Insic

Privacy Policy

Effective Date: May 2020

A summary introduction to this Privacy Policy can be found here.
Please note that you may print this Privacy Policy using your browser’s print function, download it for your records, or access it later on our websites.

insic GmbH (hereinafter “insic”) takes data protection obligations very seriously and designs its services so that as little personal data as possible is collected, processed, and used.

The collection, processing (including storage, modification, transfer, blocking, and deletion), and use of your data is carried out exclusively in compliance with applicable data protection laws.

Data will only be transmitted to third parties for the purposes of the insic age verification system, as required by law (BDSG, GDPR, GlüStV, JMStV, TMG, GlücksspielG SH, RennwLottG, and GWG). This ensures your participation with insic’s contractual partners. No further transfer of your personal data to third parties takes place.

Access to personal data is granted only to authorized persons trained in data protection law and only to the extent necessary to perform the contractual relationship.

insic undertakes to support users, as far as legally and technically possible, in exercising their rights under Articles 12–22 GDPR. This includes, in particular, the right to information, correction, deletion, and restriction of processing.

If you contact us (e.g., via contact form), we use the data you provide solely for communication purposes. Legal basis: Art. 6(1)(b) GDPR. Data collected will be automatically deleted after responding.


A. Collection, Processing, and Use of Data When Accessing Our Website (Without Registration)

You can access information about our company and products at www.insic.de without registering.

Data collected automatically:

  • IP address of the device,

  • Date and time of access,

  • Title of the accessed page and the referring page (Referrer URL),

  • Access status and error codes,

  • Browser and operating system information.

Legal basis: Art. 6(1)(f) GDPR – legitimate interest in ensuring stability and security.

Data may be stored temporarily in internal log files for statistical purposes and website administration.

Cookies

  • Session cookies: Deleted after closing the browser. Used for login authentication and load balancing.

  • Persistent cookies: Store language/country settings or dismissals of site notices. Deleted automatically after a set duration.

Legal basis: Art. 6(1)(f) GDPR – to optimize and personalize the user experience.


B. Collection, Processing, and Use of Data for Services

1. Age and Identity Verification

a) Data Collection & Changes

  • Required: salutation, first/last name, address, email, place/date of birth, ID copy, and possibly bank details.

  • Additional depending on the verification method (e.g., mobile number, device data, IP).

  • Data transmission is encrypted (note: 100% security on the Internet cannot be guaranteed).

b) Plausibility & Duplicate Check

  • Address plausibility checks and duplicate checks are performed.

c) Bank Data Verification

  • Plausibility check (easykonto),

  • 1-cent transfer with security code,

  • Optional Schufa account check.

d) Transmission to Third Parties (for Verification)

  • (1) Schufa Ident Check – confirms only age 18+, no credit check.

  • (2) PostIdent / E-PostIdent / POSTID – verification via Deutsche Post.

  • (3) ASTIdent / ShopIdent – verification via local partner shops.

  • (4) GiropayID – verification via GiroSolution.

  • (5) ID recognition – via IDENTT GmbH.

  • (7) PEP & Sanctions List Check – via TOLERANT Software GmbH.

  • (8) OASIS player ban check – via Hessian Ministry of the Interior.

  • (9) Additional methods – detailed on insic’s website.


2. Transmission of Validation Data to Partners

  • After validation, necessary data (e.g., name, address, email, mobile number, status, hash codes, majority status, and possible ban info) is transmitted to connected partners.

  • Transmission is encrypted and only occurs after explicit user confirmation.

  • Data is not disclosed to third parties except when legally required (e.g., tax, AML, gambling law).

  • External service providers may process data under strict instructions, only for as long as necessary (e.g., identification, payment processing).


3. Self-Exclusion

  • Users may request blocking/deletion of their account (e.g., gambling addiction).

  • Encrypted digital keys (hash codes from name, birthdate, and email) are stored to prevent re-registration during statutory exclusion periods.


4. Information Services

  • Only minimal data is stored (email or phone number) for sending service updates.

  • You may cancel information services at any time.

  • insic does not send newsletters, advertising SMS, or marketing information.


C. Data Transfer Within the Online Service

  • Personal data transmitted on insic websites is encrypted with SSL.

  • Note: 100% Internet security cannot be guaranteed.


D. Data Security

  • insic implements technical and organizational measures required by GDPR.

  • Data centers are located in Germany, ISO/IOC 27001:9001 certified.

  • Service providers include Amazon Web Services (AWS, Frankfurt, EU-US Privacy Shield) and Nexinto GmbH (Hamburg).


E. Transfer of Data to Public Authorities

  • Only upon written presentation of enforceable administrative or judicial orders, or where legally required.


F. Consent

  • Any consent given for data collection, processing, or use may be revoked at any time (via email: support@insic.de or fax: +49 4102 607 6010-9).


G. Right of Access / Deletion of Data

  • Users have the right to free access to stored personal data and to request deletion.

  • Requests via email or fax will be answered promptly (note: email is not fully secure).

  • Deletion: personal address data is overwritten so that recovery is impossible.

  • After termination, data is deleted unless statutory retention applies.

  • Automatic deletion/anonymization occurs after 14 days, 6 months, or 1 year, depending on platform requirements.


H. Changes to the Privacy Policy

  • insic reserves the right to amend this Privacy Policy in line with new services or technical developments.


I. Data Protection Officer / Contact

  • The Data Protection Officer is listed in the Impressum.

  • Contact:

Privacy Overview

This website uses cookies so that we can provide you with the best user experience possible. Cookie information is stored in your browser and performs functions such as recognising you when you return to our website and helping our team to understand which sections of the website you find most interesting and useful.