Mega Medusa Casino Privacy Policy
Navigation
Introduction to the Mega Medusa Casino Privacy Policy
At Mega Medusa Casino, we treat the privacy and security of your personal information as a fundamental priority. This privacy policy document has been prepared in accordance with the Australian Privacy Act 1988 and the thirteen Australian Privacy Principles (APPs), as well as the General Data Protection Regulation (GDPR) where applicable to users in relevant jurisdictions. Whether you are browsing our site, registering an account, or enjoying our 4,000+ casino games, you deserve to know exactly how your personal data is collected, processed, stored, and protected.
The Mega Medusa Casino privacy policy applies to all visitors, registered members, and users of the megamedusa-1.com website and its associated services, including our mobile app (available as an Android APK and iOS PWA via Safari). By using our platform, you acknowledge that you have read and understood this policy. We are committed to full transparency regarding our data collection practices, our use of cookies, and the data protection standards we uphold on your behalf. If you have any questions at any time, our dedicated team is available to assist you.
Identity of the Data Controller
Mega Medusa Casino is operated by a company registered and licensed in Curaçao, under the jurisdiction of the Government of Curaçao. As the entity that determines the purposes and means of data processing, this company acts as the data controller for all user data collected through the megamedusa-1.com platform. All data processing activities are subject to applicable privacy laws and the commitments made in this document.
If you wish to contact us regarding any matter related to this Mega Medusa Casino privacy policy, including exercising your privacy rights or raising a concern about data security, please reach out using the contact details provided at the end of this document. We aim to respond to all privacy-related enquiries within five business days.
Personal Data We Collect
As part of providing a safe, legal, and enjoyable online casino experience, Mega Medusa Casino engages in data collection across several categories of personal information. Understanding what we collect and why is a core element of Mega Medusa Casino data protection. The following outlines each category in full:
Identification and Contact Data
- Full legal name, date of birth, and gender
- Residential address, postcode, and country of residence
- Email address and mobile phone number
- Username and account credentials
- Government-issued identification documents (passport, driver's licence) collected during mandatory KYC verification prior to first withdrawal
Financial Data
- Payment method details (PayID, Visa, Mastercard, Skrill, Neteller, Paysafecard, Neosurf, Bitcoin, Ethereum, Litecoin, bank transfer)
- Transaction history, deposit amounts, and withdrawal records
- Bank account details or e-wallet identifiers where applicable
- Source of funds documentation, as required under AML compliance obligations
Gaming Activity Data
- Game history, bet amounts, wins, and losses across our 4,000+ game catalogue
- Bonus usage, free spins redemptions, and wagering requirement progress (35x the bonus amount)
- VIP programme level (Bronze, Silver, Gold, Platinum, Diamond) and cashback reward history
- Session duration, time of play, and frequency of gaming activity
- Responsible gambling settings, including deposit limits, bet limits, loss limits, session limits, cooling-off elections (24h, 48h, 7 days, 30 days), and self-exclusion periods (6 months, 1 year, 5 years, permanent)
Technical and Device Data
- IP address and approximate geolocation data
- Browser type, version, and operating system
- Device identifiers and screen resolution
- Referring website and exit page data
- Log files, error reports, and session tokens
Communication Data
- Live chat transcripts and support ticket history
- Email correspondence and responses to surveys or promotions
- Marketing preferences and subscription status
Sensitive Data
In limited circumstances, Mega Medusa Casino may process sensitive categories of personal data, such as information relating to responsible gambling interventions — including self-exclusion histories shared with us by recognised third-party exclusion schemes. This type of personal information is handled with the utmost care and is processed only where legally required or with your explicit consent. Confidentiality of sensitive data is maintained at all times.
Data Received from Third Parties
We may also receive personal information about you from trusted third parties, including:
- Payment service providers performing identity or fraud checks
- KYC and AML verification partners
- Affiliate marketing partners (if you arrived at our site via a referral link)
- Social media platforms (if you interact with our social channels)
Methods of Data Collection
The data collection practices at Mega Medusa Casino take place through several channels, all designed to ensure that we gather only what is necessary for the legitimate purposes outlined in this privacy policy:
- Direct provision — you supply personal data when you register an account, complete KYC verification, make a deposit or withdrawal, redeem a bonus, or contact our support team via live chat or email.
