GICNT Registry · Certified Operators · Compliance Reports · Standards
EST. 2019
gicnt.org
Global iGaming Compliance & Trust
Independent Standards & Certification Authority
GICNT's mission is to establish and uphold global standards for responsible, transparent and fair iGaming operations — protecting players, enabling regulators, and certifying operators who meet the highest standards of compliance. Our certification is not paid. It is earned.

Privacy Policy

GICNT is an independent certification body for gambling compliance. This policy explains, in plain terms, what personal data we process when you visit gicnt.org or engage our certification services, why we process it, and what rights you have.

Who we are and how to contact us

GICNT is an independent certification body that assesses gambling operators against published standards covering licensing, player protection, AML & KYC, fair play, data security and advertising.

If you have any question about this policy or about the data we hold about you, email us at [email protected] .

What this policy covers

This policy applies to personal data we collect when you visit or interact with gicnt.org, when you contact us, and when you or your organisation apply for, undergo or maintain a GICNT certification. It also applies to personal data of individuals connected with those activities, such as directors, beneficial owners and compliance personnel of the operators we assess.

This policy does not apply to external websites we link to; those sites have their own privacy statements.

Personal data we process

3.1 Data you provide

When you contact us or apply for certification, you may give us your name, job title, business email address and telephone number, the name of your organisation, and the content of your enquiry.

3.2 Certification and compliance data

Where you or your organisation apply for or maintain a certification, we process the documentation needed for our assessments — corporate and licensing documents, player-protection records, AML & KYC documentation, test reports and information-security material. Much of this concerns your organisation, but it can contain personal data of individuals (directors, shareholders, key personnel, and in some records customers). We process such personal data only to the extent necessary to perform the assessment and keep the certification record.

3.3 Data collected automatically

When you visit our website, we collect limited technical data: IP address, browser type, operating system, pages viewed, and time of visit, through server logs and cookies . We do not use this data to identify you and we do not profile website visitors.

How we use your information

  • to answer your enquiries and provide information about our standards and services;
  • to assess certification applications and issue certificates;
  • to maintain certification records and evidence compliance;
  • to meet legal and regulatory obligations, including responding to lawful requests from regulators;
  • to operate and secure the website; and
  • to send you updates about our services, only where you have consented to receive them.

We process personal data only where data protection law gives us a lawful basis:

  • Performance of a contract — providing certification services you or your organisation requested;
  • Legal obligation — where we must retain records or respond to authorities, including anti-money-laundering obligations;
  • Legitimate interest — running and securing our website and managing our certification business; and
  • Consent — for any direct marketing or non-essential cookies; you may withdraw consent at any time.

We do not intentionally collect special categories of personal data (health, ethnicity, biometrics and similar). Where such data appears incidentally within records you submit, we process it only where the law allows.

Who we share data with

We do not sell personal data and we do not share it for third-party marketing. We disclose personal data only where needed to deliver certification or where the law requires:

  • certification teams and assessors engaged to perform assessments;
  • accredited test laboratories verifying game integrity and RNG;
  • professional advisers (legal, audit, insurance);
  • IT and hosting providers acting on our instructions under data processing agreements; and
  • regulators or public authorities where we have a legal obligation to disclose.

Cookies

Our website uses cookies — small text files stored on your device. We use strictly necessary cookies for the site to function correctly; these do not require consent. Any analytics or preference cookies are loaded only with your consent, which you can give, refuse or withdraw through our cookie banner or your browser settings. Disabling essential cookies may prevent parts of the site from working.

A full inventory of the cookies we use will be published on this page as the site is completed.

How long we keep data

We keep personal data only for as long as the purpose it was collected for continues, plus any period required by law:

  • Enquiries and correspondence — deleted once resolved, unless they lead to an engagement;
  • Certification records — for the life of the certification plus the retention period required by applicable law;
  • Website analytics and logs — in aggregated form for a limited operational period.

When the period ends, data is securely deleted or irreversibly anonymised.

How we protect data

We apply organisational and technical measures aligned with the ISO/IEC 27001 control set that we use for our own data-security standard (GICNT-DS): encryption of data in transit and, where appropriate, at rest; role-based access control; documented incident response; and breach notification to the relevant authority and affected individuals within the window the law requires. No method of transmission or storage is completely secure; if you believe your data may have been compromised, contact us at [email protected] immediately.

Your rights

Under the UK GDPR and the EU GDPR you have the right to:

  • Access the personal data we hold about you;
  • Rectify inaccurate or incomplete data;
  • Erasure — ask us to delete data where there is no longer a lawful basis to keep it;
  • Restrict processing while a dispute about the data is resolved;
  • Portability — receive data you provided, in a structured, machine-readable format;
  • Object to processing based on legitimate interests or to direct marketing; and
  • Complain to the data protection supervisory authority in your country (in the United Kingdom, the Information Commissioner’s Office).

How to exercise your rights

Email [email protected] and we will respond within one calendar month. We may ask you to verify your identity first, and we will act on your request free of charge unless it is manifestly unfounded or excessive.

Changes to this policy

We may update this policy as our services, our standards or the law change. The current version is always available at https://gicnt.org/privacy-policy/, and the effective date is shown at the top of this page. Where changes are material, we will bring them to the attention of operators with an active certification.