
This policy explains what personal data the operator collects, why it collects it, how long it keeps it and what rights you hold under the General Data Protection Regulation and the Bundesdatenschutzgesetz. It applies to account holders, visitors and anyone contacting support. Processing takes place in accordance with Article 13 and Article 14 GDPR, and nothing here reduces rights that statute grants you.
1. Controller and Data Protection Officer
Responsibility for processing rests with the operating company named in the site imprint.
- 1.1 Controller: the licensed operating company behind the MobilePay official site, whose registered address and commercial register entry appear in the Impressum.
- 1.2 Data protection officer: reachable at the postal address in the Impressum, marked for the attention of the Datenschutzbeauftragter, or at help@mobileplay.com.
- 1.3 Supervisory authority: the competent Landesdatenschutzbehörde for the operator's registered seat.
- 1.4 Scope: this policy covers the website, the mobile browser interface and any payment confirmation step routed through a connected application.
2. Categories of Data Collected
Data reaches the operator in three ways: you supply it, your device transmits it automatically, or a payment provider returns it.
Confirmation steps completed inside the MobilePay app generate transaction metadata that flows back to the operator, and the table below sets out what each category covers.
3. Purposes and Legal Bases
At MobilePay official site, each processing operation rests on a defined legal basis, and none happens without one.
- 3.1 Contract performance (Art. 6(1)(b) GDPR): opening and running your account, crediting deposits, executing withdrawals, awarding loyalty points and handling support requests.
- 3.2 Legal obligation (Art. 6(1)(c) GDPR): age verification, identity checks, anti-money-laundering duties, source-of-funds enquiries, tax records and enforcement of statutory deposit ceilings.
- 3.3 Legitimate interests (Art. 6(1)(f) GDPR): fraud prevention, detection of duplicate accounts, bonus abuse monitoring, network security and improvement of the MobilePay site.
- 3.4 Consent (Art. 6(1)(a) GDPR): marketing emails, promotional messages and non-essential cookies, withdrawable at any point with effect for the future.
- 3.5 Vital and public interests (Art. 6(1)(d) and (e) GDPR): player protection measures, including intervention where risk indicators appear.
4. Automated Decisions and Profiling
Some checks run without human involvement, and you deserve a clear statement of which.
- 4.1 Risk scoring: transaction patterns generate automated indicators that may restrict deposits, even where you attempt to deposit again.
- 4.2 Limit enforcement: self-imposed caps register at payment level as well as operator level, so an automated block applies if you switch methods.
- 4.3 Verification triage: document checks may route automatically, with higher loyalty tiers receiving accelerated processing.
- 4.4 Human review: you may request human intervention, express your view and contest any automated outcome under Art. 22(3) GDPR.
5. Recipients and Transfers
Data leaves the operator only where a purpose above requires it, and every recipient works under a contract satisfying Art. 28 GDPR. The MobilePay official site discloses the following categories of recipient.
- 5.1 Payment providers: transaction data, sufficient to settle deposits and return funds to the originating instrument.
- 5.2 Game suppliers: session data needed to run the titles you open, without registration details.
- 5.3 Verification services: identity and address data for document checks.
- 5.4 Regulatory authorities: data required under gambling and anti-money-laundering law, disclosed on lawful request.
- 5.5 IT and hosting providers: technical data under processing agreements.
- 5.6 Third countries: transfers outside the EEA occur only under standard contractual clauses or an adequacy decision.
6. Retention Periods
At MobilePay official site, nothing is kept indefinitely, and deletion follows automatically once the relevant period expires.
7. Cookies and Tracking
The MobilePay app confirmation flow sets no advertising identifiers, and cookie handling on the website follows §25 TTDSG.
- 7.1 Essential cookies: session management, login state and security, set without consent as they are technically necessary.
- 7.2 Functional cookies: language preference, favourites tab, lobby filter settings.
- 7.3 Analytical cookies: aggregated usage measurement, set only after consent.
- 7.4 Marketing cookies: set only after explicit opt-in through the consent banner.
- 7.5 Withdrawal: you may change cookie settings at any time through the banner link in the site footer.
8. Your Rights
At MobilePay official site, you hold the following rights and may exercise any of them free of charge, with a response due within one month.
- 8.1 Access (Art. 15): obtain confirmation of processing and a copy of your data.
- 8.2 Rectification (Art. 16): correct inaccurate or incomplete records.
- 8.3 Erasure (Art. 17): request deletion, subject to statutory retention duties that override it.
- 8.4 Restriction (Art. 18): limit processing while a dispute over accuracy or lawfulness runs.
- 8.5 Portability (Art. 20): receive data you supplied in a structured, machine-readable format.
- 8.6 Objection (Art. 21): object to processing based on legitimate interests, including profiling.
- 8.7 Withdrawal of consent (Art. 7(3)): stop consent-based processing at any point, without effect on past lawfulness.
- 8.8 Complaint (Art. 77): lodge a complaint with a supervisory authority in your place of residence or work.
9. Security Measures
Technical and organisational measures under Art. 32 GDPR protect the data held on the MobilePay site, and the list below covers the principal ones.
- 9.1 Encryption: transport encryption across all connections and encryption at rest for identification documents.
- 9.2 Access control: role-based permissions, with document access limited to verification staff.
- 9.3 Authentication: payment confirmation by fingerprint or code inside the payment application, removing the need to enter card details on a device keyboard.
- 9.4 Monitoring: logging of access to sensitive records and automated alerts on irregular patterns.
- 9.5 Breach notification: notification to the supervisory authority within 72 hours and to affected persons where a high risk arises.
10. Data Provision and Consequences of Refusal
Some data you must supply, and the effect of withholding it differs by category.
- 10.1 Mandatory for contract: registration details, without which no account can open.
- 10.2 Mandatory by law: identity and address documents, without which no withdrawal can clear.
- 10.3 Optional: marketing preferences, refusal of which affects nothing beyond receiving offers.
- 10.4 Consequence: failure to provide requested verification documents within thirty days may lead to account closure and return of deposits.
11. Minors
No MobilePay official site account may be opened by anyone under 18, and the operator processes no data knowingly relating to minors. Where evidence of an underage account emerges, the account closes, gameplay is voided and the data is deleted save where retention law requires otherwise. Parents or guardians who suspect that a minor has registered should contact help@mobileplay.com immediately.
12. Changes to This Policy
This policy may change where law, technology or processing purposes change. The operator publishes each revision here with an updated version date, and notifies registered users by email at least seven days before material changes take effect. Continued use after that date constitutes acknowledgement of the revised version.