Last updated: June 8, 2026
Privacy Policy
Notice under arts. 13 and 14 of Regulation (EU) 2016/679 (GDPR) and Legislative Decree 196/2003 as amended by Legislative Decree 101/2018.
This English version is provided for convenience only. The Italian version is the sole legally binding text under Italian law.
1. Data controller
The data controller is Led-Web, with registered office in Pradamano, Udine, Italy, reachable at info@led-web.net.
Data Protection Officer (DPO): where appointed, reachable at dpo@tipos.pro.
2. Categories of processed data
- Registration data: name, email, password (hashed), date of birth.
- Profile data: avatar, nickname, preferences.
- Operational data: bets entered, bookmaker wallets, amounts, sports events, markets, outcomes, analytics.
- Uploaded images: photos of scanned slips (processed by AI models for structured data extraction).
- Payment data: handled by a PCI-DSS certified payment processor; TipOS only receives the transaction outcome and the last 4 digits of the card.
- Technical data: IP address, user agent, access logs, session identifiers, anonymised telemetry.
- Cookies: see section 8.
3. Purposes and legal bases
- Service delivery — contract performance (art. 6(1)(b) GDPR).
- Subscriptions and billing — contract + legal obligations (art. 6(1)(b, c)).
- Customer support — contract performance (art. 6(1)(b)).
- Security, anti-fraud, abuse prevention — legitimate interest (art. 6(1)(f)).
- Tax and accounting obligations — legal obligation (art. 6(1)(c)).
- Newsletter and direct marketing — consent (art. 6(1)(a)), revocable at any time.
4. Processing methods
Data are processed with electronic tools, in a lawful, fair and transparent manner, adopting technical and organisational measures adequate to guarantee an appropriate security level (art. 32 GDPR): encryption in transit (TLS) and at rest, access control, periodic backups, password hashing.
5. Recipients
Data may be shared, within the purposes above, with:
- Hosting and cloud infrastructure providers (EU-based servers);
- PCI-DSS certified payment processors;
- AI service providers for slip processing (under art. 28 GDPR DPAs);
- Transactional email and customer support services;
- Consultants, accountants, lawyers where necessary;
- Competent authorities where required by law.
An up-to-date list of Processors is available on request at privacy@tipos.pro.
6. Extra-EU data transfers
Where some providers (e.g. AI services) process data outside the European Economic Area, transfers occur under adequate safeguards pursuant to arts. 44–49 GDPR: EU Commission adequacy decisions or Standard Contractual Clauses (SCC) supplemented by additional measures.
7. Retention period
- Account and operational data: for the entire subscription duration and for 30 days after closure, then deleted or anonymised.
- Billing data: 10 years as per Italian tax law.
- Security logs: 12 months maximum.
- Slip images: deleted within 30 days from AI processing, unless the user opts to retain them.
- Marketing data: until consent withdrawal.
8. Cookies and similar technologies
We use technical cookies necessary for the Service (exempt from consent under art. 122 Legislative Decree 196/2003) and, subject to consent via a banner compliant with the Italian DPA guidelines of 10 June 2021, analytics and third-party cookies. You can change preferences at any time from the "Cookie preferences" link at the bottom of the site.
9. Data subject rights
Under arts. 15–22 GDPR you have the right to:
- Access your personal data;
- Request rectification or erasure;
- Obtain restriction of processing;
- Object to processing based on legitimate interest or marketing;
- Receive data in a structured format (portability);
- Withdraw consent at any time, without prejudice to the lawfulness of previous processing;
- Not to be subject to automated decisions with significant effects.
Exercise your rights by writing to privacy@tipos.pro. We reply within 30 days.
10. Complaints to the supervisory authority
You have the right to lodge a complaint with the Italian Data Protection Authority (Piazza Venezia 11, 00187 Rome — garante@gpdp.it) or the EU supervisory authority of your residence.
11. Minors
The Service is reserved to adults. We do not knowingly collect data from users under 18. Upon report, such data will be deleted without delay.
12. Notice changes
We may update this notice. Changes will be published on this page with the update date and, for material changes, communicated via email or in-app notice.