2
How We Use Your Data
2.1 Service Provision
We use your information to:
- Create and manage your gaming account
- Process deposits, withdrawals, and gaming transactions
- Provide customer support and technical assistance
- Enable game functionality and features
- Maintain game records and transaction history
- Process bonuses, promotions, and rewards
2.2 Security and Fraud Prevention
Your data helps us:
- Verify your identity and prevent unauthorized access
- Detect and prevent fraud, money laundering, and other illegal activities
- Monitor for suspicious gaming patterns or account activity
- Comply with Know Your Customer (KYC) requirements
- Investigate disputes and resolve conflicts
- Protect against technical attacks and security threats
2.3 Legal Compliance
We process your data to:
- Comply with gaming laws and regulations
- Meet anti-money laundering requirements
- Respond to legal requests and court orders
- Report suspicious activities to authorities
- Maintain required records for auditing purposes
2.4 Service Improvement
We analyze data to:
- Improve game features and user experience
- Develop new games and services
- Personalize content and recommendations
- Conduct research and analytics
- Test new features and functionality
- Optimize app performance and stability
⚖️ Legal Basis: We process your data based on contract performance, legal obligations, legitimate interests, and your consent where required. You can withdraw consent for marketing communications at any time.
3
Data Sharing and Disclosure
🚫 We Never Sell Your Data: We do not sell, rent, or trade your personal information to third parties for their marketing purposes.
3.1 Service Providers
We share data with trusted partners who help us provide services:
Service Type |
Data Shared |
Purpose |
Examples |
Payment Processors |
Financial data, transaction details |
Process payments |
EasyPaisa, JazzCash, Banks |
Identity Verification |
Identity documents, personal info |
KYC compliance |
Document verification services |
Cloud Services |
All data types (encrypted) |
Data storage and processing |
AWS, Google Cloud |
Analytics |
Usage data, device info |
Service improvement |
Google Analytics, Firebase |
Customer Support |
Account data, communication |
Provide support |
Support ticket systems |
3.2 Legal Requirements
We may disclose your information when required by law:
- To comply with legal processes (subpoenas, court orders)
- To report suspicious activities to law enforcement
- To respond to government investigations
- To comply with gaming authority requests
- To enforce our terms and conditions
- To protect our rights and safety
3.3 Business Transfers
In the event of a merger, acquisition, or sale of assets, your information may be transferred to the new entity, subject to the same privacy protections.
🔒 Data Protection Agreements: All third parties who access your data are bound by strict confidentiality agreements and must implement appropriate security measures.
4
Data Security and Protection
🛡️ Our Security Commitment
We implement industry-leading security measures to protect your personal information from unauthorized access, alteration, disclosure, or destruction.
4.1 Technical Safeguards
- Encryption: All data is encrypted in transit (SSL/TLS) and at rest (AES-256)
- Secure Infrastructure: Data hosted on secure, certified cloud platforms
- Access Controls: Multi-factor authentication and role-based access
- Network Security: Firewalls, intrusion detection, and DDoS protection
- Regular Updates: Security patches and system updates
- Vulnerability Testing: Regular security audits and penetration testing
4.2 Organizational Measures
- Staff Training: Regular privacy and security training for all employees
- Access Limitation: Data access limited to authorized personnel only
- Confidentiality Agreements: All staff bound by strict confidentiality rules
- Incident Response: Defined procedures for security incident handling
- Data Minimization: Regular reviews to ensure we only hold necessary data
- Secure Disposal: Secure deletion of data when no longer needed
4.3 Your Security Responsibilities
Help us protect your account by:
- Using a strong, unique password
- Enabling two-factor authentication when available
- Keeping your login credentials confidential
- Logging out from shared devices
- Reporting suspicious activity immediately
- Keeping your contact information updated
🚨 Security Incident Response: In the unlikely event of a data breach, we will notify affected users and relevant authorities within 72 hours as required by law.
5
Your Privacy Rights and Controls
You have comprehensive rights regarding your personal data. We provide easy-to-use tools and clear processes to exercise these rights.
👁️
Right to Access
Request a copy of all personal data we hold about you, including how it's used and who it's shared with.
✏️
Right to Rectification
Correct or update any inaccurate or incomplete personal information in your account.
🗑️
Right to Erasure
Request deletion of your personal data when it's no longer necessary or you withdraw consent.
⏸️
Right to Restrict Processing
Limit how we use your data in certain circumstances while maintaining your account.
📦
Right to Data Portability
Receive your data in a machine-readable format to transfer to another service provider.
🚫
Right to Object
Object to processing based on legitimate interests, including direct marketing communications.
⚖️
Right to Complain
Lodge a complaint with a supervisory authority if you believe your rights have been violated.
🤖
Automated Decision-Making
Request human review of any automated decisions that significantly affect you.
