Section 01
Introduction
This Privacy Policy ("Policy") is published by bdd333 ("bdd333", "the Platform", "we", "us", "our") and applies to all users ("Player", "User", "you") who access, browse, register on, or interact with the bdd333 online casino and sports betting platform, available at https://bdd333.app, including all associated subpages, game environments, promotional interfaces, and customer support channels.
The purpose of this Policy is to give you a clear, honest, and comprehensive account of what personal data bdd333 collects, why it is collected, how it is stored and processed, with whom it may be shared, how long it is retained, and what rights you hold in relation to that data. We believe that informed players make better decisions, and transparency is a cornerstone of how bdd333 operates.
This Policy should be read in conjunction with bdd333's Terms & Conditions, which govern the contractual relationship between you and the platform. By creating a bdd333 account or by continuing to use the platform having been presented with this Policy, you acknowledge that you have read, understood, and consent to the data practices described herein.
Scope: This Policy covers personal data collected through the bdd333 website and mobile-optimised interface. It does not govern the data practices of third-party game studios, payment providers, or external websites that may be referenced in passing within bdd333's content. Those parties operate under their own independent privacy frameworks.
Section 02
Data We Collect
bdd333 collects personal data through several channels: directly from you when you register or interact with the platform, automatically through your device and browser when you visit the site, and from third-party service providers who assist in delivering platform functionality. The categories of data we collect are described below.
2.1 Registration & Account Data
- Full name as it appears on your government-issued identity document.
- Date of birth (used for age verification — players must be 18 years or older).
- Mobile phone number (used as your primary account identifier and for OTP verification).
- Username (chosen by you at registration).
- Encrypted password (bdd333 stores passwords using one-way hashing — plain-text passwords are never stored).
- Preferred language and currency (English / BDT ৳ for Bangladesh-market players).
2.2 Identity Verification Data
For the purposes of Know Your Customer (KYC) compliance and fraud prevention, bdd333 may request and retain copies of:
- National Identity Card (NID) — front and back image.
- Passport biographic data page, where NID is unavailable.
- Utility bill or bank statement issued within the past three months (proof of address).
- Selfie photograph or short video taken at the time of KYC submission (liveness check).
2.3 Financial Transaction Data
- Mobile wallet numbers associated with bKash, Nagad, Rocket, or Upay transactions.
- Transaction reference IDs provided by payment providers.
- Deposit amounts, withdrawal amounts, and timestamps of all financial transactions.
- Account balance history and bonus credit ledger entries.
2.4 Gaming Activity Data
- Game sessions: game title, session start/end timestamps, stake amounts, game outcomes, and RTP data.
- Sports bets: event, market selection, odds accepted, stake, settlement outcome, and settlement time.
- Responsible gaming tool settings: deposit limits, session time reminders, self-exclusion periods.
2.5 Technical & Device Data
- IP address at the time of login and during active sessions.
- Device type, operating system, and browser version.
- Geolocation data (country-level only, derived from IP address — bdd333 does not collect GPS coordinates).
- Session duration, pages visited, and interaction events (clicks, scrolls, button activations).
- Cookie identifiers and local storage values (see Section 6 for full cookie disclosure).
2.6 Communications Data
- Content of support tickets and live chat transcripts submitted through the bdd333 support system.
- Email correspondence sent to or received from [email protected].
- Records of promotional opt-in and opt-out preferences.
What bdd333 Does Not Collect: bdd333 does not collect full payment card numbers, card CVV codes, or bank account credentials. All financial transactions are processed exclusively through mobile wallet providers (bKash, Nagad, Rocket, Upay) using their own secure authentication flows. bdd333 never handles raw card data.
The table below summarises the primary data categories, the purposes for which they are collected, and the legal basis applied under internationally recognised data protection principles:
| Data Category |
Primary Purpose |
Legal Basis |
| Registration & Account Data |
Account creation, login authentication, player communications |
Contract performance |
| Identity Verification (KYC) |
Age verification, fraud prevention, AML compliance |
Legal obligation / Legitimate interest |
| Financial Transaction Data |
Deposit/withdrawal processing, dispute resolution, fraud monitoring |
Contract performance / Legal obligation |
| Gaming Activity Data |
Service delivery, responsible gaming monitoring, game integrity |
Contract performance / Legitimate interest |
| Technical & Device Data |
Security, fraud detection, platform optimisation |
Legitimate interest |
| Communications Data |
Customer support, complaint handling, marketing (where opted in) |
Contract performance / Consent |
Section 03
How We Use Your Data
bdd333 uses the personal data it collects for the following clearly defined purposes. We do not use your data for any purpose not listed here without first obtaining your explicit consent.
