Who are we?
www.winmasters.com, operated by WM Interactive Limited which is a Maltese Company whose registered address is at 170, Pater House, Level 1 (Suite A174), Psaila Street, Birkirkara, BKR 9077, Malta, with company registration number C-65151 and is regulated by the Malta Gaming Authority (MGA).
We may be contacted at email@example.com
Our Data Protection Officer may be contacted on firstname.lastname@example.org
Why do we collect Personal Data?
We need to collect data from you to be able to provide you with the service of remote gaming. This may include the need to share this data with our partner companies and service providers, with whom we would have established safeguards to protect your data, for the purpose of providing you our services as requested.
When we provide remote gaming services to our customers, we must collect personal data from you to comply with legal obligations related to our gaming licence obligations to the Malta Gaming Authority, for company tax reporting obligations to the tax authorities in Malta and to meet our obligation to assist authorities, when requested, in the investigation of potential criminal activity.
We also have a legitimate interest to protect our services from promotion abuse, prevent fraud and internet security risks. This also allows us to ensure the security, integrity, accessibility and availability of our services.
We will also ask you if you wish to receive marketing communications from us or third parties, like our contracted service providers, on our behalf. You have the right at all times to withdraw your consent through your account profile privacy settings.
Personal data that we collect
Your personal information, which we collect and use, relates to the following:
- Personal identification and communication details provided to us by completing the registration form on the website or any other information you submit to us through the website or by email.
- Verification documents provided for Identity, Payment Method verification and other documentation we may request due to our obligations at law.
- Contact information through the website, email, telephone or other media.
- Your answers to questionnaires or surveys we conduct.
- Elements of transactions, including financial accounts information that you may provide us, made through the website, telephone or other media.
- Details of your visits to the site, including but not limited to traffic data, site information, weblogs and other contact information.
- Telephone calls or chat sessions to and from our Customer Service Department are recorded for security and education purposes along with the resolution of questions arising from the service provided to you.
We do not collect special categories of data on a regular basis, however, we may receive such data from you if you tell us that you have a problem controlling your betting activity. We would treat such data as equivalent to health data and protect it accordingly.
Cookies are small text files (composed only of letters and numbers) that a web server places on your computer or mobile device when you visit a webpage. When used, the cookie can help make our Services more user-friendly, for example by remembering your language preferences and settings.
Types of Cookies used
There are five main types of Cookies:
- Strictly Necessary Cookies – These Cookies are essential to enable you to login, navigate around and use the features of our Services. We do not need to obtain your consent in order to use these Cookies. These Cookies can be used for security and integrity reasons - for example to detect violation of our policies and for support or security features.
- Functionality Cookies – These Cookies allow our Services to remember choices you make (such as your language) and provide enhanced and personalized features. For example, these Cookies are used for authentication (to remember when you are logged-in) and support other features of our Services.
- Performance Cookies – These Cookies collect information about your online activity (for example the duration of your visit on our Services), including behavioral data and content engagement metrics. These Cookies are used for analytics, research and to perform statistics (based on aggregated information).
- Marketing or Advertising Cookies – These Cookies are used to deliver tailored offers and advertisements to you, based on your derived interests, as well as to perform email marketing campaigns. They can also be used to limit the number of times you see an advertisement as well as help measure the effectiveness of the advertising campaign. They are usually placed by our advertisers (for example advertising networks) and provide them insights about the people who see and interact with their ads, visit their websites or use their app.
- Social media Cookies – Our website includes social media features, such as the Facebook "Like" or "Share" buttons. These features are either hosted by a third party or hosted directly on our Services. Your interactions with these features are governed by the privacy statement of the company providing these features.
|Provider / Service||Type||Purpose|
|Analytics Cookies||First party Cookies||
These Cookies are used to collect information regarding how you interact with the content on our Services. We use the information to improve the Services and to offer personalized products and content.
|Hotjar||Third party Cookies||
|Xtremepush||Third party Cookies||
Performance, Marketing or Advertising Cookies
|Google Analytics||Third party Cookies||
|Google Tag Manager||Third party Cookies||
|Google AdWords||Third party Cookies||
Marketing or Advertising Cookies
|Netrefer||Third party Cookies||
Marketing or Advertising Cookies
|Incapsula||Third party Cookies||
Strictly necessary Cookies
|Other cookies||First and Third party Cookies||
Strictly necessary Cookies
These unlisted cookies might be in use on internal sections of the Services, in order to customize and simplify the user experience on the site by remembering choices you made and your log in credentials.
How to manage your Cookie settings
Please note that we do not recognize or respond to automated browser signals regarding Cookies, including "Do Not Track" requests. However, there are various ways in which you can manage and control your cookie settings. Please remember that, by deleting or blocking cookies, some of the features of the Services may not work properly or as effectively.
- Turning off Cookies via your web browser Most web browsers will provide you with some general information about cookies, enable you to see what cookies are stored on your device, allow you to delete them all or on an individual basis, and enable you to block or allow cookies for all websites or individually selected websites. You can also normally turn off third party cookies separately. Please note that the settings offered by a browser or device often only apply to that particular browser or device.
How do we use your personal data?
We use your personal data to:
- Create, operate, and manage your account.
- Participate in games and perform relevant functions to participate in them.
- Carry out identification procedures for your participation in the game.
- Promote your bets, including card payments and online payments.
- Compliance with the legal and regulatory frameworks governing our operations, including transmission of personal details, personal data about transactions and traffic data to authorities.
- Creating personal profiles for Anti-Money Laundering Risk Assessment purposes.
