Last updated: 14 September 2023
The Bearo Casino privacy policy explains how personal information may be handled through bearo1.com and the website, account and services. The data controller is Bearo N.V. , a company incorporated under the laws of Curaçao with company number 162488, registered at Abraham de Veerstraat 9, Willemstad, Curaçao.
The categories and purposes below depend on which features are used. Additional privacy information may be provided for a particular payment, verification or communication process.
This policy applies when you visit the website. Where the relevant functions are enabled, it also applies when you create or use an account, contact support, use payment or verification features, take part in promotions or otherwise interact with the services.
Bearo Casino account data may include details entered in registration or profile forms, account identifiers, login records, preferences and information used to keep the account accurate and secure.
The registration fields, minimum age requirements and account information collected are:
Registration fields: email address, strong password, date of birth, country of residence, preferred currency, and optionally full name and phone number.
Minimum age: 18 years (or higher if required by your jurisdiction).
Additional account information: username, account ID, IP address at registration, language preference, communication consents, and security questions/answers if enabled.
We verify age at registration and may request further proof later. If you are under the legal age, your account will be closed and data deleted except for mandatory compliance records..
When you contact Bearo Casino, we may process your contact details, message content, relevant account references and records needed to respond, investigate an issue and maintain a service history.
Support channels, chat storage, call recording and communication retention are:
Live chat (24/7 on bearo1.com) and email support (support@bearo1.com).
Chat transcripts and email threads are stored on secure servers for 2 years after the ticket is closed, for quality and compliance purposes.
Calls are not routinely recorded, but if a callback is arranged and recorded, you will be informed at the start of the call.
Do not send passwords or one-time security codes through support.
Where payment functions are enabled, Bearo Casino payment data may include payment-method identifiers, transaction amounts, currencies, timestamps, status information, account balances and references linked to deposits, withdrawals, reversals or disputes.
Payment providers and the division of responsibility between those providers and the controller are:
We integrate with third-party payment service providers, including (but not limited to) Skrill, Neteller, MiFinity, Payz, AstroPay, Bank Transfer solutions, and cryptocurrency payment gateways (such as CoinsPaid).
For Bearo Casino transactions, the provider processes your full payment details (card number, crypto wallet address, etc.) on its secure PCI-DSS compliant platform. We do not store complete card numbers, CVV codes or crypto private keys.
We receive a token, transaction reference, amount, and status to credit your account.
Responsibility for data handling at the payment stage lies with the respective provider; we are the controller for the transactional records once received.
Full payment credentials should be entered only through the designated secure payment process.
Where verification is required, Bearo Casino verification data may include identity, age, address, location, payment ownership, source-of-funds or related compliance material, together with the outcome and history of the review.
Verification providers, document types and review procedures are:
We use Sumsub (Sum and Substance Ltd) and its secure portal to collect and verify documents.
Documents requested may include: government-issued photo ID (passport, driving licence, national ID card), recent utility bill or bank statement for address proof, a selfie with ID document, payment method screenshots (showing ownership), and source-of-funds or wealth documentation (e.g., payslip, tax return).
Bearo Casino verification may combine automated checks with manual review by the trained compliance team. Outcomes are stored for 5 years after account closure for audit and anti-money laundering requirements.
Sumsub acts as a processor and is contractually bound to security and confidentiality standards.
Use of the Bearo Casino website and services may generate internet protocol addresses, browser and device details, language settings, requested pages, timestamps, referring information, session identifiers and security events.
The hosting, logging and security configuration is:
The bearo1.com infrastructure is hosted on Amazon Web Services (AWS) in data centres located in Frankfurt, Germany.
Server logs (including IP, user agent, timestamps) are collected for security monitoring and debugging. These logs are retained for 12 months.
All web traffic is encrypted via TLS 1.3.
We use Cloudflare for DDoS mitigation and content delivery, which may process limited technical data at edge locations globally.
Depending on the technologies used, Bearo Casino cookies or similar storage may support essential website functions, security, preferences, measurement or other disclosed purposes.
Cookie categories, consent controls, analytics tools and advertising technologies are:
Essential cookies: session ID, CSRF token, cookie consent status. Necessary for the site to function.
Preferences: language, currency, display settings (1 year persistence).
Bearo Casino analytics and performance tools include Google Analytics 4 (with IP anonymisation enabled) and Hotjar heatmaps (session recordings only for logged-in pages with sensitive fields masked).
