Privacy Policy
What personal data Softico collects, why we hold it, who processes it for us, and the rights you have over it.
1. Who controls your data
The operating entity named in the site footer is the data controller for everything described here. Questions, requests and complaints go to privacy@softico.app; a named data protection officer is appointed as part of the licensing process and will be listed here.
2. What we collect
- Account data
- Email address, password hash (argon2id — we never see the password), display name, referral code, two-factor secret (encrypted), language and currency preferences.
- Identity data
- Verification status, level and result. The documents and selfies themselves are collected and stored by our verification provider, not by us; we hold the outcome and the reference.
- Financial data
- Deposit and withdrawal addresses, transaction hashes, amounts, and every ledger entry that makes up your balance. We take no card details.
- Gameplay data
- Every bet, its stake, its outcome, the seeds and nonce that produced it, and the game it belonged to. This is what makes provable fairness possible, and it is also our evidence in a dispute.
- Technical data
- IP address, user agent, device fingerprint, session and login history, and the security events attached to them.
- Support data
- Messages you send us, and chat messages you post in public rooms.
We minimise deliberately. Data we do not need is data we do not collect: no card numbers, no identity documents on our own storage, no advertising identifiers.
3. Why we hold it
- To run your account
- Performance of the contract between us — authentication, balances, bets, payouts, support.
- To meet legal obligations
- Anti-money-laundering checks, sanctions screening, record keeping, and reporting where a regulator requires it.
- To keep the platform safe
- Our legitimate interest in preventing fraud, multi-accounting, bonus abuse, account takeover and collusion.
- To protect players
- Responsible-gaming limits, self-exclusion enforcement and, where indicators appear, a support contact.
- To send you marketing
- Consent only, and only until you withdraw it. Every message carries a one-click unsubscribe. Transactional email is not marketing and continues regardless.
4. Who processes data for us
We use a small number of sub-processors, each under a written agreement limiting them to our instructions:
- Identity verification
- Sumsub — collects and stores your identity documents; returns a status to us.
- Payments
- NOWPayments — processes cryptocurrency deposits and payouts.
- Game suppliers
- Aggregators and studios whose games run inside the game window; they receive a pseudonymous session, not your identity.
- Infrastructure
- Managed Postgres, Redis, object storage and CDN providers within the EU where the option exists.
- A transactional email provider for verification, security and receipt messages.
- Error and performance monitoring
- Application monitoring with personal fields redacted before they leave the process.
We do not sell personal data, and we do not share it with advertising networks.
5. How long we keep it
- Account, ledger and gameplay records: for the life of the account and then for the period the licensing jurisdiction requires — typically five years after closure, because they are the evidence behind every payout.
- IP addresses and raw device data: ninety days for security analysis, then anonymised.
- Identity verification records: as required by anti-money-laundering law, held primarily by the verification provider.
- Self-exclusion records: kept indefinitely. That is the only way an exclusion can be honoured if you try to register again.
- Support conversations: two years.
- Audit log entries: append-only and never deleted. Corrections are new entries, never edits.
6. How we protect it
- TLS 1.3 in transit; database encryption at rest; encrypted backups.
- Passwords hashed with argon2id; two-factor secrets encrypted with AES-256-GCM in a dedicated column.
- Session tokens are opaque, rotated on privilege change, and revocable per device from your account.
- Logs are redacted at source: no passwords, no tokens, no two-factor codes, ever.
- The audit log is append-only at the database privilege level, not merely by application convention.
- Admin access is role-based, two-factor gated, and every action is attributed to a named person.
No system is perfect. If a breach affects you and the law requires it, we will tell you and the relevant authority within the statutory window.
7. Your rights
- Access — a copy of the personal data we hold about you.
- Rectification — correction of anything inaccurate.
- Erasure — deletion, except where anti-money-laundering, accounting or self-exclusion obligations require us to keep a record.
- Portability — your account and transaction history in a machine-readable format.
- Objection and restriction — including to any processing based on our legitimate interests.
- Withdrawal of consent — for marketing, at any time, without affecting your account.
- Complaint — to your local supervisory authority, whether or not you have raised it with us first.
Write to privacy@softico.app. We answer within thirty days and will ask you to verify your identity first — otherwise the access right becomes an attack.
9. International transfers
Some processors operate outside your country. Where data leaves the European Economic Area we rely on an adequacy decision or on standard contractual clauses, and we prefer EU-hosted regions when a provider offers them.
10. Children
This service is for adults. We do not knowingly collect data about anyone under 18. If we learn that we have, we close the account, delete the data we are permitted to delete, and return any deposited funds to their source.
11. Changes
The date at the top of this page is the version in force. Material changes are announced by email and in-product before they take effect.