live
News
Calendar-today
Wett Tipps
Fußball
bonus
Bonus

Data Protection Policy of Tipico Muenchen Ltd

The object of the information on data protection provided below is to advise you about the website operated at https://sports.tipico.com and the Tipico Games APP and via Tipico betting shops, through which Tipico Muenchen Ltd., as controller under data protection law (Article 4[7] GDPR), processes personal data (Article 4[1] GDPR) as well as the purposes and legal basis of such processing (Article 4[2] GDPR). In providing this information, Tipico Muenchen Ltd. is also discharging its obligation under data protection law to provide information as is incumbent on the controller pursuant to Article 12, 13 GDPR when data are collected from the data subject.


Mandatory information pursuant to Articles 13, 14 GDPR


Identity of the controller:

Tipico Muenchen Ltd., Tipico Tower, Vjal Portomaso, STJ 4011, St. Julian’s, Malta is the controller within the meaning of Article 4(7) GDPR for the collection of data via the webpages operated at https://sports.tipico.com, the Tipico APP and the Tipico betting shops. The controller can be contacted via email at info@tipico.com or also, after registration as a player, using the contact form provided in the member area. The offering of sports betting is based on licence no. MGA/CRP/972/2022 of 7 November 2022 issued by the Malta Gaming Authority to Tipico Muenchen Ltd. Tipico Muenchen Ltd. is part of the internationally operating Tipico Group of companies
(https://www.tipicogroup.com/).

With regard to the registration process and the associated administration of your personal master and address data, your communication data (with the exception of messages and documents that you only address to the responsible party, e.g. in the context of betting operations) as well as the information that the operator (Tipico Muenchen Ltd.) processes in the course of the registration or login process (comparison with internal
company blocking databases, retrieval of creditworthiness data relevant to player protection as well as identity and age verification in accordance with the respective provisions of the state betting laws), Tipico Muenchen Ltd. is the responsible party within the meaning of Art. 24 GDPR . If you use your Tipico login data for an offer of Tipico Muenchen Ltd., only the aforementioned data will be transferred to their system. This is done exclusively for the following purposes:

Administration of customer accounts
Determination of location of residence
Compilation of communication data
Avoidance of mistaken identity and false information
Detection of identity fraud
Identification, identity and age check and verification (to ensure
compliance with the requirements under the law for the protection of
minors and to prevent money laundering as well as terrorist financing)
Credit rating and check, including determination of the place of
residence, income and financial situation of players
Compliance with legal identification and verification obligations, such
as in accordance with the Money Laundering Act (GwG), state betting
laws, laws for the protection of minors, industrial and/or tax law, betting
laws of the country of Malta, as well as other regulatory obligations
Ensuring responsible betting, assessment of betting activities,
checking for the existence of selfexclusions or thirdparty exclusions
with mandatory exclusion institutions and for the purpose of preventing
betting addiction

The designation as „responsible party“ in the following text addresses Tipico Muenchen Ltd. and the processing operations carried out by it in each case under its own responsibility.

Data protection officer:

The data protection officer of
Tipico Muenchen Ltd.. can be reached at
Tipico Muenchen Ltd., Data Protection Officer, Tipico Tower, Vjal
Portomaso, St Julian’s, STJ4011, Malta, email: dpo@tipico.com. This data protection officer also serves as data protection officer for Tipico Group within the meaning of Article 37(2) GDPR.

The categories of personal data concerned:

Personal master data, such as form of address, title, first name, family
name (also former), sex, names at birth, date of birth, place of birth,
nationality, personal ID or passport data (including pictures of the data
subject contained therein)
Address data, addresses that can be used for service of notice including
street, street number, postal code, city/town and country of the relevant
address.
Payment data, such as account data (IBAN, BIC, credit institution) credit card details (expiration date as well as the card’s CVN the latter will not be stored but used solely for the purpose of verification), SEPA direct debits or other data for payment processing (for example, information about the payment provider you selected, and transaction as well as verification data transmitted by the payment service providers used), payment date, amount of payment, data about the redemption of
vouchers or voucher credit, data relating to checks verifying the origin of
assets and funds.
Communication data, such as telephone number, email address,
messages and documents that you provide to the controller.
Credit data, such as credit scores, credit indicators, information on the
financial situation, negative entries, any copies of rental agreements, bills for ancillary charges, electricity bills or bank account statements or other evidence for the origin of your funds.
Contractual data, such as customer reference, player ID, player name
(pseudonym), betting history, betting turnover, winnings and losses,
customer account opening and closure data.
Special bettingrelated information relating to online betting, such
as data on current player exclusions, providerspecific deposit limits
and/or other limits and restrictions, data on current betting activities with
the controller, login and user data, transactionrelated data on the
account balance (distinguishing between the balance in real money and
bonus credit), deposits (time, amount and payment service provider),
payouts (time, amount and payment service provider), chargebacks
(time, amount and payment service provider), stakes (time, amount and
bet), winnings (time, amount and bet), cancelled stakes (time, amount
and game), bonus credit sessionrelated data, KYC and KYC status.
Visitor data, IP addresses, device and domain data of visitors and
ordering parties, date and time of an inquiry, time zone difference to
Greenwich Mean Time (GMT), content of request (specific page), access
statutes/HTTP status code, , website from which the request is made,
browser, operating system and its interface, language and version of the
browser software, pathway and requested resource, where the APP is
used also installation data (e.g. app version and time of installation), data on content and features you use, the content entered by you (e.g.
information in forms and click data), the duration of use and information
on your device (e.g. device model and operating system).
Persistent cookies, i.e. cookies that, for the duration of the visit on a
website, are stored on the visitor’s computer for a predefined period.
Session cookies, i.e. cookies that are deleted when the session ends
or, if the user is inactive for a lengthy period of time, after the browser is
closed.

