The Clubhouse Casino Australia

Privacy Policy

This Privacy Policy explains how personal information may be collected, used, shared, stored and protected when you interact with The Clubhouse Casino services.

Last updated: 4 December 2025

Personal DataAccount, identity, transaction, gaming and technical information.

Legal ProcessingContract, legal obligations, legitimate interests and consent.

Data SecurityTechnical, administrative and physical safeguards are used.

Your RightsAccess, correction, objection, portability and other applicable rights.

1. General Information

The Clubhouse Casino recognises the importance of handling personal information responsibly. This Policy describes the way personal data may be collected, processed, disclosed and protected when you use the casino website, related services or communicate with the operator.

Processing is carried out with reference to applicable privacy and data-protection requirements, including the General Data Protection Regulation (GDPR) and the Personal Information Protection and Electronic Documents Act (PIPEDA) where those frameworks apply.

The services are intended for people aged 18 or over. Personal data from anyone below the permitted age is not knowingly collected. If information relating to a minor is identified, appropriate steps may be taken to handle or remove it in accordance with applicable law.

2. About the Operator

The casino service identified in the source policy is owned and operated by Novatrix SRL, a company incorporated under the laws of Costa Rica under registration number 3-102-893958.

Its registered address is Province 03 of Cartago, County 07 of Oreamuno, Potrero Cerrado, North Side of Manuel Avila Camacho School, Costa Rica. Novatrix SRL operates under E-gaming licence No. 0000002 issued by the Tobique Gaming Commission.

Vixatrix Limited, incorporated in Cyprus under registration number HE 459370 and registered at Pavlou Nirvana 4, Alpha Tower, 1st floor, Flat/Office 11, 3021 Limassol, Cyprus, acts as payment agent for Novatrix SRL.

For the processing described in this Policy, the operator acts as Data Controller because it determines the purposes and means by which personal information is processed.

A Data Protection Officer has been designated to assist with privacy matters, legal rights and questions about the handling of personal information.

3. Personal Data and Processing

Personal data means information that identifies you, or that can reasonably be linked to you. It may be processed to provide casino services, meet regulatory requirements, maintain account security and support the operation of the platform.

The type of information collected depends on how you interact with the service, which account features you use and whether additional verification is required.

4. Categories of Data

Identity Data

Name, username, date of birth, gender, nationality and identification details such as passport or ID information.

Contact Data

Residential address, proof-of-address information, email address, telephone number and other communication details.

Financial Data

Banking and payment-card information together with source-of-funds or source-of-wealth documentation where required.

Transaction Data

Records relating to deposits, withdrawals and other financial transactions connected with the account.

Gaming Data

Games played, wagering history, login and logout activity, bonuses used and responsible-gaming measures associated with the account.

Technical Data

IP address, approximate location, browser information, device or platform details, operating system, time zone and login information.

Marketing Data

Marketing preferences, communication choices and information supplied while interacting with customer support or promotional services.

5. Why Personal Data Is Processed

Service Delivery

Information may be used to create and manage accounts, verify identity, process payments, provide access to games and promotions, respond to enquiries and deliver other requested services. This processing may rely on the performance of a contract.

Legal and Regulatory Compliance

Personal data may be processed for KYC checks, Anti-Money Laundering requirements, responsible-gaming obligations and regulatory reporting. The legal basis for this processing is compliance with applicable legal obligations.

Fraud and Risk Management

Information may be reviewed to detect fraud, bonus abuse, unauthorised activity and other risks. Legitimate interests in protecting customers and the business may provide the legal basis for this processing.

Marketing and Personalisation

Where permitted, personal data and communication preferences may be used to provide promotional content, tailored offers and marketing messages. Processing may rely on consent and/or legitimate interests, depending on the circumstances.

Analytics and Service Improvement

Website and usage information may be analysed to understand traffic, improve user experience, investigate technical problems and support research or service optimisation. This processing may rely on legitimate interests.

AI-Assisted Customer Communications

Third-party conversational AI tools may be integrated into messaging and support workflows to assist with customer conversations, retrieval of support information, pattern analysis and preparation of responses. The stated legal basis for this activity is the legitimate interest in streamlining operational processes.

Security

Personal data may also be processed to monitor, maintain and improve platform security. This may rely on legitimate interests and applicable legal obligations.

