Privacy Policy

Version: 1.0  |  Last Updated: July 31, 2026

This Privacy Policy ("Policy") describes how Supabet ("we", "us", or "the Operator"), operating through the website supabet-casinos.com (the "Website"), collects, uses, stores, and protects your personal data. It also explains your rights in relation to that data.

This Policy forms part of our overall framework of legal documents, which also includes our Terms & Conditions and Responsible Gaming Policy. By using our Website and Services, you acknowledge that you have read and understood this Policy.

We are committed to processing your personal data in accordance with applicable data protection legislation, including the General Data Protection Regulation (GDPR) (EU) 2016/679 and any national implementing legislation.

1. Introduction

1.1 Who We Are

Supabet is an online gaming platform accessible at supabet-casinos.com. We are the data controller in respect of the personal data you provide to us or that we collect about you in connection with your use of the Website and Services.

1.2 Scope of This Policy

This Policy applies to all personal data we collect from or about you when you:

  • Visit or browse the Website;
  • Register for or use an Account;
  • Make deposits or withdrawals;
  • Participate in Games, Events, or Promotions;
  • Contact our customer support team;
  • Subscribe to marketing communications.

1.3 Contact Details

If you have any questions or concerns regarding this Policy or our data processing activities, please contact our Data Protection Officer (DPO) at:

2. Data We Collect

2.1 Data You Provide Directly

We collect personal data that you voluntarily provide to us, including:

  • Registration Data: Full legal name, date of birth, gender, country of residence, email address, phone number, and chosen username/password;
  • Identity Verification (KYC) Data: Copies of government-issued identification, proof of address, and payment method documentation;
  • Financial Data: Payment method details (e.g., card numbers, e-wallet accounts), transaction history, deposit and withdrawal records;
  • Communication Data: Contents of messages sent to our support team, complaints, and feedback;
  • Responsible Gaming Data: Limit settings, cooling-off or self-exclusion requests, and any related correspondence.

2.2 Data We Collect Automatically

When you access or use the Website, we automatically collect certain technical and behavioural data, including:

  • Device & Technical Data: IP address, device type, operating system, browser type and version, screen resolution;
  • Usage Data: Pages visited, time spent on pages, clickstream data, search terms used, and referring URLs;
  • Gaming Activity Data: Games played, bets placed, outcomes, session durations, wagering patterns;
  • Cookie & Tracking Data: Data collected via cookies, web beacons, pixels, and similar technologies (see Section 6).

2.3 Data from Third Parties

We may receive personal data about you from third parties, including:

  • Identity verification and KYC service providers;
  • Payment processing companies;
  • Fraud detection and anti-money laundering service providers;
  • Marketing affiliates and partners (where you have consented to data sharing);
  • Publicly available sources and regulatory databases (e.g., self-exclusion registers).

3. How We Use Your Data

3.1 Purposes of Processing

We process your personal data for the following purposes:

  • Account Management: To register and maintain your Account, verify your identity, and manage your profile;
  • Service Delivery: To provide access to Games, process transactions, and deliver the Services;
  • KYC & Compliance: To verify your age and identity, conduct due diligence, and comply with anti-money laundering obligations;
  • Fraud Prevention & Security: To detect, investigate, and prevent fraudulent activity, cheating, and other prohibited conduct;
  • Customer Support: To respond to your queries, complaints, and requests;
  • Responsible Gaming: To monitor gaming behaviour, apply player protection tools, and support responsible gambling obligations;
  • Marketing & Promotions: To send you promotional communications and personalised offers where you have given your consent or where we have a legitimate interest (subject to your right to opt out);
  • Analytics & Website Improvement: To analyse usage patterns, improve the Website, and optimise the user experience;
  • Legal Obligations: To comply with applicable laws, regulations, and requests from regulatory or law enforcement authorities.

