What this policy covers
This policy applies to donbet-australia.com and to nothing else. Every page on this domain, every guide, every table, every contact email sent to our editorial address: all of it sits inside. Leave the domain and the policy stops applying, instantly and completely.
That boundary matters more here than on an ordinary website, because the subject we write about is a gambling brand. Follow a link from one of our pages to DonBet and you land on a platform operated by Santeda International B.V., licensed in Curaçao under 1668/JAZ. From that moment you are dealing with a separate company under its own privacy policy, its own data practices and its own regulatory framework. What happens there is invisible to us. We cannot see what you register with, what you deposit, what you play or which documents you upload. Nor could we retrieve any of it if you asked, and deleting it is equally beyond us.
The same goes for any other external site we link to, whether a support service, a regulator or a sporting body. Each one runs its own show. Outbound links get chosen on editorial merit rather than on how the destination arranges its data handling, so read their policies if that matters to you.
One more clarification, because readers do ask. This policy is about you as a reader of a website. It offers no advice on protecting your privacy at a casino, and it describes none of the operator's obligations. Those are genuinely different topics, and blurring them leads people to send us requests we have no power to act on.
Information we collect
Collection has been kept deliberately minimal. No account system on this site, no login, no newsletter form quietly harvesting addresses, no profile being assembled in the background. What we do hold falls into four narrow categories.
The categories in detail
Technical server logs. Like every web server on the internet, ours records requests: your IP address, the time of the request, the page requested, the HTTP status returned, your browser's user-agent string, plus the referring URL where the browser sends one. This is automatic and unavoidable. It is how a web server works, and how anybody diagnoses a broken page or an attack.
Aggregate analytics. We measure which pages get read, roughly where readers are (country and often state level, derived from IP rather than precise location), which class of device they use and how they arrived. It comes back to us in aggregate. The question being asked is whether the payments guide outperforms the bonus guide, never what any individual did.
Correspondence. Email our editorial address and we hold your email address, your message and our reply. Nothing beyond that, and only because a conversation is impossible otherwise.
Cookie preferences. Your choice on the consent banner is stored so we do not badger you on every page. Storing it is the whole point of the mechanism; the details sit on the cookie settings page.
| Category | Examples | Why we have it | Retention |
|---|---|---|---|
| Server access logs | IP address, timestamp, URL requested, status code, user-agent, referrer | Security, abuse detection, diagnosing errors, keeping the site up | Up to 30 days, then overwritten |
| Aggregate analytics | Page views, session counts, country and state, device type, traffic source | Understanding which guides are useful and where they fail readers | Aggregated indefinitely; visitor-level records up to 14 months |
| Contact correspondence | Your email address, the message you sent, our reply | Answering you, and keeping a record of corrections we agreed to make | 24 months from the last message in the thread |
| Cookie consent record | Which categories you accepted or refused, and when | Honouring your choice and demonstrating it was made | 12 months, then we ask again |
| Security and rate-limit data | Blocked request counts, bot signatures, challenge results | Keeping scrapers and attack traffic off the site | Up to 30 days |
You will notice no row for names, none for dates of birth, and nothing covering what a gambling account would need. That absence was designed in rather than overlooked.
Information we do NOT collect
The negatives are worth stating explicitly, because readers arriving from a gambling context reasonably assume the worst. Here is the list of things that simply are not held anywhere on our side.
- No payment data. No card numbers, no bank details, no PayID identifiers, no crypto wallet addresses. There is no cashier on this domain and no way to send us money even if you wanted to.
- No identity or KYC documents. No passports, driver licences, utility bills or selfies. Where a page describes what verification involves, it is describing the operator's process, which we take no part in. Never email us a copy of an ID.
- No gambling history. Whether you hold an account anywhere, what you have staked, what you have won or lost, which games you favour: all unknown to us, with no mechanism by which we could find out.
- No account credentials. No usernames, no passwords, no security answers. We will never ask for any of them, so a message claiming to be us and asking is a scam.
