Buzz Group Ltd Privacy Notice
1. About This Privacy Notice
This Privacy Notice explains how we use personal data and your rights under data protection laws.
Our websites buzzbingo.com and buzzcasino.com are operated by Buzz Bingo Digital Limited. Buzz Bingo Digital Limited trades from Office 208, Unit 1.02, World Trade Centre, 6 Bayside Road, Gibraltar, GX11 1AA and the Data Protection Officer is registered with the Gibraltar Regulatory Authority.
Our clubs and badabingo.co.uk are operated by Buzz Group Limited. Buzz Group Limited is incorporated and registered in England and Wales with company number 00794943 and the registered office is Unit 1, Castle Marina Road, Nottingham NG7 1TN. Buzz Group Limited is registered with the ICO under registration number Z8801135.
2. Contacting Us
For any questions, concerns, comments or to exercise your data protection rights, please contact our Data Protection Officer at:
1 Castle Marina Road
Nottingham
NG7 1TN
DPO@buzzbingo.com
0808 169 1459 (please request a call back if required)
3. What types of personal information do we collect?
We collect personal information when you interact with us and use our services. This information is provided to us by you when you register for the first time and when you make use of our products or contact us. Sometimes third parties or publicly available sources provide us information about you.
Information you provide or may need to provide to us:
- At registration:
- Your personal details, such as your name, email address, postal address, telephone or mobile number and date of birth.
- During the business relationship:
- Photographic identification and proof of address documents (to conduct due diligence)
- Banking and financial details (to establish the source of funds where a transaction is involved)
- Your account login details or club membership details, such as your username and password
We may collect the following categories of personal data relating to employees, officers, authorised signatories and other associated individuals of our merchants and vendors:
- Work History (including position, department and title history and salary and benefits from previous employment)
- Education and Training History
- Criminal Information
- Military service
- Nationality
- Information on government-issued cards (e.g. national identification card, Passport, work permit, driving license, other licenses, etc)
- Certificates and Qualifications
- Signatures
- CV
- Bank Account Details
- Business Address
- Business Email Address
- Business Telephone number
- Job title
- Through your use of our services:
- Information about how you interact with our products
- Information about your online browsing behaviour on Buzz Bingo websites, mobile apps, and other online content – please see our Cookies Policy for more details; www.buzzbingo.com/cookies-policy
- Information about any devices you have used to access our Services (such as model, operating system, IP address, browser type, mobile device identifier).
- Recording phone calls and webchat interactions – we may monitor or record phone calls and webchat interactions:
- To check that we have carried out your instructions correctly
- To resolve queries or issues
- For regulatory purposes
- To help improve our quality of service
- To help us train our staff
- Or to help detect or prevent fraud or other crimes.
Other sources of personal data
- Where we provide personalised services, we may use third-party data about you, for example, your Twitter or Facebook feeds, to get to know you better and to provide more effective personalisation.
- Data received from our business partners and from other organisations, such as specialist companies providing verification services, credit reference agencies, and fraud prevention agencies.
- Publicly available sources, like postcode lookup.
This list of personal data types collected by Buzz Bingo is not exhaustive and further information may be requested from you when Buzz Bingo considers it fair and necessary to do so.
Special categories of data
- Personal data collected by Buzz Bingo may include so-called “special categories of data,” such as health data related to responsible gambling. We will only collect, use and disclose Sensitive Data, and transfer it across borders if we have received your explicit consent or as permitted by law (see Section 4E for further details).
- We have in place additional measures to protect your sensitive personal data and its confidentiality.
4. Why do we collect your Personal Data and on what basis?
We recognise the trust our customers place in us as a service provider. In return, Buzz Bingo is open about why we collect your data. First and foremost, collecting your information is essential for providing you with the services and products you want. In addition, your data is used to personalise and improve your experience using our services and to contact you from time to time with important information. In some cases, we need to collect and use your information to comply with the law.
