Privacy Policy

Version 2.0 — last updated 2 August 2026.

GamblingSelfExclusion.com ("GSE", "we") processes personal data to submit self-exclusion requests to online gambling operators on your instruction. This notice is provided under Articles 13 and 14 of the EU General Data Protection Regulation (GDPR) and the UK GDPR.

1. Who is responsible (controller)

GSE is the data controller for the processing described here. Contact for all data protection matters, including requests and complaints: privacy@gamblingselfexclusion.com. We answer within 30 days (extendable by two months for complex requests, Art. 12(3)). We have not appointed a Data Protection Officer; the contact address above reaches the person accountable for data protection.

2. Data we collect

  • Account data: email, password hash, preferred language.
  • Identity data you self-attest: full legal name, date of birth, postal address, country of residence, and an optional national ID reference.
  • Consent and signature records: agreement version, typed signature, timestamp, IP address, device user-agent.
  • Request records: operators contacted, delivery status, operator responses (confirmed, declined, no reply).
  • Billing status from Stripe: subscription state, period, customer/subscription reference. We never receive or store your card number.
  • Technical data: security logs and the audit trail of your requests.

We never collect or store passport, driving licence or ID-card images. The service is not for children; you must be 18 or older.

3. Special category data (Art. 9)

A self-exclusion request can reveal information about gambling harm and therefore your health. We process this only on the basis of your explicit consent under Art. 9(2)(a) GDPR, given when you sign the authorization agreement. You can withdraw that consent at any time, free of charge, without affecting processing already carried out.

4. Lawful bases (Art. 6)

  • Art. 6(1)(b) — performance of your contract with GSE: account, billing, delivering requests.
  • Art. 6(1)(a) together with Art. 9(2)(a) — your explicit consent to disclose your identity details to the operators you select.
  • Art. 6(1)(c) — legal obligations, e.g. accounting records.
  • Art. 6(1)(f) — our legitimate interest in fraud prevention, security logging and keeping evidence that a request was authorized and delivered.

5. Who receives your data

  • Gambling operators you select. They receive your full legal name, date of birth, email, postal address and country, so they can identify and block your accounts. Each operator is an independent controller for its own use of that data.
  • Processors acting for us: Supabase (hosting and database), Resend (transactional email), Stripe (payments, an independent controller for card data).
  • Regulators, only when you ask us to escalate an unanswered or refused request.

We do not sell personal data and do not use it for advertising profiling.

6. Transfers outside the EEA (Art. 49)

Many operators are established outside the EEA, including in countries without an EU adequacy decision (for example Curaçao). Those transfers rest on your explicit consent under Art. 49(1)(a), given after being informed of the risk: such operators may not be bound by GDPR-equivalent safeguards and enforcement of your rights against them may be difficult or impossible. If you are not comfortable with that risk, do not select those operators.

7. Irreversible disclosure

Once a request has been delivered, GSE cannot recall, correct or erase the data held by that operator. Deleting your GSE account erases your data at GSE only; to exercise rights against an operator you must contact the operator directly. We list every recipient in your data export so you can do so.

8. Retention

  • Account, identity and request records: while your account exists, then erased on deletion.
  • Signed agreement and delivery evidence: erased with your account; we keep no copy afterwards other than the anonymised deletion log.
  • Deletion log (user ID, timestamp, no other personal data): 3 years, as evidence that we honoured your request.
  • Invoices and accounting records: retained by Stripe and by us for the statutory period (typically 7 years).

9. Your rights

  • Right of access (Art. 15) — see everything we store about you.
  • Right to data portability (Art. 20) — download it as a machine-readable JSON file.
  • Right to rectification (Art. 16) — correct inaccurate personal data.
  • Right to erasure / "to be forgotten" (Art. 17) — permanently delete your account and personal data.
  • Right to restriction (Art. 18) — have us pause processing while a dispute is resolved.
  • Right to object (Art. 21) — object to processing based on legitimate interest.
  • Right to withdraw consent (Art. 7) — future exclusion requests will not be sent after withdrawal.
  • Right to lodge a complaint (Art. 77) with your national supervisory authority, or in the UK with the ICO.

Signed-in users can exercise access, portability and erasure instantly and free of charge at Privacy & your data. For rectification, restriction, objection or if you are not signed in, email privacy@gamblingselfexclusion.com from your registered address.

10. Automated decision-making

We do not make decisions producing legal effects about you by automated means alone. Requests are sent only after you personally sign an authorization. Any operator's decision to close an account is made by that operator, not by GSE.

11. Security

Data is stored in the EU with encryption in transit and at rest, row-level access controls so users can only reach their own records, role-based administrative access and audit logging. If a breach is likely to result in a risk to your rights, we notify the supervisory authority within 72 hours and you without undue delay (Art. 33–34).

12. Cookies and changes

Cookie use is described in our cookie policy. Material changes to this notice are announced by email or in-app before they take effect; where a change concerns consent-based processing we ask for fresh consent.