Privacy Policy
How jogodobicho collects, uses, shares, protects and deletes your personal data, the legal basis for each of those things, and how you exercise your rights as a data subject under the LGPD.
Some company details have not been provided yet and appear as “to be provided”. None were assumed: a made-up tax ID would be worse than a missing one.
1. Who is the controller of your personal data
The controller of the personal data processed on the website jogodobicho.com and in the official apps of the jogodobicho brand is [to be provided], registered under CNPJ nº [to be provided], with its address at [to be provided], authorised to operate the fixed-odds betting lottery by the Secretaria de Prêmios e Apostas of the Ministério da Fazenda (SPA/MF) under authorisation [to be provided].
The controller is the party that decides why and how your data is processed. Where this Policy says “we”, it refers to that company. Where it says “you”, it refers to anyone who visits the site, opens an account, bets, deposits or withdraws.
This Policy explains, in plain language, what data we collect, why we collect it, who we share it with, how long we keep it, and what you may require from us at any time. It is written to be read by you, not only by lawyers.
Legal basis: Lei nº 13.709/2018 (LGPD), art. 5º, VI, VII and IX · Lei nº 14.790/2023, art. 2º · Lei nº 13.756/2018, art. 29 (fixed-odds betting lottery) · Portaria SPA/MF nº 1.475/2024 (.bet.br domain)
2. Data Protection Officer (DPO) and how to reach them
We have a Data Protection Officer, appointed by written instrument, who acts as the channel of communication between you, the company and the Autoridade Nacional de Proteção de Dados (ANPD).
You can reach the DPO at [to be provided]. You do not need to justify why you are writing or to fill in a form first: writing is enough.
If you would rather use the general channels, contact customer support at [to be provided]; if you have already complained and were not satisfied with the answer, use the Ombudsman (Ouvidoria) at [to be provided]. Data protection requests received through any of those channels are forwarded to the DPO.
Legal basis: LGPD, art. 41 and §§ 1º and 2º · Resolução CD/ANPD nº 18/2024 (DPO Regulation) · Portaria SPA/MF nº 1.231/2024 (customer service and ombudsman channels)
3. Who this Policy applies to, and what the terms we use mean
This Policy applies to the website jogodobicho.com, to the official jogodobicho apps, and to all support we provide by email, telephone, chat or messaging.
Access to demonstration mode — the fun mode, with no economic value, in which no money is staked, won or lost — does not require registration. In that mode we process only technical browsing data, and there is no bet within the meaning of the law, because there is no financial stake by the bettor.
Betting with real money, depositing or withdrawing does require a registered and verified account. That is not a commercial choice of ours: prior identification of the bettor is a regulatory obligation, and there is no way to move funds with us without identifying yourself.
To make this easier to read, these are the terms used throughout the text:
- Personal data: any information that identifies you or makes you identifiable, directly or indirectly.
- Sensitive personal data: among others, biometric data — in our case, the image of your face used to prove that you are you.
- Processing: any operation performed on data — collecting, storing, using, sharing, correcting, deleting.
- Data subject: you, the person the data relates to.
- Processor: a company that processes data on our behalf and according to our instructions.
Legal basis: LGPD, art. 5º, I, II, V, VII and X · Lei nº 14.790/2023, art. 2º, I and VIII, and art. 3º, II · Portaria SPA/MF nº 1.231/2024, art. 31 (bettor registration)
4. Personal data we process
We collect the data below directly from you, from your devices when you use our services, and from the verification sources required by the regulation:
We do not ask for, and do not want, data we do not need. If you spontaneously send us unnecessary information — for example, in a support attachment — we delete it, unless there is a legal duty to retain it.
Some of this data is mandatory by regulation: without it we cannot open or maintain your betting account. Mandatory fields are marked as such on the registration form.
- Identification and registration data: full name, nationality, CPF, date of birth, gender, full address, country of residence, telephone number and email address.
- Identity verification data: a copy of an official photo ID, a facial image with liveness proof, and the results of CPF, age, restricted-list and politically exposed person checks.
