1. Introduction
This Privacy Policy explains how Grosvenor Casino Hull collects, uses, stores, shares and protects personal data relating to customers, prospective customers and visitors to the premises and website. The policy applies to all individuals whose personal data is processed in connection with the services provided by Grosvenor Casino Hull.
Personal data is handled in accordance with the UK General Data Protection Regulation (UK GDPR), the Data Protection Act 2018 and applicable sector-specific requirements imposed by the UK Gambling Commission (UKGC). This policy should be read together with the Terms and Conditions, Cookie Policy and Responsible Gambling information, as those documents are directly connected to personal data processing.
Questions about this policy and requests to exercise data protection rights should be directed to the Data Protection Officer using the contact details in Section 9.
2. Who Is the Data Controller
For the purposes of this Privacy Policy, Grosvenor Casino Hull is the data controller. As data controller, Grosvenor Casino Hull determines the purposes and means of processing personal data described in this document.
Where third-party service providers act as data processors on behalf of Grosvenor Casino Hull, appropriate contractual safeguards are implemented to ensure processing is carried out only on documented instructions and in compliance with applicable data protection law.
3. Personal Data Collected
The following categories of personal data are collected and processed:
Personal identification data
- Examples: full name, date of birth, address, phone number, email address
- Main purposes: account registration, identity verification, age validation
Financial data
- Examples: payment details, transaction history, source of funds information
- Main purposes: processing transactions, affordability checks, anti-money laundering (AML) compliance
Technical data
- Examples: IP address, device type, browser, geolocation
- Main purposes: security monitoring, fraud prevention, operation of the service
Gaming activity data
- Examples: betting patterns, session duration, game preferences
- Main purposes: responsible gambling monitoring, regulatory compliance
Identity documents
- Examples: passport, driving licence, utility bills
- Main purposes: Know Your Customer (KYC) verification, regulatory obligations
Communications data
- Examples: records of correspondence with the customer support team
- Main purposes: customer support, dispute resolution
Personal data is obtained directly from the individual (for example, when registering, using the services or making contact) and, where permitted by law, from third-party sources such as fraud-prevention agencies and credit reference agencies.
4. Lawful Bases for Processing
Personal data is processed on the following lawful bases under UK GDPR:
Performance of a contract
Processing that is necessary to provide services to the user, including account management and transaction processing.Legal obligation
Processing that is required to comply with obligations under the Money Laundering, Terrorist Financing and Transfer of Funds (Information on the Payer) Regulations 2017, UKGC licence conditions and other applicable legislation.Legitimate interests
Processing for purposes such as fraud prevention, security monitoring and service improvement, where such interests are not overridden by the rights and freedoms of the individual.Consent
In specific situations, for example certain marketing communications, processing is based on consent. Consent may be withdrawn at any time. Withdrawal of consent does not affect the lawfulness of processing carried out before consent was withdrawn.
The lawful basis for each processing activity is documented and can be provided on request.
5. Use of Personal Data
Personal data is used for the following purposes:
- Verifying identity and age prior to granting access to gambling services, in line with UKGC requirements.
- Conducting ongoing customer due diligence and monitoring to meet anti-money laundering and counter-terrorist financing obligations.
- Monitoring gambling activity to identify indicators of problem gambling and to meet responsible gambling obligations under UKGC licence conditions.
- Detecting, investigating and preventing fraud, cheating and other unlawful activity.
- Processing and recording financial transactions.
- Responding to enquiries, complaints and requests from regulators.
- Operating and enforcing self-exclusion schemes and applying self-exclusion periods as required by the UKGC.
- Maintaining and improving the security and operation of the services.
6. Sharing of Personal Data
Personal data may be shared with the following categories of recipients, in each case only to the extent necessary and in accordance with applicable law:
- The UK Gambling Commission and other regulatory or supervisory authorities, where required by law or licence conditions.
- Law enforcement agencies and government bodies, where disclosure is legally required.
- Fraud-prevention agencies and identity-verification providers, for KYC, AML and related compliance purposes.
- Payment service providers, for the processing of payments and related transactions.
- IT, hosting and security service providers acting as data processors.
Personal data is not sold to third parties. Where data is shared with processors, they are required to process personal data only on documented instructions, to maintain appropriate security measures and to comply with applicable data protection legislation.
7. Retention of Personal Data
Personal data is retained only for as long as necessary for the purposes described in this policy or as required by law or regulatory obligation.
In accordance with the Money Laundering, Terrorist Financing and Transfer of Funds (Information on the Payer) Regulations 2017, customer due diligence, identification, verification and supporting records are retained for a minimum of five years following the end of the business relationship.
UKGC requirements also oblige retention of self-exclusion records for the duration of any self-exclusion period and for a period thereafter, to ensure that self-exclusion is correctly implemented and enforced.
Where retention of personal data is required by legal or regulatory obligation, the right to erasure may not apply to the relevant data. If an erasure request is made, any applicable legal or regulatory restrictions on that request will be explained in the response.
8. Your Data Protection Rights
Under UK GDPR, individuals have the following rights in relation to their personal data:
Right of access
The right to request confirmation of whether personal data is being processed and, if so, to receive a copy of that data.Right to rectification
The right to request correction of inaccurate personal data and completion of incomplete data.Right to erasure
The right to request deletion of personal data, subject to overriding legal or regulatory retention obligations.Right to restriction of processing
The right to request that processing of personal data be limited in certain circumstances.Right to data portability
Where processing is based on consent or contract and carried out by automated means, the right to receive personal data in a structured, commonly used and machine-readable format and, where technically feasible, to have that data transmitted to another controller.Right to object
The right to object to processing based on legitimate interests and to object at any time to processing for direct marketing purposes.Rights related to automated decision-making and profiling
The right not to be subject to a decision based solely on automated processing, including profiling, which produces legal effects or similarly significant effects, unless such processing is permitted by law and appropriate safeguards are in place.
To exercise any of these rights, contact the Data Protection Officer using the details in Section 9. A response will be provided within one calendar month of receipt of the request. In complex cases, this period may be extended by up to two further months; in such cases the requester will be informed of the extension and the reasons for it.
9. Contact Details
Queries about this Privacy Policy, requests to exercise data protection rights, or concerns about the handling of personal data should be directed to:
Data Protection Officer
Grosvenor Casino Hull
[Address]
[Email address]
[Telephone number]
If the response is not considered satisfactory, a complaint may be lodged with the Information Commissioner’s Office (ICO), the UK supervisory authority for data protection matters:
Information Commissioner’s Office
Wycliffe House
Water Lane
Wilmslow
Cheshire
SK9 5AF
Website: ico.org.uk
10. Changes to This Policy
This Privacy Policy is reviewed periodically and updated when necessary to reflect changes in processing activities, legal requirements or regulatory guidance. The current version of the policy is made available on the website and can be provided at the premises on request.
Continued use of the services following an update to this Privacy Policy constitutes acknowledgement of the revised policy. Where changes are material and contact details are available, reasonable steps will be taken to notify affected individuals directly.