Under data protection laws, we also need to identify a specified lawful basis upon which we are processing your personal information. We rely on different bases for different processing activities, as detailed below
a) Under the contract – when it is necessary for the performance of a contract to which you are a party. Our terms and conditions, which you have accepted at registration, set out the terms of the contract and the services we will provide:
To make our services available to you as part of our contract
- To provide gaming and betting services, activities or online content, to provide you with information about them and to deal with your requests and enquiries
- For "service administration purposes", such as password reminders, service messages, such as site maintenance, updates to our Privacy and Cookies Policy or Terms of Use, to let you know if your Buzz Bingo account has become dormant and to ask if you would like to use it again before we close it
- To process your transactions
b) Under legitimate interests - It is necessary to process your data for the purposes set out below, except where our interests are overridden by the interests, rights or freedoms of affected individuals (such as you). To determine if we can process your data on this basis, we shall consider several factors, such as what you were told at the time you provided your data, what your expectations are about the processing of the data, the nature of the data, and the impact of the processing on you.
To personalise your experience
- To offer a more relevant, tailored service; for instance, we could use your playing history to provide personalised recommendations and products
- If you are signed in or subscribed to our marketing offers, you will receive a personalised service. If you don’t want to receive these services you can unsubscribe from marketing offers, or disable personalisation by contacting our help centre or by email at DPO@buzzbingo.com
To improve our services and products
- To provide you with the most user-friendly online navigation experience
- For analysis and research purposes so that we may improve the services offered by Buzz Bingo
- Testing new systems and checking upgrades to existing systems
- Evaluating the effectiveness of marketing and for market research and training
- Customer modelling, statistical and trend analysis, with the aim of developing and improving products and services
To contact and interact with you
- Contact customers about our services, for example by phone, email or post or social media
- Manage promotions and competitions you choose to enter
- Invite you to take part in and manage customer surveys, questionnaires and other market research activities carried out by Buzz Bingo and by other organisations on our behalf (We carry out market research to improve our services, however, if we contact you about this, you do not have to take part in the activities. If you tell us that you do not want us to contact you for market research, we will respect this choice and this will not affect your ability to use our services).
- Respond to your queries and complaints.
To make your game safer and more enjoyable
- To deter, prevent or detect the use of third-party software in peer-to-peer gambling
- To deter, prevent, or detect any activities conducted in breach of the Buzz Bingo Terms and Conditions.
For Recruitment Purposes
- Documenting information collected from job applicants as part of the application process, authentication and verification
- Contacting purposes
- Evaluating the respective suitability of applicants
- Contact job applicants about their application for example by phone, email or post or social media.
- Evaluating job applicants/ candidates for their qualification for a particular job, background screening (if you are offered a position with us)
- Defining a salary and other basic contract information for a new hire.
c) Under the legal obligation – when it is necessary in order to comply with mandatory legal obligations to which we are subject under EU or local laws:
- To determine where you are accessing the services from
- To make sure we offer our services to eligible persons
- Crime detection, prevention, and prosecution
- To verify your identity and establish the source of funding in any transaction
- To conduct appropriate anti-fraud checks (by completing online searches using a third-party identity provider). Please note that this will not affect your credit rating
- To assess and manage any potential risks and prevent problem gambling.
- To communicate with employee contacts in case of an emergency.
d) Under your consent
Marketing and market research
- We will send you relevant offers and news about our products and services in several ways including by email, SMS, phone call, post, and social media targeted advertising, but only if you have previously agreed to receive these marketing communications. When you register with us we will ask if you would like to receive marketing communications, and you can change your marketing choices online, over the phone or in writing at any time.
Recruitment and Human resources
- For our initiation or fulfilment of our employment agreement with applicants and employees in terms of data retention and processing information
- Where you have given your consent:
- we provide references to third parties you have requested
- we will process data as described in any future consent given
We may use information which we hold about you to show you relevant advertising on third-party sites (e.g. Facebook, Google, Instagram, Snapchat and Twitter). If you don’t want to be shown targeted advertising messages from us, some third-party sites allow you to request not to see messages from specific advertisers on that site in future. If you want to stop all personalised services from us, including targeted advertising messages on third-party sites you can contact our help centre or by email at DPO@buzzbingo.com to disable personalisation.
