This Privacy Policy describes how ISocial Sports Private Limited ("BeBetta", "we", "our", "us"), a company incorporated under the laws of India with its registered office at BVR Ek, Opposite Inder Residency, Ellisbridge, Ahmedabad, Gujarat – 380006, India, collects, uses, stores, shares, transfers, and erases your personal data when you use the BeBetta mobile application, the website www.bebetta.in, and associated services (collectively, the "Platform").

BeBetta acts as a Data Fiduciary under the Digital Personal Data Protection Act, 2023 ("DPDP Act") and the Digital Personal Data Protection Rules, 2025 ("DPDP Rules"), and, where applicable to users in the European Union / European Economic Area or the United Kingdom, as a Data Controller under Regulation (EU) 2016/679 ("GDPR") and the UK GDPR.

This Policy also serves as the notice required under Section 5 of the DPDP Act. It is designed to be understandable independently of any other document. You may access this notice, and every request for consent we make, in English or in any language specified in the Eighth Schedule to the Constitution of India. To request a copy in another language, use the in-app language selector or write to our Data Protection Officer at the contact details in Section 16.

1. Scope and Applicability

This Privacy Policy applies to:

This Policy is governed by and drafted to comply with the DPDP Act, 2023 and the DPDP Rules, 2025, the GDPR (for EU/EEA/UK users), the Information Technology Act, 2000 (to the extent applicable to matters not covered by the DPDP Act), and Google's API Services User Data Policy (for the optional Gmail integration).

2. Key Terms

3. Personal Data We Collect, Purposes, and Legal Bases

In accordance with Section 5(1) of the DPDP Act and Rule 3 of the DPDP Rules, the table below provides an itemised description of each category of personal data we collect, the specific purpose for which it is processed, and the legal basis for that processing under both the DPDP Act and the GDPR. We collect and process only such personal data as is necessary for each specified purpose.

What we do not do: We do not sell personal data in identifiable form. We do not use Google user data for advertising or profiling. We do not process children's personal data for commercial analytics, brand-partner sharing, behavioural monitoring, tracking, or targeted advertising under any circumstances (Section 13).

4. How We Obtain Your Consent

Where consent is our basis for processing, it is obtained in accordance with Section 6(1) of the DPDP Act and Articles 4(11) and 7 of the GDPR: it is free, specific, informed, unconditional, and unambiguous, and given through a clear affirmative action — such as ticking an unticked box or activating a clearly labelled toggle. We never rely on pre-ticked boxes, silence, inactivity, or your mere use of the Platform as consent.

Our consent architecture is granular. At onboarding and within the in-app Privacy Centre, you are presented with separate, individually controllable consents for:

Declining any optional consent will not affect your access to BeBetta's core gaming and rewards features. Each consent request is presented in clear and plain language, is available in English or any Eighth Schedule language, and includes the contact details of our Data Protection Officer.

4.1 Consent Records

We maintain auditable records of every consent given, including what you consented to, when, the version of the notice presented to you, and any subsequent modification or withdrawal. Under Section 6(10) of the DPDP Act, the burden of proving that notice was given and consent obtained rests with us, and our records are maintained accordingly.

4.2 Consent Manager

You may also give, manage, review, or withdraw your consent through a Consent Manager registered with the Data Protection Board of India, once such Consent Managers are operational. We will interoperate with registered Consent Managers as required by the DPDP Rules.

4.3 Fresh Consent for New Purposes

If we propose to process your personal data for a purpose not covered by your existing consents, we will present you with an updated notice and obtain fresh, affirmative consent before the new processing begins. Continued use of the Platform is never treated as consent to a new processing purpose.

5. Withdrawing Your Consent

You may withdraw any consent, in whole or in part, at any time, with the same ease with which you gave it (Section 6(4), DPDP Act; Article 7(3), GDPR). Each consent listed in Section 4 has its own toggle in the in-app Privacy Centre (Profile → Privacy Centre → My Consents). You may also withdraw consent by writing to our DPO, or through a registered Consent Manager.

Upon withdrawal:

6. Receipt Scanning and SMS Parsing — Detailed Disclosure

6.1 Receipt Scanning (Android and iOS)

When you submit a receipt via camera scan, image upload, or QR/barcode scan, our systems use optical character recognition to extract the transaction fields itemised in Section 3, validate the transaction against fraud-detection rules before awarding rewards, and store only the extracted data (the raw image is retained only where required for fraud adjudication, and is deleted once adjudication concludes).

6.2 SMS Transaction Parsing (Android Only)

6.3 Fraud Prevention

We apply automated anomaly detection to flag duplicate, altered, or suspicious receipts; a 72-hour reward hold for new users pending verification; manual review of escalated cases by authorised staff in a logged environment; and configurable thresholds on spend amounts and submission frequency. This processing is necessary to protect the integrity of the rewards programme.

