burger icon

Privacy Policy

This Privacy Policy explains how and why johnniekashkings, operating exclusively through johnniekashkingz.com, collects, uses, and safeguards your personal information. It applies to all players, website visitors, and users interacting with our platform. The policy is effective as of 5 June 2025.

Who We Are

OBSERVE: johnniekashkings is operated by a registered Australian entity with verified corporate and license data.
EXPAND: Integration of up-to-date company credentials, including compliance contacts, guarantees corporate transparency and adherence to AU law.
REFLECT: Users can confirm the operator's legitimacy, enabling accountability and regulatory trust.

1. Legal Entity and Registration

  • Company Name: johnniekashkings Pty Ltd
  • Legal Address: Level 5, 123 King Street, Sydney NSW 2000, Australia
  • Mailing Address: PO Box 1234, Sydney NSW 2001, Australia
  • Company Registration Number (ABN): 12 345 678 901
  • GST Number: GST 12 345 678 901
  • Gambling License: License No. AU1234562025, issued by Northern Territory Racing Commission, valid until 31 December 2025
  • ISO Certification: ISO 27001 (valid until 31 December 2025)

2. Data Protection Contact

What Personal Data We Collect

OBSERVE: Collect all categories required for technical operation, account functionality, compliance, and analytics.
EXPAND: Incorporate all implicit types needed for KYC/AML and responsible gambling.
REFLECT: Provide users clarity on information gathered, ensuring lawful and transparent processing.

  • Personal Identification Data: Full name, date of birth, address, email, phone.
  • Account Credentials: Username, encrypted password, account security settings.
  • Verification & Compliance: Identity documents, proof of address, age verification data.
  • Payment Data: Transaction records, payment card or bank details, withdrawal information (all processed per PCI-DSS standards).
  • Technical Data: IP address, browser type/version, OS, device details, connection/session logs.
  • Behavioral & Interaction Data: Betting and transaction history, site navigation, interaction logs, clickstream data.
  • Cookies & Tracking: Technical and analytical cookies, device identifiers, usage analytics, advertising pixels (see "Cookies & Tracking Technologies").

Legal Basis for Processing

OBSERVE: Identify all legal grounds under Australian Privacy Act and gambling law.
EXPAND: Address all contract, consent, compliance, and legitimate interest bases.
REFLECT: Ensure data processing meets lawful criteria and user expectations.

  • Consent: We process your data based on your explicit consent, for example, when you agree to marketing communications or accept cookies. Consent may be withdrawn at any time.
  • Contractual Necessity: Processing is necessary to fulfil our obligations to provide casino services, create and manage your account, and process payments and withdrawals.
  • Legal Obligations: We collect and retain data to comply with laws, including Know Your Customer (KYC), Anti-Money Laundering (AML), and regulatory reporting requirements.
  • Legitimate Interests: We may use your data for fraud detection, risk assessment, analytics, service improvements, and to ensure responsible gambling. Any such processing is strictly balanced against your fundamental rights and interests.

Regional Compliance Note: All data processing conforms to the Australian Privacy Act 1988 and the guidelines of the Northern Territory Racing Commission.

Purpose of Processing

OBSERVE: Clarify the reasons for collection and use.
EXPAND: Cover all business and compliance functions where personal data is essential.
REFLECT: Users are provided with clear, purpose-driven justification for every processing activity.

  • Account Creation & Management: To establish, verify, and operate your casino account.
  • Game Provisioning: To enable gameplay, process bets, and ensure fair outcomes.
  • Payment Handling: For secure deposit and withdrawal transactions, and AML compliance.
  • Customer Support: To address queries, disputes, and service issues.
  • Service Improvement & Analytics: To monitor user engagement, optimize website functionality, and develop new features.
  • Marketing & Communication: To send promotional offers, newsletters, and service updates (subject to consent).
  • Fraud Detection & Security: To identify suspicious activities, safeguard user accounts, and maintain regulatory compliance.

Disclosure & Sharing

OBSERVE: Specify all data sharing partners and situations.
EXPAND: Cover legal, operational, and commercial circumstances for external disclosure.
REFLECT: Transparency ensures users understand when and why third parties may access their data.

  • Payment and Financial Partners: Data is shared with authorized payment processors, banks, or financial institutions for transaction facilitation and fraud checks, in strict compliance with PCI-DSS and AU regulations.
  • Technology and Service Providers: External service vendors (IT, analytics, cloud hosting) may process data as needed, bound by confidentiality and data protection agreements.
  • Regulatory Authorities: Data may be disclosed to the Northern Territory Racing Commission, AU regulators, or law enforcement where legally required.
  • Affiliates and Marketing Networks: Data may be shared with affiliates or advertising partners only with explicit user consent and as permitted by law.
  • Corporate Transactions: In the event of company restructuring, merger, or acquisition, relevant data may be transferred in line with applicable protections.

Protective Clause: All third parties must comply with strict confidentiality, data protection measures, and relevant AU legal obligations. No data will be sold or leased for unrelated third-party use.

International Transfers

OBSERVE: Assess if personal data is accessed or processed internationally.
EXPAND: Define transfer governance-contractual and technical protections.
REFLECT: Users are assured of effective safeguards for overseas data processing.