Purposes of the processing:

Personal data are collected and processed for the following purposes:

Formation, implementation and/or termination of betting contracts with
regards to the participation in bets offered by the controller
Administration of customer accounts
Determination of location of residence
Compilation of communication data
Avoidance of mistaken identity and false information
Detection of identity fraud
Identification, identity and age check and verification (to ensure
compliance with the requirements under the law for the protection of
minors and to prevent money laundering as well as terrorist financing)
Credit rating and check, including determination of the place of residence, income and financial situation of players
Execution of betting operation, making available, implementing, billing
and ending participation in games via https://sports.tipico.com and/or the
Tipico APP in exchange for real money or bonus credit
Examination and processing of thirdparty claims for payment, fulfilment, rescission, injunction and/or damages, especially users of the web lineup available at https://sports.tipico.com and/or the Tipico APP and other third parties
Fulfilment of own legal, regulatory or contractual information, notification, information, retention and other obligations in accordance with, for instance, commercial and tax law, or in accordance with state betting laws
Advertisement, especially direct ads as well as business, service and
product advertisement to interested parties
Payment of winnings from bets
Receipt and allocation of deposits in member accounts
Compliance with legal identification and verification obligations, for
example in accordance with the Money Laundering Act (FMGwG), state
betting laws, laws for the protection of minors, industrial and/or tax law,
betting laws of the country of Malta, as well as other regulatory obligations
Ensuring responsible betting, assessment of betting activities, checking
for the existence of selfexclusions or thirdparty exclusions with
mandatory exclusion institutions and for the purpose of preventing betting addiction
Handling of payment transactions
Monitoring of payment and betting behaviour and any changes to account settings, for the purpose of player protection, the control of money laundering and terrorism, the identification, prevention and the
elimination of fraud and/or manipulation attempts
Administration of existing contracts (contract management)
Enforcement of contractual fulfilment claims, also via third parties such
as lawyers factoring and/or debt collection companies
Fulfilment of contractual obligations and/or for the purpose of
implementing precontractual measures
Customer communication
Administration of closed user groups and user access made available for such purpose, including customer or user accounts and/or portals
Operation, improvement and refinement of the product lineup, the
website and the Tipico APP
Display of the website, and guarantee of stability and security of the
online and the APP lineup
Ensuring network and information security, including prevention of
unauthorised access to the network operated by the controller
Anonymisation of personal player data for statistical and research
purposes as well as transfer to nonprofit research institutions and/or
prudential authorities.

Information on data origin:

Personal data are collected from the data subject (website user, players
willing to register or already registered) and via third parties. Data are
collected from third parties especially in connection with player identification and verification, money laundering checks, compliance with legal obligations or from authorities or regulatory obligations on the part of the controller or in connection with requests for what are known as thirdparty exclusions. When registering a customer card and a customer card account associated with this card in a Tipico betting shop, personal data may also be collected via the respective independent operators of the betting shop (‚Tipico franchise partner‘) acting as sales partners. Bets via the customer card can only be placed in the betting shops operated by the Tipico franchise partner issuing the card. The Tipico franchise partner collects personal information when issuing customer cards and opening customer card accounts exclusively on behalf of, and at the sole responsibility of, Tipico Muenchen Ltd. No joint responsibility with the respective Tipico franchise partner on site is established in this respect.

Legal basis for processing:

The legal basis for processing are:

Consent given in accordance with Article 6(1)(a) GDPR
If such consent has been given, the data subject has the right to
withdraw such consent anytime without such withdrawal affecting the
lawfulness of the processing based on consent before its withdrawal.
Article 6(1)(b) GDPR and/or Article 6(1)(c) GDPR
Article 6(1)(f) GDPR to the extent that the following purposes apply:
Advertisement, especially direct ads as well as business, service and
product advertisement to interested parties; enforcement of contract
fulfilment claims also via third parties, such as lawyers, factoring and/or
debt collection companies; administration of closed user groups and user access made available for such purpose, including customer or user accounts and/or portals; operation, improvement and refinement of the product lineup, the website and the Tipico APP; display of the website, and guarantee of stability and security of the online and the APP lineup; ensuring network and information security, including prevention of unauthorised access to the network operated by the controller; anonymisation of personal player data for statistical and research purposes as well as transfer to nonprofit research institutions and/or prudential authorities.
Article 9(2)(g) and/or (h) GDPR, in the processing of such information for the purpose of statutory prevention of addiction and protection of
gamblers in accordance with the provisions of the Betting Acts adopted
by the individual federal states (Bundesländer) or any other federal,
provincial and/or Maltese laws or regulations relating thereto.