4. Legal Bases for Processing

4.1 Lawful Basis

We process your personal data on the following legal bases under the GDPR:

  • Performance of a Contract (Article 6(1)(b) GDPR): Processing necessary to fulfil our contractual obligations to you, including account registration, transaction processing, and provision of Games;
  • Legal Obligation (Article 6(1)(c) GDPR): Processing required to comply with applicable legal obligations, including KYC/AML requirements, responsible gaming obligations, and regulatory reporting;
  • Legitimate Interests (Article 6(1)(f) GDPR): Processing necessary for our legitimate interests, including fraud prevention, network security, improving our services, and direct marketing to existing customers (where such interests are not overridden by your rights);
  • Consent (Article 6(1)(a) GDPR): Processing based on your explicit consent, such as for direct marketing to new subscribers, or the use of non-essential cookies. You may withdraw your consent at any time without affecting the lawfulness of processing carried out prior to withdrawal.

5. Data Sharing & Third Parties

5.1 Categories of Recipients

We may share your personal data with the following categories of third parties:

  • Identity & KYC Verification Providers: To verify your identity, age, and address;
  • Payment Service Providers: To process deposits, withdrawals, and refunds;
  • Game Software Providers: To deliver game content and record game outcomes;
  • Fraud Prevention & AML Providers: To detect and prevent financial crime;
  • IT & Cloud Service Providers: For hosting, data storage, and platform maintenance;
  • Customer Support Platforms: To manage and respond to support requests;
  • Marketing & Analytics Providers: To serve targeted advertising and analyse Website traffic;
  • Regulatory & Law Enforcement Authorities: Where required by law or regulation;
  • Self-Exclusion Register Operators: To enforce self-exclusion and responsible gaming obligations.

5.2 No Sale of Personal Data

We do not sell, rent, or trade your personal data to third parties for their own marketing purposes.

5.3 Business Transfers

In the event of a merger, acquisition, restructuring, or sale of all or part of our business, your personal data may be transferred to the acquiring entity. You will be notified of any such transfer and any material changes to this Policy in advance.

6. Cookies & Tracking Technologies

6.1 What Are Cookies?

Cookies are small text files that are placed on your device when you visit a website. They are widely used to make websites function efficiently and to provide information to the website owner. We also use similar tracking technologies such as web beacons, pixels, and local storage objects.

6.2 Types of Cookies We Use

  • Strictly Necessary Cookies: Essential for the Website to function correctly. These cannot be disabled without affecting the basic operation of the Website;
  • Performance & Analytics Cookies: Collect anonymised data about how visitors use the Website, to help us improve functionality and user experience (e.g., Google Analytics);
  • Functional Cookies: Enable the Website to remember your preferences and settings (e.g., language, currency, login status);
  • Marketing & Targeting Cookies: Used to deliver relevant advertising and promotional content based on your interests and browsing behaviour;
  • Third-Party Cookies: Set by our trusted partners (e.g., game providers, payment processors, analytics platforms) for the purposes described above.

6.3 Managing Cookies

When you first visit the Website, you will be presented with a cookie consent banner allowing you to accept or reject non-essential cookies. You can change your cookie preferences at any time by accessing the cookie settings on the Website, or by configuring your browser settings. Please note that disabling certain cookies may affect the functionality of the Website.

7. Data Security

7.1 Security Measures

We implement appropriate technical and organisational measures to protect your personal data against unauthorised access, disclosure, alteration, or destruction. These measures include:

  • SSL/TLS encryption for all data transmitted between your device and the Website;
  • Secure storage of personal data on encrypted servers;
  • Access controls and role-based permissions restricting internal access to personal data;
  • Regular security audits and penetration testing;
  • PCI-DSS compliant payment processing infrastructure;
  • Employee training on data protection and information security.

7.2 Data Breach Notification

In the event of a personal data breach that is likely to result in a risk to your rights and freedoms, we will notify the relevant supervisory authority within 72 hours of becoming aware of the breach, in accordance with our obligations under the GDPR. Where the breach is likely to result in a high risk to you personally, we will also notify you directly without undue delay.

