Mega Medusa Casino

Aussie Player Welcome: 4000€ + 300 FS

Activate Now

Mega Medusa Casino Privacy Policy

Navigation

At Mega Medusa Casino, we understand that privacy is not merely a legal obligation — it is the foundation of the trust you place in us every time you log in, deposit funds, or spin a reel. The Mega Medusa Casino privacy policy has been carefully drafted to comply with the Australian Privacy Act 1988 (Cth), the Australian Privacy Principles (APPs), and, where applicable, the General Data Protection Regulation (GDPR). This document explains exactly what personal data we collect, why we collect it, how we protect it, and what rights you hold as an Australian player. We encourage you to read this page in full before creating an account so you can make an informed decision about your personal information.

1. Identity of the Data Controller

Mega Medusa Casino is operated by a company registered in Curaçao and licensed by the Government of Curaçao. For all matters relating to data protection and the handling of your user data, this operating entity acts as the data controller — meaning it determines the purposes and means of processing your information. Our official website operates under the domain megamedusaau.com. If you have any questions about how we handle your personal information, please contact us directly via the details provided in the Data Protection Officer section below.

2. Personal Data We Collect

As part of registering and using Mega Medusa Casino, we engage in comprehensive data collection to deliver a safe, compliant, and enjoyable gaming experience. The categories of personal data we may collect include:

2.1 Identification Data

  • Full legal name and date of birth
  • Gender and nationality
  • Government-issued identification documents (passport, driver's licence, national ID card)
  • Selfie or biometric verification image submitted during Know Your Customer (KYC) checks

2.2 Contact Data

  • Email address (e.g., the address you registered with)
  • Residential address, city, state/territory, postcode, and country
  • Phone number (mobile or landline)

2.3 Financial Data

  • Payment method details (partial card numbers, e-wallet identifiers, cryptocurrency wallet addresses)
  • Transaction history including deposits, withdrawals, and bonus usage
  • Source of funds declarations, where required under anti-money laundering (AML) obligations
  • Bank statements or proof-of-income documents submitted at our request

2.4 Gaming Activity Data

  • Game sessions, betting history, wagering amounts, and outcomes
  • Bonus activations, free spin usage, and VIP programme tier history
  • Responsible gambling settings (deposit limits, loss limits, session limits, self-exclusion status)
  • Interaction records with live dealer tables and tournament participation

2.5 Technical and Device Data

  • IP address, browser type and version, operating system, and device type
  • Session timestamps, login history, and geolocation data
  • Cookie identifiers and similar tracking technologies (see our cookie policy below)
  • Mobile device identifiers when using our Android APK or iOS PWA

2.6 Communication Data

  • Live chat transcripts with our support team
  • Email correspondence sent to or received from [email protected]
  • Records of promotional communications you have opted into or out of

2.7 Sensitive Data

On occasion, and only when strictly necessary, Mega Medusa Casino may process sensitive information such as health-related data disclosed during responsible gambling interactions. We handle such data with the highest degree of confidentiality and will never use it for marketing or profiling purposes.

2.8 Data from Third Parties

We may receive personal information about you from third-party sources, including payment processors, identity verification services, fraud prevention agencies, and marketing affiliates. Any user data received from third parties is incorporated into your account record and treated in accordance with this privacy policy.

3. Methods of Data Collection

The Mega Medusa Casino data collection process operates through several distinct channels:

  • Registration form: You provide identification and contact details when creating an account.
  • KYC verification: You submit documents and biometric information to satisfy legal identity checks before your first withdrawal.
  • Deposit and withdrawal transactions: Financial information is captured whenever you move funds to or from your account.
  • Gameplay: Our systems automatically log all gaming sessions and results.
  • Cookies and tracking technologies: Our website places cookies in your browser to improve functionality and analyse usage patterns.
  • Customer support interactions: All conversations are recorded for quality assurance and compliance.
  • Third-party partners: Affiliates and verification providers may share data with us when you arrive at our site via their platforms.