- Automated technologies — our servers and analytics tools automatically collect technical and usage data when you visit megamedusa-1.com, including through cookies, web beacons, pixel tags, and similar tracking technologies.
- Third-party sources — as described above, we may receive verified identity, fraud-prevention, and referral data from licensed third-party partners operating under strict confidentiality agreements.
Purposes of Data Processing
At Mega Medusa Casino, data processing is conducted strictly for legitimate, specified, and transparent purposes. We do not process your personal information in any manner that is incompatible with the purposes for which it was originally collected. The table below summarises our key processing activities:
| Purpose | Description |
|---|---|
| Account Management | Creating, maintaining, verifying, and securing your player account at Mega Medusa Casino |
| Service Provision | Enabling access to our 4,000+ game catalogue from 50+ providers including Pragmatic Play, Evolution Gaming, Play'n GO, NetEnt, and Microgaming |
| KYC / AML Compliance | Meeting legal obligations under anti-money laundering and know-your-customer regulations before processing any withdrawal |
| Fraud Prevention and Data Security | Detecting, preventing, and investigating suspicious or fraudulent activity to protect your user data and the platform |
| Responsible Gambling | Monitoring gaming patterns to identify at-risk behaviour and administering player protection tools including limits and exclusions |
| Customer Communication | Responding to enquiries, sending transactional notifications, and delivering promotional offers subject to your marketing preferences |
| Platform Improvement | Analysing usage patterns and cookies data to optimise performance, navigation, and the overall player experience |
| Legal Obligations | Retaining records as required by applicable Australian and international laws and responding to regulatory or law enforcement requests |
Legal Basis for Processing
For users in Australia, Mega Medusa Casino data protection practices are grounded in the Australian Privacy Act 1988 and the Australian Privacy Principles. Depending on the nature of the data processing activity, we rely on one or more of the following legal bases:
- Contractual necessity — processing required to fulfil our obligations under your player agreement (e.g., account creation, payment processing, bonus administration)
- Legal obligation — processing mandated by law, such as KYC/AML identity checks, tax reporting, and regulatory record-keeping requirements
- Legitimate interests — processing for fraud prevention, platform security, data security, and responsible gambling monitoring, where such interests do not override your fundamental privacy rights
- Consent — processing for direct marketing communications and non-essential cookies, where you have provided explicit, freely given, and informed agreement
Where GDPR applies to users located in eligible jurisdictions, we additionally rely on the lawful bases set out in Article 6 of the GDPR, and Article 9 for sensitive categories of personal data. In all cases, Mega Medusa Casino processes the minimum amount of personal information necessary to fulfil the relevant purpose.
Mega Medusa Casino Cookie Policy
The Mega Medusa Casino cookie policy governs our use of cookies and similar tracking technologies on megamedusa-1.com. Cookies are small text files placed on your device that help us deliver a better, more personalised experience. We use four distinct categories of cookies, each with a clear and specific purpose:
Essential Cookies
These cookies are strictly necessary for the website to function correctly. They enable core features such as secure login, session management, shopping cart functionality, and access to your account. Because they are fundamental to the operation of our service, essential cookies cannot be disabled. Without them, certain parts of megamedusa-1.com would not function as intended.
Analytical Cookies
Analytical cookies help us understand how visitors interact with our site. They collect anonymised data on page views, time on site, traffic sources, and user journeys. This data processing allows us to continuously improve our platform and deliver a better experience for Australian players. We use industry-standard tools for this purpose, with appropriate data anonymisation and aggregation measures in place to protect your privacy.
Functional Cookies
Functional cookies remember your preferences and settings — such as your preferred language, currency display (AUD), and layout options — so you do not have to re-enter them each visit. These cookies enhance the personalisation of your Mega Medusa Casino experience without tracking you for advertising purposes.
Marketing Cookies
Marketing or advertising cookies track your browsing behaviour across websites to build a profile of your interests and deliver relevant promotional content. At Mega Medusa Casino, marketing cookies are placed only with your explicit consent. You may withdraw that consent and update your preferences at any time through our Cookie Preference Centre, accessible from the footer of every page on megamedusa-1.com. We are committed to a transparent cookie policy that puts control firmly in your hands.
