Your Privacy Matters to bm8. bm8 does not sell your personal data to third parties for their own marketing purposes. All data processing activities described in this Policy are conducted for legitimate operational, regulatory, or security purposes directly connected to the provision of bm8's services to Malaysian players.
1 Introduction & Scope
This Privacy Policy ("Policy") applies to all personal data collected and processed by bm8 ("bm8", "we", "us") in connection with your use of the bm8 platform accessible at bm8.biz and any associated interfaces. "Personal data" means any information that identifies or can reasonably be used to identify a living individual.
This Policy applies to all registered bm8 players, prospective players who browse bm8.biz without registering, and any individual who contacts bm8 support. By registering an account with bm8 or continuing to use the platform, you acknowledge that you have read and understood this Policy and consent to the processing activities described herein.
bm8 serves players primarily located in Malaysia — across Kuala Lumpur, Selangor, Penang, Johor Bahru, and other states. Where any applicable data protection law of Malaysia or the jurisdiction from which bm8 operates imposes requirements on bm8 as a data controller or processor, bm8 will comply with those requirements to the extent they apply to its operations.
2 Personal Data We Collect
bm8 collects personal data through multiple channels, including account registration, KYC verification, gameplay activity, financial transactions, and customer support interactions. The categories of personal data collected are described below.
| Data Category |
Specific Data Points |
Collection Point |
| Identity Data |
Full legal name, date of birth, nationality, MyKad or passport number |
Registration & KYC verification |
| Contact Data |
Email address, mobile phone number, residential address |
Registration & KYC verification |
| Financial Data |
Bank account details, e-wallet identifiers (Touch 'n Go, DuitNow, Boost, GrabPay), deposit and withdrawal history, wallet balance |
Payment processing |
| Gaming Activity Data |
Bet history, game session logs, win/loss records, Mix Parlay selections, live casino participation records |
Platform usage |
| Technical Data |
IP address, device type, browser type and version, operating system, session duration, pages visited |
Automatic collection via cookies and server logs |
| Communication Data |
Live chat transcripts, email correspondence, support ticket history |
Customer support interactions |
| Responsible Gaming Data |
Self-exclusion status, deposit limit settings, session time alerts, cooling-off period records |
Responsible gaming tool usage |
bm8 collects only the data necessary for the purposes described in this Policy. Where you choose not to provide certain information, bm8 may be unable to provide certain services — for example, withdrawals cannot be processed without verified financial account details.
3 How bm8 Uses Your Personal Data
bm8 processes personal data for the following purposes:
- Account Management — To create, maintain, and administer your bm8 player account, including authentication, password recovery, and account security.
- Service Delivery — To process deposits, execute bets and game sessions, settle winnings, and process withdrawal requests in MYR via your chosen payment method.
- Identity Verification (KYC) — To verify your identity and age (21+) in compliance with applicable gaming authority requirements and anti-money laundering obligations.
- Fraud Prevention & Security — To detect, investigate, and prevent fraudulent transactions, unauthorised account access, collusion, bonus abuse, and other prohibited conduct described in bm8's Terms & Conditions.
- Regulatory Compliance — To maintain records required by applicable international gaming authority guidelines, including bet histories and transaction logs, for audit and compliance purposes.
- Responsible Gaming — To monitor gameplay patterns that may indicate problem gambling behaviour and to administer self-exclusion, deposit limit, and cooling-off period tools.
- Customer Support — To respond to your enquiries, resolve disputes, and maintain records of support interactions for quality assurance and compliance purposes.
- Platform Improvement — To analyse aggregated, anonymised usage data to improve the bm8 platform, game catalogue, and user experience for Malaysian players.
- Marketing Communications — Where you have provided explicit consent, to send you promotional offers, bonus notifications, and platform updates. You may withdraw consent at any time by contacting bm8 support.
bm8 does not use automated decision-making processes that produce legally significant effects on players without human review, except where required by applicable regulatory obligations.
4 Legal Basis for Processing
bm8 processes personal data on the following legal bases:
- Contractual Necessity — Processing required to perform the contract between bm8 and the player (account management, payment processing, game provision).
