Privacy & Security
Information Gathering
Betable Limited, operating the platform accessible at ivybet-casino.co.uk and licensed by the United Kingdom Gambling Commission under licence number 23328, acts as the data controller responsible for the collection, storage, and processing of personal data submitted by users of this website. The following categories of personal data are subject to processing in the course of service provision:
- Identity Data: Full legal name, date of birth, gender, and government-issued identification documentation, including copies of passports, national identity cards, and driving licences, as required for the purposes of identity verification and age verification in accordance with applicable gambling regulations.
- Contact Data: Residential address, electronic mail address, and telephone number, as provided during the account registration process or subsequently amended by the account holder.
- Financial Data: Bank account details, payment card information, transaction histories, deposit and withdrawal records, and source of funds documentation, collected for the purpose of facilitating financial transactions and fulfilling obligations under anti-money laundering legislation.
- Technical Data: Internet Protocol addresses, browser type and version, device identifiers, operating system information, session duration data, and referring uniform resource locators, collected automatically through the use of cookies and similar tracking technologies upon access to this website.
- Usage Data: Records of gaming activity, wager histories, game preferences, account login timestamps, and behavioural patterns observed during interaction with the platform.
- Communications Data: Records of correspondence submitted through customer support channels, including the content of electronic messages, live chat transcripts, and any attachments provided in connection with support enquiries.
- Compliance Data: Self-exclusion records, responsible gambling declarations, affordability assessments, and any documentation submitted in connection with safer gambling obligations imposed upon the operator by the United Kingdom Gambling Commission.
Personal data is collected directly from data subjects at the point of account registration, through ongoing use of the platform, and, where applicable, from third-party identity verification service providers, fraud prevention agencies, and credit reference agencies engaged by the operator for the purposes of regulatory compliance.
Data Usage
Personal data collected from users of this platform is processed exclusively for the purposes set out herein. Processing activities are conducted on the basis of one or more lawful grounds established under the United Kingdom General Data Protection Regulation and the Data Protection Act 2018, including the performance of a contract to which the data subject is party, compliance with legal obligations to which the operator is subject, the pursuit of legitimate interests of the operator, and, where applicable, consent provided by the data subject.
- Account Administration: Personal data is processed to establish, maintain, and administer user accounts, including the verification of identity and age, the enforcement of account terms and conditions, and the management of account-related correspondence.
- Service Provision: Usage data and financial data are processed to facilitate access to the gaming services offered through this platform, to process deposits and withdrawals, and to ensure the accurate settlement of wagers and the correct crediting of winnings to user accounts.
- Legal and Regulatory Compliance: Personal data is processed to satisfy obligations imposed upon the operator under applicable gambling legislation, anti-money laundering regulations, counter-terrorism financing requirements, and the conditions of the operating licence granted by the United Kingdom Gambling Commission. This includes the conduct of know-your-customer checks, source of funds investigations, and the monitoring of gaming activity for indicators of problem gambling.
- Fraud Prevention and Security: Technical data and financial data are processed to detect, investigate, and prevent fraudulent activity, money laundering, and other unlawful conduct, including through the use of automated screening tools and the sharing of data with fraud prevention agencies where lawfully permitted.
- Safer Gambling: Usage data is processed to monitor gaming behaviour and to identify indicators of harmful gambling patterns. Where such indicators are identified, appropriate interventions may be implemented in accordance with the operator's responsible gambling obligations and the requirements of the United Kingdom Gambling Commission.
- Customer Support: Communications data is processed to respond to enquiries, resolve complaints, and provide assistance to users in connection with the use of the platform and associated services.
- Marketing Communications: Where consent has been obtained from the data subject, contact data and usage data may be processed for the purpose of delivering promotional communications regarding offers, products, and services available through the platform. Data subjects retain the right to withdraw consent to the processing of personal data for marketing purposes at any time.
- Platform Improvement: Aggregated and anonymised usage data and technical data may be processed for the purposes of analysing platform performance, identifying technical issues, and improving the functionality and user experience of the website.
Personal data shall not be processed for purposes incompatible with those specified herein, nor shall it be transferred to third parties for their own independent marketing purposes without the explicit consent of the data subject.
Data Security
Betable Limited implements a comprehensive framework of technical and organisational measures designed to ensure the security, integrity, and confidentiality of personal data held in connection with the operation of this platform. These measures are maintained and reviewed on an ongoing basis to ensure their continued adequacy in light of developments in data security standards and the evolving risk environment.
- Encryption: All personal data transmitted between users and the platform is protected through the application of Transport Layer Security protocol, ensuring that data in transit is rendered unreadable to unauthorised third parties. Sensitive personal data held in storage, including financial data and identity documentation, is subject to encryption at rest using industry-standard cryptographic algorithms.
- Access Controls: Access to personal data held by the operator is restricted on a need-to-know basis. Robust authentication mechanisms, including multi-factor authentication requirements, are applied to administrative systems in which personal data is stored or processed. Access privileges are reviewed and audited on a regular basis.
