PRIVACY AND COOKIES POLICY

casongo.ng

Version 1.0 | Effective and last updated: 21 August 2026

1. GENERAL INFORMATION

This Privacy and Cookies Policy (“Policy”) applies when you visit casongo.ng, open or use an account, place bets or play games, make deposits or withdrawals, contact us, respond to promotions, or otherwise use our websites, mobile interfaces and related services (together, the “Services”). It should be read with our General Terms and Conditions and Responsible Gambling rules.

The Services are operated by One World Unity Projects Limited, a company incorporated in Nigeria, with registered address at PLOT-C, BLOCK-IX, ALHAJI ADEJUMO AVENU, ILUPEJU INDUSTRIAL ESTATE OSHODI, EXPRESSWAY ANTHONY, LAGOS, MUSHIN, LAGOS STATE (“Casongo”, “we”, “us” or “our”).

For the processing described in this Policy, we act principally as data controller. A service provider may act as our processor or, where it determines its own purposes and means, as a separate controller.

Some personal data is necessary to register or administer an account, verify age and identity, process payments, comply with gambling, anti-money laundering and other legal duties, or protect the Services. If you do not provide required data, we may be unable to open or maintain your account, process a transaction or provide some Services. Optional processing will be identified when the data is requested.

2. PERSONAL DATA WE COLLECT

We collect only personal data that is reasonably adequate, relevant and limited to the stated purposes.

Depending on your interaction with us, this may include:

  • Identity and age-verification data: full name, date of birth, nationality, signature, photograph, tax or national identification number, identity-document details and copies, and verification results.
  • Contact and account data: residential address, email address, telephone number, username, account identifiers, communication preferences and account status.
  • Financial and transaction data: payment method and account details, deposits, withdrawals, chargebacks, wallet balances, betting stakes, winnings, losses and transaction history. We generally receive only the payment data needed for processing and reconciliation.
  • Gambling and usage data: bets and games played, preferences, bonuses, session and gameplay history, limits, self-exclusion status, responsible-gambling interactions and account notes.
  • Verification, compliance and risk data: know-your-customer and source-of-funds information, sanctions and politically exposed person screening, fraud indicators, device and account-linkage signals, investigations and relevant communications with regulators or law-enforcement bodies.
  • Technical data: IP address, device and advertising identifiers, browser and operating-system information, device model and settings, language, time zone, approximate location derived from IP, log-in records, URLs, clickstream, page interactions, error and security logs, and cookie or similar-technology data.
  • Communications data: emails, live-chat records, complaints, survey responses and customer-support calls where calls are recorded after appropriate notice.
  • Marketing data: campaign interactions, consent records, opt-outs, referral information and inferred interests, subject to the choices described below.

We do not treat a device identifier, cookie identifier or similar data as anonymous where it can be linked to your account or otherwise identify or single you out.

3. SENSITIVE PERSONAL DATA

Under the NDP Act, sensitive personal data includes genetic and biometric data used to uniquely identify a person, health data, and information revealing racial or ethnic origin, religious or similar beliefs, sex life, sexual orientation, political opinions or trade-union membership, as well as any further category prescribed by the NDPC.

We may process limited sensitive personal data where necessary and permitted by law, for example biometric verification results used for identity assurance or health-related information voluntarily disclosed in connection with self-exclusion, gambling-harm support or a complaint. We will identify both a lawful basis under section 25 of the NDP Act and an additional condition under section 30 before processing sensitive personal data. Depending on the facts, this may be explicit consent, the establishment or defence of legal claims, vital interests, or substantial public interest grounded in Nigerian law. We do not assume that all gambling-addiction information must be retained by law.

Access to sensitive personal data is restricted, security controls are proportionate to its higher risk, and it is not retained indefinitely. The retention rules in section 10 apply.

4. HOW WE OBTAIN PERSONAL DATA

We obtain data directly from you and automatically through the Services. We may also obtain data from payment providers, identity-verification and fraud-prevention providers, banks and financial institutions, public registers, sanctions and politically exposed person databases, affiliates, advertising or analytics partners (where permitted), regulators, law-enforcement bodies, and other persons who lawfully provide it.

Where data is obtained from another source, we provide the information required by law within the applicable period unless a lawful exception applies.

5. PURPOSES AND LAWFUL BASES

We document the purpose and lawful basis for each processing activity. Consent is not bundled into acceptance of general terms and is not used where the processing is in fact necessary for a contract or legal obligation.

Account and Services

Examples: Register and administer accounts; authenticate users; place and settle bets; manage bonuses; provide support.

Primary lawful basis: Contract; steps requested before contract.

Payments

Examples: Process deposits, withdrawals, refunds and reconciliations; maintain financial records.

Primary lawful basis: Contract; legal obligation.

