This privacy instrument was last reviewed in September 2026. Users are notified of material processing updates via WhatsApp and official alerts.
Currently Activev5.2 18+
SECTION 01

WHO WE ARE & DATA CONTROLLER IDENTIFICATION

Gold365 ("Gold365", "the Platform", "We", "Us", or "Our") represents India's foremost, high-liquidity peer-to-peer (P2P) sports betting exchange, digital gaming wagering platform, and interactive entertainment portal operating under accredited international regulatory oversight. This comprehensive, exhaustive Privacy Policy ("Policy") governs the automated collection, systemic storage, cryptographic processing, analytical evaluation, cross-border transmission, and regulatory disclosure of Personal Identifiable Information (PII) belonging to all visitors, registered members, transaction originators, and verified account holders across our digital touchpoints.

For the formal statutory purposes of the Digital Personal Data Protection Act, 2023 (DPDP Act 2023, Act No. 22 of 2023, Republic of India), the Information Technology Act, 2000 (IT Act 2000, Section 43A and Section 72A as amended), the Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011 ("SPDI Rules 2011"), and the global gold benchmarks established under the General Data Protection Regulation (GDPR Regulation EU 2016/679), the designated statutory "Data Fiduciary" and "Data Controller" responsible for determining the means, lawful bases, parameters, and architectural frameworks of your personal data processing is Gold365 Interactive Consortium Limited.

Data Fiduciary ParameterCorporate & Operational Statutory Specification
Corporate Legal DesignationGold365 Interactive Consortium Ltd. (Trading Internationally as Gold365 India)
Corporate Licensing AuthorityCuracao eGaming Consortium Commission, Remote Digital Gaming Sub-License No. 8048/JAZ2020-013
Primary Operational Web Domainshttps://gold365play.com, secure enterprise mirror cluster nodes, native Android APK distribution mirrors
Statutory Data Protection Officer (DPO)Grievance Redressal Officer & Principal Data Compliance Lead (dpo@gold365play.com)
Indian Regulatory Jurisdiction NexusDigital Personal Data Protection Act, 2023 (Ministry of Electronics and Information Technology - MeitY)
Information Security StandardsISO/IEC 27001:2022 Certified Information Security Management Systems & PCI-DSS 4.0 Level 1 Audit Compliance

Gold365 functions predominantly as an impartial, automated order-matching sports betting exchange. Because our core exchange technology pairs opposing sports wagers (Back and Lay selections) between independent natural persons in real-time, transparency, cryptographic record integrity, non-repudiation, and stringent financial data hygiene form the bedrock of our operating infrastructure. We do not operate as an opaque, predatory bookmaker; rather, our technical servers act as an encrypted marketplace where fair market odds, real-time match liquidity, and verifiable transactional records are maintained with total institutional integrity.

In our capacity as a responsible Data Fiduciary under Indian law, we recognize that the stewardship of your confidential biographical details, financial records, and wagering footprints requires constant vigilance and continuous technical refinement. Our information security protocols undergo recurring third-party audits to ensure that the fundamental rights of Indian Data Principals are upheld at every operational tier. Whether you are generating a virtual practice Demo ID to test exchange software dynamics or moving substantial real-money balances via Unified Payments Interface (UPI) banking networks, your data is shielded by multi-layered defensive frameworks.

INSTITUTIONAL PRIVACY STATEMENT

Gold365 guarantees that your private financial details, governmental identification documents (such as Aadhaar, PAN, and Indian Passports), and linked Unified Payments Interface (UPI) virtual payment addresses are never commercialized, monetized, sold, rented, or traded to third-party marketing brokers or advertisement aggregators under any circumstances whatsoever.

SECTION 02

SCOPE & APPLICABILITY OF THIS PRIVACY POLICY

This Privacy Policy applies ubiquitously to any individual natural person ("User", "Player", "You", "Your", or "Data Principal") who visits, navigates, creates a trial Demo ID on, registers an authentic real-money betting account with, downloads software from, executes deposits through, wagers on, or communicates with the Gold365 ecosystem. The territorial and architectural scope of this instrument encompasses all digital surfaces under our operational control.

  • The primary official website located at gold365play.com alongside all authorized domestic subdomains, content delivery network (CDN) edge nodes, and encrypted mirror portals.
  • The proprietary Gold365 Android Native APK mobile applications, progressive web applications (PWA), and optimized mobile browser user interfaces.
  • All peer-to-peer sports exchange markets, live interactive casino streaming feeds, traditional Indian card tables (including Live Teen Patti and Andar Bahar), and virtual sports simulators.
  • All real-time customer support interactions conducted over official WhatsApp Business concierge endpoints, Telegram emergency alert broadcast channels, and direct email helpdesks.
  • All banking and settlement channels, automated UPI callback webhooks, IMPS bank payout processors, and decentralized cryptocurrency deposit addresses.
  • All verification, anti-fraud telemetry screenings, Know Your Customer (KYC) document pipelines, and Prevention of Money Laundering Act (PMLA) audit registries.
TERRITORIAL RESTRICTIONS & INDIAN STATE LEGAL NOTICE

Under the Constitution of India (Seventh Schedule, List II, Entry 34), state legislatures possess jurisdiction regarding gambling enactments within their territorial borders. Residents domiciled in Indian States where local statutory enactments expressly prohibit online real-money wagering (specifically Andhra Pradesh, Telangana, Assam, Odisha, Nagaland, and Sikkim) are strictly barred from opening real-money accounts. Any digital footprints or geolocation markers originating from excluded territories will be filtered to comply with regional enactments.

