How c2222 Collects, Uses, and Protects Your Personal Data
At c2222, your privacy is a core commitment — not an afterthought. This Privacy Policy explains in clear, formal terms exactly what personal data we collect when you use our platform, the lawful basis on which we process it, how long we retain it, and the rights you hold over your own information. We encourage every member to read this document in full before registering an account.
Six Privacy Principles That Guide Every c2222 Decision
These principles underpin the full Privacy Policy that follows. They represent the values c2222 holds on data handling and the standards every member can expect when trusting us with their personal information.
c2222 collects only the personal data that is strictly necessary to operate the platform, verify your identity, process your transactions, and meet legal obligations. We do not collect data for its own sake. If a piece of information is not needed to serve you or comply with regulation, we do not request it.
c2222 will never sell, rent, or trade your personal data to third-party marketers, data brokers, or advertising networks. Your information exists solely to enable your account, secure your transactions, and deliver the c2222 service. Any sharing with third parties is strictly limited to the operational partners described in this policy.
All data transmitted between your device and the c2222 platform is encrypted using 256-bit SSL/TLS protocols. Sensitive fields such as payment details and identity documents are stored with additional encryption at rest. Access to personal data within c2222 is restricted to authorised personnel on a strict need-to-know basis.
You have the right to access, correct, export, and in certain circumstances request the deletion of your personal data held by c2222. These rights can be exercised at any time by contacting our support team. We will acknowledge your request within 48 hours and aim to fulfil it within 30 calendar days from receipt.
c2222 does not retain your data indefinitely. Retention periods are set in accordance with legal obligations and legitimate business necessity. Transaction records are retained for a minimum of 5 years to comply with anti-money laundering requirements. Account data is deleted or anonymised within 90 days of confirmed account closure.
If we make material changes to this Privacy Policy, we will notify you via the email address registered on your c2222 account at least 7 days before the changes take effect. We will never make substantive changes silently. The current version of this policy is always available at c2222.io/privacy-policy.
This Privacy Policy ("Policy") describes how c2222 ("c2222", "we", "us", "our") collects, processes, stores, and shares personal data when you access or use the c2222 platform at c2222.io and any associated mobile or web applications (collectively, "the Platform"). This Policy applies to all registered members, prospective members who browse the Platform, and any other individual whose personal data we process in connection with the c2222 service.
By accessing the Platform or registering a c2222 account, you acknowledge that you have read and understood this Policy and consent to the collection and processing of your personal data as described herein. This Policy forms part of the binding agreement between you and c2222 and should be read alongside our Terms & Conditions and Responsible Gaming policy.
This Policy applies to personal data collected from players across Bangladesh, including residents of Dhaka, Chittagong, Sylhet, Khulna, Rajshahi, Barisal, Rangpur, Mymensingh, and Cox's Bazar, as well as Bangladeshi players accessing the Platform from abroad.
For the purposes of this Policy, c2222 acts as the data controller in respect of the personal data it collects directly from members and Platform visitors. As data controller, c2222 determines the purposes for which personal data is processed and the means by which it is processed.
Where c2222 engages third-party service providers to process personal data on its behalf (for example, KYC verification providers, payment processors, or game platform providers), those third parties act as data processors under instructions from c2222. c2222 remains responsible for ensuring that such processors handle your data lawfully and securely.
For any questions regarding how c2222 processes your personal data, or to exercise any of your data rights described in this Policy, please contact our data support team at: [email protected] (plain text — not a clickable link).
c2222 collects the following categories of personal data, depending on your interaction with the Platform:
| Category | Data Types | When Collected |
|---|---|---|
| Identity Data | Full legal name, date of birth, gender, nationality, NID / passport number | Registration & KYC verification |
| Contact Data | Email address, mobile phone number, residential address | Registration & account updates |
| Financial Data | bKash / Nagad / Rocket account numbers, bank account details, Visa/Mastercard last 4 digits, transaction history, deposit and withdrawal amounts | Deposit, withdrawal & payment processing |
| Verification Documents | Copies of government-issued ID, selfie photographs, proof of address documents | KYC verification & enhanced due diligence |
| Gameplay Data | Game session logs, bet amounts, win/loss records, game preferences, bonus usage history | During Platform use |
| Technical Data | IP address, device type, browser type and version, operating system, session timestamps, referral URL | Automatically on Platform access |
| Communications Data | Live chat transcripts, email correspondence, support ticket records | When you contact support |
| Responsible Gaming Data | Self-exclusion requests, deposit limit settings, session limit preferences, reality-check configurations | When responsible gaming tools are activated |
c2222 does not collect sensitive personal data such as racial or ethnic origin, political opinions, religious beliefs, trade union membership, genetic data, or health data, except where health or behavioural data is provided voluntarily in the context of a responsible gaming or self-exclusion request, in which case it is processed solely to fulfil that request.
c2222 collects personal data through the following channels:
- Directly from you: When you register an account, complete KYC verification, make a deposit or withdrawal, contact our support team, respond to a survey, or participate in a promotional offer.