4. Purposes of Data Processing

The data processing activities carried out by Mega Medusa Casino serve the following specific and legitimate purposes:

Purpose Description
Account Management Creating and maintaining your player account, processing login sessions, and managing profile updates.
Service Provision Delivering our 4,000+ game catalogue, processing deposits (minimum A$20) and withdrawals (minimum A$30), and operating payment methods including PayID, Visa, Mastercard, Skrill, Neteller, cryptocurrency and more.
Legal and Regulatory Compliance Fulfilling KYC and AML obligations mandated by our Curaçao gaming licence, verifying age and identity, and reporting suspicious transactions to competent authorities.
Fraud Prevention and Security Detecting and preventing unauthorised account access, bonus abuse, money laundering, and other fraudulent activities that could compromise data security.
Responsible Gambling Monitoring gaming behaviour to identify problem gambling indicators and enforcing cooling-off periods, session limits, and self-exclusion requests.
Marketing and Communication Sending promotional emails, bonus notifications, and personalised offers — only where you have given explicit consent.
Analytics and Improvement Analysing aggregate gameplay and website usage data to refine our platform, improve game performance, and develop new features for Australian players.
VIP Programme Management Administering the five-tier loyalty programme (Bronze, Silver, Gold, Platinum, Diamond) and managing cashback rewards between 10% and 20%.

5. Legal Basis for Data Processing

Under both the Australian Privacy Act 1988 and the GDPR (where applicable to European visitors), Mega Medusa Casino relies on the following legal bases for data processing:

  • Contractual necessity: Processing your personal data is necessary to perform the contract between us (i.e., the Terms and Conditions you accepted at registration).
  • Legal obligation: Certain processing activities — including KYC verification and AML reporting — are required by law and cannot be avoided.
  • Legitimate interests: We process some user data to prevent fraud, ensure platform security, and improve our services, provided these interests do not override your fundamental rights.
  • Consent: For marketing communications, behavioural profiling, and certain non-essential cookies, we process your data only where you have given us clear, informed, and freely given consent. You may withdraw consent at any time.

6. Cookie Policy

The Mega Medusa Casino cookie policy governs how we use small text files — known as cookies — that are stored in your browser when you visit megamedusaau.com. Cookies allow us to recognise returning visitors, remember your preferences, and gather analytical insights. Below is a breakdown of the cookie categories we use:

6.1 Essential Cookies

These cookies are strictly necessary for the website to function. They manage your login session, keep your shopping basket active (in this case, your game lobby selections), and maintain security tokens. Essential cookies cannot be disabled without breaking core site functionality.

6.2 Analytical Cookies

Analytical cookies help us understand how players interact with our platform. We use these to measure traffic, identify popular games, and track user journeys through the site. The resulting data is aggregated and anonymised where possible so that individual players cannot be identified. This type of data collection allows us to continuously improve the player experience.

6.3 Functional Cookies

Functional cookies remember your preferences — such as your chosen language, preferred currency display, or previously selected game filters — so that you do not have to reset them on every visit. These cookies enhance personalisation and convenience.

6.4 Marketing Cookies

Marketing cookies are placed by us or by trusted third-party advertising partners to deliver relevant promotional content based on your interests and browsing behaviour. These cookies may track your activity across other websites. You can opt out of marketing cookies at any time through our cookie preference centre or your browser settings.

By continuing to use megamedusaau.com without changing your browser settings, you consent to our use of cookies as described in this cookie policy. A cookie banner is displayed on your first visit, giving you granular control over non-essential categories.

7. Sharing Your Personal Data with Third Parties

Mega Medusa Casino values your confidentiality and does not sell your personal information to unaffiliated third parties for their own marketing purposes. However, we do share user data in the following circumstances:

7.1 Payment Processors and Financial Partners

To facilitate deposits and withdrawals via PayID, Visa, Mastercard, Skrill, Neteller, Paysafecard, Neosurf, Bitcoin, Ethereum, Litecoin, and bank transfer, we must share necessary financial details with licensed payment service providers. These providers process your data under their own privacy policy and are contractually bound to maintain appropriate information security standards.

