ina77 Privacy Policy

ina77 is committed to protecting the privacy of every member. This Privacy Policy explains precisely what personal data we collect, why we collect it, how we use and protect it, and what rights you hold over your own information.

Effective: 1 January 2026 256-Bit SSL Encrypted Indonesia Market
Summary: ina77 collects only the personal data necessary to operate a safe, compliant, and high-quality gaming platform for Indonesian members. We do not sell your data. We do not share it with advertisers. Access to your data within our organisation is strictly limited to staff with a documented operational need.
Section 1

Definitions

For the purposes of this Privacy Policy, the following terms have the meanings set out below:

  • "ina77", "we", "us", "our" — refers to ina77 and its operating group entities responsible for the processing of personal data in connection with the Platform.
  • "Platform" — the ina77 website at ina77.club, including all sub-pages, member portals, game interfaces, and mobile-optimised views.
  • "Member", "you", "your" — any individual who has registered an account on the Platform or who accesses the Platform as a visitor without a registered account.
  • "Personal Data" — any information that identifies or could reasonably be used to identify a natural person, whether directly (e.g., full name, national identity number) or indirectly (e.g., device fingerprint, session token in conjunction with other data).
  • "Processing" — any operation performed on Personal Data, including collection, recording, storage, retrieval, use, disclosure, transmission, erasure, or destruction.
  • "Data Controller" — the entity that determines the purposes and means of processing Personal Data. ina77 acts as the Data Controller for all Personal Data collected through the Platform.
  • "Third-Party Processor" — an external company engaged by ina77 to process Personal Data on ina77's behalf, under a binding data processing agreement that limits the processor to processing only as directed by ina77.
  • "KYC" — Know Your Customer identity verification procedures, encompassing the collection and review of government-issued identification documents required to verify member identity prior to the processing of withdrawal requests.
  • "Rupiah", "IDR", "Rp" — Indonesian Rupiah, the exclusive transaction currency of the Platform.
Section 2

Data We Collect

ina77 collects Personal Data across the following categories. We apply a data minimisation principle: we collect only what is genuinely necessary for the stated purpose.

Category Examples Mandatory?
Identity Data Full legal name, date of birth, nationality, KTP number or passport number Yes — for KYC verification
Contact Data Email address, Indonesian mobile number (+62 format), registered city or province Yes — for account communication
Financial Data Bank account name and number (BCA, BRI, BNI, Mandiri, etc.), e-wallet identifier (OVO, DANA, GoPay, ShopeePay, LinkAja), transaction history, deposit and withdrawal amounts in Rupiah Yes — for payment processing
Account Data Username, encrypted password hash, account creation timestamp (WIB), login history, session activity logs Yes — for account security
Gaming Activity Data Games played, wagers placed, outcomes, bonus usage, game session durations, responsible gaming tool settings Yes — for regulatory compliance and responsible gaming
Technical Data IP address, device type and OS, browser type and version, screen resolution, time zone (WIB/WITA/WIT), session cookie tokens Yes — for platform security and fraud detection
Communications Data Support chat transcripts, email correspondence with ina77, WhatsApp message logs where initiated by the member Optional — generated by member-initiated contact
KYC Document Data Scanned or photographed copy of government-issued KTP or passport (image file), selfie verification image where required Yes — for withdrawal eligibility

We do not collect special categories of sensitive personal data (as defined under applicable data protection law) — including health data, biometric data used for unique identification, political opinions, or religious beliefs — except where a member voluntarily discloses such information in the context of a responsible gaming assessment or support interaction, and where such disclosure is strictly necessary for providing the requested support.

Section 3

How We Collect Data

ina77 collects Personal Data through three primary channels:

  • Directly from you: when you complete the ina77 registration form, submit KYC documents, make a deposit or withdrawal request, set responsible gaming limits, contact customer support via live chat or WhatsApp, or respond to a platform survey or promotion.
  • Automatically through Platform technology: when you access the Platform, our servers and client-side scripts automatically log Technical Data including your IP address, device identifiers, browser fingerprint, page navigation sequences, session duration, and game interaction events. This data is collected via first-party session cookies and server access logs. See Section 9 for full details of our cookie practices.
  • From regulated third-party sources: we may receive identity verification confirmation signals from our KYC and anti-fraud service providers, and transaction status notifications from payment processing partners (including the banks and e-wallet operators listed in Section 2). We do not purchase data from data brokers or marketing list providers.
Section 5

How We Use Your Data

ina77 uses the Personal Data we collect for the following purposes:

  • Account management: creating, maintaining, and securing your ina77 account; authenticating your identity at login; processing password reset requests; and communicating account-critical notifications such as deposit confirmations, withdrawal status updates, and security alerts.
  • Payment processing: executing Rupiah-denominated deposits and withdrawals via your registered BCA, BRI, BNI, Mandiri, CIMB Niaga, OCBC NISP, BSI, Bank Permata, or e-wallet account; reconciling transaction records; and resolving any payment disputes.
  • KYC and AML compliance: verifying your identity and age prior to enabling withdrawal functionality; screening your name and transaction patterns against applicable sanctions and PEP (politically exposed persons) lists; monitoring transaction sequences for indicators of money laundering or fraud.
  • Responsible gaming: monitoring gaming activity patterns to identify potential problem gambling behaviours; enforcing member-set deposit, loss, and session limits; processing cooling-off and self-exclusion requests; and contacting members proactively where our responsible gaming monitoring flags a concern.
  • Platform security: detecting and investigating suspicious login attempts, session hijacking, multi-accounting, bonus abuse, and automated bot activity; maintaining platform integrity and protecting all members from fraud.
  • Customer support: responding to your enquiries via live chat, WhatsApp, and email; resolving account, payment, and game disputes; maintaining support interaction records for quality assurance and staff training.
  • Analytics and improvement: analysing aggregated, anonymised platform usage data to improve game load performance, navigation design, localisation quality, and customer support response times. This analysis uses de-identified data sets wherever possible.
  • Promotional communications (where you have consented): sending you personalised or general notifications about bonuses, seasonal promotions (including Idul Fitri, Ramadhan, and Indonesian Independence Day campaigns), new game launches, and platform updates.
Section 6

Data Sharing & Disclosure

ina77 does not sell, rent, or trade your Personal Data to any third party. We share Personal Data only in the following strictly defined circumstances:

  • Payment processing partners: we share the minimum necessary financial and identity data with the bank or e-wallet operator required to execute a specific transaction — for example, sharing your registered account name and bank account number with BCA or BRI to process a Rupiah withdrawal. These parties act as independent data controllers for their own regulatory compliance purposes.
  • KYC and identity verification providers: we share identity document data with our contracted KYC verification service provider for the sole purpose of confirming document authenticity and cross-referencing submitted identity details. All such providers operate under binding data processing agreements with ina77.
  • Anti-fraud and AML service providers: we share transactional and behavioural data with contracted anti-fraud and AML screening providers for the purpose of detecting financial crime. These providers do not use the data for any purpose other than the contracted screening service.
  • Hosting and infrastructure providers: our Platform hosting, database, content delivery, and security infrastructure providers may process Technical Data as a necessary consequence of providing their services. All providers are bound by contractual data processing terms restricting use to infrastructure provision only.
  • Regulatory and law enforcement authorities: where ina77 is legally required to disclose Personal Data to a licensing authority, tax authority, financial intelligence unit, or law enforcement agency pursuant to a lawful demand, we will comply with that demand. Where legally permissible, we will notify the affected member of such a disclosure.
  • Corporate transactions: in the event of a merger, acquisition, or asset sale involving ina77, member Personal Data may form part of the transferred assets. Any acquiring entity will be required to honour this Privacy Policy or provide members with advance notice of any material change and an opportunity to close their accounts before the change takes effect.
Confirmed: ina77 has never sold member Personal Data to an advertising network, data broker, or marketing agency. We have no commercial arrangements that involve the sale or rental of member data.
Section 7

International Data Transfers

ina77 operates infrastructure across multiple jurisdictions to ensure platform availability, redundancy, and performance for members accessing the Platform from across Indonesia — including Jakarta, Surabaya, Medan, Bandung, Bali, Yogyakarta, Semarang, and all other regions. As a consequence, your Personal Data may be transferred to and stored on servers located outside of Indonesia.

Where such international transfers occur, ina77 ensures that equivalent data protection standards apply by implementing one or more of the following safeguards: binding contractual clauses with the receiving party that impose data handling obligations no less protective than those required under applicable data protection standards; restricted transfers limited to countries with independently assessed adequate data protection frameworks; or, where neither of the above applies, processing the transfer on the basis of your explicit consent following disclosure of the associated risks.

Members who wish to obtain information about the specific safeguards applied to any international transfer of their Personal Data may submit a request to our Data Protection Officer at the contact details set out in Section 14.

