Privacy Policy

SAMO iGAMING — GDPR COMPLIANT — LAST UPDATED: JULY 2026

We process personal data in accordance with the GDPR. Player KYC and balance data are managed by the operating partner — Samo iGaming does not store player PII directly.

1. Introduction

Samo iGaming ("we", "us") is committed to protecting the privacy of users of the Survivor Crash platform. This Privacy Policy describes what data we collect, how we use it, and the rights you have regarding your personal information. We comply with the General Data Protection Regulation (GDPR) and applicable data protection laws.

2. Data We Collect

We process the following categories of data: (a) Account data — name, email, company name for B2B contacts; (b) Game data — bet amounts, cash-out multipliers, round IDs, and game outcomes for audit and settlement purposes; (c) Technical data — IP address, browser type, and usage analytics for security and performance monitoring; (d) KYC data — processed by operators, not stored by Samo iGaming directly.

3. Legal Basis for Processing

We process personal data based on: (a) Contractual necessity — to provide the game service to operators; (b) Legal obligation — to maintain audit trails and comply with regulatory requirements; (c) Legitimate interest — to prevent fraud and ensure game integrity; (d) Consent — for marketing communications, which can be withdrawn at any time.

4. Provably Fair Data

Game round data — including server seeds, client seeds, nonces, crash points, and HMAC hashes — is stored in an immutable audit ledger. This data is essential for the Provably Fair verification system and is retained for the duration required by applicable gaming regulations (typically 5-7 years).

5. Data Sharing

We do not sell personal data. Game data is shared with the operating partner for settlement and player account management. Aggregate, anonymized data may be used for analytics and product improvement. Data may be disclosed to regulatory authorities or testing laboratories (GLI, iTech Labs) as part of compliance audits.

6. Data Security

We implement industry-standard security measures: TLS 1.3 encryption for all API traffic, HMAC-SHA256 webhook signatures, environment-variable-based secret management, role-based access control, and immutable audit logging. API keys are never stored in source code. Player balances and KYC data are managed by operators, not by Samo iGaming.

7. Data Retention

Game round and transaction data is retained for a minimum of 5 years to meet regulatory audit requirements. Contact messages are retained for 2 years. Analytics data is anonymized after 12 months. You may request deletion of your personal data, subject to legal retention obligations.

8. Your Rights

Under GDPR, you have the right to: (a) Access your personal data; (b) Rectify inaccurate data; (c) Erase your data ("right to be forgotten"); (d) Restrict or object to processing; (e) Data portability; (f) Withdraw consent at any time. To exercise these rights, use our contact form and select "General Inquiry".

9. Cookies

The platform uses essential cookies for authentication and session management. Analytics cookies may be used to understand usage patterns. Non-essential cookies require explicit consent and can be managed through your browser settings.

10. International Transfers

Data may be transferred to and processed in countries outside your jurisdiction. Where this occurs, we ensure appropriate safeguards are in place, such as Standard Contractual Clauses (SCCs) approved by the European Commission.

11. Contact

For privacy inquiries or to exercise your data protection rights, reach out via our contact form. You also have the right to lodge a complaint with your local data protection authority.