Privacy Policy

Privacy Policy

Version: 1.0  |  Last Updated: 31 July 2025  |  Effective Date: 31 July 2025

This Privacy Policy ("Policy") describes how Supabet ("we", "us", or "our"), operating through the website supabet-review.com (the "Website"), collects, uses, stores, and protects personal data relating to users of our Platform ("you" or the "Player").

We are committed to protecting your privacy in full compliance with the General Data Protection Regulation (EU) 2016/679 (GDPR) and all applicable national data protection legislation. Please read this Policy carefully. By using the Website, you acknowledge that you have read and understood this Policy.

This Policy should be read alongside our Terms & Conditions and our Responsible Gaming Policy.

1. Introduction

1.1. Who We Are

Supabet is the operator of the online gaming platform accessible at supabet-review.com. We act as the Data Controller in respect of all personal data processed through the Platform. As Data Controller, we determine the purposes and means of processing your personal data and bear responsibility for its lawful and secure handling.

1.2. Scope of This Policy

This Policy applies to all personal data we collect about individuals who:

  • Register or apply to register an Account on the Platform;
  • Browse or interact with the Website;
  • Contact our customer support team;
  • Participate in promotions, tournaments, or surveys;
  • Subscribe to marketing communications.

2. Data We Collect

2.1. Data Provided by You

We collect personal data that you voluntarily provide to us, including:

  • Identity Data: Full name, date of birth, gender, nationality, government-issued ID number;
  • Contact Data: Email address, telephone number, residential address;
  • Account Data: Username, password (stored in encrypted form), security questions;
  • Financial Data: Payment method details, transaction history, source of funds documentation;
  • KYC Documents: Copies of identity documents, proof of address, and other verification materials;
  • Responsible Gaming Data: Self-declared limits, self-exclusion requests, and problem gambling disclosures;
  • Correspondence: Any communications you send us via email, live chat, or contact forms.

2.2. Data We Collect Automatically

When you access the Website, we automatically collect certain technical and behavioural data, including:

  • Technical Data: IP address, browser type and version, operating system, device type, screen resolution;
  • Usage Data: Pages visited, time spent on pages, links clicked, game sessions played, bet history;
  • Geolocation Data: Country and region-level location derived from your IP address;
  • Cookie Data: Tracking identifiers and session data (see Section 6).

2.3. Data from Third Parties

We may receive personal data about you from the following third-party sources:

  • KYC / AML Verification Providers: Identity verification and fraud prevention agencies;
  • Payment Processors: Transaction confirmation and fraud screening data;
  • Analytics Partners: Aggregated and pseudonymised behavioural analytics;
  • Publicly Available Sources: Sanctions lists, politically exposed persons (PEP) databases, adverse media.

3. How We Use Your Data

We use your personal data for the following purposes:

  • Account Registration & Management: To create, verify, and manage your Player Account;
  • Service Delivery: To provide access to games, process bets, and facilitate financial transactions;
  • Identity & Age Verification (KYC): To verify your identity, age, and eligibility in compliance with applicable law;
  • Anti-Money Laundering (AML) Compliance: To detect, investigate, and prevent financial crime;
  • Fraud Prevention & Security: To protect against fraudulent activity, unauthorised access, and abuse;
  • Customer Support: To respond to your enquiries and resolve complaints;
  • Responsible Gaming: To monitor player behaviour, enforce protection measures, and provide harm-prevention support;
  • Marketing Communications: To send you promotional offers, newsletters, and personalised recommendations, where you have given explicit consent;
  • Personalisation: To tailor the Website experience to your preferences;
  • Analytics & Improvement: To understand usage patterns and improve the Platform;
  • Legal Compliance: To meet our obligations under applicable laws and regulations.

4. Legal Bases for Processing

We rely on the following legal bases under GDPR Article 6 for processing your personal data:

Purpose Legal Basis
Account creation and service deliveryPerformance of a contract (Art. 6(1)(b))
KYC / AML complianceLegal obligation (Art. 6(1)(c))
Fraud prevention & securityLegitimate interests (Art. 6(1)(f))
Responsible Gaming monitoringLegal obligation / Legitimate interests (Art. 6(1)(c) & (f))
Marketing communicationsConsent (Art. 6(1)(a))
Website analyticsLegitimate interests (Art. 6(1)(f))
Legal claims and regulatory complianceLegal obligation / Vital interests (Art. 6(1)(c) & (d))

Where we process special category data (e.g., health-related information disclosed in the context of Responsible Gaming), we rely on Article 9(2)(b) (employment and social protection) and/or explicit consent under Article 9(2)(a) of the GDPR.

5. Data Sharing & Third Parties

5.1. Recipients of Your Data

We may share your personal data with the following categories of third parties:

  • KYC & Identity Verification Providers: To conduct mandatory identity and age verification;
  • Payment Service Providers: To process deposits, withdrawals, and refunds;
  • Game Software Providers: To deliver and maintain game content;
  • IT & Cloud Infrastructure Providers: To host and maintain the Platform;
  • Customer Support Platforms: To manage support tickets and live chat;
  • Marketing & Analytics Partners: Where you have consented to marketing communications;
  • Fraud Prevention & AML Agencies: To screen against sanctions and fraud databases;
  • Regulatory & Law Enforcement Authorities: Where required by law or court order.

5.2. No Sale of Data

We do not sell, rent, or trade your personal data to any third party for their own marketing purposes.

