1. Introduction
This Privacy Policy ("Policy") describes how 22club ("22club", "we", "us", "our") collects, processes, stores, and shares personal data in connection with the operation of the 22club online gaming platform at 22club.co and all associated services.
22club is committed to protecting the privacy of all individuals who interact with our platform, including registered Members, prospective Members, and general website visitors. We process personal data only where we have a lawful basis to do so, and we implement appropriate technical and organisational measures to protect data from unauthorised access, loss, or disclosure.
By registering an account with 22club or continuing to use the platform, you acknowledge that you have read and understood this Policy and consent to the processing of your personal data as described herein. This Policy should be read alongside our Terms & Conditions and Responsible Gaming policy.
2. Data Controller
The data controller responsible for your personal data is the legal entity operating 22club under its international gaming authority licence. Details of the data controller, including its registered address and licensing information, are available on request from the 22club compliance team. For all data-related enquiries, contact us at: [email protected]
3. Data We Collect
3.1 Information You Provide Directly
When you register, verify your identity, deposit funds, or contact support, 22club collects the following categories of personal data:
- Identity Data: Full legal name, date of birth, nationality, and government-issued identification number (e.g., MyKad number or passport number for Malaysian residents).
- Contact Data: Email address, mobile telephone number, and residential address (including postcode, city, and country).
- Financial Data: Bank account details, eWallet identifiers (Touch 'n Go eWallet, Boost), and transaction history associated with your 22club account.
- Verification Documents: Copies of identity documents, proof of address, and payment method documentation submitted during the KYC (Know Your Customer) process.
- Account Credentials: Username and encrypted password hash. 22club does not store plaintext passwords.
- Communications: Records of your interactions with the 22club support team, including live chat transcripts and written correspondence.
3.2 Information Collected Automatically
When you access and use 22club, we automatically collect certain technical and behavioural data, including:
- Device & Technical Data: IP address, device type, operating system, browser type and version, and screen resolution.
- Usage Data: Pages visited, games played, bet amounts, session duration, login timestamps, and navigation paths within the platform.
- Location Data: Approximate geographic location derived from your IP address, used for fraud prevention and regulatory compliance. 22club does not collect precise GPS location data.
- Cookie Data: Data collected via cookies and similar tracking technologies, as described in Section 7 of this Policy.
4. How We Use Your Personal Data
22club uses your personal data for the following purposes:
- Account Management: To create, maintain, verify, and administer your 22club account, including processing deposits, withdrawals, and bet settlements.
- KYC & Regulatory Compliance: To verify your identity and age, comply with anti-money laundering (AML) obligations, and fulfil reporting requirements imposed by our licensing authority.
- Fraud Prevention & Security: To detect, investigate, and prevent fraudulent transactions, account takeovers, bonus abuse, and other prohibited conduct as defined in the 22club Terms & Conditions.
- Responsible Gaming: To monitor gaming activity for indicators of problem gambling and, where appropriate, to apply protective measures including deposit limit enforcement and self-exclusion.
- Customer Support: To respond to your enquiries, resolve disputes, and process complaints through the 22club support team.
- Platform Improvement: To analyse aggregated usage data, identify technical issues, and develop new features and games that better serve the 22club membership.
- Marketing Communications: To send promotional offers, bonus notifications, and platform updates to Members who have opted in to marketing communications. You may opt out at any time from within your account settings.
- Legal Compliance: To comply with applicable laws, regulatory directions, court orders, and requests from competent authorities.
5. Legal Basis for Processing
22club processes your personal data on one or more of the following legal bases:
- Contractual Necessity: Processing is necessary to perform the contract between you and 22club — specifically, to operate your account and provide gaming services.
- Legal Obligation: Processing is required to comply with AML regulations, licensing conditions, and other applicable legal obligations.
- Legitimate Interests: Processing is necessary for 22club's legitimate interests, including fraud prevention, platform security, and service improvement, provided those interests are not overridden by your rights and freedoms.
- Consent: Where we rely on your consent (e.g., for marketing communications), you may withdraw that consent at any time without affecting the lawfulness of prior processing.
6. Data Sharing and Disclosure
22club does not sell or rent your personal data to third parties. We may share your data in the following limited circumstances:
- Service Providers: We engage carefully selected third-party processors to assist with payment processing, identity verification, fraud detection, cloud hosting, and customer support tooling. All processors are bound by data processing agreements that prohibit them from using your data for any purpose other than providing services to 22club.
- Game Providers: Certain game providers (e.g., live dealer studios) may receive anonymised session data necessary to deliver their games. Where identifiable data is shared, it is subject to the same data protection standards.
- Regulatory Authorities: We will disclose personal data to our licensing authority, financial intelligence units, or law enforcement agencies where required by law, a court order, or a legitimate regulatory request.
- Business Transfers: In the event of a merger, acquisition, or sale of assets, your personal data may be transferred to the successor entity, subject to equivalent data protection obligations.
In all cases, 22club ensures that any sharing of personal data is conducted on a minimum-necessary basis and is subject to appropriate contractual or legal safeguards.
