Universal Poker Logo

Privacy Policy

Last updated: 7 July 2026

Quick navigation

Jump directly to a section for faster review.

1. INTRODUCTION

This Privacy Policy (Part B) explains how we collect, use, share, and protect your personal data when you use the Platform, in accordance with the UK GDPR and the Data Protection Act 2018. It should be read together with Part A (Terms & Conditions) and Part C (Cookie Policy).

This Privacy Policy applies to both companies that operate the Platform: Universal Affiliates Limited and CMA Solutions Limited. Section 2 explains which of the two companies is responsible for your personal data.

We process personal data only to the extent necessary to support fairness, transparency, user protection, fraud prevention, and legal/regulatory compliance.

2. DATA CONTROLLER

The Data Controller responsible for your personal data depends on which entity is your Contracting Party for the relevant Partner Offer or activity, determined in the same way as under Part A, Clause 1.2:

Universal Affiliates Limited (Company No. 11667550) is the Data Controller for your account-level data (e.g. login credentials, profile, general support), and for any data relating to a Partner Offer for which it is designated as the Contracting Party under Part A, Clause 1.2. This designation is made per Partner Operator, and is not automatically determined by whether that operator is a GB Licensed Operator or an International Operator.

CMA Solutions Limited (Company No. 16824488) is the Data Controller for any data relating to a Partner Offer for which it is designated as the Contracting Party under Part A, Clause 1.2. This designation is made per Partner Operator, and is not automatically determined by whether that operator is a GB Licensed Operator or an International Operator.

The identity of your Data Controller for a specific Partner Offer is disclosed to you before you apply for it, in the same way as your Contracting Party is disclosed under Part A, Clause 1.2. Which Partner Offers are available to you at all is a separate matter governed by Geo-Blocking (Part A, Clauses 1.4, 1.6, 1.7 and 9) — for example, if you are resident in the United Kingdom, the Platform only presents Partner Offers relating to GB Licensed Operators to you — but this availability rule does not, of itself, determine which company is your Data Controller for those offers.

Both companies are separate, independently responsible legal entities under common ultimate ownership, registered at the same address below, and both apply the identical UK GDPR standards set out in this Privacy Policy regardless of which one is your Data Controller. In this Privacy Policy, we refer to Universal Affiliates Limited and CMA Solutions Limited together as "the Companies" purely as drafting shorthand for convenience. This does not create, imply, or evidence a "group" as defined by the Companies Act 2006, a holding/subsidiary relationship, a joint venture, or joint and several liability between the two companies — see Part A, Clause 1.3 for further detail on their corporate separateness.

Universal Poker is the shared trading name used by Universal Affiliates Limited and CMA Solutions Limited to operate the Platform.

Sutherland House, 1759 London Road, Leigh-on-Sea, Essex, SS9 2RZ (registered office of both companies)

Contact for all privacy and data protection queries: contact@universalpoker.com. If you know which company's services your query relates to, please mention it to help us route your request, though this is not required.

Neither company has appointed a Data Protection Officer (DPO), as neither meets the thresholds requiring mandatory DPO appointment under the UK GDPR (Article 37). The contact point for all data protection matters for either company is the address and email above.

We keep this DPO-threshold assessment under review as either company's processing activities evolve, and would appoint a DPO for either or both companies if it became required.

We may record acceptance events for compliance/evidential purposes, including the specific Partner Operator and Partner Offer applied for, which determines your Data Controller under this Section 2.

3. THE DATA WE COLLECT & HOW WE USE IT

You are not required to provide all data, but without certain data some features cannot function.

A) Account creation (mandatory)

  • Data: email, encrypted password, declared country, identifiers/timestamps, and optional profile/contact fields you choose to provide (e.g., full name, Discord ID, Telegram).
  • Purpose: account creation and security, operational service delivery, account administration/support, and compliance controls including legal eligibility verification by jurisdiction, and determining which of the Companies (Universal Affiliates Limited or CMA Solutions Limited) is your Data Controller as described in Section 2
  • Lawful basis: Contract; Legitimate interests (security/compliance)

B) Apply for deal / reactivation (optional)

  • Data: operator username (and where needed operator-registered email), application metadata/status logs
  • Purpose: process and operationally manage your request; liaise with operators/affiliate systems
  • Lawful basis: Contract (or Consent where a specific feature requires it)

