35bf Privacy Policy
At 35bf, your privacy is taken seriously. This Privacy Policy explains exactly what personal data we collect, how we use it, who we share it with, and how we keep it safe — so you can make informed decisions about your 35bf account and your data.
Summary: 35bf collects personal data necessary to operate a safe, compliant, and personalised gaming platform for Bangladesh players. We do not sell your personal data to third parties. We use industry-standard encryption and access controls to protect your information at all times. This policy applies to all users of the 35bf website and related services.
Introduction
This Privacy Policy ("Policy") describes how 35bf ("35bf", "We", "Us", "Our") collects, processes, stores, and protects personal data submitted by users ("Player", "You", "Your") of the 35bf platform, accessible at 35bf.io. This Policy forms part of the overall agreement between you and 35bf and should be read alongside the Terms and Conditions and the Responsible Gaming Policy.
35bf is committed to responsible data handling. We process personal data only where a clear legal basis exists, we retain it only for as long as necessary, and we give you meaningful control over the data we hold about you. We do not engage in the sale, rental, or unauthorised sharing of personal data under any circumstances.
By registering an account with 35bf or by continuing to use the 35bf platform after the publication of this Policy, you acknowledge that you have read and understood its contents. If you do not agree with any part of this Policy, you should cease using the platform and may request voluntary account closure by contacting the 35bf support team.
This Policy applies to all personal data collected via the 35bf website, mobile-optimised web experience, any associated communication channels (including email, WhatsApp, and live chat), and interactions with 35bf's customer support team.
Data We Collect
35bf collects the following categories of personal data in the course of operating the platform and fulfilling its obligations to Players:
| Category | Examples | Purpose |
|---|---|---|
| Identity Data | Full legal name, date of birth, national ID number, passport number | Account registration, KYC verification, age verification |
| Contact Data | Email address, mobile phone number, WhatsApp number, residential address | Account communications, support, verification, notifications |
| Financial Data | bKash number, Nagad number, Rocket number, Upay number, bank card last four digits, transaction history | Deposit and withdrawal processing, fraud prevention, AML compliance |
| Technical Data | IP address, device type, browser type and version, operating system, session timestamps | Platform security, fraud detection, service optimisation |
| Usage Data | Games played, bet amounts, session duration, win/loss history, bonus claims | Responsible gaming monitoring, platform personalisation, compliance |
| Communications Data | Support chat transcripts, email correspondence, WhatsApp message records | Customer support, dispute resolution, quality assurance |
| Verification Documents | Scanned/photographed national ID card, passport, proof of address, payment method screenshot | KYC compliance, identity verification, anti-fraud |
We collect only the minimum personal data required to fulfil the stated purposes. Where data is requested that is not strictly necessary, its provision will be marked as optional at the point of collection.
How We Collect Data
35bf collects personal data through the following channels and mechanisms:
- Direct Registration: When you create a 35bf account, you actively provide identity, contact, and financial data through the registration form.
- KYC Submission: When you submit verification documents in response to a KYC request from the 35bf compliance team, the documents and any data extracted from them are collected and stored.
- Deposits and Withdrawals: When you initiate a financial transaction, 35bf receives transaction metadata from the relevant payment processor (bKash, Nagad, Rocket, Upay, Visa, Mastercard, Dutch-Bangla Bank, or City Bank). This includes transaction reference numbers, amounts, timestamps, and the masked identifier of the payment instrument used.
- Platform Interaction: As you use the 35bf website — browsing games, placing bets, adjusting account settings — technical and usage data is automatically collected via server logs and first-party analytics tools.
- Cookies and Tracking Technologies: 35bf uses cookies and similar technologies to maintain session continuity, remember preferences, and gather aggregate usage statistics. See Section 7 for full details.
- Customer Support: When you contact the 35bf support team via live chat, email, or WhatsApp, records of those communications are retained for quality assurance, compliance, and dispute resolution purposes.
- Third-Party Verification Providers: Where 35bf uses regulated third-party KYC or identity verification services to cross-check the documents you provide, data may be exchanged with those providers as part of the verification process.
