Startup Playbook for Future Gaming Operators
Privacy Policy
Last updated: August 27, 2025
FlexPlay respects your privacy and is committed to protecting your personal data. This Privacy Policy explains what information we collect, how we use it, how we protect it, and what rights you have under applicable laws, including the General Data Protection Regulation (GDPR).

When you visit our website https://flexplay.io/, and use our services, you trust us with your personal information collected through the website, and/or any related services, sales, marketing or events (we refer to them collectively in this privacy policy as the “Services”).

Please read this Privacy Policy carefully to understand how we handle your data.
Contact Information
For any inquiries related to this Privacy Policy or your data, please contact us at:
Evenbet Gaming Limited
64, "Excalibur", B. Bontadini street, Birkirkara, Malta
Phone: +356 27761655
Mailing address: 112, IGA HUB, Level 2, Salvu Psaila Str, Birkirkara, BKR 9076, Malta
Email: info@flexplay.io
Purpose of Data Collection
We process your data for legitimate business interests, to fulfill contractual obligations, comply with legal requirements, and/or with your consent. The legal basis for data processing is clearly stated in each relevant section of this policy.

Please read this privacy policy carefully as it will help you make informed decisions about sharing your personal information with us.
1. What type of information do we collect?
We collect personal information that you provide to us such as name, address, contact information, passwords and security data, and payment information, as well as information from other sources (including publicly available personal information, credentials, IP address and/or browser and device characteristics, and online identifiers).

We collect personal information that you voluntarily provide to us when expressing an interest in obtaining information about us or our products and services, when participating in activities on the Services or otherwise contacting us.

The personal information that we collect depends on the context of your interactions with us and the Services, the choices you make and the products and features you use. 

The personal information we collect can include the following:

1.1. Information you provide to us: when you contact us via forms or email (e.g., name, email address, and any information you voluntarily submit).
We collect first name, maiden name, last name, nickname, ID, phone numbers, email addresses, business email, business phone number, real estate records including purchase and sale prices and neighbor info, business entity filings, corporate affiliations, business associates, social media, and other similar data.

1.2. Credentials.
We collect passwords, password hints, and similar security information used for authentication and account access.
All personal information that you provide to us must be true, complete and accurate, and you must notify us of any changes to such personal information.

1.3. Analytics data: including IP address, browser type, device information, pages visited, and usage patterns through tools such as Google Analytics, Yandex Metrica or Meta.
We automatically collect certain information when you visit, use or navigate the Services. This information does not reveal your specific identity (like your name or contact information) but may include device and usage information, such as your IP address, browser and device characteristics, operating system, language preferences, referring URLs, device name, country, location, information about how and when you use our Services and other technical information. This information is primarily needed to maintain the security and operation of our Services, and for our internal analytics and reporting purposes.

1.4. Cookies and similar technologies: like many businesses, we also collect information through cookies and similar technologies. Specific information about how we use such technologies and how you can refuse certain cookies is set out in our Cookie Policy, available at Cookie Policy.

1.5. Online Identifiers.
We collect devices, applications, tools and protocols, such as IP (Internet Protocol) addresses, cookie identifiers, or others such as the ones used for analytics and marketing, device’s geolocation, and other similar data.

1.7. Information collected from other open sources.
We may collect limited data from public databases, marketing partners, and other outside sources. We may obtain information about you from other sources, such as public databases, joint marketing partners, as well as from other third parties.
2. How do we use your information?
We process your information for purposes based on legitimate business interests, the fulfillment of our contract with you, compliance with our legal obligations, and/or your consent.
We process your personal information for these purposes in reliance on our legitimate business interests, in order to enter into or perform a contract with you, with your consent, and/or for compliance with our legal obligations. We indicate the specific processing grounds we rely on next to each purpose listed below.

We use the information we collect or receive:

2.1. To send you marketing and promotional communications.
We and/or our third-party marketing partners may use the personal information you send to us for our marketing purposes, if this is in accordance with your marketing preferences. You can opt-out of our marketing emails at any time (see the “WHAT ARE YOUR PRIVACY RIGHTS” below).

2.2. To send administrative information to you.
We may use your personal information to send you product, service and new feature information and/or information about changes in our terms, conditions, and policies.

2.3. Fulfill and manage your orders.
We may use your information to fulfill and manage your orders, payments, returns, and exchanges made through the Services.

2.4. Deliver targeted advertising to you.
We may use your information to develop and display content and advertising (and work with third parties who do so) tailored to your interests and/or location and to measure its effectiveness.

2.5. Improve our website, services, and user experience.
We may use your information to request feedback and to contact you about your use of our Services.

2.6. To protect our Services.
We may use your information as part of our efforts to keep our Services safe and secure (for example, for fraud monitoring and prevention).

2.8. To enforce our terms, conditions and policies for Business Purposes, Legal Reasons and Compliance.
We may share your data to be able to have a Compliance Procedure required by the law of Malta, or to enforce that pir policy correlates with the local law.

2.9. To respond to legal requests and prevent harm.
If we receive a subpoena or other legal request, we may need to inspect the data we hold to determine how to respond.

2.10. To Analyze website performance and trends.
We may use your information for data analysis, identifying usage trends, determining the effectiveness of our promotional campaigns and to evaluate and improve our Services, products, marketing and your experience. 
3. How we store and protect data
Your data is stored on secure servers within the European Economic Area (EEA). We implement technical and organizational measures to prevent unauthorized access, loss, or misuse of your data, including encryption and access control.

We take the protection of your personal data seriously and follow the requirements of the General Data Protection Regulation (GDPR). To ensure your information is safe, we apply the following measures:

3.1. Secure Connections (HTTPS): All data transferred between your browser and our website is encrypted using SSL/TLS technology.

