Policy
DRAGONBET: PRIVACY POLICY
(including SECURITY, SOCIAL MEDIA, and Data Protection Complaints Policy and Procedure)
HEAD OFFICE
2 Alexandra Gate,
Fford Pengam,
Cardiff,
United Kingdom,
CF24 2SA
A company registered in England and Wales with company number 15718764.
Privacy Policy
This privacy policy explains how we use, collect, and protect your personal data in compliance with the UK General Data Protection Regulation (“UK GDPR”).
We ask that you read this privacy policy carefully as it contains important information on who we are, how and why we collect, store, use and share personal information, your rights in relation to your personal information and on how to contact us and supervisory authorities in the event you have a complaint.
Who We Are
This website is operated by DragonBet Ltd.
We collect, use and are responsible for certain personal information about you. For the purposes of data protection legislation, the controller of any personal information collected through this website is DragonBet Ltd (company number 15718764), 2 Alexandra Gate, Fford Pengam, Cardiff, CF24 2SA, UK (‘DragonBet’). With regard to information received from third parties, DragonBet Ltd is the processor of your data.
Please see the ICO register for more information.
If you have any questions about our privacy policy, you may raise them with our data protection officer by contacting [email protected].
If you feel like we have mishandled your data in any way or that you were unable to enjoy the full exercise of your rights and freedoms under the UK GDPR, you can make a complaint with us. For this purpose, and in line with the Data (Use and Access) Act 2025 (DUAA), we have included our ‘Data Protection Complaints Policy and Procedure’ at the end of this Policy.
You may also always contact the Information Commissioner’s Office at https://ico.org.uk/ if you wish to do so.
This website is not intended for those under the age of 18, and we do not knowingly collect or use personal information about children.
Our Collection and Use of your Personal Information
We may collect personal information about you, which is categorised together as follows:
|
Personal data we collect |
Where does this personal data come from? |
|
Identity data (such as name, date of birth, marital status, etc) |
|
|
Contact data (such as your address, email address, telephone numbers) |
|
|
Financial and Transaction Data (such as bank and payment details, business and financial details) |
|
|
Technical and Usage data (such as IP address, browser type and version, location, operating system details etc). |
|
|
Marketing data (such as your selected marketing preferences in relation to communications from us and selected third party partners). |
|
You can edit your identity data, contact data, and marketing data at any time.
How we Use your Personal Data and Legal Bases
We only use your personal data where we are allowed to do so legally. We rely on certain lawful bases for this. The most common bases we rely on are:
- Where we need to process your personal information in order to fulfil the contract we have, or are about to, enter into with you;
- Where it is in the legitimate interests of ourselves, or a third party, that the processing takes place and your data rights do not override these legitimate interests;
- Where we need to comply with a legal or regulatory obligation;
- We may also rely on consent, where we seek your agreement that you would like to receive marketing material from us and to share details with third parties for this purpose.