7.2 Identity Verification and KYC Providers

Before your first withdrawal, Mega Medusa Casino requires mandatory KYC verification. We share identification documents and biometric data with specialised third-party verification services that operate under strict data protection agreements and applicable law.

7.3 Regulatory and Law Enforcement Authorities

We may disclose personal data to government agencies, law enforcement bodies, or regulators — including the Curaçao Gaming Authority — where required by law, court order, or regulatory directive. Such disclosures are made in good faith and limited to what is strictly necessary.

7.4 Game Providers and Software Partners

Aggregated or pseudonymised gameplay data may be shared with game providers such as Pragmatic Play, Evolution Gaming, Play'n GO, NetEnt, Microgaming, Yggdrasil, Hacksaw Gaming, Push Gaming, Spribe, Red Tiger, Nolimit City, and Relax Gaming for the purpose of RNG certification, game analytics, and jackpot management. These partners do not receive directly identifying personal information.

7.5 Marketing Affiliates

If you arrived at Mega Medusa Casino via an affiliate link, we may share limited tracking data (such as your registration confirmation) with the referring affiliate for commission purposes. No sensitive personal data is shared in this context.

7.6 Group Companies

Where applicable, personal data may be shared within the corporate group that operates Mega Medusa Casino for internal administrative, compliance, and support functions, always under strict data protection safeguards.

8. International Data Transfers

Because Mega Medusa Casino is operated from Curaçao and uses third-party providers based in various countries, your personal data may be transferred to, stored in, or processed in jurisdictions outside Australia. Some of these jurisdictions may not offer the same level of data protection as Australian law. Where this occurs, we take the following safeguards:

  • We enter into Standard Contractual Clauses or equivalent data transfer agreements with recipients.
  • We conduct transfer impact assessments to ensure adequate protection is maintained.
  • We only transfer user data to recipients that have implemented appropriate technical and organisational information security measures.
  • Where GDPR applies, transfers are governed by Chapter V of the GDPR and its associated mechanisms.

9. Data Security at Mega Medusa Casino

Mega Medusa Casino data security is treated as a top operational priority. We implement a multi-layered security framework designed to protect your personal information from unauthorised access, disclosure, alteration, or destruction. Key security measures include:

9.1 Encryption

All data transmitted between your device and our servers is encrypted using 256-bit SSL/TLS technology — the same standard used by major financial institutions worldwide. This means your login credentials, financial transactions, and personal data are protected during transit at all times.

9.2 Firewalls and Intrusion Detection

Our infrastructure is protected by enterprise-grade firewalls and intrusion detection systems (IDS) that continuously monitor for suspicious activity. Any anomalous behaviour is flagged and investigated by our security team in real time.

9.3 Data Storage Security

Regarding data storage, all records containing personal information are held on secured servers with restricted access controls. Only authorised personnel who require the data to fulfil their job responsibilities may access it, and all access is logged and audited regularly. Mega Medusa Casino conducts periodic penetration testing and vulnerability assessments to identify and remediate security weaknesses before they can be exploited.

9.4 RNG Certification

Our Random Number Generator (RNG) has been independently certified by accredited testing laboratories, confirming the fairness and integrity of all game outcomes. While RNG certification is primarily about fairness, it also demonstrates our commitment to operating a trustworthy, transparent platform where user data and gaming outcomes are beyond manipulation.

9.5 Staff Training and Access Controls

All employees and contractors with access to personal data undergo mandatory data protection training. Role-based access controls ensure that staff members can only view the personal information necessary for their specific duties, reducing the risk of internal data breaches and reinforcing confidentiality across the organisation.

10. Data Retention Periods

We do not retain your personal data indefinitely. Mega Medusa Casino applies the following retention schedule based on the nature of the data and the legal requirements that govern it:

Data Category Retention Period Reason
Account registration data Duration of account + 5 years after closure AML and regulatory obligations
KYC and identity documents 5–7 years after account closure Legal and compliance requirements
Financial transaction records 7 years Tax and financial record-keeping laws
Gaming session logs 5 years Dispute resolution and auditing
Customer support communications 3 years Quality assurance and legal reference
Marketing consent records Until consent is withdrawn + 1 year Evidence of lawful data processing
Cookie and analytics data Up to 24 months Platform analytics and optimisation

Following the expiry of the applicable retention period, your personal data will be securely deleted or anonymised so that it can no longer identify you as an individual. Data storage beyond these periods only occurs where required by law or in connection with an unresolved legal dispute.