Criteria for storage period:

Personal data are processed until the purpose of the collection or in the case of further processing of further processing have been fully achieved. The data are erased once the purpose for processing has been fulfilled. The controller also has a data retention policy to comply with the retention obligations.
Recipients of personal data:

Processors, such as technical service providers, tracking technology
providers, maintenance service providers that service, maintain, repair
and update the controller’s hardware and software, service providers for
administration of customer data and the handling and processing of
inquiries with customer service via the chat feature, by email or in writing, affiliated companies for the use of group structures and the fulfilment of reporting obligations towards any parent company and/or a company owner, analysis services, with systems for website performance monitoring and security systems.
Credit agencies and address services, especially in connection with in
contract formation, fulfilment and/or termination and/or the enforcement
of contractual fulfilment claims, for determination of location, compilation
of communication data, avoidance of mistaken identity and false
information, detection of identity fraud, identification, identity and age
check and verification (to ensure compliance with the requirements under the law for the protection of minors and to prevent money laundering as well as terrorist financing), credit rating and check, including determination of the place of residence, income and financial situation of bettors, compliance with legal identification and verification obligations, for example in accordance with the Money Laundering Act (FMGwG), state betting laws, laws for the protection of minors, industrial and/or tax law, betting laws of the country of Malta, as well as other regulatory obligations, ensuring responsible betting, assessment of betting activities, checking for the existence of selfexclusions or thirdparty exclusions with mandatory exclusion institutions and for the purpose of preventing betting addiction.
Banks (to handle payment transactions)
Thirdparty debtors, in connection with the enforcement of contractual
fulfilment claims
Courts, authorities and/or enforcement agencies, especially in
connection with the enforcement of contractual fulfilment claims and/or
the defence against thirdparty claims for payment, fulfilment, rescission,
injunction and/or damages and within the scope of fulfilling obligations of
the controller, for example under tax law, control of money laundering or
terrorism or state betting laws
Representatives of the legal profession in the event of deficiencies in
contract formation, implementation and/or termination; in connection with
the enforcement of contractual fulfilment claims and/or the defence
against claims for payment, fulfilment, rescission, injunction and/or
damages and other claims of the data subject and/or third parties.
Representatives of professions providing tax advice, especially in
connection with contract formation, implementation and/or termination
and in connection with the fulfilment of obligations of the controller under
commercial and tax law.
Contractual or legal representatives of data subjects (in the event of
deficiencies in contract formation, implementation and/or termination; in
connection with the enforcement of contractual fulfilment claims and/or
the defence against thirdparty claims for payment, fulfilment, rescission
and/or damages)
Payment service providers, for the handling of payment transactions,
i.e. deposits and payouts as well as debiting of stakes as well as the
crediting of winnings
Members of Tipico Group, to the extent that there is legal or contractual
basis or the data subject has given their consent.
Tipico franchise partners (operators of local Tipico betting shops),
to the extent that you open a local customer card account there and use
this account to participate in sports bets and/or perform deposits and
payouts via a local customer card account, and for the purpose of account settlement between Tipico Muenchen Ltd. and the respective Tipico franchisee.
Creditors of the data subject, to the extent that the controller is obliged
to disclose the data subject’s personal data on account of a legal, court
ordered or regulatory obligation.
Marketing and advertising agencies, provided prior approval for the
marketing activities has been obtained
Communication platform providers
Social media platforms
Where applicable, (partial) legal successors that acquire Tipico
Muenchen Ltd. or any share of the company or Tipico Group as a whole.

Automated individual decisionmaking:

As your data is processed, you may be subject to automated individual
decisionmaking within the meaning of Article 22 GDPR, including profiling. The processing of your data may lead to an automated decision in individual cases within the meaning of Art 22 GDPR (including profiling). This may be the case when making decisions about your eligibility as a player, your further eligibility to play by applying legal and regulatory requirements for player protection and/or combating money laundering and terrorism, as well as whether you are included in the group of recipients of certain marketing campaigns. In connection to this, your deposit and betting behaviour (also behaviour history) or also your score transmitted to the controller by an information office or generated by the controller themselves may be taken into account. In individual cases, and in consideration of having or not having reached specific levels, this may lead to restriction of services, the complete or partial block of your customer account, the nonacceptance of an offer to enter into of a betting contract or to open a customer account. As
this automated decision can have legal consequences for you or, in a similar manner, a substantial detrimental impact on you, you can contest the decision, request its manual review and present your own position.

Information about the obligation to provide data through the data
subject:

The provision of personal data is partly stipulated by the law (e.g. by tax law, the antimoney laundering specifications or state betting law). Furthermore, you may be obliged to provide such personal data as are required to establish, implement or terminate contractual relationships and to fulfil the related contractual, legal and/or regulator obligations. Without such data, the controller is routinely unable to implement contracts and/or comply with their obligations under the law. For the sake of greatest possible transparency under data protection law, the controller shall point out any obligations to provide information separately in each individual case prior to implementing the actual data collection situation.

Your rights as the data subject affected by data processing:

You have the following
rights in your dealings with the controller
pursuant to Articles 15 through 22 GDPR:

Right to access (for details see Article 15 GDPR), rectification (for
details see Article 16 GDPR), erasure (for details see Article 17
GDPR), restriction of processing (for details see Article 18 GDPR) and
data portability (for details see Article 20 GDPR).
The right to object (for details see Article 21 GDPR) to processing for
purposes of the legitimate interest pursued by the controller or by a
third party (Article 6[1][f] GDPR).

