Privacy & Cookies Policy
This policy explains which personal data we process when you visit offset-list.com or contact us, the legal basis on which we do so, how long we keep the data, who we share it with and what rights you have. We process personal data in accordance with the General Data Protection Regulation (GDPR / EU 2016/679) and, for cookies, the Dutch Telecommunications Act. We do not sell personal data. This English text is a translation provided for convenience; the Dutch version is the binding one.
Offset List is an independent information website. We are not a gambling operator and we do not process deposits, wagers or player accounts. Payments and player records held by operators are governed by their own privacy statements.
1. Data controller
The data controller within the meaning of Article 4(7) GDPR for the processing of personal data through this website is:
- OPTIMAL INVEST s.r.o., operator of offset-list.com
- Address: Štichova 647/38, Háje, 149 00 Prague 4, Czech Republic
- Company registration number (IČO): 28193679
- VAT number: CZ28193679
- E-mail: [email protected]
You may use the e-mail or postal address above for any question about this policy or about the processing of your personal data. We are not required to appoint a data protection officer under Article 37 GDPR and have not appointed one; privacy requests are handled at [email protected].
2. Personal data we process
We process only the categories of data listed below. We do not request and do not knowingly process special categories of personal data within the meaning of Article 9 GDPR, such as health or biometric data.
- Technical data in server logs: IP address, date and time of the request, requested URL, HTTP status code, volume of data transferred, browser type and version, operating system and, where sent by your browser, the referring page.
- Local storage on your device: your age confirmation and your cookie choice (accept or reject). These values are held in the local storage and session storage of your own browser.
- Contact data: your e-mail address, the content of your message and any details you include in it, when you contact us by e-mail or through the contact form.
- Statistical data: only if you consent through the cookie banner, aggregated usage statistics on pages viewed and session duration.
3. Purposes, legal bases and retention periods
We process personal data only for the purposes set out below, on the legal basis stated in each case under Article 6(1) GDPR, and for no longer than the period stated.
- Providing and technically operating the website (serving requests, displaying pages). Legal basis: legitimate interests, Article 6(1)(f) GDPR — our interest in a functioning, available website. Retention: server logs are rotated daily and automatically deleted after a maximum of 30 days; in practice we keep 14 days of log files.
- Security, fraud and abuse prevention (detecting attacks, spam and automated abuse). Legal basis: legitimate interests, Article 6(1)(f) GDPR — our interest in network and information security. Retention: the same period as above (maximum 30 days); only log entries relating to a specific incident are kept for the duration of the investigation, up to a maximum of 6 months.
- Age verification (18+) and recording your cookie choice. Legal basis: legitimate interests, Article 6(1)(f) GDPR, and for the storage itself the strictly-necessary exemption; we are moreover required to prevent minors from being exposed to gambling-related advertising. Retention: the age confirmation expires when you close the browser tab (session storage); your cookie choice is kept for a maximum of 12 months or until you clear site data in your browser.
- Answering your question or report. Legal basis: legitimate interests, Article 6(1)(f) GDPR — your interest and ours in receiving a substantive reply to your own enquiry. Retention: up to 12 months after the last correspondence, unless longer retention is necessary to handle a complaint or dispute.
- Analytics on the use of the guide. Legal basis: your consent, Article 6(1)(a) GDPR (and Article 11.7a of the Dutch Telecommunications Act). We place no analytics cookies unless you click "Akkoord" (Accept). Retention: analytics cookies have a lifetime of no more than 13 months; aggregated statistics that cannot be linked to an individual may be kept longer.
- Complying with legal obligations (for example keeping records or responding to a lawful request from a competent authority). Legal basis: legal obligation, Article 6(1)(c) GDPR. Retention: the period prescribed by the applicable law.
Once a retention period ends, the data is deleted or irreversibly anonymised. Where a statutory retention obligation prevents deletion, we restrict processing of that data to the purpose of that obligation alone.
4. Are you obliged to provide data?
You are under no statutory or contractual obligation to provide us with personal data. Processing technical data in server logs is technically unavoidable on any website visit. Providing your e-mail address and message is entirely voluntary; the only consequence of not providing it is that we cannot answer your question. Refusing analytics cookies has no effect whatsoever on your access to or use of the site.
5. Recipients of your personal data
We do not sell, rent or trade personal data. We do not use contact details to encourage you to gamble and we do not share them with operators as a marketing list. Your data may be processed by the following categories of recipients:
- Hosting and infrastructure provider: processes server logs and supplies the storage and server capacity on which the website runs. The server is located in the United States; see section 6 for the safeguards we apply.
- E-mail and domain services provider: processes the content of e-mail correspondence you send us.
- Security, anti-spam and network service providers (including any CDN or DDoS protection): process traffic data such as the IP address in order to repel attacks.
- Web analytics provider: only if you have consented to analytics cookies.
- External advisers (legal, accounting) and competent authorities: only where required by law or necessary for the establishment, exercise or defence of legal claims.
All these parties act as processors solely on our instructions and under a data processing agreement pursuant to Article 28 GDPR, subject to confidentiality and to an obligation to apply appropriate security measures. On request we will tell you the identity of the processors engaged at that time.
Operators we link to are independent controllers with their own privacy statements, which apply as soon as you visit their website. We do not ourselves transmit personal data to the operator when you click through: your browser connects to their domain directly, which is how the operator receives your IP address and browser data. Measurement of affiliate click-throughs takes place on their domain and under their responsibility.
6. Transfers outside the EEA
Yes, transfers do take place. The web server on which offset-list.com runs is located in the United States (data centre in the State of New York). This means that the technical data in our server logs — including your IP address — is processed in a country outside the European Economic Area (EEA). E-mail you send us may likewise be processed by a service provider outside the EEA. We do not transfer personal data to international organisations.