- Account Administration: Creating, maintaining, and securing your bdd333 player account, including login verification, password reset procedures, and session management.
- Transaction Processing: Facilitating deposits and withdrawals through bKash, Nagad, Rocket, and Upay; reconciling transaction records; and resolving payment disputes.
- Identity Verification: Confirming that you meet the minimum age requirement of 18 years, verifying that the payment methods you use are registered in your own name, and complying with anti-money laundering (AML) obligations.
- Game Delivery: Transmitting your gameplay data to the relevant game studio (Pragmatic Play, Evolution Gaming, NetEnt, Microgaming, Spribe, Ezugi) to enable real-time game sessions and settle game outcomes accurately.
- Responsible Gaming: Monitoring your gaming patterns to detect early signs of problem gambling behaviour and to enforce any responsible gaming limits or self-exclusion periods you have set on your account.
- Fraud Prevention & Security: Analysing IP addresses, device fingerprints, and betting patterns to identify and prevent fraudulent activity, bonus abuse, multi-accounting, and unauthorised access attempts.
- Customer Support: Responding to account queries, technical issues, deposit/withdrawal problems, and formal complaints submitted through any support channel.
- Platform Improvement: Analysing aggregated, anonymised usage data to understand how players interact with the bdd333 interface and identify opportunities to improve navigation, game selection, and promotional offerings.
- Marketing Communications (Opt-In Only): Sending promotional emails or SMS messages about bonuses, new games, seasonal promotions (e.g., BPL season, Eid offers, Pohela Boishakh specials), and platform updates — only where you have provided explicit consent to receive such communications.
- Legal Compliance: Retaining records as required by applicable laws and responding to legitimate requests from law enforcement or regulatory authorities.
Section 04
Legal Basis for Processing
bdd333 processes personal data only where a valid legal basis exists. The four legal bases bdd333 relies upon are described below:
- Contract Performance: Processing is necessary to fulfil bdd333's obligations to you under the Terms & Conditions — for example, processing a withdrawal request or delivering a game session you have staked money on.
- Legal Obligation: Processing is required for bdd333 to comply with applicable legal requirements — for example, retaining KYC documents to satisfy anti-money laundering obligations or producing transaction records in response to a lawful authority request.
- Legitimate Interests: Processing serves bdd333's legitimate business interests where those interests are not overridden by your rights — for example, fraud detection, platform security monitoring, and aggregated analytics used to improve service quality.
- Consent: Processing is carried out on the basis of your freely given, specific, informed, and unambiguous consent — for example, sending you promotional marketing communications. You may withdraw consent at any time without detriment to your account status.
Withdrawing Consent: Where bdd333 processes your data on the basis of consent, you have the right to withdraw that consent at any time. Withdrawal of consent does not affect the lawfulness of processing carried out before the withdrawal. To withdraw marketing consent, use the unsubscribe link in any marketing communication or contact
[email protected].
Section 05
Data Sharing & Third Parties
bdd333 does not sell, rent, or trade your personal data to any third party for their own commercial purposes. Data is shared with third parties only in the following defined circumstances:
- Payment Providers: Transaction data is shared with bKash, Nagad, Rocket, and Upay as necessary to process deposits and withdrawals. Each provider operates under its own privacy policy and is independently responsible for data processed through its platform.
- Game Studios: Your player ID and real-time session data are transmitted to the relevant game studio (Pragmatic Play, Evolution Gaming, NetEnt, Microgaming, Spribe, Ezugi) to enable live game sessions. Studios use this data solely to deliver and settle the game session; they do not receive your full personal profile or financial transaction history.
- Identity Verification Services: Where automated KYC checking tools are used, KYC documents may be processed by a third-party identity verification provider operating under a strict data processing agreement with bdd333. Verified documents are not retained by the provider beyond the verification process.
- Fraud Prevention & Security Partners: Anonymised device fingerprint data and risk-scoring signals may be shared with specialist fraud prevention technology providers to protect the integrity of the bdd333 platform and all players on it.