Purposes of Processing your Data
We use your personal information to:
|
Purpose of processing |
Data type(s) |
Lawful basis for processing |
|
Identity verification |
Identity data, contact data. |
Legal obligation. We must be able to verify your identity to meet our regulatory obligations. |
|
Creating and managing your account with us |
Identity data, financial data, contact data. |
Contract. Without this information we would not be able to register you as a customer, maintain an accurate record of your activity, or address any queries you may have about your use of the service. |
|
Maintaining records of your transactions. |
Identity data, financial and transaction data, technical and usage data. |
Legal obligation. We are required to keep accurate records of customer transactions for at least five years. |
|
Processing your transactions, wagers and winnings |
Identity data, contact data, financial and transaction data, technical and usage data. |
Contract. Without this information, we would not be able to process your bets in line with regulatory requirements or fulfil our contract with you. |
|
Improving and personalising our services |
Identity data, contact data, financial and transaction data, marketing data, technical and usage data. |
Legitimate interest (in cases where cookies and similar technologies are not employed to collect data) Without this data, we would not be able to offer you the best experience on our website/app. Consent. As this relates to data collected though CAPI – see section below for more information. |
|
Building personal profiles |
Identity data, contact data, financial and transaction data, marketing data, technical and usage data. |
Legitimate interest. Without this information we would not be able to offer you the best user experience and tailor the website/app to your preferences. |
|
Direct Marketing of offers and promotions |
Identity data, contact data, marketing data. |
Explicit consent. This may be withdrawn at any time. * This includes data collected for retargeting campaigns |
|
Market Research |
Identity data, marketing data, transaction data. |
Legitimate Interest, Without processing this data, we would not be able to optimise our offers. ** |
|
Notifying you of changes to website or services which may affect you |
Identity data. contact data, technical data. |
Contract (primary), legal, legitimate interests. We would seek to keep you informed of changes to your favourite services. We will do so by email, in app notifications, and onsite banners. Material T&C changes will be communicated to you in advance and will require your consent where needed. |
|
Retaining records of correspondence |
Identity data, contact data |
Legitimate Interest. Without retaining such data, we would not be able to deal with complaints, nor be in a position to resolve such matters at a later date. |
|
Administering the website including internal operations such as troubleshooting, data analysis, surveys etc. |
Identity data, contact data, marketing data, technical and usage data. |
Legitimate Interest. Without such data, we would not be able to ensure that the website always behaves as our customers expect it to, nor to understand how to give you the best experience on our site/app. |
|
Carrying out KYC checks, financial checks (e.g., to make credit decisions), and other checks to prevent money laundering and fraud |
Identity data, contact data, financial and transaction data |
Legal, contract. We need to check whether you are legally allowed to use our services, and whether you have the financial means to use our services. We may do so by requesting copies of your ID, proof of address, and your debit cards (if a financial threshold is met). We are legally required to conduct due diligence to make sure you are not involved in money laundering and fraud. |
* You sign up for marketing by opting in at registration, and you can withdraw consent by updating your preferences in ‘My Account’, the ‘unsubscribe’ link in emails, a ‘STOP’ reply to SMS, or by contacting customer service.
** Customer data is taken and pseudonymised by us and aggregated. We then input this data into our AI Assistant (powered by Claude), which then gives us information that we use to optimise our services. Since the data we input to our AI Assistant is not connected to any account number or other identity data, and it is in an aggregated form, no data sharing between DragonBet and Anthropic occurs. However, you may exercise your right to object to the processing of your personal data in this way, in line with the rights set out in the UK GDPR and explained in the section titled ‘Your Data Right’ below.
Conversion API
We utilise the Meta and Google powered Conversion API (CAPI) tools into our system. CAPI is a server-to-server tracking tool, similar to a cookie, which lets us collect various types of data. The purpose of this collection is to track user journeys to assess the success of our various ad campaigns, or keywords we use throughout our website. We will collect two types of data: contact data, and event data. Please see below, for a further breakdown.
Types of Data we collect:
- Email address (hashed)
- Phone number (hashed
- First and last name (hashed)
- IP address
- Device and browser type
- User behaviour (i.e., page view, purchase, search, sign up, and other events)
We will also share this data (hashed) with Meta and Google, who will use it for their own marketing practices.
Upon entering the DragonBet website, you will have the opportunity to consent to this tracking technology (in the same pop-up as cookie consent).
We will hold data collected by this tool for 2 years. Meta will also hold the data for 2 years. You can view Meta’s policy on this here. Google anonymises advertising data after 18 months. You can view Google’s policy on this here.
Change of Purpose
We will only use the data collected for the purposes we have specified above, unless we reasonably consider we need to use if for another purpose which is compatible with the original purpose. If there is any change in purpose, we will inform you both of the purpose and the legal basis upon which such processing will take place. There may be instances where we process your personal data without your knowledge or consent, if this is legally required.
Sharing your Personal Data
DragonBet may share your personal data with trusted third parties in order to carry out the purposes laid out above. When sharing your data with third parties, we will be the controller of your data.