- Automatically through the Platform: When you access c2222.io, our systems automatically collect technical data including your IP address, device identifiers, browser type, and session activity through server logs, cookies, and similar tracking technologies (see Section 8 — Cookies & Tracking).
- From third-party providers: Where you connect to the Platform via a third-party authentication service, or where our KYC and fraud-prevention partners share verification outcomes with us to confirm your identity. c2222 may also receive data from payment providers (bKash, Nagad, Rocket, Upay, Visa, Mastercard) to confirm the status of financial transactions.
- From publicly available sources: In limited circumstances relevant to fraud prevention or compliance, c2222 may consult publicly available records including sanction lists and politically exposed persons (PEP) databases.
c2222 processes your personal data only where a recognised lawful basis exists. The primary bases on which c2222 relies are as follows:
- Contractual necessity: Processing your identity data, contact data, and financial data is necessary to register your account, process your deposits and withdrawals, and deliver the c2222 gaming and betting service you have contracted for. Without this processing, c2222 cannot provide the service.
- Legal obligation: c2222 is required by applicable anti-money laundering (AML) regulations, know-your-customer (KYC) requirements, and responsible gaming obligations to verify your identity, retain financial records, and monitor for suspicious activity. Processing necessary to fulfil these obligations is carried out on the basis of legal obligation.
- Legitimate interests: c2222 processes technical data (IP addresses, device identifiers, session logs) and gameplay data on the basis of its legitimate interest in detecting and preventing fraud, ensuring platform security, preventing bonus abuse, and improving the c2222 service. Where legitimate interests are relied upon, c2222 has assessed that its interests are not overridden by your fundamental rights and freedoms.
- Consent: Where c2222 sends you optional marketing communications (promotional offers, bonus alerts, tournament notifications) by email or SMS, this is done on the basis of your explicit consent provided at registration or subsequently via your account preferences. You may withdraw this consent at any time by updating your notification preferences or contacting [email protected].
c2222 uses the personal data we collect for the following specific purposes:
- To create and manage your c2222 account, including verifying your identity and age (21+ requirement) at registration and during ongoing KYC reviews.
- To process deposits and withdrawals via your chosen payment method (bKash, Nagad, Rocket, Upay, Visa, Mastercard) and to maintain accurate transaction records.
- To provide access to the full c2222 game library including live casino tables, cricket betting markets, slots, and table games.
- To operate the c2222 Coin loyalty programme and the VIP membership tier, including calculating rewards points and processing tier upgrades.
- To detect, investigate, and prevent fraud, money laundering, multiple-account abuse, bonus misuse, and any other prohibited conduct described in our Terms & Conditions.
- To personalise your Platform experience by surfacing game recommendations, relevant promotions, and content based on your gameplay history and preferences — only where you have not opted out of personalisation.
- To send you mandatory service communications including account security alerts, transaction confirmations, KYC requests, and material policy updates. These communications cannot be opted out of while your account is active.
- To send you optional marketing communications (bonus offers, tournament invitations, seasonal promotions related to events such as BPL, IPL, T20 World Cup, Eid, Pohela Boishakh, Victory Day) where you have given consent.
- To operate our responsible gaming programme, including administering self-exclusion requests, enforcing deposit limits, and monitoring for signs of problem gambling behaviour.
- To respond to your support enquiries via live chat, email, or ticket, and to maintain a record of support interactions for quality assurance purposes.
- To comply with applicable law, including AML obligations, and to respond to lawful requests from regulatory or law enforcement authorities.
c2222 does not sell your personal data. We share personal data only in the following limited circumstances and only to the extent necessary for the stated purpose:
- KYC and identity verification providers: c2222 shares identity documents and personal details with regulated third-party KYC service providers to verify your identity and age in compliance with our legal obligations. These providers act as data processors under contractual obligations to handle your data securely and solely for the KYC purpose.
- Payment processors: To facilitate deposits and withdrawals, c2222 shares the minimum necessary financial data with our payment partners (bKash, Nagad, Rocket, Upay, Dutch-Bangla Bank, Visa/Mastercard networks). These partners are independently regulated financial institutions with their own data protection obligations.
