IGAMING ACADEMY WEBSITE PRIVACY NOTICE
We ask that you read this Website Privacy Notice carefully as it contains important information on who we are, how and why we collect, store, use and share personal information, your rights in relation to your personal information and on how to contact us or the supervisory authorities in the event you have a complaint.
- GENERAL INFORMATION
This website is operated by iGaming Academy Limited, with registration number C70374 (hereinafter referred to as the “IGA” or “Controller” or “Company” or “We” or “Us”).
We collect and use certain personal data about you. When we do so, we are regulated under the General Data Protection Regulation 2016/679 (hereinafter referred to as the “GDPR”), which applies across the European Union, and the national Data Protection Act (Chapter 586 of the Laws of Malta) (hereinafter referred to as the “Privacy Law”).
This Privacy Notice explains:
- how we collect and use your personal data;
- the categories of personal data we process;
- the legal bases on which we process your personal data;
- how we safeguard and protect your personal data;
- how long we retain your personal data; and
- your rights in relation to the processing of your personal data.
This Privacy Notice applies to:
- visitors to our website;
- users of our eLearning platforms;
- current, former, and prospective customers;
- suppliers, contractors, and service providers; and
- individuals whose personal data is processed by IGA on behalf of its corporate clients
- OUR WEBSITE
This Privacy Policy is hosted at iGaming Academy | Expert Training for iGaming Professionals (hereinafter referred to as the “Website”). The Website is an informational website about our Company’s vision and goals, showcasing our Company’s services.
- DATA CONTROLLERS AND DATA PROCESSOR ROLES
IGA may act either as:
- An independent Data Controller; or
- A Data Processor acting on behalf of its corporate clients.
Where IGA acts as a Data Controller
IGA acts as a Data Controller where we determine the purposes and means of processing personal data, including in relation to:
- website administration;
- account management;
- billing and invoicing;
- customer relationship management;
- marketing communications;
- compliance with legal obligations; and
- business operations and administration.
Where IGA acts as a Data Processor
IGA acts as a Data Processor where we process personal data solely on behalf of our corporate clients and in accordance with their documented instructions, including the provision of eLearning and training services.
In such cases, the relevant corporate client remains the Data Controller.
- WHEN WE COLLECT YOUR PERSONAL DATA
We may collect your personal data when you:
- Visit our website;
- Contact us by email, telephone or online forms;
- Register for courses or training programmes;
- Access our eLearning platforms;
- Enter into contracts with us;
- Engage with us on social media; and
- Subscribe to communication or marketing updates.
We may also receive personal data from corporate clients who use our services.
- WHAT INFORMATION WE COLLECT
Depending on the nature of our relationship with you, we may collect and process the following categories of personal data:
Identification and Contact Information:
- First name and surname;
- Work email address;
- Job title;
- Company name;
- Work telephone number; and
- Office location.
Employment-Related Information
Where provided by our corporate clients:
- department;
- business unit;
- line manager details; and
- employment status.
Billing and Financial Information:
- Company billing address;
- EU VAT number; and
- Accounts department contact details.
Technical Information
When you visit our websites or platforms, we may automatically collect:
- IP address;
- browser type and version;
- device information;
- operating system;
- date and time of access;
- website usage data; and
- authentication and security logs.
IGA does not intentionally collect special categories of personal data unless required by law or explicitly necessary for a specific service.
- PURPOSE OF COLLECTION
We collect and process your personal data for the following purposes:
- to operate, maintain, and improve our Website and eLearning platforms;
- to respond to your enquiries, requests, and communications submitted via our Website or contact forms;
- to register you for, and administer your participation in, courses and training programmes;
- to create and manage your learner or customer account;
- to process orders, payments, and invoices and to fulfil our contractual obligations to you;
- to send you marketing communications, newsletters, and service updates where you have provided your consent or where we have a legitimate interest to do so;
- to analyse Website usage and improve user experience through analytics and performance monitoring;
- to ensure the security and integrity of our systems, platforms, and Website, including fraud prevention and access control;
- to comply with our legal and regulatory obligations, including obligations under applicable tax, anti-money laundering, and data protection law; and
- to establish, exercise, or defend legal claims in the event of a dispute.
- OUR LEGAL BASIS FOR PROCESSING YOUR PERSONAL INFORMATION
When we use your personal information, we are required to have a legal basis for doing so. There are various legal bases on which we may rely, depending on what personal information we process and why.