By accessing our Platform or initiating registration via our verified WhatsApp concierge, you explicitly affirm that you have attained the minimum legal age of majority (eighteen years of age or older), possess complete contractual competence under Section 11 of the Indian Contract Act, 1872, and provide informed, affirmative, unambiguous consent to the data collection, retention, and processing protocols detailed herein.

This Policy also extends to third-party digital touchpoints directly interfacing with Gold365 infrastructure, such as payment gateway intermediaries, automated identity verification gateways, and cloud telephony relays. However, where an external third-party platform operates under separate statutory custody (such as your personal banking institution or mobile telecommunications carrier), their independent privacy terms govern that specific communication leg. Gold365 assumes responsibility exclusively for the data streams flowing within our direct technological architecture.

SECTION 03

CATEGORIES OF PERSONAL DATA WE COLLECT

To deliver an ultra-fast, secure, and regulatory-compliant P2P sports betting exchange experience, Gold365 collects diverse categories of personal and technical data. In accordance with the foundational statutory principle of "Data Minimisation" codified under Section 6 of the DPDP Act 2023, we collect exclusively such data as is strictly necessary, adequate, relevant, and proportionate to fulfill lawful operational purposes.

3.1 Identity & Contact Telemetry Data

During initial account onboarding, WhatsApp-based authentication, and profile configuration, we process fundamental biographical markers. This includes your legal first and last name, date of birth, biological gender, mobile telephone number verified via OTP SMS or WhatsApp interactive dispatch, active electronic mail address, residential postal address, state of domicile, national citizenship, and unique alphanumeric Gold365 Member ID.

3.2 Indian Statutory Identity Verification (KYC) Data

To fulfill statutory anti-money laundering obligations and ensure absolute 18+ adult age compliance, Gold365 collects government-issued identification documentation prior to authorizing cumulative withdrawals exceeding designated thresholds or when elevated risk flags emerge. This includes:

  • Permanent Account Number (PAN): Ten-digit alphanumeric PAN card copies used for verifying taxpayer identity and preventing tax evasion under Indian financial regulations.
  • Aadhaar Card Records: Masked Aadhaar cards (wherein only the terminal four digits remain legible in strict adherence to UIDAI directives) or offline XML Aadhaar verification tokens.
  • Alternative Identity Credentials: Official Indian Passport photocopies, Election Commission of India Voter Identity Cards, or valid State Driving Licences.
  • Proof of Address (POA): Recent utility bills (electricity, piped gas, municipal water), post-paid cellular bills, or certified scheduled bank account statements dated within the prior 90 days.
  • Facial Biometric Liveness Verification: Real-time high-resolution photographic selfie portraits or video stream snippets to eliminate identity theft, synthetic avatars, and deepfake forgery.

3.3 Financial, Banking & UPI Settlement Data

Because Gold365 operates in Indian Rupees (INR) with sub-3-minute automated settlement capabilities, our transaction processing engines record critical banking markers. This includes your Unified Payments Interface (UPI) Virtual Payment Address (e.g., username@okaxis, username@okhdfcbank, mobile@paytm), bank account holder name, scheduled commercial bank branch name, IFSC code, account number, credit/debit card truncation hashes (last four digits only; CVV codes are never stored), and cryptocurrency public wallet addresses for USDT transactions.

3.4 Exchange Wagering, Market & Gaming Behavioural Data

Every order executed across our cricket betting exchange, football books, tennis courts, and live casino dealer rooms is systematically time-stamped and logged. This comprises placed bet timestamps, matched decimal odds, Back versus Lay proposition types, currency stake volumes, cancelled orders, market liquidity positions, cashout executions, session durations, loss streaks, and fancy session predictions.

3.5 Technical, Network & Hardware Telemetry Data

Whenever you interface with Gold365 web or mobile nodes, our web server daemons automatically harvest network diagnostic telemetry. This encompasses your public Internet Protocol (IPv4 and IPv6) address, approximate geographic city and state coordinates, internet service provider (e.g., Reliance Jio, Bharti Airtel, Vodafone Idea, ACT Fibernet), browser fingerprint, device model (e.g., Samsung Galaxy, Apple iPhone, Xiaomi, OnePlus), operating system version, screen resolution, referral URLs, and battery status metrics used for bot detection.

3.6 Customer Support & Communications Records

Every exchange of electronic messages between you and our support specialists is chronologically archived. This includes verbatim transcripts of WhatsApp conversations with our onboarding concierge, live chat interactions, recorded telephone audio logs from dispute resolution calls, and customer feedback surveys. These records serve as definitive evidential documentation in the event of transactional reconciliation challenges.

