We use cookies to provide you with a great user experience. By using Betway, you agree to our cookie policy
Casino Games
Recent Big Winners

Privacy Policy

  1. General

The Constitution of Malawi provides for the right to privacy under section 21. The section provides that every person shall have the right to personal privacy, which shall include the right not to be subject to searches of his or her person, home or property; the seizure of private possessions; or interference with private communications, including mail and all forms of telecommunications.
Due to the evolving nature of information and communication technology and the need to protect privacy of the individual, Malawi has enacted the Data Protection Act, 2024 (“DPA”) to provide for the use and protection of personal data and to regulate the collection, use, transmission, storage and processing of personal data.
In compliance with the DPA, Golden Bay Limited, (“the Company”) wishes to inform its users of the way it processes their Personal Data in this Privacy Policy.

Due to the evolving nature of information and communication technology and the need to protect privacy of the individual, Malawi has enacted the Data Protection Act, 2024 (“DPA”) to provide for the use and protection of personal data and to regulate the collection, use, transmission, storage and processing of personal data.

In compliance with the DPA, Golden Bay Limited, (“the Company”) wishes to inform its users of the way it processes their Personal Data in this Privacy Policy.

  1. Definitions
The definitions to key terms for the purpose of this policy can be found below.
“Data Controller” means an individual, private entity, public authority or agency or any other body who or which, alone or jointly with others, determines the purposes and means of the processing of personal data.
“Data Processor” - means an individual, private entity, public authority or agency or any other body who or which processes personal data on behalf of or at the direction of a data controller or another data processor.
“Data Subject” means an individual to whom personal data relates.
“Personal Data” - means any information relating to an individual who can be identified or is identifiable, directly or indirectly by reference to an identifier such as a name, an identification number, location data, an online identifier or one or more factors specific to the physical, physiological, genetic, psychological, cultural, social or economic identity of that individual.
“Processing” means any operation or set of operations which is performed on personal data, whether or not by automated means, such as collection, recording, organisation, structuring, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, dissemination or otherwise making available, alignment or combination, restriction, erasure or destruction.
“Services” - The goods and services, which includes the access to betting platforms or websites, promoted, offered, or provided by the Company and Betway.
  1. Data Controller
The Data Controller is Golden Bay Limited, with registered office at 6 Umodzi Street, New Naperi, Blantyre, Malawi, who is the license holder for online betting services through its own brands (hereinafter referred to as Betway).
  1. Information that we collect
We collect Personal Data either because (i) it is required to be able to promote, offer or supply our Services to you; or (ii) to improve our Services. A full list of why we process your information can be found below under “How we use your information”. You are under no obligation to provide Personal Data to us. However, much of the Personal Data we request is essential for the provision and quality of our Services (for example, enabling you to place your bets on our websites). We may not be able to provide you with our Services if you choose to withhold the requested information.
When you navigate to websites and mobile applications of brands which are managed by us, we collect browser and cookie information. In addition, we may also collect your IP address and technical information relating to the device you are accessing our websites from.

During the registration process and when you subsequently use your account, you are requested to submit specific Personal Data including, but not limited to:
  • your first and last name;
  • date of birth;
  • credit card or other payment data;
  • identity number;
  • home or another physical address;
  • e-mail address; and
  • phone/mobile number or other contact data.
In addition to the above, you will be asked to create a unique username and password combination for your account. This information is required to enable easy access to our Services.

Once you have created an account and have become a registered customer, additional information is processed on an on-going basis to ensure that our Services are offered to you in the best possible manner. You must use your unique username and password to access your account.

When you are logged into your account, we may collect:
  • a record of all internet communications and details of your visits to our websites;
  • technical information relating to the device, such as the device identifier, and browser you use to access our websites;
  • details of transactions you carry out through the site, such as payments, withdrawals and wagers;
  • communications with us or our employees which includes calls, emails, and messages sent through the live chat service;
  • information regarding your location, including IP address.
In certain instances, we may also request that you send us additional information to verify your identity. This may include: 
  • copies of photographic identification documents;
  • proof of address; and
  • source of funds for your account.
Your documents are always stored and treated in a secure manner.
In some limited instances, we may conduct open-source checks which involves the access of public records and publicly available information about you including news articles, social media accounts, forums posts and official records.
To ensure your safety and that of the Company, we use services provided by third parties to help us decide whether to accept transactions from you by assessing your method of payment and the devices you use to visit our websites. These third-party services check whether the device or method of payment has been utilised for fraudulent or abusive transactions in the past such as reported instances of identity theft, promotion abuse, or credit card fraud.