The types of third parties that we will be sharing your data with include:
- KYC and age-verification providers (TransUnion International UK Limited). This processing is undertaken to fulfil our legal and regulatory obligation to carry out customer identification. Please note that, while acting on our requests, TransUnion may process publicly available data. You can find out more about what TransUnion does, how it uses and processes data, and the sources of this information at https://www.transunion.co.uk/legal/privacy-centre/pc-credit-reference.
- Platform providers (Playbook Engineering)
- Third party software providers (Synalogik, Freshworks, Intercom, Databricks)
- Affiliate marketing services including for customer re-targeting campaigns (and including affiliate marketing platforms such as Meta and Google)
- Profile building platforms (Segment, Amplitude)
- Social media partners
- Banking and Payment providers (Global Payments, Paysafe, Xace, Allied Irish Bank, Public Bank Enterprise)
- Marketing and market research (SendGrid, Symplify, Mobius)
- Government authorities, if we are required by law or court order to disclose certain types of your personal data
- Alternative dispute resolution providers, such as Independent Betting Adjudication Service (IBAS), in the case of a dispute;
- Police, in rare circumstances where there is a threat to life
- If ownership of all or part of our business changes, or we undergo reorganisation, we may transfer your personal data to the new owner of the successor company to allow them to continue to provide the Services requested by you
- While negotiating or in relation to a business transaction, such as a merger, change of control, sale of assets, or bankruptcy.
When sharing your data, DragonBet will only disclose your personal information which it deems to be necessary and proportionate to the aim of the processing and where it has been assured by such third party, through Data Processing Agreements, that it will be used in compliance with data protection legislation.
Some third parties are located outside of the UK. In such cases, we have appropriate agreements which ensure that your data is processed in a way which is in line with UK standards. See the section below on Internet-based data transfers for more information.
Internet-based data transfers
Given the global nature of the Internet, using the Internet to collect and process information necessarily involves the transmission of information on an international basis. Some of the data processors engaged to process information may be outside the European Economic Area. Therefore, by browsing our website and communicating electronically with us, you acknowledge and agree to our processing of your information in this way.
If your data is transferred to a third-party located in a jurisdiction not covered by UK adequacy agreements, we will enter into EU Standard Contractual Clauses (EU SCCs) with a UK addendum, or an International Data Transfer Agreement (IDTA). This way we can ensure that the third-party processors have in place such equivalent safeguards protecting your data as are required under the UK GRPR.
Your Data Rights
Under the UK GDPR, you, as a data subject have a number of rights which are detailed below. Some of these only apply in specific circumstances and are qualified in several respects by exemptions which are provided for in data protection legislation. We will advise you in our response to your request if we are relying on any such exemptions.
Note that generally there will be no fee attached to your exercise of any of the rights below, unless your request is complex or the related information has to be delivered to you in an unusual manner. We may require proof of identity to verify that the individual making the request is entitled to copies of any personal data.
- Access to personal data: You have a right to request a copy of the personal information that we hold about you. Should you with to make such a request, please email [email protected]. You should include adequate information to identify yourself and relevant contact details that will reasonably assist us in fulfilling your request. Your request will be dealt with as soon as possible.
- Correction of personal data: You can request us to correct any personal data that we are processing about you which is incorrect. We provide you with online account settings and tools to access the information we hold on your account or email [email protected]. Please remember to always ensure your data is current and updated.
- Right to withdraw consent: Where we have relied upon your consent to process your personal data, you have the right to withdraw that consent. To change your marketing preferences, you can visit the Account tab when you log into your account or email [email protected].
- Right of erasure: You can request us to erase your personal data where there is no compelling or regulatory reason to continue processing. This right is not a guaranteed or absolute right.
- Right to data portability: This right allows you to request that we transfer your personal data to a third party. This information will be provided in a machine-readable format such as .csv (readable on Microsoft Excel or equivalent) or .pdf (readable on Adobe Acrobat or equivalent). You have this right as is relates to data processing which you consented to, or which was necessary to fulfil a contract with you. To make a request, contact our Data Protection Officer at [email protected]; we will seek to acknowledge you request within three working days, and to fulfil your request within one month. More complex requests may take longer.
