Information Security Statement
Information security is a core part of Gembet Privacy Policy because personal data and account information are processed to support licensed gaming services and secure account management. The policy describes the measures used to protect user information while maintaining compliance with operational, security, and verification requirements.
Gembet applies multiple security controls to safeguard personal information and account activity. Deposits and withdrawals are processed through secure payment gateways, while eligible withdrawals require OTP verification to reduce the risk of unauthorised transactions. The platform also monitors unusual login activity and sends notifications when important account events occur, including access from new devices or account session changes. Users can review their login history and remotely sign out from individual devices or all active sessions. Personal documents submitted during identity verification are stored securely and handled confidentially. These security measures apply across supported services, including Gembet Malaysia, to help protect personal data and maintain the integrity of customer accounts. 
How Gembet use users Personal Data
Gembet personal data is processed only for purposes related to account administration, platform operation, security, and legal compliance. The information collected is limited to what is required to provide services, protect user accounts, process transactions, and fulfil verification obligations.
Personal data may be used to:
- Create and maintain a user account.
- Verify identity during the KYC process before withdrawals.
- Process deposits and withdrawals through supported payment methods.
- Confirm account ownership when password recovery or account restoration is requested.
- Detect suspicious login attempts, unauthorised access, or other security risks.
- Send notifications about important account events, including logins from new devices and security-related changes.
- Maintain records required for fraud prevention, risk assessment, and regulatory compliance.
- Respond to customer support requests and investigate reported account issues.
- Monitor platform performance and resolve technical errors affecting account access or transaction processing.
- Keep internal records needed for audit, operational, and security purposes.
Access to personal information is restricted to authorised personnel who require the data to perform their operational responsibilities. Identity documents submitted during verification are handled confidentially and stored using appropriate security measures. Gembet does not process more personal information than is necessary for the purposes described in this policy, and data handling procedures are applied in accordance with the platform’s security and operational requirements.
Ways to Protect Personal Data
Protecting Gembet personal data is an essential part of account management and information security. Technical safeguards, access controls, and verification procedures are applied to reduce the risk of unauthorised access, data misuse, and fraudulent activity throughout the lifecycle of an account.
Personal information is protected through a combination of organisational and technical measures:
- Secure payment gateways are used to process deposits and withdrawals.
- OTP verification is required for eligible withdrawal requests to confirm account ownership.
- Login activity is monitored to identify unusual access attempts or suspicious behaviour.
- Security notifications are sent when important account events occur, such as sign-ins from new devices or remote session changes.
- Login history allows users to review devices, IP addresses, and recent account access.
- Remote logout functions make it possible to end active sessions from individual devices or all connected devices.
- Identity documents submitted during KYC verification are stored securely and handled confidentially.
- Access to personal information is limited to authorised personnel whose responsibilities require it.
- Security procedures are reviewed as part of ongoing operational and risk management processes.
Users also contribute to protecting Gembet accounts by maintaining a strong password, keeping login credentials confidential, enabling available security features, and reporting suspected unauthorized access without delay. These combined measures support the confidentiality, integrity, and controlled processing of personal information across the platform.
Liability Measures for Breach of Privacy Policy
Compliance with the rules described in Gembet Privacy Policy helps maintain account security, protect stored information, and support regulatory obligations. When privacy-related requirements are not followed, Gembet reviews each situation individually before deciding on the appropriate action.
A breach may involve providing false identity details, attempting to access another user’s account, sharing login credentials, submitting forged verification documents, bypassing security controls, or using personal information without proper authorisation. Gembet assesses the available evidence, account history, technical records, and verification data before applying any restriction.
Depending on the nature and severity of the violation, the following measures may apply:
- Request additional identity or ownership verification before account access is restored.
- Restrict selected account functions while a security review is in progress.
- Suspend deposits, withdrawals, or account activity until verification is completed.
- Reject documents that have been altered, falsified, or do not meet verification requirements.
- Block unauthorized access attempts originating from suspicious devices, IP addresses, or locations.
- Permanently close accounts involved in identity fraud, account takeover attempts, or repeated privacy violations.
- Retain security logs and related records when required for legal, regulatory, or fraud investigation purposes.
- Report unlawful activity to the relevant authorities where disclosure is required by applicable law or licensing obligations.
These measures are intended to protect users, preserve data integrity, and maintain secure platform operations. The principles described in the Gembet Privacy Policy apply consistently to all accounts. Within Gembet Malaysia, privacy-related decisions are based on documented evidence, verification results, internal security procedures, and applicable regulatory requirements rather than automated actions alone.
Conclusion
Our Privacy Policy explains how we collect, process, store, and protect personal data throughout the account lifecycle. Gembet apply technical safeguards, verification procedures, controlled data access, and continuous security monitoring to support secure platform operations and comply with applicable licensing requirements. Gembet also define clear responsibilities for users and the measures that may apply if privacy rules are violated. By following these principles, a transparent framework for handling personal information while helping users understand how their data is managed, protected, and used when accessing our services.
FAQ
What information do you collect?
Gembet collects registration details, contact information, transaction records, technical device data, login history, and verification documents when required for identity confirmation.
Why do you process personal data?
Personal data is processed to create and manage accounts, complete payments, verify identity, improve security, prevent fraud, and comply with legal and licensing requirements.
How is my information protected?
Gembet uses encrypted connections, controlled access, authentication procedures, activity monitoring, and security reviews to protect stored personal information from unauthorized access.
Is identity verification required?
Verification may be requested before withdrawals or when additional security checks are necessary. Documents are reviewed to confirm account ownership and regulatory compliance.
Can my account be restricted for privacy violations?
Yes. Accounts may be temporarily restricted or permanently closed if false information, forged documents, unauthorised access attempts, or other privacy policy violations are identified.
Do you share personal data with third parties?
Information may be shared only when necessary with authorised service providers, payment partners, verification providers, or competent authorities in accordance with legal obligations.