Section 8

Data Retention

ina77 retains Personal Data only for as long as necessary to fulfil the purpose for which it was collected or to comply with applicable legal, regulatory, or licensing obligations. The following general retention periods apply:

Data Category Retention Period Basis
Active account data Duration of account + 5 years post-closure AML/KYC regulatory obligation
Transaction records (deposits/withdrawals) 7 years from transaction date Financial record-keeping obligation
KYC document copies 5 years post account closure AML regulatory obligation
Gaming activity logs 3 years from log creation Licensing obligation; responsible gaming
Support interaction records 3 years from interaction date Legitimate interest; dispute resolution
Technical / server access logs 12 months from log creation Legitimate interest; security monitoring
Self-exclusion records Indefinite (or statutory minimum if longer) Responsible gaming compliance
Marketing consent records Duration of consent + 3 years Demonstration of lawful basis

At the end of the applicable retention period, Personal Data is securely deleted or anonymised in accordance with our internal data destruction procedures. Anonymised or aggregated data sets — from which no individual can be identified — may be retained indefinitely for analytical purposes.

Section 9

Cookies & Tracking Technologies

The ina77 Platform uses first-party cookies and similar tracking technologies to deliver a functional, secure, and personalised experience. We use the following categories of cookies:

  • Strictly necessary cookies: required for the Platform to function. These include session authentication tokens, CSRF protection tokens, and load-balancing cookies. These cannot be disabled without rendering the Platform inoperable.
  • Functional cookies: used to remember your preferences across sessions — such as your preferred language setting, responsible gaming limit configurations, and last-accessed game category. These cookies do not track behaviour across external sites.
  • Analytics cookies: used to collect anonymised usage data — including which pages are visited most frequently, how long members spend in specific game categories, and which navigation paths are most commonly used. This data is used solely to improve Platform design and performance. Analytics data is processed in aggregated, de-identified form.
  • Security and fraud-detection cookies: used to detect unusual patterns of behaviour consistent with automated bot activity, credential stuffing attacks, or multi-account operation. These cookies form part of our fraud prevention infrastructure and are strictly necessary for Platform security.

ina77 does not use third-party advertising cookies, retargeting pixels, or cross-site tracking technologies that would allow external advertising networks to build profiles of your behaviour across websites other than ina77.club. You may manage cookie preferences for non-essential categories via your browser settings. Note that disabling functional or security cookies may degrade your Platform experience or prevent certain features from operating correctly.

Section 10

Security Measures

ina77 implements a layered technical and organisational security framework to protect Personal Data against unauthorised access, disclosure, alteration, loss, or destruction. Our core security measures include:

  • Encryption in transit: all data transmitted between your device and the ina77 Platform is encrypted using TLS 1.3 with AES-256-GCM cipher suites. Connections using TLS 1.1 or below are rejected at the server level.
  • Encryption at rest: sensitive Personal Data stored in ina77's databases — including KYC document images, financial account identifiers, and password hashes — is encrypted at rest using AES-256 symmetric encryption with keys managed through a dedicated key management service.
  • Access controls: access to systems containing Personal Data is governed by a least-privilege policy. Each staff member is granted access only to the data categories and systems genuinely required for their specific role. All privileged access is logged and subject to regular access review.
  • Multi-factor authentication: all internal ina77 staff accounts with access to member data require multi-factor authentication. Member accounts include optional 2FA via SMS OTP, with mandatory 2FA required for withdrawal requests above defined value thresholds.
  • Intrusion detection and monitoring: ina77 operates continuous automated monitoring of network traffic, system logs, and database query patterns for indicators of unauthorised access or data exfiltration. Anomalies trigger alerts to our security operations team for immediate investigation.
  • Penetration testing and vulnerability management: the Platform undergoes scheduled third-party penetration testing. Critical and high-severity vulnerabilities are subject to a mandatory remediation timeline. ina77 operates a responsible disclosure policy for external security researchers.

No data security system is impenetrable. In the event of a data breach that presents a material risk to the rights and freedoms of affected members, ina77 will notify impacted members and, where required by applicable law, the relevant supervisory authority within the timeframe prescribed by the applicable regulation.

Section 11

Your Data Rights

Subject to applicable data protection law and the limitations that may apply under our regulatory obligations (including AML record-keeping requirements), you hold the following rights over your Personal Data held by ina77:

Right of Access

Request a copy of the Personal Data ina77 holds about you, together with information about how it is processed and under what legal basis.

Right to Rectification

Request correction of any inaccurate or incomplete Personal Data we hold about you. Certain corrections (e.g., name changes) may require supporting documentation.

Right to Erasure

Request deletion of your Personal Data where it is no longer necessary for the purpose for which it was collected, subject to our legal retention obligations under AML and licensing regulations.

Right to Restrict Processing

Request that we restrict the processing of your Personal Data to storage only — for example, while the accuracy of your data is contested or while you are exercising your right to object.