SECTION 04

METHODS & MODALITIES OF DATA COLLECTION

Gold365 captures information across multiple operational touchpoints utilizing direct, automated, and authorized third-party ingestion channels. We never utilize covert spyware, intrusive screen scraping, unauthorized microphone access, or deceptive background monitoring tools.

4.1 Direct Information Provided by You

The vast preponderance of personal data maintained within our encrypted datastores originates directly from your conscious, affirmative disclosures. This occurs whenever you register an account, fill out digital profile forms, converse with our verified 24/7 WhatsApp concierge desk, upload KYC documents through our secure portal, submit unique 12-digit UPI UTR transaction numbers, or participate in platform surveys and bonus promotional campaigns.

4.2 Automated Ingestion via Digital Tracking Protocols

As you interact with our exchange odds screens, dynamic charts, and live casino dealer streams, automated diagnostic cookies, HTML5 local storage tokens, session storage cache objects, and web beacon tags log your navigation paths. These technologies ensure your live session remains authenticated, eliminate latency during fast in-play odds transitions, and instantly alert our defensive perimeter if concurrent logins from conflicting IP addresses are detected.

4.3 Ingestion from Authorized Third-Party Partners

To validate transaction integrity and prevent international cybercrime, Gold365 receives operational telemetry from reputable third-party partners under strict non-disclosure and processing agreements:

  • Licensed Banking Intermediaries & Payment Aggregators: NPCI-accredited UPI merchant rails, IMPS banking nodes, and payment gateways that dispatch cryptographic webhook confirmations featuring your 12-digit UTR reference number upon successful fund transfers.
  • Automated KYC & Sanctions Screening Engines: Identity validation bureaus that match submitted PAN credentials against government databases, PEP (Politically Exposed Persons) registries, and international anti-terrorist financial sanction blacklists.
  • Cybersecurity & Bot-Mitigation Networks: Cloudflare Enterprise security layers and fraud-scoring vendors that identify malicious DDoS botnets, proxy networks, TOR exit nodes, and automated odds-scraping algorithms.
  • Responsible Gaming Consortia: Collaborative self-exclusion registries that signal if an incoming registrant has requested self-exclusion on peer licensed exchange platforms.

We strictly forbid our technology partners from repurposing data ingested on our behalf. All data sharing pipelines utilize mutual TLS (mTLS) authentication and API request signing to guarantee that ingestion streams cannot be intercepted or tampered with by hostile actors.

SECTION 05

PURPOSES FOR PROCESSING YOUR PERSONAL DATA

Under Section 4 and Section 5 of the DPDP Act 2023, personal data must be processed solely for explicit, lawful, and reasonable purposes specified to the Data Principal at the time of collection. Gold365 processes your data strictly in pursuit of the following operational, commercial, and statutory objectives:

Operational Processing PurposeUnderlying Data Types ProcessedLawful Justification & Business Rationale
Account Creation & WhatsApp ProvisioningMobile number, chosen username, password hash, demographic markersExecution of contractual obligations under Terms & Conditions
P2P Order Execution & Odds SettlementBack/Lay stake values, market selections, timestamped order logsCore platform service delivery; contractual performance
Instant 60-Second UPI Deposit & Withdrawal ProcessingUPI VPA handles, UTR numbers, bank IFSC, account holder namesSettlement of contractual payouts and financial reconciliation
Statutory KYC, Age Gate & AML VerificationAadhaar (masked), PAN cards, passports, liveness selfie feedsMandatory compliance with PMLA 2002 and licensing conditions
Fraud Prevention, Anti-Syndicate & Bot DefenseDevice IDs, IP telemetry, browser fingerprints, betting patternsLegitimate interests in safeguarding platform market integrity
Responsible Gambling Pattern TelemetrySession frequency, loss velocity, deposit amounts, self-exclusion notesStatutory duty of care and player protection obligations
Transactional Messaging & Security AlertsMobile telephone number, registered email, WhatsApp accountCrucial account security, 2FA OTPs, payout transfer confirmation
STRICT NON-COMMERCIALIZATION PLEDGE

Gold365 categorically does not sell, license, lease, barter, or distribute your email address, phone number, or banking records to external cold-calling telemarketers, credit card issuers, loan agencies, or independent marketing agencies. Your contact details are preserved solely for Gold365 operational security, platform messaging, and legitimate service enhancement.

Any internal machine learning algorithms or analytical models trained on platform telemetry utilize strictly anonymized, aggregated datasets. Individual user profiles are never subjected to automated profiling that generates adverse legal or financial determinations without manual human review and oversight by an authorized compliance officer.

SECTION 06

STATUTORY & LAWFUL BASES FOR PROCESSING UNDER LAW

Every processing activity executed across the Gold365 digital framework is anchored in an explicit, recognized lawful ground recognized under Section 4 of the Digital Personal Data Protection Act, 2023, the Information Technology Act, 2000, and international data protection standards. We never process personal data in an arbitrary, undocumented, or ungrounded manner.