We also like to hear your views to help us improve our services, so we may contact you for market research purposes. You always have the choice about whether to take part in our market research.
e) Special categories of data
We will only process such data if one or more of the following applies:
- You have given us your explicit consent
- It is necessary for the purposes of conducting the obligations and exercising specific rights of Buzz Bingo or of the data subject in the field of employment and social security and social protection law
- It relates to personal data which you have made public
- It is necessary for the establishment, exercise or defence of legal claims
- It is necessary for reasons of substantial public interest, on the basis of European Union or Member State law, as applicable to us.
- It is necessary for the purpose of obligating with our regulatory requirements.
5. Cookies and similar technologies
- Buzz Bingo's websites and Apps use cookies for various purposes:
- To identify the Account Holder's preferred language, so it can be automatically selected when the Account Holder returns to the Website
- To ensure that bets placed by the Account Holder are associated with the Account Holder's betting coupon and Account
- To ensure that the Account Holder receives any bonuses for which they are eligible, and or analysis of the Website traffic, so as to allow Buzz Casin to make suitable improvements to the functionality of the website.
- More information can be found in our Cookie Policy online.
Mobile Phone Applications - Push Notifications for Buzz Bingo Mobile Applications
Push Notifications
- Our mobile applications may send you push notifications to keep you informed about updates, promotions, and other relevant information. These notifications are designed to enhance your user experience by providing timely and relevant information.
Purpose of Push Notifications
We use push notifications to:
- Inform you about new features and updates.
- Provide promotional offers and discounts.
- Send reminders and alerts related to your account or usage of our services.
Managing Push Notification Preferences
You have full control over the push notifications you receive. You can manage your preferences through the settings menu on your mobile. Here, you can choose to:
- Enable or disable push notifications.
- Select the types of notifications you wish to receive.
Opting In and Out
- When you first install our mobile application, you will be prompted to opt-in to receive push notifications. You can change your preferences at any time by accessing the notification settings within the app.
Data Handling
We ensure that any data collected through push notifications is handled in accordance with our privacy policy. We do not share your personal information with third parties without your consent, except as required by law.
6. When do we share your personal information?
We do not share your personal information to third parties outside the Buzz Group for marketing purposes. However, there are circumstances when we share your personal data with third parties that provide services to you on our behalf, and with other third parties in the course of complying with our legal obligations. Other examples of when we share your personal information include when we enter any kind of merger or business sale. Even when it is shared, we ensure that your personal information will only be used for the purposes outlined in this policy.
With other companies within Buzz Group
We may share the personal data we collect with other companies in the Buzz Group for the following purposes:
- Providing you with products and services and notifying you about either important changes or developments to the features and operation of those products and services
- Responding to your enquiries and complaints
- Administering offers, competitions, and promotions
- Facilitating the secure access to online platforms
- Updating, consolidating, and improving the accuracy of our records
- Undertaking transactional analysis
- Undertaking risk analysis
- Assessing and managing any risks and preventing problem gambling
- Testing new systems and checking upgrades to existing systems
- Crime and fraud detection, prevention, and prosecution, as well as ensuring compliance with regulatory requirements and our T&Cs
- Evaluating the effectiveness of marketing, and for market research and training
- Customer modelling, statistical and trend analysis, with the aim of developing and Improving products and services.