5.1 How to Exercise Your Rights
To exercise any of these rights:
- In-App: Use the privacy settings in your account dashboard
- Email: Contact privacy@3pattiland.net with your request
- Support: Contact customer support through live chat
- Written Request: Send a signed letter to our data protection officer
5.2 Response Time and Verification
- We respond to requests within 30 days (may extend to 60 days for complex requests)
- Identity verification may be required to protect your privacy
- Some requests may be declined if they conflict with legal obligations
- We provide clear explanations if we cannot fulfill a request
6
Cookies and Tracking Technologies
We use cookies and similar technologies to enhance your experience, analyze usage, and provide personalized content.
6.1 Types of Cookies We Use
Cookie Type |
Purpose |
Duration |
Can You Disable? |
Essential Cookies |
Basic website functionality, security, login |
Session/1 year |
No - Required for service |
Performance Cookies |
Analyze site usage, improve performance |
2 years |
Yes - Through settings |
Functional Cookies |
Remember preferences, personalization |
1 year |
Yes - May affect experience |
Marketing Cookies |
Targeted advertising, campaign tracking |
1-2 years |
Yes - Through cookie banner |
6.2 Managing Cookie Preferences
You can control cookies through:
- Cookie Banner: Accept or reject non-essential cookies when you visit
- Privacy Settings: Modify cookie preferences in your account
- Browser Settings: Configure cookie settings in your web browser
- Opt-Out Tools: Use industry opt-out tools for advertising cookies
6.3 Third-Party Cookies
We may allow selected third parties to place cookies for:
- Web analytics (Google Analytics)
- Social media integration
- Advertising and remarketing
- Customer support tools
- Payment processing
🍪 Cookie Notice: Disabling certain cookies may limit functionality. Essential cookies cannot be disabled as they are necessary for basic website operation and security.
7
Third-Party Services and Integrations
7.1 Integrated Services
Our platform integrates with third-party services to enhance functionality:
💳 Payment Providers
- EasyPaisa & JazzCash: Mobile wallet transactions
- Banking Partners: Bank transfer processing
- Payment Gateways: Secure payment processing
📊 Analytics and Performance
- Google Analytics: Website usage analysis
- Firebase: App performance monitoring
- Crashlytics: Error reporting and app stability
🔒 Security and Verification
- Identity Verification Services: KYC compliance
- Fraud Detection: Transaction monitoring
- Security Scanners: Threat detection
7.2 Data Sharing with Third Parties
When we share data with third parties:
- Data is shared only for specified purposes
- Third parties are contractually bound to protect your data
- We conduct due diligence on all partners
- Data sharing is limited to what's necessary
- We monitor compliance with privacy standards
7.3 Social Media Integration
If you connect social media accounts:
- We may access profile information you've made public
- Social media platforms may track your interactions
- You can disconnect social accounts anytime
- Social media privacy policies apply to their services
🔗 External Links: Our platform may contain links to third-party websites. We are not responsible for the privacy practices of external sites. Please review their privacy policies before sharing information.
8
Data Retention and Deletion
8.1 Retention Periods
We retain your data for different periods based on data type and legal requirements:
Data Type |
Retention Period |
Reason |
After Deletion |
Account Information |
Account lifetime + 7 years |
Legal compliance, dispute resolution |
Permanently deleted |
Transaction Records |
7 years after transaction |
Financial regulations, audit requirements |
Archived then deleted |
Gaming Activity |
5 years after last activity |
Gaming regulations, fraud prevention |
Permanently deleted |
Identity Documents |
7 years after account closure |
AML compliance, legal requirements |
Securely destroyed |
Marketing Data |
Until consent withdrawn |
Marketing communications |
Immediately removed |
Support Communications |
3 years after resolution |
Service improvement, training |
Permanently deleted |
8.2 Automated Deletion
We implement automated systems to:
- Regularly review data retention schedules
- Automatically delete data when retention periods expire
- Archive data that must be retained for legal compliance
- Anonymize data where possible for research purposes
- Securely wipe deleted data from all systems
8.3 Account Closure
When you close your account:
- Active data is immediately inaccessible
- Personal information is deleted within 30 days
- Financial records are retained per legal requirements
- Anonymized data may be retained for analytics
- You receive confirmation of account closure
9
International Data Transfers
9.1 Global Service Provision
As a global platform, we may transfer your data to countries outside Pakistan to:
- Provide our services through cloud infrastructure
- Enable payment processing through international partners
- Access specialized technical and security services
- Comply with international legal requirements
- Facilitate customer support across time zones
9.2 Transfer Safeguards
When transferring data internationally, we ensure:
- Adequacy Decisions: Transfer to countries with adequate protection levels
- Standard Contractual Clauses: EU-approved contract terms for protection
- Binding Corporate Rules: Internal policies ensuring consistent protection
- Certification Programs: Partners with recognized privacy certifications
- Encryption: All transferred data is encrypted in transit and at rest
9.3 Key Transfer Destinations
- United States: Cloud services with Privacy Shield/adequacy protections
- European Union: GDPR-compliant data processing
- Singapore: Asia-Pacific data center with local protections
- India: Regional processing with contractual safeguards
🌍 Your Rights: You have the right to know about international transfers and can request information about the safeguards in place to protect your data.
10
Children's Privacy Protection
🔞 Age Restriction: Our services are not intended for individuals under 18 years of age. We do not knowingly collect personal information from children.
10.1 Age Verification
We implement strict age verification measures:
- Age declaration during registration
- Identity document verification
- Regular compliance audits
- Account suspension for underage users
- Cooperation with parents and guardians
10.2 Parental Rights
If you are a parent or guardian and believe your child has provided us with personal information:
- Contact us immediately at privacy@3pattiland.net
- We will verify the relationship and investigate
- Underage accounts will be immediately suspended
- All personal information will be deleted
- We will implement additional safeguards to prevent future access
10.3 Detection and Response
If we discover an underage user:
- Account access is immediately terminated
- All personal data is deleted within 48 hours
- Any transactions are reversed where possible
- Parents/guardians are notified if contact information is available
- Enhanced verification measures are implemented
11
Marketing Communications and Preferences
11.1 Types of Communications
We may send you various types of communications:
📧 Service Communications (Cannot Opt-Out)
- Account verification and security alerts
- Transaction confirmations and receipts
- Important policy updates and changes
- Security and fraud prevention notices
🎯 Marketing Communications (Can Opt-Out)
- Promotional offers and bonuses
- New game announcements
- Newsletter and gaming tips
- Personalized recommendations
11.2 Communication Channels
- Email: Promotional offers, newsletters, updates
- SMS: Account alerts, bonus notifications, security codes
- Push Notifications: App alerts, game reminders, promotions
- In-App Messages: Feature announcements, tips, offers
11.3 Managing Preferences
You can control marketing communications through:
- Account Settings: Modify preferences in your profile
- Unsubscribe Links: Click unsubscribe in any marketing email
- SMS Opt-Out: Reply STOP to any marketing SMS
- App Settings: Disable push notifications in device settings
- Customer Support: Contact support to update preferences
11.4 Personalization
We personalize communications based on:
- Gaming preferences and activity
- Deposit and gameplay patterns
- Device and platform usage
- Geographic location
- Communication engagement history
✅ Respect for Preferences: We honor your communication preferences and process opt-out requests within 48 hours. You can always change your mind and re-subscribe.
12
Privacy Policy Updates and Changes
12.1 When We Update This Policy
We may update this Privacy Policy to reflect:
- Changes in our data practices
- New features or services
- Legal or regulatory requirements
- Industry best practices
- User feedback and requests
- Security enhancements
12.2 Notification Process
We will notify you of material changes through:
- Email Notification: Sent to your registered email address
- In-App Alerts: Prominent notifications in the mobile app
- Website Banner: Notice on our website homepage
- Updated Policy: New "Last Updated" date at the top
12.3 Your Options
When we make significant changes:
- You'll have 30 days to review the changes
- Continued use means acceptance of new terms
- You can close your account if you disagree
- Customer support is available to answer questions
- Previous versions are archived for reference
12.4 Version History
We maintain a record of policy changes:
- Version 2.0: January 1, 2025 - Enhanced user rights, GDPR compliance
- Version 1.5: July 1, 2024 - Added cookie management, international transfers
- Version 1.0: January 1, 2024 - Initial privacy policy
📜 Policy Archive: Previous versions of our Privacy Policy are available upon request for comparison and reference purposes.
13
Legal Basis for Data Processing
13.1 GDPR Compliance
Under GDPR and similar laws, we process your data based on the following legal grounds:
Processing Purpose |
Legal Basis |
Examples |
Service Provision |
Contract Performance |
Account management, gaming services, payments |
Legal Compliance |
Legal Obligation |
KYC verification, AML reporting, tax obligations |
Fraud Prevention |
Legitimate Interest |
Security monitoring, suspicious activity detection |
Marketing |
Consent |
Promotional emails, targeted advertising |
Service Improvement |
Legitimate Interest |
Analytics, user experience enhancement |
13.2 Legitimate Interest Assessment
When relying on legitimate interest, we balance:
- Our business needs and those of third parties
- Your privacy rights and freedoms
- Your reasonable expectations
- The nature and sensitivity of the data
- Available safeguards and mitigation measures
13.3 Consent Management
When we rely on consent:
- Consent is freely given, specific, and informed
- You can withdraw consent at any time
- Withdrawal doesn't affect past processing
- We maintain records of consent given
- Separate consent for different processing purposes
📋 Acknowledgment and Acceptance
By using our platform, you acknowledge that you have read, understood, and agree to this Privacy Policy. If you have any questions about how we handle your personal data, please contact our privacy team.
Policy Version: 2.0
Last Updated: January 1, 2025
Effective Date: January 1, 2025
Next Review: July 1, 2025