Privacy Policy
Brand: Zizobet | Website: zizzobett.uk | Version: 1.0 | Last Updated: 23 September 2026
1. Introduction
1.1. Welcome to Zizobet (referred to in this document as "we", "us", or "our"). We operate the online gaming platform accessible at zizzobett.uk (the "Platform"). We are committed to protecting your personal data and respecting your privacy at every stage of your relationship with us.
1.2. This Privacy Policy (the "Policy") explains in clear and transparent terms:
- what personal data we collect from you and how we obtain it;
- the purposes for which we use that data;
- the legal bases that permit us to process it;
- with whom we share it and the safeguards we apply;
- how long we keep it;
- the rights you hold over your own data and how to exercise them.
1.3. This Policy applies to all visitors, registered users, and any other individuals whose personal data we process in connection with the Platform. It should be read alongside our Terms & Conditions and our Responsible Gaming Policy.
1.4. We process personal data in accordance with the UK General Data Protection Regulation (UK GDPR) as it forms part of domestic law by virtue of the European Union (Withdrawal) Act 2018, together with the Data Protection Act 2018 and any applicable secondary legislation.
1.5. By accessing or using the Platform, you acknowledge that you have read and understood this Policy. If you do not agree with its terms, please discontinue use of the Platform immediately.
2. Data We Collect
2.1. Data You Provide Directly
When you register an account, make deposits, contact our support team, or otherwise interact with the Platform, you provide us with personal data, including but not limited to:
- Identity Data: full name, date of birth, gender, username;
- Contact Data: email address, telephone number, residential address, postcode;
- Verification & KYC Data: government-issued photographic identity documents (e.g. passport, driving licence), proof of address documents, source of funds documentation;
- Financial Data: payment card details (partial), bank account information, transaction history, deposit and withdrawal records;
- Account Preferences: chosen currency, language, communication preferences, responsible gaming limits;
- Communications Data: records of correspondence with our support team, including live chat transcripts, emails, and call recordings where applicable.
2.2. Data We Collect Automatically
When you visit or use the Platform, certain data is collected automatically via technical means:
- Technical Data: IP address, browser type and version, operating system, device identifiers, screen resolution;
- Usage Data: pages visited, session duration, click-path, search queries within the Platform, game history, betting patterns;
- Location Data: approximate geographic location inferred from your IP address;
- Cookie & Tracking Data: data gathered through cookies, pixels, and similar technologies as described in Section 6.
2.3. Data We Receive from Third Parties
We may receive personal data about you from trusted third parties in certain circumstances, including:
- Identity Verification Providers: electronic KYC and age-verification services that confirm your identity and age against public and private records;
- Fraud & AML Screening Providers: databases used to detect suspicious activity, politically exposed persons (PEPs), or sanctions-list matches;
- Payment Processors: confirmation of payment status and fraud risk scores;
- Responsible Gaming Databases: data shared via self-exclusion schemes such as GAMSTOP, in compliance with applicable regulatory requirements;
- Analytics & Affiliate Partners: referral and attribution data indicating how you discovered the Platform.
2.4. Special Category Data
In limited circumstances we may process special category data as defined under Article 9 UK GDPR — for example, health-related information you voluntarily disclose when requesting responsible gaming support or self-exclusion. We process such data only where strictly necessary and on the basis of explicit consent or as required by law.
3. How We Use Your Data
3.1. We use the personal data we hold about you for the following purposes:
| Purpose | Description |
|---|---|
| Account Registration | Creating and managing your player account, verifying your identity and eligibility, and enabling you to access Platform services. |
| Contract Performance | Processing bets, game play, deposits, withdrawals, and administering promotions and bonuses. |
| KYC & Age Verification | Confirming that you are aged 18 or over and that the identity you have provided is genuine, as required by applicable law. |
| Fraud Prevention & Security | Detecting and preventing fraud, money laundering, collusion, and other unlawful or prohibited activity on the Platform. |
| Regulatory Compliance | Meeting Anti-Money Laundering (AML), Counter-Terrorist Financing (CTF), and other legal and regulatory obligations. |
| Responsible Gaming | Monitoring player behaviour to identify potential signs of problem gambling and implementing protective measures, including self-exclusion. See our Responsible Gaming Policy. |
| Customer Support | Responding to your queries, complaints, and requests, and maintaining records of those interactions. |
| Marketing & Personalisation | Sending promotional communications, personalising content, and tailoring offers, where you have given consent or where we rely on legitimate interests (with opt-out available). |
| Analytics & Improvement | Analysing user behaviour and Platform performance to improve our services, fix technical issues, and develop new features. |
| Legal Claims | Establishing, exercising, or defending legal claims when necessary. |
3.2. We will not use your personal data for purposes that are incompatible with those described above without first providing you with notice and, where required, obtaining your consent.