The legal bases we may rely on include:
Consent: Where you have given clear consent for us to process your personal information for a specific purpose. This includes where you:
- submit an enquiry or request through our “Contact Us” form;
- communicate with us through our online chat services;
- subscribe to receive newsletters, marketing communications, or other updates from us; or
- consent to the use of analytics, marketing, or other non-essential cookies on our website.
Where required by applicable law, IGA will obtain your consent before:
- sending you electronic marketing communications; and
- placing non-essential cookies or similar technologies on your device.
Where processing is based on your consent, you have the right to withdraw your consent at any time. Withdrawal of consent will not affect the lawfulness of any processing carried out prior to such withdrawal.
Performance of Contract: where such processing is necessary for the performance of a contract to which you are a party, or to take steps at your request prior to entering into a contract. This includes processing personal data when you register for one of our online courses or training programmes, purchase our services, or otherwise request that we provide services to you.
For these purposes, we may process your personal data to:
- provide training and eLearning services;
- register and manage your participation in courses and programmes;
- create and administer customer and learner accounts;
- administer and perform our contractual obligations;
- process orders, payments, and invoices;
- communicate with you regarding the services requested;
- provide customer and technical support; and
- take any other steps necessary to fulfil our agreement with you.
Legitimate interests: where the use of your personal data is necessary for our legitimate interests or the legitimate interests of a third party, provided that such interests are not overridden by your interests, fundamental rights, or freedoms.
In particular, we may process personal data for the following legitimate interests:
- maintaining and developing our business relationships;
- providing, maintaining, and improving our services, eLearning platforms, and website functionality;
- enhancing user experience, user interface design, and the overall performance of our website;
- ensuring the security, integrity, and proper operation of our systems, platforms, and website, including through the use of strictly necessary cookies and similar technologies;
- responding to enquiries, requests, and communications;
- preventing fraud, unauthorized access, misuse of our services, and other unlawful activities;
- promoting and marketing relevant business services to corporate representatives in their professional capacity, where permitted by applicable law; and
- establishing, exercising, or defending legal claims, as well as managing disputes, regulatory matters, and judicial or administrative proceedings.
Before relying on legitimate interests as a lawful basis for processing, we carefully assess and balance our interests against your rights and freedoms to ensure that your personal data is processed fairly and proportionately.
Right to Object: Where we process your personal data on the basis of our legitimate interests, you have the right to object to such processing at any time. If you wish to exercise this right, please contact us using the details provided in Section 15 (Contact Details) below. We will consider your objection and cease processing unless we can demonstrate compelling legitimate grounds that override your interests, or the processing is necessary for the establishment, exercise, or defence of legal claims.
- COMPLIANCE WITH LEGAL OBLIGATIONS
We may process your personal data where necessary to comply with a legal obligation applicable to us. This includes processing required to:
- comply with applicable tax, accounting, financial reporting, and record-keeping obligations;
- prevent, detect, and investigate fraud, money laundering, and other unlawful activities;
- comply with applicable laws, regulations, court orders, regulatory requirements, and industry standards; and
- respond to lawful requests, orders, or directions from public authorities, regulatory bodies, law enforcement agencies, courts, or other competent authorities.
Where processing is necessary to comply with a legal obligation, the provision of certain personal data may be mandatory. Failure to provide such information may prevent us from fulfilling our legal or regulatory obligations.
Sharing of Personal Data
We may disclose your personal data to third parties where necessary for the purposes described in this Privacy Notice, including to:
- competent regulatory authorities, supervisory bodies, courts, law enforcement agencies, and other public authorities where disclosure is required by law or is necessary for the establishment, exercise, or defence of legal claims;
- our professional advisers, including external legal counsel, auditors, accountants, educational consultants, and other professional service providers;
- third-party providers of information technology, cloud hosting, data storage, cybersecurity, website management, and other technical support services;
- payment processors, banking institutions, and billing service providers for the administration of payments and financial transactions;
- marketing, communications, analytics, and customer relationship management service providers acting on our behalf; and
- any other service providers, contractors, or business partners where disclosure is necessary for the provision of our services and the operation of our business.
All third parties that process personal data on our behalf are required to implement appropriate technical and organisational measures to protect personal data, maintain its confidentiality and security, and process it only in accordance with our instructions and applicable data protection legislation.
