Privacy Policy
Version 1.1 — 2026
KasoPlex is committed to protecting your privacy. This policy explains how we collect, use, and protect your personal data in compliance with GDPR, COPPA, and applicable financial regulations.
1. Data Collected
Account data: phone number, pseudo, email (optional), age of birth, profile avatar, age verification timestamp (COPPA).
Identity data: KYC identity documents (national ID, passport), collected for identity verification only. Processed by Didit (third-party KYC provider).
Financial data: transaction history, Mobile Money numbers (MTN, Orange, Moov), wallet balances, commission history. Used ONLY for transactions and AML compliance.
Activity data: projection history, bets placed, comments posted, badges earned, followed users list.
Technical data: IP address, approximate geolocation, device type, OS, browser (user-agent). Collected exclusively for fraud prevention and platform security.
Consent data: cookie preferences, age verification method, opt-in dates. Stored in audit_log for GDPR audit trail.
2. Legal Basis for Processing
Account & authentication: Contractual necessity (ToS acceptance).
Age verification & COPPA: Legal obligation (US FTC COPPA rule 16 CFR §312) + contractual necessity.
KYC/AML: Legal obligation (FATF, FinCEN, local anti-money laundering rules).
Fraud prevention: Legitimate interest (protecting platform & users).
Analytics & error reporting: Legitimate interest (improving service) — subject to consent (cookies banner).
3. Third-Party Vendors & Data Sharing
KYC Documents: KYC/identity verification collected for identity verification only. Processed by a third-party provider.
Firebase (Google): Auth (OTP SMS), optional analytics. Google Privacy
Mobile money operators (MTN, Orange, Airtel, Moov): Payment processing. Data: phone, amount only.
AWS (PostgreSQL): Database hosting (EU servers). Privacy
Sentry (optional): Error reporting. Collects: stack traces, browser info. Privacy — Requires opt-in.
We do NOT: Sell your data. Share with advertisers. Use third-party trackers. Process data outside legal requirements.
4. Data Security
Encryption in transit: TLS 1.2+, HTTPS only, HSTS headers.
Encryption at rest: Sensitive fields (phone, email) encrypted with deterministic encryption. Passwords: encryption (10 rounds).
Access control: Role-based (user, creator, admin). JWT tokens with 30-day expiry. Audit logging on all sensitive operations.
KYC data: Handled exclusively by third-party provider. We store only verification results (verified: yes/no), not the documents themselves.
5. Data Retention
Active account: Data retained as long as account exists + 30 days after hard deletion.
Transaction data: 5 years (FATF AML requirement).
Audit logs: 90 days for fraud investigation, then anonymized.
Technical logs (IP, device): 12 months max.
Images (projections): Deleted 30 days after market resolution.
After hard deletion: All PII removed from database. Backup copies destroyed within 60 days.
6. Your Rights (GDPR + CCPA + COPPA)
Access: Download all your data (profile, transactions, bets, comments) in JSON format from Settings → Export Data.
Correction: Update profile info (name, email, avatar) directly in account settings.
Deletion (hard delete): Request permanent data removal via Settings → Security → Request Permanent Deletion. We will anonymize all PII, delete wallet balances, remove from social graphs, and complete within 30 days.
Portability: Export your data in JSON/CSV format from account settings.
Objection to processing: Opt out of analytics/error reporting via the cookies banner at any time.
Withdraw consent: You can withdraw consent for optional processing (Sentry, Firebase Analytics) at any time via Settings → Cookies.
Parental rights (COPPA): If you are a parent/guardian of a minor who created an account, you may request deletion of their data. Contact privacy@kasoplex.com with proof of guardianship.
7. Cookies & Tracking
Essential cookies (always enabled):
kb_token(JWT, 30 days, secure, httpOnly) — Authenticationkb_refresh(refresh token, 30 days, secure, httpOnly) — Session renewal
Optional cookies (requires consent):
- Firebase Analytics — Understand how you use KasoPlex
- Sentry error tracking — Improve reliability
Local storage (non-sensitive only): Theme preference, age verification status, wallet goals.
No: Advertising cookies, third-party trackers, cross-site tracking, fingerprinting.
Cookies banner: Shown on first visit. Revoke consent anytime in Settings → Cookies.
8. Contact & Data Protection Officer
For privacy questions: privacy@kasoplex.com
Mailing address: KASOPLEX SARL, 49 rue Jean Jacques Rousseau, 94800 Villejuif, France
Data Protection Officer: privacy@kasoplex.com
Response time: Requests answered within 30 days (GDPR requirement).
9. COPPA Compliance (US)
KasoPlex restricts access to users 18 years and older. Age verification is required at signup. We do not knowingly collect data from users under 13. If you are a parent and believe your child has created an account, contact privacy@kasoplex.com immediately for account deletion.
10. Changes to This Policy
We may update this policy anytime. Changes take effect immediately upon posting. Continued use after changes constitutes acceptance. We will notify you of material changes via email or in-app notification.