Privacy policy
What personal data we collect, how we use it, how long we retain it, and how to exercise your rights under India’s Digital Personal Data Protection Act 2023.
How your data is handled
- Data Fiduciary identity
- What data we collect
- What we do not collect
- Purposes of processing
- Legal basis under DPDPA 2023
- Cookies and tracking technologies
- Affiliate links and operator data
- Third-party services and processors
- Cross-border data transfers
- Data retention periods
- Your rights under DPDPA 2023
- Children and minors
- Security measures
- Breach notification
- Data Protection Officer
- Right to complaint
- Updates to this policy
- Contact
Data Fiduciary identity
Naseebbet ("we", "us", "our") is the Data Fiduciary as defined under Section 2(i) of the Digital Personal Data Protection Act 2023 for personal data collected through the website naseebbet.com. We determine the purposes and means of processing personal data described in this policy.
What data we collect
- Server logs: IP address, browser user-agent, referring URL, pages visited, timestamps, HTTP response codes. Collected automatically by web server software for security and traffic analysis. Retention: 30 days.
- First-party cookies: session cookies for site functionality (cart-style preference storage, no tracking). Retention: session lifetime + 30 days.
- First-party analytics: aggregated, cookie-less analytics (Plausible) tracking page views, referrer, device type, country. No personal identification possible from analytics data alone.
- Email correspondence: if you contact us at hello [at] naseebbet [dot] com, privacy [at] naseebbet [dot] com or grievance [at] naseebbet [dot] com, we retain the email thread for the duration of correspondence and 12 months after the last reply.
- Click-through tracking: when you click an affiliate link (/go/{operator}/), we log the click event with timestamp, IP and referrer for affiliate-attribution purposes. No personally identifying data is shared with the operator beyond the standard HTTP referrer.
What we do not collect
- Nothing belonging to an advertising network: there is no Google Ads tag, no Meta Pixel and no DoubleClick call anywhere in the page source
- Behavioural profiles that follow a reader from one website to the next are never assembled, purchased or consulted
- Nothing is passed to a data broker, and no aggregator pixel has ever been placed in the page templates
- Financial identifiers stay outside our systems entirely — PAN, Aadhaar, bank account numbers and payment card details are never requested, because this is a review publication rather than a betting operator, and your account with any operator is invisible from here
- Sensitive-category personal data as defined under DPDPA 2023 — biometric records, health information and GPS-precise location among them — is neither collected directly nor inferred from anything else we hold
Purposes of processing
- Site security and abuse prevention (server logs)
- Aggregate traffic analytics for editorial planning (Plausible)
- Affiliate-attribution accounting (click-through tracking)
- Editorial correspondence (email)
- Compliance with applicable law (record retention as required)
Personal data gathered for these purposes is not reused for automated decision-making, for profiling or for marketing of any kind. Each purpose is served by the smallest record that satisfies it, and a record that has outlived its stated purpose is discarded outright, never repurposed for something else.
Legal basis under DPDPA 2023
- Section 4(1)(a) consent: implicit consent given by visiting the site and not opting out of cookies (functional cookies are essential)
- Section 7(c) legitimate use: for compliance with legal obligations (record-keeping)
- Section 7(g) legitimate use: for performance of any function under any law (regulatory compliance)
Cookies and tracking technologies
Only first-party cookies are written from naseebbet.com. Third-party tracking cookies, advertising pixels and browser-fingerprinting techniques are absent by design, not merely switched off in a setting somewhere, and the individual file names, their stated purposes and their expiry periods are itemised in our Cookie Policy.
Affiliate links and operator data
A /go/{operator}/ link performs a redirect to the operator’s own domain, carrying a parameter that attributes the click to Naseebbet. Once that redirect completes you are inside their systems: whatever they store is stored under their name, on the legal basis their own notice sets out, and for a period they alone determine. This policy governs naseebbet.com and stops at the moment of handover.
Nothing travels back in the other direction either. Your operator account, your betting history, your wallet balance and every action taken after the handover remain entirely invisible from this side, because the commercial arrangement is a click-attribution model and carries no data feed from the operator to the publication.
