Legal
Cosmobet Data Notice
A straight explanation of the personal data Cosmobet holds about UK players, why we hold it, who we share it with and the rights you can use under UK GDPR and the Data Protection Act 2018.
In one line: Cosmobet only holds the data it genuinely needs to verify your age, secure the account, process payments, prevent fraud and meet UK Gambling Commission rules. You can request a copy, a correction or a deletion at any time.
This Data Notice explains how Cosmobet ("we", "us", "our") handles personal data when you use cosmobett.net or any associated service. It applies to every adult UK resident who registers an account, browses the site or contacts the support team. By using Cosmobet you agree to the practices set out below; if you do not agree, please stop using the service and close your account from the dashboard.
Your UK GDPR rights, first
Most data-notice pages bury this. We put it up front because it is what most readers want to know. Under UK GDPR you have the right to access the personal data we hold about you, to ask us to correct anything inaccurate, to ask us to delete it (subject to the regulatory retention windows below), to restrict or object to certain processing, to receive a portable copy of the data you have provided, to withdraw consent for marketing at any time and to complain to the Information Commissioner's Office at ico.org.uk if you feel we have not handled your data properly.
To use any of those rights, email the Data Protection Officer at privacy@cosmobett.net. We aim to respond inside five working days and always reply inside the statutory one calendar month. We may ask for proof of identity before releasing personal data so the response goes to the right person, but the request itself is free and we will not require a reason for it.
What personal data we hold
When you open a Cosmobet account we ask for the minimum information needed to verify you and meet UK Gambling Commission Know-Your-Customer expectations: full name, date of birth, residential address, email, phone number and a username. We also record the sign-up IP, the device fingerprint and the time of registration so we can spot suspicious patterns.
During verification we may ask for a photo ID such as a passport or driving licence, a recent proof of address such as a bank statement or utility bill, and, for higher-stakes accounts, a proof of source of funds such as a payslip or savings statement. Every deposit, withdrawal, bet and spin generates transactional data (method, amount, currency, game or market, outcome) which we are legally required to retain. We also collect technical data such as browser type, operating system, broad geographic location based on IP and the pages you visit, mostly to keep the platform secure and fast.
Why we hold it and the legal basis
We process personal data on the legal bases set out in Article 6 of the UK GDPR. Performance of a contract covers operating your account, processing deposits and paying out withdrawals. Legal obligation covers age verification, anti-money-laundering checks, regulatory reporting to the UK Gambling Commission and lawful information requests from the police or HMRC. Legitimate interest covers fraud prevention, platform analytics and improving the slot lobby. Consent covers non-essential marketing emails, push notifications and personalised promotions; that consent can be withdrawn at any time from your account preferences or via the unsubscribe link in any marketing message.
Who we share data with
We share data only with parties that play a direct role in operating Cosmobet safely. That covers our payment processors (Stripe, Trustly, Worldpay and similar) for deposits and withdrawals; identity verification providers such as Onfido and GBG for KYC checks; the game studios (Pragmatic Play, NetEnt, Evolution, Play'n GO, Hacksaw and similar) who supply the games you launch; analytics providers such as Google Analytics 4 in a privacy-preserving configuration; cloud hosting providers based in the UK and EEA; and the UK Gambling Commission, GamStop and law enforcement when we are required to do so by law.
We never sell your personal data, and we never share it with third parties for their own marketing purposes. Every processor that handles data on our behalf is bound by a data-processing agreement that requires them to apply at least the same standards of confidentiality and security as we do, and to delete the data at the end of the engagement.
How long we keep it
Account and transactional data is kept for the lifetime of the account and for a further seven years after closure, in line with UK Gambling Commission record-keeping requirements and HMRC tax legislation. Marketing preferences are kept until you withdraw consent or close your account. Technical analytics data is held for 26 months in identifiable form and then either anonymised or deleted. Documents uploaded for verification are kept securely for six years after the last use of the account, then destroyed.
How we keep it secure
Cosmobet runs on HTTPS with HSTS across the whole estate, with TLS 1.3 by default and modern cipher suites only. Card details are tokenised by PCI-DSS certified processors and never stored on Cosmobet servers. Production databases are encrypted at rest with AES-256 and access is restricted on a strict least-privilege basis with mandatory two-factor authentication for every team member. External CREST-accredited penetration testing runs on a documented schedule and continuous automated vulnerability scanning runs against every release.
International transfers
Most processing takes place inside the United Kingdom or the European Economic Area. Where data does need to leave the UK and EEA, the transfer relies on the UK International Data Transfer Agreement or the European Commission's Standard Contractual Clauses, supplemented by appropriate technical measures such as encryption in transit and at rest.
Children
Cosmobet is strictly an 18+ service. We do not knowingly collect personal data from anyone under the age of eighteen. If you are a parent or guardian and believe a minor has registered, please contact us immediately so we can close the account and refund any deposits.
Changes to this notice
We may update this Data Notice from time to time to reflect changes in the law, regulation or our own practices. Material changes will be notified by email at least 30 days before they take effect, and the "Last updated" date below will always reflect the current version. Continued use of Cosmobet after the change takes effect is taken as acceptance of the updated notice.
Last updated: 4 June 2026