  1. How we use your information
We use the information we collect to protect you or other third parties, provide, maintain, protect and improve our Services, and develop new Services. We also use this information to offer you tailored content like giving you more relevant promotional offers, should you consent to receive our promotional marketing material.
We process your Personal Data for the purposes of:
  • creating and managing your account;
  • providing you with gambling services;
  • if necessary, contacting you via your registered contact information in connection with the management and operation of your account;
  • processing your online financial and wagering transactions;
  • researching your preferences to develop new features, functionality, products and services;
  • ensuring our websites function correctly and identifying any technical issues;
  • complying with all our legal and regulatory requirements, such as those relating to the identification of individuals under anti-money laundering legislation and ensuring responsible gambling;
  • preventing fraudulent activity or cheating;
  • determining what promotions and bonuses to offer you should you consent to receive marketing material; and
  • providing you, unless you have opted out, with information, by the contact methods you authorise us to use, about our Services, and selected third party services, products, competitions, prizes and offers.
We actively manage our financial liabilities and risk on events and markets. Liability and exposure controls can be applied across betting markets and/or individual accounts to manage those liabilities. The Company may assess your data (including Personal Data) to determine motivations for opening an account or placing a bet. Should your activity stand out from what we consider to be ordinary and expected behaviour, further analysis is performed. In line with our terms and conditions, we may exclude you from certain promotions or from placing certain bets as a result of this investigation. Examples of unusual betting behaviour can be, though is not limited to:
  • larger than expected bets appearing on a very specific outcome. For example, a correct set score in an ITF tennis match;
  • a bet being placed by a customer who may be privy to information regarding the potential outcome of an event;
  • a customer changing their established betting pattern;
  • an alert from a sport’s governing body or monitoring agency; and
  • a large number of bets placed in a short time period on one specific outcome.

Any analysis performed is a private business owned commodity and is not transmitted to any third party. We reserve the right to apply restrictions to customer accounts where the Company believes it to be appropriate due to their betting activity.
  1. Who we share your Personal Data with
Certain trusted third-party entities provide services essential to our ability to offer our Services to you. These third parties include but are not limited to:
  • those that supply the software and games for our websites;
  • banking and payment services;
  • identity verification companies;
  • fraud prevention and risk management companies.
We are required to share some of your information with these entities to offer our Services to you. In these instances, we take reasonable measures to ensure that the third party has appropriate security and privacy arrangements in place to ensure your data is protected.

In compliance with regulatory obligations, we may be required to disclose your information to government authorities, such as the police or regulators. Personal Data may also be shared with regulators, agencies, or relevant sports bodies in instances where we become suspicious that an account holder may be involved in match-fixing or the breach of sports regulations. We will also disclose information as required to enforce our terms of use as stated in our Terms and Conditions.

In the event of the sale of our business, or other business event, which results in us having to transfer your Personal Data to a third party, you will be notified via email or notice posted on our websites to explain the identity of the new Data Controller and your options regarding your Personal Data.

Our websites may contain links to and from the websites of third-party organisations. Please note that these websites may have their own privacy policies and that we do not accept any responsibility whatsoever for these policies. Please check these policies carefully before you submit any Personal Data.
  1. Marketing and Opting Out

    The Data Controller reserves the right to process Personal Data for marketing purposes. In certain limited circumstances, we also reserve the right to provide this information to our third-party partners for the purpose of marketing our services to you provided that you have already consented or give us your consent to do this.

    We request your consent to market to you when you first create an account with us, you can choose not to receive marketing/promotional material at any time. By opting out or denying such consent has no influence on the registration of a gaming account.

    If you have opted out of marketing from us, we will take all reasonable steps to ensure you no longer receive promotional material about our services. This may affect your eligibility for certain promotional bonuses.
    Even if you unsubscribe from our marketing mailing list, we may continue to send out periodic e-mails and/or SMSes informing you of technical, service or security issues related to a product or service you requested, confirming you requested a product or service, or providing periodic updates or information relating to the product or service you requested or any other form of communication we are obliged to send you in terms of legislation.

    Please note that should you opt out of receiving marketing/promotional material from us, there might be a delay in removing you from our marketing/promotional lists. We ask that you give us a period of 14 days from opting out to remove you from our mailing list. Should you continue to receive marketing/promotional material after 14 days from opting out, we ask that you notify us in order to investigate why you have not been removed from the mailing list.

  2. Your rights  

    We respect your privacy rights and therefore you may contact us at any time and request the following:

  • the Personal Data we hold about you;
  • to rectify your Personal Data if it becomes inaccurate or incomplete;
  • to have incomplete Personal Data completed. This may include providing a supplementary statement. Whether or not this is appropriate in any particular case depends on the purposes for which your information is being processed;
  • to erase your Personal Data if:
    • your Personal Data has been processed unlawfully by us; or
    • your Personal Data is no longer necessary for the purposes for which it was collected by us; or
    • You object to processing and there is no overriding legitimate interest for continuing to process your Personal Data.
  • to restrict our processing of your Personal Data if:
    • you contest the accuracy of the Personal Data held by us (for a period enabling us to verify the accuracy of the Personal Information);
    • our processing activities are unlawful; or
    • we no longer need your Personal Data but you would like us to retain it to ensure its continued availability to you in connection with any legal claims.
You undertake to update us if there are any changes or inaccuracies in your Personal Data.

Please note that objecting to our processing of your Personal Data will result in us being unable to continue to offer our Services to you which may lead to us closing your account. When requesting any of the above information from us, you have the right to ask that your Personal Data be provided to you in a generally understandable format.

