Your privacy matters to us. This Privacy Policy explains what personal data 666duit collects, why we collect it, how it is used and protected, and what rights you hold in relation to that data as a Member of the 666duit platform.
666duit ("we", "us", "our", "the Platform") is committed to protecting the personal data of all Members and visitors to its platform in accordance with applicable data protection law and the data privacy obligations imposed on us under our international gaming authority licence. This Privacy Policy describes the nature, scope, and purposes of the personal data processing carried out by 666duit in the course of providing online gaming services to Members across Malaysia and other permitted jurisdictions.
We recognise that trust is foundational to the relationship between a gaming platform and its members. Malaysian players who choose 666duit are sharing sensitive financial and identity information with us — information that enables us to operate legally, prevent fraud, and fulfil our regulatory obligations. This Privacy Policy is our commitment to handle that information with care, transparency, and proportionality.
This Policy should be read alongside the 666duit Terms & Conditions, which form the complete legal framework governing your use of the platform.
When you create a 666duit account, we collect: full legal name; date of birth; email address; mobile number; country and state of residence (e.g., Selangor, Kuala Lumpur, Johor, Penang); and a username and password of your choosing. This information is mandatory for account creation and forms the core of your Member profile.
To fulfil our anti-money-laundering (AML) and Know Your Customer (KYC) obligations under our international gaming licence, 666duit may request documentary evidence of identity and address. This includes copies of government-issued identification (Malaysian MyKad, passport), proof of residential address (utility bill, bank statement), and — in some circumstances — source-of-funds documentation. KYC verification is triggered at specific withdrawal thresholds and where our compliance processes flag a requirement for additional due diligence.
We collect the payment method details necessary to process deposits and withdrawals, including e-wallet identifiers (Touch 'n Go eWallet, Boost, GrabPay), Malaysian bank account numbers (Maybank, CIMB, Public Bank), FPX transaction references, DuitNow IDs, and USDT TRC20 wallet addresses where applicable. We do not store full card numbers or banking passwords — financial transaction data is handled through our licensed payment processor integrations.
We record all transactions associated with your 666duit account: deposits, withdrawals, bets placed, games played, bet outcomes, bonus claims, and cashier history. This transactional record is retained for regulatory compliance, dispute resolution, and responsible gaming monitoring purposes.
When you access 666duit, we automatically collect: IP address; browser type and version; device type and operating system; session timestamps; pages visited; and geolocation data (derived from IP address). This data is used for security monitoring, fraud prevention, and platform performance optimisation.
If you contact 666duit support via email or live chat, we retain a record of your communications — including the content of messages, timestamps, and support agent responses. This record is retained for quality assurance and dispute resolution purposes.
666duit collects personal data through the following channels:
666duit processes your personal data for the following purposes:
666duit processes personal data on the following legal bases:
666duit does not sell your personal data to third parties. We share personal data only in the following circumstances:
7.1 666duit operates under an international gaming licence, and some of our service providers and data processors are located outside Malaysia. Where personal data is transferred internationally, 666duit ensures that such transfers are subject to appropriate safeguards — including standard contractual clauses, data processing agreements with contractual protections, or transfers to jurisdictions with an adequate level of data protection as recognised under applicable frameworks.
7.2 By registering a 666duit account, you acknowledge that your personal data may be processed in jurisdictions outside Malaysia in connection with the services described in this Policy.
8.1 666duit retains personal data for as long as necessary to fulfil the purposes set out in this Policy, unless a longer retention period is required by applicable law or licensing conditions. The primary retention periods applicable to 666duit Member data are as follows:
8.2 Upon expiry of the applicable retention period, personal data is securely deleted or anonymised in accordance with 666duit's data disposal procedures.
9.1 The 666duit website uses cookies and similar tracking technologies to deliver and improve the platform experience. The categories of cookies deployed on 666duit are as follows:
9.2 You can manage cookie preferences through your browser settings. Note that disabling functional or analytics cookies may affect your 666duit experience. Strictly necessary cookies cannot be disabled through browser settings without breaking core platform functionality.