- Legal Obligation — Processing required to comply with applicable gaming authority obligations, anti-money laundering requirements, and KYC mandates.
- Legitimate Interests — Processing conducted for bm8's legitimate operational interests, including fraud prevention, platform security, and responsible gaming monitoring, where these interests are not overridden by player rights.
- Consent — Processing of data for marketing communications and non-essential analytics, where explicit consent has been obtained and can be withdrawn at any time.
5 Data Sharing & Third Parties
bm8 does not sell, rent, or trade your personal data to third parties for their own independent marketing purposes. bm8 may share your personal data with the following categories of third parties, strictly for the purposes described in this Policy:
- Payment Processors — Banks and e-wallet operators (including Maybank, CIMB, Touch 'n Go eWallet, DuitNow, FPX, Boost, and GrabPay) to process your deposit and withdrawal transactions.
- Game Software Providers — Licensed game studios (such as PG Soft, Pragmatic Play, JILI, and Evolution Gaming) receive the minimum data required to authenticate your session and deliver game services.
- KYC & Identity Verification Services — Third-party identity verification providers who assist bm8 in authenticating player identity documents during the KYC process.
- Fraud Detection & Security Providers — Specialist providers whose tools assist bm8 in identifying and preventing fraudulent access, collusion, and financial crime.
- Regulatory Authorities — Applicable gaming authority bodies, law enforcement agencies, and courts, where disclosure is required by law, court order, or regulatory directive.
- Professional Advisers — Legal, audit, and compliance advisers engaged by bm8 who are bound by confidentiality obligations.
All third parties to whom bm8 discloses personal data are contractually required to handle such data in compliance with applicable data protection standards and to use it solely for the purposes for which it was shared.
6 Cookies & Tracking Technologies
bm8 uses cookies and similar tracking technologies on bm8.biz to support platform functionality, maintain secure sessions, analyse usage patterns, and — where consent is given — deliver relevant promotional content. The following cookie categories are used:
- Strictly Necessary Cookies — Essential to the operation of the bm8 platform. These cookies enable login session management, security token validation, and core platform functions. They cannot be disabled without impairing platform usability.
- Performance & Analytics Cookies — Collect anonymised data about how players navigate and use bm8.biz, including pages visited, session duration, and error events. This data helps bm8 improve platform performance and user experience.
- Functional Cookies — Remember your preferences (such as language settings and display preferences) to personalise your bm8 experience across sessions.
- Marketing Cookies — Where consent has been provided, these cookies support the delivery of relevant promotional content. They are not used to build profiles for resale to third-party advertisers.
You may manage cookie preferences through your browser settings. Blocking all cookies will impair the functionality of the bm8 platform, including the ability to maintain a logged-in session.
7 Data Retention
bm8 retains personal data only for as long as necessary to fulfil the purposes for which it was collected or as required by applicable regulatory and legal obligations. The following general retention periods apply:
- Account and identity data is retained for the duration of your active bm8 account and for a minimum of five (5) years following account closure, in compliance with applicable gaming authority record-keeping requirements.
- Transaction and betting records are retained for a minimum of five (5) years from the date of the relevant transaction or wager.
- KYC verification documents are retained for a minimum of five (5) years from the date of submission, consistent with applicable anti-money laundering obligations.
- Customer support communications are retained for three (3) years from the date of the last interaction.
- Technical and analytics data is retained in anonymised or aggregated form and does not identify individual users after the applicable retention period.
Dormant Accounts. Where a bm8 account has been inactive for an extended period, bm8 may apply its account dormancy policy as described in the Terms & Conditions. Personal data associated with dormant accounts is retained for the minimum regulatory period regardless of account status.
8 Data Security
bm8 implements technical and organisational security measures designed to protect your personal data against unauthorised access, disclosure, alteration, or destruction. These measures include:
- 256-bit SSL/TLS encryption for all data transmitted between your browser and bm8's servers;
- Encrypted storage of sensitive data, including KYC documents and financial account identifiers;
- Role-based access controls limiting internal access to personal data to bm8 personnel with a legitimate need;
- Multi-factor authentication requirements for privileged system access;
- Regular security assessments and vulnerability testing of bm8's platform infrastructure;
- Incident response procedures for detecting, reporting, and remediating data security events.