- Game platform providers: Some games on the c2222 Platform are delivered by third-party studios including Pragmatic Play, Evolution Gaming, NetEnt, Microgaming, Spribe, and Ezugi. These providers may receive a session token and a pseudonymous player identifier to initialise your game session. They do not receive your full name, payment details, or identity documents.
- Fraud and security services: c2222 may share technical data (IP addresses, device fingerprints) with fraud prevention and cybersecurity service providers to protect the Platform and its members.
- Legal and regulatory authorities: c2222 will disclose personal data to law enforcement agencies, regulatory bodies, or courts where required to do so by applicable law, a lawful court order, or a legitimate regulatory request. c2222 will, where legally permitted, notify you of such a request.
- Business transfers: In the event of a merger, acquisition, restructuring, or sale of all or part of c2222's business, your personal data may be transferred to the acquiring entity as part of that transaction. You will be notified of any such transfer and the applicable privacy terms of the new entity before the transfer takes effect.
All third-party data processors engaged by c2222 are subject to written data processing agreements that require them to: (a) process data only on c2222's documented instructions; (b) implement appropriate technical and organisational security measures; (c) not sub-process data without c2222's prior written consent; and (d) return or delete data upon termination of the engagement.
c2222 uses cookies and similar tracking technologies (including local storage, session storage, and pixel tags) on the Platform to deliver a functional and personalised experience. The categories of cookies we use are as follows:
| Cookie Type | Purpose | Can Be Disabled? |
|---|---|---|
| Strictly Necessary | Essential for the Platform to function: session management, authentication tokens, security tokens, load balancing | No — required for the service to operate |
| Functional | Remembers your preferences: language selection, game lobby layout, last-visited game category, responsible gaming settings | Yes — disabling may reduce personalisation |
| Analytics | Aggregated, anonymised data on how members navigate the Platform, which features are most used, and where technical errors occur — used to improve the service | Yes — opt out via account preferences |
| Security | Device fingerprinting and behavioural signals used by our fraud prevention systems to detect suspicious login attempts and account takeover attempts | No — required for account protection |
c2222 does not use third-party advertising cookies or cross-site tracking cookies. You will not be tracked across external websites by c2222 cookies. You may manage your cookie preferences through your browser settings; however, disabling strictly necessary cookies will prevent you from logging in and using core Platform features.
c2222 retains personal data only for as long as is necessary for the purposes for which it was collected, or as required by applicable law. The following retention schedule applies:
- Account and identity data: Retained for the duration of your active account, plus 5 years following account closure, in compliance with anti-money laundering record-keeping requirements.
- Transaction and financial records: Retained for a minimum of 5 years from the date of each transaction, in compliance with applicable financial regulations.
- KYC documentation (ID copies, selfies, proof of address): Retained for the duration of your active account, plus 5 years following account closure. Original documents are deleted promptly once verification is confirmed; only the verification outcome and a secure reference are retained during the active account period.
- Gameplay and betting records: Retained for 3 years from the date of the session or wager, or for the duration of any related dispute or investigation, whichever is later.
- Support communications: Retained for 2 years from the date of the last interaction in the relevant support thread.
- Marketing consent records: Retained for the duration of your active account plus 2 years, to demonstrate your consent history if required.
- Technical / log data (IP logs, session logs): Retained for 12 months from collection, after which they are automatically purged or anonymised.
- Self-exclusion and responsible gaming records: Retained permanently or for the full duration of the self-exclusion period plus 5 years, as these records are operationally necessary to enforce self-exclusion requests and prevent re-registration.
Upon expiry of the relevant retention period, c2222 will securely delete or irreversibly anonymise the data so that it can no longer be linked to you as an individual.
As a c2222 member, you hold the following rights in respect of your personal data. To exercise any of these rights, contact us at [email protected] with the subject line "Data Rights Request" and a description of your request. We will acknowledge your request within 48 hours and respond substantively within 30 calendar days (Bangladesh Standard Time, UTC+6).
- Right of Access: You may request a copy of all personal data c2222 holds about you, along with information about how it is processed, the legal basis for processing, retention periods, and any third parties with whom it has been shared.
- Right to Rectification: If any personal data we hold about you is inaccurate or incomplete, you have the right to request that we correct or complete it without undue delay.
- Right to Erasure ("Right to Be Forgotten"): In certain circumstances — for example, where data is no longer necessary for the purpose it was collected, or where you have withdrawn consent and no other lawful basis applies — you may request deletion of your personal data. Note that erasure requests cannot be fulfilled where retention is required by legal obligation (for example, AML record-keeping requirements).