With third parties
We may share personal data with third parties in the following circumstances:
- When ordered to do so by any regulatory body and/or under any legal provision contained in the governing law
- We may instruct and authorise the Financial Institution with which an Account Holder's account is held to disclose any information as may be requested by the Regulator in respect of an Account Holder's account
- In order to establish, exercise or defend our legal rights
- For fraud detection and control purposes, we may transfer your personal data to third parties, including but not limited to so-called Address Verification System service providers, Payment Service Providers, Financial Institutions and credit reference agencies such as Transunion, which will leave a “soft” footprint on your credit file; more details: Privacy Centre | An Information & Insights Company (transunion.co.uk)
Furthermore, we reserve the right to disclose the Account Holder’s personal data to relevant parties where Buzz Group has reasonable grounds to suspect irregularities involving a Buzz Group Account
- With service providers to enable us to provide our services, such as companies that help us with technology services, storing and combining data, recruitment management and processing payments or providing relevant online advertising for our products and services
- With external auditors who may conduct independent checks as part of our accreditations
- With self-exclusion service provider GAMSTOP to match identities of customers who are attempting to register and/or access a pre-existing account while being registered as self-excluded. For more information visit https://www.gamstop.co.uk/privacy-policy
- To an organisation we sell or transfer (or enter into negotiations to sell or transfer) any of our businesses or any of our rights or obligations under any agreement we may have with you to. If the transfer or sale goes ahead, the organisation receiving your personal data can use your personal data in the same way as us; or
- To any other successors in title to our business.
7. Do we transfer your data outside the EEA?
The personal data that we collect from you may be transferred to, and stored at, a destination outside the European Economic Area ("EEA"). It may also be processed by companies operating outside the EEA who work for us or for one of our service providers. For instance, the computer servers used to host a website could be located outside the EEA – this is not unusual given that the internet is a global environment. Your personal information could be held at a destination which offers a different level of data protection than in the EEA, including Australia, Serbia, India, US. To ensure your personal information remains safe when transferred like this, we will take all reasonable steps to maintain a suitable level of protection in line with this Policy and our obligations under data protection laws.
Where any of our processing activities require your personal data to be transferred outside of the EEA, we will only make that transfer if:
- We have put in place appropriate safeguards to protect your personal data, such as the contractual Model Clauses adopted by the European Commission or a relevant data protection authority; or
- The country to which the personal data is to be transferred has an adequacy decision from the European Commission, confirming that the third country provides adequate protection for your personal information; or
- You explicitly consent to the transfer; or
- The transfer is necessary for one of the reasons specified in the data protection laws, such as the performance of a contract with you.
Compliance with Schrems II Ruling and ICO IDTA
Data Transfers Outside the UK and EEA
In light of the Schrems II ruling, we have implemented additional measures to ensure that any data transfers outside the UK and EEA are lawful and compliant.
Lawful Basis for Data Transfers
We rely on the following mechanisms to ensure the legality of data transfers:
- Standard Contractual Clauses (SCCs) approved by the European Commission.
- Binding Corporate Rules (BCRs) where applicable.
- Adequacy decisions by the European Commission for certain countries.
- ICO International Data Transfer Agreement (IDTA) and Addendum, which provide a framework for ensuring the adequacy of third countries for international transfers under UK GDPR.
ICO International Data Transfer Agreement (IDTA)
The ICO IDTA is a key document that we use to establish where we can transfer data to. It includes:
- Transfer Agreement Templates: Standard templates that outline the terms and conditions for data transfers.
- Addendum Templates: Additional clauses that may be required to address specific transfer scenarios.
- Risk Assessment Tool: A tool to assess the risks associated with international data transfers and ensure compliance with UK GDPR.
Additional Safeguards
To further protect your data, we have implemented additional safeguards, including:
- Regular assessments of the legal environment in the destination country by our Data Protection Officer.
- Encryption of data during transit and at rest.
- Robust access controls and monitoring to prevent unauthorized access.
Commitment to Data Protection
We are committed to maintaining the highest standards of data protection. Our practices ensure that the level of data protection is equivalent to that guaranteed within the EU, even when your data is transferred outside the UK and EEA.
8. How long will Buzz Group keep my data?
We will only retain your information for as long as is reasonably necessary to carry out the purposes outlined above and to satisfy our legal obligations. While you are a customer, we will usually need to retain your information to meet our legal and contractual requirements. However, when you cease using Buzz Group services, we will normally still retain your personal information for a period of time.