- Financial and transactional data: payment accounts held in your name, deposits, withdrawals, balance, statement of movements, and the prudential limits you set.
- Gameplay data: bets placed, amounts, times, games accessed, results, prizes, session time, and the history of breaks, limit changes and self-exclusion.
- Device and connection data: IP address — including the one used at registration and at each change to your registration details —, device identifiers, operating system, browser, language and access logs.
- Geolocation data: approximate location derived from the IP address and, if you authorise it, the precise location of your device.
- Support data: messages, emails, telephone call recordings and the history of your requests.
- Communication data and preferences: consents granted or withdrawn, channels chosen, and interactions with our communications.
Legal basis: LGPD, art. 5º, I and II, and art. 6º, III (necessity) · Portaria SPA/MF nº 1.231/2024, arts. 31 and 32 · Portaria SPA/MF nº 1.143/2024 (identification and monitoring)
5. What we process each item of data for, and on what legal basis
The LGPD requires every use of data to have a legal basis. Below we state, for each purpose, what ours is — and you will see that most of what we do does not depend on your consent, because it derives from a legal obligation or from performance of the contract we have with you:
Where we rely on legitimate interests, we assess beforehand whether the purpose is concrete, whether the processing is the minimum needed to achieve it, and whether your expectations and rights are preserved. You may ask us to explain that assessment through the DPO channel.
- Opening, maintaining and operating your account, recording bets, crediting prizes, processing deposits and withdrawals, and providing support — legal basis: performance of the contract (LGPD, art. 7º, V).
- Verifying your identity and your age, validating your CPF, screening restricted lists and politically exposed persons, and keeping your registration up to date — legal basis: compliance with a legal and regulatory obligation (LGPD, art. 7º, II).
- Preventing and combating money laundering and terrorist financing, monitoring atypical transactions and reporting them to the competent authorities — legal basis: compliance with a legal and regulatory obligation (LGPD, art. 7º, II).
- Complying with responsible gambling obligations: limits, session-time alerts, breaks, self-exclusion and protection of anyone showing signs of risk — legal basis: compliance with a legal and regulatory obligation (LGPD, art. 7º, II).
- Transmitting information on bettors, bets and wallets to the SPA/MF supervisory system and responding to requests from authorities — legal basis: compliance with a legal and regulatory obligation (LGPD, art. 7º, II).
- Retaining registration, gameplay and financial records for the periods required by the regulation — legal basis: compliance with a legal and regulatory obligation (LGPD, arts. 7º, II, and 16, I).
- Issuing tax documents and calculating taxes and withholdings on prizes — legal basis: compliance with a legal obligation (LGPD, art. 7º, II).
- Preventing fraud, account use by third parties, collusion, result manipulation and promotion abuse, and securing the system — legal basis: legitimate interests (LGPD, arts. 7º, IX, and 10) and, in registration identification and authentication processes, art. 11, II, item “g”.
- Exercising and defending rights in administrative, judicial or arbitral proceedings — legal basis: LGPD, art. 7º, VI, and, as regards sensitive data, art. 11, II, item “d”.
- Sending offers, promotions and news by email, SMS, push notification or messaging — legal basis: consent (LGPD, art. 7º, I).
- Collecting the precise location of your device — legal basis: consent (LGPD, art. 7º, I). Approximate location by IP address, where needed to comply with legal access restrictions, relies on art. 7º, II.
Legal basis: LGPD, arts. 7º, 10, 11 and 16 · Lei nº 14.790/2023, arts. 23 to 25 · Lei nº 9.613/1998 (anti-money laundering) · Portaria SPA/MF nº 1.143/2024 · Portaria SPA/MF nº 1.231/2024 · Portaria SPA/MF nº 722/2024
6. What depends on your consent: marketing and geolocation
Two things, and only two, depend on your consent: marketing communications and the collection of your device precise location. You can use your account normally without consenting to either.
Consent is free, informed and specific: we ask separately for each purpose, never bundled into acceptance of the Terms of Use, and we record when and how you gave it.
