Privacy Policy
Privacy Policy
Last Updated: July 23, 2026
Introduction
HellWinz ("we," "us," "our," or the "Company"), accessible at hellwinz.co, is committed to protecting the privacy and personal information of our users, customers, and website visitors ("you" or "User"). This Privacy Policy explains how we collect, use, disclose, store, and protect your personal information when you access or use our website, platform, and related services (collectively, the "Services").
This Privacy Policy is designed to comply with the Privacy Act 1988 (Cth), including the Australian Privacy Principles (APPs) set out in Schedule 1 of that Act, as well as other applicable data protection laws, including the General Data Protection Regulation (GDPR) where relevant to users accessing our Services from the European Economic Area. By accessing or using our Services, you acknowledge that you have read, understood, and agree to the practices described in this Privacy Policy.
If you do not agree with the terms of this Privacy Policy, please do not access or use our Services.
Information We Collect
We collect several categories of personal information in order to provide, maintain, and improve our Services, and to comply with our legal and regulatory obligations.
2.1 Information You Provide Directly
- Identity Information: full name, date of birth, gender, government-issued identification documents (for age and identity verification purposes).
- Contact Information: email address, residential address, phone.
- Account Information: username, password, account preferences and security.
- Financial Information: payment card details, bank account details, cryptocurrency wallet addresses, transaction history, and billing address (processed through secure third-party payment processors).
- Verification Documents: proof of identity, proof of address, and source-of-funds documentation as required for Know Your Customer (KYC) and Anti-Money Laundering (AML).
- Communications: records of correspondence with our customer support team, including chat logs, emails, and phone call recordings where.
2.2 Information Collected Automatically
- Device Information: IP address, browser type, device identifiers, operating system, and device.
- Usage Data: pages visited, time spent on the Services, click patterns, referral URLs, and session.
- Location Data: approximate geographic location derived from your IP address, used primarily for jurisdictional compliance and fraud.
- Cookies and Tracking Technologies: information collected via cookies, pixels, web beacons, and similar technologies (see Section 8 below).
2.3 Information from Third Parties
We may receive personal information about you from identity verification providers, payment processors, fraud prevention services, marketing partners, and publicly available sources, including government sanctions and self-exclusion registers.
Purposes for Collecting and Using Your Information
We collect and use your personal information for the following purposes:
- To create, verify, and manage your.
- To provide, operate, and maintain our.
- To process transactions, deposits, and.
- To comply with age verification, identity verification, and responsible gambling.
- To detect, prevent, and investigate fraud, money laundering, and other unlawful.
- To communicate with you regarding your account, transactions, promotions, and service.
- To personalise your experience and provide tailored offers and.
- To conduct internal analytics, research, and service.
- To comply with applicable laws, regulatory requirements, and requests from law enforcement or regulatory.
- To enforce our Terms and Conditions and protect our legal.
Legal Basis for Processing
Where the GDPR applies to our processing of your personal information, we rely on the following legal bases:
| Legal Basis | Example Use Case |
|---|---|
| Performance of a contract | Managing your account and processing transactions |
| Legal obligation | Identity verification, AML/KYC checks, tax reporting |
| Legitimate interests | Fraud prevention, service improvement, direct marketing to existing customers |
| Consent | Marketing communications, non-essential cookies |
Under the Australian Privacy Principles, we collect personal information only by lawful and fair means, and only where reasonably necessary for our functions and activities.
Responsible Gambling and Sensitive Information
We may collect information relating to your gambling behaviour, self-exclusion requests, and deposit limits in order to support responsible gambling practices. This information may be shared with responsible gambling bodies and self-exclusion registers where required by law or where you have opted into such programs.
If you are concerned about your gambling habits, we encourage you to contact Gambling Help Online (available 24/7 across Australia) or the National Gambling Helpline on 1800 858 858. We take our responsible gambling obligations seriously and provide tools including deposit limits, self-exclusion, time-out periods, and reality checks within your account settings.