Right to lodge a complaint with a supervisory authority:

According to Article 77 GDPR, you have the right to complain to the
supervisory authority if you believe that the processing of the personal data relating to you is not compliant with the law.The address of the supervisory authority responsible for the controller is:

Information and Data Protection Commissioner (IDPC)

Floor 2, Airways House,
Triq IlKbira,
TasSliema SLM 1549, Malta
Tel: +356 2328 7100
Email: idpc.info@idpc.org.mt
Web: https://idpc.org.mt/

Other data protection information and guidance

Data security:

The controller uses appropriate technical and organisational security
measures to protect your data against accidental or intentional
manipulation, partial or complete loss, destruction or against unauthorised access by third parties. For example, the controller uses a role and rights concept based on which only dedicated departments in the controller are allowed to access your personal data and process it they include Support, the Account and Payment Department or the Compliance Department. The computer/server on which the controller (or their processor) stores your personal data is located in a secure environment with restricted access. The controller has invested substantial funds in our server, database, data backup, firewall and encryption technologies in order to protect the collected and processed data. These technologies have been installed as part of the
stateoftheart security architecture. In addition, security measures are
being continuously improved to the state of the art.

Registration/Login area:

Participation in online bets offered by the respective controller requires prior registration in the system. To allow bettors and persons interested in playing access to the betting lineup as authenticated users and to handle the business process, your personal data needs to be processed in the course of the registration. In this case, the controller collects such data as mandatory information as are needed to create your betting account, to fulfil customer identification obligations, to combat fraud and to remedy disruptions or to maintain the functionality of the portal. If you have forgotten your password or your username for this area, you have the option of requesting that these credentials be sent to you again by entering your email address. The data collected as part of the ‚Forgot password?‘ feature are used only for the purpose of resending the forgotten login credentials.

Processing by payment service providers:

The controller uses several payment service providers (hereinafter referred to as ‚payment service provider‘). The transaction data, which may include the verification data about your identity, are stored both in the system of the controller and in the systems of the payment service providers. With regard to the transaction data processed by it, each party is responsible for its own activities in accordance with Article 4 point 7 GDPR. If you have any questions about the payment service provider’s data protection, you can get in touch with the payment service provider directly. The processing of personal data in connection with payments is based on Article 6(b), (f) GDPR. It is recommended that you familiarise yourself with the data protection provisions of the respective payment service provider.

Special conditions that relate to specific payment service providers:

1. Klarna Bank AB (publ), Sveavägen 46, 111 34 Stockholm, Sweden. You will find more information about the processing of your personal data by Klarna at https://cdn.klarna.com/1.0/shared/content/legal/terms/0/de_at/privacy
2. PayPal (Europe) S.a.r.l. et Cie S.C.A. (“PayPal”), 2224 Boulevard Royal L2449, Luxembourg. You will find more information about the
processing of your personal data by PayPal at https://www.paypal.com/myaccount/privacy/privacyhub
3. Paysafe Prepaid Services Limited (‚Paysafecard‘), Grand Canal House, Upper Grand Canal Street, Dublin 4, Ireland. You will find more
information about the processing of your personal data by Paysafecard
at https://www.paysafe/com/en/paysafegroup/comprehensiveprivacy
policy
4. Skrill Limited (‚Skrill‘), 25 Canada Square, London E14 5LQ, United
Kingdom. You will find more information about the processing of your
personal data by PayPal at https://www.skrill.com/en/footer/comprehensiveprivacypolicy/?btag=a
_67633b_4575c_Cj0KCQjws4aKBhDPARIsAIWH0JWvxCVEbu1
vbEVnUnyWawEXDXgzvyU
5qwr1gdpufU0bQ9GsRjKpUaAvEPEALw_wcB&program=SKRILL
5. Neteller (‚Neteller‘), Paysafe Financial Services Limited., 25, Canada
Square, Level 27, London E14 5LQ, UK & Paysafe Payment Solutions
Limited, Kilmore House, 3rd Floor, Park Lane, Spencer Dock, Dublin D01 YE64, Ireland. You will find more information about the processing of your personal data by Neteller at https://www.neteller.com/en/comprehensiveprivacy
policy?btag=a_94953b_2560c_&program=NTAFFILIATE
6. PXP Financial Limited of The Corn Mill 1 Roydon Road, Stanstead
Abbotts, Hertfordshire SG12 8XL, England (hereinafter „PXP“). PXP
processes the following data jointly with the data controller: First Name,
Last Name, Date of Birth, Address and Residence, IP Address, Contact
Data and Transaction Data. PXP processes this data only for the purpose of processing your payments or refunds and to conduct or assist in investigations required by law in connection with suspected money laundering, terrorist financing or other illegal activity. For more
information about PXP’s processing of your personal data, please visit:
https://www.pxpfinancial.com/privacypolicy/
7. Trustly Malta Ltd (‚Trustly‘) Tagliaferro Business Center, High Street c/w Gaeity Lane, Sliema, Malta. You will find more information about the
processing of your personal data by Trustly at https://www.trustly.net/aboutus/privacypolicy
8. UAB MIR Lithuania („MuchBetter“), J.Balcikonio st.3 LT 08200, Vilnius, Lithuania. For more information about MuchBetter’s processing of your personal data, please visit https://muchbetter.com/legal/privacypolicy/
9. Clearhaus A/S, CVR nr 33749996, P.O. Pedersens Vej 14, 8200 Aarhus, Denmark (“Clearhaus”) for the processing of Apple Pay transactions. For more information about Clearhaus’ processing of your personal data, please visit https://www.clearhaus.com/privacy/

The controller uses the following service provider to process credit
card, bank, and EPS payments:

Worldpay B.V. („Worldpay“), De Entrée 248, 1101 EE, Amsterdam,
Netherlands. You will find more information about the processing of your
personal data by Worldpay at https://online.worldpay.com/terms/privacy

