Zowin card game

Privacy Notice and Data Protection Statement

1. Overview

MOBILE INCORPORATED Limited (the “Company”, “we”, “us”, or “our”) is committed to safeguarding the privacy and Personal Data of individuals who access or use our Services.

This Privacy Notice explains how we collect, use, store, disclose, and protect Personal Data when you interact with our websites, mobile applications, gaming platform, and related services (collectively, the “Services”).

By using the Services, you acknowledge and agree that your Personal Data will be processed in accordance with this Notice and applicable data protection laws.

The Company processes Personal Data in compliance with:

  • Regulation (EU) 2016/679 (General Data Protection Regulation – “GDPR”)
  • the Malta Data Protection Act (Chapter 586 of the Laws of Malta)
  • applicable Malta Gaming Authority (“MGA”) regulatory obligations, including AML, responsible gaming, and player protection requirements

2. Data Controller Identification

MOBILE INCORPORATED Limited acts as the Data Controller for all Personal Data processed through the Services.

Registered Office:

Elite Business Centre, Trejqa Ta’ Box Box, Msida MSD1840, Malta

Company Registration Number: C 84149

Data Protection Officer (DPO)

Email: legal@zowin.vet

Address: Elite Business Centre, Trejqa Ta’ Box Box, Msida MSD1840, Malta

The Data Protection Officer is responsible for overseeing compliance with applicable data protection legislation and handling privacy-related enquiries.

3. Data Protection Framework

The Company processes Personal Data in accordance with GDPR principles, ensuring that:

  • Lawfulness, fairness, transparency: data is processed in a lawful and transparent manner
  • Purpose limitation: data is collected for specific, explicit, and legitimate purposes
  • Data minimisation: only necessary data is collected and processed
  • Accuracy: Personal Data is kept accurate and updated where necessary
  • Storage limitation: data is retained only for as long as required
  • Integrity and confidentiality: appropriate security measures are applied
  • Accountability: compliance with data protection obligations can be demonstrated

4. Categories of Personal Data Collected

We may collect and process the following categories of Personal Data:

Identity Information

  • full name
  • date of birth
  • nationality
  • gender

Verification and Compliance Data

  • government-issued identification documents
  • proof of address
  • source of funds and/or source of wealth information (where required)

Contact Information

  • email address
  • telephone number
  • residential address

Account and Usage Data

  • login credentials
  • account activity and gaming history
  • account settings, limits, and preferences
  • transaction history

Financial Data

  • payment method information
  • deposits and withdrawals
  • payment transaction records

Technical Data

  • IP address
  • device identifiers
  • browser and operating system details
  • usage logs and interaction data

Communication Data

  • customer support correspondence
  • responsible gaming interactions
  • compliance-related communications

Certain categories of data may be subject to enhanced security controls due to regulatory sensitivity.

5. Purposes of Processing

Personal Data is processed for the following purposes:

  • registering and managing user accounts
  • verifying identity, age, and eligibility
  • providing gaming and betting services
  • processing deposits, withdrawals, and payments
  • complying with AML, KYC, and regulatory obligations
  • monitoring for fraud, abuse, and suspicious activity
  • ensuring responsible gaming and player protection
  • maintaining platform security and system integrity
  • responding to customer enquiries and requests
  • fulfilling legal and regulatory reporting obligations
  • improving Services and user experience

6. Legal Basis for Processing

We process Personal Data under one or more of the following legal bases:

  • Contractual necessity: to provide Services and manage user accounts
  • Legal obligation: to comply with AML, KYC, MGA, and other regulatory requirements
  • Legitimate interests: including fraud prevention, security, and service improvement
  • Consent: where required, such as for marketing communications

Where consent is relied upon, it may be withdrawn at any time without affecting prior lawful processing.

7. Data Sharing and Disclosure

Personal Data may be disclosed to third parties where necessary, including:

  • payment processors and financial institutions
  • identity verification and AML service providers
  • IT infrastructure, hosting, and cloud service providers
  • professional advisers (legal, audit, compliance)
  • regulatory authorities, including the Malta Gaming Authority and FIAU where required

The Company does not sell Personal Data to third parties.

8. International Transfers

Where Personal Data is transferred outside the European Economic Area (EEA), the Company ensures appropriate safeguards are in place, such as:

  • European Commission adequacy decisions, or
  • Standard Contractual Clauses (SCCs) or equivalent safeguards under GDPR

9. Data Retention

Personal Data is retained only for as long as necessary to fulfil legal, regulatory, and operational requirements.

Retention periods are based on:

  • AML and gaming regulatory obligations
  • contractual requirements
  • dispute resolution and audit obligations

When no longer required, Personal Data is securely deleted or anonymised.

Certain compliance records, including breach documentation, may be retained for at least five (5) years where required.

10. Security Measures

The Company implements appropriate technical and organisational measures to protect Personal Data, including:

  • encryption of sensitive information
  • access control mechanisms
  • secure system architecture and monitoring
  • internal data protection policies
  • staff training on privacy and security

Security controls are reviewed periodically and updated where necessary.

11. Data Subject Rights

Subject to applicable law, individuals may exercise the following rights:

  • right of access to Personal Data
  • right to rectification
  • right to erasure (where legally applicable)
  • right to restriction of processing
  • right to object to processing
  • right to data portability
  • right to withdraw consent (where applicable)

Requests should be submitted to the Data Protection Officer.

Individuals also have the right to lodge a complaint with the Office of the Information and Data Protection Commissioner (Malta).

12. Personal Data Breaches

In the event of a Personal Data breach, the Company will:

  • identify and contain the incident
  • assess risks to affected individuals
  • implement corrective and preventive measures
  • notify the competent supervisory authority within 72 hours where required
  • notify affected individuals where the breach presents a high risk
  • document and retain breach records for compliance purposes

13. Minors

The Services are strictly intended for individuals aged 18 years or older.

The Company does not knowingly collect Personal Data from minors. Any such data identified will be deleted and related accounts will be closed where appropriate.

14. Cookies and Tracking Technologies

Cookies and similar technologies are used to support:

  • essential website functionality
  • security and fraud prevention
  • performance and analytics
  • user experience improvements

Where required, cookie consent is obtained through an appropriate consent management tool.

15. Policy Updates

This Privacy Notice may be updated periodically to reflect changes in legal, regulatory, or operational requirements.

The latest version will always be published on the Company’s official website and will replace any prior versions.

16. Governing Law

This Privacy Notice is governed by the laws of Malta and interpreted in accordance with the GDPR and applicable Maltese data protection legislation.