Contents
- 01 Introduction
- 02 Data Controller
- 03 Data We Collect
- 04 How We Collect Data
- 05 Legal Basis for Processing
- 06 How We Use Your Data
- 07 Sharing Your Data
- 08 Payment Data
- 09 Cookies & Tracking
- 10 Data Retention
- 11 Data Security
- 12 Your Rights
- 13 Children's Privacy
- 14 Marketing
- 15 Policy Updates
- 16 Contact Us
01 Introduction
pkr97 ("we", "us", "our", "the Company") takes the privacy of our players seriously. This Privacy Policy applies to all personal data collected, processed, and stored in connection with your use of the pkr97 platform, accessible at pkr97.bio and any associated services, applications, or communications channels operated by pkr97.
pkr97 serves primarily Pakistani players — in Karachi, Lahore, Islamabad, Faisalabad, Rawalpindi, Multan, and beyond — and we have designed our data practices to reflect the expectations and needs of a Pakistani audience while also meeting the standards required under our international gaming authority licensing framework.
This policy should be read alongside our Terms & Conditions and Responsible Gaming Policy, both of which form part of the overall agreement between you and pkr97. Capitalised terms not defined in this policy carry the meaning given to them in the Terms & Conditions.
Plain-language summary: pkr97 collects only the data it genuinely needs to operate the platform, comply with licensing and anti-money-laundering obligations, and provide you with a high-quality gaming experience. We do not sell your personal information to unaffiliated third parties.
02 Data Controller
For the purposes of applicable data protection law, pkr97 is the data controller in respect of the personal data of players using the platform. As data controller, pkr97 determines the purposes and means by which your personal data is processed.
pkr97 operates under international gaming authority licensing. Where data processing activities are carried out by third-party service providers on behalf of pkr97 (such as KYC verification providers, payment processors, and customer support software vendors), those third parties act as data processors under pkr97's instructions and are subject to data processing agreements that bind them to equivalent standards of data protection.
If you have any questions about pkr97's role as data controller, or wish to exercise any of your data rights as described in Section 12 of this policy, please contact pkr97 Support via live chat or at [email protected].
03 Data We Collect
pkr97 collects the following categories of personal data in connection with your use of the platform:
3.1 Identity & Registration Data
- Full legal name (as it appears on your CNIC or passport)
- Date of birth
- Gender (optional)
- National identification number (CNIC) — collected at KYC verification stage
- Copies of government-issued identity documents (CNIC, passport) for KYC purposes
3.2 Contact Data
- Pakistani mobile telephone number
- Email address
- Residential address (city and province level, with full address collected at KYC stage)
3.3 Account & Transactional Data
- Username and hashed account password (pkr97 does not store passwords in plain text)
- Account registration date and IP address at registration
- Deposit and withdrawal history, including transaction amounts, timestamps, and payment methods used
- Gaming history, including game sessions, bet amounts, win/loss records, and game types accessed
- Bonus and promotional activity records
- VIP tier status and loyalty point accumulation history
- Responsible gaming limit settings applied to your account
3.4 Technical & Device Data
- IP address and geolocation data (country and city level) at each login
- Device type, operating system, and browser version
- Device fingerprint data (used for fraud prevention and duplicate account detection)
- Session timestamps and platform navigation data
- Cookie identifiers and tracking pixel data (see Section 9)
3.5 Communications Data
- Records of live chat support conversations
- Email correspondence with pkr97 Support
- Records of complaints and dispute submissions
- Marketing communication interaction records (email opens, click-throughs) — only where you have opted in
3.6 KYC & Compliance Data
- Identity document images submitted during verification
- Source of funds declarations (where requested)
- Politically Exposed Person (PEP) and sanctions screening results
- AML risk scoring data generated by pkr97's compliance systems
Sensitive Data: pkr97 does not intentionally collect special-category sensitive personal data (such as health, biometric, or religious data) unless this is strictly necessary for a specific compliance purpose and disclosed to you in advance.
04 How We Collect Your Data
pkr97 collects personal data through the following means:
- Direct submission: Information you provide when registering, completing KYC verification, making deposits or withdrawals, contacting Support, or updating your account profile.
- Automated platform systems: Technical and behavioural data collected automatically as you use the pkr97 platform, including device data, session logs, and gaming activity records.
- Cookies and tracking technologies: Data collected via cookies, web beacons, and similar technologies as described in Section 9 of this policy.
- Third-party KYC providers: Identity and document verification data returned by pkr97's accredited KYC service partners when processing your identity verification submission.