3.2. Access Control: Only authorized employees and service providers can access personal data, and only for necessary purposes.

3.3. Data Minimization: We collect and process only the information we need to provide our services.
3.4. Regular Security Testing: We monitor our systems and apply updates to protect against vulnerabilities and cyber-attacks.

3.5. Data Breach Procedures: In case of a data breach, we will notify the competent supervisory authority and affected users as required by GDPR.

We keep your information for as long as necessary to fulfill the purposes outlined in this privacy policy unless otherwise required by law. Once data is no longer needed, we securely delete or anonymize it.

We will only keep your personal information for as long as it is necessary for the purposes set out in this privacy policy, unless a longer retention period is required or permitted by law (such as tax, accounting or other legal requirements). No purpose in this policy will require us keeping your personal information for longer than 2 years.

When we have no ongoing legitimate business need to process your personal information, we will either delete or anonymize it, or, if this is not possible (for example, because your personal information has been stored in backup archives), then we will securely store your personal information and isolate it from any further processing until deletion is possible.
4. How do we share and transfer information?
We only share information with your consent, to comply with laws, to provide you with services, to protect your rights, or to fulfill business obligations.

We may process or share data based on the following legal basis:

4.1. Consent:
We may process your data if you have given us specific consent to use your personal information in a specific purpose.

4.2. Legitimate Interests:
We may process your data when it is reasonably necessary to achieve our legitimate business interests.

4.3. Performance of a Contract:
If we have entered into a contract with you, we may process your personal information to fulfill the terms of our contract.

4.4. Legal Obligations:
We may disclose your information where we are legally required to do so in order to comply with applicable law, governmental requests, a judicial proceeding, court order, or legal process, such as in response to a court order or a subpoena (including in response to public authorities to meet national security or law enforcement requirements).

4.5. Vital Interests:
We may disclose your information where we believe it is necessary to investigate, prevent, or take action regarding potential violations of our policies, suspected fraud, situations involving potential threats to the safety of any person and illegal activities, or as evidence in litigation in which we are involved.

4.6. Sharing with our Affiliates:
We may share your personal data with our affiliates, including companies within our corporate group, for purposes related to providing and improving our services, marketing activities (where legally permitted), and business operations. Any such sharing will comply with GDPR requirements, and our affiliates will be bound by appropriate confidentiality and data protection obligations.

4.7. Service providers 
We may as well share your data with those who assist us with hosting, analytics, and communication. We ensure that all service providers adhere to GDPR and maintain appropriate security measures for your personal data.
5. Transparency in data processing
We are committed to ensuring transparency in how we process your data
6. What are your privacy rights under GDPR?
Under the General Data Protection Regulation (GDPR), in the EU territory, you may review, change, or terminate your account at any time.

You have certain rights under applicable data protection laws. These may include the right (i) to request access and obtain a copy of your personal information, (ii) to request rectification or erasure; (iii) to restrict the processing of your personal information; and (iv) if applicable, to data portability. In certain circumstances, you may also have the right to object to the processing of your personal information. To make such a request, please use the contact details provided below. We will consider and act upon any request in accordance with applicable data protection laws.

If we are relying on your consent to process your personal information, you have the right to withdraw your consent at any time. Please note however that this will not affect the lawfulness of the processing before its withdrawal.

If you are resident in the European Economic Area and you believe we are unlawfully processing your personal information, you also have the right to complain to your local data protection supervisory authority. In Malta, it will be Office of the Information and Data Protection Commissioner (Malta).
7. What is our stance on third-party websites?
We are not responsible for the safety of any information that you share with third-party providers who advertise, but are not affiliated with our websites.

The Services may contain advertisements from third parties that are not affiliated with us and which may link to other websites, online services or mobile applications. We cannot guarantee the safety and privacy of data you provide to any third parties. Any data collected by third parties is not covered by his privacy policy. We are not responsible for the content or privacy and security practices and policies of any third parties, including other websites, services or applications that may be linked to or from the Services. You should review the policies of such third parties and contact them directly to respond to your questions.
8. Data breach
A privacy breach occurs when there is unauthorized access to or collection, use, disclosure or disposal of personal information. 

You will be notified about data breaches when FlexPlay believes you are likely to be at risk or serious harm. For example, a data breach may be likely to result in serious financial harm or harm to your mental or physical well-being. In the event that FlexPlay becomes aware of a security breach which has resulted or may result in unauthorized access, use or disclosure of personal information, FlexPlay will promptly investigate the matter and notify the applicable Supervisory Authority not later than 72 hours after having become aware of it, unless the personal data breach is unlikely to result in a risk to the rights and freedoms of natural persons.
9. Controls for do-not-track features
Most web browsers and some mobile operating systems and mobile applications include a Do-Not-Track (“DNT”) feature or setting you can activate to signal your privacy preference not to have data about your online browsing activities monitored and collected. No uniform technology standard for recognizing and implementing DNT signals has been finalized. As such, we do not currently respond to DNT browser signals or any other mechanism that automatically communicates your choice not to be tracked online. If a standard for online tracking is adopted that we must follow in the future, we will inform you about that practice in a revised version of this privacy policy.
10. Do we make updates to this policy?
We may update this privacy policy from time to time. The updated version will be effective as soon as it is accessible. If we make material changes to this privacy policy, we may notify you either by prominently posting a notice of such changes on our website or by directly sending you a notification via email. We encourage you to review this privacy policy frequently to be informed of how we are protecting your information.
11. How can you contact us about this policy?
If you have questions or concerns about this policy, please contact us at info@flexplay.io