Privacy Policy: What Is Collected, Why, and What You Can Do About It
This policy sets out what personal information is collected when you use this site and hold an account with LEON Casino, why each piece is needed, who else can see it, how long it stays on file and which rights you hold over it. For players in Australia the reference framework is the Privacy Act 1988 (Cth) and the thirteen Australian Privacy Principles it contains, and this document follows that structure rather than paraphrasing it loosely.
It is written to be used. Each right below is paired with the mechanism for using it, and each statement about protection names the measure behind it. The platform is for adults aged 18 and over only.
The Starting Position
A real-money gambling account cannot exist without sensitive information changing hands. Identity documents, payment details and a record of what you played are structural requirements, not preferences, so the honest framing is this: what the service and the law require is collected, none of it is sold, and anything optional is labelled as optional.
Where you have a genuine choice, marketing above all, it is yours and it is reversible in a click. Where no choice exists, identity verification being the clear case, this policy says so rather than dressing an obligation up as a benefit.
What Is Collected
The information falls into six groups, and it helps to see them separately because they carry different rules:
- Identity information. Full name, date of birth, residential address and the documents supplied for verification, such as an Australian driver licence or a passport.
- Contact information. Email address and phone number, used for account notices, security alerts and, only with consent, promotional messages.
- Payment information. The method used, deposits and withdrawals, and balance history. Full card numbers are handled by the payment processors themselves and are not stored on the platform.
- Verification records. Results of the identity, age and source-of-wealth checks required under anti-money-laundering obligations, together with the documents uploaded for them.
- Technical information. IP address, approximate location derived from it, device type, operating system and browser, all captured automatically when you connect.
- Activity information. Games opened, bets placed, session start and end times, pages viewed and the responsible gambling settings applied to the account.
Why Each Group Is Collected
Different information rests on a different basis, and the distinction is the practical one: it decides what you can decline without losing the service.
- To operate the account. Identity, contact and payment information exist to open the account, process deposits, pay out withdrawals and keep a record you can audit. Without them there is no account to run.
- To meet legal obligations. Verification records and transaction histories are collected because anti-money-laundering and counter-terrorism financing rules attached to the operating licence require them. Consent is not involved, and these cannot be opted out of while the account is open.
- With your consent. Promotional email, SMS and push notifications go out only if you say yes, and that consent can be pulled back whenever you like, from the communication preferences screen or the opt-out link carried by every message. Declining marketing changes nothing about playing, depositing or withdrawing.
- For legitimate business interests. Technical and activity information supports fraud detection, bonus-abuse checks, security monitoring and improvement of the site itself.
The line to carry away: verification is mandatory, marketing is optional, and the two are never traded against each other.
Who Else Sees It
Your information is not sold, rented or handed to unrelated companies for their own marketing. It is disclosed only where running the service or complying with the law requires it, and each recipient receives the minimum its role needs:
- Payment providers, including the processors behind Visa, Mastercard and Skrill, to move funds in and out of the account.
- Verification agencies, to confirm identity, age and address against independent sources.
- Game studios, among them Pragmatic Play, NetEnt, Play'n GO and Evolution, which get the technical session data a game needs to run and nothing that identifies you personally.
- The licensing authority, and law enforcement, where a valid legal demand, an active investigation or a condition of the licence compels disclosure.
- Technical service providers, such as hosting and email delivery, bound by contract to confidentiality and to using the data only for the task given to them.
Be clear-eyed about this one. The operator is based outside Australia, so your information is processed offshore: it is stored and handled where Bluewave Interactive N.V. . and its service providers run their systems, which includes jurisdictions outside this country.
Australian Privacy Principle 8 deals with exactly this situation. It requires that information disclosed overseas remains subject to protections comparable to those the Act sets, and the contracts binding the processors named above impose the same confidentiality, security and purpose limits this policy sets out, wherever the servers physically sit. What that does not do is place an offshore processor under the direct supervision of an Australian regulator, and no policy wording could. Knowing where your data goes is part of deciding whether to open an account.
