Privacy Policy and Cookie Policy
This privacy policy covers turbiini.info, an independent review site. It is deliberately written alongside a second question most policies leave out: what the operator collects, which is a much larger set of personal data and a different controller entirely. Knowing which side holds what is what makes a data request land in the right inbox.
Two controllers, two very different data sets
turbiini.info publishes reviews and guides. We hold no player accounts, take no deposits, see no balances and receive no identity documents. What we process is limited to what any website sees when a page is served. Turbiini, the operator, is a separate data controller: it holds the account, the KYC file, the transaction history and the device log, and its own privacy policy governs all of it.
The practical consequence is simple. A request about your account data, a copy of your file or the erasure of your player profile goes to the operator's support desk, because we could not action it even if we wanted to. A request about analytics data collected on these pages goes to us.
What this site collects
On an ordinary visit, turbiini.info records technical data only: device type and operating system version, browser and version, IP address, the pages opened and time spent on each, referral source and screen dimensions. IP addresses are truncated for analytics purposes so that individual visitors are not singled out. No name, no email address and no payment data is collected by browsing, because there is nothing on this site to register for.
Data usage is narrow and stated plainly: understanding which guides are read so the weak ones get rewritten, measuring page performance, and detecting abuse of the infrastructure. We do not sell, licence or trade personal data, and we do not share it with advertising networks or data brokers.
Cookies and how to switch them off
The cookie policy splits into three categories. Strictly necessary cookies keep the page functioning and remember basic state; without them parts of the site simply break. Functional cookies remember preferences such as language, so that a Finnish reader who switched to English is not switched back on the next visit. Analytical cookies count page views in aggregate.
Only the first category is unavoidable. Non-essential cookies can be refused in the consent banner or cleared and blocked in your browser settings, and doing so leaves every article on this site fully readable. Declining analytics costs you nothing and costs us only a slightly less accurate picture of which pages need work.
How long anything is kept
Retention is capped rather than open-ended, and the periods differ by purpose.
| Data category | Retention period | What happens afterwards |
|---|---|---|
| Server access logs | Up to 90 days | Deleted, including from rotated backups |
| Analytics events (truncated IP) | Up to 14 months | Deleted or reduced to non-identifying aggregates |
| Consent record | Up to 12 months | Expires, and the banner asks again |
| Email correspondence with the editorial desk | Up to 24 months | Deleted, or sooner on request |
| Aggregate, non-identifying statistics | Indefinite | Retained for trend comparison; no individual is identifiable |
Third parties we rely on
A small number of processors sit behind this site: a hosting and content-delivery provider that serves the pages, and a web analytics service that counts visits. Each may set its own cookies and see technical request data as a consequence of doing its job. We assess providers against data-protection criteria before using them and review that assessment periodically. Where infrastructure is distributed across jurisdictions, transfers are governed by standard contractual clauses and processing agreements.
Outbound links to the operator are affiliate links, and clicking one hands you over to the operator's own environment where its policy applies from that moment. How that commercial relationship works, and why it does not change our verdicts, is set out on the affiliate disclosure page.
Encryption, SSL and the account habits that matter
Every page here is served over HTTPS with SSL/TLS encryption, so the connection between your browser and the site cannot be read by anyone else on the same network. On the operator's side the same encryption protects far more sensitive traffic — card numbers, document scans, an address typed into the cashier — and the padlock beside the address bar is the two-second check worth making before any field is filled in. Encrypted storage and role-based access on the server side are the companion measures; encryption in transit alone is not enough.
Two habits on the player's side do more than any policy text. First, a password used nowhere else, because credential reuse is the single most common route into a gambling account. Second, two-factor authentication switched on in the account security settings: with 2FA active, a stolen password on its own does not reach the balance. Add a third if you share devices — never stay signed in on a machine that is not yours, and change the password rather than hoping an abandoned session expires quietly.
Your GDPR rights and how to use them
As a data subject in Finland you hold the full set of rights under the GDPR, against us for what we hold and against the operator for what it holds. They are not favours; they are enforceable, and a licensed operator will have a documented procedure for each.
| Right | What it lets you do | Where to send it |
|---|---|---|
| Access | Obtain a copy of the personal data held about you | Either controller, for its own data |
| Rectification | Correct data that is wrong or out of date | The operator for account details; us for correspondence |
| Erasure | Have data deleted where no legal duty requires keeping it | Either controller; note the exception below |
| Portability | Receive your data in a machine-readable format | Primarily the operator |
| Objection | Object to processing based on legitimate interests, including profiling for marketing | Either controller |
| Restriction | Freeze processing while a dispute over accuracy is resolved | Either controller |
| Withdraw consent | Turn off analytics or marketing consent at any time | Banner and browser settings here; account settings there |
The exception worth knowing in advance: erasure is not absolute at a gambling operator. Anti-money-laundering and accounting rules oblige it to retain transaction and identity records for a statutory period even after an account is closed, and a self-exclusion record is deliberately kept so the exclusion cannot be undone by deleting the account. That is a legal obligation on the operator, not a refusal.
Contact and complaints
For anything concerning data held by this site — an access request, a correction, a deletion, or a question about the analytics we run — write to privacy@turbiini.info. We aim to acknowledge within 48 hours and to resolve substantive requests within 30 calendar days, which is the GDPR window. Editorial corrections go to support@turbiini.info instead, and the routes are listed on our support page.
If a response from either controller does not satisfy you, the supervisory authority in Finland is the Office of the Data Protection Ombudsman, and complaining to it is free. Where the complaint concerns the operator's licence conduct rather than its data handling, the route runs through the operator's dispute channel first — that order is explained on our complaints page. This policy is updated when practices change, with the current version always published here; the rest of our documentation starts from the English homepage and the terms of use.