Marketing: pixels for Facebook, Twitter, and Google Ads may be placed only when you land on the site via a campaign link and you have accepted marketing cookies. No third-party ad networks serve retargeting ads based on gambling activity.
A cookie consent banner (provided by CookieYes) appears on your first visit, allowing you to accept or reject non-essential cookies. Your choice is saved for 12 months.
Where a cookie notice or consent interface is used, it will provide the applicable choices.
Bearo Casino may use account, transaction, device and behavioural information to protect credentials, detect unusual activity, investigate prohibited conduct and prevent fraud or technical abuse.
Automated detection tools, risk providers and any resulting decision process are:
We deploy SEON Fraud Prevention for real-time digital footprint analysis, device fingerprinting, and transaction monitoring.
The Bearo Casino in-house rules engine flags patterns such as: multiple accounts from same IP, rapid deposit/withdrawal attempts, contradictory geo-location, and bot-like behaviour.
Automated decisions that have legal or significant effects (e.g., account restriction) are reviewed by a human within 24 hours. You have the right to contest such decisions by contacting privacy@bearo1.com.
Any fraud data related to known scammers or carders may be shared with authorised industry bodies (e.g., ETHoca, Cifas equivalent) when legally justified.
Bearo Casino personal data may be used to provide and secure the website and services, create and administer accounts, process enabled transactions, respond to communications, conduct required verification, operate promotions, prevent misuse, keep records and meet legal obligations.
Marketing, personalisation or profiling will apply only where those activities are enabled and described through the relevant notice or preference control. The configuration for those activities is:
Bearo Casino direct marketing by email or SMS is only sent if you have opted in. You can withdraw consent at any time via account settings or the unsubscribe link.
On-site personalisation: game recommendations based on your play history (no automated profiling with legal effect). You can disable personalisation in account preferences.
Profiling for risk and AML: transaction patterns and affordability checks are used to assign risk categories (low, medium, high) for AML and responsible gambling interventions. This is a legal requirement and cannot be opted out of.
No fully automated individual decision-making is used to deny service without human involvement.
The lawful bases used by Bearo Casino for each purpose are as follows:
Performance of a contract (account service, payment processing): creating and managing your account, processing deposits and withdrawals, providing games, applying Terms.
Bearo Casino may process data to meet legal obligations such as identity verification, anti-money laundering checks, responsible gambling interventions, record-keeping for tax or gaming regulation, and disclosure to authorities.
Legitimate interests: ensuring network and information security, fraud prevention, direct marketing (where soft opt-in or legitimate interest applies under applicable e-privacy law), service improvement analytics, and internal reporting. We have balanced these interests against your rights and freedoms.
Consent: non-essential cookies, marketing emails/SMS where required by law, special category data (if ever requested). Consent may be withdrawn at any time through the relevant preference centre or by contacting us, without affecting processing already carried out lawfully.
Bearo Casino may share information with service providers supporting hosting, security, communications, payments, verification, games, professional advice or other enabled functions, and with public authorities where disclosure is legally required.
The payment providers, verification providers and other material recipients are:
Bearo Casino payment processors may include Skrill (Paysafe Group), Neteller, MiFinity, AstroPay, CoinsPaid, and relevant banking intermediaries.
Verification provider: Sumsub (Sum and Substance Ltd).
Cloud hosting & CDN: Amazon Web Services (Germany), Cloudflare.
Communications: SendGrid (email delivery), tawk.to (live chat platform).
Analytics & marketing tools: Google Analytics, Hotjar, Facebook, Twitter, Google Ads (only when consent is given).
Fraud prevention: SEON Technologies Ltd.
Bearo Casino game services are operated by third-party studios (e.g., NetEnt, Pragmatic Play, Evolution Gaming), which may receive your user ID and game session data for functionality, but they do not receive your payment details.
Professional advisors: auditors, legal counsel, and compliance consultants bound by confidentiality.
Regulators and law enforcement: Curaçao Gaming Control Board, financial intelligence units, police or courts upon valid legal request.
Where information is shared, it should be limited to what is needed for the provider’s role and handled under applicable contractual and legal safeguards.
Bearo Casino international transfers may occur where information is moved across borders.
The destinations, transfer mechanism and safeguards are:
Curaçao: as operator, data is processed in Curaçao which is considered to have an adequate level of protection for EU data subjects by virtue of its association with the Netherlands (European Netherlands).
