LEGAL REFERENCE

How batu128 Handles Your Account Data

This is the batu128 privacy policy in plain language. We wrote it so you can see, before you open an account, exactly what we collect, why we keep...

Data handlingAccount privacyCookies disclosedIndonesia scopeLast updated 2024
batu128 How batu128 Handles Your Account Data

Our Privacy Posture and Scope

Service availability is jurisdiction-dependent. Users are responsible for checking local law before access.

SUPPORT

Privacy Contact Paths

If you have a question about your data, reach us through any of the channels below. Our privacy desk handles access requests, deletion requests and consent changes separately from general account support.

Team online

Privacy Inbox

Email our data team directly for access requests, corrections or deletion. We acknowledge within one business day and resolve within the window set by Indonesian data rules where they apply.

In-Account Form

Once you're signed in, the privacy form sits inside your account settings. Submit consent changes, opt out of marketing messages, or download a copy of your stored records straight from there.

Live Chat Escalation

Live chat agents can route privacy questions to the dedicated reviewer on shift. Ask for the data officer and your ticket is flagged for a written response from our compliance team.

REVIEW SIGNALS

How This Policy Is Maintained

We review this document on a fixed cadence so the wording matches what actually happens behind your account.

Quarterly Review

Our legal and product teams sit down every quarter to walk through this policy line by line, checking that each clause still matches the data flows running in our live environment.

Version History

Every change to this policy is logged with a date and a short note describing what shifted. You can ask the privacy desk for the previous version if you want to compare wording.

Named Reviewer

A named data protection lead signs off on each revision. That person, not an anonymous committee, is accountable for the language you read on this page right now.

External Counsel

We brief outside Indonesian counsel before publishing material changes. Their notes shape how we describe retention, consent and cross-border processing in the sections above.

Plain Language Pass

After legal sign-off, an editor rewrites dense clauses into language you can read on a phone. Nothing is removed — the meaning stays, the sentences get shorter.

Reader Feedback

If you flag a passage that reads ambiguous, we log it. Repeated questions on the same clause trigger a rewrite in the next review cycle rather than waiting a full year.

Consistent Across Our Policy Pages

This privacy policy lines up with our other legal pages so you don't have to chase contradictions across the site.

Terms of ServiceDefinitions of account, session and transaction used here match the Terms exactly, so a word means the same thing whichever legal page you opened first.
Cookie NoticeThe cookie categories named below mirror the toggles in our cookie banner. If you change a setting there, the description here stays accurate.
KYC StatementIdentity documents collected for verification are described identically on the KYC page and in the data categories listed within this policy.
Retention ScheduleTime windows for keeping logs, financial records and closed-account data are written the same way across the retention schedule and this document.
Marketing ConsentOpt-in and opt-out wording for promotional messages matches the consent panel in your account settings, with no extra clauses hidden here.
Complaints PageThe escalation path for a privacy complaint is the same path described on our complaints page, ending at the same named reviewer.
Regional NoticesWhere Indonesian rules add a clause, that clause appears verbatim on both the regional notice page and inside the relevant section of this policy.

What This Policy Page Shows You

The layout here is built around clarity, not marketing. Each block below points to a fixed element you'll find on this page every time you visit.

Data Categories

A labelled list of every category we collect: identifiers, device data, session logs, transaction references. Each category has a one-line purpose attached so you read intent next to data.

Retention Windows

Plain numbers for how long each category stays on file. No vague phrases like 'as needed' — actual months and years, tied to the legal duty that requires them.

Your Rights Panel

A panel listing the rights you can exercise: access, correction, erasure, portability, objection. Each right links to the form or contact that triggers it inside your account.

Third-Party Processors

A short, named list of processors we share data with for payment routing, fraud checks and hosting. You see who, for what, and the country they operate from.

Change Log

A dated change log sits near the bottom so you can scan what moved since your last visit. New clauses are marked, removed clauses are noted in strikethrough.

Last Reviewed Stamp

A timestamp at the top tells you when a human last walked this document. If that date is older than a quarter, you're looking at a draft waiting for the next review.

Privacy Questions We Hear Often

We collect your name, contact details, date of birth and identity document during sign-up. Once you're active, we also log device data, session times and transaction references tied to deposits or withdrawals you make.

Only the minimum needed to settle a transaction. When you fund via DANA, OVO, GoPay or QRIS, the wallet sees the reference and amount. They don't receive your gameplay history or your wider account profile.

Active account data stays while your account is open. After closure, financial and verification records are retained for the period Indonesian gaming and anti-fraud rules require, typically five years, then scheduled for secure deletion.

Yes. Submit a deletion request through the in-account privacy form or our privacy inbox. We'll erase what we can immediately and explain which records must be held longer to meet legal retention duties.

We use session cookies to keep you signed in and analytics cookies to see which lobby areas need fixing. You control non-essential cookies through the banner on first visit and the settings panel afterwards.

Some hosting and fraud-check processors operate from regional data centres outside Indonesia. Transfers happen under contractual safeguards listed in the third-party processors section, and only where local law permits the routing.

Material changes trigger an in-account notice the next time you sign in. Smaller edits appear in the change log with a date. The last-reviewed stamp at the top always reflects the most recent walkthrough.