4. Legal Bases for Processing
4.1. Under the UK GDPR, every processing activity must be justified by at least one lawful basis. The bases on which we rely are:
4.1.1. Performance of a Contract (Article 6(1)(b) UK GDPR)
Processing is necessary for the performance of the contract between you and Zizobet — specifically, the Terms & Conditions you accepted on registration. This covers account creation, payment processing, game provision, and bonus management.
4.1.2. Legal Obligation (Article 6(1)(c) UK GDPR)
We process data where required to comply with a legal obligation, including KYC identity checks, AML and CTF record-keeping, age-verification requirements, and reporting obligations to regulatory or law-enforcement authorities.
4.1.3. Legitimate Interests (Article 6(1)(f) UK GDPR)
Where processing is necessary for our legitimate business interests (or those of a third party) and those interests are not overridden by your rights and freedoms. This includes fraud prevention, network and information security, responsible gaming monitoring, internal analytics, and direct marketing to existing customers (subject to your right to opt out).
4.1.4. Consent (Article 6(1)(a) UK GDPR)
For certain activities — such as sending promotional emails, placing non-essential cookies, or processing special category data — we rely on your explicit, freely given, specific, and informed consent. You may withdraw consent at any time without detriment; however, withdrawal does not affect the lawfulness of processing carried out before withdrawal.
4.1.5. Vital Interests & Public Task
In exceptional circumstances we may process data to protect vital interests or where processing is necessary in the substantial public interest, particularly in connection with responsible gaming interventions.
5. Data Sharing & Third Parties
5.1. We do not sell your personal data to third parties. We share personal data only where necessary and under appropriate safeguards, as set out below.
5.2. Categories of Recipients
- Identity & Age Verification Providers: to confirm player eligibility and comply with know-your-customer requirements;
- Payment Service Providers & Financial Institutions: to process deposits and withdrawals, including providers of the following payment methods available on the Platform:
- Visa & Mastercard (debit cards)
- PayPal
- Skrill
- Neteller
- Paysafecard
- Apple Pay
- Google Pay
- Bank Transfer (Faster Payments)
- Trustly (Open Banking)
- MuchBetter
- Fraud & AML Screening Services: to detect and prevent financial crime, including PEP/sanctions checks;
- Self-Exclusion Scheme Operators: including GAMSTOP, to honour self-exclusion requests as required by applicable regulation;
- Game Software Providers: third-party game studios that supply the games available on our Platform may receive limited technical data necessary to run the games;
- Analytics & Marketing Technology Providers: to help us understand Platform usage and deliver relevant communications (subject to cookie consent);
- Customer Support Tools: providers of live chat, ticketing, and communication platforms used to deliver our support service;
- Regulatory & Law-Enforcement Authorities: where required by law, court order, or regulatory instruction — for example, responding to lawful requests from the Information Commissioner's Office (ICO) or other competent authorities;
- Professional Advisers: lawyers, auditors, and other professional consultants under strict confidentiality obligations;
- Business Successors: in the event of a merger, acquisition, or sale of the business, your data may be transferred as part of that transaction, subject to equivalent protections.
5.3. All third-party data processors are required to process your data only on our documented instructions and to implement appropriate technical and organisational security measures. We maintain written data-processing agreements with each processor as required by Article 28 UK GDPR.
6. Cookies & Tracking Technologies
6.1. The Platform uses cookies and similar technologies (including pixels, web beacons, and local storage) to ensure the Platform functions correctly, to analyse usage patterns, and to deliver relevant marketing messages.
6.2. Types of Cookies We Use
| Category | Purpose | Consent Required? |
|---|---|---|
| Strictly Necessary | Essential for login, session management, security, and core Platform functionality. Cannot be disabled. | No |
| Functional / Preference | Remembers your language, currency, and display preferences to personalise your experience. | Yes |
| Analytics / Performance | Measures how users interact with the Platform to identify performance issues and improve features (e.g. Google Analytics). | Yes |
| Marketing / Targeting | Used to deliver relevant advertisements, track ad campaign performance, and limit how often you see a particular ad. | Yes |
6.3. On your first visit to the Platform, you will be presented with a Cookie Consent Banner that allows you to accept all cookies, reject non-essential cookies, or manage your preferences by category. You may update your preferences at any time by accessing the cookie settings in the footer of the Platform.
6.4. Please note that disabling certain categories of cookies may affect the functionality of the Platform or limit your access to certain features.