Kindly note that the above rights are not absolute. There are instances where applicable law or regulatory requirements allow or require us to refuse your request. For example, we may refuse your request in instances where we need to process the Personal Data to exercise or defend legal claims. In addition, in certain instances, your Personal Data may have been destroyed, erased, or made anonymous in accordance with our record retention obligations and practices.

To exercise your rights, you are required to submit a request detailing what information you wish to enquire about, together with proof of identity to customer support at [email protected]. We may then request further details in order to process your request.

If you are not satisfied with how we have processed your Personal Data and want to raise a complaint, please contact us directly at [email protected].

If you are still not satisfied with our response or believe we are not collecting or processing your Personal Data in accordance with the applicable laws, you can lodge a complaint with the Office for Malawi Information Communications and Technology Authority established in Malawi whose contact details are available at www.zicta.zm/.


  1. Cookie Policy

    Cookies are text files containing a small amount of information that are downloaded to your device when you visit a website. Most websites utilise cookies to improve your online experience and to ensure that content and functions are delivered and used more effectively.

    Cookies perform various different functions. For example, some cookies are session cookies which are downloaded to your device temporarily for the period that you spend browsing a particular website. These cookies might allow you to navigate between pages more efficiently or enable websites to remember the preferences you selected. Other cookies are persistent cookies which can be used to help websites remember you as a returning visitor or to ensure the online adverts you receive are more relevant to your specific needs and interests.

    The primary use of cookies on our websites, either directly by the Company or our chosen partner(s), is to:

  • enable you to save time and facilitate future access to the site;
  • identify how people navigate through our website to improve our Service, content and the effectiveness of our communications;
  • collect and share device data to detect and prevent devices associated with fraud and money laundering;
  • identify account and device irregularities and detect and prevent fraudulent transactions and abuse of our customer accounts and our Services.

You agree that the Data Controller may, from time to time, place cookies on your device to save information (such as your username, password, personal details, e-mail address, and technical device information such as the model and its IP address) to make full use of the functionality and Services on our websites and to allow your browser to identify you as a user. This ensures that you do not have to re-enter your information each time you visit our websites. These cookies cannot be used to run programs or deliver viruses to your computer and are uniquely assigned to you. Additionally, these cookies can only be read by the web server(s) that placed the cookies on your device.

At any time, you can amend your browser settings to block some or all cookies from the Data Controller. However, if you block cookies from the Data Controller, some or all the of functionality of our websites may not perform as intended. For example, you may not actually be able to place any bets.

Further information about cookies and how to delete them from your browser can be found at: http://www.allaboutcookies.org.
  1. Transfer and Storage of your Personal Information

    The data we collect from you may be transferred to, and stored at, a destination outside of Malawi. It may also be processed by staff operating outside Malawi who work for the Company or for one of our suppliers. Such staff may be engaged in, among other things, the fulfilment of your request, the processing of your payment details, the provision of support services, or any other activity related to servicing any of your requests that you might place with us from over the course of your time with us.

    We will take all reasonably necessary steps to ensure that your Personal Data is treated securely and in accordance with this privacy policy by making sure such data transfers comply with applicable laws. Once we
    have received your data, we will use strict procedures and security measures to prevent unauthorised access and ensure the integrity and availability of your Personal Data.

    We are required to keep full records of all financial and wagering transactions together with any identification provided. We will hold your Personal Data on our systems for as long as is necessary under our legal obligations.

  2. Retention

    Except as otherwise permitted or required by applicable law or regulatory requirements, we endeavour to retain your Personal Data only for as long as we believe is necessary to fulfil the purposes for which the Personal Data was collected (including but not limited to for the purpose of meeting any legal, accounting or other reporting requirements or obligations). We may, instead of destroying or erasing your Personal Data, make it anonymous such that it cannot be associated with or traced back to you.

  3. How we keep your information secured

    We take great care in implementing and maintaining the security of the Services and your data. We have put in place appropriate physical and technological safeguards to help prevent unauthorised access, to maintain data security, and to appropriately use the information we collect online. These safeguards vary based on the sensitivity of the information that we collect and store.
    We employ industry standard procedures and controls to ensure the safety of our users’ information, such as:

  • securing network topology, which includes intrusion prevention and firewall systems;
  • encrypted communication;
  • authentication and access Control; and
  • external and internal audit tests.
Although we take reasonable steps to safeguard information, we cannot be responsible for the acts of those who gain unauthorised access or abuse the Services. We make no warranty, express, implied or otherwise, that we will prevent such access.
  1. Minors

    The Services are not designated to users under the age of 18. If you are under 18, you should not use the Services nor provide any Personal Data to us. We do not knowingly collect the Personal Data of persons under 18 years of age.
    We reserve the right to access and verify any Personal Data collected from you. In the event that we become aware that a user under the age of 18 has shared any information, we will discard such information. If you have any reason to believe that a minor has shared any information with us, please contact us [email protected].

  2. Support

    If you wish to unsubscribe from marketing communications, please contact Customer Support on: [email protected].

    If you have any questions (or comments) concerning this Privacy Policy, you are welcome to send it to us at: [email protected] for attention to the: Data Protection Officer.

    Policy Reviewed: June 2024