gc22 Privacy Policy
Your privacy matters to gc22. This Privacy Policy explains exactly what personal data we collect from registered players in Bangladesh, how we use it, who we share it with, and how you can exercise control over your own information at any time.
How gc22 Handles Your Data
These cards summarise the most important points of the gc22 Privacy Policy. They are provided for convenience and do not replace the full legal text further down this page.
Data We Collect
gc22 collects only the personal data necessary to operate your account, verify your identity, process BDT deposits and withdrawals, and comply with applicable anti-money laundering obligations. We do not collect data we have no use for.
How We Protect It
All data stored and transmitted through gc22 is protected by 256-bit SSL encryption. Access to personal data within gc22 is restricted to authorised personnel on a strict need-to-know basis. We do not sell personal data to third parties.
Who We Share It With
gc22 shares personal data only with the payment processors (bKash, Nagad, Rocket, Upay, partner banks), game studios, and identity verification providers necessary to operate the platform. We do not share data with advertisers or data brokers.
Your Control
You have the right to access, correct, and request deletion of your personal data held by gc22. These requests can be submitted at any time by contacting our support team at [email protected]. We respond to all data requests within 30 days.
Cookies & Tracking
gc22 uses strictly necessary session cookies to keep you logged in, and analytics cookies to improve platform performance. We do not use advertising or cross-site tracking cookies. You can manage cookie preferences through your browser settings.
Data Retention
gc22 retains personal data for as long as your account is active and for a minimum of five years after account closure to comply with financial record-keeping and anti-money laundering obligations under applicable regulations. Specific retention periods are detailed in the full policy below.
1. Introduction
This Privacy Policy ("Policy") describes how gc22 ("gc22", "we", "us", or "our"), the operator of the online casino and sports betting platform at gc22.io, collects, processes, stores, and discloses personal data relating to individuals ("you" or "your") who access or use the gc22 platform, including its website, account management tools, games, betting markets, and customer support services.
gc22 takes the privacy of its players seriously. This Policy is written in formal English and is intended to give you a clear and complete picture of how your personal data is handled. By registering an account with gc22 or by continuing to use the gc22 platform after this Policy has been published, you acknowledge that you have read and understood the terms set out herein.
This Policy should be read alongside the gc22 Terms & Conditions, which govern the overall relationship between you and gc22. Defined terms used but not defined in this Policy have the meanings given to them in the gc22 Terms & Conditions.
2. Personal Data We Collect
gc22 collects personal data in three principal ways: (a) information you provide directly to us; (b) information generated automatically by your use of the platform; and (c) information obtained from third-party service providers such as payment processors and identity verification agencies.
Information you provide directly:
- Full legal name, date of birth, and residential address (collected during registration and KYC verification).
- Mobile phone number and email address used to create and manage your gc22 account.
- Government-issued identity document details (national ID card number, passport number) submitted during KYC verification.
- Payment method details, including mobile wallet numbers (bKash, Nagad, Rocket, Upay) and bank account identifiers used for deposits and withdrawals.
- Communications you send to gc22 support via live chat or email, including the content of those messages.
- Responsible gaming preferences, such as deposit limits or self-exclusion requests, that you set through your account dashboard.
Information collected automatically:
- IP address, device type, operating system, and browser type collected when you access the gc22 platform.
- Session data including login timestamps, session duration, pages visited, and games or betting markets accessed.
- Betting and gaming history, including stakes placed, outcomes, and account balance changes.
- Cookie identifiers and similar tracking technologies as described in Section 6 of this Policy.
Information from third parties:
- Identity verification outcomes from KYC service providers, including confirmation or rejection of identity documents.
- Transaction confirmation data from payment processors including bKash, Nagad, Rocket, Upay, Dutch-Bangla Bank, City Bank, BRAC Bank, Islami Bank, and Sonali Bank.
- Fraud screening and anti-money laundering flags generated by our compliance service partners.
| Data Category | Examples | Source |
|---|---|---|
| Identity Data | Full name, date of birth, NID number | You / KYC provider |
| Contact Data | Email address, mobile number | You |
| Financial Data | bKash/Nagad wallet number, bank account ID | You / Payment processor |
| Technical Data | IP address, device type, browser | Automatically collected |
| Usage Data | Betting history, session logs, game activity | Automatically collected |
| Communications Data | Support chat transcripts, email correspondence | You |
| Compliance Data | AML flags, fraud screening results | Third-party compliance partners |
3. How We Use Your Personal Data
gc22 uses personal data only for specific, documented purposes. We do not use personal data for any purpose incompatible with those listed below without first obtaining your explicit consent or as otherwise required by law.
- Account creation and management: To register your gc22 account, verify your identity and age (21+ requirement), maintain your account, and communicate essential account information to you.
- Transaction processing: To process deposits and withdrawals via bKash, Nagad, Rocket, Upay, and partner banks in Bangladeshi Taka, and to maintain accurate financial records of all transactions.
- KYC and anti-money laundering compliance: To verify the identity of players, check against sanctions lists, and fulfil anti-money laundering obligations including source-of-funds checks where applicable.