7. Commercial Analytics and Data Sharing — Full Disclosure

A part of BeBetta's business is the generation of aggregated market intelligence — such as category-level consumer spend reports, brand preference indices, and campaign measurement analytics — which BeBetta licenses or sells to third parties. Your transaction data is included in these products only if you have given the separate, opt-in Commercial Analytics consent described in Section 4(b).

7.1 Categories of Recipients

Where you have given the applicable consent, receipt-derived insights may be shared with the following categories of recipients:

Form of sharing: insights shared with these recipients are aggregated and anonymised in accordance with the standard in Section 10.3. We do not share your personal data with these recipients in identifiable form. If any future product were to involve sharing identifiable personal data, it would require a further separate consent naming the recipient category and purpose.

7.2 Other Disclosures

Where personal data we process is likely to be used to make a decision that affects you, or is disclosed to another Data Fiduciary, we ensure its completeness, accuracy, and consistency as required by Section 8(3) of the DPDP Act.

8. International Data Transfers

Your personal data is primarily stored and processed in India. If personal data is transferred outside India, such transfer will comply with Section 16 of the DPDP Act and any Central Government notification restricting transfers to specific countries or territories.

For users in the EU/EEA or UK, any transfer of personal data outside the EEA/UK is made only: (a) to jurisdictions covered by an adequacy decision of the European Commission (or UK equivalent); or (b) subject to appropriate safeguards under Article 46 GDPR, such as Standard Contractual Clauses, together with supplementary measures where necessary. You may obtain a copy of the relevant safeguards by contacting our DPO.

9. Security and Breach Notification

10. Data Retention and Erasure

10.1 Retention Schedule

10.2 Erasure and the Deletion Cascade

Upon your withdrawal of consent, your erasure request, or when the specified purpose is no longer being served (whichever is earlier), we will, unless retention is required by law: (a) erase your personal data from our production systems, analytics platforms, model-training datasets, reporting pipelines, backups (on the next scheduled backup cycle), and archived cohort datasets; and (b) cause every Data Processor to erase the personal data we made available to it, obtaining certification of erasure (Section 8(7), DPDP Act; Article 17 GDPR). Where you do not approach us for the specified purpose or exercise any rights for the period prescribed under the DPDP Rules, the purpose is deemed no longer served and erasure follows automatically; we will notify you at least 48 hours before such erasure so you may retain your account if you wish.

10.3 Anonymisation Standard

Data is treated as anonymised — and therefore outside the scope of this Policy — only where it has been irreversibly transformed such that you can no longer be identified, directly or indirectly, by any means reasonably likely to be used. Pseudonymised data, and aggregated outputs from which individual-level data remains recoverable, remain personal data and are erased as part of the deletion cascade.

11. Your Rights (All Users — DPDP Act)

12. Additional Rights for EU/EEA and UK Users (GDPR)

If you are located in the EU/EEA or the UK, you additionally have the following rights, exercisable free of charge, to which we will respond within one month (extendable by two further months for complex requests, with notice):

13. Children's Data

BeBetta is intended only for individuals aged 18 and above.

14. Cookies and Tracking Technologies

Our website uses cookies for session management and authentication (strictly necessary), and — only with your consent given through the cookie banner — analytics and preference cookies. Non-essential cookies are off by default. You may change your choices at any time via the cookie settings link in the website footer or your browser settings. Declining non-essential cookies does not affect core functionality.

15. Grievance Redressal and Complaints to the Board

Step 1 — Contact us: raise any grievance regarding our obligations or your rights through Privacy Centre → Raise a Grievance, or by writing to the Grievance Officer / DPO at the details in Section 16. We will acknowledge within 48 hours and respond within the period prescribed under the DPDP Rules, and in any event within 30 days.

Step 2 — Data Protection Board of India: if you are not satisfied with our response, or in the case of a personal data breach, you may complain to the Data Protection Board of India in the manner prescribed under the DPDP Act and DPDP Rules, through the Board's digital portal (details are published by the Board and linked in our Privacy Centre). Please note that under Section 13(3) of the DPDP Act, you must first exhaust the grievance redressal opportunity with us before approaching the Board.

EU/EEA/UK users may additionally complain to their supervisory authority as described in Section 12.

16. Data Protection Officer and Contact

We have designated a Data Protection Officer (DPO), based in India, who is the point of contact for all questions, rights requests, and grievances under this Policy:

Data Protection Officer: [Name of DPO — to be designated by the Board of Directors]

Email: dpo@bebetta.in (rights requests and grievances); grievance@bebetta.in (grievance redressal); legal@bebetta.in (legal notices)

Address: ISocial Sports Private Limited, BVR Ek, Opposite Inder Residency, Ellisbridge, Ahmedabad, Gujarat – 380006, India

The business contact information of the DPO is published on our website in accordance with Section 8(9) of the DPDP Act.

17. Changes to This Policy

We may update this Policy to reflect changes in our features, legal requirements, or practices. When we make material changes we will update the version number and "Last Updated" date, notify you by in-app notice and email, and — where a change involves a new or expanded processing purpose — obtain your fresh, affirmative consent before that processing begins. We will never treat your continued use of the Platform as consent to a new processing purpose.