- Right to restrict processing of personal data: You have the right, in certain circumstances, to request that we suspend our processing of your personal data. Where we suspend our processing of your personal data we will still be permitted to store your personal data, but any other processing of this information will require your consent, subject to certain exemptions.
- Right to object to processing of personal data: You have the right to object to our use of your personal data which is processed on the basis of our legitimate interests. However, we may continue to process your personal data, despite your objection, where there are compelling legitimate grounds to do so, or we need to process your personal data in connection with any legal claims.
- Right to object to direct marketing, which can be done by opting-out of direct marketing. You also have a right to object to any profiling to the extent that it relates to direct marketing only.
- Right to request an explanation of the logic involved where we make decisions about you solely through automated means.
- Right to complain to your national data protection regulator.
Raising a complaint
If you believe we have mishandled your data, or that you were unable to exercise your rights, you can make a complaint. Please follow the procedure set out at the end of this policy: ‘Data Protection Complaints Policy and Procedure’.
Retention of your Personal Data
We will retain your personal data for the period necessary to provide you with Services. Accordingly, your personal data shall be maintained for up to 5 years following the closure of Your Account (if applicable) or the last contact with us emanating from you. Where it is no longer necessary to process your personal data we will delete it securely. We may be subject to legal and regulatory requirements to keep personal data for a longer period, in particular pursuant to any applicable statutory limitation period.
We need to retain certain personal data for a few reasons.
We are obliged under Ordinary Code 3.5.4 of the Gambling Commission’s Licence Conditions and Codes of Practice to ensure that customers who self-exclude with us remain excluded for seven years after their chosen period of exclusion ends unless they contact us to say they would like to recommence gambling with us. Should you have self-excluded with us and wish to return to gambling at a later date, we are obliged by Ordinary Code 3.5.4 (5f) and 3.5.4 (7) to conduct a phone call with you and discuss the implications of your wish to recommence gambling. In order for us to fulfil these requirements, we must retain certain personal data to ensure we can identify persons who have self-excluded with us.
We are required by section 40(3) of the Money Laundering Regulations 2017 to retain some data for five years after your account has been closed. All such data will then be deleted at the end of that retention period. Your “right to ensure” does not apply to such data.
We may also retain some of your personal data in cases where your account is inactive for whatever reason. This is because we are obliged to demonstrate compliance with the Money Laundering Regulations 2017 section 40(3) (b, i and ii) in relation to transactions with you and customer due diligence measures taken during the course of our customer relationship with you. We will delete such records when five years have expired following your last use of our services. In exceptional circumstances, we may retain transaction records for up to 10 years, per the Money Laundering Regulations section 40(4).
We may also retain some of your personal data where you register with us but do not ultimately deposit funds with us. This is because we must proceed, per the Money Laundering Regulations 2017 section 4 (1b), as though our business relationship with you will be of some duration from the moment contact is established with you. For these purposes, this means that when you register with us, you make contact, and from that point we have record keeping duties which we must fulfil. As detailed elsewhere in this section, this leads to various legal and regulatory obligations which we must fulfil.
We retain other data regarding your account primarily to allow us to comply, and demonstrate compliance, with the Gambling Act 2005 and other legislation. We also retain such data on the legal basis of legitimate interests, in case any claim or investigation arises against us in relation to your account
IP Address
Your bowser generates information, including which language the Website is displayed in, and your Internet Protocol address (“IP address”). An IP address is a set of numbers which is assigned to your computer during a browsing session. The IP address is generated whenever you log on to the internet via your internet service provider or your network. Your IP address is automatically logged by our servers and used to collect traffic data about visitors to our website. We also use your IP address to help diagnose problems with our server, and to administer our website.
