Taking Control of Your Data: How to Exercise Your Rights Under the Gembet Privacy Policy
The Gembet Privacy Policy explains how personal information may be collected and used when someone creates an account, verifies an identity, completes transactions, or interacts with the platform. Uploading an identity document does not prevent a player from later asking what information is held, correcting inaccurate details, or questioning why specific records are still required. The official policy page states that it explains what information is collected, why it is collected, and how the collected information is used.
However, data control does not always mean that every record must be deleted immediately on request. Access, correction, withdrawal of consent, account closure, and deletion are separate processes. Financial, security, dispute, fraud-prevention, and regulatory records may remain necessary after an account is closed.
This guide gives Singapore players a practical seven-step process for submitting a clear privacy request without assuming that access, deletion, or a fixed response time is guaranteed in every situation.
What the Gembet Privacy Policy Can Help You Request
| Request Type | Purpose | Possible Limitation |
| Data access | Ask what personal information is held and how it has been used | Identity checks, legal exceptions, and request scope may apply |
| Correction | Update inaccurate or incomplete account information | Evidence may be required before verified details are changed |
| Consent withdrawal | Stop specified optional uses, such as marketing | Essential processing may continue when legally permitted or required |
| Account closure | Disable future access and end the customer relationship | Closure does not automatically erase every record |
| Deletion request | Ask for unnecessary information to be removed or anonymised | Records needed for legal or business purposes may be retained |
| Retention explanation | Ask what remains stored, why, and for how long | The answer may vary by record category and applicable law |
Under Singapore’s Personal Data Protection Act, individuals can request access to and correction of personal information held by an organisation. Individuals may also withdraw consent with reasonable notice, although the organisation should explain the likely consequences.
These statutory rights should not be confused with an unlimited right to demand immediate deletion. The exact process may depend on the operator, the governing privacy terms, the player’s location, and the law applicable to the account.
1. Read the Current Policy Before Sending a Request
Open the current Gembet Privacy Policy rather than relying on an old screenshot, copied article, or previous support conversation. Privacy terms, operating entities, contact channels, and request procedures can change.
Record the following information:
- The policy date or version, if shown.
- The named company responsible for processing the data.
- The privacy or support contact channel.
- The categories of information collected.
- The purposes stated for processing.
- The listed retention and data-sharing terms.
- Any available complaint or appeal process.
Use the contact method displayed on the current policy or official support area. Do not send identification documents to an address copied from an unofficial review, forum, or social-media message.
2. Submit a Focused Data Access Request
A data access request asks the platform to identify personal information associated with the account. It should be specific enough for the privacy team to locate the correct records without requesting an unnecessary amount of additional identification.
Request Flow: Identify the account → Define the requested records → Select a date range → Verify your identity → Save the request reference → Review the response
Possible categories to request include:
- Registration and profile information.
- Identity-verification records.
- Deposit, withdrawal, and transaction information.
- Login dates, IP records, and security activity.
- Device or browser information linked to the account.
- Marketing preferences and consent records.
- Support conversations and complaint history.
- Information shared with service providers, where applicable.
A request for “everything” may be harder to process than a defined request. State the relevant period and explain whether you want account data, transaction history, verification information, or a broader privacy report.
PDPC guidance says organisations should verify the identity of the person making an access request. It also explains that when access cannot be provided within 30 days, the individual should be informed as soon as possible of when a response can be expected.
A practical message is:
Subject: Personal Data Access Request
Hello, I am requesting access to the personal information associated with my account. Please provide my profile information, verification records, transaction history, login records, consent preferences, and support history for the period [date] to [date]. Please confirm any identity-verification steps, applicable limitations, and the expected response process.
3. Correct Inaccurate Account Information
Incorrect names, addresses, phone numbers, or banking information can create verification and transaction problems. The correction process should clearly identify the existing information, the accurate replacement, and the evidence supporting the change.
- Review pending activity. Check for unresolved deposits, withdrawals, verification reviews, or disputes.
- Collect current evidence. Prepare only the documents necessary to prove the requested correction.
- Explain the error. State exactly which field is inaccurate and how it should appear.
- Use a secure channel. Submit documents through the verified upload tool or current Gembet help channel.
- Save confirmation. Keep the request number and the final correction notice.
Singapore PDPC guidance states that an organisation should correct personal data as soon as practicable, subject to applicable grounds for refusing or limiting the correction.
Do not send more sensitive information than required. A request to change a residential address may need proof of address, but it should not automatically require unrelated payment credentials or full banking passwords.
4. Withdraw Consent for Optional Processing
Consent withdrawal can be appropriate when a player no longer wants marketing emails, promotional messages, behavioural profiling, or another optional use described in the Gembet Privacy Policy.
