Effective Date: 1 June 2026 | Data Controller: xx66 | Contact: [email protected]
Six Core Privacy Commitments from xx66
Data Minimisation
xx66 collects only the personal information necessary to provide and secure the service, comply with legal obligations, and prevent fraud. We do not harvest data for unrelated commercial purposes.
No Sale of Personal Data
xx66 does not sell, rent, or auction your personal data to third-party marketers or data brokers. Your information is used solely for the operational and legal purposes described in this policy.
Encrypted Storage
All sensitive personal data stored by xx66 — including CNIC verification records and payment account details — is encrypted at rest using industry-standard encryption protocols.
Player Rights Respected
You have the right to access, correct, and request deletion of your personal data held by xx66, subject to applicable legal retention requirements. See the Your Rights section for full details.
Pakistan-Contextual Processing
xx66's primary player base is in Pakistan. Data processing is conducted with awareness of local payment infrastructure (JazzCash, Easypaisa, HBL, UBL) and the applicable legal context for Pakistani users.
Transparent Communication
When xx66 makes material changes to this Privacy Policy, registered players are notified by email before the changes take effect. The current policy is always available at xx66.lat/privacy-policy.
Data We Collect
xx66 collects personal data in the following categories:
| Category | Examples | When Collected |
|---|---|---|
| Identity Data | Full name, date of birth, CNIC number, nationality | Registration & KYC verification |
| Contact Data | Email address, mobile number (Pakistan) | Registration |
| Financial Data | JazzCash/Easypaisa mobile number, bank account details, transaction history in PKR | Cashier use |
| Technical Data | IP address, device type, browser, operating system, session timestamps | Automatically on platform use |
| Usage Data | Games played, bets placed, session duration, feature interactions | Automatically during gaming sessions |
| Communications Data | Live chat transcripts, support email content | When you contact xx66 support |
xx66 does not collect special category data (such as health data, biometric data, or political opinions) except where required for responsible gaming assessment purposes, and only with your explicit consent.
How We Collect Data
2.1 Directly From You
The majority of personal data xx66 holds about you is provided directly by you: at the point of registration, when completing KYC verification, when making deposits or withdrawals through JazzCash, Easypaisa, or bank transfer, and when you contact our support team.
2.2 Automatically
When you access xx66.lat, certain technical and usage data is collected automatically by our platform servers and analytics infrastructure. This includes your IP address, device characteristics, browser type, the pages you visit, the games you open, and the duration of your sessions. This data is collected via server logs, session cookies, and first-party analytics tools.
2.3 From Third Parties
In limited circumstances, xx66 may receive personal data about you from third parties. This includes identity verification data returned by KYC service providers during the verification process, and fraud or AML screening data returned by risk management partners. xx66 requires all third-party processors to handle your data in accordance with applicable data protection standards.
Purpose of Processing
xx66 processes your personal data for the following purposes:
- Account management: Creating, maintaining, and securing your xx66 account and login credentials.
- Service delivery: Providing access to casino games, sports betting, live dealer tables, and the PKR cashier.
- Payment processing: Facilitating deposits and withdrawals via JazzCash, Easypaisa, HBL, UBL, Meezan Bank, and other supported methods.
- Identity verification (KYC): Confirming your identity and age (18+) as required before processing withdrawals above thresholds or as mandated by our licensing obligations.
- Fraud prevention and AML: Detecting and preventing fraudulent activity, money laundering, and the funding of unlawful activities through the xx66 platform.
- Responsible gaming: Monitoring usage patterns to identify indicators of problem gambling and enforcing self-imposed limits and self-exclusion requests.
- Customer support: Responding to your enquiries and resolving disputes.
- Platform improvement: Analysing aggregated usage data to improve game performance, cashier flows, and the overall player experience.
- Legal compliance: Meeting obligations under applicable laws and responding to lawful requests from regulatory or law enforcement authorities.