- Right to Restriction of Processing: You may request that c2222 restricts the processing of your data while a dispute about its accuracy or lawfulness is resolved.
- Right to Data Portability: Where processing is based on your consent or on contract, and is carried out by automated means, you may request a copy of your personal data in a structured, commonly used, machine-readable format (such as JSON or CSV) for transfer to another service provider.
- Right to Object: You have the right to object to processing carried out on the basis of c2222's legitimate interests. c2222 will cease such processing unless it can demonstrate compelling legitimate grounds that override your interests. You have an unconditional right to object to processing for direct marketing purposes at any time.
- Right to Withdraw Consent: Where processing is based on your consent (for example, marketing communications), you may withdraw that consent at any time. Withdrawal of consent does not affect the lawfulness of processing carried out before the withdrawal.
c2222 implements a comprehensive set of technical and organisational security measures to protect your personal data against unauthorised access, accidental loss, destruction, or disclosure. These measures include:
- Encryption in transit: All data exchanged between your browser or device and the c2222 Platform is encrypted using TLS 1.2 or higher (256-bit SSL). This applies to login, registration, deposits, withdrawals, and all API communications.
- Encryption at rest: Sensitive data fields including identity document references, payment method details, and KYC outcomes are encrypted at rest using AES-256 encryption on c2222's database infrastructure.
- Access controls: Access to systems containing personal data is restricted to authorised c2222 personnel on a strict need-to-know basis, enforced through role-based access controls and multi-factor authentication for administrative systems.
- Penetration testing: c2222 conducts regular third-party security assessments and penetration tests to identify and remediate vulnerabilities in the Platform and its underlying infrastructure.
- Incident response: c2222 maintains a documented data breach response procedure. In the event of a security incident that poses a risk to your personal data, c2222 will notify affected members within 72 hours of becoming aware of the breach, including details of the nature of the incident, the data affected, and the steps being taken to mitigate harm.
While c2222 employs industry-standard security measures, no electronic system is entirely immune to attack. You are responsible for maintaining the security of your own account credentials. If you suspect your account has been accessed without your authorisation, contact [email protected] immediately.
c2222 operates exclusively as an adults-only platform. Registration, deposit, and participation in any real-money gaming or betting activity is strictly prohibited for persons under the age of 21. c2222 does not knowingly collect personal data from any person under the age of 21.
If you are a parent or guardian and believe that a person under 21 in your care has provided personal data to c2222 or registered an account on the Platform, please contact us immediately at [email protected] with the subject line "Minor Account Report". Upon receipt of a verified report, c2222 will immediately suspend the account, void any associated balances or wagers, and permanently delete all personal data associated with that account.
We encourage parents and guardians to make use of parental control software to restrict access to online gambling platforms for persons under 21 in their household. c2222 supports responsible parenting tools and will cooperate fully with any parental safeguarding request received through the appropriate channel.
c2222 reserves the right to update or modify this Privacy Policy at any time. We distinguish between two types of changes:
- Material changes — changes that significantly affect your rights, the categories of data we collect, the purposes for which we use it, or the third parties with whom we share it — will be communicated to you via the email address registered on your c2222 account at least 7 days before they take effect. A prominent notice will also be displayed on the Platform. Continued use of the Platform after the effective date of a material change constitutes your acceptance of the revised Policy.
- Non-material changes — corrections to typographical errors, clarifications that do not alter substantive meaning, or updates to reflect changes in our operational structure that do not affect your rights — may take effect immediately without advance notice.
The current version of this Privacy Policy is always available at c2222.io/privacy-policy. The "Last Updated" date at the top of the document reflects the date of the most recent revision. We recommend checking this page periodically to stay informed of any updates.
If you have any questions, concerns, or requests relating to this Privacy Policy or the way c2222 handles your personal data, please contact us using the details below:
- Email: [email protected] (plain text — not a clickable link)
- Subject Line for Data Requests: "Data Rights Request" or "Privacy Enquiry"
- Support Hours: 24 hours a day, 7 days a week, Bangladesh Standard Time (UTC+6)
- Response Commitment: Acknowledgement within 48 hours; substantive response within 30 calendar days
For urgent security matters — including suspected unauthorised account access, data breaches affecting your personal information, or reports of a minor accessing the Platform — please mark your email subject line as "URGENT: Security" for priority handling by our security team.
Your Data Is Safe With c2222 — Now Explore the Platform
Now that you understand how c2222 protects your privacy, you are ready to enjoy Bangladesh's most trusted online casino experience. Browse our game categories, review the FAQ, or head to the casino lobby.