6.1 Contractual Performance & Necessity

When you register an account, request a Gold365 ID, and click to accept our Terms and Conditions, a legally enforceable bilateral contract is formed pursuant to Section 10A of the Information Technology Act, 2000 and Section 10 of the Indian Contract Act, 1872. Processing your contact details, financial handles, and bet orders is strictly necessary for us to fulfill our contractual obligations—namely, providing odds liquidity, matching Back and Lay propositions, crediting winnings, and executing withdrawals.

6.2 Compliance with Statutory Legal Obligations

As an internationally licensed digital wagering enterprise interfacing with the Indian banking system, Gold365 is subject to stringent mandatory regulatory duties. Under the Prevention of Money Laundering Act, 2002 (PMLA) and Master Directions issued by banking authorities, we are legally mandated to verify member identities, confirm age eligibility, monitor for suspicious financial velocity, and preserve financial transaction audit logs for minimum statutory intervals.

6.3 Legitimate Business Interests

We process technical device telemetry, network diagnostics, and behavioral wagering telemetry on the grounds of our legitimate business interests. These interests include maintaining ironclad cybersecurity defenses, stopping distributed denial of service (DDoS) cyberattacks, detecting automated bot scripts, eliminating illegal syndicate match manipulation, and enhancing server throughput across peak Indian Premier League (IPL) cricket fixtures.

6.4 Explicit, Informed & Freely Given Consent

For non-essential features—such as promotional marketing alerts sent via WhatsApp or Telegram, optional personalized bonus notifications, and performance tracking cookies—we rely exclusively upon your explicit, informed, affirmative consent. You maintain the autonomous right to withdraw this consent at any time without incurring punitive account penalties.

SECTION 07

DATA SHARING, DISCLOSURE & THIRD-PARTY INTERFACES

Gold365 maintains a rigorous, zero-tolerance policy against the unauthorized dissemination, commercial broker syndication, or predatory monetization of personal data. We disclose personal information strictly to vetted recipients who operate under legally binding Data Processing Agreements (DPAs) incorporating strict non-disclosure, confidentiality, and data hygiene covenants.

7.1 Authorized Data Processors & Technology Vendors

To deliver frictionless gaming and high-speed banking, we collaborate with certified enterprise service providers who process data solely upon our explicit instructions:

  • Indian UPI Merchant Gateways & Banking Node Rails: Licensed payment partners who facilitate immediate INR deposit validation and automated 60-second UPI payouts via National Payments Corporation of India (NPCI) settlement rails.
  • KYC, AML & Identity Verification Bureaus: Accredited document authentication providers who perform cryptographic verification of PAN and Aadhaar records, PEP screenings, and biometric liveness checks.
  • Enterprise Cloud Infrastructure & Tier-4 Server Hosts: ISO/IEC 27001 certified cloud server infrastructure providers offering end-to-end encrypted database storage, automatic load balancing, and failover redundancy.
  • Cybersecurity, Anti-DDoS & Bot Defense Systems: Enterprise web application firewall (WAF) services that inspect incoming network traffic packets to neutralize malicious SQL injections, credential stuffing attacks, and scrapers.
  • Customer Relationship Management & WhatsApp Cloud APIs: Meta-authorized Business Solution Providers who relay official account activation credentials, deposit approvals, and two-factor authentication tokens.

7.2 Disclosure to Statutory Regulators & Law Enforcement Bodies

Gold365 may be compelled to disclose specific customer records, transaction histories, and IP telemetry to governmental authorities, law enforcement agencies, cybercrime investigation departments, judicial courts, or financial regulators (such as the Financial Intelligence Unit - India / FIU-IND) only upon the receipt of an authentic, legally valid court subpoena, formal statutory warrant, or binding statutory notice issued under applicable Indian or international law.

Prior to complying with any governmental disclosure directive, our internal legal counsel conducts a rigorous proportionality assessment to verify that the request emanates from a legitimate statutory jurisdiction, complies with due process, and restricts requested data elements exclusively to the subject matter of the formal inquiry.

STRICT PROHIBITION ON COMMERCIAL RESALE

Under no circumstance will Gold365 ever sell, lease, disclose, or make available your personal telephone numbers, bank account numbers, or wagering logs to insurance companies, lending apps, marketing telemarketers, or spam aggregators.

SECTION 08

CROSS-BORDER DATA FLOWS & INTERNATIONAL TRANSFERS

Gold365 operates an international digital exchange network with resilient distributed cloud server arrays spanning secure offshore financial and data jurisdictions, including Tier-3 and Tier-4 data center facilities located in Frankfurt (Germany), Singapore, and Ireland. Consequently, personal data collected from users residing in India may be transmitted, processed, and stored on servers situated outside the geographic borders of the Republic of India.

8.1 Compliance with Section 16 of the DPDP Act 2023

Section 16 of the Digital Personal Data Protection Act, 2023 permits the cross-border transfer of personal data to foreign jurisdictions, except to countries or territories specifically blacklisted or restricted by central governmental gazette notification. Gold365 guarantees that all international transfers are executed strictly to jurisdictions that uphold equivalent, robust personal data protection standards and human rights safeguards.