Age, identity and compliance

Examples: Verify age and identity; conduct KYC, AML/CFT, sanctions and source-of-funds checks; respond to lawful authorities.

Primary lawful basis: Legal obligation; public interest where grounded in law.

Safety and integrity

Examples: Detect fraud, collusion, bonus abuse, cyberattacks and account compromise; enforce rules and establish legal claims.

Primary lawful basis: Legitimate interests; legal obligation; legal claims for sensitive data.

Responsible gambling

Examples: Operate limits and self-exclusion; identify risk indicators; provide interventions and meet applicable regulatory duties.

Primary lawful basis: Legal obligation where applicable; legitimate interests; explicit consent or another section 30 condition for health data.

Analytics and improvement

Examples: Measure performance, troubleshoot, develop features and understand use of the Services.

Primary lawful basis: Legitimate interests for proportionate first-party analysis; consent for non-essential cookies/tracking.

Marketing

Examples: Send opted-in promotions and measure campaigns; maintain suppression lists.

Primary lawful basis: Consent; legitimate interests only where lawfully available and documented.

5.1 Legitimate interests

Where we rely on legitimate interests, we identify the interest, assess necessity and balance it against your rights, reasonable expectations and the possible impact on you. Examples include securing the Services, preventing fraud, improving first-party operations and defending legal claims. You may object as described in section 11. We will stop unless we demonstrate overriding legitimate grounds or need the data for legal claims.

5.2 Consent

Where we rely on consent, it must be freely given, specific, informed and unambiguous, and evidenced by a clear affirmative action. We keep a record of consent and make withdrawal as easy as giving it.

Withdrawal does not affect processing already carried out lawfully. Refusing optional consent does not prevent access to core Services, but some optional features may not work.

6. CHILDREN AND PERSONS UNDER 18

The Services are not directed to, and may not be used by, anyone under 18. We use proportionate age-and identity-assurance measures and may request documents or third-party verification. A user must not submit a child’s personal data to create or operate an account.

If we learn that a person under 18 has attempted to use the Services or that we collected a child’s data, we will suspend the account, prevent gambling activity and review the data promptly. We will erase or anonymise data that is not needed, while retaining only what is necessary to protect the child, return funds, prevent repeat registration, investigate misconduct, comply with law or establish legal claims. Where appropriate and lawful, we may communicate with a parent or guardian or a competent authority. If processing a child’s data is based on consent, we will obtain and verify the consent of the parent or legal guardian as required by section 31 of the NDP Act, unless a statutory exception applies.

7. AUTOMATED DECISION-MAKING AND PROFILING

We may use rules, models and risk indicators to profile account activity for fraud prevention, AML/CFT monitoring, security, responsible-gambling interventions, marketing segmentation, bonus eligibility and operational risk. These tools may flag activity, recommend limits, pause a transaction or refer an account for investigation.

We will not make a decision based solely on automated processing that produces legal or similarly significant effects on you unless the decision is necessary for a contract, authorised by Nigerian law with suitable safeguards, or based on your consent, as permitted by the NDP Act. Where the statutory right applies, you may request human intervention, express your point of view and contest the decision.

Significant account restrictions, closure or withholding of funds will be subject to meaningful human review unless law prevents disclosure or requires immediate action. Contact the DPO using section 17.

8. SHARING PERSONAL DATA

We do not sell personal data. We may disclose only the data reasonably necessary to:

  • affiliates supporting shared technology, compliance, security, customer support or corporate administration;
  • identity, age-verification, AML/CFT, fraud-prevention and responsible-gambling service providers;
  • banks, payment processors, payment schemes and financial institutions;
  • cloud hosting, cybersecurity, communications, analytics and customer-support providers;
  • professional advisers, auditors, insurers and prospective parties to a corporate transaction, subject to confidentiality and lawful due diligence;
  • gambling, tax, data-protection and other regulators, courts, law-enforcement agencies or public authorities where required or authorised by law; and
  • advertising and marketing providers only in accordance with your consent and applicable law.

Processors are bound by written agreements that define subject matter, duration, purpose, data types, security, confidentiality, assistance, deletion or return, audit rights and restrictions on sub-processors.

Separate controllers are responsible for their own compliance. We remain accountable for selecting and overseeing processors and do not disclaim responsibility merely because a third party is involved.

External links are governed by the third party’s own privacy notice. We encourage you to read it before providing data.

9. INTERNATIONAL DATA TRANSFERS

Some recipients or hosting locations may be outside Nigeria. Before a transfer, we document the destination, recipient, data, purpose, risks and transfer mechanism. We transfer personal data only where the recipient country, territory, sector or organisation is subject to an adequate level of protection recognised under the NDP Act, or where appropriate safeguards are in place under an NDPC-recognised or approved cross-border data transfer instrument. Safeguards may include approved contractual clauses, binding corporate rules, an applicable code or certification mechanism, together with supplementary technical and organisational measures where needed.

