Written against the Privacy Act 1988 and the thirteen Australian Privacy Principles, with the uncomfortable answers stated rather than softened.

Privacy Policy: How Your Personal Information Is Handled
What this document is for
Opening a betting account means handing over more than an email address. Identity documents, card details, a betting history and a device fingerprint all end up in one place, and a reader is entitled to know precisely what that place holds, who else sees it, and what can be demanded back.
This LEON Bet policy is written to be used rather than skimmed. Each section states what is collected, why, and what you can do about it. Where an answer is uncomfortable, such as the fact that closing an account does not delete everything, it is stated plainly instead of being softened, because a privacy notice that only contains good news is not a privacy notice.
LEON Bet is operated by Bluewave Interactive N.V. under licence № OGL/2024/1161/0454, issued by Curaçao Gaming Authority. The platform accepts Australian players, holds balances in AUD, and therefore handles the personal information of Australian residents.
The legal framework we work to
For players in Australia, the reference point is the Privacy Act 1988 (Cth) and the thirteen Australian Privacy Principles (APPs) it contains. Those principles govern how personal information is collected, used, disclosed, secured, corrected and sent overseas, and they give individuals rights that do not depend on a company's goodwill.
Two APPs are called out separately later on because they carry the most practical weight: APP 8, which restricts disclosure of personal information to recipients outside Australia, and APP 12, which grants a right of access to the information held about you.
The information collected
Nothing here is gathered speculatively. Each category exists because an account cannot legally or technically function without it, or because you chose to provide it.
| Category | Specific items | Source |
|---|---|---|
| Identity | Full name, date of birth, gender where provided, nationality, residential address | Provided at registration |
| Contact | Email address, mobile number, preferred contact language | Provided at registration or in account settings |
| Verification (KYC) | Scans or photographs of a government-issued identity document, proof of address, and where required a selfie or liveness check | Uploaded during verification |
| Financial | Payment method type, masked card numbers, e-wallet identifiers, deposit and withdrawal records, currency, source-of-funds evidence where requested | Generated by transactions and by AML checks |
| Account activity | Login timestamps, betting and gaming history, stakes, bonus participation, balance movements, responsible gambling settings | Generated by your use of the account |
| Technical | IP address, approximate location derived from it, device type, operating system, browser, screen configuration, session identifiers | Collected automatically |
| Communications | Live chat transcripts, emails and support tickets, including attachments you send | Generated when you contact support |
| Preferences | Marketing opt-ins and opt-outs, cookie consent choices, notification settings | Your own selections |
Full card numbers and card security codes are not stored on the platform's own systems; payment details are handled through the payment provider processing the transaction.
Why each category is collected
Australian privacy law asks organisations to be specific about purpose. Four distinct grounds apply here, and the difference between them determines what you can refuse.
Performance of the contract between you and the operator. Identity, contact, financial and account activity data are needed to open an account, credit deposits, settle bets, process withdrawals and provide support. Without them there is no service to provide, so this data cannot be withheld while keeping an active account.
Legal and regulatory obligation. Verification data, source-of-funds evidence and transaction records are collected to satisfy anti-money-laundering and counter-terrorism-financing duties imposed on the operator by its licence, and to confirm that every account holder is at least 18. These obligations override an individual request to erase the data concerned.
Legitimate interests of the operator. Technical and behavioural data supports fraud detection, bonus abuse detection, multi-account detection, debugging, capacity planning and product improvement. These interests are balanced against your privacy, and the data used for them is kept to what the purpose actually requires.
Your consent. Marketing by email, SMS or push notification, personalised promotional offers, and non-essential cookies rest on consent alone. Consent is requested separately, never bundled into the registration checkbox that covers the terms, and withdrawing it is a single action in account settings.
The practical summary: verification and transaction data is mandatory, marketing is optional. Refusing marketing does not restrict access to games, bonuses already awarded, or withdrawals.
Who your information is disclosed to
LEON Bet does not sell, rent or trade your personal information. It is not passed to advertising brokers or to unrelated companies for their own use. Disclosure happens only to the following categories of recipient, only for the purpose named, and only to the extent needed:
- Payment providers and financial institutions, to process deposits and withdrawals and to investigate disputed transactions and chargebacks.
- Identity verification and anti-fraud services, to confirm that documents are genuine and that an applicant is who they claim to be.
- Game studios and content providers, which receive the pseudonymous session and wager data needed to run a game round and settle it correctly. They do not receive your identity documents.
- Technology and communications suppliers, including hosting, security monitoring and messaging services acting under contract and on the operator's instructions.
- The licensing authority, auditors, regulators and law enforcement, where disclosure is required by law, by a valid legal process, or by the terms of the licence.