Security
We do everything in our power to protect user-information you provide on account registration. DragonBet safeguards your data through both technical and organisational controls, audited to the ISO 27001 standard, and upheld by a competent ISMS. The controls include: access control, cryptographic controls, security awareness training, incident management procedure, general IT security, and supplier relationship management.
We provide your information to third parties for the purposes outlined above, and data transfers may occur in certain circumstances which have been detailed. Your information will be disclosed to carefully selected suppliers that are engaged with DragonBet to process the information on our behalf or otherwise as required by law or the requirements of any applicable regulatory authority. We will never sell your data to third parties. Such third-party suppliers also have various security measures in place, such as strict access control procedures, encryptions, or other measures, as required by Article 32 of the GDPR.
All customer data is held on a remote gaming system at our platform providers’ (Playbook Engineering Ltd) back-office database, however customer data can only be accessed by DragonBet. Access to the back-office is controlled via an IP whitelist and connections are made via a VPN server, meaning that only DragonBet internal IP addresses have access to customer data. Our platform provider is audited to the same standard as DragonBet.
All of our users’ information, not just sensitive information, is stored on servers in secure operating environments (Microsoft SharePoint with servers located in the UK).
Cookies
Cookies are small text files that record Your preferences when You visit certain online pages, and are stored on Your computer or other connected device. We use a variety of first party and third party cookies, as well as both persistent and session cookies. We and (where relevant) our affiliates and third party service providers use cookies to:
a. track the use of the Service;
b. monitor traffic to the Service;
c. improve the Service by making it easier and more relevant for You;
d. obtain and pass on analytics regarding Your use of the Website and the Service
e. to understand Your preferences for advertising purposes; and
f. to provide You with relevant advertising when visiting our Website.
Online browsers can usually be set to either accept or decline cookies. However, if cookies are declined You may not be able to fully experience the interactive features of the Service.
Please see our Cookie Policy to find out more information relating to cookies used on our website.
Social Media
We want social media to be a friendly and relaxed environment for all to enjoy. We use social media to talk to you, answer your questions, supply you with news and let you know about things you might be interested in, including market movers. Views and news published by DragonBet does not constitute betting advice and should not be treated as such.
To ensure our social media pages are enjoyable for all users please adhere to the rules below.
The following terms and conditions apply to content, promotions, apps and tabs on DragonBet social media accounts:
Social Media Terms & Conditions
- Our social media channels are restricted to individuals aged 18 and older.
- You may not advertise or promote non- DragonBet products via our social media channels without prior consent from DragonBet, via [email protected].
- Any betting opinion or news expressed by DragonBet does not constitute betting advice and should not be treated as such.
- DragonBet cannot be held responsible for the content of others on our social media channels.
- No gambling of any kind may take place between DragonBet and its customers via DragonBet social media channels.
- Any racism, sexism, bullying or harassment of any kind will be removed and the original user may be blocked temporarily or permanently.
- Any defamatory language will be removed and the original user may be blocked temporarily or permanently.
- DragonBet retain the right to remove any content or block any user, temporarily or permanently.
- Content on our social media channels could change at any time and should not be solely relied upon.
- If you have any problems regarding our social media pages please email us: [email protected].
Changes to Privacy Policy
If we decide to change our privacy policy we will post those changes on this page. If you have any questions about the security of our website, or the information we hold on you, you can send an email to [email protected].
This privacy policy is effective from 19.08.2026.
Data Protection Complaints Policy and Procedure
Last updated: 11 June 2026
DragonBet understands that there are occasions when things may go wrong, and that you may feel that we have not addressed a data protection concern appropriately or that you may feel that you have not enjoyed the full exercise of your rights and freedoms under the UK General Data Protection Regulation (“UK GDPR”) or General Data Protection Regulation (“GDPR”).
We take your data protection concerns seriously and, accordingly, have in place a process for dealing with complaints about this.
How to make a data protection complaint
Should you have a complaint about the way we have handled any aspect of data protection, or feel that we have infringed data protection laws, you can make a complaint to our Data Protection Officer at [email protected].