- Network Security: The platform's technical infrastructure is protected by firewalls, intrusion detection systems, and continuous monitoring mechanisms designed to identify and respond to unauthorised access attempts and other security incidents in a timely manner.
- Data Minimisation: Personal data is collected and retained only to the extent necessary for the purposes for which it was collected. Retention periods are determined by reference to applicable legal and regulatory requirements and the operational necessity of the data in question.
- Retention and Deletion: Personal data is retained for a period of no less than five years following the closure of a user account, in accordance with obligations imposed by anti-money laundering legislation and gambling regulations. Upon the expiry of applicable retention periods, personal data is securely deleted or anonymised in accordance with established data disposal procedures.
- Third-Party Processors: Where personal data is shared with third-party service providers engaged by the operator, such sharing is conducted solely on the basis of written data processing agreements that impose obligations equivalent to those applicable to the operator under applicable data protection legislation. Third-party processors are subject to due diligence assessments prior to engagement.
- Incident Response: Procedures are maintained for the identification, assessment, and reporting of personal data breaches. In the event that a breach is determined to present a risk to the rights and freedoms of data subjects, notification shall be made to the Information Commissioner's Office within the timeframe prescribed by applicable legislation, and affected data subjects shall be informed where required.
- Staff Training: All personnel engaged in the processing of personal data are subject to data protection training and are bound by confidentiality obligations with respect to any personal data to which they are afforded access in the course of their duties.
Your Rights
Data subjects whose personal data is processed by Betable Limited are afforded a range of rights under the United Kingdom General Data Protection Regulation and the Data Protection Act 2018. These rights may be exercised by submitting a written request to the operator using the contact details provided in the section below. The operator is required to respond to such requests within one calendar month of receipt, subject to any extension permitted under applicable legislation in cases of complexity or volume.
- Right of Access: Data subjects are entitled to request confirmation as to whether personal data concerning them is being processed, and, where such processing is confirmed, to obtain a copy of the personal data held together with information regarding the purposes of processing, the categories of data concerned, and any recipients to whom the data has been or may be disclosed.
- Right to Rectification: Data subjects are entitled to request the correction of inaccurate personal data held by the operator, and the completion of incomplete personal data, without undue delay.
- Right to Erasure: Data subjects are entitled to request the deletion of personal data held by the operator where such data is no longer necessary for the purposes for which it was collected, where consent on which processing is based has been withdrawn, or where the data has been unlawfully processed. This right is subject to limitations where continued retention is required for compliance with legal obligations or for the establishment, exercise, or defence of legal claims.
- Right to Restriction of Processing: Data subjects are entitled to request that the processing of their personal data be restricted in specified circumstances, including where the accuracy of the data is contested or where processing has been determined to be unlawful but erasure is not requested.
- Right to Data Portability: Where processing is carried out by automated means on the basis of consent or contractual necessity, data subjects are entitled to receive personal data provided by them to the operator in a structured, commonly used, and machine-readable format, and to request the transmission of such data to another controller where technically feasible.
- Right to Object: Data subjects are entitled to object to the processing of their personal data where such processing is carried out on the basis of the legitimate interests of the operator or for the purposes of direct marketing. Where an objection is raised to processing for direct marketing purposes, the processing of personal data for such purposes shall cease without delay.
- Rights in Relation to Automated Decision-Making: Data subjects are entitled not to be subject to decisions based solely on automated processing, including profiling, that produce legal or similarly significant effects, except where such processing is necessary for the performance of a contract, is authorised by applicable law, or is based on the explicit consent of the data subject.
- Right to Withdraw Consent: Where processing is based on the consent of the data subject, such consent may be withdrawn at any time without affecting the lawfulness of processing carried out prior to withdrawal.
- Right to Lodge a Complaint: Data subjects who consider that the processing of their personal data by the operator is in breach of applicable data protection legislation are entitled to lodge a complaint with the Information Commissioner's Office, the supervisory authority responsible for data protection in the United Kingdom, accessible at ico.org.uk.
The operator shall not charge a fee for the handling of requests relating to the exercise of data subject rights, except where requests are manifestly unfounded or excessive, in which case a reasonable administrative fee may be applied or the request may be declined, with reasons provided to the data subject.
Get in Touch
All correspondence relating to the processing of personal data, the exercise of data subject rights, or any other matter arising under this privacy documentation should be directed to the operator using the following contact details. Requests submitted electronically shall be acknowledged upon receipt and addressed within the timeframes prescribed by applicable data protection legislation.
Betable Limited, operating ivybet-casino.co.uk, may be contacted in relation to data protection matters by electronic correspondence addressed to the following address:
Electronic Correspondence: [email protected]
Data subjects are advised that, in order for requests relating to the exercise of rights to be processed efficiently, sufficient information should be included in correspondence to enable the operator to identify the data subject and locate the relevant personal data. The operator may request additional verification information where necessary to confirm the identity of the individual submitting the request, in order to ensure that personal data is not disclosed to unauthorised parties.