Our Commitment
Privacy at the Core of dbajie
These cards highlight the six pillars of our approach to data protection. The full legal detail for each area is contained in the sections below.
Minimal Data Collection
dbajie collects only the personal data that is strictly necessary to operate your account, process payments, and comply with legal obligations. We do not collect data for its own sake or sell it to data brokers.
256-bit SSL Encryption
All data transmitted between your device and the dbajie platform is protected by industry-standard 256-bit SSL encryption. Your personal details and payment information are never transmitted in plain text.
No Sale of Personal Data
dbajie does not sell, rent, or trade your personal data to any third party for marketing or commercial purposes. Your information is used solely to provide and improve the dbajie platform experience.
Strict Access Controls
Access to your personal data within dbajie is restricted to staff members who require it to fulfil their role. All staff with data access are bound by confidentiality obligations and receive regular data protection training.
Your Rights Respected
You have the right to access, correct, export, and request deletion of your personal data at any time. dbajie has a dedicated process for handling data subject requests, with a target response time of 30 days.
Breach Notification
In the unlikely event of a data breach affecting your personal information, dbajie will notify all affected players promptly and take all necessary remediation steps to protect your data and prevent further exposure.
1. Information We Collect
When you register for and use a dbajie account, we collect certain categories of personal data in order to provide you with a safe, compliant, and functional platform experience. The categories of data we collect, and the context in which each is collected, are set out below.
1.1 Registration Data
When you create a dbajie account, we collect the following information directly from you:
- Your full legal name as it appears on your official identification document.
- A valid email address to which you have sole access.
- Your Bangladesh mobile phone number.
- Your date of birth (used to verify that you are 18 years of age or older).
- A username and encrypted password of your choosing.
- Your residential address in Bangladesh.
1.2 Identity Verification (KYC) Data
As part of our Know Your Customer (KYC) programme, we may request copies of official documents to verify your identity and age. Documents we may collect include:
- Bangladesh National Identity Card (NID) — front and back.
- Valid passport (photo page).
- Bangladesh driving licence.
- Proof of residential address (utility bill, bank statement, or official correspondence dated within the past three months).
- Proof of payment method ownership (screenshot of bKash, Nagad, or Rocket account registered in your name).
KYC documents are stored securely and are handled in strict accordance with the provisions of this Privacy Policy. They are not shared with third parties except where required by law.
1.3 Financial Transaction Data
When you make deposits or withdrawals, we collect transactional data necessary to process and record the financial activity on your account:
- Payment method type (bKash, Nagad, Rocket, Upay, Visa, Mastercard).
- Transaction amount in Bangladeshi Taka (৳).
- Transaction date, time (Bangladesh Standard Time, UTC+6), and reference number.
- Payment account identifiers (mobile number for MFS providers, last four digits for card payments).
dbajie does not store full card numbers. Card payment data is handled exclusively by PCI-DSS compliant payment processing partners.
1.4 Usage and Platform Data
While you use the dbajie platform, we automatically collect certain technical and behavioural data to ensure platform performance, security, and regulatory compliance:
| Data Type | Examples | Purpose |
|---|---|---|
| Device & Browser Data | Device type, OS version, browser type, screen resolution | Platform compatibility, fraud prevention |
| IP Address | IPv4 / IPv6 address at time of login | Geolocation compliance, security monitoring |
| Session Data | Login timestamps, session duration, pages visited | Responsible gaming monitoring, security |
| Betting & Game History | Games played, bet amounts, outcomes, bonus usage | Account records, dispute resolution, AML compliance |
| Communication Records | Live chat logs, support email correspondence | Customer service quality, dispute resolution |
1.5 Data We Do Not Collect
dbajie does not collect or process the following categories of sensitive personal data: racial or ethnic origin, political opinions, religious beliefs, trade union membership, genetic data, biometric data (beyond document photographs submitted for KYC), health data (except where voluntarily disclosed in connection with a responsible gaming request), or sexual orientation. If you voluntarily disclose any such information — for example, when contacting support regarding a health-related self-exclusion request — it will be treated with the highest level of confidentiality and used only for the purpose for which it was disclosed.