You may withdraw consent at any time, through your account preferences, through the unsubscribe link in our messages, or by writing to [to be provided]. Withdrawal is free of charge and takes effect as soon as we process it; it does not invalidate processing carried out beforehand, nor does it affect processing that relies on another legal basis.
We do not send advertising to anyone under self-exclusion, to anyone who has requested a break, or to persons under 18. Operational messages — withdrawal confirmations, security alerts, notice of changes to these policies — are not marketing and continue to be sent, because they derive from the contract and from the regulation.
Legal basis: LGPD, arts. 7º, I, 8º, §§ 4º and 5º, and 18, IX · Portaria SPA/MF nº 1.231/2024 (advertising and responsible gambling)
7. Facial biometrics and other sensitive data
To prove that you are who you say you are, the regulation requires facial recognition with liveness proof at registration. The image of your face is sensitive personal data and receives heightened protection.
We process that data to comply with the legal and regulatory obligation to identify the bettor, and to ensure fraud prevention and your own security in registration identification and authentication processes. We do not use it for advertising, we do not sell it, and we do not release it for training third-party models.
Capture is performed by a specialist supplier acting as a processor, under contract and according to our instructions. We retain the verification result and the material the regulation requires to remain available to the supervisor, for the period stated in section 12.
Legal basis: LGPD, art. 5º, II, and art. 11, II, items “a” and “g” · Portaria SPA/MF nº 1.231/2024, art. 31, § 3º (facial recognition with liveness proof) · Portaria SPA/MF nº 1.143/2024
8. Monitoring, fraud prevention and automated decisions
We monitor transactions and betting behaviour by automated means. This is mandatory and serves to detect atypical transactions, mismatches between the amounts staked and the declared economic capacity, signs of fraud or of an account operated by a third party, and signs of problem gambling.
This monitoring may trigger automatic consequences: a request for additional documentation, a precautionary hold on a withdrawal, a temporary restriction of the account, or suspension of the registration. None of them becomes final without human review when you request it.
You have the right to request a review of decisions taken solely on the basis of automated processing that affect your interests, and to receive information about the criteria used, subject to commercial and industrial secrecy and to the anti-money laundering rules that prohibit us from disclosing details of a report made to an authority.
Legal basis: LGPD, arts. 6º, VI, and 20 · Lei nº 9.613/1998, arts. 10 and 11 · Portaria SPA/MF nº 1.143/2024 · Portaria SPA/MF nº 1.231/2024 (responsible gambling)
9. Sharing with public authorities
We share data with public authorities where the regulation so requires or where there is a legitimate request. We do not ask for your authorisation to do so, because compliance with the law cannot be made conditional on the data subject consent — but we state here, in advance, who we share with and for what:
Whenever the law allows us to tell you about a request, we tell you. In anti-money laundering matters, however, the regulation itself prohibits us from notifying the person concerned of a report, and we comply with that prohibition.
- Secretaria de Prêmios e Apostas of the Ministério da Fazenda (SPA/MF): periodic transmission of information on bettors, bets, movements and wallets to the supervisory system, and supervisory access when required.
- Conselho de Controle de Atividades Financeiras (COAF): reporting of suspicious transactions and of transactions subject to mandatory reporting, within the deadlines set by the regulation.
- Secretaria Especial da Receita Federal do Brasil: tax information, withholdings and prizes paid.
- Autoridade Nacional de Proteção de Dados (ANPD): notification of security incidents and responses to requests.
- The Judiciary, the Public Prosecution Service and police authorities: upon court order, formal request, or in the cases provided for by law.
- Bodies and entities responsible for betting integrity, where there is evidence of result manipulation, within the required deadlines.
Legal basis: LGPD, art. 7º, II and VI, and art. 23 · Lei nº 9.613/1998, arts. 10 and 11 · Lei nº 14.790/2023, arts. 23 to 25 · Portaria SPA/MF nº 722/2024 (transmission and supervision) · Portaria SPA/MF nº 1.143/2024
10. Processors and partners that handle data on our behalf
Part of the operation depends on suppliers. They process data on our behalf, under a written contract requiring them to follow our instructions, adopt security measures, refrain from using the data for their own purposes, and delete it when the service ends. These are the categories:
We do not sell your personal data and we do not release it to third parties for their own advertising. The up-to-date list of categories of recipients and, on request, the identity of the entities we share your data with are provided through the DPO channel.