8.2 Contractual Safeguards & Standard Contractual Clauses (SCCs)

Whenever personal data is transferred across international boundaries, Gold365 implements robust statutory safeguards:

  • Standard Contractual Clauses (SCCs): Enforceable corporate data transfer agreements compelling recipient entities to afford data protection standards identical to those mandated by Indian and EU privacy legislation.
  • End-to-End Cryptographic Tunneling: All data in transit across oceanic fiber cables is encrypted using TLS 1.3 cryptographic suites with 256-bit Advanced Encryption Standard (AES) keys, rendering interception by hostile entities mathematically impossible.
  • Technical & Organizational Controls: Foreign server nodes are governed by strict biometric physical access barriers, zero-trust network architectures, and multi-tenant cryptographic isolation.

We periodically re-evaluate international server jurisdictions to verify political stability, judicial independence, and adherence to international cybersecurity treaties. In the event that a foreign jurisdiction enacts hostile surveillance legislation, we retain automated failover mechanisms to migrate datastores to alternative compliant sovereign territories within hours.

SECTION 09

DATA RETENTION SCHEDULES & ERASURE FRAMEWORKS

In conformity with the storage limitation principles articulated under the DPDP Act 2023 and international privacy accords, Gold365 retains personal data exclusively for the duration necessary to accomplish the explicit business and legal purposes for which it was originally collected, or as required by governing statutory enactments.

Data Category / Record TypeStandard Statutory Retention DurationGoverning Legal & Statutory Justification
Active Account Identity & Profile RecordsDuration of active account lifecycle + 5 years post-closurePrevention of Money Laundering Act (PMLA) 2002 audit mandate
Financial Transactions & UPI Settlement LogsMinimum 5 to 7 calendar years from transaction dateMandatory financial accounting, taxation, and banking reconciliation laws
KYC Identification Documentation (PAN, Aadhaar)5 years following formal termination of business relationshipSection 12 of PMLA 2002 statutory customer verification records retention
Exchange Betting Slips & Live Odds Wagers3 calendar years from market settlement conclusionDispute resolution, integrity audits, and fair-settlement arbitration
Customer Care Chats, WhatsApp Logs & Emails2 calendar years from date of inquiry ticket closureQuality assurance, grievance handling, and customer service optimization
Technical Server Telemetry, IP Logs & CookiesRolling 90 to 180 days on automated purge cyclesCybersecurity intrusion detection, bot scoring, and server optimization

Upon the expiration of the applicable retention schedule, or upon receipt of a valid, legally authenticated request for data erasure (where no competing statutory obligation mandates continued storage), personal data is securely purged from live production databases using DoD 5220.22-M cryptographic sanitization standards or converted into irreversibly anonymized statistical aggregates devoid of individual identifiers.

Where account balances remain dormant or unclaimed, transactional records are archived into cold-storage encrypted vaults accessible exclusively to our Principal Compliance Officer. This ensures that dormant accounts can be lawfully reactivated or liquidated upon proper identity re-verification by the rightful account owner or designated legal nominee.

SECTION 10

COOKIES, WEB BEACONS & TRACKING ARCHITECTURE

The Gold365 website, progressive web application, and digital odds consoles utilize cookies, pixel tags, session storage tokens, and web beacon scripts to deliver an exceptionally responsive, personalized, and secure digital exchange experience. Cookies are miniature alphanumeric text files placed on your computer, smartphone, or tablet hard drive by our web servers.

10.1 Classification of Cookies Deployed on Gold365

  • Strictly Necessary & Security Cookies: Indispensable tokens required for basic platform operation, session persistence, multi-factor authentication validation, and CSRF (Cross-Site Request Forgery) protection. Without these cookies, authenticated access to the exchange and withdrawal portals is technically impossible.
  • Performance & Latency Optimization Cookies: Analytical cookies that calculate page load velocities, edge server response times, and WebSocket telemetry during high-traffic cricket matches, ensuring zero-lag odds synchronization.
  • Functional & Preference Cookies: Configuration tokens that remember your chosen odds display format (Decimal, Fractional, American), active currency settings (INR), audio settings on live casino tables, and preferred sportsbook sport categories.
  • Analytical & Fraud-Detection Cookies: Aggregated, privacy-preserving tracking tools that identify anomalous navigational velocity, multi-tab odds manipulation, and bot scraping attacks across exchange order books.

10.2 User Autonomy & Cookie Management Controls

You maintain sovereign control over cookie deployment. Through your web browser settings (Google Chrome, Mozilla Firefox, Safari, Microsoft Edge, Brave), you may choose to inspect, block, reject, or purge all non-essential cookies. Please recognize that disabling strictly essential cookies will impair key platform features, including your ability to maintain persistent login sessions or submit in-play exchange bet slips.