For a full breakdown of the individual cookies we use, their expiry periods, and their third-party providers, please refer to our interactive cookie manager. You may review and update your cookie preferences at any time, and changes will take effect immediately.
Sharing Your Personal Data with Third Parties
Mega Medusa Casino does not sell your personal information to third parties under any circumstances. We may, however, share user data with selected partners in limited and strictly controlled circumstances, always subject to binding confidentiality and data protection agreements:
Payment Providers
We share the financial and identification data necessary to process transactions with our licensed payment service providers. These include the processors behind PayID, Visa, Mastercard, Skrill, Neteller, Paysafecard, Neosurf, and supported cryptocurrency networks (Bitcoin, Ethereum, Litecoin). All payment partners are contractually bound to maintain the confidentiality and information security of your data and may not use it for any other purpose.
Regulatory and Law Enforcement Authorities
We are legally required to share relevant personal data with regulators, law enforcement agencies, and supervisory bodies upon receipt of a valid legal request. This includes cooperation with AML/CFT (counter-terrorism financing) investigations and responses to court orders. Mega Medusa Casino takes these obligations seriously and ensures that only the minimum necessary personal information is disclosed in each case.
Identity Verification and KYC Partners
To comply with KYC obligations — mandatory before any first withdrawal is processed — we work with accredited third-party identity verification services. These partners process your identification documents under strict confidentiality agreements and are contractually prohibited from using your personal data for any purpose beyond the specific verification task.
Technology and Game Software Partners
Our game catalogue is powered by 50+ software providers, including Pragmatic Play, Evolution Gaming, Play'n GO, NetEnt, Microgaming, Yggdrasil, Hacksaw Gaming, Push Gaming, Spribe, Red Tiger, Nolimit City, and Relax Gaming. These providers may receive limited technical user data — such as anonymised session tokens — solely to facilitate game delivery and RNG (Random Number Generator) certification. All providers are certified by independent testing laboratories.
Responsible Gambling Organisations
Where a player has elected self-exclusion, Mega Medusa Casino may share relevant information with recognised multi-operator exclusion schemes to help enforce the restriction across participating platforms. This sharing is conducted in your best interest and forms part of our responsible gambling commitment.
International Data Transfers
As Mega Medusa Casino is operated by a Curaçao-registered company and partners with providers located around the world, your personal data may be transferred to and stored in countries outside Australia. When such international transfers occur, we ensure that appropriate safeguards are in place to protect your personal information to a standard at least equivalent to the protections offered under Australian privacy law. These safeguards include:
- Standard contractual clauses approved by relevant data protection authorities
- Binding corporate rules applicable to transfers within corporate groups
- Adequacy decisions where the destination country has been assessed as providing sufficient data protection
- Contractual confidentiality and information security obligations imposed on all international recipients of user data
You may request further information about the specific safeguards applicable to any international transfer of your personal data by contacting our Data Protection Officer at [email protected].
Data Security at Mega Medusa Casino
Mega Medusa Casino data security is underpinned by robust technical and organisational measures designed to protect your personal information against unauthorised access, disclosure, alteration, loss, or destruction. Information security is not an afterthought at Mega Medusa Casino — it is embedded into every layer of our platform and operations.
Technical Security Measures
- 256-bit SSL/TLS encryption applied to all data in transit between your device and our servers
- Advanced firewall systems and intrusion detection tools to block unauthorised network access
- Encrypted data storage for sensitive personal data and all financial records
- Multi-factor authentication options available for all player accounts
- Regular penetration testing and independent vulnerability assessments to identify and remediate weaknesses
- RNG (Random Number Generator) certification by independent testing laboratories for all games
Organisational Security Measures
- Strict role-based access controls — only authorised personnel with a documented, legitimate operational need can access user data
- Comprehensive staff training on data protection, information security, and the requirements of this privacy policy
- Data breach detection protocols and a formally documented incident response plan aligned with Australian notification obligations
- Regular internal audits of all data processing activities to ensure ongoing compliance
While Mega Medusa Casino implements information security measures that meet and often exceed industry standards, no online system can guarantee absolute security. We therefore encourage you to use a strong, unique password for your Mega Medusa Casino account and to contact us immediately at [email protected] if you suspect any unauthorised access or suspicious activity relating to your account.