Typically, we will store your personal information for a period of 6 years after you cease being a customer of Buzz Group, beginning at the date your account is closed.
Meanwhile, for job applicants, we will hold data for a period of 12 months. There are several reasons which we retain your information, these include:
- To comply with legal obligations under EU/local laws (for example, anti-money laundering regulations, or licensing regulations)
- To establish or defend legal claims (for example negligence claims) which could be made against us.
9. Your rights & choices over your personal information
- We appreciate that by law and subject to certain conditions, you have a number of rights concerning the personal information we hold about you. If you wish to exercise these rights, you should contact our Data Protection Officer using the details set out above in Section 3. These rights include the right to access, amend and erase the personal information we hold about you, the right to object to the processing of your data, the right to withdraw consent, and the right to data portability. You also have the right to complain to your data protection authority if you are concerned with how we process your information. In addition, you have certain rights relating to automated decision-making and ‘profiling.’ Further information and advice about your rights can be obtained from the UK data protection authority, (the Information Commissioner’s Office or “ICO”) or from your country’s data protection regulator.
Right to access and rectify the information we hold about you
- According to GDPR and DPA 2018, customers are permitted to make Data Subject Access Requests (DSAR). These requests can be made when you would like to gain access to all of the information we hold about you. In order to process this request, we will require a valid form of I.D. This is a safety measure designed to ensure that personal data is disclosed to the correct individual.
- You can make a DSAR via our online form.
- When you submit this request, all personal data that we hold about you will be shared with you directly.
- There are some exceptions and conditions under which DSARs can be refused. In such cases, you will be notified of the decision and justification.
Right to delete your data
In some circumstances, you can ask us to erase personal information we hold about you (‘the right to be forgotten’). This includes when:
- The information is no longer necessary in relation to the purpose for which it was collected (as explained in our privacy notice)
- If you previously gave consent to the use of your information, but decide to withdraw it and we cannot justify another legal ground for using it under data protection law
- We process your information based on our legitimate interests and we cannot demonstrate overriding legitimate grounds to continue processing the information
- We don’t have a lawful ground under data protection law to process your information
- The data has to be erased to comply with a legal requirement
This right is subject to mandatory retention periods under EU/local laws.
Right to restrict processing
You have the right to ask us to restrict (‘block’ or ‘suppress’) the processing of your personal information. When processing is restricted, we can still store your information, but will not use it further. We keep lists of people who have asked for further use of their information to be ‘blocked’ to make sure the restriction is respected in the future. This right is available to you when:
- You dispute the accuracy of the personal information (while we verify matters).
- The processing is unlawful, and you object to the erasure of the information and request that we restrict processing instead
- We no longer need the data, but you require it to establish, exercise or defend a legal claim; and
- We process your information for our legitimate business interests but you object (i.e. while we verify the grounds for continued processing).
Right to Data Portability
You have the right to receive personal information you provide to us, in a ‘commonly used machine-readable format.’ This allows you to obtain and reuse your information for your own purposes across different services. For example, if you decide to switch to a different provider, this enables you to move, copy or transfer your information easily between our IT systems and theirs safely and securely, without affecting its usability. This is not a general right however, and only arises when the processing of your information is:
- based on your consent or where it is necessary for the performance of a contract, and
- when the information is processed by solely by automated means.
Right to object
Based on your particular situation, you can object to the processing of your personal information, which is:
- based on our legitimate business interests (including profiling); or
- done for research and statistical purposes.
You also have the right to object to the use of your personal information for direct marketing purposes (including profiling), such as when you receive emails from us notifying you about other Buzz Group services which we think will be of interest to you.
Right to withdraw consent
When we rely on your consent as the basis to process your personal information – such as for sales and marketing communications (see section 4D) – you have the right to withdraw your consent at any time. We’ll always strive to make it easy for you to withdraw consent by choosing an “unsubscribe” option in every communication you receive from us. If you find this isn’t the case, then just contact our Data Protection Officer in the ways outlined above in Section 2, and we’ll try to fix things ASAP.
