Urgent Thoughts of self-harm or suicide are an emergency — call your local emergency number, 988 (US/CA), 116 123 (UK/IE) or 112 (EU). Gambling helplines →
PlayerHelpline.com Player protection reference

Independent · non-commercial
No operator funding · no affiliate links · 18+
Reference edition 2026.1 · reviewed 14 August 2026

Legal · document 01

Privacy Policy

What this site processes when you visit it, why, on what legal basis, for how long, and what you can require us to do about it. Written to be read: the short version is that there are no accounts, no advertising, no profiling, and the three tools on the home page keep your input inside your own browser.

Effective14 August 2026 Last updated14 August 2026 Version2.1 ControllerMerci Europe s. r. o.

Who we are

PlayerHelpline.com (“we”, “us”, “our”) is an independent, non-commercial reference on online player protection and gambling-related harm. The site is published and operated by Merci Europe s. r. o., a company registered in the Czech Republic, which is the controller of the personal data described in this policy within the meaning of Article 4(7) GDPR.

Controller — registered company details Verified against the Czech Commercial Register
Legal name
Merci Europe s. r. o.
Legal form
Společnost s ručením omezenýmPrivate limited liability company, Czech Republic
Registered office
Radniční 3
434 01 Most
Czech Republic
Company number (IČO)
117 28 051
Register
Commercial Register kept by the Regional Court in Ústí nad LabemSection C, insert 47506
Registered since
9 August 2021
Represented by
Hum Jae Park, sole managing director (jednatel)Authorised to represent the company acting alone
Contact for data matters
[email protected]Mark the subject line “data request”

Registered-office post is accepted for formal notices. No data protection officer is appointed, as the criteria in Article 37 GDPR are not met; because the controller is established in the Czech Republic, our lead supervisory authority is the Czech Office for Personal Data Protection (Úřad pro ochranu osobních údajů).

Written enquiries on any subject, including data-protection requests, go to [email protected]. If we later appoint a data protection officer or an EU/UK representative, their details will appear in this section.

Summary

  • No registration, no accounts, no logins — there is nothing to sign up for.
  • No advertising network, no behavioural tracking, no profiling, and no sale or sharing of personal data.
  • The risk self-check, cost projection and action checklist all run in your browser and send nothing to us.
  • Routine processing is limited to hosting logs and, where used, aggregate non-identifying statistics.
  • If you email us, we process what you write for as long as we need to deal with it.

What we process

Technical data in hosting logs

As with any web server, our hosting provider records requests. A log entry may contain your IP address (truncated where technically possible), timestamp, the resource requested, HTTP status code, bytes transferred, referring URL and user-agent string. We use these for delivery, diagnostics and security, not to build a picture of an individual.

Aggregate usage statistics

We may use a privacy-preserving analytics service configured so that it sets no advertising cookies, attempts no cross-site tracking and creates no persistent identifier or profile. What we see is aggregate: page views, entry pages, approximate country, device category, referring domain.

Correspondence

If you email us we process your address, your message, any attachments and our reply. Please do not send health information, financial details, gambling account credentials or another person’s data. If you do send sensitive information, we treat it as confidential and delete it once the enquiry is closed.

The three client-side tools

The home page carries three interactive tools. All three are implemented as plain JavaScript executing on your device. None of them has a server endpoint, and the site has no mechanism for receiving their contents:

Risk self-check (Tool 01)
Your nine answers and the resulting score exist only in the page’s memory. They are not written to cookies, local storage or session storage, are not transmitted, and are discarded when you close or reload the page.
Cost projection (Tool 03)
The amounts you enter are used for arithmetic in the browser and are never sent anywhere. Changing a figure recalculates locally; nothing is logged.
Action checklist (Tool 02)
Ticks are held in the page only. This is a deliberate trade-off: it means your progress does not survive a reload, and it also means no record exists that you were working through it.

Because none of this data reaches us, we cannot produce it in response to any request, including a lawful one. The printed output of the checklist exists only on your device or paper.

What we do not collect

  • No names, addresses or telephone numbers, unless you volunteer them by email.
  • No payment or bank data — the site takes no payments of any kind.
  • No gambling account credentials. We never ask for them, and nor should any legitimate support service.
  • No advertising identifiers, tracking pixels, fingerprinting scripts or data brokerage.
  • No special category data (health, beliefs and similar) — by design, not by policy alone.

Purposes and legal bases

Where the EU or UK GDPR applies, we rely on the following:

Purpose Data Legal basis
Delivering the site and keeping it available Technical log data Legitimate interests — operating a functioning service
Detecting and preventing attacks, abuse and fraud Technical log data Legitimate interests — security
Understanding, in aggregate, which material is read Non-identifying aggregate statistics Legitimate interests; consent where local law requires it
Answering your enquiry or correction Correspondence Legitimate interests, or steps taken at your request
Meeting legal obligations and lawful requests As applicable Compliance with a legal obligation

Where we rely on legitimate interests we have assessed that the processing is limited to what is necessary and does not override your rights. You may object at any time — see Your rights.

