🇻🇳 Vietnamese 🇬🇧 English

Privacy Policy

1. Commitment to Privacy

Ventures Lab Malta Limited (the "Company", "we", "our", or "us") is committed to respecting and protecting the privacy of every individual whose Personal Data we process. We recognise that safeguarding Personal Data is an essential component of maintaining customer confidence and meeting our legal and regulatory responsibilities.

This Privacy Policy explains how the Company collects, uses, stores, shares, retains, and protects Personal Data obtained through our websites, gaming platform, mobile applications, and any related products or services (collectively referred to as the "Services").

By using the Services, customers acknowledge that their Personal Data will be processed in accordance with this Policy and applicable law.

2. Applicable Legislation

The Company's processing of Personal Data is governed by applicable European Union and Maltese legislation, including:

  • Regulation (EU) 2016/679 (General Data Protection Regulation ("GDPR"));
  • the Malta Data Protection Act (Chapter 586 of the Laws of Malta);
  • regulatory obligations issued by the Malta Gaming Authority ("MGA"), including those relating to player protection, anti-money laundering, responsible gaming, and regulatory reporting; and
  • other applicable legal or regulatory requirements governing privacy and information security.

3. Data Controller Information

Ventures Lab Malta Limited acts as the Data Controller in relation to Personal Data processed through the Services.

Registered Office

Quad Central, Q3, Level 1, Office 5

Triq l-Esportaturi

Birkirkara, Malta

Company Registration Number: C 89206

Data Protection Officer

Email: dpo@manclub.eco

The Company has established internal governance arrangements to oversee compliance with applicable privacy legislation. The Data Protection Officer monitors the Company's privacy programme, supports internal compliance initiatives, and serves as the primary point of contact for data protection enquiries.

4. Information We Collect

The categories of Personal Data collected depend on the nature of the customer's interaction with the Services.

The Company may process the following categories of information:

Identification Information

  • full name;
  • date of birth;
  • nationality;
  • gender;
  • identity document details.

Customer Verification Information

  • copies of government-issued identification;
  • proof of residential address;
  • documentation relating to source of funds or source of wealth where required by law.

Contact Information

  • postal address;
  • email address;
  • telephone number.

Gaming and Account Information

  • customer account details;
  • betting and gaming activity;
  • transaction history;
  • account balances;
  • deposit and withdrawal history;
  • responsible gaming settings;
  • customer preferences.

Financial Information

  • payment methods;
  • banking information where applicable;
  • payment verification information.

Technical Information

  • IP address;
  • browser type;
  • operating system;
  • device identifiers;
  • cookie identifiers;
  • usage information;
  • approximate location derived from technical information where permitted.

Communications

  • customer support requests;
  • complaints;
  • feedback;
  • communications relating to compliance, responsible gaming, or security.

5. How Personal Data Is Used

The Company processes Personal Data for legitimate business, contractual, and regulatory purposes, including to:

  • create and administer customer accounts;
  • verify identity, age, and eligibility;
  • process deposits, withdrawals, and payment transactions;
  • fulfil anti-money laundering and customer due diligence obligations;
  • detect fraud, financial crime, and security threats;
  • provide responsible gaming measures;
  • improve the functionality and security of the Services;
  • communicate operational information and customer support responses;
  • comply with legal obligations and requests from competent authorities.

Personal Data is processed only for purposes that are compatible with those for which it was collected.

6. Legal Grounds for Processing

The Company processes Personal Data where one or more lawful grounds under the GDPR apply.

These may include:

  • performance of a contract with the customer;
  • compliance with legal and regulatory obligations;
  • the Company's legitimate interests, provided these do not override the rights and freedoms of the individual; and
  • consent, where consent is specifically required by law.

Where processing is based on consent, consent may be withdrawn at any time without affecting processing carried out prior to withdrawal.

7. Disclosure of Personal Data

The Company may disclose Personal Data where disclosure is necessary for operational purposes or to comply with legal obligations.