European Economic Area (EEA): Bearo Casino primary servers are in Frankfurt (AWS eu-central-1). Data stays within the EEA for core hosting.
United Kingdom: if you are a UK resident, transfers to the UK are covered by the EU adequacy decision for the UK.
Other countries (e.g., for fraud prevention, analytics, or non-EEA provider sub-processors): we rely on European Commission Standard Contractual Clauses (SCCs) incorporated into Data Processing Agreements, supplemented by technical measures such as encryption and pseudonymisation where necessary.
You can request a copy of relevant safeguards via privacy@bearo1.com.
The applicable Bearo Casino data retention periods are:
Bearo Casino account and profile data is retained for the life of the account plus 5 years after closure, to handle disputes and comply with Curaçao gaming record-keeping rules.
Transaction records (deposits, bets, withdrawals): 5 years from the transaction date.
Verification documents: 5 years after the last use of the account (AML requirement).
Support communications: 2 years after ticket resolution.
Server and access logs: 12 months.
Marketing consent records: indefinitely (to prove consent), but marketing profiles deleted upon withdrawal of consent.
Cookie data: as per the consent manager, typically up to 12 months for analytics, session cookies expire at the end of session.
Anonymised data may be kept indefinitely. After the retention period, data is securely deleted or irreversibly anonymised.
Bearo Casino uses security measures to protect information against unauthorised access, loss, alteration or disclosure:
Encryption in transit: TLS 1.3 across the entire platform.
Encryption at rest: AES-256 encryption for databases and backup storage.
Access controls: role-based access with multi-factor authentication for employees; strict least-privilege policy.
Bearo Casino security controls include annual penetration testing by an independent security firm, vulnerability scans, and compliance audits (PCI DSS for payment token handling).
Staff training: all personnel with access to personal data receive privacy and security training.
Physical security: cloud infrastructure secured by AWS data centre certifications (ISO 27001, SOC 1/2/3).
No online system guarantees absolute security. Use a strong password, protect access codes and contact us promptly if you suspect unauthorised account activity.
The Bearo Casino privacy rights available to you and the procedure for exercising them are:
Depending on the applicable framework, you may have the following rights regarding your personal data:
Access: request a copy of the information we hold about you.
Correction: ask us to correct inaccurate or incomplete data.
Deletion (right to be forgotten): request erasure where there is no compelling reason to retain it.
Restriction: ask us to limit processing in certain circumstances.
Portability: receive your provided data in a structured, machine-readable format.
Objection: object to processing based on legitimate interests (including profiling) or for direct marketing.
Withdrawal of consent: where processing is based on consent, you can withdraw it at any time.
For a Bearo Casino privacy request, submit your request via email to privacy@bearo1.com from your registered email address. We may request additional verification to confirm your identity. We will respond within 30 calendar days, which may be extended to 90 days in complex cases (we will inform you of any extension).
You may also have the right to lodge a complaint with the Curaçao Gaming Control Board (for privacy matters within its regulatory mandate) or, if you are located in the EEA, with your local data protection supervisory authority. For the UK, contact the Information Commissioner’s Office (ICO). The primary supervisory authority for our processing is Curaçao Data Protection Authority, Pletterijweg 43, Willemstad, Curaçao (or its successor body).
Bearo Casino services are intended only for adults who meet the applicable minimum age. The minimum age and procedure for handling information about anyone below that age are:
Minimum age: 18, or the legal gambling age in your jurisdiction if higher.
Bearo Casino verifies date of birth at registration and via verification checks. If we discover that someone underage has registered, we immediately close the account, forfeit any winnings in line with our Terms, and delete all personal data except what must be kept to prevent re-registration (email/ID hash on a blocklist). Parents or guardians who suspect underage use should contact us immediately.
Bearo Casino may update this policy when the services, processing activities or legal obligations change. The updated version and effective date will be published on the website, and material changes will be communicated where required.
The Bearo Casino privacy contact details are as follows:
Data controller: Bearo N.V.
Privacy contact: Data Protection Officer, Bearo N.V.
Email: privacy@bearo1.com
Registered address: Abraham de Veerstraat 9, Willemstad, Curaçao
Supervisory authority: Curaçao Data Protection Authority (contactable via the address above) or, for EEA residents, the supervisory authority in your country of residence.