2. The information we collect2.1 As part of providing you with the Services, we collect your Personal Information on registering an account. “Personal Information" means any information from which you can be personally identified, including your name, surname, email address, home address, telephone number, mobile number and date of birth, credit card/debit card details and any other details as might be requested from you for the purpose of registration. We may also collect information from you if you request information or customer support. 2.2 As part of providing you with the Services, we also collect information about the transactions you undertake, including details of payment cards used, details of the games you played and underlying gaming transactions, details such as traffic information, location data, communication data including IP address and browser type, pages visited, content viewed, clicked links, URLs visited after you visited our website. 2.3 We may also collect information and communications on forums on websites, including chat rooms and message boards, profile comments, chat messaging with other operators or other users. We also collect your response to marketing campaigns from us or through our third parties, that is open/click on such emails; your social media profile details (name, profile photo and other information you make available to us) when you connect with or contact us through a social media account; information derived based on profiling activity (see below); and information from third party databases to comply with our legal and regulatory obligations. 2.4 Not all the personal information we hold about you will come always directly from you. We may also collect information from third parties such as our partners, service providers and publicly available websites (i.e social media platforms), to comply with our legal and regulatory obligations, offer Services we think may be of interest, to help us maintain data accuracy and provide and enhance the Services.
4. Disclosing your Personal Information4.1 Except as described in this Policy, we will not intentionally disclose the Personal Data that we collect or store on the Service to third parties without your prior explicit consent. We may disclose information to third parties in the following circumstances: 4.2 Any company within our Group (including to its employees, and all sub-contractors) which assists us in providing the Services or which otherwise has a need to know such information. 4.3 Any third party which assists us in providing the Services, including (but not limited to) payment processors, regulators where there is a breach or suspicion of breach of the relevant law pertaining to the relevant jurisdiction including the UK Gambling Commission, the Malta Gaming Authority, Sweden Spelinspektionen and Directorate General for the Regulation of Gambling. 4.4 Any third party which can assist us in verifying the accuracy of your Personal Information, including financial institutions and credit reference agencies (a record of the search may be retained by such third party) and also in the event of a merger, sale, restructure, joint venture, assignment, transfer, or other disposition of all or any portion of our business, assets. 4.5 Any third party which assists us in monitoring use of the Services, including the detection and prevention of fraud and collusion. 4.6 Any contractors or other advisers auditing any of our business processes or who have the need to access such information for the purpose of advising us. 4.7 Any law enforcement body which may have any reasonable requirement to access your Personal Information; 4.8 Any regulatory body or authorised entity which may have any reasonable requirement to access your Personal Information; and 4.9 Any of our potential purchasers or any investors in it or in any company within our Group (including in the event of insolvency). 4.10 If at any time you wish us to stop processing your Personal Information for the above purposes, then you may contact us and we will take the appropriate steps to stop doing so. Please note that when exercising your right to restrict processing, your Account will be closed and any promotional bonus, prizes or benefits which may have been acquired will be forfeited. Following the closure of your Account, we will retain and may continue to process your Personal Data as necessary to comply with our legal obligations. Under Malta Gaming Authority (MGA) licensing requirements, we are bound to satisfy a number of statutory obligations, specifically but not solely, the Prevention of Money Laundering and Funding of Terrorism Regulations (LN 372/2017) Article 13, which obliges us to retain any information stored for a minimum period of five years from the closure of your Account, for the purposes of the prevention, detection, analysis and investigation of money laundering or funding of terrorism activities. After this period has elapsed, your Personal Data will be deleted from our records. You may contact us by sending an email to email@example.com
5. Data Subject Rights5.1 We respect your privacy rights and provide you with reasonable access to the Personal Data that you may have provided through your use of the Services. Your principal rights under the GDPR are: a. the right for information; b. the right to access; c. the right to rectification; d. the right to erasure; e. the right to restrict processing; f. the right to object to processing; g. the right to data portability; h. the right to complain to a supervisory authority; and i. the right to withdraw consent. 5.2 If you wish to access or amend any other Personal Data we hold about you, or to request that we delete any information about you, you may contact us by sending an email to firstname.lastname@example.org. Once your request is received, we will send you an acknowledgment and handle it promptly. We will respond to these requests within a month, with a possibility to extend this period for particularly complex requests in accordance with Applicable Law. We will retain your information for as long as your account is active, as needed to provide you services, or to comply with our legal obligations, resolve disputes and enforce our agreements. Please see 5.3 below when requesting that we delete any information about you. 5.3 When you exercise the right to erasure, your Account will be closed and any promotional bonus, prizes or benefits which may have been acquired will be forfeited. Following the closure of your Account, we will retain and may continue to process your Personal Data as necessary to comply with our legal obligations. Under Malta Gaming Authority (MGA) licensing requirements, we are bound to satisfy a number of statutory obligations, specifically but not solely, the Prevention of Money Laundering and Funding of Terrorism Regulations (LN 372/2017) Article 13, which obliges us to retain any information stored for a minimum period of five years from the closure of your Account, for the purposes of the prevention, detection, analysis and investigation of money laundering or funding of terrorism activities. After this period has elapsed, your Personal Data will be deleted from our records. 