Privacy Policy Statement

1. Introduction

MOBILE INCORPORATED Limited (the “Company”, “we”, “us”, or “our”) recognises the importance of protecting personal privacy and is committed to ensuring that Personal Data is handled in a lawful, fair, and transparent manner.

This Privacy Policy Statement explains how Personal Data is collected, processed, used, disclosed, and safeguarded when individuals use our websites, gaming platform, mobile applications, and any related services (collectively, the “Services”).

By accessing or using the Services, you acknowledge that your Personal Data will be processed in accordance with this Policy and applicable legal requirements.

The Company operates in compliance with:

  • Regulation (EU) 2016/679 (General Data Protection Regulation – GDPR)
  • the Malta Data Protection Act (Chapter 586 of the Laws of Malta)
  • Malta Gaming Authority (“MGA”) regulatory requirements, including obligations relating to AML, responsible gaming, and player protection

2. Data Controller Information

MOBILE INCORPORATED Limited acts as the Data Controller responsible for determining the purposes and means of processing Personal Data.

Registered Office:

Elite Business Centre, Trejqa Ta’ Box Box, Msida MSD1840, Malta

Company Registration Number: C 84149

Data Protection Officer (DPO)

Email: legal@gemwin.eco

Address: Elite Business Centre, Trejqa Ta’ Box Box, Msida MSD1840, Malta

The Data Protection Officer oversees compliance with applicable data protection legislation and serves as the contact point for privacy-related matters.

3. Data Protection Approach

The Company applies the core principles of data protection law when processing Personal Data:

  • Lawfulness, fairness, transparency: processing is carried out in a transparent and lawful manner
  • Purpose limitation: data is collected only for specified, legitimate purposes
  • Data minimisation: only data necessary for operational and regulatory purposes is collected
  • Accuracy: Personal Data is maintained and updated where necessary
  • Storage limitation: data is retained only for as long as required
  • Integrity and confidentiality: appropriate safeguards protect Personal Data
  • Accountability: compliance with GDPR obligations is continuously monitored and demonstrable

4. Personal Data We Process

We may collect and process the following categories of Personal Data:

Identity Data

  • full name
  • date of birth
  • nationality
  • gender

Verification Data

  • identity documents issued by government authorities
  • proof of residential address
  • source of funds and/or source of wealth documentation (where applicable)

Contact Data

  • email address
  • telephone number
  • residential address

Account & Gaming Data

  • login credentials
  • gameplay and betting activity
  • account balances, limits, and preferences
  • transaction history

Financial Data

  • deposit and withdrawal records
  • payment method details
  • transaction processing information

Technical Data

  • IP address
  • device identifiers
  • browser type and operating system
  • system logs and usage activity

Communication Data

  • customer service communications
  • responsible gaming interactions
  • compliance-related correspondence

Some categories of data may be classified as higher risk and are subject to additional safeguards.

5. Purposes of Processing

Personal Data is processed for the following purposes:

  • account creation and administration
  • identity and age verification
  • provision of gaming and betting services
  • processing financial transactions
  • compliance with AML, KYC, and regulatory obligations
  • fraud detection and prevention
  • responsible gaming monitoring and intervention
  • ensuring platform security and integrity
  • responding to customer support requests
  • fulfilling legal and regulatory reporting obligations
  • improving services, systems, and user experience

6. Legal Basis for Processing

We process Personal Data only where permitted under applicable law, including:

  • Contractual necessity: to provide Services and manage customer accounts
  • Legal obligation: to comply with MGA, AML, KYC, and other regulatory requirements
  • Legitimate interests: including fraud prevention, security, and service improvement
  • Consent: where required, such as for marketing communications

Where consent is used, it may be withdrawn at any time without affecting prior lawful processing.

7. Disclosure of Personal Data

Personal Data may be shared with third parties where necessary, including:

  • payment processors and financial institutions
  • identity verification and AML/KYC service providers
  • IT hosting, infrastructure, and cloud service providers
  • professional advisers (legal, audit, compliance)
  • regulatory and enforcement authorities, including the Malta Gaming Authority and FIAU where required by law

The Company does not sell Personal Data under any circumstances.

8. International Transfers

Where Personal Data is transferred outside the European Economic Area (EEA), appropriate safeguards are applied, including:

  • adequacy decisions by the European Commission, or
  • Standard Contractual Clauses (SCCs) or equivalent GDPR-approved mechanisms

9. Data Retention

Personal Data is retained only for as long as necessary for legal, regulatory, and operational purposes.

Retention periods are determined by:

  • AML and gaming regulatory requirements
  • contractual obligations
  • audit and dispute resolution needs

Once no longer required, Personal Data is securely deleted or anonymised.

Certain compliance records, including breach documentation, may be retained for a minimum of five (5) years where required.

10. Security of Personal Data

The Company maintains appropriate technical and organisational safeguards, including:

  • encryption of sensitive data
  • access control and authentication mechanisms
  • secure network and system monitoring
  • internal security policies and procedures
  • employee training on data protection and cybersecurity

These measures are regularly reviewed and updated to address evolving risks.

11. Rights of Individuals

Subject to applicable law, individuals have the right to:

  • access their Personal Data
  • correct inaccurate or incomplete data
  • request deletion where legally permissible
  • restrict processing
  • object to processing
  • request data portability
  • withdraw consent where applicable

Requests may be submitted to the Data Protection Officer.

Individuals may also lodge complaints with the Office of the Information and Data Protection Commissioner (Malta).

12. Personal Data Breach Handling

In the event of a Personal Data breach, the Company will:

  • identify and contain the incident
  • assess potential risks
  • implement corrective measures
  • notify the supervisory authority within 72 hours where required
  • notify affected individuals where there is a high risk
  • maintain detailed breach records for compliance purposes

13. Age Restrictions

The Services are strictly intended for individuals aged 18 years or older.

The Company does not knowingly collect Personal Data from minors. Any such data identified will be deleted and relevant accounts will be closed where appropriate.

14. Cookies and Similar Technologies

Cookies are used to support:

  • essential platform functionality
  • security and fraud prevention
  • analytics and performance monitoring
  • user experience improvements

Where required, cookie consent is obtained through a consent management tool.

15. Policy Updates

This Privacy Policy may be updated periodically to reflect legal, regulatory, or operational changes.

The most recent version will always be made available through the Company’s official website.

16. Governing Law

This Privacy Policy is governed by the laws of Malta and interpreted in accordance with the GDPR and applicable Maltese data protection legislation.