Third-party services and processors
| Service | Purpose | Data shared | Location |
|---|---|---|---|
| Cloudflare | CDN, DDoS protection | IP, request metadata | Global edge nodes |
| Plausible Analytics | Traffic analytics | Aggregated, no PII | EU (Germany) |
| Hosting provider | Site hosting, server logs | IP, request data | India (primary), EU (backup) |
| Email service | hello@/privacy@/grievance@ delivery | Email contents | India (primary) |
Each processor is contractually bound to security and confidentiality terms equivalent to DPDPA 2023 standards.
Cross-border data transfers
Cloudflare CDN nodes are global; analytics processing happens in the EU; primary hosting is in India with EU backup. All cross-border transfers are to jurisdictions with comparable data-protection frameworks (EU GDPR, UK GDPR). The Government of India under Section 16 of DPDPA 2023 may restrict transfers to specific countries; we comply with any such notifications.
Data retention periods
| Data category | Retention period | Basis |
|---|---|---|
| Server logs | 30 days | Security, then aggregated/discarded |
| Functional cookies | Session + 30 days | Site functionality |
| Plausible analytics | Indefinite (no PII) | Editorial planning |
| Email correspondence | 12 months after last reply | Editorial workflow + record-keeping |
| Affiliate click logs | 24 months | Commission reconciliation |
| DSAR records | 3 years after closure | DPDPA 2023 audit trail |
Your rights under DPDPA 2023
- Right to access (Section 11) — obtain confirmation of processing and a summary of personal data held
- Right to correction and erasure (Section 12) — correct inaccurate data; request erasure where lawful basis no longer applies
- Right to grievance redressal (Section 13) — raise complaints with our Data Protection Officer
- Right to nominate (Section 14) — designate another person to exercise your rights in case of incapacity or death
- Right to withdraw consent (Section 6) — withdraw any consent given for processing at any time
Any of these rights is exercised in writing to privacy [at] naseebbet [dot] com. State which right is being invoked and enclose proof of identity, since a request cannot be actioned until it has been matched to the Data Principal it concerns. A substantive reply is issued within 30 days of receipt, and a request that is refused is refused in writing with reasons.
Children and minors
The site is written for an adult audience and is not intended for anyone under 18; personal data is never knowingly collected from a minor. Section 9 of DPDPA 2023 conditions the processing of a child’s personal data on verifiable parental consent, and where such data reaches us in spite of the age restriction it is deleted immediately, without waiting for a request to arrive. A parent or guardian with reason to believe a child has submitted data may raise it at privacy [at] naseebbet [dot] com, enclosing evidence of guardianship; the record is located and erased once that evidence is checked.
Security measures
- HTTPS/TLS encryption on all connections
- Firewall and DDoS protection (Cloudflare)
- Access control on backend systems with multi-factor authentication
- Regular security patching of WordPress core, plugins, themes
- Daily automated backups with 30-day retention
- No storage of payment card or financial data
Breach notification
Under Section 8(6) of DPDPA 2023, we notify affected Data Principals and the Data Protection Board of India of personal-data breaches without undue delay (target: within 72 hours of detection). Notifications include the nature of the breach, categories of data affected, likely consequences, and mitigation measures.
Data Protection Officer
Email: privacy [at] naseebbet [dot] com
Oversight of this policy rests with the DPO, who takes data-subject access requests from receipt through to closure, keeps the audit trail those requests generate, and serves as the designated liaison to the regulator on any matter arising under DPDPA 2023.
Right to complaint to the Data Protection Board of India
If we fail to address your grievance, you may lodge a complaint with the Data Protection Board of India under Section 27 of DPDPA 2023. The Board’s contact details are published on the Ministry of Electronics and Information Technology website.
Updates to this policy
Three things trigger a revision: an amendment to the governing statute, a genuine change in how data is handled here, and the addition or removal of a processor in the stack. A material change is announced by a site-wide banner that runs for 30 days from the moment the new text takes effect, and each version carries its own effective date, the most recent of which is the version in force. A superseded version ceases to apply on publication of its replacement, and no revision is given retroactive effect over data already collected under the earlier text.
Contact
Routine correspondence about this policy is handled at privacy [at] naseebbet [dot] com. Formal grievance redressal under the IT Rules 2021 runs through the separate address grievance [at] naseebbet [dot] com, monitored on its own so that the statutory response clock is tracked against each complaint individually.