Legal Basis for Processing
35bf processes personal data on one or more of the following legal bases, depending on the nature of the processing activity:
- Contractual Necessity: Processing that is required to perform the contract between you and 35bf — including account creation, deposit processing, withdrawal processing, and game participation — is carried out on the basis that it is necessary to fulfil our contractual obligations to you.
- Legal Obligation: Certain processing activities — particularly KYC verification, anti-money laundering (AML) checks, and the retention of transaction records — are required by applicable laws and regulations. 35bf is obliged to carry out this processing regardless of your preferences.
- Legitimate Interests: 35bf processes some personal data on the basis of its legitimate interests as a business operator, including fraud prevention, platform security, responsible gaming monitoring, and internal analytics. Where we rely on legitimate interests, we ensure that those interests are not overridden by your fundamental privacy rights.
- Consent: Where 35bf processes personal data for marketing communications, profiling for promotional purposes, or any other purpose not covered by the above bases, we will obtain your explicit consent prior to processing. You may withdraw consent at any time by contacting the 35bf support team.
No Consent Required for Core Operations: The core functions of the 35bf platform — registration, deposits, withdrawals, gaming, and KYC — are processed on the basis of contractual necessity and legal obligation. Withdrawing consent for optional processing (e.g., marketing emails) will not affect your ability to use the platform or access your account.
How We Use Your Data
35bf uses the personal data it collects for the following specific purposes:
- Account Management: To create, maintain, and administer your 35bf account, including processing your login credentials, managing your account balance, and applying account-level settings such as deposit limits and self-exclusion preferences.
- Identity and Age Verification: To verify that you meet the minimum age requirement of 21 years and that the identity information provided at registration is accurate and genuine. This is a non-negotiable compliance requirement.
- Payment Processing: To facilitate deposits to and withdrawals from your 35bf account via your registered payment method, and to maintain accurate records of all financial transactions.
- Fraud Prevention and Security: To detect, investigate, and prevent fraudulent transactions, account takeover attempts, multi-accounting, bonus abuse, and other activities that are prohibited under the 35bf Terms and Conditions.
- Responsible Gaming: To monitor your gaming activity for indicators of problematic behaviour, to enforce deposit limits and self-exclusion periods you have requested, and to fulfil 35bf's responsible gaming obligations.
- Customer Support: To respond to your enquiries, process complaints, and maintain records of communications sufficient to resolve disputes and improve service quality.
- Legal and Regulatory Compliance: To comply with applicable anti-money laundering regulations, record-keeping obligations, and any lawful requests from regulatory or law enforcement authorities.
- Platform Improvement: To analyse aggregate usage patterns, identify bugs and performance issues, and make data-informed improvements to the 35bf user experience.
- Marketing Communications (Consent-Based): Where you have provided explicit consent, to send you information about 35bf promotions, bonuses, tournaments, and seasonal offers relevant to Bangladesh players. You may opt out at any time.
35bf does not use personal data for automated decision-making that produces significant legal effects without human oversight, except where required by regulatory compliance obligations.
Data Sharing and Disclosure
35bf does not sell, rent, or trade your personal data to any third party for their independent commercial purposes. Personal data is shared only in the following controlled and lawful circumstances:
- Payment Service Providers: To process your deposits and withdrawals, 35bf shares necessary transaction data with payment processors including bKash, Nagad, Rocket, Upay, Visa, Mastercard, Dutch-Bangla Bank, and City Bank. These providers act as independent data controllers for the portions of data they process under their own privacy terms.
- KYC and Identity Verification Providers: Regulated third-party identity verification services may receive copies of your identity documents and personal details for the purpose of performing automated or manual verification checks. All such providers are contractually bound to use your data solely for verification purposes.
- Game Studio Partners: Third-party game providers (including Pragmatic Play, Evolution Gaming, NetEnt, Microgaming, Spribe, and Ezugi) may receive your anonymised player ID and game session data in order to deliver and maintain game functionality. These providers do not receive your full identity or financial data.
