Privacy policy: what this site does with data, and what an operator does

Two separate questions, deliberately answered in one place. The first half covers dragonia.io, which collects almost nothing. The second half covers the operator, which by law collects a great deal.

Part one: what dragonia.io collects

This is a publishing site, not a service. There is no account, no login, no cashier and no form asking for a name. The only personal data that reaches us arrives in two ways: the standard server log kept by the hosting provider — IP address, timestamp, requested page, browser and referrer — and whatever you choose to type into an email if you write to the editorial desk.

Server logs exist for security and troubleshooting, are held briefly and are not used to build a profile of anyone. We do not sell, rent or trade data, we run no advertising or profiling cookies, and we do not operate a newsletter that would need a mailing list in the first place.

Cookie policy in plain terms

Our cookie policy is short because the cookie list is short. Technically necessary cookies keep the site working — remembering a language choice, for example — and where aggregated audience measurement is used, it reports page counts and traffic sources rather than identifying individuals.

Control sits with you in either case: every browser can block or delete cookies for a specific domain, and refusing ours costs you nothing, since none of the reading material on this site is gated. Partner links that leave for the operator are covered by that operator's own cookie policy from the moment the click lands, which is worth knowing before you accept anything on the other side.

Data usage, legal basis and retention under GDPR

dragonia.io is aimed at readers in Italy and applies GDPR — Regulation (EU) 2016/679 — as its baseline. The legal basis for keeping server logs is legitimate interest in operating a secure website. The basis for correspondence is the handling of your own request. That is the complete list, because data usage here does not extend beyond publishing pages and answering email.

Retention follows the same minimalism: logs are kept for a short technical window and correspondence for as long as the exchange is live plus a reasonable archival period. Nothing is retained because it might one day be useful.

Your rights, and how to use them

Under GDPR you may request access to the personal data held about you, its correction, its deletion, a restriction on processing, a copy in portable form, and you may object to processing based on legitimate interest. You can also complain to the Italian supervisory authority, the Garante per la protezione dei dati personali.

To exercise any of these against us, write through the contact page. In practice the honest answer is usually that we hold nothing beyond an email thread. Requests concerning a casino account go to the operator instead: it is the data controller for everything created inside its platform, and we have no access to any of it.

Part two: what the operator holds and how to check it is protected

An operator's obligations look nothing like ours. Registration, verification and the cashier generate identity documents, a home address, transaction history and technical login records — and financial regulation requires most of it to be kept rather than deleted on request. The operator's own privacy policy sets out that list in full, and it is a document worth opening once instead of never.

Everything typed into a cashier travels over a channel protected by encryption, so anyone listening on the same public network sees only meaningless characters. SSL encryption on every page that accepts input is the baseline expectation of a licensed site, and the padlock beside the address bar is the two-second way to confirm it before a field is filled in. So when readers ask is it safe to hand over a document scan, the answer rests on three checkable things rather than on reassurance: an encrypted connection, a named and verifiable licence, and careful account habits.

How to judge data protection before you register

A secure casino makes four things easy to find, and a five-minute check covers all of them. First, the padlock and a valid certificate on the exact domain you are about to type credentials into. Second, a published privacy policy that names the data controller company, states retention periods and lists the third parties involved — payment providers, document-verification services, the regulator. Third, the licence or concession number in the footer, matched against the public register. Fourth, two-factor authentication available in the account settings.

On your own side the useful habits are dull and effective: a password reused nowhere else, two-factor authentication switched on, documents uploaded only inside the logged-in account area rather than by email, and no logging in from a friend's laptop. A session left open on a device you no longer control is closed faster by changing the password than by hoping. Data protection is a shared job — the operator supplies SSL encryption and a policy, you supply the discipline that makes a session safe and secure.

Changes to this policy

If this privacy policy changes materially, the revision date on the page changes with it and the affected section is rewritten rather than patched invisibly. Continued use of the site after publication means the current version applies. Related reading: our terms of use, the about us page explaining how the site is run, and the English homepage.

LF

Ludovica Ferraris

Online casino analyst • independent reviews • updated: August 2026

Play Now