6.5. For further information on how to manage or delete cookies from your browser, please refer to your browser's help documentation or visit www.allaboutcookies.org.
7. Data Security
7.1. We implement comprehensive technical and organisational security measures to protect your personal data against unauthorised access, accidental loss, alteration, disclosure, or destruction. These measures include:
- Transport Layer Security (TLS/SSL) encryption for all data transmitted between your device and our servers;
- AES-256 encryption at rest for sensitive data stored on our systems;
- Multi-factor authentication (MFA) for staff access to systems containing personal data;
- Role-based access controls ensuring that only authorised personnel can access personal data on a need-to-know basis;
- Continuous network monitoring, intrusion detection systems, and regular penetration testing;
- PCI DSS compliance frameworks for the handling of payment card data;
- Regular staff training on data protection and information security;
- Documented incident response procedures for managing and reporting data breaches.
7.2. In the event of a personal data breach that is likely to result in a risk to your rights and freedoms, we will notify the Information Commissioner's Office (ICO) within 72 hours of becoming aware of it, as required by Article 33 UK GDPR. Where the breach is likely to result in a high risk to your rights, we will also notify you directly without undue delay.
7.3. While we take every reasonable step to protect your data, no transmission over the internet can be guaranteed to be completely secure. You are responsible for keeping your login credentials confidential and for ensuring that your device is adequately protected.
8. Data Retention
8.1. We retain your personal data only for as long as is necessary to fulfil the purposes for which it was collected, or as required or permitted by applicable law. The table below sets out our standard retention periods:
| Data Category | Retention Period | Legal Basis for Retention |
|---|---|---|
| Account & Identity Data | 5 years after account closure | AML / legal obligation |
| KYC & Verification Documents | 5 years after the end of the business relationship | Proceeds of Crime Act 2002; AML Regulations |
| Transaction Records | 6 years after the transaction date | Legal obligation; tax and financial regulations |
| Responsible Gaming & Self-Exclusion Records | Duration of exclusion + 5 years | Legal obligation; player protection duty |
| Customer Support Communications | 3 years after closure of the interaction | Legitimate interests; legal claims |
| Marketing Preferences & Consent Records | Until consent is withdrawn, plus 1 year thereafter | Consent; accountability obligations |
| Technical & Usage Logs | Up to 12 months | Legitimate interests; security |
8.2. At the end of the applicable retention period, data will be securely deleted or irreversibly anonymised in accordance with our internal data lifecycle procedures.
8.3. In certain circumstances (e.g. where legal proceedings are anticipated or ongoing), we may retain data beyond the standard periods. In such cases, data will be flagged with a legal hold and reviewed periodically.
9. Your Rights
9.1. Under the UK GDPR, you hold a number of important rights in relation to your personal data. A summary of each right and how to exercise it is set out below:
9.1.1. Right of Access (Subject Access Request — SAR)
You have the right to obtain a copy of the personal data we hold about you, together with information about how we process it. We will respond to SARs within one calendar month of receipt.
9.1.2. Right to Rectification
You have the right to request that inaccurate or incomplete personal data be corrected without undue delay.
9.1.3. Right to Erasure ("Right to be Forgotten")
In certain circumstances, you have the right to request the deletion of your personal data — for example, where the data is no longer necessary for the purpose for which it was collected or where you withdraw your consent. This right is not absolute and may be limited by legal obligations (e.g. AML record-keeping requirements).
9.1.4. Right to Restriction of Processing
You have the right to request that we restrict the processing of your personal data in certain situations — for example, while we investigate a disputed accuracy claim.
9.1.5. Right to Data Portability
Where processing is based on your consent or on a contract and is carried out by automated means, you have the right to receive your data in a structured, commonly used, and machine-readable format and to transmit it to another controller.
9.1.6. Right to Object
You have the right to object to processing based on our legitimate interests, including profiling and direct marketing. Where you object to direct marketing, we will cease processing your data for that purpose immediately.
9.1.7. Rights in Relation to Automated Decision-Making
You have the right not to be subject to a decision based solely on automated processing — including profiling — that produces legal or similarly significant effects on you. Where we carry out automated decision-making relevant to your account (e.g. risk assessments), you may request human review of the decision.
9.1.8. Right to Withdraw Consent
Where processing is based on consent, you may withdraw it at any time. This does not affect the lawfulness of processing before withdrawal.
9.2. How to Exercise Your Rights
To exercise any of the above rights, please contact us using the details provided in Section 13 of this Policy. We may need to verify your identity before processing your request. We will respond within one calendar month; in complex cases this may be extended by a further two months, of which you will be notified.