Legal Basis for Processing
xx66 processes your personal data on the following legal bases:
Processing your identity, contact, and financial data is necessary to perform the contract between you and xx66 — i.e., to provide the betting and gaming services you have registered for.
KYC verification, AML screening, and the retention of transaction records are processed on the basis of legal obligation under applicable gaming and financial regulations.
Technical and usage data processing for fraud prevention, platform security, and service improvement is based on the legitimate interests of xx66 and its player community, subject to your interests not overriding those interests.
Where xx66 sends optional marketing communications or processes special category data for responsible gaming assessment beyond the contractual baseline, processing is based on your explicit consent, which may be withdrawn at any time.
Data Retention
xx66 retains personal data for as long as necessary to fulfil the purposes described in this policy or as required by applicable law. The following general retention periods apply:
- Account and identity data: Retained for the duration of the account relationship and for a minimum of 5 years following account closure, to comply with AML record-keeping obligations.
- Transaction and financial records: Retained for a minimum of 5 years from the date of the transaction.
- Support communications: Retained for 2 years from the date of the last communication in a given case.
- Technical and usage logs: Retained for 12 months on a rolling basis unless required for an ongoing investigation or dispute.
When personal data is no longer required, it is deleted or anonymised in a secure manner. Anonymised, aggregated data (which can no longer identify you) may be retained indefinitely for analytical purposes.
Data Security
xx66 implements appropriate technical and organisational security measures to protect your personal data against accidental loss, unauthorised access, disclosure, alteration, or destruction. Measures include:
- TLS encryption for all data transmitted between your browser and xx66.lat.
- Encryption at rest for sensitive personal data including identity records and payment information.
- Access controls limiting personal data access to xx66 personnel and service providers with a legitimate need.
- Regular security assessments of the platform and associated infrastructure.
- Two-factor authentication (2FA) available to all xx66 players to protect account access.
While xx66 takes all reasonable precautions, no internet-connected system is immune to all security threats. In the event of a personal data breach that is likely to result in risk to your rights, xx66 will notify affected players without undue delay in accordance with applicable obligations.
Your Rights
Subject to applicable law, you have the following rights in relation to personal data held by xx66:
- Right of access: You may request a copy of the personal data xx66 holds about you.
- Right to rectification: You may request correction of inaccurate or incomplete personal data.
- Right to erasure: You may request deletion of your personal data, subject to legal retention obligations.
- Right to restriction: You may request that xx66 restricts processing of your data in certain circumstances.
- Right to object: You may object to processing based on legitimate interests, including for direct marketing purposes.
- Right to withdraw consent: Where processing is based on consent, you may withdraw that consent at any time without affecting the lawfulness of prior processing.
To exercise any of the above rights, please contact xx66 at [email protected] with the subject line "Data Rights Request" and your registered username. xx66 will respond within 30 calendar days of receiving a valid request. Identity verification may be required before the request is processed.
Minors
The xx66 platform is strictly for adults aged 18 and above. xx66 does not knowingly collect personal data from persons under 18 years of age. If xx66 becomes aware that personal data has been collected from a minor, the account will be suspended and the data will be deleted. If you believe a minor has registered on xx66 using false age information, please contact [email protected] immediately.
Changes to This Privacy Policy
xx66 may update this Privacy Policy from time to time to reflect changes in our data practices, legal obligations, or platform services. Where material changes are made, xx66 will notify registered players by email at least 7 days before the revised policy takes effect. The effective date at the top of this page will be updated accordingly. Your continued use of the xx66 platform after the effective date of an updated policy constitutes your acknowledgement of the revised terms.
Contact Us
For any questions, concerns, or requests related to this Privacy Policy or the personal data xx66 holds about you, please contact:
Email: [email protected] — Subject: "Privacy Policy Enquiry"
xx66 endeavours to respond to all privacy-related communications within 10 business days. For data rights requests, the response period is 30 calendar days from receipt of a valid, verified request.