Boabet Privacy Policy

Document version: 3.6
Last updated: 27 April 2026

Blue Boulder Limited is responsible for deciding why and how personal data connected with Boabet is processed. This makes the Company the data controller for information collected through the website, mobile applications, account services, payments, games, customer support and related functions.

Personal data includes information that identifies a player directly or can be linked to that player. Depending on how the services are used, this may include a name, postal address, date of birth, account details, payment card information, transaction records, gaming activity, communications, device data and other information associated with the account.

This policy explains what information is handled, why it is processed, who may receive it, how long it may be kept and which rights are available to users. Processing is carried out under the data-protection rules that apply where the Company operates. The policy may be revised, and users will be informed when a material change is made.

About Us

Blue Boulder Limited forms part of a corporate group that includes Blue Boulder Live Limited. Companies within the group own or operate several gaming brands, including Boabet, Vera&John and InterCasino.

Certain account, compliance, product and marketing activities may involve another group company. Data may therefore be shared within the group for account administration, regulatory checks, fraud prevention, service analysis, product recommendations or communications accepted by the player.

Any group company acting for Blue Boulder Limited must follow the applicable instructions and safeguards. Registration with one brand does not automatically permit another independently operated group website to send direct marketing unless the user has registered there or otherwise provided valid permission.

How Do We Collect Your Personal Data?

Personal data is collected when a user chooses to create and use a Boabet account. Registration is voluntary, but some information is required before the Company can provide account-based services such as real-money games, deposits, withdrawals and customer support.

Information may be obtained through several sources:

  • Details entered during registration or later added to the account;
  • Identity, age and account-verification information;
  • Deposit, withdrawal and payment-method records;
  • Gaming history and use of slots, random-number-generator games or live casino services;
  • Messages, telephone calls, chat conversations and support requests;
  • Responses to research surveys conducted by the Company or an appointed research provider;
  • Website and mobile-application activity, including technical and device information;
  • Data supplied by fraud-prevention, verification, credit-reference or similar service providers;
  • Information voluntarily published by a user in a public area of the website; and
  • Cookie data, including IP address, browser, device, location-related and visit information.

Disclosure of Personal Information

Personal data may be disclosed within the corporate group where this supports the purposes described in this policy. It may also be supplied to processors that provide technology, verification, payment, analytics, customer-service, security, marketing or other operational services. Processors are permitted to handle the information only for the assigned service and under contractual duties intended to protect it.

The Company may also disclose data where:

  • A law, regulator, court, public authority or enforcement body requires it;
  • Disclosure is necessary to establish, exercise or defend legal rights;
  • Operation of the website is transferred to another group company;
  • Site operations are outsourced to an external provider;
  • A corporate financing, investment, restructuring, merger, purchase, sale or transfer is proposed or completed; or
  • Information must be reviewed during negotiations connected with such a transaction.

Recipients remain subject to appropriate privacy and security controls, and disclosure is limited to the relevant purpose.

Transferring Your Personal Data Outside the EEA

The Company states that it does not ordinarily transfer personal data outside the European Economic Area. If a future processing arrangement requires information to be transferred beyond the EEA, reasonable measures will be taken to preserve a level of protection consistent with applicable data-protection requirements and this Privacy Policy.

If a service provider, group company or other authorized recipient is located in a country with a different privacy framework, the Company will assess the arrangement and apply safeguards covering confidentiality, access, security and permitted use. An overseas recipient may not use the data independently for unrelated purposes.

Safety

Technical and organizational controls are used to reduce the risk of loss, alteration, misuse or unauthorized access. The security framework includes digital and physical perimeter measures, access controls, financial controls, operational checks and procedures connected with account security.

The Company is subject to oversight in jurisdictions where it holds gambling licences. External providers supporting security or identification must follow its instructions and safeguards.

No system can guarantee absolute protection. Users should keep credentials confidential, maintain accurate contact details and use available security settings. The Company’s responsibility for a compromise depends on the circumstances, including whether it resulted from the Company’s negligence.

Marketing

Marketing may be carried out by the Company, a group member or an appointed provider acting under its instructions. Where consent is required, communications follow the choices recorded for the account. Cookies may also support personalized on-site content based on general behaviour and preferences.

Promotional material may concern games, jackpots, campaigns, loyalty or VIP benefits, rewards and other Boabet offers. A user may separately agree to information about other group brands. Consent can be changed, withdrawn or limited by channel. Withdrawal stops future promotional use but does not prevent necessary account, transaction, security, legal or regulatory messages.

Marketing Communications from Our Website

Users can select whether Boabet may send promotional communications and which channels may be used. Available channels may include email, SMS, telephone calls, postal mail and application push notifications.

Preferences can be changed as follows:

  • Use the unsubscribe link in a promotional email or update account settings;
  • Reply with the STOP instruction to an eligible marketing SMS or change account settings;
  • Remove telephone marketing permission through account settings;
  • Disable postal marketing through account settings; and
  • Turn off push notifications in the device settings.

After email, SMS or telephone marketing is removed through account preferences, the change is expected to take effect within 72 hours. A postal-mail opt-out may require up to 28 days because material may already be scheduled or in distribution. These periods apply only to promotional messages; necessary account, transaction, security or legal notices may continue.

Marketing Communications from Other Group Gaming Sites

A player may choose to receive marketing relating to Boabet and other gambling websites owned by the same group. This does not give every group brand unrestricted permission to contact the player.

A group website with which the player has not registered will not independently send direct marketing solely because it belongs to the group. Blue Boulder Limited continues to control those communications unless another valid relationship and permission exist.