We do not engage in invasive cross-site tracking or behavioral surveillance across external un-affiliated websites. The analytical tokens deployed by Gold365 measure interactions exclusively within the borders of our own web properties and native applications to optimize server capacity during peak Indian Premier League (IPL) and ICC World Cup matches.

SECTION 11

YOUR STATUTORY DATA PROTECTION RIGHTS UNDER THE DPDP ACT

As a valued Member and registered Data Principal, you are endowed with comprehensive statutory rights codified under Chapter III (Sections 11 through 14) of the Digital Personal Data Protection Act, 2023, alongside corresponding global data privacy frameworks. Gold365 is committed to ensuring that you can exercise these rights freely, transparently, and without procedural impediment.

Right to Access & Summary (Section 11)

You have the statutory right to request a concise summary of the personal data currently being processed by Gold365, the specific operational processing activities undertaken, and the identities of all third-party data processors with whom your information has been shared.

Right to Correction & Erasure (Section 12)

You possess the right to correct inaccurate or misleading personal data, complete incomplete biographical records, update outdated contact numbers, and request the permanent erasure of your personal data where retention is no longer mandated by statutory enactments (such as PMLA).

Right of Grievance Redressal (Section 13)

You are entitled to prompt, transparent grievance resolution regarding any perceived infringement of your data privacy. Gold365 maintains an institutional Grievance Redressal Officer dedicated to acknowledging inquiries within 72 hours and resolving tickets within 30 calendar days.

Right to Nominate (Section 14)

You have the right to officially nominate another natural person who shall, in the unfortunate event of your physical incapacitation or demise, possess the legal authority to exercise your data protection rights and request fund repatriation.

To submit a formal Data Subject Access Request (DSAR) or exercise your statutory privacy rights, dispatch an electronic communication from your registered email address to our Data Protection Officer at dpo@gold365play.com or message our dedicated compliance helpdesk over verified WhatsApp. We process all valid requests free of charge following basic identity confirmation to prevent fraudulent data harvesting.

Upon receipt of a verified request for data portability, our engineering team generates an encrypted, machine-readable JSON or CSV archive containing your historic transaction ledgers, matched betting histories, and registered profile attributes, allowing seamless transmission to alternative compliant services.

SECTION 12

TECHNICAL, CRYPTOGRAPHIC & ORGANIZATIONAL DATA SECURITY

At Gold365, safeguarding the sanctity, confidentiality, and operational availability of user data is an existential business priority. Handling crores of rupees in daily turnover across high-stakes sports exchange markets necessitates military-grade cyber defense postures. We implement holistic technological, physical, and administrative safeguards that fully comply with Section 8(5) of the DPDP Act 2023, Rule 5(8) of the SPDI Rules 2011, and the ISO/IEC 27001:2022 international information security benchmark.

  • 256-Bit SSL/TLS 1.3 Transport Encryption: All communications between your client device and our edge servers are cloaked within end-to-end cryptographic tunnels using modern cipher suites (ECDHE-RSA-AES256-GCM-SHA384), rendering packet sniffing and man-in-the-middle exploits completely impotent.
  • AES-256 Bit Encryption at Rest: All stored databases, identity verification records, KYC document images, and transaction histories are encrypted at rest using industry-standard Advanced Encryption Standard with 256-bit keys managed through hardware security modules (HSM).
  • Multi-Factor Authentication (MFA / 2FA): All critical operational surfaces—including administrative portals, high-value withdrawal authorizations, and password modification dialogues—mandate secondary biometric or time-based one-time password (TOTP) verification.
  • Role-Based Access Control (RBAC): Employee access to customer personal records is strictly governed on a "need-to-know" basis. Customer support representatives possess visibility only into truncated identifiers necessary to troubleshoot immediate inquiries.
  • Continuous Penetration Testing & Red Team Audits: Independent, accredited ethical cybersecurity firms execute quarterly penetration tests, vulnerability assessments, and automated threat hunting against our digital boundaries.
  • Automated Intrusion Detection & DDoS Shielding: Enterprise cloud WAF configurations absorb volumetric DDoS attacks up to multi-terabit scales while real-time SIEM systems analyze event logs for anomalous intrusion attempts.
SHARED RESPONSIBILITY SECURITY NOTICE

While Gold365 maintains bank-grade cybersecurity perimeters, information security remains a shared obligation. You are strictly advised to maintain complex, unique account passwords, never divulge OTP verification codes to third parties, avoid accessing accounts across public Wi-Fi hotspots without VPN protection, and immediately alert our security team if you suspect your personal device has been compromised.

In the improbable event of a suspected or confirmed data security incident, Gold365 maintains an institutional Incident Response Plan. In strict adherence to Section 8(6) of the DPDP Act 2023, our Data Protection Officer will notify the Data Protection Board of India and affected Data Principals within seventy-two (72) hours of incident verification, accompanied by remedial action guidance.