5.3. Third-Party Processors

All third-party data processors are engaged pursuant to written data processing agreements ensuring GDPR-compliant handling of your personal data. We conduct appropriate due diligence on all processors before engagement.

6. Cookies & Tracking Technologies

6.1. What Are Cookies?

Cookies are small text files stored on your device by your web browser. We use cookies and similar tracking technologies (web beacons, pixel tags, local storage) to ensure the Website functions correctly and to improve your user experience.

6.2. Types of Cookies We Use

Cookie Type Purpose Consent Required?
Strictly NecessaryEnable core Website functionality (login sessions, security, language preferences)No
Performance / AnalyticsMeasure site usage, traffic sources, and user behaviour patternsYes
FunctionalRemember your preferences (e.g., currency, game history)Yes
Targeting / AdvertisingDeliver relevant promotional content based on your interestsYes

6.3. Managing Cookies

When you first visit the Website, a cookie consent banner will be displayed. You may accept all cookies, reject non-essential cookies, or customise your preferences. You may also manage or delete cookies at any time via your browser settings. Please note that disabling certain cookies may affect the functionality of the Website.

7. Data Security

7.1. Security Measures

We implement industry-standard technical and organisational security measures to protect your personal data against unauthorised access, disclosure, alteration, or destruction. These measures include:

  • Transport Layer Security (TLS) encryption for all data transmitted between your browser and the Website;
  • AES-256 encryption for sensitive data stored at rest;
  • Firewalls, intrusion detection systems, and regular vulnerability scanning;
  • Role-based access controls limiting staff access to personal data to authorised personnel only;
  • Regular security audits and penetration testing;
  • PCI-DSS compliance for payment card data handling.

7.2. Data Breach Notification

In the unlikely event of a personal data breach that poses a risk to your rights and freedoms, we will notify the relevant supervisory authority within 72 hours of becoming aware of the breach, as required by GDPR Article 33. Affected individuals will be notified without undue delay where the breach is likely to result in a high risk to their rights.

8. Data Retention

8.1. Retention Periods

We retain personal data for no longer than is necessary for the purposes for which it was collected. Typical retention periods are as follows:

Data Category Retention Period
Account & Identity DataDuration of account + 5 years after closure
KYC Documents5 years from account closure or last transaction
Financial Transaction Data5 years from the date of transaction
Responsible Gaming Records5 years from account closure
Marketing PreferencesUntil consent is withdrawn + 1 year
Customer Support Correspondence3 years from resolution of query
Technical / Log Data12 months
Cookie DataAs specified per cookie type (typically 30 days – 2 years)

Longer retention periods may apply where required by law, regulatory obligation, or ongoing legal proceedings.

9. Your Rights

Under the GDPR, you have the following rights in relation to your personal data:

  • Right of Access (Art. 15): To obtain a copy of the personal data we hold about you;
  • Right to Rectification (Art. 16): To request correction of inaccurate or incomplete data;
  • Right to Erasure (Art. 17): To request deletion of your data where it is no longer necessary for the purpose for which it was collected (subject to legal retention obligations);
  • Right to Restrict Processing (Art. 18): To request that we limit our processing of your data in certain circumstances;
  • Right to Data Portability (Art. 20): To receive your data in a structured, machine-readable format;
  • Right to Object (Art. 21): To object to processing based on legitimate interests or for direct marketing purposes;
  • Right to Withdraw Consent (Art. 7(3)): To withdraw consent at any time where processing is based on consent, without affecting the lawfulness of prior processing;
  • Right to Lodge a Complaint: To submit a complaint to the competent data protection supervisory authority in your country of residence.

To exercise any of the above rights, please contact our Privacy team at [email protected]. We will respond within 30 days of receipt of your request. Requests may be extended by a further two months where the complexity and volume of requests so requires, in accordance with GDPR Article 12(3).

10. International Data Transfers

10.1. Transfers Outside the EEA

Some of our third-party service providers are based outside the European Economic Area (EEA). Where we transfer personal data to countries not deemed to provide an adequate level of data protection by the European Commission, we ensure appropriate safeguards are in place, including:

  • Standard Contractual Clauses (SCCs) approved by the European Commission;
  • Adequacy decisions where applicable;
  • Binding Corporate Rules (BCRs) for intra-group transfers.

You may obtain further details on the specific safeguards applied to international transfers by contacting us at [email protected].

11. Minors

The Platform is intended exclusively for individuals aged 21 years and over in accordance with the applicable minimum age for online gambling in Greece. We do not knowingly collect or process personal data relating to persons under this minimum age. If we become aware that we have inadvertently collected data relating to a minor, we will take immediate steps to delete such data and close the associated Account. If you believe a minor has provided us with their personal data, please contact us immediately at [email protected].

12. Changes to This Policy

We reserve the right to update this Privacy Policy at any time to reflect changes in our practices, technology, or applicable law. The updated Policy will be published on this page with a revised version number and effective date. For material changes, we will notify registered Players via email or a prominent Website notice. We encourage you to review this Policy periodically. Your continued use of the Platform after the effective date of changes constitutes acceptance of the revised Policy.

13. Contact Information

If you have any questions, concerns, or requests relating to this Privacy Policy or your personal data, please contact us using the details below:

We aim to acknowledge all privacy-related queries within 48 hours and to provide a full response within the statutory 30-day period. If you are not satisfied with our response, you have the right to lodge a complaint with the competent national data protection authority.