At Alderney Casino (“we”, “us”, “our” or “the Website”), we take the security of our Website, systems and visitors’ information seriously. This Security Policy explains the measures we take to protect the Website and how visitors, partners and security researchers can report a suspected security issue.
This policy applies to https://alderney-casino.com/ and the systems used to operate it.
1. Our Security Approach
We use reasonable and proportionate technical and organisational measures to protect the Website and any personal data we process against unauthorised access, loss, misuse, alteration, disclosure or destruction.
Our approach is risk-based. The safeguards we use may be reviewed and updated as the Website, technologies, legal requirements and security risks change.
Where appropriate, these measures may include:
- Encryption of data transmitted between your browser and the Website using HTTPS/TLS.
- Restricted access to Website administration areas and business systems.
- Strong password requirements and multi-factor authentication for authorised administrators where available.
- Access controls that limit data access to people who need it for legitimate business purposes.
- Security updates, patching and maintenance for supported software, plugins, themes and hosting infrastructure.
- Backups and recovery procedures designed to support continuity following a technical incident.
- Monitoring, logging and protective tools intended to identify suspicious activity or system issues.
- Reviews of third-party service providers that process data or support Website operations.
No online system can be guaranteed to be completely secure. However, we work to identify, reduce and manage relevant security risks in a timely and responsible way.
2. Website Security
We aim to maintain a secure browsing environment for visitors. You should check that your browser displays a secure HTTPS connection before submitting any personal information through the Website.
You are responsible for using a secure device, keeping your browser and operating system updated, and protecting your own account credentials or contact information. Do not send passwords, payment-card details or other highly sensitive information to us by unencrypted email.
Alderney Casino is an informational website. Unless expressly stated otherwise, we do not provide gambling accounts, accept bets, process deposits or withdrawals, or collect payment-card information for gambling activity.
If you follow a link to a third-party casino, gaming platform or service provider, that website has its own security practices, privacy notice and terms. Please review them carefully before registering, sharing personal information or making a payment.
3. Protection of Personal Data
Where we process personal data, we take measures appropriate to the nature of the information and the risks involved. These measures are designed to protect the confidentiality, integrity and availability of personal data.
We limit access to personal data to authorised persons and service providers who need it to operate, maintain or improve the Website, or to meet legal and regulatory obligations.
More information about how we collect, use, retain and share personal data is available in our [Privacy Policy]. Information about cookies and similar technologies is available in our [Cookie Policy].
4. Third-Party Services
The Website may rely on third-party providers for hosting, analytics, email delivery, security, content delivery, affiliate tracking or similar operational services.
While we take reasonable steps to select suitable providers, we cannot control every aspect of a third party’s systems or security practices. Third-party providers process information in accordance with their own terms, policies and applicable legal obligations.
Links to external websites are provided for information or convenience. We are not responsible for the security, availability or data-handling practices of external websites.
5. Reporting a Security Vulnerability
We welcome good-faith reports of potential vulnerabilities affecting the Website. If you believe you have discovered a security issue, please report it to us as soon as possible.
Security contact: [email protected]
Alternative contact: [email protected]
Subject line: Security Vulnerability Report
Please include, where possible:
- A clear description of the suspected issue.
- The affected page, feature or URL.
- Steps that allow us to reproduce the issue.
- The potential impact of the issue.
- Screenshots, logs or proof-of-concept material where it is safe and necessary to provide it.
- Your preferred contact details, if you would like us to follow up.
We aim to acknowledge reports within [e.g. five business days] and will investigate credible reports as promptly as reasonably possible. We may contact you for additional details or clarification.
The UK National Cyber Security Centre recommends making a vulnerability-reporting route easy to find and may support publishing this contact route through a public security page or a security.txt file.
6. Responsible Disclosure Rules
To protect visitors, partners and the Website, please act responsibly when testing or reporting a possible vulnerability.
You must not:
- Access, alter, download, disclose or delete data that does not belong to you.
- Attempt to access accounts, systems or administrative areas without permission.
- Disrupt Website availability, including through denial-of-service or similar attacks.
- Introduce malware, harmful code or malicious files.
- Use social engineering, phishing, impersonation or physical-security attacks.
- Test third-party services, payment providers, affiliate partners or linked websites through our Website.
- Publicly disclose a vulnerability before giving us a reasonable opportunity to investigate and address it.
Good-faith research that follows these rules and is limited to confirming the vulnerability will not normally lead to action by us. However, this does not prevent us from taking action where we reasonably believe conduct has caused harm, breached these rules or violated applicable law.
7. Security Incidents
If we identify a suspected security incident, we will assess the issue, take appropriate steps to contain and investigate it, and implement remedial measures where necessary.
Where an incident involves personal data, we will assess whether notification is required under applicable data-protection law. Where legally required, we will notify the appropriate regulator and affected individuals within the applicable timeframes.
8. Policy Changes
We may amend this Security Policy to reflect changes in our Website, technical measures, service providers, legal requirements or security practices.
Any updates will be posted on this page with a revised “Last updated” date. We encourage visitors to review this policy periodically.
9. Contact Us
If you have questions about this Security Policy, please contact:
[Alderney Gambling Control Commission]
Email: [email protected]
Security reports: [email protected]
Registered address: St Anne’s House Queen Elizabeth II Street Alderney, Channel Islands GY9 3TB