Contents
1. Introduction
k138.club ("k138", "we", "us", "our") operates an online casino and sportsbook platform accessible at https://k138.club, providing gambling and gaming services primarily to players in Malaysia. We recognise that privacy is important to our players, and we are committed to protecting the personal data you share with us when you register, deposit, play, or otherwise interact with the k138 platform.
This Privacy Policy ("Policy") describes what personal data k138 collects, the purposes for which it is processed, how long it is retained, who we share it with, and the rights you hold in relation to your personal data. This Policy applies to all players, registered members, and visitors to k138.club.
By registering an account with k138 or using our Services, you acknowledge that you have read and understood this Privacy Policy and consent to the collection and processing of your personal data as described herein. This Policy should be read alongside our Terms & Conditions and Responsible Gaming Policy.
2. Data Controller
For the purposes of applicable data protection law, the data controller responsible for your personal data is k138.club. The data controller determines the purposes and means by which personal data is processed. Queries relating to this Policy or to how k138 handles your personal data should be directed to our Data Protection contact at [email protected] (plain text โ not a clickable link).
Where k138 engages third-party processors to handle personal data on its behalf (for example, payment processors, game software providers, or identity verification services), those processors are contractually bound to process data only on k138's instructions and to implement appropriate technical and organisational security measures.
3. Data We Collect
k138 collects personal data through several channels: directly from you during registration and account management; automatically through your use of the platform; and from third parties where required for identity verification or fraud prevention.
3.1 Data You Provide Directly
- Registration data: Full legal name, date of birth, gender, residential address, email address, and mobile phone number.
- Identity verification documents: Copy of government-issued identity card (MyKad), passport, or other acceptable national identification document; utility bill or bank statement as proof of address.
- Payment data: Details of the payment method used for deposits and withdrawals, including e-wallet account identifiers (e.g., Touch n Go eWallet registered number, Boost account), bank account details for FPX transactions, and cryptocurrency wallet addresses for USDT transactions. k138 does not store full card numbers โ card payments are tokenised by our payment processor.
- Support communications: Records of your interactions with k138's customer support team via live chat or email, including the content of your queries and our responses.
- Responsible gaming data: Deposit limits, loss limits, session time preferences, and self-exclusion requests that you set or submit through the platform.
3.2 Data Collected Automatically
- Device and browser data: IP address, device type, operating system, browser type and version, screen resolution, and device language settings.
- Usage and behavioural data: Pages visited, games played, bet amounts, session duration, navigation patterns, and feature interactions within the k138 platform.
- Transaction history: Complete records of deposits, withdrawals, bets placed, game results, bonus redemptions, and balance movements.
- Cookies and similar technologies: See Section 7 (Cookies & Tracking) for full details.
3.3 Data from Third Parties
k138 may receive personal data about you from third-party identity verification services, fraud prevention databases, and sanctions screening providers as part of our KYC (Know Your Customer) and anti-money laundering ("AML") compliance processes.
The following table summarises the primary categories of personal data k138 processes:
| Category | Examples | Source |
|---|---|---|
| Identity Data | Name, date of birth, MyKad / passport number | You / KYC provider |
| Contact Data | Email address, mobile number, residential address | You |
| Financial Data | E-wallet ID, bank account, transaction history | You / payment processor |
| Technical Data | IP address, device ID, browser type | Automated collection |
| Usage Data | Games played, bets placed, session duration | Automated collection |
| Compliance Data | KYC documents, AML screening results | You / third-party provider |
4. How We Use Your Data
k138 uses the personal data it collects for the following primary purposes:
- Account registration and management: To create and maintain your k138 player account, verify your identity, and manage your account settings and preferences.
- Service delivery: To enable you to access and use all k138 Services including live casino games, the sportsbook, slot games, and associated features.
- Payment processing: To process deposits and withdrawals via Touch n Go eWallet, Boost, GrabPay, FPX bank transfers, Visa, Mastercard, and USDT, and to maintain accurate transaction records.
- Regulatory compliance: To fulfil obligations under applicable KYC, AML, and responsible gaming regulations, including age verification and transaction monitoring.