Disclosure of Your Information
We may disclose your personal information to:
- Payment Processors: including providers supporting POLi, PayID, credit/debit card processing, and cryptocurrency payment gateways used by Australian.
- Identity Verification Providers: third parties engaged to confirm your identity and age.
- Regulatory Authorities: including the Office of the Australian Information Commissioner (OAIC), AUSTRAC, and relevant state or territory gambling regulators, where.
- Law Enforcement Agencies: where disclosure is required or authorised by law.
- Service Providers: including cloud hosting providers, customer support platforms, marketing agencies, and analytics providers, bound by confidentiality.
- Corporate Transactions: in connection with a merger, acquisition, restructuring, or sale of.
We do not sell your personal information to third parties for their own independent marketing purposes without your consent.
Cross-Border Data Transfers
Your personal information may be stored, processed, or transferred outside Australia, including to jurisdictions that may not have data protection laws equivalent to the Privacy Act 1988. Where we disclose personal information overseas, we take reasonable steps to ensure that the overseas recipient handles your information in a manner consistent with the Australian Privacy Principles, in accordance with APP 8. Where applicable, we implement appropriate safeguards such as standard contractual clauses for transfers involving the European Economic Area.
Cookies and Tracking Technologies
We use cookies and similar tracking technologies to operate our Services, remember your preferences, analyse usage patterns, and deliver targeted advertising. Categories of cookies used include:
- Strictly Necessary Cookies: required for core functionality such as login and.
- Performance Cookies: used to analyse site usage and improve.
- Functional Cookies: remember your preferences and.
- Advertising Cookies: used to deliver relevant advertisements and measure campaign.
You can manage cookie preferences through your browser settings, though disabling certain cookies may affect the functionality of our Services.
Data Security
We implement reasonable technical and organisational measures to protect your personal information against unauthorised access, alteration, disclosure, or destruction. These measures include encryption of sensitive data, secure server infrastructure, access controls, and regular security assessments. However, no method of electronic transmission or storage is completely secure, and we cannot guarantee absolute security.
In the event of a data breach that is likely to result in serious harm, we will comply with our notification obligations under the Notifiable Data Breaches (NDB) scheme established under Part IIIC of the Privacy Act 1988, including notifying affected individuals and the OAIC where required.
Data Retention
We retain your personal information for as long as necessary to fulfil the purposes outlined in this Privacy Policy, including to satisfy legal, accounting, regulatory, and AML/KYC record-keeping obligations, which may require retention of certain records for a minimum of seven years following account closure. Where information is no longer required, we take reasonable steps to securely destroy or de-identify it.
Your Rights
Depending on your location and applicable law, you may have the following rights regarding your personal information:
- Access: the right to request a copy of the personal information we hold about you.
- Correction: the right to request correction of inaccurate or incomplete.
- Deletion: the right to request deletion of your personal information, subject to legal retention.
- Objection: the right to object to certain processing activities, including direct.
- Portability: the right to receive your personal information in a structured, commonly used format (where applicable under GDPR).
- Withdrawal of Consent: the right to withdraw consent at any time where processing is based on.
- Complaint: the right to lodge a complaint with the Office of the Australian Information Commissioner (OAIC) or another applicable supervisory.
To exercise any of these rights, please contact us using the details provided in Section 14 below.
Children's Privacy
Our Services are intended solely for individuals who are 18 years of age or older. We do not knowingly collect personal information from minors. If we become aware that we have inadvertently collected information from a person under 18, we will take reasonable steps to delete that information promptly.
Changes to This Privacy Policy
We may update this Privacy Policy from time to time to reflect changes in our practices, technology, legal requirements, or other factors. We will post the updated Privacy Policy on our website and update the "Last Updated" date accordingly. We encourage you to review this Privacy Policy periodically.
Contact Us
If you have any questions, concerns, or requests regarding this Privacy Policy or our handling of your personal information, please contact us at:
Email: [email protected].
If you are not satisfied with our response, you may lodge a complaint with the Office of the Australian Information Commissioner (OAIC), which can be contacted through their official channels, or with another relevant data protection authority in your jurisdiction.