C) Dashboard / performance

  • Data: rake generated (including provisional or estimated values where operator reporting is pending), reward estimates, deal status
  • Purpose: provide dashboard reporting
  • Lawful basis: Contract Performance (Art. 6(1)(b)) — displaying performance data in your dashboard is part of the contracted service. You may control this as a personal display preference via account settings.
  • Note: Dashboard values are sourced from Partner Operator reporting channels and may be delayed, reconciled, or adjusted retroactively

D) Referrers (commission verification only)

  • Data shared: masked identifiers/alias + aggregated metrics
  • Not shared: name/email/address/password
  • Purpose: commission verification; disputes; audit trail
  • Lawful basis: Legitimate Interests (UK GDPR Art. 6(1)(f)) — necessary for transparent commission verification and the commercial operation of the Platform. A Legitimate Interests Assessment (LIA) has been conducted and is available on request.
  • Right to object: you may object at any time via Account Settings or by emailing contact@universalpoker.com. If you object, we will suppress non-essential dashboard or platform visibility to the Referrer where technically available. Strictly limited masked reporting may continue where necessary for commission calculation and verification (masked site username or platform identifier, relevant site/operator, gross rake, net rake and deal/application status only). No real name, email, address, password or unmasked identifier will be shared.
  • Removing your objection: if you remove your objection, reporting resumes on a forward-looking basis only from the date the objection was removed — no historic data from the objection period is retroactively shared

E) Support

  • Data: contact details, messages, account identifiers, diagnostics/security logs
  • Purpose: support/enforcement/abuse prevention
  • Lawful basis: Contract; Legitimate interests

F) Technical/security/anti-abuse (always-on)

  • Data: device/browser, login events, IP-derived location signals, account and identity-related information where available, security logs, fraud indicators, geo-blocking signals (incl. VPN/proxy indicators)
  • Purpose: security, legal age and eligibility checks by jurisdiction, fraud prevention, anti-money-laundering compliance support, social responsibility safeguards, geo-blocking enforcement, and restricting access from prohibited or high-risk jurisdictions where required
  • Lawful basis: Legitimate interests; Legal obligation where applicable

4. LEGITIMATE INTERESTS (TRANSPARENCY)

We use legitimate interests for Platform security, fraud prevention, compliance controls, and referrer-visible reporting for commission verification. Where we rely on legitimate interests, we apply safeguards such as data minimisation, access controls, and pseudonymisation/masking. You have the right to object to legitimate interests processing — see Section 3D above for details.

5. PARTNER OPERATORS

Partner Operators are independent third parties. If you use their services, they process your data under their own privacy policies and terms. We do not control their KYC decisions, gameplay, or payments/rewards.

6. MARKETING & COMMUNICATIONS

We send marketing emails only where you have opted in (or where permitted). You can unsubscribe at any time. We may use an email provider (e.g., Brevo). If email analytics/tracking is enabled, we use consent controls where required by law. We maintain opt-in/opt-out controls and suppression handling for marketing communications. Where applicable to our services, marketing and promotional activity is operated in alignment with the Gambling Commission's Licence Conditions and Codes of Practice (LCCP), the CAP Code, and ASA advertising rules.

7. COOKIES & ANALYTICS

We use strictly necessary cookies (e.g. for authentication and security). Where analytics or marketing cookies are enabled (including GA4), we use a cookie consent mechanism and only load non-essential cookies after you have given consent where required by law.

You can manage or withdraw cookie consent at any time via Cookie Settings on the Platform. For full details, see our Cookie Policy at /cookie-policy. This Privacy Policy (Part B) should be read together with our Terms & Conditions (Part A) and Cookie Policy (Part C).

8. INTERNATIONAL TRANSFERS

While both companies are UK-based, our technical infrastructure is global. Your data may be processed outside the UK — in particular, our primary database (Supabase) is hosted in the United States (AWS US East, Northern Virginia).

Where transfers occur, we rely on the UK International Data Transfer Addendum (UK IDTA) and/or the UK Addendum to the EU Standard Contractual Clauses (SCCs), incorporated into our providers' Data Processing Addenda, which contractually bind them to protect your data to UK standards. Section 9 below lists the specific safeguards used for each service provider.

This applies identically regardless of whether Universal Affiliates Limited or CMA Solutions Limited is your Data Controller: both companies use the same technical infrastructure and the same transfer safeguards.

