Privacy Policy

Five questions, answered in the order people actually ask them.

Last updated: August 2026

Who holds my data?

Whoever operates this website acts as data controller. A joint controller, other brands inside the same business group and a parent company process parts of it as well. There is a Data Protection Officer in post, reachable on dpo@lizaro.com. The General Data Protection Regulation is the framework everything below sits inside.

What exactly is collected?

GroupWhat it covers
Registrationname, date of birth, email address, phone number, country, account currency
Due diligenceidentity card, driving licence or passport number, proof of address, social security number, source of wealth and funds, bank ID, financial statements
Transactionsdeposits, withdrawals, payment routes, references, balances
Behaviourlogin times, device and browser, IP address, pages and games opened

Most of it comes from you. The due diligence set does not stop there: public and government databases, internet and social media sources, commercially available databases, financial and credit institutions, fraud prevention agencies and public authorities all feed into it where the law requires that depth of check.

Why is it held?

To open and run the account. To verify age and identity. To meet anti-money laundering obligations under the 5th AML Amendment. To process money and keep the records the law requires. To detect fraud and keep the site standing up. Nothing on that list is optional for us, which is why an account cannot be run without it.

Who else sees it?

Authorised employees. Brands within the same entity or operator. Contractors, agents, joint controllers, affiliates and subsidiaries. Third-party providers running parts of the platform. Whichever law enforcement, regulatory and licensing authorities have a right to ask.

And one rule that deserves to be stated rather than buried in that list: if you submit a complaint or a review about us to a third-party platform — a casino review site, a gambling forum, a dispute resolution body — we may disclose personal data to that platform, limited to what identifies the account, on the basis of our legitimate interest in protecting our business reputation.

How long, and what can I ask for?

Data stays for the life of the account, then gets deleted or anonymised once no legal or business need remains. Anti-money laundering rules and other regulation extend that where they apply, and there the retention clock belongs to the rule rather than to us.

Your rights: access, correction, erasure where nothing requires us to keep it, restriction, objection, portability, and withdrawal of a consent you gave earlier without that affecting anything done before. Send any of them to dpo@lizaro.com from the registered address. You may also complain to the supervisory authority where you live, where you work, or where you believe an infringement happened.

Security and cookies

Traffic runs over SSL and access to due diligence records is limited to staff whose work requires it. At your end the account is yours to protect: anything done with the correct email and password counts as done by you, so a password reused from another site is the weakest link in the chain.

Cookies come in four categories. Essential ones keep sessions and security working and cannot be switched off. Functional ones remember preferences. Performance ones measure how pages get used. Targeting ones support advertising. The last two run on consent, and a Cookie Settings panel with Accept all, Decline all and Save & Close sits on every page.

← Back to the homepage