Privacy Policy Overview

This Privacy Policy explains how personal information is collected, processed, protected, disclosed, and securely destroyed on the WinWin website. The platform follows the Kenya Data Protection Act and recognised international standards. Use of data is based on your consent, obtained at registration and through your ongoing choices. This document also sets out user rights and how to exercise them.

What We Collect and How We Protect It

Personal data we collect

  • Identity and KYC: full name, date of birth, nationality, national ID or passport details, and verification documents.
  • Contact information: email address, mobile number, and residential address.
  • Account and usage: username, settings, responsible gaming preferences, customer support records, and communications.
  • Transactions: deposits, withdrawals, bets, wins, payment instrument identifiers as tokenised by payment providers.
  • Device and technical data: IP address, device identifiers, browser type, operating system, language, and approximate location where permitted.
  • Compliance records: sanctions screening results, AML checks, and risk assessments.
  • Cookies and analytics: website interaction metrics and performance statistics.

Why we collect this information

  • To open and service the account and provide online services.
  • To verify identity, confirm age, and comply with the Betting, Lotteries and Gaming Act and the Proceeds of Crime and Anti-Money Laundering Act.
  • To meet obligations under the Kenya Data Protection Act 2019 and directions from the Office of the Data Protection Commissioner.
  • To maintain security, prevent fraud, and support responsible gambling.
  • To improve site performance and user experience through analytics.

How we protect your data

  • Encryption in transit using TLS and encryption at rest for sensitive fields.
  • Access controls, role-based permissions, and multi-factor authentication for authorised staff.
  • Network monitoring, logging, and periodic security testing.
  • Segregated environments and backups with integrity checks.
  • Payment processing aligned to PCI DSS by payment providers.
  • Staff confidentiality commitments and regular training.
  • Data minimisation, pseudonymisation where practical, and secure destruction protocols.

Your rights under Kenya law

  • Access a copy of your personal information.
  • Request correction of inaccurate or incomplete records.
  • Ask for deletion where allowed by law.
  • Object to or restrict processing in certain cases.
  • Withdraw consent at any time.
  • Request portability where technically feasible.
  • Lodge a complaint with the Office of the Data Protection Commissioner.

Compliance statement

WinWin acts as the data controller for this website and follows the Kenya Data Protection Act 2019 and the Data Protection (General) Regulations 2021. Processes are aligned to GDPR principles of lawfulness, fairness, purpose limitation, and accountability.

Purposes for Using Your Information

We use personal data only for lawful, specific purposes and in a transparent manner.

Core uses

  • Account creation, sign in, and customer support.
  • Verification, KYC, and age checks.
  • Processing deposits, bets, and withdrawals.
  • Operating online casino and sportsbook services.
  • Responsible gaming tools and interventions.
  • Detecting, preventing, and investigating fraud or misuse.

Improvement and analytics

  • Measuring site performance and troubleshooting.
  • Developing new features and enhancing usability.
  • Aggregated statistics to improve content and layout.

Marketing and preferences

  • Sending service announcements and policy updates.
  • Marketing communications based on your consent and preferences, which you can change at any time.

Compliance and legal

  • Meeting tax, AML, and regulatory requirements.
  • Responding to lawful requests, disputes, and enforcement.

Legal bases

Processing is based on consent, performance of a contract, legal obligation, or legitimate interests that are not overridden by your rights.

How to Access, Update, or Delete Your Data

Requesting access or changes

  • Submit a request through account settings or the Help Centre indicated on the website.
  • We may ask for identity documents to confirm it is your account.
  • A response is usually provided within 30 days as required by Kenya law.

Correction and deletion

  • You may update most fields in your profile at any time.
  • You may ask us to delete information that is no longer required by law or contract.
  • Certain records must be kept for up to 7 years for anti-money laundering and regulatory purposes.

Consent to checks and payments

By using WinWin, you consent to security screening, identity verification, sanctions checks, and monitoring for fraud and responsible gambling. You also agree that payment data may be processed by authorised payment providers and financial institutions for transactions and chargeback management.

How to contact us

Use the contact channels listed on the website to reach the Data Protection Officer for privacy requests or complaints.

Children and Age Restrictions

This website is intended only for users who are 18 years or older under Kenya law. Account creation by a minor is not permitted. The operator cannot confirm age without documents and may request proof when needed. If a parent or guardian believes a minor has provided personal data, they may contact us to request deletion and closure of the account.

Cross-Border Transfers of Personal Data

Personal information may be processed outside Kenya in countries where service providers, payment partners, or hosting centres operate. Using the site indicates your consent to such transfers in line with Kenya Data Protection Act requirements. Appropriate safeguards are applied, such as contractual protections, encryption, and due diligence of recipients. All partners are required to maintain confidentiality and use the information only for the agreed purpose. Where required, transfers are notified to or approved by the Office of the Data Protection Commissioner.

Scope and Effect of This Disclaimer

This Privacy Policy includes a disclaimer that may limit or clarify how certain rules apply in practice. The disclaimer takes effect when you accept this Policy by signing up, ticking acceptance, or otherwise acceding to the terms. If any part of this document conflicts with local law, the law prevails to the extent of the conflict. Nothing in this document removes statutory rights available under Kenya law.

Cookies and Similar Technologies

What cookies are

Cookies are small text files stored on your device by websites to remember settings and understand usage.

How we use cookies

  • Essential cookies for sign in, security, and core functions.
  • Functional cookies to remember preferences.
  • Analytics cookies to measure traffic and behaviour for statistics.
  • Advertising cookies to manage frequency and relevance.

Retention

Most cookies are kept for up to 1 year. Some session cookies are deleted when you close the browser.

Your choices

You can manage cookies in your browser or through the consent manager on the site. Blocking some cookies may affect certain services.

Your Acceptance of This Policy

Using this website means you fully accept this Privacy Policy and consent to the collection and use of data as described. The current version on the site prevails over any earlier version. Continued use after changes indicates acceptance of the updated document.

Sharing Data With Third Parties

When sharing may occur

  • Where required by law, court order, or to address disputes.
  • To fulfil agreements such as payment processing, identity verification, hosting, and customer support.
  • To protect the integrity of the services and investigate suspected violations.

Information on recipients

A list of key categories of third parties is maintained on the website. If a specific party is not listed, you will be informed of the purpose and scope before sharing where reasonably possible.

Consent

Providing information and using the services indicates consent to share it with such third parties for these purposes. All recipients must protect confidentiality and process only as instructed.

Updated: