Privacy Policy
This privacy policy explains how lucky-nugget-casino-new-zealand, operating via lucky-nugget-nz.com, collects, uses, stores, and protects your personal data. The policy applies to all players and website visitors in New Zealand who use our services or interact with our website. Effective as of 6 November 2025, this document outlines your rights and our obligations under New Zealand law and international standards.
Who We Are
OBSERVE: Our legal operator is Bayton Ltd, with headquarters at Villa Seminia, 8, Sir Temi Zammit Avenue, Ta' Xbiex XBX 1011, Malta. For New Zealand and international operations, Baytree Interactive Limited also acts as an operator, regulated under the Malta Gaming Authority (MGA/B2C/145/2007) and Kahnawake Gaming Commission (00892). lucky-nugget-casino-new-zealand is a brand of Super Group (SGHC) Limited, with support channels through lucky-nugget-nz.com.
- Legal Address: Villa Seminia, 8, Sir Temi Zammit Avenue, Ta' Xbiex XBX 1011, Malta
- Contact Email (Support/Data Protection): support@lucky-nugget-nz.com
- Website: https://lucky-nugget-nz.com
- Data Protection Officer: Finn Gallagher (Contact via above email)
- Licensing: Malta Gaming Authority (MGA/B2C/145/2007), Kahnawake Gaming Commission (00892)
REFLECT: All data processing is managed by Bayton Ltd and Baytree Interactive Limited as data controllers, in strict accordance with NZ and international privacy regulations.
What Personal Data We Collect
OBSERVE: We collect information necessary for providing regulated online gambling services. Data categories include:
- Personal Data: Full name, date of birth, email address, phone numbers, residential address, identity documentation.
- Technical Data: IP address, device identifiers, browser type, operating system, access logs, connection times.
- Payment Data: Bank account details, credit/debit card numbers (tokenized), electronic wallet information, transaction records.
- Behavioral Data: Game and betting history, deposit and withdrawal activity, session logs, clickstream data.
- Cookies & Similar Technologies: Session cookies, persistent cookies, third-party analytics and advertising cookies, device fingerprinting identifiers.
EXPAND: Such data is collected directly from users, automatically via our platform, or through trusted partners when required for compliance or service delivery.
REFLECT: Collection is limited to what is necessary for lawful purposes, regulatory compliance, and user experience enhancement.
Legal Basis for Processing
OBSERVE: Our processing of your personal data is justified under the following legal bases:
- User Consent: Explicit consent is obtained for marketing, cookies, and certain data transfers; you may withdraw at any time.
- Contract Fulfillment: Data processing required to open, maintain, and operate your account, process transactions, and deliver gaming services.
- Legal Obligations: Compliance with anti-money laundering (AML), know-your-customer (KYC), tax, and regulatory reporting requirements under NZ and international law.
- Legitimate Interests: Protecting service integrity, fraud prevention, IT security, service analytics, and direct communications (within legal limits).
REFLECT: We ensure that no data is processed without a valid, documented legal basis, and regularly review these bases for ongoing compliance.
Purpose of Processing
OBSERVE: Your data is processed strictly for business and compliance reasons:
- Service Provision: To enable account creation, identity verification, secure access, payment processing, and withdrawal facilitation.
- Service Improvement: Analysis and enhancement of platform performance, customer experience, and product features.
- Marketing Communications: With your consent, to send offers, promotions, and updates relevant to lucky-nugget-casino-new-zealand via lucky-nugget-nz.com.
- Analytics & Reporting: Internal analytics, regulatory submissions, and reporting to authorities as required.
- Fraud & Security: Detection, investigation, and prevention of fraud, abuse, or illegal activities.
REFLECT: Data is never used for automated decision-making without human review, and is not sold to third parties.
Disclosure & Sharing
OBSERVE: Data may be disclosed only under strict conditions and only to:
- Payment Partners: Banks, payment processors, and financial intermediaries for transaction completion.
- Service Providers: IT hosting, customer support, identity verification, analytics, and marketing vendors under binding confidentiality agreements.
- Regulators & Law Enforcement: Malta Gaming Authority, Kahnawake Gaming Commission, NZ authorities, or other competent bodies as lawfully required.
- Affiliates: Super Group (SGHC) Limited subsidiaries for service management and regulatory compliance.
- Advertising Networks: Only with explicit consent, and subject to your preferences.
EXPAND: All third parties are required to process data in accordance with contractual, legal, and technical safeguards.
REFLECT: No data will be shared for secondary purposes without your informed consent.
International Transfers
OBSERVE: Due to the global nature of our operations, your data may be transferred to, and processed in, countries outside New Zealand, including Malta, Canada (Kahnawake), and Guernsey.