Rights related to automated decision-making, including profiling
We sometimes use systems to make automated decisions based on your personal information. This helps us to make sure our decisions are quick, fair, efficient and correct, based on what we know. These automated decisions can affect the products, services or features we may offer you now or in the future, or the ability to use our services.
We may use automate decisions making in the following situations:
- tailoring products and services – we may pace you in groups with similar customers (segments) to study and learn about preferences and your needs and offer more tailored experience for you.
- detecting fraud - we use your personal information to help decide and detect if your account may be being used for fraud or money-laundering. If we think there is a risk of fraud, we may block or suspend the account.
- opening account - when you open an account with us, we check that the product or service is relevant for you, based on what we know. We also check that you meet the conditions needed to open the account. This may include checking age, residency, nationality or financial position.
Data protection law seeks to safeguard individuals against harm that may arise from decision-making - including profiling - that takes place without human intervention. You have the right not to be subject to a decision - including profiling - when it is based on the automated processing of your personal information and it has a legal effect or a similarly significant effect on you.
Please note that the right does not apply when the processing is:
- necessary for entering into or for the performance of a contract with you; or
- when it is authorised by law; or
- when it is based on your explicit consent.
10. Security of your data
Buzz Group is committed to protecting the personal information you entrust to us. We take all reasonable steps to ensure that all information collected through our websites is handled securely and in line with this Policy and strict data protection standards. Accordingly, we have adopted robust procedures and technologies to protect your data from unauthorised access and improper use.
All information sent to and from Buzz Group sites is encrypted using 256 BIT Transport Layer Security (TLS) technology.
Your credit card details are encrypted and sent only to our PCI DSS-compliant Payment Service Provider. Buzz Group is dedicated to protecting our customer's confidential information and, as part of doing so, Buzz Group is certified towards the Payment Card Industries Data Security Standard.
The security of Buzz Groups systems and applications is tested several times per year by third-party security experts. Furthermore, Buzz Group has an Intrusion Detection System that monitors all network traffic 24/7 for signs of attacks or intrusions.
Buzz Group has a dedicated fraud department and advanced systems in place to detect and prevent suspicious activity, to ensure that Buzz Group's websites remain a secure playing field. Any account involved in suspicious activity will be suspended and investigated to the fullest extent. Should you have any doubts about any activity on your account, such as unrecognised transactions in the transaction history or surprising changes in the balance, please contact us immediately using the contact details in section 2.
11. Complaints
If you wish to raise a complaint on how we have handled your personal data, you can contact us to have the matter investigated by contacting our Data Protection Officer, using the contact details in section 2.
If you are not satisfied with our response or believe we are not processing your personal data in accordance with the law, you can complain to the UK data protection authority, the Information Commissioner’s Office, the “ICO,” or your national data protection regulator.
12. Data Protection Officer
Buzz Bingo has an appointed Data Protection Officer (DPO). The Data Protection Officer (DPO) has key responsibilities that include informing and advising the controller or processor on data protection obligations, monitoring compliance with data protection regulations, providing advice on data protection impact assessments, cooperating with the Commissioner, and acting as a contact point for data subjects and the Information Commissioner, The DPO can be contacted at DPO@buzzbingo.com.
13. Changes to Buzz Group Privacy Notice
This Privacy Notice may be updated from time to time to reflect changes in the way we process your information or the way in which our data processing is regulated, so you may wish to check it each time you submit personal information to us. The date of the most recent revisions will appear on this page. If you do not agree to these changes, please do not continue to submit personal information to Buzz Group or use Buzz Group services in any way. Otherwise, by continuing to do this, you will be deemed to have accepted the changes to the Privacy Notice. You can also delete your Buzz Group account at any time.
If significant changes are made to the Privacy Notice, for instance affecting how we would like to use your personal information, we will provide a more prominent notice (including, for certain services, notification of Privacy Notice changes by email).
Last updated: October 2024