Privacy Policy

Introduction

Ffbet (the "Company") processes personal data as the data controller in accordance with applicable data protection laws, including the General Data Protection Regulation (GDPR). This Privacy Policy explains what personal data we collect, how we use it, with whom we share it, the safeguards we apply, and the rights you may exercise in relation to your information. For questions about this Policy, contact our Data Protection Officer at privacy@ffbet.

Scope and Application

This Policy applies to all individuals who access or use Ffbet services, including players, applicants, and other users. It governs data collected through account registration, gameplay, customer support interactions, marketing communications, and any other engagement with Ffbet.

Privacy Principles

We apply GDPR-based principles in all processing activities, namely:

  • Lawfulness, fairness and transparency — we rely on valid bases and inform you clearly about processing.
  • Purpose limitation — data is collected for specific, explicit purposes and not used in ways that are incompatible.
  • Data minimisation — we collect only data that is necessary for the stated purposes.
  • Accuracy — we maintain accurate data and correct errors promptly.
  • Storage limitation — retention periods are defined and applied in a retention policy.
  • Integrity and confidentiality — we implement appropriate technical and organizational measures to safeguard data.
  • Accountability — we maintain records of processing activities and compliance measures.

Categories of Personal Data We Collect

We collect data in connection with your use of the services, including:

  • Registration data — username, password, date of birth, country of residence, full name, email address, phone number and postal address where applicable.
  • Profile and activity data — IP address, device information, login times, transaction history, payment method details, gameplay history, bonuses, applied limits, self-exclusion status, and communications with support.
  • Financial data — payment history, bank/credit card details where required to process transactions, and withdrawal history.
  • Identity and verification data — copies of identification documents (e.g., passport or ID card), proof of address, and any documents required for verification.
  • Other data we generate or collect during use — customer support interactions, preferences, and feedback.

Data Sources and Verification

The majority of data is provided directly by you. We also obtain information from verification providers for identity and age checks, and we may consult:

  • Open sources and public records where permitted by law
  • Self-exclusion registers to enforce exclusion where applicable
  • Payment service providers to connect transactions to your account
  • Banks or financial institutions involved in processing payments
  • Third-party service providers engaged to verify source of funds or conduct risk assessments

Data Use and Legal Bases

We process personal data for the following purposes and on the corresponding legal bases:

  • Performance of a contract — to provide and manage your account and our services.
  • Legal compliance — to meet licensing, AML/CFT, and regulatory obligations.
  • Legitimate interests — to secure the platform, detect and prevent fraud, and improve our services.
  • Consent — for processing activities based on your explicit consent, including certain marketing communications where permitted by law.

Responsible Gaming, Age Verification and Self-Exclusion

We implement age verification to ensure eligibility for products and apply self-exclusion measures in accordance with responsible gaming policies. Data collected for these purposes may be used to assess risk, enforce limits, and cooperate with self-exclusion registers or regulators as required by law.

Data Retention

We retain personal data in accordance with applicable law and regulatory requirements. In general, we keep records for five to ten years after account closure. Health-related data provided for responsible gaming assessments will be deleted after review by the responsible gaming function and the Data Protection Officer. Closed or self-excluded accounts are retained securely for the retention period and then destroyed.

Data Sharing with Third Parties

We share personal data only as necessary to provide services and comply with legal obligations. Recipients include:

  • Payment service providers and banks
  • Corporate services, auditors and legal counsel
  • Analytics, identity verification and AML service providers
  • Marketing and communications platforms
  • Game providers and other entities within the corporate group
  • National self-exclusion registers
  • Regulators, law enforcement and other authorities as required by law

International Transfers

Where possible, we keep data within the European Economic Area (EEA). If transfers outside the EEA are necessary, we implement appropriate safeguards, including Standard Contractual Clauses. Some processors and affiliates may reside outside the EEA, including in jurisdictions not deemed adequate by the EU. In such cases, we apply contractual protections and additional safeguards to ensure data protection and lawful transfer.

Data Security

We implement appropriate technical and organizational measures to protect personal data against accidental or unlawful destruction, loss, alteration, unauthorized disclosure, and access. This includes access controls, encryption where appropriate, routine security assessments, and an incident response framework.

Your Rights

You have rights under applicable data protection law, including:

  • Right of access to your personal data and to obtain a copy
  • Right to rectify inaccuracies or incomplete data
  • Right to erasure where legally permissible
  • Right to restrict processing
  • Right to object to processing, including direct marketing
  • Right to data portability
  • Right to withdraw consent where consent is the basis for processing
  • Right to lodge a complaint with a supervisory authority

Exercising Your Rights

To exercise any rights, contact our Data Protection Officer at privacy@ffbet. We may require identity verification before fulfilling requests. We will respond within legally prescribed timeframes and inform you of the outcome.

Data Retention of Communications and Marketing

Marketing communications are subject to your preferences. You may withdraw consent or unsubscribe in relation to certain communications in accordance with applicable law.

Changes to This Policy

We may update this Privacy Policy from time to time. Material changes will be described clearly, with the effective date stated at the top of the policy. Continued use of the services after changes constitute acceptance of the revised policy.

Governing Law and Complaints

This Policy is governed by applicable data protection laws. You may lodge complaints with the competent supervisory authority if you believe your data rights have been violated or processing is unlawful.