10.1 666duit implements technical and organisational security measures appropriate to the sensitivity of the personal data we process. These measures include:
10.2 No data transmission over the internet can be guaranteed to be 100% secure. While 666duit takes all reasonable precautions, Members acknowledge that they share responsibility for account security — particularly in relation to credential management and the use of two-factor authentication where available.
Subject to applicable law and the conditions of our international gaming licence, 666duit Members hold the following rights in relation to their personal data:
To exercise any of the above rights, please submit a written request to [email protected]. 666duit will respond within 30 days of receipt of a valid request. We may require verification of your identity before processing a data subject request.
The 666duit platform is strictly intended for adults aged 21 and above. 666duit does not knowingly collect personal data from individuals under the age of 21. Where 666duit becomes aware that personal data has been collected from a person under 21 — whether through a registration misrepresentation or otherwise — the relevant account will be closed immediately, all personal data associated with that account will be deleted to the extent permitted by applicable law and AML obligations, and any balance held in the account will be returned to the source of funding following verification.
If you believe that a person under the age of 21 has registered a 666duit account, please notify us immediately at [email protected].
The 666duit platform may contain links to or integrations with third-party services — for example, game providers' demonstration environments or payment processor interfaces. This Privacy Policy applies solely to data processed by 666duit in its capacity as data controller. 666duit is not responsible for the privacy practices of third-party services accessed via links from the 666duit platform. Members are advised to review the privacy policies of any third-party services they engage with independently of 666duit.
14.1 666duit reserves the right to amend this Privacy Policy at any time to reflect changes in applicable law, licensing requirements, business practices, or platform functionality. Material amendments will be notified to Members via their registered email address and/or via an in-platform notification, with not less than 7 days' advance notice before the amended Policy takes effect.
14.2 The current version of the Privacy Policy, identified by its effective date, is always accessible at 666duit.org/privacy-policy. Continued use of the 666duit platform following the effective date of any amendment constitutes acceptance of the updated Privacy Policy.
For all privacy-related queries, data subject requests, or complaints regarding 666duit's handling of your personal data, please contact us in writing:
Every connection between your browser and the 666duit platform — including login, cashier, and game sessions — is protected by TLS 1.3 encryption. This prevents any third party from intercepting your credentials or financial data as it travels between your device and our servers. The padlock in your browser address bar confirms this protection is active.
666duit does not sell, rent, or broker Member personal data to third-party data buyers, advertisers, or data brokers — ever. Data sharing is limited to the specific service providers listed in Section 6, all of whom are bound by contractual data protection obligations. Your information stays within the 666duit ecosystem and its licensed service partners.
Section 11 of this Policy sets out your full suite of data rights: access, rectification, erasure, restriction, portability, objection, and withdrawal of consent. Submitting a data subject request to 666duit is straightforward — email [email protected] with your account details and your specific request. We respond within 30 days.
Data protection practices at 666duit are not self-regulated. Our international gaming authority licence imposes mandatory data handling standards — including KYC record retention, AML reporting obligations, and player data security requirements — that are subject to external audit and regulatory review. Compliance is not optional; it is a licence condition.
666duit collects only the personal data necessary to deliver the service, fulfil regulatory obligations, and maintain platform security. We do not collect excessive or irrelevant personal data. Where data is collected for a specific purpose and that purpose is fulfilled, the data is retained only for the minimum period required under applicable law and then securely deleted.
In the event of a personal data breach affecting Member data, 666duit has documented incident response procedures requiring detection, containment, assessment, and notification within timeframes mandated by our licensing conditions. Where a breach poses a high risk to Members, we will notify affected individuals directly — including Members from Kuala Lumpur, Penang, and all other states — without undue delay.
Questions about how your personal data is handled? Our support team is available around the clock. Or head straight to your 666duit account to manage your privacy and communication preferences.
21+ Gambling involves risk. Please play responsibly.