- TRANSFERS OF DATA OUTSIDE EU / EEA
Where your data is transferred to entities or other third parties whose headquarters or place of data processing is not located in a member state of the European Union or the European Economic Area, we ensure, before transferring the data, that one of the following conditions is met: (a) an appropriate level of data protection exists (e.g. through an adequacy decision of the European Commission or through suitable guarantees such as EU standard contractual clauses agreed between us and the recipient); or (b) you have provided sufficient consent to the transfer.
- SECURITY
Your personal data is processed in IGA office located in Malta. Hosting and storage of your data takes place on dedicated servers of our service providers located in the EU.
We have appropriate security measures in place to prevent personal information from being accidentally lost or used or accessed in an unauthorised way. These measures include, but are not limited to, access controls, encryption, and internal audit procedures. We limit access to your personal information to those who have a genuine business need to know it. Those processing your information will do so only in an authorised manner and are subject to a duty of confidentiality. We will notify you and any applicable regulator of a suspected data security breach where we are legally required to do so.
- YOUR RIGHTS
As a data subject, you may contact us at any time to make use of your rights, which are, the right to:
- receive information about the data processing and a copy of the processed data;
- demand the rectification of inaccurate data or the completion of incomplete data;
- demand the erasure of personal data;
- demand the restriction of the data processing;
- receive your personal data in a structured, commonly used, and machine-readable format and to request the transfer of that data to another controller in certain circumstances;
- object to the data processing;
- withdraw a given consent at any time to stop a data processing that is based on your consent;
- complain to a competent supervisory authority.
In response to such requests, we reserve the right to require the individual making the request to provide certain details about themselves so that we can validate that the individual is indeed the person to whom the data refers. We are required to respond to the request of the individual within 30 days and we will endeavour to do so wherever possible. Where a request is manifestly unfounded or excessive, we reserve the right to charge a reasonable fee or refuse to act on the request, in accordance with Article 12(5) of the GDPR.
Where a data subject chooses not to provide any personal data, or where any of the rights set out above are exercised to limit the processing of personal data, we may be unable to provide the relevant services, or there may be restrictions on the services which can be provided.
In certain circumstances your right of access may be lifted in whole or in part in accordance with the provisions of the Privacy Law:
- for purposes of proper fulfilment of our or the supervisory authorities’ duties, as these are derived from the Prevention of Money Laundering Act (Chapter 373 of the Laws of Malta) and any applicable anti-money laundering legislation (hereinafter referred to as the “AML Law”); or
- to avoid obstruction of official or legal inquiries, analyses, investigations or procedures for the purposes of the AML Law and to ensure that prevention, investigation and detection of money laundering and terrorist financing is not jeopardised.
Further, as per the GDPR, your right to erasure can also be lifted to the extent that processing is necessary:
- for exercising the right of freedom of expression and information;
- for compliance with a legal obligation which requires processing by Union or Member State law to which we are subject;
- for reasons of public interest in the area of public health in accordance with points (h) and (i) of Article 9(2) of the GDPR as well as Article 9(3) of the GDPR;
- for archiving purposes in the public interest, scientific or historical research purposes or statistical purposes in accordance with Article 89(1) of the GDPR in so far as the right referred to in paragraph 1 of Article 89 is likely to render impossible or seriously impair the achievement of the objectives of that processing; or
- for the establishment, exercise or defence of legal claims.
For further information on each of those rights, including the circumstances in which they apply, please contact us (see Section 15 ‘Contact Details’ below).
In the event that you wish to complain about how we have handled your personal data, you may contact us (see Section 15 ‘Contact Details’ below). We will then look into your complaint and work with you to resolve the matter.
If you still feel that your personal data has not been handled appropriately according to the law, you can submit your complaint to the Office of the Information and Data Protection Commissioner (IDPC), whose contact details are available at: https://idpc.org.mt.
- DATA RETENTION
Where IGA acts as a Data Processor
Where IGA acts as a data processor, personal data is retained in accordance with the data retention policy of the relevant corporate client. After the applicable retention period, your personal data will be irreversibly destroyed. Any personal data held by IGA for marketing, service update notifications, and requests for services or products will be retained until such time as you notify IGA that you no longer wish to receive such communications.