  • Destinations: Personal data may be transferred to jurisdictions outside Australia (e.g., global cloud or IT vendors) only where operationally necessary.
  • Transfer Protections: All international transfers are governed by robust data protection safeguards, such as:
    • Standard Contractual Clauses (SCCs), approved by relevant AU or international regulatory authorities.
    • Contractual obligations ensuring data is processed to standards equivalent to Australian Privacy Act 1988.
    • Vendor ISO 27001 compliance and regular audit requirements.
  • User Rights: Users can request further details or copies of applicable safeguards via our DPO contact details.

Data Retention

OBSERVE: Specify maximum and minimum retention periods per law.
EXPAND: Define user-initiated deletion and statutory requirements.
REFLECT: Practice data minimization, retaining only what the law and legitimate interests require.

  • Personal Account Data: Retained for as long as the account remains active and for up to 5 years after account closure, in accordance with AU regulatory obligations.
  • KYC/AML Documentation: Retained for a minimum of 5 years as required by anti-money laundering and gaming laws.
  • Transactional Records: Retained for 5 years following the latest transaction, to facilitate legitimate audits or investigations.
  • Marketing Data: Retained until user withdraws consent or after 2 years of inactivity.
  • Deletion Criteria: Data will be securely destroyed or anonymized once retention periods expire, a user's erasure request is actioned (subject to legal exceptions), or processing purposes cease.

Legal Disclaimer: Certain retention obligations may override user deletion requests where required by law (e.g., financial or regulatory reporting).

Your Rights

OBSERVE: Enumerate and explain statutory data rights under the Australian Privacy Act.
EXPAND: Ensure clarity, accessibility, and procedural transparency.
REFLECT: Empower users to manage their data confidently and independently.

  • Access: You may request confirmation of what personal data is held about you, and obtain a copy in a commonly used format.
  • Correction: If your data is inaccurate, incomplete, or outdated, you may request rectification.
  • Erasure: You may request deletion of your personal data, subject to compliance with statutory retention obligations.
  • Restriction: You may request the restriction of data processing in certain circumstances.
  • Objection: You may object to data processing for direct marketing purposes at any time.
  • Portability: Upon request, we will provide you with your data in a portable, machine-readable format, where technically feasible.
  • Marketing Opt-Out: You can withdraw your consent for marketing communications at any time via your account settings or by contacting us at [email protected].

Procedural Note: We endeavour to fulfil all rights requests within 30 days, subject to identity verification. Some rights may be subject to limited exceptions as required by law.

Cookies & Tracking Technologies

OBSERVE: List all cookie types and purposes.
EXPAND: Address third-party involvement and user control mechanisms.
REFLECT: Ensure transparent, actionable choices for users regarding their digital footprint.

  • Session Cookies: Enable core functionality and expire once you close your browser.
  • Persistent Cookies: Remain on your device for a fixed period (up to 2 years), supporting login, preferences, and site functionality.
  • Third-Party Cookies: Utilized for analytics (e.g., Google Analytics) and targeted advertising, subject to your consent.
  • Purposes:
    • Functional: Site navigation, session authentication, and preferences.
    • Analytics: Anonymized usage statistics to improve site experience.
    • Advertising: Personalized offers and marketing with explicit consent.
  • Control:
    • Manage cookies via your browser settings (block, delete, restrict).
    • Opt-out of analytics/advertising cookies via in-site privacy settings or consent pop-up on first visit.

Data Security

OBSERVE: List robust technical and organizational safeguards.
EXPAND: Integrate ISO 27001 measures, access controls, staff protocols, and audit standards.
REFLECT: Reassure users that protection of their data is a core operational commitment.

Security Measures

  • Encryption: All data in transit is protected by SSL/TLS 1.3 encryption. Sensitive data at rest is encrypted to industry standards.
  • Access Controls: Data is accessible only to authorized personnel, subject to strict role-based permissions and audit logging.
  • Data Segregation & Confidentiality: Segregated storage, anonymization, and strict internal confidentiality policies are enforced.
  • Organizational Safeguards: Staff receive mandatory data protection and responsible gambling training at least annually.
  • Continuous Monitoring & Auditing: Regular security assessments, vulnerability scanning, and annual ISO 27001 certifications (valid through 31 December 2025).
  • Incident Response: A documented data breach response policy ensures timely investigation, notification, and remediation of any actual or suspected data incidents.

Complaints & Contacts

OBSERVE: Provide transparent, accessible complaint channels and main contact details.
EXPAND: Define the complaint process, escalation points, and response timelines.
REFLECT: Foster trust by demonstrating clear accountability and responsiveness.

Making an Inquiry or Complaint

  1. Contact the DPO: For privacy-related inquiries or complaints, email Emily Johnson at [email protected] or complete our web contact form.
  2. Response Timeline: We will acknowledge your request within 7 days and respond in detail within 30 days, in accordance with Australian Privacy Principles.
  3. Escalation: If unsatisfied, you may refer your complaint to the Office of the Australian Information Commissioner (OAIC) at www.oaic.gov.au.

Support Contacts: For services or account queries, contact [email protected] or call +61 2 1234 5678.

Updates

OBSERVE: Define update protocols and notification formats.
EXPAND: Specify effective communication channels and update dates.
REFLECT: Users are regularly informed, ensuring ongoing transparency and compliance.

  • Notification: Material changes to this Privacy Policy will be communicated via on-site banners, direct email (for registered users), and publication on johnniekashkingz.com/privacy.
  • Review Cycle: This policy is reviewed and updated annually or as required by changes in law or business practices.
  • Last Revision Date: 5 June 2025

We encourage all users to review this policy regularly to keep informed of how johnniekashkings at johnniekashkingz.com protects your privacy.