- No sensitive information. Nothing about your health, race, religion, political views, sexuality, union membership or criminal record, in the specific sense the Privacy Act gives that term.
- No selling, renting or trading. Data is not sold to anyone. Mailing lists are not rented, and reader information is never swapped with other publishers or with gambling operators.
If you are ever unsure whether a request for information genuinely came from us, apply this test: the only thing we ever need is an email address, and only because you emailed us first.
How we use your information
Every use falls into one of three buckets. There is no fourth held quietly in reserve, and no clause further down this page that widens the first three once you have stopped reading.
Running and securing the site. Logs tell us when a page is throwing errors, when an image refuses to load in some particular browser, and when somebody is hammering the server with automated requests. Without them a broken page could sit broken for weeks, because hardly anyone reports these things.
Making the content better. Analytics is how we learn that readers land on the withdrawal timings section and bounce straight back out, which usually means the table has gone confusing on a phone. It also decides which guides get expanded and which get rewritten. Editorial feedback, arriving as numbers.
Replying to you. Send a correction, a copyright query, an accessibility problem or a complaint, and your email address gets used to answer it, then to follow up if the fix takes a while.
What never happens: advertising profiles, retargeting campaigns that follow you around the web, attempts to identify individual readers out of analytics, or reader information passed to gambling operators. There is no automated decision-making producing any effect on you either. No decision exists to be made. You read a page, and that is the entire interaction.
Analytics and third-party services
Running a website means other companies get involved, and honesty means naming the categories rather than pretending the stack is smaller than it is. They are described generically on purpose. Providers get swapped, and a policy that names a specific product goes stale the moment we change one.
Who is in the chain
Hosting and content delivery. The site is served through a content delivery network so that pages load quickly across Australia. A CDN necessarily sees the technical metadata of every request, meaning IP address, requested URL and browser type, because it has to route and cache the response. It also filters malicious traffic before it reaches the origin server, which is a large part of why we use one.
Web analytics. A measurement service processes page-view data and hands it back to us as reports. It sees the same technical metadata, plus which pages were viewed in what order. We configure it for aggregate reporting and never use it to single out individuals.
Email. Messages to our editorial address pass through a mail provider, which does what any mail host does with mail: stores it and delivers it.
Each of these providers processes data on our behalf, under contract, for the purpose we specify. None of them is free to repurpose it. Where a provider sits outside Australia, the cross-border section below applies. There are no third-party advertising networks running on this site, which removes an entire category of tracking that most gambling-adjacent websites carry around.
Your rights under the Privacy Act 1988
The Privacy Act 1988 (Cth) and the thirteen Australian Privacy Principles set the baseline for how personal information is handled in this country. Parts of what follows are rights in the strict statutory sense; other parts are simply how we choose to operate. Either way, ask and you will get it.
| Right | What it means in practice here | How to use it |
|---|---|---|
| Access (APP 12) | Ask what we hold about you. Realistically that is an email thread, if you have written to us | Email the editorial address from the address in question |
| Correction (APP 13) | Have inaccurate information about you fixed | Tell us what is wrong and what it should say |
| Deletion | Have your correspondence removed from our mailbox | Ask, and we delete unless a legal obligation prevents it |
| Anonymity (APP 2) | Read the entire site without identifying yourself. No account, no wall | Nothing required — this is the default |
| Withdraw cookie consent | Reverse an earlier acceptance of non-essential cookies | Reopen the banner or clear cookies in your browser |
| Complain | Escalate if you think we have mishandled your information | To us first, then to the OAIC |
None of this costs anything and no form is required. Write in plain English, tell us what you want, and we act on it, normally within a few business days and, for an access request, inside 30 days at the outside. We may ask you to confirm you control the email address involved. Handing someone else's correspondence to a stranger who asked nicely would be a far worse privacy outcome than a mild delay.