Cookies and storage

The site is static HTML, CSS and JavaScript. It sets no advertising or profiling cookies, and the interactive tools deliberately use no browser storage at all. Any cookie or equivalent that is used falls into one of these categories:

Category Purpose Consent Duration
Strictly necessary Security, load balancing, delivery of requested pages Not required Session, or up to 12 months for security tokens
Statistics Aggregate, non-identifying measurement Requested where local law requires it Session, or cookieless
Preference Not currently used; would only ever be set by your own action Not required Up to 12 months
Marketing Not used on this site

You can block or delete cookies in your browser, and we honour the Global Privacy Control signal where our tooling supports it. Nothing on this site requires you to accept tracking in order to read it.

Processors and disclosure

We keep third parties deliberately few. Those that may process data on our behalf, under a written processing agreement, are:

  • Hosting and content delivery provider — serves the pages, maintains security logs.
  • Email provider — receives and stores correspondence.
  • Privacy-focused analytics provider — produces aggregate statistics, where used.

Beyond these, we disclose personal data only where legally required, or where necessary to establish, exercise or defend legal claims. We do not sell personal data and do not “share” it for cross-context behavioural advertising as US state privacy statutes define those terms.

Organisations in our helpline directory are independent of us. Contacting one creates a relationship between you and them under their own privacy notice; we receive no report of who contacted whom, and we could not link such a report to a visit even if we received one.

International transfers

Our providers may process data outside your country, including in the United States. Where personal data leaves the European Economic Area or the United Kingdom, we rely on an adequacy decision where one exists, and otherwise on the European Commission’s Standard Contractual Clauses with the UK Addendum where applicable, together with technical measures such as encryption in transit and at rest.

Retention

Hosting logs
Kept no longer than needed for security and diagnostics — as a rule up to 30 days — then deleted or irreversibly aggregated. Entries relevant to a live security incident are held until it is closed.
Aggregate statistics
Held in aggregate form, which is no longer personal data, for up to 26 months.
Correspondence
Up to 24 months after the last message, so we can follow up corrections and show how enquiries were handled, then deleted.
Tool input
Never stored. It exists in your browser and only until the page is closed or reloaded.

Security

The site is served over HTTPS with modern TLS. Our primary safeguard is minimisation: the most reliable way to protect data is not to hold it, which is why the tools were built to keep your input local. Access to correspondence is restricted to those who need it and protected by multi-factor authentication. No method of transmission or storage is completely secure, and we cannot guarantee absolute security. Where a personal data breach is likely to result in a risk to your rights, we will notify the competent supervisory authority and, where required, affected individuals.

Security vulnerabilities can be reported to [email protected]. Please allow us a reasonable period to remedy an issue before publishing it.

Your rights

Subject to the conditions in applicable law, you may:

  • obtain confirmation of whether we process your personal data, and a copy of it;
  • have inaccurate data corrected and incomplete data completed;
  • have data erased where no overriding basis for keeping it exists;
  • obtain restriction of processing while a dispute is resolved;
  • receive data you provided in a portable format, where that right applies;
  • object to processing based on legitimate interests, including profiling — we carry out none;
  • withdraw consent at any time where processing rests on consent, without affecting processing already carried out lawfully.

Write to [email protected]. We respond within one month, extendable by two further months for complex requests, and we will tell you if an extension applies. Requests are free unless manifestly unfounded or excessive.

A practical limit

We hold no accounts and no identifier linking a log entry to a person, so in most cases we cannot connect technical records to you. Where that is the case we cannot comply with an access or erasure request in respect of that data, and we will explain why rather than ask you to send identity documents we have no basis to hold.

US state privacy rights

If you are a resident of California or another state with comparable legislation, you have the right to know what personal information is collected, to access, delete and correct it, and not to be discriminated against for exercising those rights. You may also opt out of sale, sharing and targeted advertising — none of which we carry out. We do not knowingly process the personal information of consumers under 16 for such purposes, because we do not carry out such purposes at all. Requests go to [email protected] and may be submitted by an authorised agent with proof of authority.

Children

This site addresses adults, and gambling is prohibited for minors. We do not knowingly collect personal data from anyone under 16, or under the higher age set by local law. Material for parents, guardians and carers is in Section 10 of the reference. If you believe a child has sent us personal data, write to us and we will delete it promptly.

Automated decisions

We carry out no automated decision-making with legal effects and no profiling. The self-check score is an arithmetic total computed in your browser: it is not a decision about you, not a clinical assessment, and not visible to us.

External links

We link to regulators, self-exclusion schemes and support organisations. Following such a link takes you to a service we do not control and whose privacy practices we cannot warrant. Read the privacy notice of any site before submitting information to it — and note the warning in Section 12 about pages that imitate helplines.

Changes

We may amend this policy to reflect changes in our practices or in the law. The effective date at the top of the page always identifies the current version. Where a change materially affects how we handle personal data, we will publish a prominent notice on the home page for a reasonable period. Continued use after the effective date means the amended policy applies to that use.

Contact and complaints

All correspondence, including privacy enquiries and rights requests, goes to a single address: [email protected]. Please put “data request” in the subject line so it is routed and logged correctly.

If our response does not satisfy you, you may complain to a data protection authority. Because the controller is established in the Czech Republic, our lead supervisory authority is the Office for Personal Data Protection (Úřad pro ochranu osobních údajů), Pplk. Sochora 27, 170 00 Prague 7, Czech Republic. You may equally complain to the authority in your own country of residence or place of work — in the United Kingdom, the Information Commissioner’s Office. We would nevertheless prefer the chance to put it right first.

Back to top · Terms & Conditions · Reference home