Preferences can be changed through Boabet account settings. Removing cross-brand consent does not affect account operation or required contractual, security or regulatory notices.

Social Media Marketing

Account information may be used to display relevant advertising or personalized group-brand content through third-party social-media platforms. The policy identifies platforms such as Facebook and Twitter as examples. These platforms operate under their own privacy terms, and users should review the settings and policies offered by the relevant provider.

When a user is signed in to Facebook, advertising tools may show tailored content. Facebook may provide information made available under the user’s settings, while the Company may supply data needed to select or measure an audience. Users can limit targeted advertising through the platform’s own advertising settings.

Cookies

Cookies are small text files stored through a browser or device. They help the website recognize a returning browser, maintain functions between pages, remember selected settings, protect account activity, understand site use and support content or advertising choices.

Cookie categories collect different data and use different legal grounds. Operational, regulatory and security cookies may be necessary for the service; analytics may rely on legitimate interests; and third-party marketing cookies require consent where applicable.

Blocking a category may reduce functionality, content availability or personalization. Cookie settings can be managed through the browser or mobile device.

Absolutely Necessary Cookies

Strictly necessary cookies support core navigation, account access, page-to-page interaction and delivery of game content in a form suitable for the user’s device. They may process information such as username, password-related session data and browser settings.

They may also support regulatory controls, detect false logins, reduce fraud and prevent prohibited multiple accounts. Disabling them may interrupt page loading, login sessions or access to content, meaning some account or gaming functions may not operate correctly.

Analytical Cookies

Analytical cookies help measure traffic, game use, repeat visits, technical errors and general website performance. The information supports testing, fault detection and service improvement.

Third-party analytics may process IP address, username-related identifiers, approximate location, device, browser and visit frequency. The Company receives anonymized, aggregated reporting rather than an individually identifiable player record.

Blocking analytical cookies does not prevent site access or gameplay, but it may reduce the Company’s ability to identify common errors and compare service performance.

Marketing, Advertising and Behavioural Cookies

Marketing cookies select relevant advertisements, limit repetition and measure campaign performance. Providers may process IP address, online identifiers, device, browser, approximate location and visit frequency, then return aggregated campaign reporting.

Approved third parties may also use behavioural cookies to understand browsing activity and select online advertising. These profiles are not intended to connect the cookie with a player’s name, postal address or similar direct details.

Blocking these cookies does not prevent use of the website’s core functions, but the advertising displayed may be less relevant to the user’s interests.

Third-Party Cookies Used on the Website

The policy identifies the following third-party tools and cookie categories:

  • Google Analytics, Google Tag Manager, Google Optimize and Google Search Console for analytics;
  • Google DoubleClick, Google Ads and Xtremepush for marketing or advertising;
  • MediaMath and DataXu for behaviour-based advertising; and
  • Facebook for behaviour-based advertising.

Third-party services operate under their own technical systems and privacy arrangements. Users can restrict non-essential cookies through the available consent controls, browser settings or device settings.

Manage Your Cookie Settings

Cookie permissions can be reviewed through the browser settings used to access Boabet. The policy provides management guidance for Internet Explorer, Firefox, Google Chrome and Safari. On a mobile device, users can search the device or browser settings for cookie controls.

Browsers may allow all cookies to be blocked, third-party cookies to be rejected or stored files to be deleted. Deleting cookies may sign the user out, reset preferences or require earlier selections to be made again.

General guidance is available through AboutCookies.org and aboutads.info/choices. Browser controls are separate from Boabet marketing preferences, so both may need to be updated when changing advertising or communication choices.

Retention of Personal Information

Personal data is retained for the period needed to provide services and satisfy legal, licensing and regulatory duties. The standard period stated in this policy is at least five years after account closure or, where relevant, after the user’s last contact with the Company.

Data may be deleted earlier where no continuing operational, contractual, legal or regulatory reason exists. Some records may remain longer for legal claims, investigations, regulatory requirements or fraud-prevention purposes.

Where a person has asked to be prevented from accessing the website, mobile applications or services, information needed to enforce that restriction will be retained for at least seven years. Keeping that record allows the Company to recognize and apply the restriction rather than treating the person as a new customer.

Updating Your Personal Information

Users can update personal information through their account. Account details should be corrected promptly when a name, address, telephone number, email address, payment information or other relevant detail changes.

Accurate information supports account administration, communication, payments, verification, security and regulatory checks. Inconsistent or outdated details may delay a transaction or require additional evidence before an account action can be completed.

Updating an account does not necessarily erase earlier records. Previous details may remain in transaction, security, compliance or audit records where retention is required. If a field cannot be changed directly, the user should contact the Company through the support route available on the website and provide the information needed to verify the request.

Your Rights

Subject to applicable law, users may have rights concerning the personal data held about them. These may include the right to:

  • Request access to personal data;
  • Receive certain information in a machine-readable format;
  • Correct inaccurate or incomplete data;
  • Withdraw consent where consent is the basis for processing;
  • Request deletion where the data is no longer needed or another legal condition for deletion applies;
  • Object to processing based on legitimate interests;
  • Object to direct marketing and related profiling;
  • Request meaningful information about decisions made solely through automated means; and
  • Complain to the relevant national data-protection authority.

These rights are not absolute. Processing may continue where another legal duty applies or compelling lawful grounds override an objection. A request may be refused or only partly fulfilled where permitted by applicable law.

The Company may require identity evidence and clarification before acting. It aims to respond within one month after the requester’s identity has been verified. Repeated or unreasonable requests may not receive a response. Rights can be exercised through the contact route provided with the website or this Privacy Policy.