Data Controller

The data controller responsible for the processing described in this policy is:

Item Detail
Legal name BitPulse Solution N.V.
Company registration number 164928
Registered address Zuikertuintjeweg Z/N (Zuikertuin Tower), Willemstad, Curaçao
Privacy contact [email protected]
Data Protection Officer Pavilion88 Data Protection Officer
DPO email [email protected]

Do not publish this policy until the legal entity and contact details have been confirmed.

Personal Data We Collect

Pavilion88 may collect personal data supplied by a member, generated through use of the platform or received from an authorised service provider.

Registration and account data

This may include:

  • name;
  • username;
  • date of birth;
  • nationality;
  • phone number;
  • email address;
  • residential address;
  • account password in protected form;
  • account preferences;
  • account status.

Identity and verification data

Where account or transaction checks are required, we may collect:

  • identity-document details;
  • document images;
  • facial or identity-verification results;
  • proof of address;
  • source-of-funds information;
  • verification status;
  • fraud and risk indicators.

The exact verification process must match the live Pavilion88 account flow.

Payment and transaction data

This may include:

  • deposit and withdrawal amount;
  • payment method;
  • wallet or bank-account details;
  • transaction reference;
  • transaction time;
  • payment status;
  • promotion attached to a transaction;
  • chargeback or dispute records.

Pavilion88 should not store full card data when a payment provider processes that information directly.

Platform and game data

This may include:

  • login time;
  • account balance;
  • game history;
  • stake and result records;
  • bonus activity;
  • daily check-in status;
  • account limits;
  • responsible-gaming interactions;
  • support records.

Device and technical data

This may include:

  • IP address;
  • browser;
  • device type;
  • operating system;
  • app version;
  • language;
  • approximate location;
  • cookie identifiers;
  • session information;
  • error and security logs.

Communication data

We may keep messages sent through support, email, live chat or other confirmed contact channels.

Do not send a password, card PIN or one-time verification code through a support message.

How We Collect Personal Data

Pavilion88 may collect personal data when a member:

  • registers an account;
  • logs in;
  • makes a deposit or withdrawal;
  • opens a game;
  • claims a promotion;
  • completes verification;
  • changes account settings;
  • contacts support;
  • uses the website, app or mobile browser;
  • accepts or changes cookie preferences.

We may also receive data from payment providers, identity-verification providers, game providers, fraud-prevention services and other parties used to provide the account service.

How We Use Personal Data

Pavilion88 may process personal data to:

  • create and manage an account;
  • confirm identity and account ownership;
  • provide login and platform access;
  • process deposits and withdrawals;
  • maintain transaction and game records;
  • provide promotions and daily check-in;
  • respond to support requests;
  • prevent fraud, abuse and unauthorised access;
  • maintain platform security;
  • identify technical problems;
  • apply account and responsible-gaming controls;
  • meet legal and regulatory duties;
  • handle complaints and disputes;
  • improve website and app performance;
  • send marketing where permitted.

Personal data should not be used for a new purpose that is incompatible with the purpose stated when it was collected.

Some processing may depend on consent. Other data may be required to create an account, process a payment, provide a requested service or meet a legal duty.

Pavilion88 should state when information is mandatory. A member may be unable to register, make a payment or use an account feature when required data is not supplied.

Consent can be withdrawn where the processing depends on consent. Withdrawal does not make earlier processing unlawful.

Cookies and Similar Technologies

Pavilion88 may use cookies, local storage and similar technologies to:

  • maintain a login session;
  • remember language and account settings;
  • protect the account;
  • record cookie choices;
  • measure website performance;
  • identify technical errors;
  • support permitted marketing.

Cookie categories and third-party tools must match the live website configuration.

Cookie controls: Consent banner on the first visit plus a persistent Cookie Settings link in the footer

Essential cookies may be required for login, security and account functions. Optional analytics or marketing tools should follow the consent settings that apply to the user.

Payments and Verification Providers

Pavilion88 may share the data required to provide an account service with authorised providers.

These may include:

  • payment processors;
  • banks and wallet providers;
  • identity-verification services;
  • game and platform providers;
  • cloud hosting and storage providers;
  • customer-support systems;
  • security and fraud-prevention services;
  • analytics providers;
  • professional advisers;
  • authorities where disclosure is required by law.