We monitor regulatory guidance from the ICO on international transfers and will review our safeguards and contracts if adequacy decisions, SCCs, or the UK IDTA framework change.

9. WHO WE SHARE DATA WITH

We do not sell your personal data. We may share it only as described below.

The service providers listed below process personal data on behalf of whichever of the Companies is your Data Controller under Section 2. Both companies use the same providers and the same safeguards, regardless of which one is your Data Controller.

Service Providers (Data Processors)

  • Supabase Inc. — database and authentication provider. Servers located in East US (Northern Virginia, USA). Transfers are covered by Supabase's executed Data Processing Addendum (DPA), incorporating the UK Addendum (B.1.0) to the EU Standard Contractual Clauses, enforceable under the UK Data Protection Act 2018. Data processed: account data, authentication records, application data, consent logs, and security logs.
  • Brevo SAS — transactional and marketing email delivery. Data may be processed in the EU and USA. Transfers are covered by Brevo's DPA incorporating applicable Standard Contractual Clauses. Data processed: email address, full name (where provided), and country.
  • Vercel Inc. — hosting and infrastructure. Servers located in the USA. Transfers are covered by Vercel's DPA incorporating applicable Standard Contractual Clauses. Data processed: request metadata, IP-derived signals, and access logs.
  • Google LLC (Google Analytics 4, when enabled) — website analytics. Servers located in the USA. Transfers are covered by Google's DPA incorporating applicable Standard Contractual Clauses. Data processed: anonymised/pseudonymised device and browser information, page view and interaction events. IP addresses are anonymised before storage where technically possible.

Referrers / Sub-Affiliates

  • We may share limited, masked reporting data (masked alias and aggregated metrics only) with the Referrer who introduced you to the Platform, solely for commission calculation, verification, and related audit purposes. No name, email, address, or password is shared. This processing is carried out on the basis of our Legitimate Interests (UK GDPR Art. 6(1)(f)). You have the right to object at any time via Account Settings or by emailing contact@universalpoker.com. If you object, we will suppress non-essential dashboard or platform visibility to the Referrer where technically available. Strictly limited masked reporting may continue where necessary for commission calculation and verification (masked site username or platform identifier, relevant site/operator, gross rake, net rake and deal/application status only). No real name, email address, postal address, password or unmasked identifier will be shared. If you later remove your objection, reporting will resume on a forward-looking basis only and no historic data from the objection period will be shared retroactively.
  • If we remove a player from a Referrer (e.g., at our discretion for compliance, fraud prevention, or enforcement of our Terms, or at the Referrer's or player's request), that Referrer immediately and permanently loses visibility of that player's data, including all historic reporting, on their dashboard. We retain our own records of the former relationship for accounting and audit purposes in line with Section 10 below.

Partner Operators

  • Where you apply for a deal, we share your operator username (and where needed operator-registered email) plus application-related identifiers and status updates with the relevant Partner Operator and/or their affiliate tracking system, to the extent necessary to process and track your application.

Self-Exclusion Compliance Handling

  • If we are notified that you are self-excluded with a Partner Operator or through a multi-operator scheme (e.g. GAMSTOP), we process relevant data to remove you from our active marketing database, suppress marketing communications to you, and close your account on our Platform, retaining only such records as required for compliance and as described in this Privacy Policy.
  • We do not reverse or override self-exclusion decisions made by Partner Operators or GAMSTOP.

Authorities and Professional Advisers

  • We may share data with regulators (including the ICO), law enforcement agencies, courts, or professional advisers where required by law, court order, or for the purposes of fraud prevention, compliance, or the establishment, exercise, or defence of legal claims.

10. DATA RETENTION

We retain data only as needed for the purposes above, compliance, fraud prevention, dispute handling, and legal requirements. Typical retention:

For retention purposes, relationship end date means the date your Platform account is closed, terminated, disabled, or otherwise moved into a terminal status.

These retention periods apply identically regardless of whether Universal Affiliates Limited or CMA Solutions Limited is your Data Controller.

