Donbet Privacy Policy for Account, Payment and Verification Data

Effective date: 22 August 2026

This Privacy Policy explains how personal data is collected and used when an individual registers, verifies an account, makes a payment, uses casino or sportsbook products, contacts support or changes safer-gambling controls. It also describes the choices and rights connected with that processing. GTW B.V., company number 165433, is the Donbet operator; CYGTW LTD may process payment-related information as payment agent.

1. Information created during the account lifecycle

1.1 Registration and identity records

Account data can include name, date of birth, residential address, country, email, username, password credentials, communication preferences and account status. Verification records can include photo identification, proof of address, selfie or liveness results and information used to establish source of funds or payment ownership.

1.2 Financial and gambling records

Transaction information can include payment method, masked card or wallet identifiers, bank references, crypto addresses and transaction hashes, deposits, withdrawals, chargebacks and currency. Gambling records can include games opened, stakes, wins, losses, bonus activity, wagering progress, bet slips, odds, settlement, VIP points, Doncoins and limit history.

1.3 Device, security and cookie data

Technical records can include IP address, device type, operating system, browser, language, session identifiers, login time, approximate location, referral data and security events. Cookies and similar storage support login, fraud checks, preferences, analytics and campaign measurement.

2. Why each category is processed

PurposeTypical dataProcessing reason
Create and administer an accountIdentity, contact and login dataPerform the account contract
Process deposits and withdrawalsPayment, transaction and verification dataPerform the contract and meet legal obligations
Confirm age and identityID, address, liveness and risk dataLegal obligation and legitimate security interests
Operate casino, sport, bonuses and VIPBet, game, wallet and reward recordsDeliver requested services
Prevent fraud and account misuseDevice, payment and behavioural signalsLegal duties and legitimate interests
Provide support and resolve disputesMessages, references and account historyContract, legal claims and legitimate interests
Send optional marketingContact details and preferencesConsent or another permitted basis, with opt-out
Improve performanceCookie, device and aggregated use dataConsent where required and legitimate interests

Data is not collected merely because it may be useful later. The processing purpose should be connected with an account, legal duty, security control, requested service or clearly explained preference.

3. Recipients and payment processing

Personal data may be shared with payment processors, banks, card schemes, identity-verification services, fraud and security suppliers, hosting and analytics providers, customer-support systems, professional advisers and public authorities where legally required. CYGTW LTD, company number HE 462903, acts as a payment agent and may receive the information needed to process or reconcile a transaction.

Recipients should receive only the data reasonably required for their role. A processor acts under contractual and security obligations; an independent bank, regulator or authority may process data under its own legal duties.

4. International transfers

The operator, payment agent and service providers can be located in different jurisdictions. Where personal data crosses borders, contractual safeguards, adequacy mechanisms or another lawful transfer method may be used. The protection applied depends on the destination, recipient and legal basis.

5. Retention is linked to purpose and legal duty

Account data is retained while the account is active and for a period afterwards where payment, tax, anti-money-laundering, fraud, dispute or regulatory records must be preserved. Support messages, transaction evidence and self-exclusion records may need different retention periods. When information is no longer required, it should be deleted or anonymised, subject to backup and legal-hold cycles.

An immediate deletion request does not automatically override a legal retention obligation. The response should explain which data can be removed and which records must remain protected.

6. Cookies and preference controls

Essential cookies maintain login, session security, language and account navigation. Analytics cookies measure page and feature use. Marketing technologies can connect a visit with a campaign or preference. A consent tool or browser settings can be used to control non-essential storage, although disabling essential cookies can interrupt login or cashier actions.

Clearing cookies signs the device out and can reset remembered preferences. It does not erase the account, bets, transactions or KYC record stored on the platform.

7. Security measures and player responsibilities

Administrative, technical and organisational controls are used to protect account and payment information. These can include encryption in transit, access restrictions, monitoring, authentication controls and incident handling. No system eliminates all risk, so account holders also have responsibilities:

  • use a unique password and protect the email account linked to Donbet;
  • verify the domain before entering credentials;
  • never disclose a password, CVV, one-time code or crypto recovery phrase;
  • sign out on shared devices;
  • report an unfamiliar login or transaction immediately.

8. Data rights and request handling

Depending on applicable law, an individual may request access, correction, deletion, restriction, objection, portability or withdrawal of consent. A request should identify the account and right being exercised. Additional identity evidence may be required so data is not released to an impostor.

Requests can be sent through live chat or [email protected]. Marketing preferences can also be changed through the message itself or account controls. Withdrawing marketing consent does not stop operational messages about security, payments, terms or responsible gambling.

9. Automated risk signals

Automated tools can flag unusual login, payment, betting or verification activity. A flag may lead to additional review rather than a final decision by itself. Where law grants a right to challenge a significant automated decision, the account holder can ask for information and human review.

10. Children and age verification

Donbet accounts are for adults aged 18 or over. Age information and identity evidence may be checked. A parent or guardian who believes a minor has supplied personal data should contact support with enough information to locate the account without sending unnecessary sensitive documents by email.

11. Complaints and policy updates

Privacy concerns should first be raised with support, with the account username and a clear description of the processing in question. Individuals may also have the right to complain to the relevant data-protection authority. This policy can be updated to reflect legal, technical or operational changes; the effective date identifies the current text.