- Payment processors: Transaction confirmation data returned by payment service providers including JazzCash, EasyPaisa, HBL, UBL, Meezan Bank, SadaPay, and USDT TRC20 network providers.
- Sanctions and PEP screening databases: Results of automated screening checks conducted against international sanctions lists and politically exposed person databases as required by pkr97's AML compliance framework.
05 Legal Basis for Processing
pkr97 processes your personal data on the following legal bases, depending on the specific processing activity:
| Processing Activity | Legal Basis |
|---|---|
| Account registration and management | Performance of contract with you as a registered player |
| Processing deposits and withdrawals | Performance of contract; legal obligation (AML) |
| KYC identity verification | Legal obligation under licensing framework |
| AML monitoring and fraud prevention | Legal obligation; legitimate interest in protecting the platform |
| Customer support communications | Performance of contract; legitimate interest |
| Responsible gaming tool administration | Legal obligation; legitimate interest in player protection |
| Marketing communications (email/SMS) | Consent (opt-in); withdrawable at any time |
| Platform security and duplicate account detection | Legitimate interest in protecting platform integrity |
| Analytics and platform improvement | Legitimate interest in improving services (anonymised where possible) |
| Compliance with legal orders or regulatory requests | Legal obligation |
06 How We Use Your Data
pkr97 uses the personal data we collect for the following specific purposes:
- Creating and administering your pkr97 account, including processing your registration and verifying your identity
- Enabling you to deposit and withdraw funds in Pakistani Rupees (PKR) through your chosen payment methods
- Providing access to pkr97's full game library, including casino games, sports betting, live dealer tables, and arcade-style games
- Administering bonus programmes, promotional offers, and the VIP Reserve loyalty programme
- Conducting Know Your Customer (KYC) verification as required under our international gaming licence
- Monitoring transactions and gaming behaviour to detect and prevent money laundering, fraud, and other prohibited conduct
- Operating responsible gaming tools on your account, including deposit limits, loss limits, cooling-off periods, and self-exclusion
- Providing customer support through live chat, email, and other communication channels
- Investigating and resolving complaints and disputes
- Sending service-related communications, including transaction confirmations, security alerts, and policy update notifications
- Sending marketing communications where you have provided consent to receive them
- Analysing aggregated and anonymised platform usage data to improve pkr97's services and user experience
- Complying with legal obligations under applicable law and the requirements of our licensing authority
Purpose limitation: pkr97 will not use your personal data for purposes that are incompatible with those listed above without first informing you and, where required, obtaining your consent.
07 Sharing Your Data
pkr97 does not sell your personal data to unaffiliated third parties for their own commercial purposes. However, we share personal data with third parties in the following limited circumstances:
7.1 Service Providers (Data Processors)
pkr97 engages trusted third-party service providers to assist with platform operations. These providers process data only on pkr97's instructions under binding data processing agreements. Categories of service providers include: KYC and identity verification providers, payment processing partners, customer support software vendors, cloud hosting and infrastructure providers, fraud detection and device fingerprinting services, and email and communications delivery providers.
7.2 Regulatory and Law Enforcement
pkr97 may disclose personal data to regulatory authorities, law enforcement agencies, or courts of competent jurisdiction where required to do so by applicable law, valid legal process, or the requirements of our gaming licence. pkr97 will notify affected players of such disclosures where legally permitted to do so.
7.3 Licensing Authority
pkr97 is obligated to share certain player data with its international gaming authority licensing body for compliance monitoring, audit, and dispute resolution purposes. Such sharing is a condition of operating as a licensed gaming platform.
7.4 Business Transfers
In the event of a merger, acquisition, or sale of all or substantially all of pkr97's business assets, personal data held by pkr97 may be transferred to the acquiring entity as part of that transaction. Affected players will be notified of any such transfer and of any resulting change to their data controller in advance of the transfer taking effect.
Cross-border transfers: Some of pkr97's service providers may be located outside Pakistan. Where personal data is transferred internationally, pkr97 ensures that appropriate safeguards are in place to protect your data to a standard equivalent to this policy.
08 Payment Data
pkr97 takes particular care with payment and financial data. The following practices apply specifically to payment information collected in connection with deposits and withdrawals:
- pkr97 does not store full bank account numbers, JazzCash/EasyPaisa account credentials, or card numbers on its own servers. Payment credentials are transmitted directly to and held by regulated payment service providers.
- Transaction records (amounts, timestamps, method references, and confirmation codes) are retained by pkr97 for AML compliance and audit purposes in line with the retention periods described in Section 10.
- Payment method information associated with your account (such as the registered mobile number linked to your JazzCash or EasyPaisa account) is used for the purpose of processing deposits and withdrawals and for verifying the ownership of payment methods during KYC review.