While bm8 takes these measures seriously, no system connected to the internet can be guaranteed as completely secure. You are also responsible for maintaining the confidentiality of your bm8 login credentials. bm8 will never ask for your password via email, live chat, or telephone. If you suspect your account has been compromised, contact bm8 support immediately at [email protected].
9 Your Data Rights
Subject to applicable law and bm8's regulatory obligations, you have the following rights in respect of your personal data held by bm8:
- Right of Access — You may request a copy of the personal data bm8 holds about you. bm8 will respond to access requests within 30 calendar days.
- Right to Rectification — You may request correction of inaccurate or incomplete personal data. Please note that changes to identity data may require re-submission of KYC documentation.
- Right to Erasure — You may request deletion of personal data that is no longer necessary for the purposes for which it was collected, subject to bm8's regulatory retention obligations. Where regulatory obligations require retention, bm8 will explain the basis for continued retention.
- Right to Restriction — You may request that bm8 restrict processing of your personal data in certain circumstances, such as where accuracy is contested or processing is unlawful.
- Right to Data Portability — Where processing is based on consent or contractual necessity, you may request that bm8 provide your personal data in a structured, machine-readable format.
- Right to Withdraw Consent — Where processing is based on your consent (e.g., marketing communications), you may withdraw that consent at any time without affecting the lawfulness of prior processing.
- Right to Object — You may object to processing conducted on the basis of legitimate interests, including profiling for responsible gaming monitoring purposes. bm8 will assess your objection and respond with its determination within 30 calendar days.
To exercise any of these rights, please submit a written request to [email protected] with sufficient information to identify your account. bm8 may request additional verification before processing sensitive data requests to protect against fraudulent access.
10 Children's Privacy
21+ Only. The bm8 platform is strictly prohibited to persons under 21 years of age. bm8 does not knowingly collect personal data from any individual under 21. If bm8 becomes aware that an account has been registered by a person under 21, the account will be immediately closed, all associated personal data will be deleted (subject to any mandatory regulatory retention obligations), and any funds within the account will be handled in accordance with bm8's underage account procedures. If you believe a minor has accessed the bm8 platform, please contact
[email protected] immediately.
11 Cross-Border Data Transfers
In order to provide its services, bm8 may transfer personal data to servers, processors, or third-party service providers located outside Malaysia. Where such transfers occur, bm8 ensures that appropriate safeguards are in place — including contractual data protection clauses consistent with applicable standards — to maintain the same level of protection afforded under this Policy.
Game providers and platform infrastructure partners operating under international gaming authority licensing frameworks are required, as a condition of their licensing, to maintain data protection standards consistent with internationally recognised data security requirements. bm8 monitors and periodically reviews the adequacy of these safeguards.
12 Changes to This Privacy Policy
bm8 reserves the right to update this Privacy Policy at any time. Material changes will be communicated to registered players via email or a prominent notice on the bm8 platform. The updated Policy will be effective from the date published at the top of this page. Your continued use of the bm8 platform following the effective date of an updated Policy constitutes your acceptance of the revised terms. If you do not accept the revised Policy, you should discontinue use of the platform and may close your account in accordance with bm8's account closure procedures.
13 Contact & Data Enquiries
For all privacy-related enquiries, data subject rights requests, or concerns regarding bm8's data handling practices, please contact bm8 using the details below:
bm8 Privacy & Data Enquiries
Email:
[email protected] (plain text — not a clickable link)
Response Target: Within 30 calendar days for formal data rights requests; within 48 hours for general privacy enquiries
Support Hours: 24 hours a day, 7 days a week
Live Chat: Available at bm8.biz when logged in to your account
bm8 takes privacy complaints seriously. If you are dissatisfied with bm8's response to a privacy concern, you may escalate the matter through applicable data protection complaint channels or the dispute resolution procedures of the relevant gaming authority.