11. Your Privacy Rights Under Australian Law

The Mega Medusa Casino privacy rights framework is aligned with the Australian Privacy Principles as set out in the Privacy Act 1988. As an Australian player, you are entitled to exercise the following rights in relation to your personal data:

11.1 Right of Access

You have the right to request a copy of the personal information we hold about you. Mega Medusa Casino will respond to access requests within 30 days. In limited circumstances (such as where disclosure would affect third-party privacy), we may redact portions of the data provided.

11.2 Right of Correction

If any personal data we hold is inaccurate, out of date, incomplete, or misleading, you have the right to request correction. We will process correction requests promptly and, where appropriate, notify third parties to whom the incorrect information was previously disclosed.

11.3 Right to Deletion

In certain circumstances, you may request that we delete your personal information — for example, if the data is no longer necessary for the purpose for which it was collected, or if you withdraw consent and there is no overriding legal basis for continued processing. Note that deletion requests may not be fulfilled where retention is required by law or for the establishment, exercise, or defence of legal claims.

11.4 Right to Restriction of Processing

You may request that we restrict the data processing of your information in cases where you contest its accuracy, where processing is unlawful, or where you have objected to processing pending verification of our legitimate interests.

11.5 Right to Data Portability

Where data processing is based on your consent or contractual necessity, and the processing is carried out by automated means, you have the right to receive your personal data in a structured, commonly used, machine-readable format and to transmit it to another controller.

11.6 Right to Object

You have the right to object at any time to data processing carried out on the basis of our legitimate interests, including profiling for marketing purposes. Where you object to direct marketing, we will cease processing your data for that purpose without delay.

11.7 Right to Withdraw Consent

Where Mega Medusa Casino processes your personal data on the basis of your consent (e.g., for marketing emails or non-essential cookies), you have the right to withdraw that consent at any time without affecting the lawfulness of processing carried out prior to withdrawal.

To exercise any of your privacy rights, please contact our Data Protection Officer at [email protected]. We will acknowledge your request within 5 business days and aim to resolve it within 30 days. In complex cases, we may require up to 60 days, in which case we will notify you of the extension.

12. Responsible Gambling and Data Processing

Mega Medusa Casino is committed to promoting responsible gambling among all Australian players. As part of this commitment, we process certain personal data — including betting patterns, session durations, and self-declared financial limits — to identify signs of problematic gambling behaviour. This data processing activity serves both a legal obligation and a genuine social responsibility.

Players can set deposit limits, bet limits, loss limits, and session time limits directly in their account dashboard. Cooling-off periods are available for 24 hours, 48 hours, 7 days, or 30 days. For more serious concerns, self-exclusion can be imposed for 6 months, 1 year, 5 years, or permanently. During any active self-exclusion period, Mega Medusa Casino will not process your account for gaming activity, and marketing communications will be suspended immediately. All responsible gambling data is treated with the strictest confidentiality.

13. Supervisory Authority — OAIC

If you believe that Mega Medusa Casino has failed to comply with this privacy policy or the Australian Privacy Principles, you have the right to lodge a complaint with the Office of the Australian Information Commissioner (OAIC). The OAIC is Australia's independent national regulator for privacy and freedom of information.

  • Website: www.oaic.gov.au
  • Phone: 1300 363 992
  • Post: GPO Box 5218, Sydney NSW 2001

We encourage you to contact us in the first instance at [email protected], as many concerns can be resolved directly and quickly. However, your right to contact the OAIC remains unconditional, and we fully support this process as part of our accountability obligations under Australian law.

For European Union players who believe their rights under the GDPR have been infringed, you also have the right to lodge a complaint with the data protection supervisory authority in your EU member state.