Visitors from the European Union
If you are reading from the EU or the UK, the GDPR framework gives you a comparable set of rights: access, rectification, erasure, restriction of processing, objection and data portability. Our lawful bases are straightforward. Legitimate interests cover security logging and aggregate measurement; consent covers any non-essential cookies, which you give or refuse on the banner and can withdraw whenever you like. In practice the outcome matches what an Australian reader gets. Email us, tell us what you want, and we do it. You also keep the right to lodge a complaint with your national supervisory authority.
Data security
Security is a set of habits rather than a product, and ours are deliberately dull. Nothing exotic, nothing that needs a diagram, just the basics applied consistently.
Every page on this domain is served over HTTPS with a valid certificate, so the connection between your browser and our server is encrypted in transit. No unencrypted version of the site exists to fall back to. Administrative access goes to the small number of people who genuinely need it, protected by strong unique credentials and multi-factor authentication, and reviewed whenever somebody stops working on the project. Server software gets patched on a routine schedule. Running a static site keeps the attack surface small: there is no reader database to breach, because we never built one.
None of that is a guarantee, and any publisher claiming otherwise is overselling. No system connected to the internet is perfectly secure. What we can offer is proportion. The less collected, the less there is to lose, and collection here sits at the floor for exactly that reason.
If something goes wrong
Australia's Notifiable Data Breaches scheme, which sits inside the Privacy Act, requires notification where a breach is likely to result in serious harm. Our process runs in that order: contain the incident, assess what was actually exposed, notify affected individuals and the OAIC where the threshold is met, then fix the underlying cause and publish what we learned. We would not sit waiting for a legal threshold before telling you your email had been exposed. We would just tell you.
Found a vulnerability on this site? Report it to the editorial address before disclosing it publicly. We will acknowledge it, investigate, and credit you if credit is something you want.
Children's privacy
This site is for adults aged 18 and over. Australian law sets the minimum gambling age at 18, and every page here is written on that assumption, this one included.
We do not knowingly collect information from anyone under 18. There is no age-gate, because a gate a child clicks straight through is theatre. There is also no registration, no profiles and no marketing pipeline, so nothing here was built to capture a young reader in the first place. If you believe a minor has sent us personal information, email us. We delete it without argument and without asking for anything beyond what we need to find the message.
Parents and guardians sharing a device with a minor should use content filtering at the operating system or network level. That genuinely works, where a checkbox does not. Our terms of use set out the same age restriction as a condition of using the site at all.
Data retention and deletion
We keep things for as long as they are useful, then stop. The retention column in the collection table above is the operative answer; the reasoning behind it is worth spelling out.
Server logs rotate on a short cycle because their whole value is short-term. You use them to diagnose something that broke recently, or to trace an attack happening right now. A log from four months back is dead weight and a liability at the same time. Analytics data is retained at visitor level for a limited window, and kept indefinitely only in aggregate form, where individual readers cannot be picked out. Correspondence lives longer, since a correction you asked for one year may need referencing the next, but two years after the last message in a thread it goes.
To request deletion, email the editorial address from the address you originally wrote in with, say you want the correspondence deleted, and it is done. We confirm once it has been. Two caveats, better stated here than discovered later. Deleting a thread also deletes our record of any correction you asked for, so make sure the fix has landed first. And where the law requires us to retain something, we retain it and tell you why. For a publisher of this size, that second situation is rare to the point of being theoretical.
Cross-border data transfers
Some of the infrastructure behind this site sits outside Australia. That is less a design choice than a description of how the modern web works: a content delivery network is by definition a global network of servers, and it is the reason a page loads quickly in Perth and in Brisbane at the same time.
In practice, technical request data may be processed on servers located overseas, in the United States, Europe or the wider Asia-Pacific region, depending on which edge node serves you. Analytics processing and email hosting may likewise happen outside Australia.
APP 8 requires us to take reasonable steps so that overseas recipients handle personal information consistently with the Australian Privacy Principles. We do that by using established providers with contractual data-protection commitments, by limiting what they receive to what the service actually requires, and by sending them nothing beyond that. The categories involved are IP addresses, page requests and browser strings rather than identity documents or financial records, so the exposure here is genuinely low. You are still entitled to know it exists rather than find out later.