2. How We Use Your Data
The personal data collected by dbajie is used exclusively for the purposes described in this section. We do not use your data for purposes that are incompatible with those stated here, and we do not use automated decision-making processes that produce legal or similarly significant effects on players without human oversight.
2.1 Account Management and Service Delivery
The primary use of your personal data is to open and maintain your dbajie account and to deliver the services you have requested. This includes:
- Processing your registration and verifying your identity and age.
- Enabling you to deposit, wager, and withdraw funds in Bangladeshi Taka via your chosen payment method.
- Providing access to casino games, live dealer tables, sports betting markets, and other platform features.
- Sending transactional communications such as deposit confirmations, withdrawal notifications, and account security alerts.
- Responding to your support requests via live chat or email.
2.2 Legal and Regulatory Compliance
dbajie is obligated to process certain categories of personal data to fulfil legal duties, including:
- Age verification to ensure that no player under the age of 18 accesses the platform.
- Anti-Money Laundering (AML) monitoring and reporting of suspicious financial activity where required by applicable law.
- Retention of financial transaction records for the statutory minimum period.
- Responding to lawful requests from courts, law enforcement agencies, or regulatory authorities.
- Enforcing self-exclusion requests and implementing responsible gaming restrictions.
2.3 Security and Fraud Prevention
We analyse platform usage data — including IP addresses, device fingerprints, login patterns, and betting behaviour — to detect and prevent fraud, account takeover attempts, bonus abuse, and other forms of financial crime. Where suspicious activity is identified, the relevant account may be suspended pending investigation, and data may be shared with law enforcement where legally required.
2.4 Platform Improvement and Analytics
Aggregated, anonymised usage data is used to understand how players interact with the dbajie platform, identify areas for improvement, and develop new features. This analysis does not involve processing personal data in a form that identifies individual players, and the output is used solely for internal product development purposes.
2.5 Marketing Communications
With your explicit consent at the time of registration (or subsequently updated through your account settings), dbajie may send you promotional communications about new games, bonus offers, seasonal promotions, and platform updates. You may withdraw consent for marketing communications at any time by updating your notification preferences in your account settings or by contacting support. Withdrawal of marketing consent does not affect the processing of your data for account management, legal compliance, or security purposes.
3. Data Sharing & Third Parties
dbajie does not sell, rent, or trade your personal data to any third party. However, in order to operate the platform and comply with legal obligations, we share certain categories of personal data with a limited set of trusted third-party service providers and, in specific circumstances, with authorities. All third-party data sharing is governed by data processing agreements that require third parties to protect your data to a standard equivalent to our own.
3.1 Payment Processing Partners
To process deposits and withdrawals, dbajie shares relevant transaction data with your selected payment service provider. The data shared is limited to what is necessary to complete the transaction — typically your payment account identifier and the transaction amount. The following payment partners are currently integrated with the dbajie platform:
- bKash — mobile financial services provider, Bangladesh.
- Nagad — mobile financial services provider, Bangladesh.
- Rocket (Dutch-Bangla Bank) — mobile banking service, Bangladesh.
- Upay — mobile financial services provider, Bangladesh.
- Visa and Mastercard — international card payment networks (processed via our PCI-DSS compliant payment gateway partner).
3.2 Game Software Providers
Casino games and live dealer tables on dbajie are powered by third-party software providers including Evolution Gaming, Ezugi, Pragmatic Play, NetEnt, Microgaming, Play'n GO, Habanero, and Spribe. These providers may receive anonymised session identifiers or game-specific data necessary to deliver the game experience, settle bets, and audit game outcomes. They do not receive your full personal profile.
3.3 Identity Verification and KYC Providers
To streamline the KYC verification process, dbajie may use trusted third-party identity verification service providers. These providers process only the data necessary for document verification and age confirmation, and are contractually prohibited from using your data for any other purpose.
3.4 Legal and Regulatory Authorities
dbajie will disclose personal data to law enforcement agencies, courts, regulatory bodies, or other government authorities where required to do so by applicable law, a court order, or a legitimate legal process. In all cases, we disclose only the minimum data necessary to satisfy the legal obligation. Where legally permissible, we will notify you of any such disclosure.
