic preferences. Analytics ones count visits and describe behaviour in aggregate. Neither category identifies a reader by name, because no reader ever supplies one.
Anyone who would rather opt out entirely has the simplest control already to hand: browser settings, which block or delete cookies per site and remember that choice on future visits. Using them costs nothing in functionality on this domain, which is exactly why measurement here is treated as optional rather than as a condition of reading.
What the operator collects, by contrast
An operator's data footprint is incomparably larger, and understanding it is part of deciding whether to open an account at all. Everything typed into a cashier — card details, a photograph of a Cartão de Cidadão, an address, an IBAN — travels over an encrypted channel and is then retained under obligations attached to the licence rather than at the sender's discretion: anti-money-laundering rules generally require identification and transaction records to be kept for years, including after an account is closed. An erasure request does not override those obligations.
From there the data moves in predictable directions: to the payment provider executing the transfer, to the service that checks documents, and to a regulator or a bank when a formal request arrives. All of that processing happens on the operator's side rather than this one, so access, copy and erasure requests concerning a gaming account have to go to its support desk. On the player's side the habits that work are dull and effective: a password reused nowhere else, two-factor authentication switched on in the account settings, and never signing in from someone else's device. Where a session was left open on hardware you no longer have, changing the password closes it faster than hoping nobody notices.