Privacy Policy v.3
Last updated on: Thursday, 24/05/2018 - 06:00 PDT
Pinnacle (otherwise referred to herein as "we" or "us") adheres to the Personal Data Protection Act of Curacao (2013) and the EU Electronic Communications Privacy Directive (EC Directive/2002/58/EC as amended by the Directive 2009/136/EC) and the EU General Data Protection Regulation (GDPR). This Privacy Policy is issued on behalf of the Pinnacle Group of companies which includes the URL www.pinnacle.com.
The data controllers for the URL Pinnacle.com are Pinbet Malta Limited, Level 4, The Penthouse, Suite 2, Ewropa Business Centre, Triq Dun Karm, Birkirkara, BKR9034 Malta, and Ragnarok Corporation N.V., Pletterijweg 43, Willemstad, Curaçao.
Our Data Protection Officer (“DPO”) can be contacted at dpo@pinnacle.com.
If you have any questions about this Privacy Policy please contact the DPO. We understand that privacy and the security of your personal information is extremely important. This policy sets out what we do with your information and what we will do to keep it secure. It also explains where and how we collect your personal information, as well as your rights over any personal information we hold about you.
Changes to the privacy notice and your duty to inform us of changes
This version was last updated on May 24, 2018 and historic versions can be obtained by contacting the DPO.
It is important that the personal data we hold about you is accurate and current. Please keep us informed if your personal data changes during your relationship with us.
1. How we use your data
We will only use your personal data when the law allows us to. Most commonly, we will use your personal data in the following circumstances:
  • Where we need to perform the contract we are about to enter into or have entered into with you.
  • Where it is necessary for our legitimate interests (or those of a third party) and your interests and fundamental rights do not override those interests.
  • Where we need to comply with a legal or regulatory obligation.
Generally we do not rely on consent as a legal basis for processing your personal data other than in relation to sending direct marketing communications to you via email, phone, post or text message, if and when applicable. You have the right to withdraw consent to marketing at any time by contacting us at customerservice@pinnacle.com.
By providing your personal information and registering with us or logging on with us when you enter our Website, you explicitly consent to us processing and disclosing your personal information in the manner set out in this Privacy Policy, or as otherwise provided in accordance with the Terms & Conditions.
Third-party links
This website may include links to third-party websites, plug-ins and applications. Clicking on those links or enabling those connections may allow third parties to collect or share data about you. We do not control these third-party websites and are not responsible for their privacy statements. When you leave our website, we encourage you to read the privacy notice of every website you visit.
2. The data we collect about you
Personal data (or personal information) means any information about an individual from which that person can be identified. It does not include data where the identity has been removed (anonymous data).
We may collect, use, store and transfer different kinds of personal data about you which we have grouped together as follows:
  • Identity Data includes first name, maiden name, last name, username or similar identifier, date of birth and gender.
  • Contact Data includes billing address, delivery address, email address and telephone numbers.
  • Financial Data includes bank account and payment card details.
  • Transaction Data includes details about payments to and from you and other details of products and services you have purchased from us.
  • Technical Data includes internet protocol (IP) address, pc tag, your login data, browser type and version, time zone setting and location, browser plug-in types and versions, operating system and platform and other technology on the devices you use to access this website.
  • Profile Data includes your username and password, purchases or orders made by you, your interests, preferences, correspondence feedback and survey responses.
  • Usage Data includes information about how you use our website, products and services.
  • Marketing and Communications Data includes your preferences in receiving marketing from us and our third parties and your communication preferences.
We also collect, use and share Aggregated Data such as statistical or demographic data for any purpose. Aggregated Data may be derived from your personal data but is not considered personal data in law as this data does not directly or indirectly reveal your identity. For example, we may aggregate your Usage Data to calculate the percentage of users accessing a specific website feature. However, if we combine or connect Aggregated Data with your personal data so that it can directly or indirectly identify you, we treat the combined data as personal data which will be used in accordance with this privacy notice.
On rare occasions, we may collect health data from you when you forward us specific medical reports. Outside this scenario, we do not collect any special categories of Personal Data about you (this includes details about your race or ethnicity, religious or philosophical beliefs, sex life, sexual orientation, political opinions, trade union membership, information about your genetic and biometric data). For the avoidance of doubt, data pertaining to self-exclusion requests are not considered to be data related to health.
If you fail to provide personal data
Where we need to collect personal data by law, or under the terms of a contract we have with you and you fail to provide that data when requested, we may not be able to perform the contract we have or provide you with the service requested.
Please note that any information which you transmit to us by email is not encrypted and is transmitted at your own risk.
3. The purpose for which we collect your personal data
We have set out below, in a table format, a description of the ways we plan to use your personal data and which of the legal bases we rely on to do so. We have also identified what our legitimate interests are where appropriate. Information on the balancing test at the basis of the legitimate interest can be obtained upon request by contacting the DPO at dpo@pinnacle.com.
Note that we may process your personal data for more than one lawful ground depending on the specific purpose for which we are using your data. Please contact us if you need details about the specific legal ground we are relying on to process your personal data where more than one ground has been set out in the table below.