14. Data Protection Officer

Mega Medusa Casino has appointed a dedicated Data Protection Officer (DPO) responsible for overseeing compliance with this privacy policy and applicable data protection law. The DPO acts as your primary point of contact for all matters relating to information security, privacy rights, and personal data requests.

Contact details for the Data Protection Officer:

  • Email: [email protected]
  • Postal address: Data Protection Officer, Mega Medusa Casino, c/o Registered Office, Curaçao
  • Response time: Within 5 business days for initial acknowledgement; full resolution within 30 days

15. Changes to This Privacy Policy

We reserve the right to update or amend this Mega Medusa Casino privacy policy at any time to reflect changes in our data practices, operational requirements, or applicable law. When we make material changes, we will notify registered players via email to the address on file and display a prominent notice on the megamedusaau.com homepage for at least 14 days before the changes take effect.

We recommend that you revisit this page periodically to stay informed about how Mega Medusa Casino protects your personal information. The date of the most recent revision will always be displayed at the bottom of this page. Continued use of our services after the effective date of any changes constitutes your acceptance of the revised privacy policy.

16. Frequently Asked Questions — Privacy at Mega Medusa Casino

What personal data does Mega Medusa Casino collect?

Mega Medusa Casino data collection spans several categories: identification data (name, date of birth, ID documents), contact data (email, address, phone), financial data (payment method details, transaction history), gaming activity data, technical data (IP address, device type, cookies), and communication records. Full details are set out in Section 2 of this privacy policy.

How does Mega Medusa Casino protect my personal information?

We protect your personal data through a combination of 256-bit SSL/TLS encryption, firewalls, intrusion detection systems, role-based access controls, regular penetration testing, and mandatory staff data protection training. Our approach to data security meets or exceeds industry standards for online gaming platforms. The Mega Medusa Casino data security framework is reviewed and updated on a continuous basis.

Can I opt out of marketing emails?

Yes. If you have opted into marketing communications from Mega Medusa Casino, you may withdraw that consent at any time by clicking the "unsubscribe" link at the bottom of any promotional email, by updating your notification preferences in your account settings, or by emailing [email protected]. Your privacy rights in this regard will be honoured promptly.

How long does Mega Medusa Casino keep my data?

Data storage at Mega Medusa Casino follows a structured retention schedule aligned with our legal obligations. KYC documents are typically retained for 5–7 years after account closure. Financial transaction records are kept for 7 years. Gaming session logs are stored for 5 years. Marketing consent records are held until consent is withdrawn, plus one additional year. Full details are provided in Section 10 of this privacy policy.

What cookies does Mega Medusa Casino use?

The Mega Medusa Casino cookie policy covers four categories: essential cookies (required for basic site function), analytical cookies (used to understand site usage), functional cookies (used to remember your preferences), and marketing cookies (used to deliver relevant promotions). You can manage your cookie preferences via our cookie consent banner or your browser settings.

How do I request access to my personal data?

To exercise your right of access under the Australian Privacy Act 1988 or GDPR, simply email our Data Protection Officer at [email protected] with a clear description of the information you seek. We will acknowledge your request within 5 business days and provide the requested data within 30 days. We may ask you to verify your identity before processing the request to ensure confidentiality.

Does Mega Medusa Casino sell my personal information?

No. Mega Medusa Casino does not sell, rent, or trade your personal information to unaffiliated third parties for commercial purposes. Your user data is shared only in the circumstances described in Section 7 of this privacy policy — that is, with payment processors, verification providers, regulatory authorities, game providers, and marketing affiliates — all under strict data protection agreements.

What is the OAIC and how can it help me?

The Office of the Australian Information Commissioner (OAIC) is the independent regulator that oversees privacy compliance in Australia. If you are unsatisfied with how Mega Medusa Casino has handled your complaint or privacy rights request, you may contact the OAIC at www.oaic.gov.au or on 1300 363 992. We are fully committed to cooperating with any OAIC investigation as part of our data protection obligations.

This page was last updated in accordance with the current Mega Medusa Casino privacy policy and reflects our ongoing commitment to information security, responsible data processing, and the protection of every Australian player's personal data and privacy rights. For questions, contact us anytime at [email protected].