6. Sources of Personal Data

Information may come from several sources depending on the services used and the verification required.

  • Directly from you when you register, use the service or communicate with support.
  • Verification providers used to confirm identity, age or residential address.
  • Financial institutions and payment providers involved in deposits, withdrawals and other transactions.
  • AML and PEP databases used for anti-money laundering screening and checks involving politically exposed persons.
  • Regulators and responsible-gaming databases where access is required to meet legal or safer-gambling obligations.
  • Business partners, including affiliate networks, advertising platforms and analytics providers, which may provide pseudonymous information for marketing or service optimisation.

7. Disclosure of Personal Information

Personal information may be shared with selected third parties where this is necessary to operate the service, meet legal requirements or support specific business functions.

  • Group companies for fraud prevention, AML, bonus-abuse prevention, responsible gaming and, where consent has been provided, direct marketing.
  • Game providers where limited information such as a username or IP address is required to provide games.
  • Payment providers for the processing and administration of financial transactions.
  • Marketing partners where consent permits promotional communication by email, SMS or telephone.
  • Law-enforcement bodies and regulators where disclosure is required by law or a valid regulatory request.
  • Communication platforms used to provide email, customer support or live-chat services.
  • AML and KYC providers used for identity, age, address and fraud-related verification.
  • Conversational AI providers, including OpenAI, Google Gemini and Anthropic, acting as Data Processors with restricted access to relevant customer-messaging information for support and workflow purposes.
  • Professional advisers and other processors, including lawyers, consultants and regulatory-service providers operating under appropriate processing arrangements.
  • Parties to a business transfer if the business is subject to a merger, acquisition, restructuring or sale.

Third parties are expected to process personal information only for defined purposes and under appropriate privacy and security requirements. The amount of data shared should be limited to what is reasonably required for the relevant function.

8. International Data Transfers

Where personal information is transferred outside the European Economic Area, appropriate safeguards may be used to protect the data.

  • Standard Contractual Clauses approved by the European Commission.
  • Transfers to jurisdictions recognised as providing an adequate level of data protection.

9. Data Retention

Personal information is retained only for as long as necessary for the purpose for which it was collected, subject to legal, contractual and regulatory requirements.

Retention periods may take into account the reason the data was collected, applicable law, the sensitivity of the information and the risk associated with unauthorised access or disclosure.

Under the anti-money laundering requirements referenced in the source policy, personal information must be retained for a minimum of five years after an account is closed. A deletion request cannot override a mandatory legal retention period.

Anonymised information may be retained for analytics, service development or marketing-related analysis where it can no longer identify an individual.

10. Consent and Your Rights

Where GDPR, PIPEDA or another applicable privacy regime provides these rights, you may be entitled to take certain actions in relation to your personal information.

  • Withdraw consent where processing is based on consent, subject to legal or contractual restrictions.
  • Request access to personal information held about you.
  • Ask for inaccurate or incomplete information to be corrected.
  • Request deletion where there is no overriding legal basis requiring retention.
  • Restrict or object to certain types of processing.
  • Request data portability where the right applies.
  • Opt out of marketing communications.
  • Lodge a complaint with an appropriate data-protection authority.

11. Automated Decision-Making

The operator states that it does not generally rely on fully automated decision-making in ordinary business processes. If automated decision-making is introduced in circumstances that require additional disclosure, relevant information will be provided where required by law.

12. Data Security

Reasonable technical, physical and administrative safeguards are maintained to reduce the risk of loss, theft, misuse, unauthorised access or other unlawful processing of personal data.

Access to personal information is limited to employees, agents, contractors and service providers who require it for legitimate business purposes.

Player Accounts are protected by account credentials. Two-factor authentication may also be available as an additional security measure. Login details should be kept private and should not be shared with another person.

13. Changes to This Privacy Policy

This Privacy Policy may be revised as technology, operational practices or legal requirements change. Users should review the Policy periodically to stay informed about how personal information is handled.

14. Contact Information

Questions about this Privacy Policy, requests concerning personal information or complaints about the handling of personal data may be directed to the Data Protection Officer.

Data Protection Officer: [email protected]

Account and service-related questions may also be raised through the casino’s available support and live-chat channels.