3.5 No Third-Party Marketing Sharing
Your personal data is never shared with third-party advertising networks, data brokers, social media platforms, or any other party for the purpose of targeted advertising or commercial profiling. The dbajie platform does not integrate third-party advertising technologies that track your behaviour across other websites.
5. Data Retention & Storage
dbajie retains personal data only for as long as it is necessary to fulfil the purposes for which it was collected, to meet legal and regulatory obligations, and to resolve any outstanding disputes. This section sets out the standard retention periods for each major category of personal data.
5.1 Retention Periods
| Data Category | Retention Period | Basis for Retention |
|---|---|---|
| Account registration data | Duration of active account + 5 years after closure | Legal obligation, dispute resolution |
| KYC identity documents | Duration of active account + 5 years after closure | AML legal obligation |
| Financial transaction records | 7 years from date of transaction | Financial record-keeping obligation |
| Betting and game history | 5 years from date of activity | Regulatory compliance, dispute resolution |
| Customer support communications | 3 years from date of communication | Quality assurance, dispute resolution |
| Self-exclusion records | Permanently retained (or as required by exclusion period) | Responsible gaming legal obligation |
| Marketing consent records | Until consent is withdrawn + 3 years | Consent management compliance |
| Session and usage logs | 13 months from date of session | Security monitoring, analytics |
5.2 Data Storage Location
All personal data collected by dbajie is stored on secure servers. Access to stored data is restricted to authorised personnel only, using role-based access controls, multi-factor authentication, and encrypted storage. Data at rest is protected by AES-256 encryption.
5.3 Data Deletion
When a retention period expires, personal data is securely deleted or anonymised in a manner that prevents reconstruction. Where data must be retained beyond the standard retention period due to an ongoing legal dispute, investigation, or regulatory hold, you will be notified where legally permissible. You may request deletion of your personal data at any time (subject to the conditions set out in Section 7), and we will action deletion requests to the extent permitted by our legal obligations.
6. Security Measures
The security of your personal data is a top priority for dbajie. We implement a layered security architecture combining technical controls, operational procedures, and staff training to protect your data against unauthorised access, loss, alteration, or disclosure.
6.1 Technical Security Controls
- Transport Layer Security (TLS 1.3): All data transmitted between your device and the dbajie platform is encrypted in transit using TLS 1.3 with 256-bit encryption. The padlock icon in your browser confirms this connection is active.
- Data Encryption at Rest: All personally identifiable data stored in dbajie databases is encrypted using AES-256 encryption.
- Password Hashing: Your dbajie account password is never stored in plain text. It is hashed using a one-way cryptographic algorithm with a unique per-user salt. dbajie staff cannot see your password.
- Two-Factor Authentication (2FA): Optional 2FA is available for your dbajie account, adding a second layer of protection by requiring an SMS verification code in addition to your password on each login.
- Intrusion Detection Systems: Automated systems monitor platform traffic and database activity around the clock for signs of unauthorised access, SQL injection, brute-force attacks, and other security threats.
6.2 Operational Security
- Access to personal data within dbajie is restricted to staff members with a documented business need, under a principle of least privilege.
- All staff with access to personal data are trained in data protection practices and are bound by confidentiality obligations in their employment agreements.
- Third-party service providers with access to personal data are assessed for security compliance before onboarding and are contractually required to maintain equivalent security standards.
- Regular security assessments and penetration testing are conducted to identify and remediate vulnerabilities proactively.
6.3 Your Responsibilities
The security of your account also depends on steps you take as the account holder. To protect your dbajie account, you should:
- Choose a strong, unique password that you do not use on any other website or application.
- Enable two-factor authentication (2FA) on your account for additional login security.
- Never share your login credentials with any other person, including family members.
- Log out of your account after each session, particularly when using a shared or public device.
- Contact support immediately at [email protected] if you believe your account has been accessed without your authorisation.