If neither adequacy nor appropriate safeguards is available, we rely only on a specific exception permitted by section 43 of the NDP Act, such as explicit informed consent after explaining the risks, necessity for a contract with you or in your interest, important public interest established by law, legal claims, or vital interests where consent cannot be given. An exception is not used for routine transfers merely because a vendor is overseas. You may request information about the applicable safeguard from the DPO, subject to lawful confidentiality limits.

10. RETENTION AND DELETION

We retain personal data only for as long as reasonably necessary for the stated purpose, a documented legal obligation, regulatory direction, dispute or legal claim. We consider the nature and sensitivity of the data, risk of harm, volume, purpose and available alternatives. At the end of the period, we securely delete or irreversibly anonymise the data. Backup copies are isolated from ordinary use and deleted through the backup cycle.

The following are general operational periods and may be shortened or extended where a documented law, regulator’s direction, legal hold, active complaint or claim requires it:

  • Account, identity, KYC/AML and core transaction records: while the account is active and ordinarily for at least five years after the relationship or relevant transaction ends, or longer where a specific gambling, AML/CFT, tax or other law requires.
  • Unsuccessful pre-contract identity or due-diligence data: normally deleted within six months where the account or contract does not proceed, unless needed for fraud prevention or a reasonably anticipated legal claim.
  • Responsible-gambling and self-exclusion records: for the duration of the account or exclusion and generally for five years afterwards where necessary to enforce exclusion, protect the individual, meet regulatory requirements or establish claims. Health-related information is reviewed more frequently and is not kept indefinitely merely because it concerns addiction.
  • Customer-support records and call recordings: normally up to three years after resolution, unless connected to a transaction, complaint, investigation or claim requiring longer retention.
  • Security, authentication and technical logs: normally 12–24 months, with longer retention for substantiated incidents or investigations.
  • Marketing-consent records: while marketing continues and afterwards for as long as needed to prove consent. Opt-out or suppression data is kept in minimal form to ensure we honour the request.
  • Cookies and similar identifiers: for the lifespan disclosed in the live cookie preference centre, subject to periodic review and renewed consent where required.

These periods must be reflected in and controlled by our internal retention schedule. Where another section of this Policy conflicts with a mandatory statutory period, the mandatory period applies.

11. YOUR DATA PROTECTION RIGHTS

Subject to the NDP Act and any lawful limitation, you may:

  • receive clear information about our processing and request access to your personal data and a copy;
  • request correction of inaccurate data and completion of incomplete data;
  • request erasure where the data is no longer needed, consent is withdrawn and no other lawful basis applies, you successfully object, or processing was unlawful;
  • request restriction while accuracy, an objection or the lawfulness of processing is being assessed, or where you need data preserved for a claim;
  • withdraw consent at any time;
  • object to processing based on legitimate interests or public interest, and object at any time to direct marketing, including related profiling;
  • receive qualifying data you provided to us in a structured, commonly used and machine-readable format and transmit it to another controller where technically feasible;
  • exercise rights relating to qualifying solely automated decisions, including human intervention and contesting the decision; and
  • lodge a complaint with the Nigeria Data Protection Commission or seek another remedy available under law.

To exercise a right, email [email protected] or write to the address in section 17. No particular form is required. We may request proportionate information to verify identity and authority, especially where a request is made by an agent. We will not ask for more data than necessary for verification.

We will respond without undue delay and ordinarily within 30 days after receiving a valid request and any reasonably necessary verification information, in line with the NDP Act and GAID. If a lawful extension or limitation applies, we will explain the reason and expected timing. Requests are ordinarily free of charge.

We will not charge a deletion fee. We may decline or limit a manifestly unfounded or excessive request only where permitted by law, and will explain the decision and complaint options.

Rights are not absolute. For example, we may retain data required by law, needed for freedom of expression, public-interest functions, legal claims, fraud prevention or protection of another person’s rights. We will apply any exception narrowly and record our reasoning.

12. DIRECT MARKETING AND COMMUNICATION PREFERENCES

We send promotional email, SMS, push or similar electronic marketing only where we have recorded valid consent or another lawful basis is demonstrably available under Nigerian law. Consent to marketing is separate from account acceptance, is not pre-ticked and can be granular by channel. We do not direct gambling marketing to persons known to be under 18, self-excluded or otherwise prohibited from receiving it.

You can opt out at any time through the unsubscribe link, account preference centre, customer service, live chat or [email protected]. We will action the request promptly and keep only a minimal suppression record. Opting out of marketing does not stop essential service, security, responsible-gambling, legal or transaction communications.