- Fraud prevention and security: To detect, investigate, and prevent fraudulent activity, account compromise, money laundering, and other prohibited conduct on the k138 platform.
- Customer support: To respond to your queries, resolve complaints, and provide technical assistance via live chat and email.
- Responsible gaming: To monitor gambling behaviour patterns that may indicate problematic gambling and to administer responsible gaming tools including deposit limits, loss limits, and self-exclusion.
- Platform improvement: To analyse usage patterns and technical performance data to improve the k138 platform's functionality, reliability, and user experience.
- Marketing communications: To send you information about k138 promotions, bonuses, and new products where you have opted in to receive such communications. You may opt out at any time.
5. Legal Basis for Processing
k138 processes your personal data under the following legal bases:
- Contractual necessity: Processing required to perform our contract with you (the Terms & Conditions) including account management, game delivery, and payment processing.
- Legal obligation: Processing required to comply with applicable legal and regulatory requirements, including KYC, AML screening, age verification, and responsible gaming obligations.
- Legitimate interests: Processing for fraud prevention, platform security, and platform improvement where these interests are not overridden by your privacy rights.
- Consent: Processing for direct marketing communications where you have provided explicit opt-in consent. You may withdraw consent at any time without affecting the lawfulness of prior processing.
6. Data Sharing and Disclosure
k138 does not sell, rent, or trade your personal data to any third party for commercial purposes. k138 shares personal data with third parties only in the following limited circumstances:
- Payment processors: Financial data is shared with payment processors and e-wallet providers (Touch n Go eWallet, Boost, GrabPay, FPX bank partners) as necessary to process your transactions.
- Game software providers: Technical session data may be shared with certified game providers (such as Pragmatic Play, Playtech, and Microgaming) as necessary for game delivery, fair play auditing, and technical support.
- Identity verification and AML providers: Identity documents and related data are shared with accredited KYC and AML screening services as part of our compliance programme.
- Regulatory and law enforcement authorities: k138 may disclose personal data to competent regulatory, governmental, or law enforcement authorities where required by applicable law, court order, or regulatory instruction.
- Corporate transactions: In the event of a merger, acquisition, or sale of all or part of k138's business, personal data may be transferred to the acquiring entity subject to equivalent privacy protections.
All third-party data processors engaged by k138 are subject to contractual data processing agreements requiring them to process data only on k138's instructions and to maintain appropriate security standards.
7. Cookies & Tracking Technologies
k138 uses cookies and similar tracking technologies on the k138.club website and platform. Cookies are small text files stored on your device that help us provide and improve our Services.
Types of Cookies Used
- Essential cookies: Required for the platform to function, including maintaining your login session, remembering your account preferences, and enabling secure transactions. These cannot be disabled without impacting your ability to use k138.
- Analytical cookies: Used to collect aggregated and anonymised usage data to help k138 understand how players navigate and use the platform, enabling us to make informed improvements.
- Functional cookies: Used to remember your preferences such as language settings, display options, and responsible gaming limits, so you do not need to re-enter them on each visit.
- Security cookies: Used to detect and prevent fraudulent activity, including recognition of devices used in previous verified sessions.
You may manage cookie preferences through your browser settings. Note that disabling non-essential cookies may affect certain platform features. k138 does not use third-party advertising cookies or share cookie data with advertising networks.
8. Data Retention
k138 retains personal data for as long as is necessary to fulfil the purposes for which it was collected, or as required by applicable law and regulatory obligations. Specific retention periods include:
- Active account data: Retained throughout the duration of your active k138 account.
- KYC and identity documents: Retained for a minimum of five (5) years following account closure, in compliance with anti-money laundering record-keeping requirements.
- Transaction records: Financial transaction records are retained for a minimum of five (5) years for regulatory compliance purposes.
- Support communications: Retained for three (3) years following resolution, or longer where the communication relates to a dispute or regulatory matter.
- Marketing preferences: Retained until you withdraw consent or request deletion, subject to any overriding legal retention requirement.