This is the best way to ensure your complaint reaches the appropriate person in a timely manner. Where other members of our team receive a complaint about data protection matters via some other mechanism, they will nonetheless pass this along as appropriate.
When we respond to a data subject access request, or other exercise of data rights, we will include details of how to complain to us within the response.
Complaints via social media
As noted above, we would ask that complaints be made to the Data Protection Officer. However, should you raise a data protection complaint via social media, the person who receives it will ask for a more secure means by which you can be contacted to address the complaint. This is because, per Information Commissioner’s Office (ICO) guidance, social media is not a secure means by which to do so.
Our pledge on data protection complaints
We will acknowledge receipt of your complaint within 30 days of receiving it. For this purpose, the 30-day period begins on the day after we receive the complaint. If the final day falls on a weekend or public holiday, we will acknowledge it by the next working day
Where we will be able to respond to your complaint within thirty (30) days, we will simply do so rather than sending both an acknowledgement and then a final response.
We will take appropriate action to respond to your complaint, including any required investigation, and keep you informed during this process, particularly if there ae any undue delays in responding to the complaint.
We will inform you of the outcome of your complaint without undue delay.
Types of data protection complaint we can deal with
We can deal with any complaint that relates to data protection legislation and requirements, but some examples include:
- Cases in which you are dissatisfied with our response to your data subject access request (DSAR) or another request within which you sought to exercise your data rights;
- Instances in which you have concerns about the data security safeguards which we have in place;
- Any concerns or complaints you may have which relate to how we collected, recorded, used, or retained your personal information.
Cases which we will not consider to be a data protection complaint
Should you be complaining about some other aspect of DragonBet’s service, for instance a transaction or general communication with customer service personnel and seek to exercise your data rights in the process, we will not treat this as a data protection complaint.
What this means is that we will not treat, for example, a data subject access request which is made alongside a more general complaint as a data protection complaint.
Should you wish to make a data protection complaint, please let us know and give us details of your complaint so that we can begin addressing in as quickly as possible.
Where we are unsure about your intent, we may ask you to clarify whether you are making a data protection complaint.
Mixed complaints
Sometimes a complaint may include both data protection issues and wider customer service, account, transaction, gambling, or operational issues. Where this happens, we will identify and handle the data protection element under this procedure. If we can provide an outcome on the data protection element sooner than the wider complaint, we will do so unless there is a justified reason not to.
Proving your identity and making a complaint on behalf of another person
On occasion, your complaint may relate to a situation where we have not met your expectations due to uncertainty on our behalf that addressing your initial effort to exercise your data rights could result in sharing personal data with a person who should not have it.
In such cases, though we will also ask for this at the time of your initial request in any case, we may request proof of identity if this is what it will take for us to be sure we would not be committing such a breach in satisfying your complaint.
If you make a request on behalf of another person, we will again have to satisfy ourselves that you have the authority to do this. Ordinarily, we will ask for such proof at the time your initial query or request. However, there may be occasions upon which the person making the data protection complaint differs from the person who made initial contact with the request or query. In such cases, we will ask you to prove that you have authority to deal with the complaint on behalf of the data subject before we fulfil the request.
Investigating your complaint
We may ask you to confirm what your complaint relates to if we are unsure.
We will consider any material held internally and any previous actions in relation to the matter you are raising, and will begin investigating it as soon as we become aware of it.
The amount of time it takes us to issue a final response to your complaint will depend on how complex it is and how much investigation is involved, but we will respond without any undue delay.
Informing you of the outcome of your complaint
We will let you know the outcome of your complaint and, in doing so, explain the steps we have taken to resolve it. If we take any actions following on from the investigation, we will inform you of these at the same time.
Where we believe that we have complied with data protection legislation, we will explain to you how we have arrived at that conclusion.
If you are still unhappy
Should you remain dissatisfied following our investigation, as always you have the right to complain to the Information Commissioner’s Office, who can be contacted at https://ico.org.uk/make-a-complaint/.