` Yo88 - Link Tải Yo88 Tài Xỉu Chính Thức 2026
GAME BÀI ĐẲNG CẤP

Privacy and Personal Data Protection Policy

1. Overview

Ventures Lab Malta Limited (the "Company", "we", "our", or "us") recognises the importance of protecting the privacy and personal information of its customers. This Privacy and Personal Data Protection Policy ("Policy") explains how Personal Data is collected, used, disclosed, stored, and otherwise processed when individuals access or use the Company's gaming products, websites, mobile applications, and associated services (collectively, the "Services").

The Company is committed to processing Personal Data responsibly and in accordance with applicable data protection legislation and regulatory obligations.

2. Legal and Regulatory Compliance

The Company processes Personal Data in accordance with applicable European Union and Maltese legislation, including:

  • Regulation (EU) 2016/679 (General Data Protection Regulation – GDPR);
  • the Malta Data Protection Act (Chapter 586 of the Laws of Malta);
  • applicable guidance issued by the Office of the Information and Data Protection Commissioner (IDPC);
  • obligations arising under the Malta Gaming Authority ("MGA") regulatory framework, including player protection, responsible gaming, and anti-money laundering requirements.

This Policy applies to all Personal Data processed by the Company in connection with its Services.

3. Data Controller

Ventures Lab Malta Limited is the Data Controller responsible for determining how and why Personal Data is processed.

Registered Office

Quad Central, Q3, Level 1, Office 5

Triq l-Esportaturi

Birkirkara, Malta

Company Registration Number: C 89206

Data Protection Officer

Email: dpo@yo88.dad

The Company has implemented governance measures to ensure compliance with data protection obligations. The Data Protection Officer oversees privacy compliance, supports internal awareness initiatives, monitors regulatory developments, and acts as the principal contact for data protection matters.

4. Types of Personal Data We Process

The Company may collect and process different categories of Personal Data depending on the services used.

These categories include:

Identity Information

  • name;
  • date of birth;
  • nationality;
  • gender;
  • identification document details.

Verification Information

  • copies of identity documents;
  • proof of residential address;
  • source of funds or source of wealth documentation where required.

Contact Information

  • postal address;
  • email address;
  • telephone number.

Account Information

  • username;
  • account preferences;
  • gaming history;
  • betting activity;
  • account limits;
  • account balances.

Payment Information

  • payment methods;
  • deposits;
  • withdrawals;
  • transaction history.

Technical Information

  • IP address;
  • browser type;
  • operating system;
  • device identifiers;
  • geolocation data where applicable;
  • website and application usage information.

Customer Service Information

  • customer support enquiries;
  • complaint records;
  • responsible gaming interactions;
  • communications relating to regulatory compliance.

Where particularly sensitive information is processed, additional organisational and technical safeguards are applied.

5. Purposes for Processing

The Company processes Personal Data for legitimate operational, contractual, and regulatory purposes, including:

  • establishing and managing customer accounts;
  • verifying customer identity and eligibility;
  • providing gaming and betting services;
  • processing financial transactions;
  • complying with anti-money laundering and customer due diligence obligations;
  • preventing fraud and other unlawful activity;
  • monitoring responsible gaming obligations;
  • responding to customer enquiries;
  • improving the quality and security of the Services;
  • complying with legal and regulatory reporting obligations.

Personal Data is not processed for purposes incompatible with those for which it was originally collected.

6. Legal Bases for Processing

The Company processes Personal Data only where one or more lawful bases under the GDPR apply.

Depending on the circumstances, processing may be necessary:

  • to perform a contract entered into with the customer;
  • to comply with statutory or regulatory obligations;
  • to pursue the Company's legitimate interests, provided those interests do not override the rights and freedoms of the individual; or
  • on the basis of the individual's consent where required by applicable law.

Where processing relies upon consent, that consent may be withdrawn at any time without affecting previous lawful processing.

7. Disclosure of Personal Data

The Company may disclose Personal Data where this is necessary for the provision of services, regulatory compliance, or legitimate business operations.