Data Storage and Retention Periods
Mega Medusa Casino data storage practices are governed by both our operational requirements and our legal obligations under Australian and international law. We retain personal data only for as long as is necessary to fulfil the purposes for which it was collected, or as expressly required by applicable regulation. Our principal retention periods are summarised below:
| Data Category | Retention Period |
|---|---|
| Account and identification data | Duration of active account plus 7 years post-closure (AML and legal requirement) |
| Financial transaction records | Minimum 7 years from the date of each transaction (regulatory requirement) |
| Gaming activity and session logs | 5 years from the date of last gaming activity |
| Customer support communications | 3 years from the date of last interaction |
| Marketing preferences and consent records | Until consent is withdrawn, plus 2 years thereafter |
| Technical log and cookie data | Up to 12 months from the date of collection |
| Self-exclusion and responsible gambling records | Duration of exclusion plus 7 years |
When data storage is no longer required for any legitimate purpose, we securely delete or irreversibly anonymise the relevant personal information in accordance with our internal data lifecycle management procedures. Anonymised, aggregated data may be retained indefinitely for statistical and research purposes, as it can no longer identify you as an individual.
Your Privacy Rights
As an Australian player, you hold significant privacy rights under the Privacy Act 1988. Mega Medusa Casino is fully committed to upholding these rights and to making it straightforward for you to exercise them at any time. Your key privacy rights in relation to the personal data we hold about you are as follows:
Right of Access
You have the right to request a copy of the personal information we hold about you. We will respond to access requests within a reasonable timeframe, and in most cases within 30 days of receipt of a verified request. Certain exemptions may apply in limited circumstances as specified by the Privacy Act 1988.
Right to Correction
If any personal data we hold about you is inaccurate, incomplete, or out of date, you have the right to request that it be corrected without undue delay. You may update certain information directly through your account settings, or contact our team for assistance with more complex corrections.
Right to Deletion
Subject to our legal and regulatory obligations — particularly mandatory AML and financial record-keeping requirements — you may request the deletion of your personal information. Where we are unable to comply in full due to legal constraints, we will explain clearly which personal data must be retained and the reason for its continued data storage.
Right to Restrict Processing
In certain circumstances defined by applicable law, you may request that we restrict the data processing of your personal information — for example, while you contest the accuracy of the data, or while an objection to processing is being assessed.
Right to Data Portability
Where technically feasible, you have the right to receive your personal data in a structured, commonly used, and machine-readable format, and to have that data transmitted directly to another controller. This right applies to personal information processed by automated means on the basis of your consent or a contract.
Right to Object
You may object to the processing of your personal information for direct marketing purposes at any time, with absolute effect. You may also object to processing conducted on the basis of Mega Medusa Casino's legitimate interests; we will cease such processing unless we can demonstrate compelling legitimate grounds that override your privacy rights.
Right to Withdraw Consent
Where we rely on your consent as the legal basis for data processing — such as for marketing cookies or promotional email communications — you may withdraw that consent at any time. Withdrawal of consent does not affect the lawfulness of any processing carried out prior to withdrawal. Opt-out options are always available through your account settings or by contacting [email protected].
To exercise any of your privacy rights, please submit a written request to our Data Protection Officer using the contact details provided in the section below. We may ask you to verify your identity before proceeding, to safeguard the confidentiality and security of your personal information. All requests will be acknowledged within five business days.
Supervisory Authority — OAIC
If you are an Australian resident and you believe that Mega Medusa Casino has not complied with your privacy rights or has mishandled your personal data in any way, you have the right to lodge a formal complaint with the Office of the Australian Information Commissioner (OAIC) — the national independent regulator responsible for privacy and freedom of information.
You can contact the OAIC through the following channels:
- Website: www.oaic.gov.au
- Phone: 1300 363 992
- Post: GPO Box 5218, Sydney NSW 2001
We encourage you to contact us directly in the first instance, as Mega Medusa Casino is committed to resolving any privacy or data protection concerns quickly, fairly, and without the need for formal escalation. Our target response time for all privacy complaints is 30 calendar days.
