Privacy Policy

1. Introduction

This Privacy Policy explains how Basswin (the trading name used by the Company that operates the website at basswin.com) collects, uses, stores and protects the personal data of visitors and registered players. The Company is the data controller for the processing described below and operates under Curaçao jurisdiction. All processing of personal data complies with the General Data Protection Regulation (GDPR), the UK GDPR for players resident in the United Kingdom, and the California Consumer Privacy Act (CCPA) and California Privacy Rights Act (CPRA) for California residents.

By using basswin.com, by registering an account or by communicating with support, the user confirms that the terms of this Privacy Policy have been read and understood. Any questions about the policy or about the processing of personal data can be addressed to [email protected] at any time.

2. Scope

This policy covers all personal data processed through:

  • The website at basswin.com and any sub-domains operated by the Company;
  • Mobile browser access and the Basswin Android application distributed from the Company’s download page;
  • Interactions with customer support through live chat, email and phone;
  • Marketing communications where the player has given consent;
  • Account management, deposits, withdrawals, gameplay and promotions.

Third-party websites that may be linked from Basswin have their own privacy policies, and the Company is not responsible for the processing performed by any such third party.

3. What Personal Data We Collect

The Company collects the categories of data listed below.

  • Identity data: full name, date of birth, nationality, gender where provided;
  • Contact data: residential address, email address, mobile number;
  • Account credentials: username, password (stored in encrypted form), security questions and answers;
  • KYC and verification documents: government-issued photo identification (passport, driving licence, national ID card or residence permit), proof of address (bank statement or utility bill), front-and-back photos of payment cards used, selfie images taken with photo identification, and, for Revolut deposits, Card Confirmation statements;
  • Financial and payment data: card details, e-wallet references, bank account details, cryptocurrency wallet addresses, and transaction records including deposits, withdrawals, bonuses, wagers and winnings;
  • Source-of-funds documentation: bank statements, salary slips, declarations and similar records, requested when triggered by anti-money-laundering (AML) checks;
  • Gameplay and betting data: wagers placed, games played, outcomes, session times and bonus activity;
  • Technical and device data: IP address, device type and operating system, browser type and version, time-zone, geolocation signals and session identifiers;
  • Behavioural and usage data: pages viewed, features used, navigation paths and interactions with the website;
  • Responsible-gambling signals: deposit limits, loss limits, self-exclusion requests, time-outs and self-assessment results;
  • Marketing preferences: consent choices for email, SMS, push and other channels;
  • Cookies and similar technologies: see the Cookies notice below for the categories used and consent management.

4. How We Collect Personal Data

Personal data reaches the Company through several channels.

  • Directly from the player: when an account is registered, when KYC documents are uploaded, when a deposit or withdrawal is made, when support is contacted, and when marketing preferences are set;
  • Automatically through site use: through cookies, server logs, device fingerprints and analytics tools that run on basswin.com;
  • From third parties: KYC and identity-verification providers, payment processors, fraud-prevention databases, affiliates who refer players, and public registers for AML screening.

5. Legal Bases for Processing (GDPR)

The Company processes personal data under one or more of the following legal bases.

  • Performance of a contract: processing needed to create and operate the player account, process deposits and withdrawals, award bonuses and provide customer support;
  • Legal obligation: processing required to meet licensing, AML, KYC, taxation, record-keeping and law-enforcement cooperation duties under the laws applicable to the Company’s jurisdiction;
  • Legitimate interests: fraud prevention, platform and account security, responsible-gambling monitoring, protection of other players, and the Company’s defence of legal claims. These interests are balanced against each player’s rights and freedoms;
  • Consent: direct marketing communications, non-essential cookies, and any processing that would otherwise require explicit permission. Consent can be withdrawn at any time.

6. How We Use Personal Data

The Company uses the data described above for the following purposes.

  • Creating and administering the player account;
  • Verifying identity, age and address as required by law and by the Company’s licence;
  • Running AML, counter-terrorist-financing and fraud checks;
  • Monitoring for signs of problem gambling and applying responsible-gambling tools;
  • Processing deposits, withdrawals, bonuses and tournament prizes;
  • Providing customer support and resolving disputes;
  • Sending transactional messages (account notifications, verification requests, payout confirmations);
  • Sending marketing communications where the player has given consent;
  • Running analytics to improve the platform, the game library and the user experience;
  • Meeting licensing, regulatory, tax and audit obligations.

7. Sharing and Disclosure

Personal data is shared only with the parties listed below and only to the extent needed for the purpose stated.