- pkr97 applies a same-method withdrawal policy as an AML control measure. This means withdrawals are generally processed to the same payment method used for deposits.
- All payment data transmitted between your device and pkr97's platform is encrypted using 256-bit SSL/TLS encryption.
09 Cookies & Tracking Technologies
pkr97 uses cookies and similar tracking technologies on the platform. The following categories of cookies are used:
| Cookie Type | Purpose | Duration |
|---|---|---|
| Essential / Strictly Necessary | Session management, authentication, security token maintenance, load balancing | Session / up to 24 hours |
| Functional | Remembering your language preference, game lobby settings, and display preferences | Up to 12 months |
| Analytics | Aggregated and anonymised platform usage analysis to understand player behaviour and improve pkr97's services | Up to 12 months |
| Fraud & Security | Device fingerprinting for duplicate account detection, bot prevention, and fraud monitoring | Up to 12 months |
| Marketing (opt-in only) | Tracking interaction with promotional content and referral programmes, only where marketing consent has been given | Up to 6 months |
Essential cookies are required for the platform to function and cannot be disabled. All other cookie categories are activated based on your consent preferences, which can be updated at any time through the Cookie Preferences option accessible in your account settings or in the cookie notice presented on first visit to pkr97.
Most modern browsers allow you to control cookie storage through browser settings. Please be aware that disabling certain categories of cookies may impact the functionality of the pkr97 platform.
10 Data Retention
pkr97 retains personal data only for as long as necessary to fulfil the purposes for which it was collected, subject to the following minimum retention periods required by our licensing obligations and applicable law:
| Data Category | Retention Period | Basis |
|---|---|---|
| Account registration data | Duration of account + 5 years post-closure | Licensing obligation; AML compliance |
| KYC identity documents | Duration of account + 5 years post-closure | AML / KYC legal requirement |
| Transaction records | Duration of account + 5 years post-closure | AML legal requirement |
| Gaming history records | Duration of account + 3 years post-closure | Licensing audit requirement |
| Support communications | 3 years from date of interaction | Dispute resolution; legitimate interest |
| Marketing consent records | Until consent withdrawn + 3 years | Legal obligation to evidence consent |
| Technical / session log data | Up to 12 months | Security and fraud prevention |
After the applicable retention period expires, personal data will be securely deleted or anonymised such that it can no longer be linked to an identifiable individual. Anonymised aggregated data may be retained indefinitely for statistical and analytical purposes.
11 Data Security
pkr97 implements a multi-layered security framework to protect your personal data against unauthorised access, disclosure, alteration, or destruction. Measures in place include:
- Encryption in transit: All data transmitted between your device and pkr97's platform is protected by 256-bit SSL/TLS encryption. The padlock icon in your browser address bar when visiting pkr97.bio confirms this encryption is active.
- Encryption at rest: Sensitive data stored on pkr97's servers — including identity documents and payment reference data — is encrypted at rest using industry-standard encryption protocols.
- Password security: Account passwords are stored in hashed form using a cryptographically secure hashing algorithm. pkr97 cannot retrieve your plain-text password and will never ask you for it.
- Two-factor authentication: pkr97 supports two-factor authentication (2FA) for all accounts and strongly recommends its activation. 2FA significantly reduces the risk of unauthorised account access even if login credentials are compromised.
- Access controls: Access to player personal data within pkr97's internal systems is restricted on a strict need-to-know basis. Staff access is role-based and subject to regular review. All internal data access is logged.
- Infrastructure security: pkr97's platform is hosted on enterprise-grade cloud infrastructure with physical security controls, network firewalls, intrusion detection systems, and regular third-party security assessments.
- Data breach response: pkr97 maintains an incident response plan for personal data breaches. In the event of a breach that poses a risk to your rights, pkr97 will notify affected players and, where required, the relevant regulatory authority, within the timeframe required by applicable law.
Your role in security: No security system is entirely without risk, and the security of your account also depends on steps you take. Please use a strong, unique password for pkr97, enable 2FA, and never share your login credentials with anyone — including persons claiming to represent pkr97 Support.
12 Your Data Rights
As a player on pkr97, you have the following rights in relation to your personal data. These rights may be subject to limitations where pkr97 has overriding legal obligations that require retention or continued processing of your data.
Right of Access
You have the right to request a copy of the personal data pkr97 holds about you, together with information about how and why it is being processed. pkr97 will respond to verified access requests within 30 days.
Right to Rectification
You have the right to request correction of inaccurate or incomplete personal data. Many contact details can be updated directly through your account settings. For identity document corrections, contact pkr97 Support.