Following the expiry of applicable retention periods, personal data is securely deleted or anonymised so that it can no longer be attributed to an identifiable individual.
9. Data Security
k138 implements industry-standard technical and organisational measures to protect your personal data against unauthorised access, disclosure, alteration, loss, and destruction. These measures include:
- SSL/TLS 256-bit encryption for all data transmitted between your browser or device and the k138 platform;
- Encryption at rest for sensitive personal data stored in k138's databases;
- Access controls and role-based permissions limiting staff access to personal data on a need-to-know basis;
- Regular security assessments, penetration testing, and vulnerability management;
- Two-factor authentication options for player accounts;
- Monitoring systems for the detection of unusual account activity and potential data breaches.
Despite k138's security measures, no internet transmission or data storage system is completely secure. Players are encouraged to use strong, unique passwords for their k138 accounts and to enable two-factor authentication. If you suspect unauthorised access to your account, contact k138 support immediately.
10. Your Rights
Subject to applicable data protection law, you have the following rights in relation to your personal data held by k138:
- Right of access: You may request a copy of the personal data k138 holds about you.
- Right to rectification: You may request correction of inaccurate or incomplete personal data. Some corrections can be made directly through your account settings.
- Right to erasure: In certain circumstances, you may request deletion of your personal data. Note that k138 may be required to retain certain data for regulatory compliance purposes even following a deletion request.
- Right to restrict processing: You may request that k138 restrict processing of your personal data in certain circumstances, for example while a rectification request is pending.
- Right to data portability: You may request a copy of personal data you have provided to k138 in a structured, machine-readable format.
- Right to object: You may object to processing based on k138's legitimate interests, including direct marketing. k138 will cease direct marketing upon receipt of an objection.
- Right to withdraw consent: Where processing is based on your consent, you may withdraw consent at any time without affecting the lawfulness of prior processing.
To exercise any of the above rights, please contact k138 at [email protected]. k138 will respond to data rights requests within 30 days. Where a request is complex or numerous, k138 may extend this period by up to 60 days with notice.
11. Children's Privacy
k138's Services are strictly for persons aged 21 years and above. k138 does not knowingly collect personal data from persons under the age of 21. If k138 becomes aware that personal data has been collected from a person under 21, that data will be deleted immediately and the associated account will be closed. If you believe a person under 21 has registered on k138, please notify us at [email protected].
12. International Data Transfers
k138's platform and some of its third-party service providers operate across multiple jurisdictions. As a result, your personal data may be transferred to and processed in countries outside Malaysia. Where such transfers occur, k138 ensures that appropriate safeguards are in place to protect your personal data, including contractual data processing agreements incorporating recognised data protection clauses. k138 only transfers personal data to jurisdictions or service providers that provide an adequate level of data protection.
13. Third-Party Links
The k138 platform does not contain links to third-party websites for commercial or advertising purposes. Where k138 works with third-party game providers, their game software may operate under separate privacy practices. k138 is not responsible for the privacy practices of third-party game studios whose software is integrated into the platform, and recommends that players review the relevant studio's privacy documentation where applicable.
14. Changes to This Policy
k138 reserves the right to update this Privacy Policy from time to time to reflect changes in applicable law, regulatory requirements, or k138's data processing practices. Material changes to this Policy will be communicated to registered players via email to the address on record and/or via a prominent platform notice at least seven (7) days before the revised Policy takes effect. The "Last Updated" date at the top of this page reflects the date of the most recent revision. Your continued use of the k138 platform following the effective date of an updated Policy constitutes your acceptance of the revised terms.
15. Contact Us
For any questions, concerns, or requests relating to this Privacy Policy or to k138's handling of your personal data, please contact k138's Data Protection point of contact via the following channels:
- Live Chat: Available 24/7 directly within the k138 platform for immediate support.
- Email: [email protected] โ for formal data rights requests, please include "Privacy Request" in the subject line.
k138 is committed to resolving privacy concerns promptly and transparently. Where a complaint cannot be resolved directly, you retain the right to escalate to the relevant data protection authority in your jurisdiction.