Security, identity checks, prevention of fraud, and player protection:
For your and the controller’s best interests, you will be informed for security reasons every time you log in using a new device so that you can check whether the device is actually yours or whether someone is attempting to gain unauthorised access to your account. For this purpose, the controller collects the following data about the device you use to access your customer account: device type; manufacturer; login time stamp; IP address; screen resolution; time zone; operating system: This will help us match the device you use with your customer account.
Where the controller is legally required or otherwise entitled to check your identity, the controller reserves the right for the purposes of their legitimate interests to check your identity and/or your credit standing with the help of the companies listed below:

1. GB Group Plc, The Foundation, Herons Way, Chester Business Park,
Chester CH4 9GB, Great Britain. For further information about the
data processing activities of GB Group, please view their privacy
policy here: https://www.gbgplc.com/en/legalandregulatory/privacy
policy/#general;
2. TransUnion International UK Limited, One Park Lane, Leeds,
Yorkshire, LS3 1EP. For further information about the data processing
activities of TransUnion and iovation please view their privacy policy
here: https://www.transunion.co.uk/legalinformation/bureauprivacy
notice, sowie https://www.iovation.com/privacy;
3. Advanced Living Technologies GmbH („Sonio”),
Landesgerichtsstrasse 18/10, Vienna, Austria. For further information
about the data processing activities of Sonio please view their privacy
policy here: https://soniogroup.com/privacypolicy/;
4. CRIF GmbH, Rothschildplatz 3/Top 3.06.B, 1020 Wien. . For further
information about the data processing activities of CRIF please view
their privacy policy here: https://www.crif.at/datenschutz/.
(hereinafter ‚verification service provider‘).

Furthermore, the controller uses the services of the providers listed below to implement the required verification of the origin of assets and funds:

1. Hooyu Ltd, Unit 3. Brandon House, For a. 180 Borough High St.
London SE1 1LB, United Kingdom
2. Tink Germany GmbH, GottfriedKellerStr. 33, 81245 Munich,
Germany (hereinafter ‚FinTecSystems‘). You will find more information
about the activities of FinTecSystems online
at https://fintecsystems.com/en/privacypolicy/
3. Factiva Limited, The News Building, 1 London Bridge Street, London
SE1 9GF (hereinafter ‚Dow Jones‘). For more information on how Dow
Jones uses your data, please go to https://www.dowjones.com/.
For this purpose, the controller sends the personal data entered by you to the companies designate above. The companies then carry out the
necessary check and verification. The information obtained in this manner provides the basis for the controller’s decision regarding establishment, implementation or termination of the contractual relationship. In addition, it is in the controller’s legitimate interest to further process the data obtained from these verification service providers for purposes of investigation, fraud prevention, responding to inquiries from or making submissions to regulatory authorities.
The controller also reserves the right to carry out security checks at any time in order to confirm the accuracy of your identity, your age and your login credentials and to check whether your use of their services and your financial transactions are possibly in breach of the General Terms and Conditions as well as the applicable law. Among other data, security checks may contain information about potentially fraudulent activities and/or other confirmations of your information obtained using thirdparty databases. The abovereferenced verification service providers are used for this purpose. The service provider may store requests sent to verification service providers in the course of security checks or identity checks. For this storage, the respective service provider is a (separate) controller within the meaning of Article 4(7) GDPR. In case of questions regarding data protection at verification service providers, please get in touch with the verification service provider directly. The processing of personal data in connection with security checks or identity checks is carried out on the basis of Article 6(1)(b), (c) and/or (f) GDPR

Research, development and quality improvement:

From time to time, the controller may process your personal data for the
purposes of research and development and to improve the quality of our
products and services. This is mainly done through the use of surveys. In such cases, the controller would contact you (either by email, via messages on the website, via popups or otherwise) to ask for your cooperation in the survey. The personal data processed for the purpose of such surveys may include your name, contact details, demographic information, incomerelated information, IP address, country of residence and your responses to survey questions or other feedback.
The controller currently uses the following data processors to conduct
surveys and/or analyses on its behalf:

1. Qualtrics, LLC („Qualtrics“), 333 W. River Park Dr., Provo, UT 84604,
USA. For more information about how Qualtrics processes your
personal data, please visit https://www.qualtrics.com/privacy
statement/.
2. Lumoame Oy („Lumoa“), Hermannin rantatie 8, 00580 Helsinki,
Finland. For more information on how Lumoa processes your personal
data, please visit https://www.lumoa.me/privacypolicy/
If the controller engages other processors to carry out surveys on its behalf, you will be informed accordingly.

External content and cookies:

1. Active JavaScript content from external providers is used on the
controller’s websites. When a website is accessed, these external
providers may receive personal data about your visit to our websites. In
this case, the data are allowed to be processed outside the EU. You can
prevent this by installing a JavaScript blocker, e.g. the browser plugin
‚NoScript‘ (www.noscript.net) or deactivating JavaScript in your browser.
However, this may limit functionality on the websites you visit.
2. The controller also uses cookies on websites, in applications and in
newsletters in order to make them more attractive for users, enable the
use of specific functions, improve our website, applications and
newsletter or in order to conduct specific statistical analyses. These so
called ‚cookies‘ are small text files that your browser can place on your
computer or mobile device and that may contain specific (personal) data
(e.g. IP address, settings in your operating system/end device, website
from where the file is retrieved, name of file, date and time of retrieval,
data volume transmitted and notification about the success of retrieval
[known as weblog]). ‚To set a cookie‘ is an alternative way of saying ‚to
place a cookie‘.
3. You can change your browser settings to ensure that your system tells
you when cookies are set so that you can accept cookies in some cases
or decide whether to accept or reject the use of specific cookies.
4. Any of the following types of cookies may be used on websites, in
applications or in newsletters:
(1) Necessary cookies: These cookies are strictly necessary to ensure that the websites or applications work properly. These cookies do not collect any personal data.
(2) Functionality and performance cookies: Performance cookies monitor the behaviour on websites and in applications and allow their performance to be improved. These cookies collect only anonymised or aggregated data. Functionality cookies ensure that the aspects previously selected by users are saved (e.g. username, language). They help to improve userfriendliness and enable us to personalise your experience. The  information collected by these cookies may include personal data. If you do not accept these cookies, functionality may be impaired and access to content on the websites, in the applications or in the newsletter may be restricted.
(3) Marketing cookies: These cookies are used to provide you with bespoke content that may be of interest to you. The controller can use these cookies to save the websites you visit and share these with third parties, e.g. advertising agencies.
(4) Personalised experience cookies: Thanks to these cookies, you can be offered a personalised online experience while you are using a website.
(5) Firstparty cookies are cookies the controller sets directly on your
device so they can offer you their services. All firstparty cookies are
strictly necessary cookies and are generally used for the following
purposes:
a. To determine where website traffic is coming from (including all
platforms and/or websites);
b. For the general functionality of the website, specifically to
ensure that all functions of our website run properly (including,
among others, language preferences in order to ensure that the
login credentials are saved for the duration of the session);
c. To measure the performance of the website;
d. For general testing purposes (also to ensure the website’s
performance and functionality);
e. For all other purposes that may become necessary and may be
considered necessary from time to time
(6) Thirdparty cookies are cookies placed on your device by third
party providers so that they can make their services available to you.
For the settings of these cookies, the cookies policy of the respective
third party will be applicable. Websites and applications currently use
the following thirdparty plugins and active script content:

a. Adform:

The controller uses Adform, a web analysis service provided by
Adform A/S, Wildersgade 10B, sal. 1, DK1408 Copenhagen,
Denmark. The technology of Adform allows advertisers to collect
and store nonpersonal data about internet users and use such data
for analysis and behaviourbased internet advertising. In order to
decide which ads should be placed, including ads for similar
products that a visitor has seen before, Adform uses a cookie mechanism but exclusively in anonymised form. The cookie includes a random identification number, options to accept or reject it, or information about campaigns / promotional activities on the website of an advertiser. With the random identification numbers of these cookies, Adform collects and stores anonymous information in the cookiebased profiles, including operating system, browser version, geographical location, URLs on which Adform displays ads, or facts about any interaction with the ads (e.g. number of clicks or views). You will find Adform’s data protection provisions at https://site.adform.com/privacycenter/overview/

b. Google:

Google Analytics: The controller uses Google Analytics, a web
analysis service of Google Inc., 1600 Amphitheatre Parkway
Mountain View, CA 94043, USA (hereinafter ‚Google‘). Google
Analytics uses various techniques, including socalled ‚cookies,
which are stored on your computer and enable analysis of the use
of this website by visitors. The information about your use of this
website gained by Google Analytics is sent to Google servers that
may be operated in countries outside the European Union and
perhaps even outside the countries that are party to the Agreement
on the European Economic Area. By activating IP anonymisation
within the Google Analytics tracking codes of this website, Google
will anonymise your IP address before it is sent. This website uses
a Google Analytics training code that has been extended to include
the operator ‚gat._anonymizeIp();‘ in order to enable anonymised
collection of IP addresses (known as IP masking). On behalf of the
operator of this website, Google will use this information to evaluate
your visit to this website, to compile reports on website activities and
to perform further services connected with use of the website and
the internet for the operator of this website. The IP address
transmitted from your browser through Google Analytics will not be
integrated with any other Google data. You have the choice of
preventing installation of Google cookies by changing the settings
of your browser software accordingly. However, it should be pointed
out that you may then not be able to make full use of all the features
on this website. Moreover, you can prevent the collection of the data
generated by the Google cookie and relating to your use of the
website (including your IP address) to Google and the processing of
such data by Google by downloading and installing the browser
plugin available at the following link
(http://tools.google.com/dlpage/gaoptout?hl=de). You will find the
security and data protection policy of Google Analytics at
https://policies.google.com/privacy?hl=de.
Google APIs: The controller uses Google APIs provided by Google.
The data generated, including the IP address, may be transferred to
Google. You can prevent the collection and forwarding of personal
data (especially your IP address) to Google and the processing of
this data by Google by deactivating the execution of JavaScript in
your browser or installing a tool like ‚NoScript‘.
Google Tag Manager: The controller uses JavaScript code provided
by Google. If you activate JavaScript in your browser and do not
install a JavaScript blocker, your browser may transmit personal
data to Google. To prevent the execution of Google JavaScript code,
you can install the JavaScript blocker (e.g. www.noscript.net).
DoubleClick: The controller uses DoubleClick, a service provided by
Google. DoubleClick is used to place ads when you visit a website.
DoubleClick uses information (but no personal data such as your
name or your email address) on your visits to this and other websites
in order to place ads for product and services that could be of
interest to you. If you wish to learn more about these methods or
would like to know what options you have to prevent this information
from being used by DoubleClick, please click here:
https://policies.google.com/technologies/ads?gl=de&hl=de.
Google Ads: The controller uses GoogleAds. Google Ads help to
monitor the effectiveness of advertising and allow target groups to
be built for promotional purposes.