Right to Erasure
You may request deletion of your personal data where it is no longer necessary for the purposes for which it was collected. Note that pkr97 is legally obligated to retain certain data (particularly KYC and transaction records) for a minimum of 5 years post account closure and cannot comply with erasure requests for this data during that period.
Right to Restrict Processing
You may request that pkr97 restrict processing of your data in certain circumstances — for example, where you contest the accuracy of the data and pkr97 is verifying it, or where processing is unlawful but you do not wish the data to be deleted.
Right to Data Portability
Where technically feasible, you have the right to receive personal data you have provided to pkr97 in a structured, commonly used, machine-readable format, and to have it transmitted to another controller of your choosing.
Right to Object
You have the right to object to processing of your personal data where pkr97 relies on legitimate interest as its legal basis. This right is particularly relevant to direct marketing, against which you may object at any time and without providing justification.
Withdrawing Consent
Where pkr97 processes your data on the basis of consent (such as for marketing communications), you may withdraw that consent at any time without affecting the lawfulness of processing carried out before the withdrawal. Withdraw consent via your account's notification settings or by contacting pkr97 Support.
To exercise any of the above rights, please contact pkr97 Support via live chat or at [email protected]. pkr97 may request identity verification before processing data rights requests to ensure that your data is not disclosed to unauthorised parties.
13 Children's Privacy
The pkr97 platform is strictly restricted to adults aged 21 years and above. pkr97 does not knowingly collect, process, or store personal data relating to individuals under the age of 21. This restriction is enforced through the KYC age verification process applied to all player accounts before withdrawals are processed.
If pkr97 becomes aware that personal data has been collected from a person under 21 years of age — whether through registration fraud, misrepresentation, or other means — that account will be immediately suspended, all personal data associated with it will be securely deleted (subject to any overriding legal obligation to retain evidence of the breach), and any deposits made will be returned subject to applicable legal requirements.
If you have reason to believe that a person under 21 has registered on pkr97, please contact pkr97 Support immediately via live chat so that the matter can be investigated and resolved without delay.
14 Marketing Communications
pkr97 may send promotional and marketing communications — including bonus offers, new game announcements, VIP Reserve programme updates, and special event promotions — by email and SMS where you have expressly opted in to receive them during registration or subsequently through your account notification settings.
You may withdraw your consent to receive marketing communications at any time by:
- Clicking the unsubscribe link contained in any pkr97 marketing email
- Updating your notification preferences in the Account Settings section of your pkr97 account
- Contacting pkr97 Support via live chat and requesting removal from all marketing communications
Withdrawal of marketing consent does not affect your receipt of service-related communications, such as withdrawal confirmations, security alerts, account verification messages, and policy update notifications, which pkr97 sends on the basis of contract performance and legitimate interest rather than consent.
Players who have requested self-exclusion under pkr97's responsible gaming tools are automatically removed from all marketing communications immediately upon self-exclusion taking effect.
15 Policy Updates
pkr97 reserves the right to update, amend, or replace this Privacy Policy at any time to reflect changes in our data practices, applicable law, licensing requirements, or the services we offer. Where changes are material, pkr97 will notify registered players in advance through one or more of the following channels: email notification to your registered address, an in-platform notification displayed upon login, or a prominent notice on the pkr97 website.
The date of the most recent revision is displayed at the top of this page under "Last Updated". Your continued use of the pkr97 platform following the effective date of any update constitutes your acceptance of the revised Privacy Policy. If you do not agree with the updated policy, you should cease using the platform and may request account closure and return of any available balance by contacting pkr97 Support.
pkr97 encourages players to review this Privacy Policy periodically. Archived versions of previous policies are available upon request from pkr97 Support.
16 Contact Us
If you have any questions, concerns, or requests relating to this Privacy Policy or pkr97's handling of your personal data, please reach out through the following channels:
- Live Chat: Available 24/7 through the pkr97 platform — typically under 90 seconds response time
- Email: [email protected] — responses within 2 hours, Monday to Saturday, 8am–10pm PST
- Support Languages: English and Urdu
When submitting a privacy-related enquiry or data rights request, please include your registered pkr97 username and a clear description of your request or concern to allow us to respond efficiently. pkr97 may request additional identity verification before actioning data rights requests to protect the security of your account.
Our commitment: pkr97 is committed to responding to all privacy-related enquiries promptly and transparently. If you are not satisfied with pkr97's handling of your data or the response to a data rights request, you have the right to escalate the matter to the data protection supervisory authority in your jurisdiction, or to the dispute resolution mechanism provided under pkr97's licensing framework.