SECTION 13

PROTECTION OF MINORS, CHILDREN'S PRIVACY & 18+ MANDATE

Gold365 is strictly, unequivocally, and uncompromisingly an adult-only digital exchange platform. Under Section 9 of the Digital Personal Data Protection Act, 2023, stringent statutory duties are imposed on data fiduciaries regarding the personal data of children (defined under Indian law as any natural person who has not attained eighteen years of age). We do not knowingly solicit, collect, process, or store personal data belonging to minors.

13.1 Multi-Layered Age Verification Defenses

To prevent underage access to real-money sports wagering, Gold365 deploys rigorous structural filtering mechanisms:

  • Mandatory Date-of-Birth Declaration: Every registrant must explicitly confirm their birth date during initial onboarding; any profile indicating an age below 18 years is instantly blocked by registration logic.
  • Government Photo ID Document Verification: Prior to processing cash withdrawals, submitted PAN cards, Aadhaar cards, or passports are verified to confirm legal adult age.
  • Biometric Facial Age Estimation: High-risk accounts are subjected to automated biometric liveness scans to identify age anomalies and proxy account operation.
ZERO-TOLERANCE UNDERAGE ACCOUNT ACTION

If Gold365 discovers or has reasonable grounds to suspect that an individual under the age of eighteen has established an account or submitted personal data, our security team will immediately freeze the account, void all pending wagers, forfeit all derived winnings, refund remaining un-wagered principal deposits, and permanently purge all associated personal records from our active member directory.

We urge parents, guardians, and educators to utilize filtering software (such as Net Nanny, CyberPatrol, or Google Family Link) to prevent minors from accessing digital gaming platforms. If you believe your child has registered an unauthorized account on Gold365, please notify our security bureau immediately at security@gold365play.com for emergency account closure.

Furthermore, Gold365 strictly refrains from undertaking any tracking, behavioral profiling, targeted advertising, or algorithmic merchandising directed at children. All marketing campaigns deployed by Gold365 adhere to advertising self-regulation codes issued by the Advertising Standards Council of India (ASCI), featuring prominent disclaimers regarding financial risk and the statutory 18+ adult age threshold.

SECTION 14

THIRD-PARTY WEBSITES, EXTERNAL APIS & AFFILIATE PORTALS

Throughout your interaction with Gold365, you may encounter hyperlinks directing you toward external websites, digital interfaces, banking portals, sports statistical providers, cricket scorecard aggregators, or third-party affiliate web pages. These external domains are operated entirely independently of Gold365 and maintain autonomous data collection, cookie deployment, and privacy practices.

Gold365 does not exercise editorial oversight, regulatory custody, or legal control over the content, privacy protocols, data security frameworks, or terms of service enforced by external entities. The inclusion of an outbound hyperlink does not constitute an endorsement, authorization, warranty, or representation of our affiliation with that third party.

When you transition from Gold365 to an external banking page (such as a commercial bank's Net Banking portal or an authorized UPI application interface), your interactions are governed exclusively by that third party's privacy documentation. We strongly encourage all users to review the privacy policies of any external destination before disclosing personal identification or financial credentials.

Similarly, while our official community engagement channels on Telegram, YouTube, and Instagram provide informative tournament match schedules and exchange tutorials, any information you publish within public social comment fields is accessible to the general public. We caution all users never to broadcast their private account numbers, registered mobile numbers, or UTR receipts across public discussion boards.

SECTION 15

DIRECT MARKETING COMMUNICATIONS & CONSENT REVOCATION

Subject to your explicit, affirmative, opt-in consent provided during registration or through account settings, Gold365 may dispatch informational, promotional, and marketing communications across authorized digital channels. These communications may notify you of upcoming Indian Premier League (IPL) high-odds fixtures, ICC World Cup deposit bonuses, weekly cashback distributions, new live casino dealer table launches, and exclusive VIP exchange loyalty rewards.

15.1 Channels of Promotional Communication

  • Official WhatsApp Broadcasts: Opted-in promotional alerts delivered via certified business communication channels featuring current match market odds and bonus codes.
  • Telegram Channel Alerts: Instant notifications regarding server status, high-liquidity order book notifications, and priority withdrawal promotions.
  • SMS & Transactional Text Notifications: Operational time-sensitive alerts concerning account activation, balance updates, and password assistance.
  • Electronic Direct Mail (EDM): Weekly statistical digests, tournament fixture guides, and seasonal promotional newsletters.

15.2 Autonomous Opt-Out & Unsubscribe Mechanisms

You retain absolute autonomy over your communication preferences. You may revoke your marketing consent at any time through simple, frictionless avenues:

  • Clicking the "Unsubscribe" hyperlink embedded within the footer of any promotional email dispatched by Gold365.
  • Replying with the keyword "STOP" or "UNSUBSCRIBE" to any promotional SMS or WhatsApp dispatch received from our verified desks.
  • Adjusting your "Notification & Marketing Preferences" within your Gold365 member dashboard.
  • Directing an electronic message to our support desk at support@gold365play.com requesting immediate removal from marketing lists.

Please note that opting out of promotional marketing dispatches does not affect critical transactional, administrative, or operational notifications (such as deposit confirmations, withdrawal UTR receipts, 2FA security codes, or statutory terms amendments) essential to managing your account.

