1w Privacy Policy
This Privacy Policy explains how personal data is collected, used, retained, shared, and transferred for 1w online services in Europe. The document covers websites, mobile applications, and related platforms where users register accounts, place bets, play casino content, and contact support channels. The policy describes data protection practices aligned with GDPR requirements for European Economic Area residents and similar regulations in other territories. The full text comprises approximately 1,500 words divided into thirteen sections that detail categories of information collected, legal grounds for processing, retention periods after account closure, international transfer safeguards, and user rights over stored records.
- How Personal Data is Collected and Protected
- Accessing and Managing Your Personal Information
- How Collected Information is Used
- Protection of Minors
- Transfer of Personal Data Outside Ireland
- Legal Disclaimer
- Use of Cookies
- Acceptance of This Privacy Policy
- Sharing Personal Data with Third Parties
- External Website Links
- FAQ
How Personal Data is Collected and Protected
This section explains where personal information originates, which categories the company records, how technical logs capture activity, and how long stored records remain active. The overview covers collection sources, data types, logging mechanisms, and retention timelines that apply to user accounts.
Sources of personal data
The platform gathers information through multiple channels during registration, account use, and service delivery. Data enters the system when users interact with websites, apps, payment processors, verification providers, and support teams.
- Registration forms collect full name, date of birth, email address, phone number, and residence details when users open accounts;
- Profile update screens record changes to contact information, preferences, currency selection, and responsible gaming limits;
- Account activity logs capture login timestamps, IP addresses, device identifiers, browser type, and session duration;
- Payment transactions add card details, wallet identifiers, deposit amounts, withdrawal requests, and transaction confirmation codes;
- Support contacts generate email records, chat transcripts, complaint descriptions, and resolution notes;
- Verification partners provide identity check results, age confirmation data, and document validation statuses;
- Community forums store usernames, post content, comment history, and interaction timestamps.
Categories of personal data
The policy organizes collected information into seven main categories that cover registration, transactions, device use, and communication with support. Each category contains specific data points that enable account management and service delivery.
| Category | Description | Examples |
|---|---|---|
| Identity | Full legal name, date of birth, nationality, address | Passport number, ID card number |
| Contact | Email, phone number, postal address | Mobile number, residential street address |
| Account | Username, password hash, account settings | Security questions, responsible gaming limits |
| Financial | Payment card details, transaction records, deposit amounts | Credit card last four digits, withdrawal history |
| Technical | IP address, browser type, operating system | Device identifier, screen resolution |
| Activity | Login timestamps, page views, bet history | Game session duration, visited sections |
| Communication | Support ticket content, email exchanges | Chat transcripts, complaint records |
Technical logs and device data
Automated systems capture technical information each time a user accesses services or opens an account. The records support security monitoring, fraud detection, and technical troubleshooting across all platforms:
- IP address collected at login and transaction confirmation;
- Device identifiers such as hardware model and operating system version;
- Browser type and version captured during session initialization;
- Operating system data including patch level and build number;
- Access timestamps recorded in UTC for each page request;
- Language preference retrieved from browser settings;
- Approximate geographic location derived from network routing data;
- Error logs documenting connection failures and application crashes.
Data retention and account closure
Active accounts maintain personal information records for the duration of the account relationship. Records remain stored for five years after an account closes to satisfy regulatory obligations across multiple jurisdictions. The company applies this retention period to all user categories and transaction histories. Financial authorities and licensing bodies require operators to keep withdrawal, deposit, and verification documents accessible during audits and investigations. After the five-year period expires, the system deletes or anonymizes all personal data that no longer serves a legal purpose. Forum posts and community contributions may persist longer to preserve discussion continuity and moderation records. Anonymization removes direct identifiers from these records so the content remains visible but cannot link back to the original account holder.
Accessing and Managing Your Personal Information
Users hold the right to exercise data protection controls through account settings and support requests. The platform allows adjustment of certain preferences and storage choices. Contact channels accept requests to access, correct, or delete stored records under applicable rules.
User rights over personal data
The privacy framework grants registered account holders several control options over stored information. Each right serves a distinct function related to transparency and autonomy:
- Access – Users can request copies of stored information and obtain confirmation of processing activities;
- Rectification – Incorrect or incomplete entries can be corrected through a verification process;
- Deletion – Removal of records takes place when no regulatory or contractual obligation requires retention;
- Restriction – Processing can be limited during dispute resolution or verification periods;
- Portability – Structured account and transaction data can be exported in machine-readable format;
- Objection – Users can oppose processing based on legitimate interests or direct marketing;
- Consent withdrawal – Previously granted permissions can be revoked at any time;
- Complaint to a supervisory authority – Data protection regulators accept formal complaints about non‑compliance.