- Platform security: To detect, prevent, and investigate fraudulent activity, Prohibited Conduct, account takeover attempts, and other security incidents affecting the gc22 platform or its players.
- Customer support: To respond to your enquiries, complaints, and responsible gaming requests, and to maintain a record of support interactions for quality assurance purposes.
- Responsible gaming: To administer deposit limits, cooling-off periods, and self-exclusion tools that you activate, and to monitor account activity for indicators of problem gambling where gc22 has a duty of care obligation.
- Platform improvement: To analyse aggregated usage data (anonymised where possible) in order to improve game selection, platform performance, and user experience for Bangladeshi players.
- Legal and regulatory compliance: To comply with applicable laws, respond to lawful requests from authorities, and enforce the gc22 Terms & Conditions.
- Marketing communications (with consent only): To send you promotional offers, bonus notifications, and seasonal campaign information via SMS or email, but only if you have explicitly opted in to marketing communications. You may withdraw consent at any time via your account dashboard or by contacting support.
4. Legal Basis for Processing
gc22 processes personal data on the following legal grounds, depending on the category of data and the purpose of processing:
- Contractual necessity: Processing required to perform the contract between you and gc22 — including account registration, transaction processing, and customer support — is carried out on the basis that it is necessary to fulfil our contractual obligations to you.
- Legal obligation: Processing required to comply with applicable anti-money laundering, counter-terrorism financing, and financial record-keeping obligations is carried out on the basis of legal compliance necessity.
- Legitimate interests: Processing for platform security, fraud prevention, responsible gaming monitoring, and platform analytics is carried out on the basis of gc22's legitimate interest in operating a safe, fair, and sustainable platform, provided that interest is not overridden by your fundamental data protection rights.
- Consent: Processing for marketing communications is carried out solely on the basis of your explicit, freely given, and revocable consent. Withdrawing consent does not affect the lawfulness of processing carried out before withdrawal.
5. Sharing Your Personal Data
gc22 does not sell, rent, or trade personal data to third parties for their own commercial purposes. Personal data is shared only in the circumstances described below, and only to the extent necessary for the stated purpose.
- Payment processors: gc22 shares financial data (wallet numbers, transaction amounts, account identifiers) with payment providers including bKash, Nagad, Rocket, Upay, Dutch-Bangla Bank, City Bank, BRAC Bank, Islami Bank, and Sonali Bank, solely to execute deposit and withdrawal transactions.
- Identity verification providers: gc22 shares identity document data with KYC and age-verification service providers to fulfil account verification requirements. These providers are contractually bound to handle data confidentially and are prohibited from using it for any other purpose.
- Game studio providers: gc22 shares a pseudonymous player identifier (not your full name or contact details) with game studio providers including Evolution Gaming, Ezugi, Pragmatic Play, NetEnt, Microgaming, Play'n GO, and Spribe, solely to facilitate game session management and dispute resolution.
- Compliance and fraud screening partners: gc22 shares data with anti-money laundering and fraud screening service providers as required to fulfil compliance obligations. These providers operate under strict data processing agreements with gc22.
- Legal and regulatory authorities: gc22 will disclose personal data to law enforcement agencies, courts, or regulatory bodies where required to do so by a lawful order, legal process, or applicable regulation. gc22 will, where legally permitted, notify you of such disclosure requests.
- Business transfers: In the event of a merger, acquisition, or sale of all or substantially all of gc22's assets, personal data held by gc22 may be transferred to the acquiring entity. You will be notified of any such transfer that materially affects your rights under this Policy.
6. Cookies & Similar Technologies
gc22 uses cookies and similar browser-based storage technologies on the gc22 platform. Cookies are small text files stored on your device that help the platform function correctly, maintain your session, and generate performance analytics.
gc22 uses the following categories of cookies:
- Strictly necessary cookies: Required for the platform to function. These include session authentication cookies that keep you logged in during a single browsing session, CSRF protection tokens, and load-balancing cookies. These cookies cannot be disabled without breaking core platform functionality.
- Functional cookies: Used to remember preferences you have set, such as your language preference or responsible gaming settings. Disabling these cookies may affect your experience but will not prevent you from accessing the platform.
- Analytics cookies: Used to collect anonymised data about how players navigate and use the gc22 platform, including which pages and games are visited most frequently. This data is used solely to improve platform performance and user experience. Analytics data is aggregated and does not identify individual players.
gc22 does not use advertising cookies, cross-site tracking cookies, or any cookies that share your data with third-party advertising networks.
You can manage or disable non-essential cookies through your browser settings. Instructions for managing cookies are available in the help documentation for all major browsers. Please note that disabling cookies may affect your ability to use certain features of the gc22 platform, including staying logged in between sessions.
7. Data Retention
gc22 retains personal data for no longer than is necessary for the purposes for which it was collected, subject to the minimum retention periods required by applicable anti-money laundering and financial record-keeping obligations.
| Data Category | Retention Period | Reason |
|---|---|---|
| Account & Identity Data | Duration of account + 5 years post-closure | AML compliance & dispute resolution |
| Transaction Records | 5 years from transaction date | Financial record-keeping obligations |
| KYC Documents | 5 years post account closure | Identity verification audit trail |
| Support Communications | 3 years from last interaction | Quality assurance & dispute evidence |
| Technical / Session Logs | 13 months from collection | Security monitoring & analytics |
| Marketing Consent Records | Duration of consent + 3 years | Consent audit trail |
Upon expiry of the applicable retention period, personal data is securely deleted or anonymised such that it can no longer be attributed to an identifiable individual. Anonymised or aggregated data may be retained indefinitely for statistical and analytical purposes without further notice.