Your Rights Under the Privacy Act 1988
Four rights matter in practice, and each has a route:
- Access. You may request a copy of what is on file about you, the right set out in Australian Privacy Principle 12. Send the request through the privacy contact route described at the end of this page. Expect an acknowledgement, an identity check before anything is released, and a response within a reasonable period.
- Correction. If something on file is wrong, outdated or incomplete, Australian Privacy Principle 13 gives you the right to have it fixed. Address, phone number and communication settings can be corrected directly in account settings; anything tied to verified identity documents needs a request, because changing it changes the verification.
- Deletion. You may ask for your data to be erased when you close the account, and here honesty is required. Deletion applies to everything no legal obligation forces the operator to keep. Verification and transaction records sit under mandatory retention and are removed only once that period ends. A deletion request therefore means exactly this: erase everything not pinned down by law today, and the remainder as each retention clock runs out. A policy promising more would be promising what it cannot deliver.
- Withdrawing marketing consent. Use the opt-out link at the foot of any message, or flip the switch in your communication preferences. It applies unconditionally and touches nothing else about the account.
If a request is refused, mishandled or ignored, raise it first through the privacy contact route below, since most problems are administrative. If it stays unresolved, the Office of the Australian Information Commissioner accepts privacy complaints from individuals and publishes the process for making one on its site. Note the limit of what that means here: the OAIC is the avenue you can use, and this is not a claim that an offshore operator falls under its supervision.
How Long Records Stay
Retention is driven by obligation rather than convenience:
- Verification and transaction records are kept for the minimum period the operator's anti-money-laundering obligations impose, which is counted in years after an account closes rather than months. The exact minimum follows from the licence conditions and is confirmed on request.
- Account and contact details are held while the account is open and removed once no legal basis for keeping them remains.
- Marketing consents and preferences are kept only until you withdraw them, plus a short record that you did so, which is what stops a withdrawn consent being quietly reinstated.
- Technical logs are kept for the shorter periods security monitoring needs, then rotated out.
Cookies and Tracking, in Short
The site uses strictly necessary cookies to keep sessions secure, performance cookies to find faults, functionality cookies to remember preferences, and advertising cookies that run only with consent. You can refuse the non-essential categories when the banner first appears and change your mind later. Our cookie policy sets out each category, the lifespans involved and the browser-level controls in full detail.
How It Is Protected
Specifics rather than adjectives. Traffic between your device and the platform is encrypted in transit with TLS. Stored records sit on access-controlled systems, with staff access limited to what a role requires. Card credentials are swapped for tokens by the processors that handle them, which is how a refund can reach a card the platform itself cannot read.
Two things are in your hands. Two-factor authentication is available on the account and is worth switching on today, since it means a stolen password on its own opens nothing. Give this site a password you use nowhere else, and never pass a one-time code to another person. Staff will not ask for your password or a code, in chat or by email, so any message that does is not from LEON Casino.
Nobody Under 18
The platform is for adults. Registration is closed to anyone under 18, age is proven at verification rather than accepted from a tick box, and the operator does not knowingly hold personal information about minors. If a check at any stage shows the holder is underage, the account is shut, any winnings fall away under the terms of service, net deposits are handled as those terms set out, and the personal information collected is deleted subject only to the retention duties above. If you believe a minor has registered using your device or details, contact support immediately.
Making a Privacy Request
A privacy request should not require detective work. Use live chat while signed in, or write to the support address published in the footer of the operator's site, and ask for the request to be routed to the data protection officer. State what you want, access, correction, deletion or an end to marketing, and the email address on the account, since identity has to be confirmed before anything is released or changed. Requests are confirmed when they land and dealt with inside the periods the Privacy Act allows for the rights above.
Changes to This Policy
This policy is reviewed when the law changes, when the platform changes, or when a new processor is engaged. The version published on this page is always the current one, and the effective date is shown with it. Material changes are notified in the account rather than left to be noticed, and continuing to use leon casino australia after a change takes effect means the revised version applies to you.