A provider should receive only the data needed for its stated function and must handle that data under an appropriate agreement.

A final provider list should be checked against the live Pavilion88 platform.

Direct Marketing

Pavilion88 may send promotion or service messages through channels permitted by the member's choices and applicable requirements.

Members can request changes to direct marketing through the account settings, message controls or privacy contact.

A service message about login, account security, payments or policy changes may still be sent when it is required to operate the account.

We should keep a record of marketing preferences and withdrawal requests.

Cross-Border Data Transfers

Personal data may be processed or stored outside Malaysia when Pavilion88 uses an overseas provider or infrastructure.

Transfer locations: Curaçao, Malaysia, Singapore and EEA cloud or service-provider locations

Before publication, confirm:

  • the country receiving the data;
  • the service provider;
  • the data categories transferred;
  • the transfer purpose;
  • the safeguards used;
  • the retention period.

Pavilion88 should use contractual, technical and organisational safeguards required for the transfer.

Data Retention

Pavilion88 should keep personal data only for the period required for the account service, transaction records, security, disputes and legal duties.

Retention schedule: Account, KYC and transaction records: 5 years after closure; support and complaint records: 2 years; technical logs: 12 months; cookie-consent records: 13 months

Different data may require different periods. Account data, payment records, support messages and security logs should not use one generic retention period unless that period is supported by the actual process.

Data should be deleted, anonymised or restricted when it is no longer required.

Data Security

Pavilion88 uses administrative, technical and organisational controls intended to protect personal data from unauthorised access, loss, misuse, alteration or disclosure.

Controls may include:

  • access restrictions;
  • protected password storage;
  • encryption in transit;
  • system logging;
  • account monitoring;
  • backup controls;
  • provider-access controls;
  • staff confidentiality;
  • incident-response procedures.

No online system can remove every security risk. Members should use a separate password, keep verification codes private and sign out on a shared device.

Data Breach Handling

Pavilion88 should assess a suspected personal-data breach when data is lost, accessed, altered or disclosed without authorisation.

The response process should cover:

  • containment;
  • investigation;
  • risk assessment;
  • record keeping;
  • provider coordination;
  • notification duties;
  • corrective action.

The final policy must match the actual Pavilion88 incident-response process and any notification duties in force.

Member Rights

Subject to the applicable requirements and permitted exceptions, a member may request:

  • information about the processing of personal data;
  • access to personal data held by Pavilion88;
  • correction of inaccurate or incomplete data;
  • withdrawal of consent where consent applies;
  • prevention of processing that causes damage or distress;
  • changes to direct-marketing preferences;
  • other rights available under the law in force.

A request may require identity confirmation before account data is released or changed.

Send a privacy request to [email protected] or the confirmed contact route on the Pavilion88 contact page.

Account Closure and Data Requests

Closing an account does not always require immediate deletion of every record.

Pavilion88 may need to keep certain account, payment, security or dispute records for a defined period. The final retention reason and period must be stated in the published schedule.

A member requesting account closure should identify the account through the confirmed support process. Do not send a password or one-time verification code.

Children and Underage Users

Pavilion88 is not intended for anyone below the legal age required to use the service.

We may close or restrict an account when information indicates that the user does not meet the age requirement.

A parent or guardian who believes that an underage person supplied personal data should contact [email protected].

Pavilion88 pages may link to payment, game, support or other external services.

A third-party service may use its own privacy notice and data practices. This policy applies only to processing controlled by the Pavilion88 entity named above.

Members should check the destination before entering account or payment details.

Policy Changes

Pavilion88 may update this policy when the platform, providers, data use or legal requirements change.

The updated version should show the effective date and last-updated date. A material change may also be communicated through the website, account or confirmed contact channel.

Old versions should be retained internally when required for compliance records.

Privacy Contact

Send privacy questions or requests to:

Contact Detail
Privacy email [email protected]
Data Protection Officer Pavilion88 Data Protection Officer
DPO email [email protected]
Support email [email protected]
Registered address Zuikertuintjeweg Z/N (Zuikertuin Tower), Willemstad, Curaçao

Use the Pavilion88 contact page for the confirmed public contact channels.