- Law Enforcement & Regulatory Authorities: bdd333 will disclose personal data to law enforcement agencies, financial intelligence units, or other competent authorities where required to do so by a valid legal instrument (court order, statutory notice, or equivalent). bdd333 will not disclose data in response to informal or unverified requests.
- Business Transfers: In the event of a merger, acquisition, or sale of bdd333's business or assets, personal data held by bdd333 may form part of the transferred assets. Affected players will be notified in advance and given the opportunity to close their accounts and withdraw any available balance before the transfer completes.
All third-party processors who handle bdd333 player data on our behalf are contractually required to process that data only for the specified purpose, to maintain appropriate technical and organisational security measures, and to delete or return the data upon termination of the service agreement.
Section 06
Cookies & Tracking Technologies
bdd333 uses cookies and similar client-side storage technologies to support the technical operation of the platform, enhance your experience, and gather anonymised analytics data. The categories of cookies in use are described below:
- Strictly Necessary Cookies: Essential for the platform to function. These cookies manage your login session, maintain your account state during a game, and support security features such as CSRF protection. They cannot be disabled without breaking core platform functionality.
- Functional Cookies: Remember your preferences such as language setting and responsible gaming notification dismissal. These do not track activity across external sites.
- Analytics Cookies: Collect anonymised, aggregated data about how users interact with the bdd333 interface — pages visited, session durations, and navigation paths. This data is used exclusively for internal platform improvement and is not shared with advertising networks.
- Fraud Prevention Cookies: Store a device fingerprint token used to detect and flag suspicious login attempts, multi-account creation, and coordinated bonus abuse patterns. These are classified as strictly necessary for platform security.
No Third-Party Advertising Cookies: bdd333 does not deploy third-party advertising cookies, social media tracking pixels, or retargeting beacons. Your browsing activity on bdd333 is not shared with ad networks or social platforms.
You may manage cookie preferences through your browser settings. Note that disabling strictly necessary cookies will prevent you from logging in or playing games on the bdd333 platform. Analytics and functional cookies may be disabled without affecting core account functionality.
Section 07
Data Retention
bdd333 retains personal data only for as long as is necessary to fulfil the purpose for which it was collected, or as required by applicable legal and regulatory obligations. The retention periods applicable to each category of data are summarised below:
| Data Category |
Retention Period |
Reason |
| Account registration data |
Duration of account + 5 years after closure |
AML / fraud investigation obligations |
| KYC identity documents |
Duration of account + 5 years after closure |
Regulatory compliance, dispute resolution |
| Financial transaction records |
Duration of account + 7 years after closure |
Financial record-keeping requirements |
| Gaming activity logs |
Duration of account + 3 years after closure |
Game integrity, dispute resolution |
| Support & communications records |
3 years from last interaction |
Complaint handling, quality assurance |
| Marketing consent records |
Until consent withdrawn + 2 years |
Evidence of consent, regulatory audit |
| Technical / device logs |
13 months on a rolling basis |
Security analysis, fraud detection |
Upon expiry of the applicable retention period, personal data is securely deleted or anonymised so that it can no longer be attributed to an identifiable individual. Anonymised, aggregated data may be retained indefinitely for statistical and business intelligence purposes.
Section 08
Data Security
bdd333 implements a layered set of technical and organisational measures to protect your personal data against unauthorised access, accidental loss, destruction, alteration, and disclosure. Key security measures in place include:
- Transport Layer Encryption: All data transmitted between your device and bdd333's servers uses TLS 1.2 or higher, preventing interception of data in transit.
- Password Security: Player passwords are stored exclusively as one-way cryptographic hashes using industry-standard algorithms. Plain-text passwords are never stored or logged anywhere within bdd333's infrastructure.
- Access Controls: Access to production data systems is restricted to authorised personnel on a strict need-to-know basis. All internal access events are logged and subject to periodic audit review.
- Two-Factor Authentication (2FA): Players are strongly encouraged to enable 2FA on their bdd333 accounts. All internal administrative accounts accessing player data systems are required to use 2FA.
- Intrusion Detection: bdd333's infrastructure is monitored continuously for anomalous access patterns, brute-force login attempts, and unusual data export activity.
- Third-Party Processor Vetting: All processors who handle bdd333 player data are assessed for security maturity prior to engagement and are contractually required to maintain equivalent data protection standards.
Despite these measures, no digital platform can guarantee absolute security. In the event of a data breach that is likely to result in a risk to your rights or interests, bdd333 will notify affected players promptly and take all reasonable steps to contain the breach, assess its impact, and prevent recurrence. If you believe your bdd333 account has been compromised, contact [email protected] immediately.
Section 09
Your Rights
As a bdd333 player, you hold the following rights in relation to your personal data. To exercise any of these rights, submit a written request to [email protected] with the subject line "Data Rights Request". We will verify your identity before processing any request and will respond within 10 business days.
Right of Access
Request a copy of all personal data bdd333 holds about you, including the categories of data, the purposes of processing, and details of any third-party recipients.
Right to Rectification
Request correction of any inaccurate or incomplete personal data held in your bdd333 account. You may update basic account details directly through your account settings panel.
Right to Erasure
Request permanent deletion of your personal data where bdd333 no longer has a legitimate or legal reason to retain it. Note that certain data must be retained to satisfy AML and financial record-keeping obligations.
Right to Restriction
Request that bdd333 temporarily restrict processing of your data — for example, while an accuracy dispute is being investigated — without requiring full deletion.
Right to Portability
Request a copy of your personal data in a structured, commonly used, machine-readable format so that it can be transferred to another service provider of your choice.
Right to Object
Object to processing of your personal data carried out on the basis of legitimate interests, including profiling. bdd333 will cease such processing unless it can demonstrate compelling legitimate grounds that override your objection.
Section 10
Children's Privacy
bdd333 is strictly an adults-only platform. No person under the age of 18 is permitted to register an account, access any gaming content, or make any financial transaction on the bdd333 platform. bdd333 does not knowingly collect personal data from individuals under 18 years of age.
Where bdd333 becomes aware — through the KYC verification process, player reports, or internal detection systems — that an account has been registered by or is being used by a person under 18, the account will be immediately and permanently closed. Any deposits made on that account will be returned to the originating payment method; any wagering activity and associated winnings will be voided in their entirety.
Parental Controls: If you are a parent or guardian and believe that a minor in your care has registered a bdd333 account without your knowledge, please contact us immediately at
[email protected]. We will investigate promptly and close the account. We also recommend using device-level parental control software to restrict access to online gambling platforms. 18+ only.
Section 11
Changes to This Privacy Policy
b
dd333 reserves the right to update or amend this Privacy Policy at any time to reflect changes in applicable law, platform functionality, data processing practices, or industry best practices. When material changes are made to this Policy, bdd333 will notify registered players by email to the address associated with their account, or by displaying a prominent in-platform notification upon their next login, no less than 14 days before the changes take effect.
Minor, non-material changes (such as typographical corrections, clarification of existing language, or updated contact details) may be made without prior notice. The "Last Updated" date displayed at the top of this Policy and in the Table of Contents sidebar will always reflect the date on which the most recent revision was published.
Your continued use of the bdd333 platform following the effective date of any revised Privacy Policy constitutes your acceptance of the updated terms. If you do not agree with the revised Policy, you should cease using the platform and close your account before the new Policy takes effect. Outstanding balances may be withdrawn prior to account closure.
Section 12
Contact & Complaints
If you have any questions about this Privacy Policy, wish to exercise any of your data rights, or have a concern about how bdd333 has handled your personal data, please contact our support team using the details below. All privacy-related enquiries are handled by bdd333's designated data protection contact.
- Email: [email protected] — use subject line "Privacy Enquiry" or "Data Rights Request" for fastest routing.
- Response Time: bdd333 aims to acknowledge all privacy enquiries within 24 hours and to provide a substantive response within 10 business days.
- Operating Hours: Support is available 24 hours a day, 7 days a week, 365 days a year — including Bangladesh public holidays.
- Escalation: If you are not satisfied with bdd333's response to a privacy complaint, you may escalate the matter to the relevant data protection supervisory authority in your jurisdiction.
Responsible Gaming Note: If your privacy enquiry is connected to a request for account closure under our Responsible Gaming programme (self-exclusion, cooling-off period, or permanent closure), please indicate this clearly in your message. Responsible Gaming requests receive priority handling and are processed separately from standard privacy enquiries. Visit our
Responsible Gaming page for full details. 18+ only.