- Regulatory and Law Enforcement Authorities: Where required by applicable law or by a lawful order from a competent authority, 35bf may disclose personal data to regulatory bodies, law enforcement agencies, or courts. 35bf will, where legally permissible, notify you of such a disclosure.
- Fraud Prevention Networks: Where 35bf has reasonable grounds to suspect fraudulent or criminal activity, relevant data may be shared with industry fraud prevention networks or shared databases to prevent harm across the wider gaming sector.
- Professional Advisers: Legal counsel, auditors, and compliance consultants engaged by 35bf may access personal data on a need-to-know basis in connection with their professional engagements. All such advisers are bound by professional confidentiality obligations.
No Third-Party Marketing: Under no circumstances will 35bf share your personal data with third parties for their own marketing, advertising, or commercial profiling purposes without your explicit prior consent. If you ever receive marketing communications purportedly from 35bf via a channel you did not authorise, please report this to [email protected] immediately.
Cookies and Tracking Technologies
35bf uses cookies and similar technologies (including local storage and session tokens) to operate and improve the platform. The following categories of cookies are used:
- Strictly Necessary Cookies: These cookies are essential for the platform to function correctly. They manage your login session, maintain your account state between pages, and enable secure communication between your browser and 35bf's servers. These cookies cannot be disabled without rendering the platform non-functional.
- Functional Cookies: These cookies remember your preferences — such as your preferred language setting, display options, and notification preferences — so that you do not need to re-enter them on each visit.
- Analytics Cookies: 35bf uses first-party analytics cookies to understand how Players navigate the platform, which pages are visited most frequently, and where technical issues occur. This data is used in aggregate and is not linked to your individual identity.
- Security Cookies: These cookies assist in detecting and preventing fraudulent login attempts, session hijacking, and cross-site request forgery (CSRF) attacks.
35bf does not use third-party advertising cookies or behavioural tracking cookies that profile you for the purposes of serving targeted advertisements on external websites.
You may adjust your browser's cookie settings to block or delete cookies at any time. Please note that blocking strictly necessary cookies will prevent you from logging in to your 35bf account. For instructions on managing cookies in your browser, refer to your browser's help documentation.
Data Retention
35bf retains personal data for as long as is necessary to fulfil the purpose for which it was collected, subject to any longer retention periods required by law or regulatory obligation. The following general retention periods apply:
- Account Data: Retained for the duration of your active account relationship with 35bf, and for a minimum of five years following voluntary or enforced account closure, to satisfy anti-money laundering and regulatory record-keeping requirements.
- Transaction Records: All deposit and withdrawal records are retained for a minimum of five years from the date of each transaction in accordance with financial record-keeping obligations.
- KYC and Identity Documents: Verification documents are retained for a minimum of five years following the completion of the KYC process or following account closure, whichever is later.
- Customer Support Records: Communications with the 35bf support team are retained for three years from the date of the interaction, or longer where the communication relates to an unresolved dispute or regulatory matter.
- Technical and Usage Logs: Server logs and platform usage data are retained for a rolling period of twelve months, after which they are aggregated or deleted.
- Marketing Consent Records: Records of your consent to receive marketing communications are retained for the duration of your account and for two years following opt-out, as evidence of the consent and its withdrawal.
At the end of the applicable retention period, personal data is securely deleted or irreversibly anonymised. Where anonymisation is not technically feasible, data is archived with access controls that prevent its use for any operational purpose.
Data Security
35bf implements a layered approach to data security, combining technical controls, organisational policies, and ongoing monitoring to protect your personal data against unauthorised access, loss, alteration, or disclosure.
- SSL/TLS Encryption: All data transmitted between your browser and the 35bf platform is encrypted using industry-standard SSL/TLS protocols. Look for the padlock icon and "https" in your browser's address bar when using 35bf.
- Encryption at Rest: Sensitive data stored on 35bf's servers — including identity documents, financial records, and account credentials — is encrypted at rest using strong encryption standards.