7. Your Privacy Rights
As a player on the dbajie platform, you hold a set of rights in relation to your personal data. dbajie is committed to honouring these rights promptly and transparently. All requests relating to your personal data rights should be submitted to [email protected] with the subject line "Data Rights Request" and sufficient information to verify your identity as the account holder.
7.1 Right of Access
You have the right to request a copy of the personal data that dbajie holds about you, along with information about how it is used and with whom it has been shared. We will provide this information in a clear, structured format within 30 days of receiving a verified request. There is no charge for a standard access request.
7.2 Right to Rectification
If any personal data that dbajie holds about you is inaccurate or incomplete, you have the right to request that it be corrected. Many pieces of account information — such as your email address and contact number — can be updated directly through your account settings. For information that cannot be self-updated (such as your registered name or date of birth), contact support with documentary evidence of the correct information.
7.3 Right to Erasure
You may request that dbajie delete your personal data where it is no longer necessary for the purpose for which it was collected, where you withdraw consent (and no other lawful basis applies), or where the data has been processed unlawfully. Please note that this right is subject to overriding legal obligations — in particular, financial transaction records, KYC documents, and self-exclusion records must be retained for the periods specified in Section 5 regardless of a deletion request.
7.4 Right to Restriction of Processing
In certain circumstances — for example, where you contest the accuracy of data we hold, or where you object to a particular use of your data — you may request that we restrict our processing of that data to storage only while the matter is resolved. During a restriction period, your data will not be used for any purpose other than secure storage unless you provide consent or a legal obligation requires otherwise.
7.5 Right to Data Portability
Where your personal data is processed on the basis of your consent or a contractual obligation, and where the processing is carried out by automated means, you have the right to receive a copy of your data in a structured, commonly used, machine-readable format (such as JSON or CSV). You may request a data export at any time by contacting support.
7.6 Right to Object to Marketing
You have the absolute right to object to the use of your personal data for direct marketing purposes at any time. Upon receipt of a valid marketing opt-out request, dbajie will cease all marketing communications immediately and update your account preferences accordingly. See Section 2.5 for further details on how to withdraw marketing consent.
7.7 How to Exercise Your Rights
To exercise any of the rights described above, submit a written request to [email protected] with the subject line "Data Rights Request". Include your full registered name, account username, and a description of the right you wish to exercise. We will verify your identity before acting on any request and will respond within 30 calendar days. In cases of complexity or high volume, we may extend this period by a further 30 days, in which case we will notify you of the extension and the reason for it.
8. Policy Updates & Contact
dbajie reviews and updates this Privacy Policy periodically to reflect changes in our data processing practices, platform features, legal requirements, or industry standards. We are committed to keeping this policy accurate, current, and written in clear English that is accessible to all Bangladeshi players.
8.1 How We Notify You of Changes
When material changes are made to this Privacy Policy, registered players will be notified by email to the address on file at least 14 days before the updated policy takes effect. The notification will clearly describe what has changed and why. A summary of material changes will also be posted at the top of this page, dated with the effective date of the revision, for a minimum of 60 days following any update.
8.2 Version History
The current version of this Privacy Policy is Version 1.0, effective 1 January 2026. This is the initial published version of the dbajie Privacy Policy. Future revisions will be assigned incremental version numbers and logged in a version history table maintained at the bottom of this page.
8.3 Continued Use as Acceptance
Your continued use of the dbajie platform after the effective date of any updated Privacy Policy constitutes your acceptance of the revised terms. If you do not agree with any changes made to this policy, you should discontinue use of the platform and contact support to request account closure and data deletion in accordance with Section 7.3.
8.4 Contact & Data Enquiries
If you have any questions about this Privacy Policy, wish to exercise your data rights, or want to raise a concern about how your personal data has been handled, please contact the dbajie support team:
- Email: [email protected] (subject line: "Privacy Enquiry" or "Data Rights Request")
- Live Chat: Available 24 hours a day, 7 days a week, via the dbajie platform.
- WhatsApp Support: Available 08:00–02:00 Bangladesh Standard Time (UTC+6).
We aim to respond to all privacy-related enquiries within 5 business days and to all formal data rights requests within 30 calendar days as detailed in Section 7.