Privacy Policy

1win processes personal data to deliver betting services while complying with data protection laws. Policy applies to website, apps, and all user interactions. Major updates notify users via email or site banner.​

Data Collection Sources

The company gathers personal information through three distinct channels during registration, gameplay, and support interactions. Direct inputs include identity documents while automatic collection captures technical usage data. Third-party sources validate provided information against public records.​

Collection MethodData Examples
User-providedName, email, phone, payment details, verification documents, support tickets ​
AutomaticIP address, device type, browser settings, transaction history, crash reports
Third-partyPayment processor data, public records for validation ​

Legal Processing Bases

Company processes data only under specific legal grounds required by applicable legislation. Contract performance covers account operations while legal obligations handle compliance requirements. Legitimate interests support security and service improvements.​

Legal BasisApplication Examples
Contract PerformanceRegistration, transactions, service delivery ​
Legal ObligationAML verification, responsible gaming checks
Legitimate InterestsFraud prevention, analytics, service optimization ​
ConsentMarketing communications (optional)

Primary Data Uses

Personal data enables core platform functions from account verification through payout processing. Legal bases determine each specific use case while ensuring compliance requirements. Company prioritizes data minimization principles throughout operations.​

Processing PurposeGoverning Basis
Account setup/verificationContract + Legitimate interest ​
Fraud prevention/AMLLegal obligation
Service delivery/paymentsContract performance ​
Technical supportContract
Security monitoringLegal obligation + Legitimate interest ​

Data Sharing Recipients

Company discloses information only to necessary third parties under strict contractual protections. Regulatory bodies receive data for compliance, while service providers operate under confidentiality agreements. User consent required for additional sharing beyond operational needs.​

Recipient CategoryDisclosure Purpose
Group companiesInternal administration ​
Service providersPayment processing, hosting, analytics
Regulators/law enforcementLegal compliance, investigations ​
AffiliatesUser referrals
Marketing partnersConsent-based only ​

Security Protection Measures

Multiple-layered defenses protect data throughout the collection, storage, and transmission phases. Industry-standard encryption secures all communications while access controls limit internal exposure. Continuous monitoring detects and responds to potential threats immediately.​

Security LayerImplementation Details
Data EncryptionTLS transmission + at-rest server encryption ​
Access ControlsRole-based employee restrictions
Network DefenseFirewalls, intrusion detection systems ​
Physical SecuritySecure data centers with 24/7 monitoring
Threat MonitoringReal-time security operations center ​

Data Retention Schedule

Company deletes data immediately when purposes complete except where legal requirements mandate retention. Account data persists five years post-closure for compliance while self-exclusion records maintain longer periods. User-initiated deletions process instantly where legally permitted.​

Data CategoryRetention Period
Active account dataUntil deletion + 5 years ​
Self-exclusion recordsExtended responsible gaming period
Transaction history5-7 years financial regulations ​
Marketing preferencesUntil withdrawal
Technical logs30-90 days operational needs ​

User Rights Summary

Individuals exercise eight core rights over personal data processing activities. Account settings handle routine requests while complex matters route through support email. Identity verification required before fulfilling data access or deletion requests.​

RightExercise Method
Access data copyAccount dashboard or [email protected] ​
Correct inaccuraciesProfile update
Request deletionSupport ticket with justification ​
Object to processingEmail notification
Withdraw consentMarketing unsubscribe ​
Restrict processingSupport request
PortabilityStructured format download ​
Lodge complaintLocal data protection authority

Cookie Categories Deployed

1win deploys four cookie categories to maintain platform operations and enhance user functionality. Each type serves distinct technical purposes from essential access through performance tracking. Users control non-essential cookies through browser settings while necessary types remain active for core service delivery.​

Cookie TypeDurationPurpose
NecessarySessionLogin authentication, secure transactions, navigation ​
FunctionalPersistentLanguage preferences, interface layout, user settings
Analytical2 yearsUsage statistics via Google Analytics (anonymous) ​
MarketingPersistentTargeted advertising, behavior tracking

International Transfer Safeguards

Data processing occurs across multiple jurisdictions with varying protection levels. EEA transfers utilize Standard Contractual Clauses ensuring equivalent protection standards. All international processors sign binding data protection agreements.​

Policy Amendment Process

Company updates policy based on regulatory changes or operational requirements. Significant modifications trigger user notifications through multiple channels. Continued platform usage constitutes acceptance of revised terms automatically.