9.3. Right to Complain
If you believe we have not handled your personal data in accordance with applicable law, you have the right to lodge a complaint with the Information Commissioner's Office (ICO):
- Website: ico.org.uk
- Helpline: 0303 123 1113
- Address: Information Commissioner's Office, Wycliffe House, Water Lane, Wilmslow, Cheshire, SK9 5AF
We would, however, appreciate the opportunity to address any concerns before you approach the ICO, and encourage you to contact us first.
10. International Data Transfers
10.1. Where we transfer personal data to recipients located outside the United Kingdom, we ensure that appropriate safeguards are in place to protect that data at an equivalent level to that required within the UK. The mechanisms we use include:
- UK Adequacy Regulations: transfers to countries or territories that the UK Secretary of State has determined provide an adequate level of data protection (currently including the European Economic Area, Switzerland, and others);
- International Data Transfer Agreements (IDTAs): the UK-approved standard contractual clauses for data transfers, published by the ICO, imposed on recipients in third countries;
- UK Addendum to EU Standard Contractual Clauses: where applicable, the ICO-approved addendum supplementing EU SCCs for UK-specific transfers;
- Binding Corporate Rules (BCRs): where applicable within corporate group structures;
- Specific Derogations: in exceptional circumstances, transfers may be made on the basis of your explicit consent or for the performance of a contract on your behalf.
10.2. You may request a copy of the safeguards in place for any specific international transfer by contacting us at the address in Section 13.
11. Minors
11.1. The Platform is intended solely for individuals who are aged 18 years or older. We do not knowingly collect personal data from persons under the age of 18.
11.2. We implement age-verification checks at the point of registration and may request documentary evidence of age at any time as part of our ongoing KYC obligations. Access to the Platform will be suspended or terminated where we have reasonable grounds to believe a user is under 18.
11.3. If you have reason to believe that a minor has provided us with personal data or has gained access to the Platform, please notify us immediately at [email protected]. We will investigate and take appropriate action, including deletion of any data collected from the minor and closure of any associated account.
11.4. For further information on our age-verification and child-protection measures, please review our Responsible Gaming Policy.
12. Changes to This Policy
12.1. We may update this Privacy Policy from time to time to reflect changes in our data processing practices, legal requirements, or operational circumstances. Any material changes will be communicated to you in advance by one or more of the following means:
- a prominent notice on the Platform;
- a notification sent to the email address registered to your account;
- a pop-up or banner requiring you to acknowledge the updated policy before continuing to use the Platform.
12.2. The Version number and Last Updated date at the top of this document will always reflect the most current version. The version history is maintained internally and is available upon request.
12.3. Your continued use of the Platform after the effective date of any updated Policy constitutes your acceptance of the revised terms, where permitted by law. If you do not accept the changes, you should close your account and cease using the Platform.
12.4. Previous versions of this Policy may be obtained by contacting us using the details in Section 13.
13. Contact Information
13.1. If you have any questions, concerns, or requests relating to this Privacy Policy or our data protection practices, please do not hesitate to contact us:
| Brand Name | Zizobet |
| Website | zizzobett.uk |
| General Support | [email protected] |
| Privacy / DPO Enquiries | [email protected] |
13.2. For all data protection matters — including subject access requests, withdrawal of consent, objections to processing, or data breach reports — please direct your correspondence to [email protected] with the subject line: "Data Protection Request – [Nature of Request]". This ensures your enquiry is routed directly to our data protection function and handled within the required statutory timeframes.
13.3. We are committed to handling all privacy-related enquiries with the utmost care, transparency, and efficiency. You will receive an acknowledgement of your request within 72 hours and a full response within one calendar month, unless a statutory extension applies.
⚠ Need Help with Gambling?
If you or someone you know is affected by problem gambling, free and confidential support is available from the following UK organisations:
- GamCare — National Gambling Helpline: 0808 8020 133 (free, 24/7) | gamcare.org.uk
- GambleAware — begambleaware.org
- Gamblers Anonymous UK — gamblersanonymous.org.uk
- Gordon Moody Association — Residential treatment | gordonmoody.org.uk
- NHS Northern Gambling Service — 0300 300 1490 | northerngamblingservice.nhs.uk
- GAMSTOP — Free UK-wide self-exclusion scheme | gamstop.co.uk
For more information on the tools and limits available to you on our Platform, please visit our Responsible Gaming Policy.
This Privacy Policy forms part of the Zizobet legal documentation suite. Please also review our Terms & Conditions and Responsible Gaming Policy. © 2026 Zizobet — zizzobett.uk. All rights reserved. Version 1.0 | Last Updated: 23 September 2026.