- Protection Measures: Transfers are protected by standard contractual clauses (SCCs), adherence to adequacy decisions, and binding corporate rules in line with international standards.
- Third Country Transfers: Where required, we ensure additional technical and organizational safeguards, including encryption and access controls.
REFLECT: All international transfers comply with NZ Privacy Act 2020 and relevant EU/UK data protection frameworks, ensuring your rights are maintained regardless of processing location.
Data Retention
OBSERVE: We retain personal data only as long as necessary for the purposes outlined, or as required by law and regulation:
- Account Data: Retained for the duration of your active account, and for up to 5 years after closure to comply with AML/KYC obligations (as of 2025).
- Transactional Data: Retained for 7 years for tax and regulatory record-keeping.
- Marketing Data: Retained until consent is withdrawn or for up to 2 years of inactivity.
- Cookies and Device Data: Retention periods vary by cookie type (see Cookies section).
EXPAND: Data is securely deleted or anonymized once retention periods expire, unless further retention is legally justified.
REFLECT: You may request earlier deletion of data, subject to overriding legal requirements.
Your Rights
OBSERVE: Under the NZ Privacy Act 2020 and aligned with GDPR standards, you have the following rights:
- Access: Request a copy of personal data we hold about you.
- Rectification: Correct inaccurate or incomplete data.
- Erasure: Request deletion of your data (subject to regulatory retention periods).
- Restriction: Restrict processing where legally justified.
- Objection: Object to certain processing, including direct marketing.
- Data Portability: Receive your data in a structured, commonly used, machine-readable format, or have it transferred to another provider.
- Withdrawal of Consent: Revoke consent for marketing or non-essential processing at any time.
- How to Exercise Rights: Contact us via support@lucky-nugget-nz.com or our contact form. We will respond within 30 days, free of charge, unless requests are manifestly unfounded or excessive.
REFLECT: All requests are handled according to NZ law, with additional protections applied as required by international standards.
Cookies & Tracking Technologies
OBSERVE: We use different types of cookies and tracking technologies on lucky-nugget-nz.com:
- Session Cookies: Essential for site operation and user authentication; deleted when you close your browser.
- Persistent Cookies: Remember preferences and login status for up to 12 months.
- Third-Party Cookies: Analytics (e.g., Google Analytics), advertising networks, and social media integrations.
EXPAND: Cookies support service delivery, analytics, personalization, and targeted advertising (with consent).
- Cookie Management: You can manage or disable cookies via your browser settings or our cookie management panel. Disabling some cookies may affect site functionality.
REFLECT: Full details are available in our Cookie Policy.
Data Security
OBSERVE: We implement industry-leading security controls to protect your data:
- Encryption: TLS 1.2+ for data in transit; AES-256 encryption for data at rest.
- Access Controls: Multi-factor authentication for staff, strict role-based access, and regular access reviews.
- Security Audits: Annual penetration testing, eCOGRA and independent audits, and continuous vulnerability assessments.
- Staff Training: Mandatory data protection and security training programs for all employees.
- Incident Response: Formal incident management procedures, with notifications to users and regulators as required by law.
- Compliance: Alignment with ISO 27001, SOC 2, and eCOGRA Safe and Fair certification standards.
REFLECT: We regularly review and update security measures to counter evolving risks and ensure ongoing compliance.
Complaints & Contacts
OBSERVE: If you have privacy concerns, you may:
- Contact our DPO: Email support@lucky-nugget-nz.com or use the online contact form. Please provide details of your concern or request.
- Escalate via eCOGRA: Submit a dispute at ecogra.org/srs/dispute.php if your complaint relates to game fairness or unresolved data issues.
- Regulatory Authority: If unsatisfied, you may contact the NZ Privacy Commissioner (https://privacy.org.nz/contact-us/) or the Office of the Maltese Information and Data Protection Commissioner (https://idpc.org.mt/contact/).
- Response Time: We acknowledge complaints within 5 working days and aim for full resolution within 30 days.
REFLECT: You are entitled to escalate complaints to supervisory authorities at any time.
Updates
OBSERVE: We may update this privacy policy to reflect changes in law, business practices, or platform technology. Material changes will be communicated through:
- Email Notifications: Sent to registered users at least 30 days before changes take effect.
- Website Banners: Prominent alerts on lucky-nugget-nz.com homepage.
- Account Dashboard Alerts: Notifications upon login.
REFLECT: The current version is always available on lucky-nugget-nz.com/privacy. Users may object or close their account if they do not accept material changes. Last updated: 6 November 2025. Any significant updates will include a summary of changes (changelog) within the policy document.