Contact channels for privacy requests
Users submit privacy requests through several channels offered by the company. The table below lists the main options, typical use scenarios, and basic verification steps.
| Contact Type | Typical Use Case | Basic Verification Requirement |
|---|---|---|
| Dedicated email | Data access requests and deletion requests | Full name and registered email address |
| In‑account request forms | Correction of account details and preference updates | Active login session |
| General support | Privacy questions and complaint submission | Account number and personal identification |
| Forum or community contacts | Community data concerns | Forum username and registration proof |
| Messaging channels | Quick inquiries and initial privacy guidance | Registered phone number or username |
Mobile app and software privacy specifics
Mobile applications and desktop software handle data under the same privacy framework that governs website operations. The policy applies to all versions of the apk and client programs distributed through official channels.
- Device identifiers collected include hardware serial numbers, advertising IDs, and operating system versions to enable secure authentication and fraud detection;
- App usage statistics track session duration, screen interactions, and feature activation to improve interface design and resolve technical errors;
- Notification permissions requested allow delivery of account alerts, security warnings, and responsible gaming reminders directly to user devices;
- Secure payment processing inside 1w apps relies on SSL and TLS encryption protocols to protect card numbers, wallet credentials, and transaction amounts;
- In‑app preference controls permit users to adjust language, currency, notification frequency, and responsible gaming limits without contacting support;
- Links to the policy appear in app settings menus and during first launch to ensure transparency about data handling practices.
How Collected Information is Used
This section sets out the legal grounds and purposes for processing personal data. The processing covers account operation, payment execution, identity verification, and service improvement activities across the 1w environment.
Legal bases for processing
The company relies on multiple legal grounds to process personal data of users. Each processing activity connects to one or more legal bases recognized under GDPR and related data protection frameworks:
- Consent. Users provide explicit agreement during registration and opt-in actions for marketing communications and cookie placement;
- Performance of a contract. Account creation, transaction execution, withdrawal processing, and service delivery require data handling to fulfill agreements with users;
- Legal obligations. Anti-money laundering checks, age verification, tax reporting, and regulatory audits mandate certain data operations;
- Legitimate interests. Fraud prevention, security monitoring, system optimization, and customer support improvement justify data use where no overriding user rights exist;
- Vital interests. Emergency situations involving user safety or public health can trigger limited data processing.
Purposes of processing
Personal data undergoes processing to deliver services, maintain security, and meet legal requirements. The following overview shows how 1w uses collected information across seven main functions.
| Purpose | Example operations | Related data categories |
|---|---|---|
| Account creation | Registration validation, profile setup, eligibility checks | Full name, date of birth, address, email, phone number |
| Access management | Login verification, session control, password recovery | Username, IP address, device identifiers, authentication tokens |
| Payments | Deposit processing, withdrawal execution, currency conversion | Payment card details, transaction history, billing address, amounts |
| Fraud control | Identity verification, KYC procedures, suspicious activity detection | Government ID, address proof, transaction patterns, device fingerprints |
| Communication | Service updates, account notifications, support responses | Email address, phone number, contact preferences, support ticket history |
| Analytics | Traffic measurement, feature usage tracking, performance optimization | Page views, click patterns, session duration, browser type, screen resolution |
| Dispute handling | Complaint investigation, regulatory reporting, evidence preservation | Correspondence records, bet history, account activity logs, transaction receipts |
Protection of Minors
The minimum age requirement stands at 18 years for account registration and service use. Basic age verification steps include date-of-birth submission during sign-up and document checks at withdrawal stages. The company reviews accounts suspected of belonging to individuals under 18 through manual verification protocols and automated flag systems. Accounts confirmed as minor-owned face immediate suspension and permanent restriction. Personal data linked to detected minor accounts gets removed from active databases within 30 days or restricted from further processing under legal retention obligations. Parental contact details help resolve underage access incidents where needed.
Transfer of Personal Data Outside Ireland
The company transfers certain records to jurisdictions beyond Ireland and the European Economic Area to deliver services, process transactions, and fulfill regulatory requirements. Recipients can include payment processors, hosting providers, and regulatory authorities located in countries that lack adequacy decisions from the European Commission.