For these transfers we rely on the safeguards of Chapter V GDPR:
- the European Commission's adequacy decision of 10 July 2023 on the EU-US Data Privacy Framework (Article 45 GDPR), to the extent that the service provider concerned is certified under that framework; and
- in all other cases, the Standard Contractual Clauses adopted by the European Commission (Article 46(2)(c) GDPR), supplemented by technical and organisational measures such as encryption in transit (TLS), strict data minimisation and short retention periods, following an assessment of the level of protection in the country concerned (transfer impact assessment).
Please note that the level of data protection in the United States may differ from that in the European Union and that US public authorities may, under certain conditions, require access to data. You may request a copy of, or further information about, the safeguards applied free of charge at [email protected].
Please note: when you click through to an operator or another external website, you leave our site. Any transfer of data by that party falls outside our responsibility and is governed by their own privacy statement.
7. Cookies and local storage
We use strictly necessary storage to make the age check and your cookie choice work; no consent is required for this. We place analytics or other non-essential cookies only after you have clicked "Akkoord" (Accept) in the cookie banner, and you may withdraw that consent at any time. We do not place third-party advertising or tracking cookies for behavioural advertising. A full overview of the cookies used, their purpose and their lifetime is set out in our cookie policy.
8. Security of your data
We take appropriate technical and organisational measures within the meaning of Article 32 GDPR to protect personal data against loss, misuse and unauthorised access. These include encrypted connections (TLS/HTTPS) for all traffic with this website, restricted and individually attributable access to data on a need-to-know basis, up-to-date server software, and minimising the data we collect. No transmission over the internet is entirely without risk; in the event of a data breach likely to result in a high risk to your rights and freedoms we will inform you in accordance with Article 34 GDPR and notify the supervisory authority.
9. Your rights under the GDPR
As a data subject you have the following rights against us:
- Right of access (Article 15 GDPR): to find out whether we process personal data about you and, if so, to receive a copy together with information about the processing.
- Right to rectification (Article 16 GDPR): to have inaccurate data corrected and incomplete data completed.
- Right to erasure / "right to be forgotten" (Article 17 GDPR): to have your data deleted where it is no longer necessary, where you withdraw consent or where you successfully object.
- Right to restriction of processing (Article 18 GDPR): to have processing suspended temporarily, for instance while the accuracy of data is being verified.
- Right to data portability (Article 20 GDPR): to receive the data you provided to us and which we process by automated means on the basis of consent or a contract, in a structured, commonly used and machine-readable format, or to have it transmitted directly to another controller.
- Right to object (Article 21 GDPR): on grounds relating to your particular situation, to object to processing we base on legitimate interests (Article 6(1)(f) GDPR), including our server logs and security processing. You may object to direct marketing at any time and without giving reasons.
- Right to withdraw consent (Article 7(3) GDPR): to withdraw your consent to analytics cookies at any time, without affecting the lawfulness of processing carried out before the withdrawal.
- Right to lodge a complaint with a supervisory authority (Article 77 GDPR), see below.
How to exercise your rights: send a request to [email protected] or by post to the address given in section 1. We respond free of charge and no later than one month after receipt of your request; where requests are complex or numerous, that period may be extended by up to two further months, in which case we will inform you within the first month (Article 12(3) GDPR). We may ask for additional information where we have reasonable doubts as to your identity (Article 12(6) GDPR); that information is used solely for verification.
Withdrawing your cookie consent: clear the site data (local storage and cookies) for offset-list.com in your browser settings. The cookie banner will then reappear so you can make a new choice, whether you previously chose "Akkoord" (Accept) or "Weigeren" (Reject).
10. Complaint to a supervisory authority
If you consider that we process your personal data in breach of the GDPR, you have the right under Article 77 GDPR to lodge a complaint with a supervisory authority, in particular in the Member State of your habitual residence, place of work or of the alleged infringement. We would appreciate it if you contacted us first, but this is not a precondition.
Given our establishment in the Czech Republic, our lead supervisory authority is:
- Úřad pro ochranu osobních údajů (Czech Data Protection Authority)
- Pplk. Sochora 27, 170 00 Prague 7, Czech Republic
- Telephone: +420 234 665 111 · E-mail: [email protected]
- Website: uoou.gov.cz
If you live in the Netherlands, you may also lodge your complaint with the Dutch supervisory authority:
- Autoriteit Persoonsgegevens
- Postbus 93374, 2509 AJ The Hague, Netherlands
- Telephone: +31 (0)88 1805 250
- Website: autoriteitpersoonsgegevens.nl
If you live in another EU or EEA Member State, you may contact the supervisory authority of your country; a list is available on the website of the European Data Protection Board.
11. No automated decision-making or profiling
We do not use automated decision-making, including profiling, that produces legal effects concerning you or similarly significantly affects you (Article 22 GDPR). We do not build profiles to predict your behaviour and we do not use your data to show you personalised gambling offers.
12. Minors
This website is intended solely for persons aged 18 or over. We do not knowingly collect personal data from persons under 18. If we discover that we have nevertheless received data from a minor, we delete it as soon as possible. If you are a parent or guardian and believe a minor has provided us with data, please contact [email protected].
13. Links to third-party websites
Our site contains links to operators' websites and to support organisations. We are not responsible for the content or the privacy practices of those websites. As soon as you open an external site, their privacy and cookie statements apply. Please read them before providing personal data there.
14. Changes to this policy
We may amend this policy when our processing activities, our service providers or the applicable law change. The current version is always available on this page, with the version number and date of last amendment shown at the top. Where changes materially affect your rights, we will post a clear notice on the website and, where required, ask for your consent again.