7. Cookies and Tracking Technologies
22club uses cookies and similar tracking technologies on its website and platform. Cookies are small text files placed on your device that allow us to recognise your browser and remember certain information about your session.
7.1 Types of Cookies We Use
- Strictly Necessary Cookies: Required for the platform to function — including maintaining your login session, managing your shopping cart during deposit flows, and applying your account preferences. These cannot be disabled.
- Performance Cookies: Collect anonymised data about how Members use 22club — which pages are visited most frequently, where errors occur, and how quickly pages load — to help us improve platform performance.
- Functional Cookies: Remember your preferences such as preferred language, game lobby filters, and display settings to personalise your 22club experience.
- Analytics Cookies: Used to understand aggregate Member behaviour patterns and measure the effectiveness of platform features. Data collected via analytics cookies is aggregated and does not identify individual Members.
You can manage cookie preferences through your browser settings. Disabling strictly necessary cookies will impair platform functionality, including the ability to remain logged in to your 22club account.
8. Data Retention
22club retains your personal data for as long as is necessary to fulfil the purposes for which it was collected, subject to the following minimum retention periods:
- Account Data: Retained for the duration of your account and for a minimum of five (5) years following permanent account closure, in compliance with AML regulatory requirements.
- Transaction Records: Retained for a minimum of seven (7) years from the date of the transaction.
- KYC Documents: Retained for a minimum of five (5) years from the date of submission or account closure, whichever is later.
- Support Communications: Retained for three (3) years from the date of the interaction.
- Marketing Data: Retained until you withdraw consent or opt out of marketing communications, at which point marketing data will be suppressed within 30 days.
Following the expiry of the applicable retention period, personal data will be securely deleted or anonymised in accordance with 22club's data disposal procedures.
9. Data Security
22club implements a multi-layered security framework to protect your personal data, including:
- 256-bit SSL/TLS encryption for all data in transit between your device and 22club servers.
- AES-256 encryption for sensitive data stored at rest, including financial records and identity documents.
- Role-based access controls limiting employee access to personal data strictly to those with a legitimate operational need.
- Regular third-party security audits and penetration testing of the 22club platform infrastructure.
- Automated anomaly detection on all 22club account login activity, with alerts triggered for unusual access patterns.
- Incident response procedures aligned with international standards, including notification obligations where a data breach affects Member rights.
While 22club takes all reasonable precautions, no system is entirely impervious to attack. You are responsible for maintaining the security of your own 22club login credentials and for reporting any suspected unauthorised access to your account without delay.
10. International Data Transfers
As 22club operates under an international gaming authority licence and uses globally distributed infrastructure and service providers, your personal data may be transferred to and processed in countries outside Malaysia. Where such transfers occur, 22club ensures that appropriate safeguards are in place, including standard contractual clauses, data processing agreements, and — where applicable — adequacy assessments, to ensure your data receives a level of protection equivalent to that required under applicable data protection principles.
11. Your Data Rights
Subject to applicable data protection law, you have the following rights in relation to your personal data held by 22club:
- Right of Access: You may request a copy of the personal data 22club holds about you.
- Right to Rectification: You may request correction of inaccurate or incomplete personal data.
- Right to Erasure: You may request deletion of your personal data, subject to overriding legal retention obligations (e.g., AML requirements).
- Right to Restriction: You may request that we restrict processing of your data in certain circumstances, such as where you contest its accuracy.
- Right to Portability: You may request that we provide your personal data in a structured, machine-readable format for transfer to another controller.
- Right to Object: You may object to processing based on legitimate interests or for direct marketing purposes at any time.
- Right to Withdraw Consent: Where processing is based on consent, you may withdraw that consent at any time without affecting the lawfulness of prior processing.
To exercise any of the above rights, please contact the 22club compliance team via the live chat facility or by written request to [email protected]. 22club will respond to all valid requests within 30 calendar days. We may require identity verification before processing rights requests.
12. Children's Privacy
The 22club platform is strictly for persons aged 21 and above. 22club does not knowingly collect personal data from individuals under the age of 21. If you believe a minor has accessed or registered on the platform, please contact us immediately at [email protected]. Any account found to belong to a minor will be immediately suspended and all associated data will be securely deleted in accordance with our data disposal procedures.
13. Changes to This Privacy Policy
22club reserves the right to update or amend this Privacy Policy at any time. Material changes will be communicated to registered Members via a notification on the platform or by email to the address registered on your account, at least 14 days before the amended Policy takes effect. The "Effective date" at the top of this page will be updated to reflect the date of the most recent revision. Continued use of 22club following the effective date of an amended Policy constitutes your acceptance of the changes.
14. Contact and Complaints
For any questions, concerns, or complaints relating to this Privacy Policy or the handling of your personal data by 22club, please contact our compliance team:
If you are not satisfied with our response to a data complaint, you may have the right to lodge a complaint with the relevant data protection supervisory authority in your jurisdiction, or with the adjudication body of 22club's licensing authority.