IGA will not retain personal data for longer than the relevant corporate client stipulates.
IGA will retain personal data for the duration of any contractual relationship with the relevant corporate client and, thereafter, for a period of 10 years to comply with applicable fiscal and statutory obligations. Where personal data is relevant to ongoing legal proceedings, it will be retained until those proceedings are finally resolved.
Where IGA acts as a Data Controller
Where IGA acts as a data controller,it will not retain your personal data for longer than is necessary to fulfil the purpose(s) for which it is processed. Any personal data held by IGA for marketing, service update notifications, and requests for services or products will be retained until such time as you notify IGA that you no longer wish to receive such communications.
IGA will retain your personal data for the duration of any contractual relationship you have with IGA and, thereafter, for a period of 10 years to comply with applicable fiscal and statutory obligations. Where personal data is relevant to ongoing legal proceedings, it will be retained until those proceedings are finally resolved.
Where you are a prospective customer and you have expressly consented to IGA contacting you, IGA will only retain your personal data: (a) until you unsubscribe from IGA communications; or, if you have not unsubscribed, (b) while you interact with IGA and IGA content; or (c) for 12 months from the date of your last interaction with IGA. In respect of any contact you may have with the IGA team, IGA will retain those details for as long as is necessary to resolve your query and for two weeks after the query is closed.
Where you are a service or product provider, IGA will retain your personal data for the duration of any contractual relationship you have with IGA and, thereafter, for a period of 10 years to comply with applicable fiscal and statutory obligations. Where personal data is relevant to ongoing legal proceedings, it will be retained until those proceedings are finally resolved.
Where you are a prospective service or product provider and you have expressly consented to IGA contacting you, IGA will retain your personal data: (a) until you unsubscribe from IGA communications; or (b) for 24 months from the date of your last interaction with IGA. In respect of any contact you may have with the IGA team, IGA will retain those details for as long as is necessary to resolve your query and for two weeks after the query is closed.
- COOKIES
We use cookies and similar technologies to:
- ensure the proper functionality, security, and performance of our Website;
- enhance and improve the user experience;
- analyse Website traffic, usage patterns, and performance;
- remember users’ preferences and settings; and
- support analytics and marketing activities.
Strictly necessary cookies are used to enable the operation and security of the Website and do not require your consent. All non-essential cookies, including analytics, functionality, and marketing cookies, are deployed only after obtaining your consent through our cookie consent management platform.
You may manage, modify, or withdraw your cookie preferences at any time through our cookie management tools or by adjusting your browser settings. Please note that disabling certain cookies may affect the functionality and performance of the Website.
For further information regarding our use of cookies and similar technologies, including the types of cookies we use and their purposes, please refer to our Cookie Policy Cookie Policy | iGaming Academy.
- PERSONAL DATA BREACHES
IGA maintains procedures for identifying, investigating, and responding to personal data breaches.
Where a personal data breach is unlikely to result in a risk to the rights and freedoms of natural persons, IGA is not required to notify the competent supervisory authority, but must document the breach internally in accordance with Article 33(5) GDPR. Where the personal data breach is likely to result in a risk to the rights and freedoms of natural persons, IGA shall notify the competent supervisory authority without undue delay and, where feasible, within 72 hours after becoming aware of the breach.
Where a breach is likely to result in a high risk to the rights and freedoms of individuals, affected individuals shall also be notified without undue delay, unless one of the exceptions under Article 34(3) GDPR applies (e.g. appropriate technical measures rendered the data unintelligible, or subsequent measures have been taken to ensure the high risk is no longer likely to materialise).
- CONTACT DETAILS
Data Protection Officer
If you have any questions regarding this Privacy Notice or the processing of your personal data, please contact:
Data Protection Officer
Email: dpo@igacademy.com
- CHANGES OF THIS PRIVACY NOTICE
IGA may update this Privacy Notice from time to time to reflect changes in legal, regulatory, operational, or technical requirements. We will notify you of any material changes where required by law.
The latest version of this Privacy Notice will always be made available on our website. This Privacy Notice was last reviewed on 8 July 2026.
- GOVERNING LAW
This Privacy Notice shall be governed by and construed in accordance with the laws of the Republic of Malta and applicable European Union data protection legislation.
In the event of any conflict between this Privacy Notice and applicable law, the applicable law shall prevail.
