Back to the resort
Privacy Policy
Last updated: 1 September 2026. Applies to swenkdenk.com and to all guests of the swenkdenk casino resort.
This Privacy Policy explains how swenkdenk AS ("swenkdenk", "we", "us") collects, uses, stores and protects personal data when you visit swenkdenk.com, make a reservation, join our loyalty programme or stay and play at the swenkdenk casino resort. We treat your personal data with the same discretion our guests expect at the tables: we collect only what we need, we keep it secure, and we tell you plainly what happens to it.
1. Who is responsible for your data
The data controller is swenkdenk AS, Strandveien 48, 1366 Lysaker, Norway, organisation number 931 482 067. Our Data Protection Officer can be reached at privacy@swenkdenk.com or by post at the address above, marked "Attn: Data Protection Officer".
2. The personal data we collect
- Identity data: full name, date of birth, nationality, and a copy of your passport or national ID card. Gaming regulations require us to verify the identity and age of every guest who enters the gaming floor.
- Contact data: postal address, email address and telephone number.
- Reservation data: dates of stay, room preferences, dietary requirements, special occasions and accessibility needs you choose to share.
- Financial data: payment card details (processed by our certified payment provider, never stored in full by us), cage transactions, chip purchases and redemptions, and front-money deposits.
- Gaming data: rated play, average bets, time on device, loyalty tier and any self-exclusion or limit-setting status.
- Security data: CCTV footage from the gaming floor and public areas, which is a regulatory requirement for licensed venues.
- Technical data: IP address, browser type, device identifiers and pages visited on swenkdenk.com, collected through cookies as set out in our GDPR/CCPA & Cookies Policy.
3. Why we use your data and our legal basis
We process personal data only when the law allows it. Performance of a contract covers handling your reservation, your stay and your payments. Legal obligation covers age and identity verification, anti-money-laundering checks, record-keeping required by gaming regulators, and the enforcement of self-exclusion. Legitimate interest covers security, fraud prevention and improving our services, always balanced against your rights. Consent covers marketing emails, personalised offers and non-essential cookies, and you may withdraw it at any time.
4. Anti-money-laundering obligations
As a licensed gaming operator, swenkdenk is required to perform customer due diligence. When transactions reach certain thresholds we may ask for proof of the source of funds and are required by law to report suspicious activity to the competent financial intelligence unit. We are legally prohibited from telling you when such a report has been made.
5. Who we share data with
We never sell your personal data. We share it only with payment processors, our hotel and reservation-system provider, IT hosting partners bound by data processing agreements, professional advisers such as auditors and lawyers, and public authorities including gaming regulators, tax authorities and law enforcement where the law requires it.
6. International transfers
Our primary systems are hosted within the European Economic Area. Where a supplier processes data outside the EEA, we rely on an adequacy decision by the European Commission or on the Commission's Standard Contractual Clauses, together with supplementary security measures.
7. How long we keep data
Reservation records are kept for five years after your stay for accounting purposes. Anti-money-laundering records are kept for at least five years after the end of the business relationship, as required by law. Standard CCTV footage is overwritten after 30 days unless it is needed for an investigation. Self-exclusion records are kept for the full exclusion period plus five years so that we can continue to protect you. Marketing preferences are kept until you unsubscribe.
8. Security
We use encryption in transit and at rest, role-based access control, multi-factor authentication for staff, regular penetration testing and staff training. Access to gaming and financial data is limited to employees whose role requires it.
9. Your rights
You have the right to access, correct, delete, restrict and port your data, and to object to certain processing. Full details, and how to exercise them, are set out in our GDPR/CCPA & Cookies Policy. You may also complain to the Norwegian Data Protection Authority (Datatilsynet) or the supervisory authority in the country where you live.
10. Children
Our website and gaming facilities are for adults only. We do not knowingly collect personal data from anyone under 18. Minors may stay in the hotel only as part of a family booking, and their data is limited to what is needed for the reservation.
11. Changes to this policy
We review this policy at least once a year. Material changes will be announced on this page and, where appropriate, by email to registered guests.