Key Aspects of Data Collection
The platform maintains absolute structural transparency regarding all data gathering workflows executed within the operational environment.
| Data Category | Purpose of Collection | Explanatory Note |
|---|---|---|
| Personal Information | Execution of regulatory compliance checks and account authentication | Full name, verified contact e-mail address, date of birth, residential address including UK Postcode |
| Technical Telemetry | Optimisation of interface rendering parameters and fraud detection | IP addresses, operational browser Cookies, device fingerprinting data, session timestamps |
| Financial Ledger Data | Processing of transactions and maintenance of audit trails | Transaction histories, payment method details, withdrawal records, wagering activity logs |
All data storage is strictly sandboxed, encrypted using industry-standard cryptographic protocols, and processed exclusively for infrastructure security, regulatory KYC/AML compliance, and service delivery. No unencrypted retention protocols are deployed, and access to stored records is restricted to authorised personnel only.
Data Transmission to Third Parties
User data may be shared with external entities exclusively under strict, limited parameters defined by operational necessity and regulatory compliance. Data transmission is permitted solely to certified software game providers and integrated payment system gateways, restricted to the minimum information required for processing standard ledger transactions and loading gaming content. The platform maintains a complete prohibition regarding the sale, trade, or leasing of personal user records to external marketing firms, advertising networks, data brokers, or any unauthorised third parties. All third-party processors are contractually bound to uphold equivalent data protection standards and are subject to regular compliance audits.
Security and Encryption Technologies
The cryptographic security infrastructure deployed across the platform utilises industry-standard SSL/TLS encryption protocols to protect data transmission channels between user devices and server environments. Physical server defenses include dedicated firewall configurations, intrusion detection systems, and continuous network monitoring frameworks designed to identify and neutralise potential security threats. Data confidentiality and protection represent the paramount operational priority for Boabet, with regular penetration testing and vulnerability assessments conducted to maintain the integrity of all defensive systems. Database encryption at rest ensures that stored records remain inaccessible to unauthorised parties even in the event of physical hardware compromise.
User Rights under GDPR
Data subjects are afforded comprehensive statutory rights under modern international privacy legal frameworks, including the following core entitlements:
- Right of Access: to obtain copies of all logged personal data held within the system
- Right to Rectification: to request correction of inaccurate or outdated records
- Right to Erasure: the "right to be forgotten" allowing for deletion of personal information subject to legal retention obligations
- Right to Restrict Processing: to limit the purposes for which data may be utilised
- Right to Data Portability: to receive personal data in a structured, machine-readable format
- Right to Object: to oppose processing activities based on legitimate interests or direct marketing purposes
- Right to Withdraw Consent: to revoke previously granted permissions for data processing activities at any time
Data Retention and Deletion
Personal information is retained only for the duration necessary to fulfil the purposes outlined in this policy or as required by applicable legal and regulatory obligations. Financial transaction records and KYC documentation are maintained for a minimum period of five years following account closure to comply with anti-money laundering legislation. Technical telemetry data is anonymised and aggregated after twelve months, removing all personally identifiable elements. Upon receipt of a valid erasure request, all non-essential data is permanently deleted from active systems within thirty days, subject to overriding legal retention requirements.
International Data Transfers
Certain data processing activities may involve the transfer of personal information to jurisdictions outside the European Economic Area. All international transfers are executed in strict compliance with GDPR requirements, utilising approved safeguards such as Standard Contractual Clauses, adequacy decisions, or binding corporate rules. Recipients of transferred data are contractually obligated to maintain equivalent protection standards, and mechanisms are established to allow data subjects to obtain copies of the safeguards applied to their information.
Changes to This Privacy Policy
This policy is subject to periodic review and amendment to reflect evolving regulatory requirements, technological developments, or operational changes. Material modifications are communicated to active account holders via registered e-mail addresses and through prominent notices displayed within the platform interface. Continued use of services following policy updates constitutes acknowledgement and acceptance of the revised terms. The date of the most recent revision is documented at the conclusion of this policy document to ensure transparency regarding the currency of the information provided.
