This Privacy Policy explains how Temple Tumble processes personal data collected from players in the United Kingdom. It describes the categories of information obtained, the legal grounds for processing, storage and security protocols, and the rights available to individuals. The policy is issued to ensure transparency regarding data handling practices and to comply with applicable data protection legislation, including the UK General Data Protection Regulation and the Data Protection Act 2018. Temple Tumble operates under a legal obligation to maintain accurate records for account management, financial transactions, and regulatory reporting. This document does not constitute marketing or promotional material; it serves solely as an administrative record of the brand’s data processing activities. All data handling procedures described herein are subject to periodic review and may be updated to reflect changes in legal requirements or operational systems.
1. Categories of Personal Data Collected During Account Operations
Temple Tumble collects personal data directly from individuals during account registration, gameplay, and financial transactions. The types of information processed include identification details such as full name, date of birth, and residential address. Verification documents, including copies of passports or driving licences, are obtained to satisfy anti-money laundering obligations under UK law. Transactional data, including deposit amounts, withdrawal requests, and game session history, is recorded for audit and compliance purposes. Technical data, such as internet protocol addresses, device identifiers, and browser type, is collected automatically when accessing the platform. Additionally, records related to communication with customer support, including correspondence regarding the temple tumble megaways slot feature, are retained for service improvement and dispute resolution.
- Registration details: name, date of birth, address, email address, telephone number.
- Identification records: copies of government-issued identification, proof of address, financial source documentation.
- Transactional information: deposit and withdrawal amounts, payment method details, game session logs.
- Technical data: IP address, operating system, browser version, device type.
- Compliance-related records: account restriction history, self-exclusion requests, responsible gambling interactions.
2. Legal Basis and Purposes for Data Processing Activities
Personal data is processed by Temple Tumble under specific lawful bases defined by UK data protection law. Where an individual plays the temple tumble megaways free demonstration version, consent may be relied upon to process limited technical data. For real-money account operations, processing is necessary for the performance of a contract, including verifying age, facilitating deposits, and enabling withdrawals. Legal obligations require the brand to process identification data for anti-money laundering checks and to report suspicious activity to the Gambling Commission. Legitimate interest is invoked to maintain network security, prevent fraud, and optimise platform functionality. Data processing relating to the temple tumble 2 max win configuration or other game mechanics is performed solely to execute player instructions and calculate outcomes. No personal data is processed for direct marketing purposes unless explicit consent has been obtained separately.
| Processing Purpose | Legal Basis | Data Categories Used |
|---|---|---|
| Account verification | Legal obligation / Contract performance | Identification documents, registration details |
| Transaction processing | Contract performance | Financial data, account balance records |
| Fraud prevention | Legitimate interest | Technical data, transaction history |
| Regulatory reporting | Legal obligation | All categories as required by law |
3. Data Storage Infrastructure, Safeguards, and Retention Schedules
Personal data is stored on servers located within the European Economic Area and the United Kingdom. Encryption protocols are applied to data in transit using Transport Layer Security, and stored data is protected through access controls that restrict processing to authorised personnel only. Temple Tumble implements multi-factor authentication for administrative accounts and logs all access attempts for audit purposes. Retention periods are determined by regulatory requirements under the Gambling Commission licence conditions. Financial records and identification documents are retained for a minimum of five years following account closure, in accordance with anti-money laundering legislation. Game session data, including records of the stone temple pilots tumble in the rough game mechanics, is archived for three years from the date of the last session. After the applicable retention period expires, data is securely deleted or anonymised. Physical documents, if accepted, are stored in locked cabinets and destroyed via cross-cut shredding.
- Data storage: encrypted servers in UK and EEA jurisdictions.
- Access controls: role-based permissions, session timeouts, audit logging.
- Retention: five years for financial and identification data; three years for game session logs.
- Deletion procedures: secure deletion tools for electronic data; shredding for physical records.
4. Player Rights, Access Requests, and Identity Verification Requirements
Individuals whose personal data is processed by Temple Tumble may exercise certain rights under UK data protection legislation. These include the right to request access to copies of personal data held, the right to rectify inaccurate information, and the right to request erasure of data where processing is no longer lawful. Players may also restrict processing in specific circumstances, object to processing based on legitimate interest, and request data portability in a structured, machine-readable format. To prevent unauthorised disclosure, all rights requests must be accompanied by proof of identity, such as a copy of a passport or driving licence. Temple Tumble will respond to verified requests within one month, extendable by two months for complex or multiple requests. Requests sent via methods other than the official data protection contact channel may require additional verification steps. No fee is charged for standard requests unless they are manifestly unfounded or excessive.

