Privacy Policy
How information is handled on this website, with an app-specific framework to complete before launch.
1. Controller, contact, and scope
DEEP BLUE COAST LIMITED, registration HE 494371, D-U-N-S Number 365899213, is the proposed controller for the Services it operates under this notice. Our address is Grigori Afxentiou, 39, ACADEMIA CENTER, BLOCK 1, Flat/Office 3, Larnaka, 6021, Larnaca, Cyprus. For privacy requests, write to support@whale.us or the postal address above, marked “Privacy”.
This notice covers the Deeb Blue company website and only those Company-operated apps and promotions that expressly adopt it. If a separate operator determines how player data is used on our platform, its own notice must identify that operator and explain our role. Complete: exact app/domain list, controller/processor relationships, any joint controllers, DPO or representative details if required, and effective date.
2. This website and app-specific disclosures
The current company website is informational. Its page code does not set cookies, use local storage, contain advertising or analytics SDKs, or collect form submissions. A web host may process request information such as IP address, requested page, browser details, and timestamps to deliver and protect the site. Confirm production hosting provider and server-log retention.
The website currently loads fonts from Google Fonts. Your browser therefore makes requests to Google that disclose network and request information, such as IP address and browser headers. See Google Fonts privacy information. Contact links open your email application; this website does not itself send or store the message.
The remaining app-related sections are a proposed disclosure structure, not confirmation that every listed data type or integration is currently used. Before adopting this notice for an app, replace conditional descriptions with the actual inventory and remove unused categories.
3. Information provided by you
- Account details: depending on the service, email, username, authentication credentials or provider identifiers, age/date of birth, and country of residence.
- Profile and community content: optional avatar, profile information, chat messages, posts, and reports if those features exist. Public content can be seen by its intended audience.
- Support correspondence: messages, account references, troubleshooting information, and records of our response.
- Promotion and prize information: entries, prize claims, recipient details, delivery information, and any tax information legally needed for a claim.
- Verification information: identity, age, address, or location evidence where a particular feature requires it.
Confirm required and optional fields, whether identity documents or selfies are collected, whether biometric templates are created, who performs verification, and whether the Company sees raw documents or only a verification result. Do not send identity documents or full financial credentials to general support. Any biometric processing needs its own purpose, legal basis, retention rules, and notices or consent where required.
4. Information collected through service use
An app may process game sessions, actions, progress, virtual-item balances, promotional balances, purchase receipts, prize outcomes, redemption requests, and records needed to investigate disputes. Technical information may include IP address, device and operating-system details, app version, timestamps, diagnostics, and fraud-prevention signals.
Confirm exact event data and device identifiers; advertising ID or tracking use; coarse versus precise location; background collection; crash logs; attribution SDKs; and the source of each field. Location collection must be explained before it occurs, including whether it is necessary for lawful eligibility and what happens if permission is declined. Device permissions are not a substitute for required privacy consent.
We do not infer from this draft that contacts, microphone, photos, health information, or precise location are collected. Any such access must be justified, implemented, and separately disclosed before being added to the final notice.
5. Information from other organizations
Depending on implemented integrations, we may receive authentication information from a sign-in provider, transaction status from a store or payment processor, verification results from an identity provider, and delivery or payout confirmation from a prize provider. Those organizations may also act as independent controllers under their own notices.
Name each actual provider, data received, purpose, controller/processor role, and privacy-policy link. Confirm whether affiliates, marketing partners, public records, sanctions databases, or other third-party sources are used. A general reference to “partners” does not replace a complete description of actual sharing.
6. Purposes and legal bases
Where the GDPR applies, each processing purpose requires an appropriate legal basis. The following mapping must be confirmed against the final service:
| Purpose | Data involved | Proposed basis |
|---|---|---|
| Create and operate an account; deliver requested play | Account, authentication, activity, balances | Contract, limited to what is objectively necessary |
| Administer entries and valid prize claims | Entries, outcomes, eligibility, delivery/payout details | Contract; legal obligation only for an identified applicable duty |
| Prevent fraud and protect accounts | Security events, device/network signals, verification results | Legitimate interests following necessity and balancing assessments; applicable legal obligations where identified |
| Respond to service requests and disputes | Correspondence and relevant account records | Contract or legitimate interests, depending on the request |
| Accounting and mandatory reporting | Relevant transaction, tax, and prize records | Identified legal obligations |
| Optional marketing, nonessential tracking, or personalized advertising | Preferences and only the identifiers/events actually used | Consent where required; other bases only where lawfully available and explained |
Our proposed legitimate interests are security, fraud prevention, resolving claims, and reliable service operation. We must assess these against your rights and reasonable expectations. We do not treat acceptance of terms as consent for every use of data. Where consent is used, you may withdraw it without affecting earlier lawful processing.
Confirm applicable statutory duties and each legitimate-interest assessment; add any analytics or profiling purposes actually implemented.
7. Recipients and disclosures
Data may be shared only with recipients needed for the disclosed purposes: hosting and infrastructure providers; authentication, communications, and support providers; payment, verification, and prize-fulfillment providers; professional advisers; and authorities where disclosure is legally required. Advertising or analytics recipients must be separately identified if used.
Providers acting on our instructions must be bound by appropriate data-processing and confidentiality terms, permitted-purpose restrictions, and protections consistent with this notice and applicable law. Independent controllers must be identified as such. We may disclose necessary records in a corporate transaction, subject to appropriate safeguards and notice of material changes.