Gold365 processes consent revocations promptly; automated systems update communication suppressions within twenty-four (24) hours of receipt. We do not charge fees, impose delays, or require complex administrative steps to opt out of promotional messages.

SECTION 16

RESPONSIBLE GAMING DATA USE & PLAYER WELFARE MONITORING

Gold365 is passionately committed to fostering a sustainable, safe, and healthy gaming environment. Wagering on sports exchange markets should always remain a pleasurable recreational diversion, never an unmanageable financial burden or emotional compulsion. In fulfillment of our statutory duty of care and licensing mandates, we analyze specific behavioral data patterns to protect vulnerable members from problem gambling behaviors.

16.1 Automated Behavioral Telemetry & Welfare Screening

Our risk management algorithms continuously monitor anonymized transactional velocity indicators, including:

  • Sudden, atypical escalations in deposit frequency or financial wagering volumes.
  • Chasing losses through rapid successive wagers following a settled negative outcome.
  • Prolonged continuous gaming sessions extending across unusual nocturnal hours.
  • Repeated failed deposit transactions indicating financial strain or payment exhaustion.

16.2 Player Protection Interventions & Support Resources

When behavioral markers trigger welfare thresholds, our compliance team may intervene by imposing temporary cooling-off timeouts, establishing mandatory daily deposit caps, or initiating direct welfare check-ins via WhatsApp. Furthermore, where a player requests formal self-exclusion, their personal details are flagged in our central exclusion registry to bar subsequent account generation across the Gold365 network.

CONFIDENTIAL ASSISTANCE HELPLINES

If you or someone you know is experiencing difficulties with gambling addiction, free and confidential support is available. Contact Hope Trust India (+91 90008 50001) or visit Gambling Therapy (gamblingtherapy.org) for 24/7 expert counseling and support.

All telemetry harvested under our responsible gaming monitoring framework is segregated from marketing engines. Behavioral welfare data is utilized solely for player protection and risk mitigation, never to formulate tailored commercial promotions or exploit player vulnerability.

SECTION 17

CHANGES, REVISIONS & NOTIFICATIONS OF POLICY AMENDMENTS

As Indian regulatory frameworks evolve—particularly regarding digital gaming guidelines, central data protection board enactments under the DPDP Act 2023, and emerging judicial precedents—Gold365 periodically reviews and amends this Privacy Policy to ensure continual compliance and total operational transparency.

Whenever material revisions are implemented that alter the nature, scope, purposes, or third-party sharing frameworks of your personal data, Gold365 will provide prominent notification prior to the changes taking effect. Notification modalities include:

  • A conspicuous modal broadcast or system banner displayed upon your next login to the website or mobile APK.
  • An official electronic dispatch transmitted to your registered email address detailing key statutory adjustments.
  • An official announcement published across our verified Telegram broadcast bulletin and WhatsApp helpdesk channels.

The "Last Updated" date indicated in the header of this instrument signifies the effective statutory timestamp of the current iteration. Your continued access to the Platform, maintenance of an active Gold365 ID, or placement of exchange bets following the promulgation of revisions constitutes your unequivocal acceptance of the updated terms.

We maintain an immutable digital archive of previous versions of this Privacy Policy. Should you require historical copies for legal or tax verification purposes, our Data Protection Officer will furnish previous versions upon written application to dpo@gold365play.com.

SECTION 18

GRIEVANCE REDRESSAL OFFICER, DPO & LEGAL CONTACT CHANNELS

Pursuant to Section 13(1) of the Digital Personal Data Protection Act, 2023 and Rule 5(9) of the Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011, Gold365 has established a dedicated, professional Grievance Redressal Mechanism to address your inquiries, concerns, and data privacy rights requests.

Compliance Officer / BureauOfficial Contact Details & Operational Responsibilities
Data Protection Officer (DPO)dpo@gold365play.com · Statutory DPDP Act compliance, Data Subject Access Requests (DSAR), privacy audits
Grievance Redressal Officergrievance@gold365play.com · Formal complaints, identity disputes, statutory appeal handling
Legal & Regulatory Affairslegal@gold365play.com · Law enforcement requests, court summons, regulatory notices, PMLA compliance
Information Security & Cyber Fraudsecurity@gold365play.com · Data breach reports, account compromise alerts, unauthorized access claims
24/7 Customer Support Desksupport@gold365play.com · Verified WhatsApp Concierge (24x7 Instant Assistance)
Statutory Response TimelinesFormal Acknowledgment within 72 hours · Comprehensive Resolution within 30 calendar days

If you are not satisfied with the grievance redressal outcome provided by our Data Protection Officer, you retain the statutory prerogative under Section 13(3) of the DPDP Act 2023 to escalate your complaint to the Data Protection Board of India (DPBI).

Gold365 is committed to cooperating fully with regulatory investigations and providing transparent, timely documentation to substantiate our data protection compliance at all times.

By accessing and using Gold365, you confirm that you have read, understood, and agree to the collection, processing, and protection of your personal data as set forth in this Privacy Policy.