Data Protection Officer
Mega Medusa Casino has appointed a dedicated Data Protection Officer (DPO) to oversee compliance with this privacy policy, all applicable data protection laws, and our internal information security standards. The DPO is your primary point of contact for any questions, concerns, access requests, or complaints relating to the processing of your personal data.
- DPO Email: [email protected]
- General Support Email: [email protected]
- Live Chat: Available 24/7 from the megamedusa-1.com homepage (replies within minutes)
- Email Support Response Time: Within 12 hours for general enquiries
Changes to This Privacy Policy
Mega Medusa Casino reserves the right to update this privacy policy at any time to reflect changes in our practices, applicable legislation, or the services we provide. When material changes are made, we will notify all registered users via email and display a prominent notice on our website. The date of the most recent revision will always be indicated at the top of this document. We encourage you to review the Mega Medusa Casino privacy policy periodically to stay informed about how your personal information is collected, used, and protected.
Frequently Asked Questions — Privacy and Data Protection
How does Mega Medusa Casino protect my personal data?
Mega Medusa Casino data security relies on multiple layers of industry-leading information security controls. All data in transit is protected by 256-bit SSL/TLS encryption. Sensitive personal data and financial records are encrypted at rest. Our systems are protected by advanced firewalls and are subject to regular independent penetration testing. Internally, strict role-based access controls and ongoing staff training ensure the highest standards of confidentiality are maintained at all times.
What cookies does Mega Medusa Casino use?
The Mega Medusa Casino cookie policy covers four types of cookies: essential, analytical, functional, and marketing. Essential cookies are required for the site to operate and cannot be disabled. Analytical, functional, and marketing cookies can be managed through our Cookie Preference Centre, accessible from every page footer on megamedusa-1.com. We are transparent about every cookie we deploy and provide full disclosure in our cookie policy manager.
Can I request deletion of my personal information?
Yes. Under your privacy rights as an Australian player, you may request the deletion of your personal data. Note that certain records — particularly financial transaction data — must be retained for a minimum of 7 years to satisfy AML and regulatory obligations. To submit a deletion request, please email our DPO at [email protected]. We will confirm receipt within five business days and respond in full within 30 days.
Does Mega Medusa Casino sell my data to third parties?
No. Mega Medusa Casino does not sell, rent, or otherwise commercially transfer your personal information to any third party. User data is shared only where strictly necessary to deliver our services — such as with payment processors, KYC partners, or game providers — and always under strict contractual confidentiality and data protection obligations. Your personal data is never used for third-party advertising without your explicit consent.
How long does Mega Medusa Casino retain my data?
Mega Medusa Casino data storage periods vary by data category. Account and financial records are retained for a minimum of 7 years post-account closure to satisfy regulatory requirements. Gaming activity logs are kept for 5 years. Technical log and cookie data is retained for up to 12 months. After these periods expire, all personal information is securely deleted or irreversibly anonymised in line with our data lifecycle management procedures.
What are my rights under the Australian Privacy Act?
Australian players hold comprehensive privacy rights under the Privacy Act 1988, including the right to access, correct, delete, restrict processing, port, and object to the use of their personal data. You also have the right to withdraw consent at any time and to lodge a complaint with the OAIC. Mega Medusa Casino is committed to honouring all of these rights and to making the process of exercising them as simple and transparent as possible.
What is the legal basis for Mega Medusa Casino processing my personal data?
Mega Medusa Casino data processing is conducted on the basis of contractual necessity, legal obligation, legitimate interests, or your explicit consent, depending on the specific activity. We always process the minimum amount of personal information necessary. If you wish to know the specific legal basis applicable to any particular data processing activity, please contact our DPO at [email protected] and we will provide a clear, written explanation.
How can I contact the Data Protection Officer?
You can reach the Mega Medusa Casino Data Protection Officer directly by emailing [email protected]. For general account support, use [email protected] or our 24/7 live chat facility. We aim to acknowledge all privacy and data protection requests within 5 business days and to resolve them in full within 30 days. Your privacy rights matter to us, and our team is dedicated to assisting you promptly and professionally.