  • Account/profile/auth data: active + normally up to 5 years after relationship end date
  • AML/compliance and customer due diligence records: normally 5 years from the later of (a) relationship end date or (b) transaction completion date. In specific cases where required by applicable law, regulation, legal hold, or regulator request, retention may be extended up to the applicable statutory maximum (up to 10 years).
  • Deal/application and dashboard/performance records: normally up to 5 years after relationship end date
  • Referrer reporting records: normally up to 5 years after relationship end date
  • Support (including support mailbox records in Gmail): typically up to 3 years from ticket closure, subject to mailbox administration capabilities and legal requirements
  • Security/anti-abuse logs: typically 12-24 months
  • Consent/compliance logs: normally up to 5 years unless a longer legal retention duty applies
  • Marketing preferences: while subscribed; suppression as needed to ensure no re-contact

11. YOUR RIGHTS

Under UK GDPR and the Data Protection Act 2018, you may have the following rights: access to your personal data; rectification of inaccurate data; erasure ('right to be forgotten') where legally applicable; restriction of processing; objection to processing (including direct marketing); data portability; and withdrawal of consent at any time where processing is consent-based. Withdrawal does not affect the lawfulness of processing carried out before withdrawal.

How to exercise your rights: Submit a request by email to contact@universalpoker.com, clearly stating your name, the email address linked to your account, and the specific right(s) you wish to exercise. You do not need to know which company is your Data Controller to submit a request — we will identify the correct company under Section 2 and respond accordingly. We may ask you to verify your identity before processing your request. We will respond within one calendar month of receipt. For complex or multiple requests, we may extend this by a further two months and will notify you accordingly.

If your country of residence changes, request an account-country update by contacting contact@universalpoker.com from your registered account email. A country of residence change may affect which Partner Offers are available to you going forward (see Part A, Clause 1.4); it does not, of itself, change your Data Controller for your account-level data or for any specific Partner Offer, which remains determined under Section 2 / Part A, Clause 1.2 for that specific offer. We may request reasonable verification information to protect account security and compliance, and we may temporarily restrict access to affected offers until verification is completed and records are updated.

Right to complain: If you are not satisfied with how we handle your data or your request, you have the right to lodge a complaint with the Information Commissioner's Office (ICO) at www.ico.org.uk or by calling 0303 123 1113. We would, however, appreciate the opportunity to address your concerns before you contact the ICO.

12. SECURITY

We use reasonable technical and organisational measures including access controls, least privilege, encryption in transit and at rest, secure credential handling, regular access reviews, monitoring, and anti-abuse processes.

Both companies rely on the same technical infrastructure and security controls described in Section 9, ensuring a consistent standard of protection for your data regardless of whether Universal Affiliates Limited or CMA Solutions Limited is your Data Controller.

13. PERSONAL DATA BREACHES

If a personal data breach occurs, we assess it promptly. Where the breach is likely to result in a risk to your rights and freedoms, the affected company (Universal Affiliates Limited or CMA Solutions Limited, as your Data Controller under Section 2) notifies the ICO without undue delay and, where feasible, within 72 hours of becoming aware of it, in accordance with UK GDPR Article 33. Where the breach is likely to result in a high risk to your rights and freedoms, we also notify you directly without undue delay, in accordance with UK GDPR Article 34.

Because both companies share the same technical infrastructure (Section 9), we investigate suspected breaches jointly where relevant, but the company that is your Data Controller remains responsible for assessing and, where required, notifying regulators and you about a breach affecting your data.

Where relevant to gambling regulatory obligations, we also notify the Gambling Commission.

14. CONTACT

Please use the single contact point below for any privacy or data protection query, regardless of which company is your Data Controller under Section 2 — we will identify the correct company and route your query accordingly.

  • Universal Affiliates Limited (Company No. 11667550) — Data Controller for account-level data and for any Partner Offer for which it is designated as the Contracting Party under Part A, Clause 1.2
  • CMA Solutions Limited (Company No. 16824488) — Data Controller for any Partner Offer for which it is designated as the Contracting Party under Part A, Clause 1.2
  • Email (for either company): contact@universalpoker.com
  • Address (registered office of both companies): Sutherland House, 1759 London Road, Leigh-on-Sea, Essex, SS9 2RZ

15. CHANGES

We may amend this Privacy Policy at any time for legal, regulatory, compliance, security, operational, or service-related reasons.

Unless stated otherwise, updates take effect when posted. We will publish the latest version and update the "Last updated" date.

Where required by our legal-consent framework, continued use of the Platform may be conditional on explicit re-acknowledgement of the latest legal documents. If you do not agree with an update, you must stop using the Platform.

Important Notice

Please review this policy periodically. We may require explicit re-acknowledgement of updated legal documents before continued Platform access.