Privacy Policy
Grand Quay Media Ltd operates Lucky-Boom-Casinos.de as an affiliate review portal. We do not offer gambling ourselves, nor do we process deposits, withdrawals, or bets. This privacy policy explains how we collect and handle your personal data when you visit our website.
We take the protection of your data seriously. This policy complies with the EU General Data Protection Regulation (Regulation (EU) 2016/679).
1. Controller
The controller responsible for your personal data is:
- Company: Grand Quay Media Ltd
- Address: 10 Triq il-Kbira, SLM 3010 Sliema, Malta
- Phone: +356 2199 2683
- Email: hello@lucky-boom-casinos.de
- Registry: Malta Business Registry, registration number C 13719
- VAT ID: MT30943371
You can reach our data-protection contact at privacy@lucky-boom-casinos.de. For postal correspondence, please use the address above, marking it for the attention of Adrian Zammit.
2. What we collect
We collect only the data necessary for the operation of an affiliate review portal. This includes:
- Server log files: When you visit our site, our web server automatically records your IP address, the date and time of your visit, your browser user agent, and the referring website. No additional profiling occurs at this stage.
- Consent records: When you give or withdraw consent for cookies or analytics, we store a timestamp and a pseudonymised identifier. This is to prove compliance with the GDPR.
- Contact-form data: If you send us a message via our contact form, we collect your name, email address, and the content of your message. We use this only to respond to your enquiry and delete it after the matter is resolved.
We do not collect payment data, government-issued IDs, or sensitive data under Article 9 of the GDPR. We never request your gambling account credentials.
3. Legal bases
Our processing is grounded on the following legal bases under Article 6 of the GDPR:
- Article 6(1)(a) – Consent: We rely on your freely given, specific, informed, and unambiguous consent for setting non-essential cookies and for activating analytics tools. You can withdraw this consent at any time with the same ease as you gave it.
- Article 6(1)(f) – Legitimate interests: We process server log files, consent records, and spam-prevention checks to maintain the security and functionality of our website. Our legitimate interest is the safe and uninterrupted provision of an independent review platform. We weigh your interests and rights carefully and find no overriding privacy impact from these minimal-data operations.
- Article 6(1)(b) – Contractual necessity: If you contact us via the form, processing your data is necessary to answer your query, which is a step taken at your request.
We do not base any processing on consent you cannot practically revoke.
4. Cookies and analytics
Our website uses cookies and similar technologies. By default, only technically necessary cookies are set without requiring your consent. Non-essential cookies, including those for analytics, are placed only after you explicitly opt in.
You can withdraw your consent to non-essential cookies at any time. The withdrawal mechanism is just as easy to activate as granting consent — typically a one-click toggle in our cookie banner. After withdrawal, we stop the related processing and delete the corresponding data unless a legal obligation to retain it exists.
We use a privacy-compliant analytics tool that anonymises user IP addresses by truncating them before any storage. The analytics provider acts as a processor under our instructions.
5. Recipients and transfers
We share your personal data only with carefully selected processors:
- Web hosting provider: responsible for server infrastructure and security
- Analytics platform: provides anonymised usage statistics
- Email service: for handling contact-form submissions
Each processor is bound by a data-processing agreement that meets the requirements of Article 28 of the GDPR. No recipient processes your data for their own purposes.
If we transfer data outside the European Economic Area, we rely on the EU Standard Contractual Clauses or an adequacy decision from the European Commission. We do not send your data to countries without an adequate level of protection.
6. Retention
We store your personal data only as long as necessary:
- Server log files: 7 days, after which only anonymised statistics remain
- Consent records: 3 years to comply with audit requirements
- Contact-form data: deleted within 3 months after your matter is resolved
Once the purpose for processing ceases to exist or a legal retention period expires, we delete or irreversibly anonymise the data.
7. Your rights under the GDPR
As a data subject, you hold the following rights:
- Right to access (Article 15): You may ask us to confirm whether we process your data and, if so, to receive a copy of it.
- Right to rectification (Article 16): You can request the correction of inaccurate data or the completion of incomplete data.
- Right to erasure (Article 17): Under certain conditions, you can ask us to delete your data — for example, if it is no longer necessary or if you withdraw consent.
- Right to restriction (Article 18): You can limit the processing of your data while we verify its accuracy or legality.
- Right to data portability (Article 20): You can request your data in a structured, machine-readable format and, where technically feasible, have us transfer it directly to another controller.
- Right to object (Article 21): You may object to processing based on legitimate interests. We then stop unless we demonstrate compelling legitimate grounds.
- Right to withdraw consent (Article 7(3)): You can