Changes to this policy
This policy will change, because sites change. Swap an infrastructure provider, adjust a retention period or add a feature that touches data, and this page gets updated with the date in the byline moving along with it.
Minor edits get handled quietly, with the new date acting as the notice: clearer wording, a corrected typo, a renamed provider category. Anything material works differently. If we start collecting a category of information we do not collect today, or use existing data for a genuinely new purpose, we will say so prominently on the site and, where consent is the basis, ask again instead of assuming your old answer stretches to cover it.
We do not backdate. The version you are reading applies from the date shown, and continued use of the site after a change indicates acceptance of the updated policy. If a change does not suit you, the remedy is immediate and costs nothing: stop reading and clear our cookies.
Contact and complaints
Privacy queries go to [email protected]. That address handles access requests, corrections, deletions, questions about anything on this page, and complaints. There is no separate privacy officer inbox. The editorial team deals with it directly, which means fewer hops and a faster answer.
For a useful reply quickly, say what you want in the first sentence, include the email address any correspondence was sent from, and add the page URL where your query concerns a specific page. Want to contact the team about something editorial rather than privacy-related? The same address works.
How a complaint runs
Write to us first and label it a complaint, so it does not get filed as general correspondence. We acknowledge within five business days, investigate, and give you a written answer with reasons, normally inside 30 days and sooner where the facts are simple. If we got it wrong, we say so, fix it, and tell you what changed so the same thing does not happen twice.
If our answer does not satisfy you, or we fail to respond in a reasonable time, escalate to the Office of the Australian Information Commissioner. The OAIC is the independent regulator for privacy in Australia; it accepts complaints from individuals and can investigate. It will normally expect you to have raised the matter with us first, which is the only reason we ask for that step.
One thing that inbox cannot resolve, however the message is worded: anything involving a gambling account. Account access, withdrawals, deposits, bonus disputes, verification documents, closure or self-exclusion at an operator. None of it is ours to touch, and none of that data ever reaches us. Those requests belong with the operator's 24/7 live chat and email support, and sending them here only costs you days.
FAQ
Do you know who I am when I read this site?
No. There is no account, no login and no registration, so you read the site anonymously by default. Our server sees an IP address and a browser string, the way every web server does, and our analytics sees a page view. Neither tells us your name, and no attempt is made to work it out. The only way we learn anything identifying is if you email us, and then we know exactly what you chose to put in the message and nothing else.
Can you delete my DonBet account or the data the casino holds on me?
No, and please do not lose time trying. We are a publisher with no connection to the operator's systems. Your account is invisible to us, your documents are inaccessible, and nothing held by Santeda International B.V. can be deleted from here. Send that request to the operator directly through its live chat or support email, quoting its own privacy policy as you do. If the operator refuses, escalate to the licensing authority named in its site footer. That route is the only one with any leverage.
Do you share reader information with gambling operators?
Never. Reader data does not go to operators, it is not sold to data brokers, and mailing lists are not rented out. Nor do we swap information with other publishers. The only companies touching data at all are the infrastructure providers described above (hosting, content delivery, analytics and email), each processing it on our instructions for a defined purpose. No commercial data flow leaves this site.
How do I make a privacy complaint if I am not happy with your answer?
Start by writing to the editorial address with the word complaint in it, which routes the message properly. We acknowledge within five business days and give you a reasoned written response, usually inside 30 days. If that does not resolve matters, take them to the Office of the Australian Information Commissioner, the independent privacy regulator. The OAIC generally expects you to have approached us first, so keep a copy of what you sent and what we replied.
Is my data safer here than on a gambling site?
It is a different risk entirely, and the honest comparison is about volume rather than skill. A casino has to hold your identity documents, your payment credentials and your full transaction history in order to operate legally. We hold an IP address in a log that rotates inside a month, plus an email thread if you started one. Less data means less to lose in the worst case. Our exposure is smaller by design, which is a rather different claim from saying our security is superior.