- Tracking transactions for the purpose of preventing fraud, abnormal betting, money laundering and fraud, including exchanging personal data with our suppliers of Payment Processing services.
- Conducting research, questionnaires and analysis.
When you consent to, we use your data to provide you with information about site changes, new services and offers. In case you do not wish to receive marketing information, you have the right to leave this service. You can re-consent to be provided with marketing information by emailing our support department or by using the relevant function under “My Account”.
Personal data that is provided to us will be shared amongst group companies which will handle relevant aspects of processing in order to provide you with requested services.
To provide our services, and for the purpose of preventing illegitimate use of our services, we perform automated individual decision-making, including profiling.
Where do we keep your data?
We take all industry standard precautions to keep your personal data secure within our European Union physically located servers. These servers may in turn be accessed through encrypted connections over the internet. For this purpose, we have in place an Information Security Management System initiative that is working towards meeting the ISO27001:2013 standard.
Third Party Transfers of Data
We may transfer data you provide to us, or inferred data based on your data for multiple purposes as described in the following.
Transfers within our Group
Your personal data is transferred within our group companies which provide us customer data processing on the basis of a contractual agreement between us in line with the GDPR. Group companies process your data on our behalf to provide you with the following services:
- Customer Support
- Payment processing
- Anti-Fraud and Anti-Money Laundering checks
- Marketing (where consent has been provided – further information below)
We ensure that data transfers within group companies are covered with appropriate controller-processor contracts and safeguards as specified by the General Data Protection Regulation (EU2016/679).
Transfers outside of our Group to third parties
When processing your betting account and its associated transactions, we may need to appeal to credit rating agencies, fraud detection agencies and money laundering agencies in line with regulatory provisions from the Malta Gaming Authority or any other relevant authority.
The purpose of such communications would be to ensure:
- Assess whether you may be a Politically Exposed Person or an individual subject to Financial Sanctions.
- Assess whether your personal details are similar to those of people suspected of having committed fraud or money laundering.
- Verify your personal details through electronic means by matching against third party databases.
- Where such information is requested by payment providers in relation to enquiries regarding fraud, we shall also provide such personal data as long as the request for information is aimed to protect your rights and/or, the legitimate interest of the company to protect itself from fraud.
We ensure that data transfers outside of group companies are covered with appropriate controller-processor contracts and safeguards as specified by the General Data Protection Regulation (EU2016/679).
Transfers to regulatory authorities
To satisfy our legal obligations, we may be requested to transfer your data to the:
- Malta Gaming Authority
- Financial Investigations and Analysis Unit
- Sanctions Monitoring Board
- Maltese and other Tax Authorities with whom we are registered
- Other applicable Law enforcement bodies where so requested
This can include transferring of all personal details, verification documents, payment and betting transaction history, communications history and any other information we have about you. The methods of transfer of such data may be prescribed by the relevant authority, over which we do not have control.
Transfers for marketing Purposes
We will share personal data with marketing partners (network providers, banks, payment processors, affiliates, etc.) only based on a freely given, specific, informed and unambiguous consent from you. Such partners would be limited to receive contact information such as e-mail address and sports preferences for marketing reasons.
Your consent may be withdrawn at all times through “My Account” or by contacting us on email@example.com.
Should you withdraw your consent, the company will inform marketing partners to stop their marketing communications to you as soon as your wish is communicated to them.
Third Country transfers
The company does not regularly share any of the personal data you provide us to third parties (outside of group companies) located outside of the European Economic Area or countries considered by the EU to provide an equivalent standard of data protection.
If the company will in the future need to carry out such transfers of personal data to third parties (outside of group companies) to be able to provide you with your requested services, we will let you know of this. In such a case, we would ensure to follow applicable data protection legislation and seek approval from our Lead Data Protection Authority to ensure that at times, your personal data rights are respected and guaranteed.
Retention and Disposal of Information
After the closure of any account, we retain your data for a period of up to 10 years due to our legal obligations towards Anti-Money Laundering and Countering Finance of Terrorism, Company and Taxation record-keeping obligations.
- For up to one (1) year: Details of your visits to the site, including but not limited to traffic data, site information, weblogs and other contact information; Telephone calls to and from our Customer Service Department
- For up to five (5) years from last activity: Personal identification and communication details provided, contact information through the website, email, telephone or other media.
- For up to ten (10) years from last activity: Elements of transactions, including financial accounts information that you may provide us, made through the website, telephone or other media
We will also keep personal data for the purpose of presenting and processing in case of a litigation or a legal process which you, the relevant authorities or us may be party in, due to our provision of services to you.
If your account in any of the above cases is not active, then we will not process the data further except for complying with the above obligations.
Your personal data rights
You have the right to:
- access to the personal information provided by you;
- request rectification of personal data that you consider incorrect;
- request for restriction of processing of data;
- request erasure of data;
- file an objection about processing of your data;
- request to export your data; and
- be informed about automated individual decision-making, including profiling; and
Your rights may be exercised in accordance with the Law, which might include restrictions on when you can exercise these rights. You can exercise these rights by contacting us on firstname.lastname@example.org
You have also the right to lodge a complaint with the Data Protection Authority, which is the Information and Data Protection Commissioner whose website may be found at http://www.idpc.org.mt/. You may also decide to lodge a complaint with your local Data Protection Authority. You may find a list with your local Data Protection Authority contact details at http://ec.europa.eu/justice/data-protection/article-29/structure/data-protection-authorities/index_en.htm
Changes to the Privacy Statement