Privacy Policy
Information Gathering
This Privacy Policy governs the collection, processing, and storage of personal data by Betable Limited, operating the digital platform accessible at ivybet-casino.co.uk, under the authority of the United Kingdom Gambling Commission, licence number 23328. All data processing activities are conducted in strict accordance with the United Kingdom General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018.
The following categories of personal data are subject to collection and processing by Betable Limited:
- Identity Data: Full legal name, date of birth, gender, nationality, and copies of government-issued identification documents, including passports and driving licences, as required for the fulfilment of statutory Know Your Customer (KYC) obligations.
- Contact Data: Residential address, electronic mail address, and telephone numbers provided at the time of account registration or subsequently updated by the data subject.
- Financial Data: Banking institution details, payment card particulars, transaction histories, deposit and withdrawal records, and source of funds documentation where applicable under anti-money laundering regulations.
- Technical Data: Internet Protocol (IP) addresses, browser type and version, device identifiers, operating system information, session durations, and referral source data collected automatically upon access to the platform.
- Behavioural Data: Wagering activity records, game participation history, betting patterns, account access timestamps, and interaction logs generated through the use of platform services.
- Communications Data: Records of correspondence conducted between the data subject and Betable Limited via electronic mail, live support channels, or other designated communication methods.
- Verification Data: Documentation and information collected in connection with age verification, identity verification, and responsible gambling assessments as mandated by the United Kingdom Gambling Commission.
Personal data is obtained directly from data subjects at the point of account registration, through ongoing use of platform services, via automated technical mechanisms, and, where legally permissible, from authorised third-party sources including credit reference agencies, fraud prevention organisations, and regulatory databases.
Data Usage
Personal data collected by Betable Limited is processed exclusively for the following defined and legitimate purposes, each of which is supported by an appropriate lawful basis as prescribed under UK GDPR Article 6 and, where applicable, Article 9:
- Account Administration: The establishment, maintenance, verification, and management of registered user accounts are conducted using identity and contact data to ensure the integrity and security of the platform. This processing is necessary for the performance of a contract to which the data subject is party.
- Regulatory Compliance: Compliance with obligations imposed by the United Kingdom Gambling Commission, His Majesty's Revenue and Customs, the Proceeds of Crime Act 2002, the Terrorism Act 2000, and associated secondary legislation necessitates the processing of identity, financial, and verification data. Such processing is conducted on the basis of legal obligation.
- Age and Identity Verification: Verification of the data subject's age and identity is mandatory prior to the activation of gambling facilities, in accordance with conditions attached to licence number 23328. Processing for this purpose is carried out on the basis of legal obligation and legitimate interest.
- Financial Transaction Processing: The facilitation, recording, and reconciliation of deposit and withdrawal transactions require the processing of financial data. This activity is performed as a necessary component of contractual performance.
- Fraud Prevention and Security: Technical and behavioural data are analysed for the purposes of detecting, investigating, and preventing fraudulent activity, unauthorised account access, money laundering, and other forms of financial crime. This processing is conducted on the basis of legitimate interest and legal obligation.
- Responsible Gambling: Betable Limited is obligated under the terms of its operating licence to monitor gambling behaviour, identify indicators of potential harm, and implement appropriate interventions. Behavioural and communications data are processed for this purpose on the basis of legal obligation and the protection of vital interests.
- Customer Support: Communications data is processed to enable the provision of assistance to data subjects in relation to account queries, technical difficulties, and dispute resolution. Processing for this purpose is necessary for the performance of a contract.
- Legal Proceedings and Dispute Resolution: Where necessary, personal data may be processed for the purposes of establishing, exercising, or defending legal claims. Such processing is conducted on the basis of legitimate interest.
- Platform Improvement and Analytics: Aggregated and anonymised technical and behavioural data may be utilised for the purposes of evaluating platform performance and informing operational decisions. Where such data remains truly anonymised, it falls outside the scope of data protection legislation.
- Marketing Communications: Where explicit consent has been obtained from the data subject in accordance with applicable legislation, contact data may be utilised to transmit promotional communications. Consent may be withdrawn at any time without detriment to the data subject.
Personal data shall not be processed for purposes incompatible with those specified above. Data is retained only for the period necessary to fulfil the purpose for which it was collected, subject to statutory minimum retention requirements imposed by regulatory authorities, which may require retention for a minimum period of five years following the cessation of the business relationship.
Personal data may be disclosed to authorised third-party processors, including payment service providers, identity verification agencies, fraud prevention bureaux, and regulatory bodies, solely to the extent necessary for the fulfilment of the purposes described herein. All third-party processors engaged by Betable Limited are required to maintain appropriate data protection standards by contractual obligation. International transfers of personal data, where undertaken, are conducted in compliance with Chapter V of UK GDPR and supported by appropriate transfer mechanisms.
Security Measures
Betable Limited has implemented a comprehensive framework of technical and organisational security measures designed to protect personal data against unauthorised access, accidental loss, destruction, alteration, and unlawful disclosure. These measures are reviewed and updated periodically to reflect developments in applicable standards and identified risks.
The technical security measures currently in place include the following:
- Encryption: All personal data transmitted between data subjects and the platform is protected by Transport Layer Security (TLS) encryption. Sensitive data retained within organisational systems is subject to encryption at rest utilising industry-standard algorithms.
- Access Controls: Access to personal data held within organisational systems is restricted on a strictly need-to-know basis. Role-based access control mechanisms are applied to ensure that personnel are granted access only to data necessary for the performance of their designated responsibilities.
- Authentication Mechanisms: Multi-factor authentication protocols are required for access to internal systems containing personal data. Privileged access is subject to enhanced authentication requirements and logging.
- Intrusion Detection and Prevention: Network monitoring systems and intrusion detection and prevention mechanisms are deployed to identify and respond to unauthorised attempts to access organisational infrastructure and data assets.
- Vulnerability Management: Regular vulnerability assessments and penetration testing exercises are conducted by qualified personnel to identify and remediate security weaknesses within the platform and associated systems.
- Data Minimisation: Technical configurations are applied to ensure that only the minimum necessary personal data is collected, processed, and retained, consistent with the principle of data minimisation as prescribed by UK GDPR Article 5(1)(c).
- Audit Logging: Comprehensive audit logs are maintained in relation to access to, and processing of, personal data. These logs are retained for a defined period and reviewed periodically as part of ongoing security monitoring activities.
- Secure Data Disposal: Personal data that has reached the end of its defined retention period is subject to secure and irreversible deletion or destruction, in accordance with documented data disposal procedures.
The organisational security measures maintained by Betable Limited include the following:
- Data Protection Policies: Formal data protection policies and procedures have been adopted and are maintained in written form. These documents are reviewed at defined intervals and following any material changes to processing activities or applicable legislation.
- Personnel Training: All personnel engaged in the processing of personal data are required to complete mandatory data protection training upon commencement of employment and at regular intervals thereafter. Awareness of data protection obligations is reinforced through ongoing communications.
- Contractual Obligations: Third-party processors and service providers engaged by Betable Limited are required to enter into data processing agreements that impose binding data protection obligations consistent with those applicable to Betable Limited itself.
- Incident Response: A documented personal data breach response procedure is maintained, providing for the prompt identification, containment, assessment, and notification of personal data bre