8. Data Retention

8.1 Retention Periods

We retain your personal data for as long as is necessary to fulfil the purposes for which it was collected, and in compliance with our legal obligations. The following general retention periods apply:

  • Account Data: Retained for the duration of the Account relationship and for a minimum of 5 years after Account closure;
  • Transaction & Financial Records: Retained for a minimum of 5 years in accordance with AML regulations;
  • KYC Documentation: Retained for a minimum of 5 years after the end of the business relationship;
  • Marketing Data: Retained until you withdraw your consent or opt out, plus a reasonable administrative period;
  • Support Communications: Retained for 3 years from the date of resolution.

Where we have no ongoing legitimate purpose to retain your personal data, it will be securely deleted or anonymised.

9. Your Rights

9.1 Rights Under GDPR

Subject to applicable law, you have the following rights in relation to your personal data:

  • Right of Access (Article 15): The right to obtain a copy of the personal data we hold about you;
  • Right to Rectification (Article 16): The right to request correction of inaccurate or incomplete personal data;
  • Right to Erasure (Article 17): The right to request deletion of your personal data, subject to our legal retention obligations;
  • Right to Restriction of Processing (Article 18): The right to request that we limit how we use your data in certain circumstances;
  • Right to Data Portability (Article 20): The right to receive your personal data in a structured, commonly used, and machine-readable format;
  • Right to Object (Article 21): The right to object to processing based on legitimate interests, including direct marketing;
  • Rights Related to Automated Decision-Making (Article 22): The right not to be subject to decisions based solely on automated processing that significantly affect you, unless such processing is necessary for a contract or based on your explicit consent.

9.2 Exercising Your Rights

To exercise any of the above rights, please submit a written request to our Data Protection Officer at [email protected]. We will respond to your request within 30 days. In complex cases, we may extend this period by a further 60 days, in which case we will inform you of the extension and the reasons for it. We may be required to verify your identity before processing your request.

9.3 Right to Lodge a Complaint

If you believe that our processing of your personal data infringes applicable data protection law, you have the right to lodge a complaint with the relevant supervisory authority in your country of residence. In Greece, this is the Hellenic Data Protection Authority (HDPA), accessible at www.dpa.gr.

10. International Data Transfers

10.1 Transfers Outside the EEA

In order to deliver our Services, your personal data may be transferred to and processed in countries outside the European Economic Area (EEA). Where such transfers occur, we ensure that appropriate safeguards are in place to protect your data, including:

  • Standard Contractual Clauses (SCCs) approved by the European Commission;
  • Transfers to countries recognised by the European Commission as providing an adequate level of protection;
  • Other legally approved transfer mechanisms where applicable.

10.2 Third-Party Processors

We require all third-party data processors that process data outside the EEA to maintain appropriate data protection safeguards and to process personal data only in accordance with our written instructions.

11. Minors

11.1 Age Restriction

Our Services are strictly intended for individuals who are 21 years of age or older. We do not knowingly collect, use, or store personal data relating to minors. If we become aware that personal data belonging to a person under the age of 21 has been collected, we will take immediate steps to delete such data and close the associated Account.

11.2 Parental Controls

We strongly encourage parents and guardians to take an active role in monitoring and controlling their children's online activities. We recommend the use of parental control software to prevent minors from accessing online gambling platforms. For more information on our approach to protecting minors, please see our Responsible Gaming Policy.

12. Changes to This Policy

12.1 Amendments

We reserve the right to update or modify this Policy at any time. Any changes will be posted on the Website with a revised version number and effective date. Where changes are material, we will endeavour to notify you by email or by a prominent notice on the Website. Your continued use of the Services following the publication of any amendments constitutes your acceptance of the revised Policy.

12.2 Previous Versions

Previous versions of this Policy are available upon request by contacting us at [email protected].

13. Contact Information

For all data protection enquiries, requests, or concerns, please contact our Data Protection Officer:

For general customer support queries unrelated to data protection, please contact us at [email protected].

Coin