YouTube: The controller uses YouTube. YouTube collects user data
through videos embedded in websites which are aggregated with
profile data from other Google services in order to display ads to
web visitors on a wide variety of or own and thirdparty websites.

c. Hotjar:

The controller uses Hotjar, a service provided by Hotjar Ltd., Level
2, St Julian’s Business Centre, 3, Elia Zammit Street, St Julian’s STJ
1000, Malta. Hotjar also uses cookies that are stored on your
computer and that allow website use to be analysed. During use,
data, particularly the IP address and user activities, may be
transmitted to a Hotjar Ltd. server and stored there. Hotjar Ltd. may
transmit this information to third parties, provided the law requires
such a transmission or to the extent that such data are processed
by third parties. You can prevent the collection and forwarding of
personal data (especially your IP address) and the processing of
this data by deactivating the execution of JavaScript in your browser
or installing a tool like ‚NoScript‘. For further information on data
protection when using Hotjar, check out the following link:
https://www.hotjar.com/privacy.

d. Adjust:

The responsible party uses Adjust, a service of the company Adjust
GmbH, Saarbrücker Str. 37A, 10405 Berlin, Germany (hereinafter
referred to as Adjust). Adjust enables all our Native Apps to capture
values relevant for marketing, such as downloads, installs and
clicks. In addition, it allows us to release new marketing campaigns
and it also has a fraud detection feature to make these campaigns
more efficient. For more information about Adjust’s privacy policy,
please visit: https://www.adjust.com/terms/privacypolicy/

e. Iovation:

The controller uses Iovation, a service provided by Iovation Inc., 111
SW 5th Avenue, Suite 3200, Portland, OR 97204, USA (hereinafter
referred to as ‚Iovation Inc.‘). Iovation Inc. also uses cookies that are
stored on your computer and that allow website use to be analysed.
During use, data, particularly the IP address and user activities, can
be transmitted to an Iovation Inc. server and stored there. Iovation
Inc. will transmit this information to third parties if the law so requires
or to the extent that such data are processed by third parties. You
can prevent the collection and forwarding of personal data
(especially your IP address) and the processing of this data by
deactivating the execution of JavaScript in your browser or installing
a tool like ‚NoScript‘. For further information on data protection when
using Iovation, check out the following link:
https://www.iovation.com/legal/privacy.

f. Salesforce:

The controller uses Salesforce Agent, a service provided by
Salesforce.com EMEA Limited, village 9, floor 26, Salesforce Tower,
110 Bishopsgate, London, Great Britain (hereinafter ‚Salesforce‘).
Salesforce also uses cookies that are stored on your computer and
that allow website use to be analysed. During use, data, particularly
the IP address and user activities, can be transmitted to a
Salesforce server and stored there. Salesforce will transmit this
information to third parties if the law so requires or to the extent that
such data are processed by third parties. You can prevent the
collection and forwarding of personal data (especially your IP
address) and the processing of this data by deactivating the
execution of JavaScript in your browser or installing a tool like
‚NoScript‘. For further information on data protection when using
Salesforce Agent, check out the following link:
https://www.salesforce.com/de/company/privacy.jsp.

g. Akamai / Akamai Cookie Sync:

The controller uses JavaScript code which is provided by Akamai
Technologies Inc., 8 Cambridge Center, 02142 Cambridge, MA,
USA (Akamai). If you activate JavaScript in your browser and do not
install a JavaScript blocker, your browser may transmit personal
data to Akamai. For more related information, check out Akamai’s
data protection notice
(http://www.akamai.de/html/policies/index.html). To prevent the
execution of Akamai’s JavaScript code without exception, you can
install a JavaScript blocker (e.g. www.noscript.net or
www.ghostery.com).

h. Emarsys:

The controller uses technology provided by Emarsys eMarketing
Systems AG, Märzstraße 1, 1150 Vienna, Austria (hereinafter
referred to as ‚Emarsys‘), which allows us to follow the behaviour of
a person on a website if this person clicks one of the emails sent by
the controller or if this person registers for receipt of emails. The
cookies to monitor website behaviour are placed when a link in an
email is clicked; in this manner, the data are allocated to your email
address. The controller uses the information to measure the
effectiveness of their marketing applications and to customise the
email content to your interests. For more information about how
Emarsys technology works, check out:
https://help.emarsys.com/hc/de/articles/115003972074Web
ExtendOverview.

i. Facebook

The controller uses Facebook. Facebook Inc. is a company for
social media and technology headquartered in Menlo Park,
California. Thanks to Facebook technology, you can be provided
ads on the controller’s Facebook pages and through paid
promotional campaigns in paid media on all of Facebook’s own
platforms. The controller also uses Facebook Customer Audiences
in order to provide adds to those who visit the websites. The
controller also uses Facebook Pixel in order to collect insights and
analyses, so that they can place adds that are relevant to their target
groups and for retargeting purposes, so that the number of ads you
see can also be limited. Campaigns are created, implemented and
analysed either internally or by a media agency or by thirdparty
provider networks that are hired to manage these campaigns. The
controller uses cookies to help you reject the display of these ads
on Facebook. You can control how Facebook uses data to show you
ads by using your settings for the display of ads in Facebook. You
will find more information on how Facebook uses personal data at
https://www.facebook.com/policies/cookies/ und
https://www.facebook.com/about/ads. In your Facebook ad preferences, you can view and manage the ads that are sent to you based on ‚Topics‘ or specific advertiser customers: https://www.facebook.com/ads/preferences/edit/. If you decide
against the receipt of targeted ads, you will still be able to see the
controller’s nontargeted online ads if your ‚Interests‘ on Facebook
are set to a target group segment (predefined by Facebook) that the
controller is in contact with. Facebook controls the display of such
ads.