Be precise about what consent is being withdrawn. A message saying “stop using my data” may be interpreted differently from a request that specifically says:
- Stop promotional email communication.
- Stop SMS marketing.
- Remove the account from personalised advertising lists.
- Withdraw consent for optional analytics cookies.
- Stop sharing information for a named optional purpose.
Under the PDPA, an individual may withdraw consent by giving reasonable notice. The organisation should inform the person of the likely consequences and must stop the affected collection, use, or disclosure unless continued processing is authorised or required by law.
Withdrawing consent required to provide an account service may affect account access. Ask for the consequences in writing before confirming a broad withdrawal request.
5. Separate Account Closure From Data Deletion
Closing an account normally prevents future use. It does not necessarily remove transaction records, security logs, verification information, complaints, or records required to investigate fraud and disputes.
The PDPA does not create a general requirement for an organisation to destroy personal information simply because an individual requests deletion. Instead, an organisation must cease retaining identifiable personal data when the original purpose is no longer served and retention is no longer necessary for legal or business purposes.
| Possible Action | Likely Treatment |
| Disable account access | May occur as part of account closure |
| Remove marketing contact details | May be completed after consent withdrawal |
| Delete duplicate or obsolete uploads | May be possible when no longer required |
| Anonymise analytics information | May be used when identification is unnecessary |
| Retain financial records | May continue for legal, audit, security, or dispute purposes |
| Retain responsible-play restrictions | May be necessary to enforce account restrictions or prevent re-registration |
Ask the privacy team to divide its answer into three categories: information deleted, information anonymised, and information retained. For retained records, request the purpose and expected retention basis.
6. Protect Yourself During the Request Process
A privacy request can itself attract phishing attempts because it involves identity and account information. Contact the platform through its verified website and do not follow unexpected links sent through private messages.
Never provide:
- Your password.
- A banking one-time password.
- A complete card security code.
- Remote access to your phone or computer.
- An unrestricted copy of an identity document through social media.
If additional identity verification is required, ask why each document is needed, how it will be transferred, and whether unnecessary fields can be covered. Keep a copy of every file submitted and the date it was provided.
This protects both the request and the broader compliance and privacy record associated with the account.
7. Track the Response and Escalate Carefully
Save the original message, automatic confirmation, reference number, supporting files, and every reply from Gembet help. Create a simple timeline showing when the request was sent and what action was promised.
If no meaningful response arrives, send a concise follow-up:
Hello, I am following up on privacy request [reference], submitted on [date]. Please confirm its current status, any outstanding verification requirement, and the expected date of the next response.
Singapore players who believe a private organisation has mishandled personal information should normally contact the organisation first, wait for its response, and then consider the appropriate escalation channel. The PDPC describes this organisation-first process in its guidance for reporting data-protection concerns.
Do not combine a privacy request with unrelated bonus, game-result, or payment complaints. Submit separate cases so the privacy issue has a clear record and responsible team.
Gembet Privacy Policy Request Checklist
- Have you read the current Gembet Privacy Policy?
- Are you using the official privacy or Gembet help channel?
- Have you identified the correct account?
- Is the requested action clearly stated?
- Have you listed the relevant data categories?
- Have you included a reasonable date range?
- Have you separated access, correction, consent, closure, and deletion requests?
- Are supporting documents necessary and current?
- Have you removed unrelated sensitive information?
- Have you requested a case reference?
- Have you saved every message and attachment?
- Have you asked what will be deleted, anonymised, or retained?
Common Privacy Request Mistakes
Assuming Every Record Must Be Deleted
Account closure and deletion are different. Some records may remain necessary for legal, security, audit, or dispute purposes.
Requesting Everything Without a Scope
A specific data category and date range can make the request easier to identify and process.
Sending Documents Through an Unverified Contact
Use the current official channel rather than an address copied from a third-party article.
Changing Verified Details Without Evidence
Corrections to identity information may require supporting documents to protect the account from unauthorised changes.
Confusing Consent Withdrawal With Erasure
Stopping a future use does not automatically remove records already retained for another valid purpose.
Best Way to Use the Gembet Privacy Policy
The best way to use the Gembet Privacy Policy is to treat each privacy right as a separate request. Ask for access when you want to understand the records held, request correction when details are inaccurate, withdraw consent for specific optional uses, and request deletion or anonymisation only for information that may no longer be necessary.
Keep the request precise, verify your identity through a secure channel, and ask for written confirmation of what action was completed. When information must remain stored, request an explanation of the category, purpose, and retention basis.
The goal is not to assume that every file can be erased immediately. It is to create a clear record, reduce unnecessary data exposure, and ensure that the information associated with the account remains accurate, limited, and handled according to the current policy and applicable law.
Experience the real deal with SG's top Live Dealers. Play Baccarat, Roulette & more.