Privacy Policy
This Privacy Policy at 1win website describes how personal information is collected, processed, stored, and protected when individuals interact with the Platform and use the services provided through it.
The Policy applies to all digital resources operated by us, including websites, mobile versions, desktop applications, and any related tools, features, or products. It also applies to all interactions carried out through customer support channels and payment systems connected to the Platform.
Personal Data refers to information that identifies or can reasonably be linked to a specific person. Such information may include identification details, contact information, account data, payment records, betting activity, technical identifiers, and communication history. Information that has been anonymized and aggregated so that identification is no longer possible is not treated as Personal Data under this Policy.
Protection of privacy is treated as a legal and operational priority. Personal Data is processed in accordance with applicable data protection laws, gambling regulations, licensing conditions, and internal compliance rules. The nature and volume of data processed depend on how the Platform is used, the services requested, and the obligations imposed by law.
Updates to this Policy may occur due to changes in legislation, regulatory guidance, technical developments, or business operations. The current version is always available on the Platform. Continued use of the services after an update confirms acceptance of the revised Policy.
Types of Personal Data Processed
Several categories of Personal Data may be processed during use of the Platform.
Identification and account data include details provided during registration and account management. This may consist of full legal name, date of birth, phone number, email address, login credentials, and security settings. Where required, identity verification documents and proof of address are processed to confirm eligibility and meet regulatory duties.
Financial and transaction data includes deposit and withdrawal records, payment method identifiers, transaction timestamps, amounts, currencies, bonus usage, and internal account balances. Sensitive payment data is processed through secure channels and, where applicable, by certified third-party payment providers.
Betting and activity data includes records of bets placed, stakes, odds, outcomes, winnings, losses, betting patterns, limits applied to the account, and responsible gaming indicators. This data supports settlement of bets, risk management, and compliance monitoring.
Communication data includes messages sent through live chat, email correspondence, call records, complaints, dispute submissions, and any other information shared with customer support. These records support service delivery, dispute resolution, and quality control.
Technical and usage data includes IP address, device type, operating system, browser type, language preferences, access times, session identifiers, and diagnostic information. This data supports security, fraud prevention, system stability, and analytics.
How Personal Data is Collected
Personal Data is collected through multiple methods depending on the interaction with the Platform.
Information provided directly is collected when a person registers an account, fills in profile fields, submits documents for verification, contacts customer support, participates in promotions, or sends feedback.
Automatic collection occurs when the Platform is accessed. Technical systems record device and usage data to enable authentication, maintain sessions, protect accounts, and support analytics. Cookies and similar technologies store preferences, support navigation, and measure traffic.
Information from third parties may be received to supplement existing data. Such sources include payment providers, identity verification services, fraud prevention agencies, and publicly available records. This information supports verification, risk assessment, and regulatory compliance.
Legal Grounds for Processing
Personal Data is processed only where a lawful basis exists under applicable data protection laws.
- Contract performance applies where processing is required to provide services, manage accounts, accept bets, settle outcomes, process payments, and handle withdrawals;
- Legal obligations apply where processing is required to meet gambling regulations, anti-money laundering rules, responsible gaming requirements, tax laws, and reporting duties imposed by regulators or authorities;
- Legitimate interests apply where processing supports security, fraud prevention, service improvement, internal administration, risk control, and protection of users and the Platform, provided such interests do not override individual rights;
- Consent applies in limited cases, such as receipt of marketing communications or participation in optional features. Consent may be withdrawn at any time through account settings or by contacting support.
Purposes of Processing
Personal Data is processed to operate and maintain the Platform and to deliver the services requested. This includes account creation, verification of age and eligibility, acceptance and settlement of bets, management of bonuses, and processing of deposits and withdrawals.
Data is processed to meet legal and regulatory duties. This includes monitoring transactions, conducting identity checks, assessing responsible gaming risks, detecting suspicious activity, and reporting where required by law.