We will not describe data as “anonymous” if it can still reasonably be linked to a person. Complete a provider register with name, service, data categories, processing location, role, and privacy link. Confirm whether any disclosures constitute a sale, sharing for cross-context behavioral advertising, or targeted advertising under applicable US laws.
8. Cookies, advertising, and choices
The current website has no cookie banner because its page code contains no cookie-based tracking. A change in hosting or integrations may change this and must be checked before production use. Optional storage or tracking must not start before consent where consent is required, and refusal must be usable.
For each app, identify essential storage, SDK identifiers, analytics, advertising, attribution, consent controls, retention durations, and how preferences can be changed. On Apple devices, tracking that falls within App Tracking Transparency must use the required permission flow. Withdrawing tracking consent must not be bypassed by fingerprinting. Device advertising settings and marketing unsubscribe controls apply only to the functions they actually manage.
We have not made a “no sale/share” statement because the advertising and vendor configuration has not been confirmed. If covered US privacy laws apply, appropriate opt-outs, recognized preference signals, sensitive-data choices, and any required appeal process must be implemented and accurately described.
9. Retention
Personal data should be kept only as long as necessary for the purpose for which it was collected, subject to applicable duties and properly documented claims or security needs. Different categories require different schedules:
- Account and play data: while needed to provide the account, followed by deletion or irreversible anonymization under the approved closure schedule.
- Prize, purchase, and accounting records: for the applicable tax, reporting, dispute, or limitation period identified for the relevant jurisdiction.
- Identity documents and verification results: only for the justified verification period, with raw documents separately assessed from minimal proof that a check occurred.
- Support and security records: for a defined period proportionate to resolution, audit, and fraud-prevention needs.
- Backups: until overwritten under a documented cycle; deleted information must not be restored to active use without reapplying deletion controls.
Complete exact periods or sufficiently specific criteria for each category, statutory references where applicable, backup cycle, and deletion completion times. No blanket seven-year period or instant-deletion promise has been assumed.
10. International transfers
Our Company is established in Cyprus. Confirm every hosting and recipient country, including remote administrative access. Where personal data is transferred outside the EEA, the final notice must explain the applicable safeguard, such as an adequacy decision or approved contractual safeguards with any necessary supplementary measures. A recipient’s location alone does not establish that a valid mechanism is in place.
You may request information about the relevant safeguards at support@whale.us. We must verify any claimed certification before relying on it and must not present consent to general terms as blanket authorization for international transfers.
11. Your rights and requests
Subject to the law and relevant exceptions, you may request access to your personal data, correction of inaccurate data, erasure, restriction, and a portable copy. You may object to processing based on legitimate interests and to direct marketing, and withdraw consent where processing relies on it. These rights do not all apply in the same way to every processing activity.
Send a request to support@whale.us. We may ask for proportionate information to establish identity or authority, without collecting unnecessary new data. For GDPR requests, the usual response period is one month; a lawful extension may apply for complex or numerous requests, with an explanation within the initial period. Fees or refusal are limited to circumstances allowed by law.
For residents covered by US state privacy laws, additional rights may include opt-outs of sale, certain sharing, targeted advertising, or qualifying profiling; limits on certain sensitive-data use; an authorized-agent process; and appeals. Confirm applicable states, business coverage, practices, disclosures, request deadlines, opt-out controls, and appeal process in a jurisdiction-specific supplement. We will not unlawfully discriminate against someone for exercising privacy rights.
12. Account deletion and retained records
See Account & data deletion for the external email request route. Provide the app name and the account identifier used for that app. A deletion request is different from logging out, uninstalling an app, or temporarily disabling an account.
Implement and name the in-app deletion route, verify the support team’s deletion workflow, and complete the retention schedule before adopting this policy. Deletion must address associated personal data and relevant processors, not merely deactivate a login. Any limited retention for a lawful obligation, fraud prevention, or a pending claim must be explained with its purpose and duration. Where appropriate, we will explain effects on pending prizes and purchased content, without making lawful deletion conditional on an unnecessary purchase, call, or cancellation step.
13. Children and age checks
Our consumer casino-style and prize services are intended for eligible adults, not children. Specify the minimum age by service and jurisdiction and the actual age-assurance process. The threshold must match eligibility rules and product access controls; a store age rating alone does not determine legal eligibility.
If you believe a child has provided personal data, contact support@whale.us. We will investigate and take the measures required by applicable law, including deletion where appropriate. We will not knowingly use children’s data for targeted advertising.
14. Security and automated decisions
Appropriate technical and organizational measures should protect personal data against unauthorized access, loss, and misuse. No system is completely secure. Verify actual encryption, access controls, staff permissions, logging, incident response, and vendor protections before making specific security claims.
Fraud or eligibility tools may flag unusual behavior. Confirm whether any decisions with legal or similarly significant effects are made solely by automated processing, including prize refusal or account closure; if so, disclose the logic in meaningful terms, significance, legal basis, and available human-review and challenge rights. A general mention of fraud prevention does not adequately explain consequential automated decision-making.
15. Complaints and changes
You can contact us about a concern using the details above. You may also complain to the Cyprus Commissioner for Personal Data Protection or another competent supervisory authority, including in your place of residence or work where applicable. You do not have to complain to us first.
We will publish a version and effective date for the finalized policy and give appropriate notice of material changes. If a new purpose requires fresh consent, we will request it before beginning that processing. The draft date above is not a statement that unverified app practices are already in effect.