If the operation is ever transferred — through corporate reorganisation, assignment of the authorisation, or sale of assets — the data may be transferred to the successor, which will be bound by this Policy and by the same regulation. You will be informed.
- Providers of identity verification, liveness proof, and restricted-list and politically exposed person screening.
- Payment institutions and payment service providers, to process deposits and withdrawals through authorised methods.
- Infrastructure, hosting and backup providers, with a data centre located in Brazil.
- Game and platform system suppliers, and certification bodies recognised by the SPA/MF.
- Anti-fraud, transaction monitoring and cybersecurity tools.
- Customer support, telephony, messaging and email delivery platforms.
- Independent auditors and lawyers, where necessary to comply with a legal obligation or to defend rights.
Legal basis: LGPD, arts. 5º, VII, 18, VII, 39 and 42 · Portaria SPA/MF nº 722/2024 (information security and data centre) · Portaria SPA/MF nº 1.231/2024, arts. 39 and 40 (confidentiality and liability) · Portaria MF/SPA nº 300/2024 (certification bodies)
11. International data transfers
The operation is hosted in Brazil. Even so, some support, security and customer service suppliers may be based abroad or may access data from another country, which constitutes an international transfer.
We transfer only where a safeguard exists: a country or body with an adequate level of protection recognised by the ANPD, standard contractual clauses approved by the ANPD, specific contractual clauses, binding corporate rules, or another applicable legal ground. Where none of those grounds applies, we do not transfer.
No international transfer relieves us of the duty to keep in Brazil, available to the supervisor, the betting and bettor records required by the regulation.
You may ask the DPO which countries your data is transferred to and under which safeguard.
Legal basis: LGPD, arts. 33, 34 and 35 · Resolução CD/ANPD nº 19/2024 (international transfers and standard contractual clauses) · Portaria SPA/MF nº 722/2024
12. How long we keep your data
We keep your data for as long as it is needed for the purposes set out in this Policy and, after that, for the period the regulation requires.
The general period is 5 (five) years from the end of the relationship — closing your account, permanent self-exclusion, or the last movement, whichever occurs last. That period is not a choice of ours: it derives from the duty to keep registration, gameplay and financial records available to the SPA/MF and to the anti-money laundering authorities.
Longer periods may apply where there are administrative, judicial or arbitral proceedings under way, an ongoing investigation, or a specific tax duty. In those cases we keep only what is necessary, and only until the reason for keeping it ends.
Once the period ends, data is deleted or irreversibly anonymised. Asking to close your account does not erase everything immediately: it erases what can be erased and keeps, under restricted access, what the law requires us to retain. We would rather say this plainly than promise an “erase everything” we could not deliver.
Legal basis: LGPD, arts. 15, 16 and 18, VI · Portaria SPA/MF nº 1.207/2024, art. 10 (records kept available to the regulator) · Portaria SPA/MF nº 1.143/2024 · Lei nº 9.613/1998, art. 10 · Lei nº 12.965/2014 (Brazilian Internet Civil Framework), art. 15 (application access logs)
13. Your rights as a data subject and how to exercise them
The LGPD grants you rights that you exercise directly with us, free of charge and as many times as you need:
To exercise any of them, write to [to be provided] from your registered email address or use the privacy area of your account. We may ask for additional information to confirm that it is really you making the request — not to make things difficult, but because handing your data to someone impersonating you would be the worst possible outcome.
We respond to requests to confirm the existence of processing and to access requests in simplified form immediately and, in full form, within 15 (fifteen) days of your request. Other requests are answered within a reasonable period and as quickly as possible. Where we cannot comply, we say why, citing the rule that obliges us to retain the data or the grounds for the refusal.
- Confirm whether we process data about you and access that data.