  • Payment processors and banks handling deposits, withdrawals and chargebacks;
  • KYC and identity-verification providers performing document checks and biometric comparisons;
  • Game and software providers delivering the slots, live casino, sportsbook and crash games listed on basswin.com;
  • AML and fraud-prevention service providers running screening and risk-scoring checks;
  • Affiliates and marketing partners receiving aggregated or opt-in data for campaign measurement;
  • The licensing authority and independent auditors performing regulatory oversight of the operator;
  • Group companies and professional advisers (legal, accounting, IT) acting on the Company’s behalf under confidentiality obligations;
  • Law enforcement, courts and regulators where disclosure is required by law or by a valid legal process.

The Company does not sell personal data to third parties for their own marketing purposes. Any sharing beyond the list above requires the player’s explicit consent.

8. International Data Transfers

Some service providers used by the Company are located outside the European Economic Area and the United Kingdom. Where personal data is transferred internationally, the Company uses one or more of the following safeguards:

  • Transfers to countries covered by a European Commission adequacy decision;
  • Standard Contractual Clauses approved by the European Commission or the UK Information Commissioner’s Office;
  • Additional technical and organisational measures where a risk assessment indicates they are needed.

A summary of international transfer safeguards can be requested through [email protected].

9. Data Retention

Personal data is retained only as long as required by law or by the purpose for which it was collected. Specific periods apply to different categories:

  • Account, transaction and KYC records: retained for at least 5 years after account closure, in line with AML and gambling-licensing requirements;
  • Responsible-gambling records: retained for the duration of any self-exclusion plus a reasonable period afterwards;
  • Marketing data: retained until consent is withdrawn or until a reasonable inactivity period elapses;
  • Technical logs: retained for shorter periods aligned with security needs, typically 12 to 24 months.

Once a retention period ends, personal data is either deleted or anonymised so that it can no longer be linked to an identified individual.

10. Your Rights

GDPR and UK GDPR

Players and visitors in the EEA or the United Kingdom have the following rights:

  • Right of access: to request a copy of the personal data held about you;
  • Right of rectification: to correct inaccurate or incomplete data;
  • Right of erasure: to request deletion in defined circumstances;
  • Right to restrict processing in defined circumstances;
  • Right to data portability for data processed on the basis of consent or contract;
  • Right to object to processing based on legitimate interests, including profiling;
  • Right to withdraw consent at any time where processing is based on consent;
  • Right to lodge a complaint with a supervisory authority, such as the UK Information Commissioner’s Office (ico.org.uk) or the relevant EEA authority.

A right can be exercised by writing to [email protected]. The Company responds within one month of a valid request and may ask for proof of identity before acting.

CCPA / CPRA (California)

California residents additionally have the right to:

  • Know what personal information is collected, used, shared or sold;
  • Request deletion of personal information;
  • Request correction of inaccurate personal information;
  • Opt out of the sale or sharing of personal information (the Company does not sell personal information);
  • Limit the use of sensitive personal information;
  • Non-discrimination for exercising any of the above rights.

Requests from California residents can be sent to [email protected] with “CCPA request” in the subject line.

11. Cookies

Basswin uses cookies and similar technologies to run essential site functions, remember preferences, measure traffic and support marketing where consent is given. Consent is captured through the cookie banner shown on first visit. Each player can review and change cookie choices at any time through the cookie-settings link in the footer. Browser settings also allow cookies to be blocked or deleted directly, though doing so may limit certain features of basswin.com.

12. Security

The Company applies technical and organisational measures appropriate to the risk, including:

  • Industry-standard SSL/TLS encryption on all pages that transmit personal data;
  • Encrypted storage of passwords and sensitive documents;
  • Role-based access controls restricting staff access to personal data on a need-to-know basis;
  • Regular security reviews, penetration testing and monitoring;
  • Staff training on data protection, confidentiality and secure handling of information.

No system can guarantee absolute security, but the Company works continuously to reduce risk and respond quickly to any incident.

13. Children and Age Restriction

Basswin is strictly for adults aged 18 or over. The Company does not knowingly collect personal data from anyone under this age. If the Company becomes aware that a minor has created an account, the account is suspended immediately, any funds are returned, and the related personal data is deleted or anonymised. Parents or guardians who believe a minor has used basswin.com should contact [email protected].

14. Responsible Gambling and Related Data

Processing linked to responsible-gambling tools (deposit limits, time-outs, self-exclusion, self-assessment results) is performed to protect players and to meet legal obligations. See the Responsible Gambling page for a full description of the tools available and the external support organisations the Company recommends.

15. Changes to This Policy

The Company may update this Privacy Policy from time to time. The current version is always available at basswin.com, with the “Last updated” date shown at the top. Material changes are notified to registered players through email or an in-account message before taking effect. Continuing to use basswin.com after a change indicates acceptance of the updated policy.

16. Contact

For any question, request or complaint related to personal data or this Privacy Policy, contact the Company through the channels below:

Complaints that cannot be resolved directly with the Company can be referred to the relevant supervisory authority, such as the UK Information Commissioner’s Office (ico.org.uk).