Privacy Policy
This Privacy Policy explains how lucky-legends ("we", "us", "our"), operating exclusively via lucky-legends-ca.com, collects, uses, discloses, and protects your personal data. It applies to all players and visitors accessing our website and services. This policy is effective as of November 6, 2025, and remains in force until further notice.
Who We Are
Operator: lucky-legends, operated by Lucky Legends LLC, registered under company number 15804.
Registered Address: Hamchako Mutsamudu, The Autonomous Island of Anjouan, Union of Comoros.
Gambling License: Computer Gaming Licensing Act 007 of 2005; License No. 15804; State of Anjouan, Union of Comoros.
Contact for Data Protection: Data Protection Officer (DPO), Lucky Legends LLC
Email:
Website: https://lucky-legends-ca.com
What Personal Data We Collect
OBSERVE: In compliance with CA privacy requirements and industry standards, we collect the following categories of personal data to ensure service delivery, legal compliance, and player protection.
- Personal Data: Full name, date of birth, residential address, email address, phone number, identification documents (for verification).
- Technical Data: IP address, device information, browser type, operating system, connection times, log files, unique device identifiers.
- Payment Data: Bank account details, credit/debit card numbers (tokenized where possible), payment processor details, transaction history, withdrawal and deposit records.
- Behavioral Data: Betting and gaming history, transaction logs, account activity, clickstream data, session duration, responsible gambling interactions.
- Cookies and Tracking Technologies: Session cookies, persistent cookies, third-party analytics and advertising cookies, device fingerprinting where permitted.
EXPAND: Data is collected directly from you during account registration, gameplay, financial transactions, and via automated means (e.g., cookies) when you access lucky-legends-ca.com.
REFLECT: Collection of each data category is limited to what is necessary for the specified purposes, with protective measures in place to prevent unauthorized use.
Legal Basis for Processing
OBSERVE: We process your personal data in accordance with applicable CA regulations and recognized international privacy standards.
- User Consent: Data processing based on your explicit consent (e.g., for marketing communications, optional features). Consent can be withdrawn at any time.
- Contract Fulfillment: Processing necessary for the creation and management of your account, verification procedures, payments, and provision of gambling services.
- Legitimate Interests: Ensuring the security of our platform, fraud detection and prevention, analytical reporting, and service improvement, provided these interests are not overridden by your fundamental rights.
- Legal Obligations: Compliance with Know Your Customer (KYC), Anti-Money Laundering (AML), regulatory reporting, and tax requirements as mandated by law.
REFLECT: Where required by law, you will be informed of the specific legal basis for particular data processing activities and your rights to object or withdraw consent.
Purpose of Processing
OBSERVE: Personal data collected by lucky-legends via lucky-legends-ca.com is processed for the following legitimate purposes:
- Provision of Casino Services: To register, verify, and manage user accounts; process deposits and withdrawals; and facilitate participation in games.
- Service Improvement: To analyze usage patterns, identify platform issues, and enhance user experience.
- Marketing and Promotions: To send promotional emails or notifications (with consent) about offers, bonuses, and new features.
- Analytics: To generate statistical reports, monitor trends, and optimize site performance using aggregated, anonymized data where possible.
- Fraud Prevention and Security: To detect and prevent fraudulent activities, unauthorized access, and breaches of terms and conditions.
- Legal and Regulatory Compliance: To fulfill obligations under gambling, financial, and anti-fraud laws applicable in CA and relevant jurisdictions.
- Customer Support: To address inquiries, resolve disputes, and provide assistance.
REFLECT: Data is used only for the purposes outlined above or as permitted or required by law, with strict access controls and monitoring.
Disclosure & Sharing
OBSERVE: We may disclose or share your personal data with third parties only when necessary and in compliance with CA privacy laws and industry standards.
- Payment Service Providers: To process deposits, withdrawals, and verify financial transactions. Data shared is limited to what is required for transaction completion and anti-fraud checks.
- Technical Service Providers: Vendors supporting IT systems, hosting, security, data analytics, and customer support.
- Regulatory Authorities: To comply with legal obligations, respond to audits or investigations, and report suspicious activities (e.g., KYC/AML reporting).
- Affiliates and Marketing Partners: For joint promotions or advertising (only with your consent where required).
- Advertising Networks: Third-party networks may receive anonymized or pseudonymized data for analytics and advertising, subject to your cookie preferences and consent.
- Protective Clauses: All third parties are contractually bound to maintain confidentiality, use data solely for the intended purpose, and implement adequate security measures.
REFLECT: We do not sell your personal data. Disclosures are carefully controlled, and cross-border transfers are subject to additional protection (see next section).
International Transfers
OBSERVE: Your data may be transferred to and processed in countries outside CA, including the Union of Comoros and other jurisdictions where our technical providers operate.
- Standard Contractual Clauses (SCC): Transfers to countries lacking equivalent data protection laws are governed by SCCs approved by regulatory authorities, ensuring adequate safeguards.
- Additional Safeguards: Technical and organizational measures (encryption, access controls) are applied to all international data transfers.
- Service Provider Obligations: All third-party processors are contractually required to comply with applicable data protection standards.
REFLECT: You may request further information or copies of relevant safeguards by contacting our Data Protection Officer.
Regional Compliance Note: All cross-border transfers are structured to meet CA regulatory expectations for data export and privacy protection.
Data Retention
OBSERVE: We retain personal data only as long as necessary for the purposes for which it was collected, or as required by law.
- Account Data: Retained for the duration of your active account plus up to 5 years after account closure, in line with KYC/AML and regulatory requirements.
- Financial and Transaction Data: Retained for a minimum of 5 years after the date of the transaction, or longer if mandated by legal obligations.
- Marketing Data: Retained until you withdraw consent or unsubscribe from communications.
- Cookies and Technical Data: Retention periods vary by cookie type; see 'Cookies & Tracking Technologies' section for details.
Deletion Criteria: Data is permanently deleted or irreversibly anonymized when retention periods expire, upon your valid request (subject to legal exceptions), or when processing purposes are completed.
REFLECT: Secure deletion methods and audit trails are implemented to ensure compliance and accountability.
Your Rights
OBSERVE: In accordance with applicable privacy laws, including the General Data Protection Regulation (GDPR) and relevant Mexican data protection regulations, you are entitled to exercise the following rights regarding your personal information processed on lucky-legends-ca.com:
- Right of Access: Request confirmation of whether your data is being processed and obtain a copy of your personal data.
- Right to Rectification: Request correction of inaccurate or incomplete data held about you.
- Right to Erasure (Right to be Forgotten): Request deletion of your personal data where legally permitted, subject to overriding legal obligations (e.g., KYC/AML retention).
- Right to Restrict Processing: Request limitation of processing where you contest data accuracy, legality, or object to deletion.
- Right to Object: Object to processing based on legitimate interests or direct marketing at any time.
- Right to Data Portability: Request a copy of your data in a structured, commonly used, and machine-readable format and transmit it to another controller, where technically feasible.
- Right to Withdraw Consent: Withdraw consent for processing activities based on consent (e.g., marketing) at any time, without affecting the lawfulness of prior processing.
- Exercising Your Rights: Submit your request via our DPO contact (see Complaints & Contacts section). You will receive a response within 30 days, free of charge, unless requests are manifestly unfounded or excessive, in which case administrative fees may apply.
- Regional Note: Where relevant, the procedures align with Mexican Federal Law on the Protection of Personal Data Held by Private Parties (Ley Federal de Protección de Datos Personales en Posesión de los Particulares, LFPDPPP) and GDPR standards.
REFLECT: We may require verification of your identity before fulfilling your request to protect your privacy and security.
Cookies & Tracking Technologies
OBSERVE: lucky-legends-ca.com uses cookies and similar technologies to enhance user experience, analyze website traffic, and deliver targeted content.
- Session Cookies: Temporary cookies that expire when you close your browser, used for authentication and navigation.
- Persistent Cookies: Remain on your device for a specified period to remember preferences and login details.
- Third-Party Cookies: Set by analytics and advertising providers (e.g., Google Analytics) for performance measurement and targeted advertising.
- Device Fingerprinting: Employed where permitted, to prevent fraud and enhance security.
- Cookie Management: You can manage or disable cookies via browser settings or, where available, through your account dashboard's privacy controls. For more details, see our dedicated Cookie Policy.
REFLECT: Disabling some cookies may impact your ability to use certain features of lucky-legends-ca.com.
Data Security
OBSERVE: We implement robust technical and organizational measures to safeguard your personal data against unauthorized access, disclosure, alteration, or destruction.
- TLS Encryption: All data transmitted to and from lucky-legends-ca.com is protected with TLS 1.2+ encryption.
- Data Encryption at Rest and In Transit: Sensitive personal and financial data is encrypted both during transmission and while stored on our servers.
- Multi-Factor Authentication: Access to administrative systems is restricted via multi-factor authentication.
- Access Controls: Role-based access restrictions ensure only authorized personnel can access personal data.
- Regular Security Audits: Periodic assessments and penetration testing are conducted to identify and address vulnerabilities.
- Staff Training: Employees receive regular training on data protection, privacy, and information security best practices.
- Incident Response: Comprehensive procedures are in place to handle data breaches, including prompt notification to affected individuals and authorities as required.
- International Standards: We strive to comply with recognized frameworks such as ISO 27001 and SOC 2 where applicable.
REFLECT: Our security measures are continuously reviewed and updated in line with technological advancements and regulatory developments.
Complaints & Contacts
OBSERVE: If you have concerns or complaints regarding your personal data processing on lucky-legends-ca.com, you may contact our Data Protection Officer.
- DPO Contact: (Please visit our website for the latest contact information.)
- Online Feedback: Use the web contact forms available on https://lucky-legends-ca.com where specified.
- Postal Address: Lucky Legends LLC, Hamchako Mutsamudu, The Autonomous Island of Anjouan, Union of Comoros.
- Complaint Procedure: Submit your complaint or inquiry via email, online form, or post. We will acknowledge your complaint within 7 days and provide a substantive response within 30 days.
- Escalation: If you are dissatisfied with our response, you may escalate your complaint to the relevant data protection authority. For CA residents, this may include the Office of the Privacy Commissioner of Canada (OPC). For Mexican residents, you may contact the National Institute for Transparency, Access to Information and Personal Data Protection (INAI).
OPC Contact: https://www.priv.gc.ca/en/
INAI Contact: https://www.inai.org.mx/
REFLECT: We take all complaints seriously and are committed to protecting your privacy rights.
Updates
OBSERVE: We may update this Privacy Policy to reflect changes in legislation, technology, or our business practices.
- Notification Procedure: Material changes will be communicated to you via email (if provided), prominent website banners, and account dashboard notifications at least 30 days before the changes take effect.
- Version Control: The current version is effective as of November 6, 2025. Previous versions and a summary of material changes will be available upon request.
- User Options: If you do not agree to the updated policy, you may object or close your account before the effective date of changes without penalty.
Last updated: November 6, 2025
REFLECT: We encourage you to review this policy regularly for updates. Your continued use of lucky-legends-ca.com confirms your acceptance of the current version.