ynappa.win

Legal

Privacy policy

This policy explains what personal data Ynappa collects, why we are legally required to collect much of it, how Zyphe carries out identity (KYC) and business (KYB) verification on our behalf, and the rights you hold over your data.

Last updated 2 September 2026

1.Who is responsible for your data

The operating entity behind Ynappa ("Ynappa", "we") is the data controller. The registered company details, address and gaming licence number are not yet published — they will appear here before real-money play opens. This site is currently a preview and does not accept real-money wagers.

Our Data Protection Officer can be reached at dpo@ynappa.win or by post at the address above. If you are unhappy with how we handle a request you may complain to the Maltese Information and Data Protection Commissioner (IDPC) or to the supervisory authority where you live.

2.What we collect

  • Account data — email address, hashed password, wallet currency, username, communication preferences.
  • Identity data — legal name, date of birth, residential address, nationality, phone number, government identity document, and the selfie or short video used for the liveness check.
  • Financial data — deposits, withdrawals, payment instrument identifiers (we never store full card numbers), source-of-funds evidence where requested.
  • Gameplay data — every stake, result, bonus, session length and studio you played, together with the responsible-gaming markers derived from them.
  • Technical data — IP address, approximate location, device and browser fingerprint, cookie identifiers, and the timestamps of every login.
  • Communications — support chats, emails and call recordings, retained for dispute resolution and regulatory audit.

3.Zyphe KYC — verifying you as a player

Our gaming licence and Maltese anti-money-laundering law oblige us to establish who you are before we release funds. We use Zyphe as our identity verification provider to perform Know Your Customer (KYC) checks. When you register or when a check is triggered, the following happens:

  • You are directed to Zyphe's secure capture flow to photograph a government-issued identity document (passport, national ID or driving licence).
  • Zyphe performs a document authenticity check — security features, machine-readable zone, tampering and template matching.
  • Zyphe performs a liveness and face-match check, comparing a live selfie against the photograph on the document. This produces biometric data, which is a special category of personal data.
  • Zyphe screens your details against sanctions lists, politically exposed person (PEP) registers and adverse media, and re-screens them periodically while your account is open.
  • Zyphe confirms you are 18 or over and that you are not present on our self-exclusion or the national exclusion registers.
  • Zyphe returns a pass, refer or fail decision plus a risk score. We receive that outcome and the extracted data fields; we do not receive your raw biometric template.

Zyphe acts as our processor for this verification and is bound by a data processing agreement under Article 28 GDPR. Zyphe is a separate controller for the limited records it must retain to meet its own regulatory and audit obligations. Zyphe's own privacy notice governs that processing.

Biometric data and your consent

The face-match and liveness check processes biometric data. We rely on your explicit consent (Article 9(2)(a) GDPR) and, in the alternative, on substantial public interest in preventing fraud and money laundering (Article 9(2)(g)). You may refuse the biometric check, in which case we will offer a manual verification route reviewed by a human compliance officer — it takes longer, and your account remains restricted to deposits under €150 until it completes. Withdrawing consent does not affect processing carried out before the withdrawal.

4.Zyphe KYB — verifying our business counterparties

Ynappa aggregates games from third-party studios and works with affiliates, payment institutions and resellers. Before we onboard any of them we run a Know Your Business (KYB) check, also through Zyphe. If you are a director, shareholder, ultimate beneficial owner (UBO) or authorised signatory of one of those companies, your personal data is processed as part of that check.

  • Company verification — registration number, legal form, registered address and good standing, confirmed against official company registries.
  • Ownership mapping — the corporate structure is unwound to identify every ultimate beneficial owner holding 25% or more.
  • Individual checks on officers and UBOs — identity verification, sanctions, PEP and adverse-media screening on named directors and beneficial owners.
  • Licence and permission checks — whether a counterparty holds the gaming or payment licences it claims, and whether those remain in force.
  • Ongoing monitoring — periodic re-screening and alerts on changes to ownership, sanctions status or licence status for as long as the relationship lasts.