13. COOKIES AND SIMILAR TECHNOLOGIES

Cookies, pixels, local storage, software development kits and similar technologies may store or access information on your device. A conspicuous banner or comparable preference tool appears before non-essential tracking is activated and identifies Casongo as the organisation responsible for its use. The banner and preference centre explain purposes and provide equally accessible accept and reject choices for non-essential categories. You do not need to scroll to discover the notice.

13.1 Categories

  • Strictly necessary: authentication, security, network management, load balancing, account and payment-session functions, accessibility and recording privacy choices. These cannot generally be disabled through our tool because the requested Services would not operate.
  • Functional: remember language, region, display and other optional preferences.
  • Analytics/performance: measure visits, navigation, errors and feature performance and help us improve the Services.
  • Advertising/targeting: measure campaigns, limit repetition, build permitted audiences and personalise advertising on our or third-party services.

Non-essential functional, analytics and advertising technologies are used only after the required specific affirmative choice. Rejecting them does not prevent use of core Services. Cookie-derived information may be personal data when linked to your account, device or other identifiers; statements that such information is always anonymous are not accurate.

13.2 Your choices and cookie lifespan

You may change or withdraw choices at any time through the “Cookie Settings” link or preference centre available on the Website. Withdrawal is as easy as consent and stops future non-essential tracking, although existing cookies may need to be removed through the tool or browser settings. Browser blocking may affect essential functions.

Session cookies expire when the browsing session ends; persistent cookies remain until their disclosed expiry or deletion. The live preference centre should list each cookie or provider, purpose, category, first/third-party status and duration, and must be kept aligned with technologies actually deployed.

14. SECURITY

We maintain risk-appropriate technical and organisational measures designed to protect personal data against accidental or unlawful destruction, loss, alteration, unauthorised disclosure or access. Measures include access controls and least privilege, authentication, encryption or pseudonymisation where appropriate, logging and monitoring, secure development and change management, backups, vendor due diligence, staff confidentiality and training, vulnerability and incident management, and periodic testing.

We conduct a data privacy impact assessment before high-risk processing, including material new profiling, biometric, responsible-gambling or large-scale monitoring activities.

No service can be guaranteed completely secure. You are responsible for keeping account credentials confidential, using secure devices and notifying us promptly of suspected compromise. This does not reduce our statutory duties or liability for processing under our control.

15. PERSONAL DATA BREACHES

We maintain and test an incident-response process. Processors must notify us promptly of a personal data breach and provide information needed for assessment. We document all breaches, their effects, risk assessment and remedial action.

Where a breach is likely to result in a risk to individuals’ rights and freedoms, we will notify the NDPC within 72 hours after becoming aware, where feasible, and provide required information in phases if necessary.

Where a breach is likely to result in a high risk, we will also communicate it to affected individuals immediately or without undue delay in clear language, including the nature of the breach, likely consequences, mitigation steps and DPO contact, unless a statutory exception applies. Delay or non-notification will be documented and justified.

16. GOVERNANCE, DPO AND POLICY CHANGES

We have designated a Data Protection Officer (“DPO”) with appropriate independence, access to senior management and responsibility for advising on compliance, monitoring, training, impact assessments, data-subject requests and cooperation with the NDPC. The DPO is not penalised for performing these duties and is supported with appropriate resources.

We may update this Policy to reflect changes in law, regulation, technology or our processing. The effective date will be updated and material changes will be brought to your attention through a prominent notice or direct communication where appropriate. If a new purpose is incompatible with the original purpose, we will provide a new notice and obtain consent or identify another valid basis before processing.

This Policy is written in English. If a translation conflicts with the English version, the English version prevails, except to the extent applicable law requires otherwise. No French-language version has precedence.

17. CONTACTS AND COMPLAINTS

Data Protection Officer
One World Unity Projects Limited
PLOT-C, BLOCK-IX, ALHAJI ADEJUMO AVENUE
ILUPEJU INDUSTRIAL ESTATE OSHODI
EXPRESSWAY ANTHONY, LAGOS, MUSHIN,
LAGOS STATE

Email: [email protected] (subject line: “ATTN: DPO”)

Please contact us first where possible so we can investigate and respond. This does not remove your right to complain directly to the Nigeria Data Protection Commission (NDPC).

At the date of this Policy, the NDPC publishes contact details and its breach/complaint services at https://ndpc.gov.ng/, including [email protected] and No. 12 Dr Clement Isong Street, Abuja, Nigeria. You may also seek judicial or other remedies available under the NDP Act.

18. OPERATIONAL ACCURACY OF THIS NOTICE

This Policy must reflect Casongo’s actual systems and practices. Before publication and after material product or vendor changes, Casongo should verify the identity of payment, KYC, analytics, advertising, cloud and affiliate recipients; countries of access or hosting; actual cookie inventory and durations; applicable gambling and AML retention rules; lawful bases; responsible-gambling workflows; and whether any decision is solely automated.

Where operational facts differ, the live notice and controls must be corrected before the relevant processing begins.