8. Data Security
gc22 implements a range of technical and organisational measures to protect personal data against unauthorised access, accidental loss, destruction, or alteration. These measures include but are not limited to:
- 256-bit SSL/TLS encryption applied to all data in transit between your device and gc22 servers.
- Encryption at rest for sensitive data categories including identity documents, financial data, and authentication credentials stored on gc22 servers.
- Role-based access controls restricting access to personal data within gc22 to authorised personnel who have a documented operational need to access it.
- Two-factor authentication for all gc22 internal systems that contain personal data, and offered as an optional security feature to all registered players.
- Regular security assessments of the gc22 platform and its supporting infrastructure to identify and remediate vulnerabilities.
- Incident response procedures that require gc22 to investigate and respond to suspected data security incidents promptly, and to notify affected players where a breach presents a material risk to their rights.
While gc22 takes all reasonable steps to protect personal data, no digital system is entirely immune from security risk. gc22 encourages players to use strong, unique passwords for their gc22 accounts and to enable two-factor authentication to reduce the risk of unauthorised account access.
9. Your Data Protection Rights
As a registered player at gc22, you have the following rights with respect to your personal data. These rights may be exercised at any time by submitting a request to [email protected]. gc22 will acknowledge all data rights requests within 5 business days and provide a substantive response within 30 calendar days.
gc22 will not charge a fee for exercising any of the rights listed above except in cases of manifestly unfounded or excessive requests, in which case a reasonable administrative fee may be applied. gc22 may request additional information to verify your identity before processing a data rights request.
10. Children & Underage Players
The gc22 platform is strictly for adults aged 21 years and above. gc22 does not knowingly collect personal data from individuals under the age of 21. The gc22 registration process includes a date-of-birth declaration, and gc22 uses KYC verification to confirm that all registered players meet the minimum age requirement.
If gc22 discovers or has reasonable grounds to believe that personal data has been collected from an individual under the age of 21, gc22 will immediately suspend the relevant account, delete the personal data collected to the extent permitted by law, and reverse any transactions associated with the account where possible.
If you believe that an underage individual has registered an account on gc22, please contact our support team at [email protected] immediately so that we can investigate and take appropriate action.
11. Cross-Border Data Transfers
gc22 operates a platform that serves players in Bangladesh. Some of the third-party service providers we use — including game studio providers, KYC verification agencies, and technical infrastructure partners — may store or process personal data on servers located outside Bangladesh.
Where personal data is transferred outside Bangladesh, gc22 takes steps to ensure that appropriate safeguards are in place to protect the data to a standard equivalent to that applied within Bangladesh. These safeguards may include:
- Standard contractual data protection clauses incorporated into contracts with third-party processors located outside Bangladesh.
- Selection of processors located in jurisdictions that maintain data protection standards recognised as adequate.
- Technical measures including encryption of data in transit and at rest applied uniformly regardless of the location of processing.
By using the gc22 platform, you acknowledge that your personal data may be transferred to, stored, or processed in countries outside Bangladesh for the purposes described in this Policy. gc22 will not transfer personal data to any processor that cannot demonstrate adequate data protection safeguards.
12. Updates to This Privacy Policy
gc22 may update this Privacy Policy from time to time to reflect changes in our data processing practices, operational requirements, or applicable legal obligations. When material changes are made to this Policy, gc22 will notify registered players by email and by displaying a prominent notice on the gc22 platform for a minimum of seven days prior to the changes taking effect.
The effective date at the top of this Policy reflects the date on which the current version came into force. Continued use of the gc22 platform after the effective date of any revised Policy constitutes acceptance of the revised terms. If you do not agree with changes to this Policy, you must stop using the platform and contact support to request account closure.
The version of this Privacy Policy currently in force is always available at gc22.io/privacy-policy. Previous versions are available on request by contacting our support team.
13. How to Contact Us
If you have any questions, concerns, or requests relating to this Privacy Policy or the way gc22 handles your personal data, please contact our support team using the details below. All privacy-related communications are handled in English.
- Email: [email protected] (responses within 4 hours for general support; data protection requests within 5 business days)
- Live Chat: Available 24/7 through the gc22 platform interface
- Support Hours: 24 hours a day, 7 days a week, Bangladesh Standard Time (UTC+6)
When submitting a data rights request, please include your full registered name, your gc22 account username, and a clear description of the request. gc22 may require identity verification before processing any data rights request to ensure that personal data is disclosed or deleted only at the request of the individual to whom it belongs.
Questions About Your Data?
Our English-speaking support team is available around the clock to answer privacy questions, process data requests, and help you manage your gc22 account settings. Ready to explore the platform? Visit gc22 Casino or check our FAQ.