- Access Controls: Access to personal data is restricted on a strict need-to-know basis. 35bf staff members are granted the minimum level of data access required to perform their role. All access is logged and subject to audit.
- Two-Factor Authentication: 35bf encourages all Players to enable two-factor authentication (2FA) on their accounts. 35bf's own internal administrative systems require multi-factor authentication for all privileged access.
- Penetration Testing: 35bf's platform infrastructure undergoes regular third-party security assessments and penetration testing to identify and remediate vulnerabilities proactively.
- Incident Response: In the event of a confirmed personal data breach affecting your rights and freedoms, 35bf will notify affected Players without undue delay, describe the nature of the breach, and outline the remedial steps taken.
Your Responsibility: While 35bf takes all reasonable technical and organisational measures to protect your data, you are also responsible for maintaining the security of your account. Use a strong, unique password for your 35bf account, do not share your login credentials with any third party, and contact [email protected] immediately if you suspect your account has been compromised.
Your Data Rights
Subject to applicable law, you have the following rights in relation to the personal data that 35bf holds about you:
- Right of Access: You may request a copy of the personal data 35bf holds about you, along with information about how it is used and with whom it is shared. 35bf will respond to verified access requests within 30 days.
- Right to Rectification: If any personal data held about you is inaccurate or incomplete, you have the right to request that it be corrected. You may update certain account details directly through your account settings, or by contacting the support team.
- Right to Erasure: You may request the deletion of personal data held about you where it is no longer necessary for the purpose for which it was collected, where you have withdrawn consent, or where processing is unlawful. This right is subject to overriding legal retention obligations — for example, 35bf cannot delete transaction records required for AML compliance during the applicable retention period.
- Right to Restriction: You may request that 35bf restrict its processing of your personal data in certain circumstances, for example while the accuracy of data is being contested or while a complaint is under review.
- Right to Data Portability: Where processing is based on consent or contractual necessity and is carried out by automated means, you may request that your personal data be provided to you in a structured, commonly used, machine-readable format.
- Right to Object: You have the right to object to processing carried out on the basis of legitimate interests, including profiling for responsible gaming monitoring, at any time. 35bf will cease processing unless it can demonstrate compelling legitimate grounds that override your interests.
- Right to Withdraw Consent: Where processing is based on your consent, you may withdraw that consent at any time. Withdrawal of consent does not affect the lawfulness of processing carried out prior to withdrawal.
To exercise any of the above rights, please submit a written request to the 35bf support team at [email protected]. Include your full registered name, account username, and a clear description of the right you wish to exercise. 35bf may request additional verification before processing a data rights request to ensure that the request is made by the genuine account holder.
Third-Party Links
The 35bf platform may contain references to or integrations with third-party services, including game studio interfaces delivered by providers such as Pragmatic Play, Evolution Gaming, NetEnt, Microgaming, Spribe, and Ezugi. When you interact with third-party game content rendered within the 35bf platform, limited session data may be exchanged with the relevant studio for the purpose of delivering and logging game outcomes.
35bf is not responsible for the privacy practices of third-party game studio providers operating their own data collection within their game interfaces. Players are encouraged to review the privacy policies of individual game studios where they have concerns about data handling within specific game environments.
Payment service providers (bKash, Nagad, Rocket, Upay, Visa, Mastercard, Dutch-Bangla Bank, City Bank) operate as independent data controllers for data processed through their own systems. Their respective privacy policies govern how they handle your payment data. 35bf has no control over, and accepts no responsibility for, the data handling practices of these independent providers.
Children and Minors
The 35bf platform is strictly for adults aged 21 years and above. 35bf does not knowingly collect personal data from any person under the age of 21. If 35bf becomes aware that personal data has been collected from a person under the age of 21, the relevant account will be immediately suspended, all data collected in relation to that account will be securely deleted, and any funds associated with the account will be handled in accordance with applicable regulatory requirements.
Underage Access: If you are a parent or guardian and believe that a minor in your care has registered an account on the 35bf platform, please contact the support team at [email protected] immediately. 35bf will investigate and take appropriate action without delay. We are committed to zero tolerance for underage gambling and actively enforce age verification procedures at registration and throughout the account lifecycle.
International Data Transfers
35bf operates as an internationally licensed offshore platform. As a result, some personal data collected from Bangladesh-based Players may be processed on servers or by service providers located outside of Bangladesh. Where data is transferred internationally, 35bf ensures that appropriate safeguards are in place to protect your data to a standard equivalent to that described in this Policy.
Safeguards used for international transfers may include contractual data processing agreements with recipient organisations, ensuring that recipients are bound by equivalent data protection and security obligations. 35bf does not transfer personal data to jurisdictions that do not provide an adequate level of data protection without first implementing appropriate contractual safeguards.
By using the 35bf platform, you acknowledge that your personal data may be processed in jurisdictions outside Bangladesh. If you have questions about the international transfer of your personal data, please contact the 35bf support team.
Changes to This Policy
35bf reserves the right to update or amend this Privacy Policy at any time. When material changes are made, the revised Policy will be published at 35bf.io/privacy-policy with an updated "Last Updated" date. Where practicable, registered Players will be notified of significant changes via email or in-platform notification.
Your continued use of the 35bf platform following the publication of a revised Privacy Policy constitutes your acknowledgment of the updated terms. If you do not agree with the revised Policy, you should cease using the platform and may request voluntary account closure in accordance with the Terms and Conditions.
We recommend that you review this Policy periodically to stay informed about how 35bf handles your personal data. The current version of this Policy is always available at 35bf.io/privacy-policy.
Contact Us
If you have any questions, concerns, or requests relating to this Privacy Policy or to the personal data 35bf holds about you, please contact the 35bf data protection team using the details below. All contact details are provided as plain text only and are not clickable links.
- Email: [email protected]
- WhatsApp: +880 1700 000000 (available 08:00–24:00 BST)
- Live Chat: Available 24/7 via the 35bf platform
When submitting a data rights request or a privacy-related complaint, please include your registered account username, the email address associated with your account, and a clear description of your request. This allows the 35bf team to locate your records and respond efficiently. 35bf will acknowledge all privacy-related enquiries within 48 hours and will provide a substantive response within 30 days.
How 35bf Protects Your Privacy
Our privacy framework is built around six core principles that govern every aspect of how we collect, use, and safeguard your personal data on the 35bf platform.
SSL Encryption by Default
Every connection between your browser and 35bf's servers is protected by SSL/TLS encryption as standard. Sensitive data including your account credentials, payment details, and identity documents is encrypted both in transit and at rest, ensuring that your information is never exposed in plain text.
Strict Access Controls
Access to your personal data within 35bf's internal systems is governed by a least-privilege policy. Only team members with a specific operational need can access any given category of data, and all internal access is logged, monitored, and subject to regular audit by the 35bf compliance team.
No Data Selling — Ever
35bf has a firm, unconditional policy against selling, renting, or trading your personal data with any third party for commercial purposes. Your data is used exclusively to operate the 35bf platform, fulfil our contractual obligations to you, and comply with applicable legal requirements.
Meaningful Data Rights
35bf gives you genuine control over your data. You can request access to the information we hold, ask for corrections, request deletion where legally permissible, and object to specific types of processing. All data rights requests are handled within 30 days by a dedicated compliance team member.
Time-Limited Retention
35bf retains personal data only for as long as it is genuinely needed. Clear retention schedules are defined for each data category — from 12-month rolling logs for technical data to five-year retention for KYC and transaction records required by AML regulations. Data is securely deleted when the retention period expires.
Transparent Processing
This Privacy Policy documents every category of data we collect, every purpose for which we use it, and every legal basis we rely upon. There are no hidden data practices at 35bf. If our processing activities change in any material way, we will update this Policy and notify registered Players promptly.
Questions About Your Privacy?
The 35bf support team is available 24/7 to answer any questions about this Privacy Policy or the data we hold about you. You can also review our FAQ for quick answers, or read the full Terms and Conditions.