- Professional advisers, where legal or accounting advice requires it.
Every commercial recipient works under a written agreement that limits use of the data to the service being supplied and requires it to be protected and, where applicable, returned or destroyed.
Information sent outside Australia
The platform's infrastructure and several of its service providers are located outside Australia, so personal information about Australian players is, in practice, disclosed overseas. Recipients are typically located in the jurisdiction of the operator's licence and in European and other jurisdictions where hosting, verification and payment partners operate.
APP 8 governs this. Before an overseas disclosure, the operator takes reasonable steps to ensure the recipient handles the information in a way consistent with the Australian Privacy Principles, through contractual commitments covering purpose limitation, security standards, breach notification and restrictions on onward transfer. Where the disclosure is required by law, or where you have been informed and have consented to a transfer that does not carry those safeguards, the position is stated to you at the time.
How long information is kept
Two different clocks run at once, and this is the part most privacy notices blur.
Information held on the basis of consent, such as marketing preferences and non-essential tracking, stops being used as soon as consent is withdrawn and is removed from active systems shortly afterwards.
Information tied to anti-money-laundering duties, tax obligations, dispute records and licence conditions is retained for the minimum period those obligations require, calculated from the closing of the account or the last transaction, whichever the relevant obligation specifies. The operator does not choose this period; it is set by the AML framework applying to the licence and cannot be shortened at a player's request.
The consequence is worth stating in plain terms: closing an account does not erase the record of it. What closure does is end active processing, stop marketing, and reduce the retained set to the material the operator is legally obliged to keep. Once the retention obligation expires, the remaining records are deleted or irreversibly anonymised.
Your rights and how to exercise them
Naming a right is not much use without the procedure. Each of the following is exercised through live chat in your account or through the operator's support service, from the email address registered to the account.
Access. You may ask for a copy of the personal information held about you and for an explanation of how it has been used. Expect an identity check first, since releasing account data to an impostor would be the larger privacy failure. A response is provided within a reasonable period, and if access is refused in part, the reason is given.
Correction. If a name, address or date of birth is wrong, submit the correct value with evidence supporting it. Verified identity fields cannot be changed on request alone, precisely because they are the anchor of the account.
Deletion. You may request erasure of your personal information. Data resting on consent or on legitimate interests is deleted. Data covered by a legal retention duty is not, and you will be told which category applies to which part of your request rather than being given a blanket yes or no.
Withdrawal of consent. Marketing consent can be withdrawn at any time in the notification settings of your account or through the unsubscribe link in any promotional message. Cookie consent is managed separately through the consent banner and your browser settings.
Objection and restriction. You may object to processing carried out on the basis of legitimate interests and ask that it be limited while the objection is considered.
Complaint. Raise the matter with the operator first, through live chat or support, setting out what happened and what outcome you want. If the response is unsatisfactory or does not arrive in a reasonable time, an Australian resident may escalate the complaint to the Office of the Australian Information Commissioner (OAIC) at oaic.gov.au. The OAIC is an independent statutory body; it is not a regulator of this platform's gaming licence, and referring to it here is a statement of your escalation route rather than a claim of oversight.
How the data is secured
- Traffic between your device and the platform is encrypted in transit, and stored credentials are hashed rather than kept in readable form.
- Verification documents are stored in restricted repositories, separated from general account data.
- Access is granted on a need-to-know basis, logged, and reviewed; support agents see only the fields relevant to the request in front of them.
- Systems are monitored for intrusion attempts and unusual account behaviour, including logins from unexpected locations.
- Two-factor authentication is available on player accounts and is the single most effective step you can take.
Your side matters too. Use a password unique to this account, do not reuse the one from your email, never share verification codes with anyone claiming to be support, and treat any message asking you to confirm card details as a phishing attempt.
Under-18s
The platform is for adults only and no account may be held by a person under 18. Personal information about minors is not knowingly collected. If an account is found to belong to someone under 18, it is suspended immediately, the associated data is quarantined and handled only as required for the closure and any legal reporting, and marketing to that address stops. A parent or guardian who believes a minor has provided personal information should contact support so that the account can be located and closed.
Contacting us about your data
Privacy requests go through live chat inside your LEON Bet account, which is the fastest route and is available to logged-in players, or through the operator's support service using the email address registered to the account. State clearly that the message is a privacy request and which right you are exercising, so it is routed to the team handling data matters rather than treated as a general query. You will receive confirmation that the request has been received and an indication of what happens next.
Cookies and similar tracking technologies are described in a dedicated policy on this site, which sets out each category, its lifespan and how to switch the optional ones off.