The following framework governs cross-border data movements:
- Standard Contractual Clauses apply to transfers toward countries without adequacy status, which secures equivalent protection levels mandated by GDPR;
- Payment processors and banks receive transaction details and financial identifiers to complete deposits, withdrawals, and fraud checks in their home jurisdictions;
- Hosting and cloud providers store encrypted account records, login logs, and technical metadata on servers located outside the EEA;
- Regulatory authorities obtain identity verification documents, transaction histories, and responsible gaming flags to satisfy anti-money-laundering and licensing obligations;
- Group companies access user profiles, activity summaries, and support correspondence to coordinate account administration across affiliated entities;
- Users can request copies of the applicable Standard Contractual Clauses and transfer impact assessments by submitting a written inquiry to the designated privacy contact address listed in the policy.
Legal Disclaimer
The Privacy Policy does not replace or override mandatory statutory provisions that apply in each user’s jurisdiction. Each updated version of the document replaces all previous editions automatically upon publication. The version date shown at the top of the policy indicates when the current text became effective. Discrepancies between different language translations resolve according to the primary reference text specified in the document header. Users should check the version date regularly to confirm the most recent rules.
Use of Cookies
The website relies on cookies, device identifiers, and similar technical tools to support essential functions. These technologies store preferences, collect analytics data, and detect fraudulent activities. Tracking mechanisms help maintain security standards and improve service delivery for registered accounts.
Cookie types and purposes
The platform uses several categories of technical tools to deliver services and protect accounts. Detailed information about each type, storage practices, and control options appears below.
| Type | Purpose | Typical data stored | How to manage or disable |
|---|---|---|---|
| Strictly necessary | Account authentication and session continuity | Session tokens, login timestamps, account identifiers | Cannot be disabled without losing access to services |
| Preference | Language selection and display settings | Language code, currency preference, interface theme | Clear through browser settings or account dashboard |
| Analytics | Performance measurement and error detection | Page views, click patterns, device type, visit duration | Opt out via browser privacy controls or dedicated analytics blockers |
| Security and fraud | Detection of suspicious login attempts and transaction anomalies | IP address, device fingerprint, access frequency, transaction patterns | Managed automatically; manual disabling weakens account protection |
| Marketing | Delivery of promotional messages and targeted offers | Campaign identifiers, referral source, bonus history | Adjust communication preferences in account settings or unsubscribe links |
Acceptance of This Privacy Policy
Account registration and use of services indicate acceptance of this Privacy Policy. Users agree to data practices described in the document when creating accounts or accessing features. Continued use after changes signals continued acceptance of updated terms. The company posts revisions with a revised date at the top of the policy page. Users should review updates regularly to stay informed about data handling practices. Disagreement with updated terms requires discontinuation of service use and account closure through support channels.
Sharing Personal Data with Third Parties
The company can share collected information with carefully selected service providers and group entities for specific operational purposes. Personal data never gets sold to external marketing organizations or third-party advertisers under this privacy framework.
Types of recipients
The operator shares user data with several distinct categories of external organizations and internal departments to deliver services and meet legal obligations.
- Internal group companies receive account and financial records to manage unified administration and consolidated reporting;
- Hosting and IT providers store databases, maintain servers, and deliver technical infrastructure for websites and applications;
- Payment institutions process deposits, withdrawals, and currency conversions across multiple channels;
- Verification and analytics services confirm user identity, detect fraud, and generate usage statistics;
- Affiliates access referral data to track conversions and manage partnership agreements;
- Regulators and law enforcement obtain records under statutory obligations and official investigation requests.
Data sharing scenarios
Personal data moves to third parties during payment processing, which covers deposits, withdrawals, and account reconciliation. Verification checks pass information to identity confirmation partners. Technical maintenance requires hosting and infrastructure providers to access system logs. Customer support tools route conversation records to ticketing platforms. Law enforcement and regulators receive data under lawful requests. Corporate restructuring events transfer records to successor entities. Every sharing arrangement follows contractual confidentiality clauses. Data use limits restrict recipients to specific purposes. Agreements prevent unauthorized secondary distribution. Recipients handle information under the same protection standards that govern initial collection and storage.
External Website Links
Services can contain direct hyperlinks and technical integrations to third-party domains and applications. Each external destination operates under separate terms and distinct privacy regulations. 1w Europe bears no responsibility for data collection, storage, or processing performed outside controlled infrastructure. Users should locate and review the privacy statements of destination platforms before submitting registration forms, contact details, payment credentials, or identity documents. Protection standards vary across operators and jurisdictions. Reading third-party policies helps users understand what information those entities collect, how long records remain stored, and what sharing arrangements exist with additional parties.