Customer support relies on Personal Data to respond to inquiries, resolve technical or payment issues, manage complaints, and handle disputes.
Communication records provide an audit trail and support accountability.
Technical processing supports maintenance, testing, and development of systems. Usage data helps identify errors, improve performance, and plan updates.
Security processing protects accounts and systems. Monitoring access patterns, detecting unusual behavior, and preventing unauthorized activity support the safety of users and the integrity of the Platform.
Marketing and communication processing supports the delivery of operational messages, updates, promotions, and offers, subject to applicable consent rules and opt-out options.
Sharing of Personal Data
Personal Data may be shared where necessary to operate the Platform or where required by law.
Sharing may occur within the corporate group for internal administration, compliance management, reporting, and risk control.
Service providers and partners may receive Personal Data to support payment processing, identity verification, hosting, analytics, marketing, and customer support. Such parties act under contractual obligations and data protection requirements.
Disclosure may occur to regulatory authorities, law enforcement agencies, courts, licensing bodies, or other public authorities where required by law or necessary to protect legal rights or public interests.
Affiliates and marketing partners may receive limited data for attribution and promotional purposes, subject to consent and contractual safeguards.
International Data Transfers
Personal Data may be processed in countries outside the country of residence. Where transfers occur, legal and technical safeguards are applied to protect Personal Data. These safeguards may include standard contractual clauses or equivalent mechanisms required under applicable data protection laws.
Security Measures
Appropriate technical and organizational measures protect Personal Data against unauthorized access, loss, alteration, or disclosure. Key security measures include:
- Encryption of data during transmission and storage using recognized industry standards;
- Restricted access to Personal Data based on role and necessity;
- Network security controls such as firewalls, monitoring systems, and intrusion detection;
- Secure hosting environments with physical access controls and continuous surveillance;
- Regular security monitoring, testing, and incident response procedures.
These measures are reviewed and updated to address emerging risks.
Data Retention
Personal Data is retained only for as long as necessary to meet operational, legal, and regulatory requirements. Retention periods depend on the type of data and applicable laws.
Account data is retained while an account is active and for a legally required period after closure. Transaction and financial records are maintained to meet accounting, tax, and anti-money laundering duties.
Communication records may be retained to resolve disputes, manage complaints, and demonstrate compliance.
When data is scheduled for deletion, secure deletion or anonymization methods are applied.
Extended Retention for Specific Purposes
Certain situations require longer retention of specific data sets. Self-exclusion records are retained to enforce responsible gaming obligations. Fraud prevention data may be retained to protect users and the Platform from repeated abuse. Legal claims and investigations may require preservation of records until resolution.
User Rights
Data protection laws grant specific rights in relation to Personal Data. These rights may include:
- Access to Personal Data held;
- Correction of inaccurate or outdated information;
- Receipt of a copy of data in a structured, machine-readable format;
- Objection to certain processing activities based on legitimate interests;
- Restriction of processing in specific circumstances;
- Withdrawal of consent where consent forms the legal basis;
- Objection to direct marketing communications.
Requests may be submitted through account settings or support channels. Identity verification may be required before action is taken. Some requests may be limited where retention is required by law or necessary to protect legal rights.
Cookies and Similar Technologies
Cookies and similar technologies store small amounts of information on a device to support functionality and preferences. These technologies help manage sessions, enable secure access, measure traffic, and analyze usage patterns.
Cookies may be categorized as necessary, functional, analytical, or promotional. Browser settings allow management of cookie preferences. Turning off certain cookies may limit access to some features.
Analytics Tools
Analytical tools measure usage patterns and support service improvement. These tools collect technical data such as IP address, access time, and page views. Data collected through analytics is used in an aggregated form and is not combined with direct identifiers unless required for security or compliance.
Secure Communication
Sensitive communication between users and the Platform is protected through encryption protocols. This protects credentials, payment information, and personal data during transmission.
Updated: