1. Who We Are
dua66 ("we," "us," "the Platform," "dua66") operates the online casino and sports betting platform available at dua66.club. dua66 acts as the data controller in respect of personal data collected through the Platform and is responsible for the lawful and transparent processing of that data.
This Privacy Policy applies to all users of the dua66 Platform, including visitors to the website and registered account holders. By creating a dua66 account or using any part of the Platform, you acknowledge that you have read and understood this Privacy Policy and consent to the processing of your personal data as described herein.
If you have questions about this Policy or wish to exercise any of your data rights, please contact us at [email protected] or through the 24/7 live chat available within the Platform.
2. Data We Collect
dua66 collects personal data through several channels in the ordinary course of operating the Platform. The categories of data we collect include:
2.1 Registration Data
- Full legal name as it appears on government-issued identity documents
- Date of birth (collected to verify the mandatory 18+ age requirement)
- Pakistani mobile number used as a primary contact and authentication identifier
- Email address (where provided)
- Residential address
- Username and password (passwords are stored in encrypted hashed form only — we do not store your plaintext password)
2.2 Identity Verification (KYC) Data
- Copies of government-issued identity documents (e.g., CNIC, passport)
- Proof of payment method ownership (e.g., screenshot of registered JazzCash or Easypaisa account)
- Selfie or liveness verification images where required
2.3 Financial Transaction Data
- Deposit and withdrawal records including amounts, dates, and payment method used
- PKR transaction history associated with your dua66 account
- Payment method identifiers (e.g., mobile wallet number, bank account last digits)
2.4 Usage and Behavioural Data
- Betting and gaming history — markets wagered on, stake amounts, game types played, session durations
- Responsible gaming tool settings such as deposit limits and self-exclusion status
- Login timestamps and IP addresses at time of login
- Device type, operating system, browser version, and screen resolution
2.5 Support Communications
- Live chat transcripts and email correspondence between you and the dua66 support team
- Complaint and dispute records
3. How We Use Your Data
dua66 processes personal data for the following purposes:
- Account Management: Creating, maintaining, and securing your dua66 account. Enabling login, password resets, and multi-factor authentication via your registered Pakistani mobile number.
- Payment Processing: Facilitating PKR deposits and withdrawals via JazzCash, Easypaisa, HBL, UBL, Meezan Bank, and Bank Alfalah. Verifying that payment methods are registered in your name.
- Identity Verification (KYC): Verifying your age and identity to comply with anti-money laundering obligations and to enforce the 18+ age restriction on all dua66 accounts.
- Responsible Gaming: Monitoring usage patterns to identify potential indicators of problem gambling. Applying deposit limits, loss limits, session controls, and self-exclusion as configured by you or determined necessary by dua66.
- Fraud Prevention and Security: Detecting and preventing unauthorised access, fraudulent transactions, and abuse of the Platform including bonus abuse and multi-account creation.
- Platform Improvement: Analysing anonymised usage data to improve game performance, interface design, payment flows, and customer support processes.
- Communications: Sending account-related notifications, transaction confirmations, and promotional communications where you have not opted out of marketing messages.
- Regulatory Compliance: Meeting obligations under applicable anti-money laundering, know your customer, and gaming regulation frameworks.
4. Legal Basis for Processing
dua66 processes your personal data under the following legal bases:
- Contractual Necessity: Processing required to perform the contract between you and dua66, including operating your account, processing payments, and settling bets.
- Legal Obligation: Processing required to comply with applicable law, including KYC/AML obligations and age verification requirements.
- Legitimate Interests: Processing for fraud prevention, security monitoring, responsible gaming oversight, and Platform improvement, where these interests are not overridden by your fundamental rights.
- Consent: Where you have given explicit consent, such as for optional marketing communications. You may withdraw consent at any time by contacting dua66 support.
5. Data Sharing
dua66 does not sell your personal data to third parties. We share personal data only in the following limited circumstances:
- Payment Processors: Transaction data is shared with JazzCash, Easypaisa, HBL, UBL, Meezan Bank, Bank Alfalah, and other payment partners solely to process your PKR deposits and withdrawals.
- Identity Verification Providers: KYC document data may be processed by certified third-party identity verification services under strict data processing agreements.
- Game Providers: Certain game interaction data is processed by certified game providers (e.g., RNG software vendors, live casino stream providers) solely to deliver the game experience.
- Regulatory and Law Enforcement Authorities: dua66 will disclose data to competent authorities when required to do so by applicable law, court order, or regulatory direction.
- Professional Advisors: Legal, financial, and auditing advisors under confidentiality obligations where required for Platform governance.
All third-party processors engaged by dua66 are contractually required to process personal data only for the specified purpose and in compliance with applicable data protection standards.
6. Data Retention
dua66 retains personal data for as long as necessary to fulfil the purposes for which it was collected, subject to the following general retention principles:
- Active Account Data: Retained for the duration of your active dua66 account relationship.
- Transaction and KYC Records: Retained for a minimum of five (5) years after account closure to comply with applicable anti-money laundering record-keeping requirements.
- Self-Exclusion Records: Retained for a minimum of five (5) years after a self-exclusion period ends to prevent re-registration during an active exclusion period.
- Support Communications: Retained for up to three (3) years for complaint management and quality assurance purposes.
Following the applicable retention period, personal data is securely deleted or anonymised so that it can no longer be attributed to an identified individual.
7. Cookies & Tracking Technologies
dua66 uses cookies and similar tracking technologies on its website. The categories of cookies used include:
- Strictly Necessary Cookies: Required for the Platform to function, including maintaining your login session and security tokens. These cannot be disabled.
- Performance Cookies: Collect anonymised data on how users interact with the Platform — page load times, error rates, navigation paths — to identify and fix technical issues.
- Functional Cookies: Remember your preferences such as language settings, last game played, and responsible gaming display configurations.
- Analytics Cookies: Used to understand aggregate usage patterns and improve the Platform. Data collected by analytics cookies is anonymised before analysis.
You may control non-essential cookies through your browser settings. Disabling certain cookies may affect the functionality of specific Platform features.
8. Security Measures
dua66 implements a range of technical and organisational measures to protect your personal data against unauthorised access, disclosure, alteration, or destruction:
- SSL/TLS Encryption: All data transmitted between your device and dua66 servers is encrypted using industry-standard Transport Layer Security protocols.
- Password Hashing: Account passwords are stored as cryptographic hashes. dua66 never stores or transmits plaintext passwords.
- OTP Authentication: Login from unrecognised devices triggers a one-time password sent to your registered Pakistani mobile number.
- Access Controls: Internal access to personal data is restricted to authorised personnel on a need-to-know basis, with all access logged and audited.
- Incident Response: dua66 maintains a data breach response procedure. In the event of a breach affecting your personal data, we will notify you and relevant authorities as required by applicable law.
While dua66 takes all reasonable steps to protect your data, no internet-based system can guarantee absolute security. You are responsible for maintaining the confidentiality of your account credentials.
9. Your Rights
Subject to applicable law, you have the following rights in respect of the personal data dua66 holds about you:
- Right of Access: Request a copy of the personal data dua66 holds about you.
- Right to Rectification: Request correction of inaccurate or incomplete personal data.
- Right to Erasure: Request deletion of your personal data where it is no longer necessary for the purpose it was collected and where no overriding legal retention obligation applies.
- Right to Restrict Processing: Request that dua66 limit the processing of your data in certain circumstances.
- Right to Data Portability: Request that your data be provided to you in a structured, machine-readable format.
- Right to Withdraw Consent: Where processing is based on consent, withdraw that consent at any time without affecting the lawfulness of prior processing.
- Right to Object: Object to processing carried out on the basis of legitimate interests.
To exercise any of these rights, contact the dua66 support team via live chat or at [email protected]. dua66 will respond to all verifiable requests within a reasonable timeframe. Identity verification may be required before data requests are actioned.
10. Minors
dua66 is strictly an 18+ platform. We do not knowingly collect personal data from individuals under the age of 18. If you believe that a minor has provided personal data to dua66, please contact us immediately at [email protected]. Upon verification, dua66 will close the relevant account and delete all associated personal data in accordance with applicable law.
Age verification is conducted as a mandatory step of the registration and withdrawal process on dua66. Players who are found to have misrepresented their age will have their accounts closed and any balances forfeited.
11. Changes to This Privacy Policy
dua66 reserves the right to update or amend this Privacy Policy at any time. When material changes are made, we will post the revised Policy on this page with an updated "Last Updated" date and, where reasonably practicable, notify registered users via the contact details held on their accounts.
Your continued use of the dua66 Platform following the publication of a revised Privacy Policy constitutes your acceptance of the changes. If you do not accept the revised Policy, you should cease using the Platform and may request closure of your account.
12. Contact Us
For any questions, concerns, or requests relating to this Privacy Policy or the processing of your personal data by dua66, please contact us through the following channels:
- Live Chat: Available 24 hours a day, 7 days a week, through the dua66 Platform interface. Our team supports Pakistani players in English with Urdu-friendly assistance available.
- Support Email: [email protected]
We aim to acknowledge all privacy-related enquiries within 48 hours and resolve them within a reasonable timeframe depending on complexity.
Your Privacy Matters to dua66
dua66 does not sell your data. We process your information only to operate your account, process payments, comply with the law, and keep the Platform safe. For more information about how we protect you, see our Terms & Conditions and Responsible Gaming pages.