Purpose/Activity

Type of data

Lawful basis for processing including the basis of legitimate interest

To register you as a new customer in order to provide our gaming services.

(a) Identity

(b) Contact

Performance of a contract with you.

To process and deliver your order including:

(a) Processing and monitoring your bets.

(b) processing card and online payments.

(c) payment processing identification, authorization and/or processing.

(d) collection of debts.

(a) Identity

(b) Contact

(c) Financial

(d) Transaction

(e) Marketing and Communications

(a) Performance of a contract with you.

(b) Necessary for our legitimate interests (to recover debts due to us and fulfil customer payments).

(c) complying with our legal and regulatory obligations.

To manage our relationship with you which will include:

(a) Notifying you about changes to our terms or Privacy Policy.

(b) Asking you to leave a review or take a survey.

(a) Identity

(b) Contact

(c) Profile

(d) Marketing and Communications

(a) Performance of a contract with you.

(b) Necessary to comply with a legal obligation.

(c) Necessary for our legitimate interests (to keep our records updated and to study how customers use our products/services).

To enable you to partake in a prize draw, competition or complete a survey.

(a) Identity

(b) Contact

(c) Profile

(d) Usage

(e) Marketing and Communications

(a) Performance of a contract with you.

(b) Necessary for our legitimate interests (to study how customers use our products/services, to develop them and grow our business).

To administer and ensure the security of our business and this website (including troubleshooting, data analysis, testing, system maintenance, support, reporting and hosting of data).

(a) Identity

(b) Contact

(c) Technical

(a) Necessary for our legitimate interests (for running our business, provision of administration and IT services, network security, to prevent fraud and in the context of a business reorganisation or group restructuring exercise).

(b) Necessary to comply with a legal and regulatory obligation.

To deliver relevant website content and advertisements to you and measure or understand the effectiveness of the advertising we serve to you.

(a) Identity

(b) Contact

(c) Profile

(d) Usage

(e) Marketing and Communications

(f) Technical

Necessary for our legitimate interests (to study how customers use our products/services, to develop them, to grow our business and to inform our marketing strategy).

To use data analytics to improve our website, products/services, marketing, customer relationships and experiences.

(a) Technical

(b) Usage

Necessary for our legitimate interests (to define types of customers for our products and services, to keep our website updated and relevant, to develop our business and to inform our marketing strategy).

To make suggestions and recommendations to you about goods or services that may be of interest to you.

(a) Identity

(b) Contact

(c) Technical

(d) Usage

(e) Profile

Necessary for our legitimate interests (to develop our products/services and grow our business).

To prevent you from accessing our services when you have disclosed to have gambling addiction sustained by medical evidence such as medical reports.

(a) Health

Necessary to protect your vital interests (Art. 9 (2) c) of the GDPR.