- Correct incomplete, inaccurate or out-of-date data.
- Request anonymisation, blocking or deletion of unnecessary or excessive data, or data processed in breach of the law.
- Request portability of your data to another service provider, subject to commercial and industrial secrecy.
- Request deletion of data processed on the basis of your consent, except where retention is mandatory.
- Find out which public and private entities we share your data with.
- Be informed that you may withhold consent, and of the consequences of doing so.
- Withdraw consent at any time.
- Request a review of decisions taken solely on the basis of automated processing that affect your interests.
Legal basis: LGPD, arts. 9º, 18, 19 and 20 · Resolução CD/ANPD nº 18/2024
14. Information security and incidents
We adopt technical and administrative measures to protect your data from unauthorised access and from accidental or unlawful destruction, loss, alteration, communication or dissemination. Among them:
No system is immune. If a security incident occurs that may create relevant risk or harm to you, we notify the ANPD and you within the period set by the authority regulation — currently 3 (three) business days from becoming aware of the incident — stating the nature of the data affected, the data subjects involved, the technical protection measures in place, the risks identified, and what we are doing to reverse or mitigate the effects.
Relevant incidents are also reported to the SPA/MF, in line with the information security obligations applicable to the operator. If you suspect unauthorised access to your account, write immediately to [to be provided] and to [to be provided].
- Encryption in transit (TLS) across all traffic, and encrypted backups held off the server. Encryption at rest for the database is being rolled out, and we do not claim here what we have not yet done.
- Role-based access control on a least-privilege basis, with a record of who accessed what.
- Authentication with an alphanumeric password requiring special characters, plus additional verification for sensitive operations.
- Hosting in a data centre located in Brazil, with a supplier holding ISO/IEC 27001 certification.
- Event logging and a non-rewritable audit trail for account operations, bets and financial movements.
- Daily backups, verified, retained for seven days and four weeks, plus a recovery plan.
- A duty of confidentiality binding our staff and our suppliers, with contractual liability for breach.
Legal basis: LGPD, arts. 6º, VII and VIII, 46, 47 and 48 · Resolução CD/ANPD nº 15/2024 (security incident notification) · Portaria SPA/MF nº 722/2024 (information security and data centre) · Portaria SPA/MF nº 1.231/2024, arts. 39 and 40
15. Cookies and similar technologies
We use cookies and similar technologies to keep your session open, remember your preferences, measure site performance, and support security and fraud prevention.
Cookies strictly necessary for operation and security do not depend on consent. Analytics and advertising cookies do, and you control them in the cookie preferences panel, which can be reopened at any time from the footer of jogodobicho.com.
The description of each cookie, its purpose and its lifetime are set out in the Cookie Policy, which forms part of this Policy and must be read together with it.
Legal basis: LGPD, arts. 7º, I and IX, and 9º · Lei nº 12.965/2014 (Brazilian Internet Civil Framework), arts. 7º and 15
16. Effective date, changes and how to complain
This is version 1.0 of this Policy, in force since 5 August 2026. Each version is identified by number and date, and earlier versions remain available for consultation — without that, it would be impossible to know which text you agreed to.
We may change this Policy when the regulation, the operation or the technology changes. Material changes are announced with reasonable notice to your registered email address and by notice on the site. Where a change depends on your consent, we ask for fresh consent: we do not presume the old one.
If you do not agree with a new version, you may close your account and withdraw your available balance, subject to the verification rules and the deadlines set out in the Terms of Use.
If something is not resolved properly, speak first with the DPO at [to be provided] and, if you are still not satisfied, with the Ombudsman at [to be provided]. You may also petition the ANPD — which considers data subject petitions against a controller once the unresolved complaint to us has been evidenced — and complain to the consumer protection bodies, which do not require that prior step.
Legal basis: LGPD, arts. 18, § 1º, 41, § 2º, II, and 55-J, IV · Lei nº 8.078/1990 (Consumer Protection Code), art. 31 · Portaria SPA/MF nº 1.231/2024 (customer service and ombudsman)