Privacy Policy
Last updated: August 2026
Controller
For the personal data described here, control rests with whoever operates this website. A joint controller, other brands inside the same business group and a parent company process parts of it. Somebody holds the Data Protection Officer role, and dpo@lizaro.com is the way to them. Framing all of it is the General Data Protection Regulation.
What is collected
Registration data — name, date of birth, email address, phone number, country, account currency.
Due diligence data — identity card, driving licence or passport number, proof of address, social security number, source of wealth and funds, bank ID, financial statements.
Transaction data — deposits, withdrawals, payment routes, references, balances.
Device and usage data — login times, device and browser, IP address, pages and games opened. On a phone this set also identifies the handset the account is normally used from, which is one of the signals behind the one-account-per-person rule.
Where it comes from
Most of it from you. Due diligence may also draw on public and government databases, internet and social media sources, commercially available databases, financial and credit institutions, fraud prevention agencies and public authorities, where the law requires that depth of check.
Why it is held
Opening and running the account. Verifying age and identity. Meeting anti-money laundering obligations under the 5th AML Amendment. Processing payments and keeping the records the law requires. Detecting fraud and keeping the service standing up.
Who it is shared with
Authorised employees. Brands within the same entity or operator. Contractors, agents, joint controllers, affiliates and subsidiaries. Third-party providers running parts of the platform. Law enforcement, regulators and licensing bodies, on the occasions they are entitled to ask.
One clause is worth stating rather than burying: if you submit a complaint or a review about us to a third-party platform — a casino review site, a gambling forum, a dispute resolution body — we may disclose personal data to that platform, limited to what identifies the account, on the basis of our legitimate interest in protecting our business reputation.
Retention
It lasts as long as the account does, and once neither a legal nor a business need is left, it is deleted or anonymised. Anti-money laundering rules and other regulation extend that where they apply.
Your rights
Access, correction, erasure where nothing requires us to keep it, restriction, objection, portability, and withdrawal of a consent given earlier without that affecting anything done before. Exercise one by writing from the registered address to dpo@lizaro.com. A complaint is also open to you at the supervisory authority covering your home, your workplace, or the spot where you believe an infringement happened.
Security
Everything travels over SSL, and due diligence records stay inside the group of staff whose work calls for them. At your end, anything done with the correct email and password counts as done by you — which is the reason biometric unlock on a phone is worth switching on and a reused password is not worth the convenience.
Cookies
Four categories. The essential ones hold sessions and security up, and there is no switching them off. Functional cookies remember preferences. Performance cookies measure how pages are used. Targeting cookies support advertising. Nothing runs in the last two without consent, and a Cookie Settings panel offering Accept all, Decline all and Save & Close waits on every page.