4. Who we might share your information with
a. For anti-money laundering, fraud detection and/or control purposes, Pinnacle has the right to transfer your personal data to third parties, including but not limited to third-party suppliers such as the police, financial integrity units, banks, ID and address verification system providers, payment service providers and financial institutions, however, only where we have assurance that they are meeting the same standards on the processing of data and security. We encourage you to read the privacy policies of our third-party suppliers.
b. Furthermore, we reserve the right to disclose your personal data to relevant third parties, such as other Pinnacle group companies, our regulators, financial integrity units, notably when Pinnacle has reasonable grounds to suspect irregularities involving your account.
c. Your data will also be shared for regular operational purposes with entities such as cloud services, data centres, payment services, banks, ID verification tools, customer communication tools, game suppliers etc.
d. We are entitled to share the information we hold on you which includes personal data and/or betting history with sporting bodies in order to investigate fraud, money laundering or sports integrity issues and to comply with our regulatory duties.
e. Some of the data processors engaged to process your personal data may be based outside of the European Economic Area (EEA) where data protection laws are not as protective as EU law. In such cases the information will continue to be subject to one or more appropriate safeguards set out in the law. We will take all reasonable steps to ensure that your personal data is treated securely and is processed with appropriate care and protection and in line with applicable legal requirements.
5. How long we keep your information
In order to comply with our legal, financial and regulatory requirements we will maintain your information for the minimum length of time required to meet those requirements. After the minimum amount of time for maintaining your data has elapsed and provided we do not have any other legitimate reason for maintaining your data, your data will be pseudonymised.
Since this policy is a global policy, the retention period will be implemented in accordance with the applicable requirements of either Malta (6 years minimum) or Curacao (10 years minimum), depending which jurisdiction you fall under.
In the event you make a request for your data to be erased and such request qualifies under our guidelines for erasure, your personal data will be anonymised. Once anonymised it is no longer recognised as personal data.
If there has been no Account Activity (as defined in our Terms and Conditions) and we have maintained your data for the minimum time required to meet our legal and regulatory requirements, your account will be closed and pseudonymised.
Accounts where there has been an instance of fraud, notification of gambling addiction and/or permanent self-exclusion, will not be anonymised so that we may continue to monitor these customers in adherence to our legal and regulatory requirements.
6. Keeping you informed about our products and services
We’d love to send you offers, competitions & exclusive content through our various marketing channels. In order to do so we require your consent to use your personal data. Your data will not be sold or given to any third parties not affiliated with Pinnacle for marketing purposes without your prior approval.
You can change your preference setting for marketing by contacting customerservice@pinnacle.com, requesting that we change your marketing preference.
7. How we secure your information
a. Pinnacle assures you that your personal data is:
  • processed in accordance with your rights;
  • processed fairly and lawfully;
  • obtained only for the above purposes;
  • adequate, relevant and not excessive for its purpose;
  • kept in a secure manner;
  • not kept longer than is necessary for its purposes.
b. Pinnacle shall take all reasonable steps to ensure that your information is kept secure and protected. In this regard, we maintain appropriate technical and organisational measures to protect your data against unauthorised or unlawful processing.
c. We recommend that you send all personal documents using our secured upload tool. Please copy and paste the following link into your browser (Followed by your client ID):
  • https://cashier.pinnacle.com/VerifyUpload.asp?customerId=
8. Your rights
Subject to certain limitations on certain rights you have the following rights in relation to your information. You can exercise any of these rights by contacting customerservice@pinnacle.com naming the right you are exercising along with the reason for your request, if applicable.
Right of Access: you have the right to request access to your personal data and supplementary information.
Right to Rectification: you have the right to request that inaccurate personal data be rectified or completed if incomplete.
Right to Erasure: you have the right to request erasure of your information where there is no longer a good reason for us to continue processing it. Please ensure that you withdraw your Account Balance prior to sending us the request. The rules enacted under the section 8 of our Terms and Conditions related to the Withdrawal of funds apply. You also have the right to ask us to delete or remove your personal data where you have successfully exercised your right to object to processing (see below), where we may have processed your information unlawfully or where we are required to erase your personal data to comply with local law. It should be noted that this right is not absolute and may be subject to our compelling reasons to maintain that information such as our adherence to legal and regulatory obligations. Please see the section “How long we keep your information” above. In the event we are unable to comply with this request you will be notified.