Recipients may include:

  • payment processors and banking institutions;
  • identity verification providers;
  • AML and fraud prevention service providers;
  • technology and cloud service providers;
  • cybersecurity providers;
  • professional advisers, including legal, audit, and compliance consultants;
  • the Malta Gaming Authority;
  • the Financial Intelligence Analysis Unit (FIAU);
  • courts, regulators, and law enforcement agencies where disclosure is required by law.

The Company does not sell or otherwise commercialise customer Personal Data.

8. International Transfers

Where Personal Data is transferred outside the European Economic Area ("EEA"), the Company ensures that appropriate safeguards are implemented in accordance with applicable data protection legislation.

These safeguards may include:

  • transfers to jurisdictions recognised by the European Commission as providing an adequate level of protection;
  • Standard Contractual Clauses approved by the European Commission; or
  • any other lawful transfer mechanism recognised under the GDPR.

9. Retention of Personal Data

The Company retains Personal Data only for the period necessary to fulfil the purposes for which it was collected or to satisfy legal, regulatory, contractual, or operational requirements.

In particular:

  • customer due diligence, AML, and regulatory records are generally retained for at least five (5) years following the end of the customer relationship;
  • financial and transaction records are retained in accordance with applicable accounting and regulatory obligations;
  • Personal Data that is no longer required is securely deleted, anonymised, or permanently destroyed.

10. Information Security

The Company has implemented technical and organisational measures designed to maintain the confidentiality, integrity, and availability of Personal Data.

These measures include:

  • encryption of sensitive information;
  • role-based access permissions;
  • authentication controls;
  • network monitoring;
  • secure infrastructure;
  • vulnerability management processes;
  • periodic security assessments;
  • employee confidentiality obligations and ongoing privacy training.

Security controls are reviewed regularly to ensure their continued effectiveness.

11. Individual Rights

Subject to applicable law, individuals may exercise the following rights:

  • request confirmation that Personal Data is being processed;
  • obtain access to Personal Data;
  • request correction of inaccurate or incomplete information;
  • request deletion of Personal Data where legally permissible;
  • request restriction of processing;
  • object to certain processing activities;
  • request transfer of Personal Data in a structured format where applicable; and
  • withdraw consent where processing is based upon consent.

Requests may be submitted directly to the Company's Data Protection Officer.

Individuals also have the right to submit complaints to the Office of the Information and Data Protection Commissioner (IDPC) where they believe that their Personal Data has been processed unlawfully.

12. Personal Data Breaches

The Company maintains documented procedures for identifying, assessing, recording, and responding to Personal Data breaches.

Where required under applicable legislation, the Company will:

  • investigate the incident promptly;
  • implement appropriate containment and remediation measures;
  • notify the competent supervisory authority within the statutory timeframe;
  • notify affected individuals where there is a high risk to their rights and freedoms; and
  • retain records of reportable incidents for audit and regulatory purposes.

13. Children's Data

The Services are intended solely for individuals who are at least eighteen (18) years of age or the minimum legal age applicable within the relevant jurisdiction.

The Company performs age verification as part of its onboarding procedures. If it becomes aware that Personal Data relating to a minor has been collected, appropriate action will be taken to terminate the account and securely remove the information where legally permissible.

14. Cookies

The Company uses cookies and similar technologies to support the operation, security, and performance of the Services.

Cookies may be used to:

  • facilitate website functionality;
  • maintain user sessions;
  • remember customer preferences;
  • analyse website usage;
  • improve performance;
  • strengthen fraud prevention measures.

Where required by law, users are provided with options to manage their cookie preferences before non-essential cookies are activated.

15. Changes to this Policy

The Company reviews this Privacy Policy periodically to ensure continued compliance with applicable legislation, regulatory guidance, operational practices, and technological developments.

Where amendments are made, the revised Policy will supersede previous versions and will be published through the Company's official website or other appropriate communication channels.

16. Governing Law

This Privacy Policy is governed by and shall be interpreted in accordance with the laws of Malta, including Regulation (EU) 2016/679 (GDPR), the Malta Data Protection Act, and all applicable requirements issued by the Malta Gaming Authority and other competent supervisory authorities.