The legal basis for KYB processing is our legal obligation under the Prevention of Money Laundering and Funding of Terrorism Regulations and our legitimate interest in not contracting with sanctioned, fraudulent or unlicensed businesses. Where you are named as an officer or UBO, we obtained your data from the company you are associated with and from public registries.

5.Why we process your data, and on what legal basis

  • To run your account and settle bets — performance of our contract with you (Article 6(1)(b)).
  • KYC, KYB, AML, sanctions screening, age verification, tax and regulatory reporting — compliance with legal obligations (Article 6(1)(c)) and, for biometrics, Article 9(2)(a) or (g).
  • Responsible gaming monitoring — detecting patterns that indicate harm, applying limits and exclusions. Legal obligation and legitimate interest in player protection.
  • Fraud, bonus abuse and collusion detection — legitimate interests (Article 6(1)(f)).
  • Marketing — your consent (Article 6(1)(a)), withdrawable at any time from your account settings or the unsubscribe link in any message.
  • Service improvement and analytics — legitimate interests, using aggregated or pseudonymised data wherever it is sufficient.

6.Who we share it with

  • Zyphe — identity (KYC) and business (KYB) verification, as described above.
  • Game studios and aggregation partners — when you open a game, the studio receives a pseudonymous session token, your stake and your jurisdiction. It does not receive your name, address or payment details.
  • Payment institutions and acquirers — to process deposits and withdrawals.
  • Regulators and authorities — our gaming regulator, the relevant financial intelligence unit, tax authorities, police and courts, where we are legally compelled. We do not notify you of a suspicious transaction report; the law forbids it.
  • Service providers — hosting, email delivery, customer support tooling, all under Article 28 processing agreements.

We do not sell your personal data, and we never have.

7.International transfers

Our infrastructure sits within the European Economic Area. Where a provider — including parts of Zyphe's screening network — processes data outside the EEA, we rely on an adequacy decision or on the European Commission's Standard Contractual Clauses with a transfer impact assessment. Ask our DPO for a copy of the safeguards applied to any specific transfer.

8.How long we keep it

  • Account, identity, KYC and KYB records, and transaction history — five years after the relationship ends, as required by AML law. This overrides most erasure requests.
  • Gameplay records — five years, for regulatory audit and dispute resolution.
  • Biometric images and liveness captures — deleted by Zyphe once the check completes and the audit trail is written, and no later than 30 days.
  • Self-exclusion records — retained for the exclusion period plus six years, so that an exclusion cannot be circumvented by re-registering.
  • Marketing preferences — until you withdraw consent, plus a suppression record kept indefinitely so we do not contact you again.

9.Automated decisions

Some decisions are made automatically: the KYC pass/refer/fail outcome, transaction monitoring alerts, bonus-abuse scoring and responsible-gaming risk markers that can trigger a limit or a cooling-off period. These can restrict your account. You have the right to obtain human review, to express your point of view and to contest the outcome — write to dpo@ynappa.win. We cannot disclose the exact thresholds of our AML monitoring, because doing so would defeat it.

10.Your rights

Under the GDPR you may request access to your data, correction of inaccurate data, erasure, restriction of processing, portability of the data you gave us, and you may object to processing based on legitimate interests. You may withdraw consent to marketing or to biometric processing at any time.

These rights are not absolute. Where AML law requires us to keep a record, we will keep it and tell you why. We respond within one month and may extend by two further months for complex requests. Verification of your identity is required before we release any data.

11.Cookies and tracking

We set strictly necessary cookies for session management, security and fraud prevention; these do not require consent. Analytics and advertising cookies are set only if you accept them in the cookie banner, and you can change that choice at any time from the footer.

12.Security

Data is encrypted in transit with TLS 1.3 and at rest with AES-256. Passwords are stored as salted Argon2id hashes. Access to identity documents is restricted to named compliance staff and every access is logged. We will notify you and the IDPC of a personal data breach where the law requires it.

13.Changes to this policy

We will post any change here and, where the change is material, email you at least 14 days before it takes effect. Continuing to use your account after that date means you accept the updated policy.

Related: terms and conditions · responsible gaming · fairness and RNG.