Right to Restrict Processing: this enables you to ask us to suspend the processing of your personal data in the following scenarios: (a) if you want us to establish the data's accuracy; (b) where our use of the data is unlawful (i.e. where it does not fall under a legal reason for processing as outlined under section 3. or your information has otherwise been obtained illegally by a third party) but you do not want us to erase it; (c) where you need us to hold the data even if we no longer require it as you need it to establish, exercise or defend legal claims; or (d) you have objected to our use of your data but we need to verify whether we have overriding legitimate grounds to use it. Please note that this right is not absolute.
Right to Data Portability: you have the right to request the personal data you have provided to us. You may make a data portability request by contacting customerservice@pinnacle.com.
Right to Object: you have the right to object to our processing of your data. It should be noted that this right is not absolute and may be subject to any reasons we have to maintain that information such as our adherence to legal and regulatory obligations. If you wish to object to direct marketing please contact customerservice@pinnacle.com requesting that you no longer wish to receive marketing materials.
It should be noted that the ability to perform our services relies on the processing of certain information, therefore, exercising certain rights may result in a loss of the service or part of it.
No fee usually required
You will not have to pay a fee to access your personal data (or to exercise any other rights). However, we may charge a reasonable fee if your request is clearly unfounded, repetitive or excessive. Alternatively, we may refuse to comply with your request in these circumstances.
What we may need from you
We may request specific information from you to help us confirm your identity and ensure your right to access your personal data (or to exercise any of your other rights). This is a security measure to ensure that personal data is not disclosed to any person who has no right to receive it. In the event you did not provide all your verification information upon registering with us, this information may be requested to complete your profile. We may also contact you to ask you for further information in relation to your request to speed up our response. Please remember to keep your password confidential – you can read the IDPC’s advice on keeping your passwords safe here.
Time limit to respond
We try to respond to all legitimate requests within one month. Occasionally it may take us longer than a month if your request is particularly complex or you have made a number of requests. In this case, we will notify you and keep you updated.
It is your responsibility to maintain that your personal information is up to date and accurate.
You have the right to lodge a complaint with a supervisory authority in the Member State of your habitual residence, place of work or place of the alleged infringement. You have the right to make a complaint at any time to the Office of the Information and Data Protection Commissioner in Malta (IDPC). We would, however, appreciate the chance to deal with your concerns before you approach the IDPC so please contact us in the first instance.
Pinnacle’s websites (including those optimised for mobile devices) and mobile applications use cookies and similar technologies to manage login sessions, provide personalised web pages and to tailor content to reflect your specific needs and interests. Once you “Accept” our banner on cookies you agree to the use of cookies and similar technologies for the purposes we describe in this policy.
What is a web cookie?
Cookies are text files containing a small amount of information that are downloaded to your device when you visit a website. They are generally used by most websites to improve your online experience and to ensure that content and functions are delivered and used more effectively.
Cookies perform various different functions. For example, some cookies are downloaded to your device temporarily for the period that you browse a particular website; these cookies might allow you to navigate between pages more efficiently or enable websites to remember the preferences you select. Other cookies can be used to help websites remember you as a returning visitor or ensure the online adverts you receive are more relevant to your specific needs and interests.
You can amend your browser settings to block some or all cookies. To do this, follow the instructions provided by your browser provider. Please be aware, if you block cookies from Pinnacle’s website some or all the website's functions may not perform as intended.
For example, you may not actually be able to place any bets. If you would like to amend your browser settings see “manage your cookies”. If you would like more information about cookies see “further information”.
The types of cookies Pinnacle uses are:
Essential Cookies
Essential Cookies are cookies which are necessary in order for a website to function correctly; they enable you to navigate our website and allow you to perform specific functions, such as accessing secure areas, placing bets, depositing funds and managing your account. Without these cookies, it would not be possible to provide our specific online services and functions.
We use Essential Cookies to:
  • Maintain your Bet Slip selections as you navigate around the site;
  • Identify you as being logged on to Pinnacle.com.
Cookies we have defined as Essential Cookies will not be used to:
    • Gather information that could be used to advertise products or services to you;
    • Remember your preferences or username beyond your current visit.
Some examples of essential cookies that Pinnacle sets:

 

BackURL

 

This cookie is used for navigation purposes.

 

 

Custid

 

This cookie is used to authenticate the customer's ID.

 

 

BrowserSessionId

 

This cookie is used in simultaneous logins to track if the user's current session is the latest.

 

 

UserAccess

 

 

This cookie defines users website access.

Performance Cookies
These cookies collect information about how visitors use a website, for instance, which pages they go to most often and if they get error messages from web pages. These cookies do not collect information that identifies a visitor. All information these cookies collect is aggregated and therefore anonymous. It is only used to improve a website's performance.
We use Performance Cookies to:
  • Provide statistics on how our website is used;
  • See how effective our promotions are;
  • Collect statistics on which markets customers are betting on;
  • Help us improve the website by measuring any errors that occur;
  • Test different designs of our website;
  • Identify your browser or device you are using to access the site.
Cookies we have defined as 'Performance' cookies will not be used to:
  • Gather information that could be used to advertise products or services to you on other websites;
  • Remember your preferences or username beyond your current visit;
  • Store personal information such as email address or name;
  • Target promotions to you on any other website;
  • Allow third parties to use the cookies for any purpose other than those listed above.
Example of performance cookies that Pinnacle sets:

 

ADRUM

 

This cookie is used to monitor End User experience.

 

 

Webmetrics-RUM

 

This cookie is used for tracking data analytics.

 

We use third-party cookies (such as Google Analytics and Silverpop Web Analytics) to gather information on customer interactions with the site so we can develop and improve the customer’s journey and provide them with an optimised service (To opt out of performance cookies, please see below).
Please be aware that opting out of our performance cookies won’t keep you from using our website, however, it will limit us from learning from your experience and may limit our ability to make accurate decisions for improving our website. However, if you wish to opt out of the web analytics that Pinnacle uses, please use the link below:
GoogleAnalytics
Functionality Cookies
These cookies allow the website to remember choices you make, such as your username, language, or the region you are in, and provide enhanced, personalised features. For instance, a website may be able to provide you with local weather reports or traffic news by using cookies to store information about the region in which you are located. These cookies can also be used to remember changes you have made to text size, fonts and other parts of web pages that you can customise. They may also be used to provide services you have requested such as watching a video or commenting on a blog. The information these cookies collect may be anonymised and they cannot track your browsing activity on other websites.
We use 'Functionality' cookies to:
  • Remember settings you've applied such as layout, preferences, colours and showing/ hiding features;
  • Remember that you have seen certain content;
  • Provide proactive live chat sessions to offer you support.
Cookies we have defined as 'Functionality' cookies will not be used to:
  • Target you with adverts on other websites;
  • Allow third parties to use the cookies for any purpose other than those listed above.
Examples of functionality cookies that Pinnacle sets:

UserPrefsCookie                 

This cookie saves information about some of the user profile related settings like default odds format, default language, view and time zone.

 

HomePageVisitedTime

This cookie gets created so that the site knows if it should redirect you to a page for returning customers.

DestUrl

This cookie is used to send customer directly to a specific league page on guest site to view lines.

 

Targeting Cookies
These cookies are used to deliver content, such as adverts, that are more relevant to you and your interests. They may also be used to limit the number of times you see an advert or measure the effectiveness of the advertising campaign. These tend to be set by third party advertising agencies with Pinnacle's permission, and may share information about websites that you have visited with other organisations, such as advertisers.
We use 'Targeting' cookies to:
  • See what pages a customer is interested in and feed this back to our email tool so we only target customers with information that is relevant to them.
  • Provide promotions to customers who have registered an account with us whether such account is funded or not.
  • Provide cross-product promotions to customers based on what markets you have viewed or the value of the bets you have placed.
  • Provide suggested third parties with information about your visit so that they can present you with adverts that you may be interested in.
Some of targeting cookies that Pinnacle uses:

Sidi

This cookie is used to gather data on a website visitor’s session activity.

 

Vidi

This cookie is used for visitor identification.

Manage your cookies
We recommend you don't change your cookie settings as it may limit your user experience and the performance of the site.
If you do want to change the cookies setting, you can do this through your browser. Different web browsers may use a different way of controlling cookies, so you'll need to use your browser's help section to find out how to do this or you can visit one of the following browser providers’ sites directly.
Further information
You can find more information about cookies at https://en.wikipedia.org/wiki/HTTP_cookie. For a video about cookies visit https://policies.google.com/technologies/cookies.
10. Changes to information
Any changes to our Privacy Policy shall be posted on this page and any such changes will become effective upon posting the revised Privacy Policy. If we make any material or substantial changes to this Privacy Policy we will use reasonable endeavours to inform you by email, notice on the Website or other agreed communications channels. If we plan to use personal data for a new purpose, we update our Privacy Policy and communicate the changes to individuals before starting any new processing.