5.4 You may update your preferences at any time by accessing your Player Account under ‘My Profile’. Please note that while any changes you make will be reflected in active user databases instantly or within a reasonable period of time, we may retain all information you submit for backups, archiving, prevention of fraud and abuse, analytics, satisfaction of legal obligations, or where we otherwise reasonably believe that we have a legitimate reason to do so. 5.5 You may decline to share certain Personal Data with us, in which case we may not be able to provide to you with some or all of the features and functionality of the Service. 5.6 At any time, you may object to the processing of your Personal Data, on legitimate grounds, except if otherwise permitted by applicable law. 5.7 In accordance with Applicable Law, we reserve the right to withhold personal data if disclosing it would adversely affect the rights and freedoms of others. Moreover, we reserve the right to charge a fee for complying with such requests if they are deemed manifestly unfounded or excessive. We may charge a reasonable administrative-cost fee if further copies are requested. 5.8 We may use your personal data for the purposes of automated decision-making when displaying marketing material and personalised advertisements based on your preferences or interests. For instance, we may show you adverts for certain games or VIP/Loyalty program offers depending upon your activity. When such processing takes place, we will request your specific and explicit consent and will always provide you with the option to opt out. We may use automated decision-making in order to fulfil obligations imposed by law to which we are subject, in which case we will inform you of any such processing. By way of example, to fulfil our obligations in relation to fraud, tax evasion, suspicious betting pattern reporting, providing alerts for responsible gaming amongst others. We may also use automated decision-making in the limited instances when this is necessary for entering into, or the performance of, a contract entered between us and the data subject. Decisions on the basis of profiling are not taken automatically without human intervention. Moreover, the process is based on our interest regarding providing customised, quality experience for the players and reward loyalty of the players. You have the right to object to the processing of your personal data for automated purposes at any time by contacting us via email@example.com
7. Security7.1 We take appropriate security measures to protect against loss, misuse and unauthorized access, alteration, disclosure, or destruction of your information. We have taken steps to ensure the ongoing confidentiality, integrity, availability, and resilience of systems and services processing personal information, and will restore the availability and access to information in a timely manner in the event of a physical or technical incident. 7.2 Your winnings and cashouts are kept strictly confidential, and winnings information is stored in secure operating environments. We do not provide winnings information to any third party unless such information is required to be disclosed by law, regulation or a similar governmental authority. 7.3 No method of transmission over the Internet, or method of electronic storage, is 100% secure. We cannot ensure or warrant the security of any information you transmit to us or store on the Service, and you do so at your own risk. We also cannot guarantee that such information may not be accessed, disclosed, altered, or destroyed by breach of any of our physical, technical, or organisational safeguards. If you believe your Personal Data has been compromised, please contact firstname.lastname@example.org. 7.4 If we learn of a security systems breach, we will inform you of the occurrence of the breach in accordance with applicable law.
8. Privacy SettingsAlthough we may allow you to adjust your privacy settings to limit access to certain Personal Data, please be aware that no security measures are perfect or impenetrable. Additionally, we cannot control the actions of other users with whom you may choose to share your information. We cannot and do not guarantee that information you post on or transmit to the Service will not be viewed by unauthorized persons. We have taken the necessary steps to protect as much as possible your Personal Information in transit by utilising HTTPS on our Website and TLS 1.2 (a strong protocol), ECDHE_RSA with P-256 (a strong key exchange), and AES_128_GCM (a strong cipher).
9. Data Retention9.1 Although we may allow you to adjust your privacy settings to limit access to certain Personal Data, please be aware that no security measures are perfect or impenetrable. Additionally, we cannot control the actions of other users with whom you may choose to share your information. We cannot and do not guarantee that information you post on or transmit to the Service will not be viewed by unauthorized persons. We have taken the necessary steps to protect as much as possible your Personal Information in transit by utilising HTTPS on our Website and TLS 1.2 (a strong protocol), ECDHE_RSA with P-256 (a strong key exchange), and AES_128_GCM (a strong cipher). 9.2 We only retain the Personal Data collected from you for as long as your account is active or otherwise for a limited period of time as long as we need it to fulfil the purposes for which we have initially collected it, unless otherwise required by law. We will retain and use information as necessary to comply with our legal obligations, resolve disputes, and enforce our agreements as follows: For the unregulated jurisdictions in which operate, and subject to us not having a legal or regulatory requirement or a risk management reason for retaining your information for a longer period, your information will not be kept for longer than 7 years post account closure. Please note that we may be required, in certain circumstances, to retain your information indefinitely (for example under our procedures on responsible gambling and self-exclusion). We will take all necessary steps to ensure that the privacy of information is maintained for the period of retention. 9.3 We may retain your personal data where such retention is necessary for compliance with a legal obligation to which we are subject, or in order to protect your vital interests or the vital interests of another natural person. 9.4 In case of the landing page (as described in section 2 above), information will be retained for a minimum period of 12 months reflecting our business needs and legal requirements.
11. Data Protection Officer11.1 We have appointed a Data Protection Officer (“DPO”) who is responsible for matters relating to privacy and data protection. The DPO can be reached on: email@example.com
12. Complaints12.1 You can report a concern or file a complaint regarding your privacy or data protection by contacting our data protection officer on firstname.lastname@example.org or at the office of the Information and Data Protection Commissioner Malta on email@example.com.
Anti Spam Policy
Funbet is subjected to an Anti-Spam policy called *zero tolerance*. Funbet is committed to keep you informed about any changes made to this policy by email or newsletter, if you have subscribed. This means that we do not send out any mass emails including information about our games or promotions. The options to register or to unsubscribe from our email list will always be offered when you register on Funbet. Members of our website may use the unsubscribe link to be removed from our mailing lists. Funbet also practices a *zero tolerance* policy for the purchase or sale of any email lists. Under no circumstances will we contact customers using purchased third party email lists.