j. Twitter

The controller uses cookies provided by Twitter International
Company, One Cumberland Place, Fenian Street, Dublin 2, D02
AX07, Ireland. This cookie is used by the feed embedded in Twitter.
It is set due to the integration of Twitter and the acceptance options
for social media. You will find more information about how Twitter
uses your personal data at https://twitter.com/en/privacy.

k. Snapchat

The controller uses cookies provided by Snap Inc. with its registered
office at 2772 Donald Douglas Loop N, Santa Monica, CA 90405,
USA. You will find more information about how Snap Inc. uses your
personal data at https://www.snap.com/enGB/privacy/privacy
policy/.

l. Microsoft 

Microsoft Bing: The controller uses cookies provided by Microsoft
Corporation of One Microsoft Way, Redmond, WA 98052, USA
(hereinafter referred to as ‚Microsoft‘). This is a cookie used by
Microsoft Bing Ads and is a tracking cookie. Thanks to it, a user who
had previously paid a visit to the controller’s website can be
contacted.
Microsoft Advertising: The controller uses cookies provided by
Microsoft Advertising for the purpose of anonymously identifying
user sessions in order to measure the effectiveness of marketing
campaigns. You will find more information about how Microsoft uses your personal data at https://privacy.microsoft.com/engb/privacystatement.

m. Zuko

The controller uses cookies provided by Formisimo Ltd.
headquartered in Colony, Piccadilly Place, Manchester, M1 3BR, UK
(hereinafter ‚Zuko‘). The cookies offered by Zuko are tracking
cookies that follow user registration step by step and indicate any
errors that occur. The controller uses these cookies to optimise the
registration process of users. You will find more information about
how Zuko processes your personal data at https://www.zuko.io/privacypolicy

n. Evidon

The controller uses cookies provided by Crownpeak Technology Inc.
which is headquarter at 707, 17th Street, Suite 3800, Denver, CO
80202, USA (hereinafter ‚Evidon‘). The cookies provided by Evidon
are used to show users a banner for allowing cookies, to show users
what categories and providers they have opted for and whether they
have given their consent or not, and to ensure that the registration
data used is valid. You will find more information about how Evidon
uses your personal data at https://www.crownpeak.com/privacy

o. Qualtrics

The controller uses Cookies provided by Qualtrics LLC, 333, West
River Park Drive Provo, UT 84604, USA. This is a session cookie
that stores information on which pages a visitor visits for a given
session. You will find more information about how Qualtrics uses
your personal data at https://www.qualtrics.com/privacystatement/
p. WordPress

The controller uses WordPress. Authors can use the WordPress
Multilingual plugin (hereinafter referred to as ‚WPML‘) for WordPress
to write and translate content in different languages. It includes
extended features for translation management and an interface for
professional content translation. The manufacturer of WPML is
OnTheGoSystems Ltd. You will find more information about how
WordPress uses your personal data at https://www.onthegosystems.com/legal/privacypolicyandgdpr
compliance/. The collected data include the language in which the
website is written and are used by WPML.


Inquiries submitted via the contact form:

The controller uses the option that allows users to get in touch with them via a contact form. When you make use of this possibility, the following
structured data are collected as mandatory information.
First name
Family name
Email address
Category of your inquiry
Concern of your inquiry
Your specific message / question.

The mandatory information collected via the contact form is used

exclusively for the purpose of establishing contact with the inquirer and to answer specific inquiries. In addition to the mandatory information, other structured data can also be provided. For you, provision of this information is voluntary. This information is:

Username

Consent to direct marketing measures:

Only registered customers of the controller have the option of being
informed via various channels about current or future product offerings,
promotions, special offers or voucher offers or about free products on offer (direct marketing). The following marketing channels that can be selected (multiple selection by user possible):
Email
Post
Phone
Push messages
SMS

The marketing settings can be selected by registered customers under
‚Settings‘ ‚Notifications‘ once they have successfully logged in to their
customer account. There, they can select the marketing channels, a
preferred marketing channel and main topics (called marketing messages). Once settings have been selected, they can be changed anytime, or a direct marketing consent can also be completely withdrawn once it has been given. Changes and withdrawals of these settings have no further effect on the provision of the product lineup. No reasons need to be given when selecting or deselecting marketing settings.
Our direct marketing provides information about the controller’s offers on a regular basis, and about Tipico Group’s offers to the extent admissible under betting law.

Newsletter tracking:

Direct marketing by email contains what are known as tracking bugs. A
tracking bug is a miniature graphic embedded in such emails that are sent in HTML format in order to enable logfile recording and a logfile analysis. This enables the statistical assessment of the success or failure of online marketing campaigns. Using the embedded tracking bug, the controller can tell whether and when an email was opened by the data subject and which links in the email the data subject activated.
The tracking bugs are stored and analysed in order to optimise our
newsletter dispatch and to better match the content of future newsletter
issues with the interests of the data subject. The personal data are not
disclosed to third parties. Using the double optin procedure, data subjects have the right to withdraw any separate consent given in this respect at all times. After a withdrawal of consent, the personal data are erased by the controller responsible for processing.

Version 1.0 Date of issue: 01.01.2025