Recipients may include:

  • payment service providers;
  • financial institutions;
  • customer verification providers;
  • anti-money laundering service providers;
  • cloud hosting and technology providers;
  • cybersecurity service providers;
  • legal advisers and auditors;
  • compliance consultants;
  • the Malta Gaming Authority;
  • the Financial Intelligence Analysis Unit (FIAU);
  • courts, regulators, and competent authorities where disclosure is required by law.

The Company does not sell Personal Data to third parties.

8. International Transfers

Where Personal Data is transferred outside the European Economic Area ("EEA"), the Company ensures that appropriate safeguards are implemented before any transfer takes place.

These safeguards may include:

  • adequacy decisions adopted by the European Commission;
  • Standard Contractual Clauses;
  • other legally recognised transfer mechanisms under the GDPR.

9. Data Retention

Personal Data is retained only for as long as necessary to fulfil legal, contractual, and operational purposes.

Retention periods may vary depending on the category of information processed.

In particular:

  • AML, KYC, and regulatory records are retained for a minimum of five (5) years following the end of the customer relationship, unless a longer period is required by law;
  • transaction records are retained to satisfy legal, accounting, and regulatory obligations;
  • information that is no longer required is securely deleted, anonymised, or destroyed.

10. Security of Personal Data

The Company maintains a comprehensive information security framework designed to safeguard Personal Data against accidental loss, unauthorised access, misuse, alteration, or disclosure.

Security measures include:

  • encryption of sensitive information;
  • role-based access controls;
  • multi-factor authentication where appropriate;
  • network and infrastructure monitoring;
  • secure backup procedures;
  • vulnerability management;
  • regular employee awareness and security training.

Security controls are reviewed periodically to ensure their continued effectiveness.

11. Individual Rights

Subject to applicable legal requirements, individuals have the right to:

  • obtain confirmation that their Personal Data is being processed;
  • access their Personal Data;
  • request correction of inaccurate or incomplete information;
  • request deletion of Personal Data where legally permissible;
  • request restriction of processing;
  • object to certain processing activities;
  • receive Personal Data in a portable format where applicable; and
  • withdraw consent where processing is based upon consent.

Requests may be submitted to the Company's Data Protection Officer.

Individuals may also lodge a complaint with the Office of the Information and Data Protection Commissioner (IDPC) if they believe their rights have been infringed.

12. Data Breach Response

The Company maintains documented procedures for identifying, investigating, managing, and recording Personal Data breaches.

Where required by applicable legislation, the Company will:

  • contain and assess the incident;
  • implement corrective measures;
  • notify the competent supervisory authority within the applicable legal timeframe;
  • notify affected individuals where the breach presents a high risk to their rights and freedoms; and
  • retain records of all reportable incidents for regulatory purposes.

13. Children's Privacy

The Company's Services are intended exclusively for persons aged eighteen (18) years or older.

Age verification measures are incorporated into customer onboarding procedures. Where the Company becomes aware that Personal Data belonging to an individual below the minimum legal age has been collected, appropriate steps will be taken to terminate the account and delete the information where permitted by law.

14. Cookies and Similar Technologies

The Company uses cookies and comparable technologies to support the operation of its Services.

These technologies may be used to:

  • maintain website functionality;
  • remember customer preferences;
  • improve system performance;
  • analyse traffic and usage patterns;
  • strengthen fraud prevention controls; and
  • enhance user experience.

Where required by applicable legislation, users are provided with options to manage their cookie preferences before non-essential cookies are deployed.

15. Policy Governance

The Company periodically reviews this Policy to ensure that it remains consistent with changes in legislation, regulatory expectations, business operations, and technological developments.

Material amendments may be implemented without prior notice where necessary to maintain legal or regulatory compliance. The current version of the Policy will be published on the Company's official website.

16. Governing Law

This Policy shall be governed by and interpreted in accordance with the laws of Malta, including the General Data Protection Regulation (EU) 2016/679, the Malta Data Protection Act, and any applicable regulatory requirements issued by the Malta Gaming Authority and other competent supervisory authorities.