Right to Data Portability

Request a machine-readable export of the Personal Data you have provided to ina77 — covering account data, transaction history, and gaming activity logs — in CSV or JSON format.

Right to Object

Object to processing carried out on the basis of ina77's legitimate interests, including direct marketing communications. Objections to marketing are actioned immediately upon receipt.

To exercise any of the above rights, submit a written request to our Data Protection Officer at the contact details in Section 14. We will acknowledge your request within 5 business days and provide a substantive response within 30 calendar days. Complex requests may require an extension of up to a further 60 days, in which case you will be notified of the extension and the reason for it before the initial 30-day period expires.

Section 12

Minors & Age Restriction

The ina77 Platform is strictly intended for adults aged 21 and above. ina77 does not knowingly collect Personal Data from individuals under the age of 21, and registration is not permitted for individuals below that age threshold.

Where ina77 becomes aware — through KYC verification, age estimation signals, or a third-party report — that an account has been registered by an individual under the age of 21, ina77 will immediately suspend the account, initiate a review, and permanently close the account upon confirmation of the age breach. Any deposited funds held in such an account will be returned to the original payment source following the completion of the account closure process. The Personal Data associated with the minor's account will be deleted as promptly as legally permissible, subject to any minimum retention period required by applicable law for fraud and AML record-keeping purposes.

If you believe that a person under the age of 21 has registered an account on the ina77 Platform, please contact our support team immediately via live chat or at the email address in Section 14.

Section 13

Amendments to This Policy

ina77 reserves the right to amend this Privacy Policy at any time. Material amendments — meaning those that significantly affect your privacy rights or the purposes for which your data is used — will be communicated to all registered members via email notification to the registered address on file, with a minimum of 14 days' advance notice before the amended policy takes effect.

Non-material amendments — such as clarifications of existing practices, updated examples, or corrections of typographical errors — may be applied without advance notice, with the updated effective date published at the top of this page. We recommend reviewing this page periodically to remain informed of our current privacy practices.

Your continued use of the ina77 Platform after the effective date of any amendment constitutes acceptance of the revised policy. If you do not agree with a material amendment and you are unable to resolve your concern by contacting our Data Protection Officer, you may close your account in accordance with the procedure described in our Terms & Conditions.

Section 14

Contact & Data Protection Officer

ina77 has appointed a Data Protection Officer (DPO) responsible for overseeing compliance with this Privacy Policy and responding to member data rights requests. You may contact the DPO or our general support team using the following details:

  • Email: [email protected] — for privacy-specific enquiries, please include "Privacy Request" in the subject line of your message. (Plain text — not a clickable link.)
  • WhatsApp: +62 812 0000 7799 — available 24/7. (Plain text — not a clickable link.)
  • Live Chat: accessible via the Platform interface at any time; please select the "Account & Privacy" category when initiating the chat.
  • Support Hours: 24 hours per day, 7 days per week, including all Indonesian national public holidays, with native Indonesian-speaking agents on every shift (WIB, WITA, and WIT time zones covered).

For formal data rights requests (access, rectification, erasure, portability, objection, restriction), written requests submitted by email receive priority handling and generate an automated acknowledgement within 24 hours. WhatsApp and live chat channels are appropriate for initial enquiries; formal written requests should be directed to the email address above to ensure a complete audit trail.

How ina77 Protects Your Privacy

Six concrete practices that back our privacy commitments — not just policy language.

256-Bit SSL Encryption

Every connection to ina77.club runs over TLS 1.3 with AES-256-GCM encryption. Your login credentials, KYC documents, and Rupiah transaction data travel over a channel that meets the same encryption standard used by Indonesia's leading internet banking platforms.

No Data Sales — Ever

ina77 has never sold member Personal Data to an advertising network, data broker, or third-party marketing company. Your data is used exclusively to operate the Platform, process your payments, and comply with our licensing obligations.

Least-Privilege Access Control

Internally, ina77 staff access only the data categories strictly required for their specific role. No employee has standing access to all member data. All privileged access is logged, reviewed quarterly, and revoked immediately upon role change or departure.

Data Minimisation

ina77 collects only the Personal Data that is genuinely necessary for a specific, stated purpose. We do not pre-collect data "in case it becomes useful later." Each data element collected has a defined purpose, legal basis, and retention period before collection begins.

Fast Rights Response

ina77 acknowledges data rights requests within 5 business days and provides a full response within 30 calendar days. Access requests are fulfilled as a machine-readable export (CSV or JSON) covering your account data, transaction history, and gaming logs.

Regular Security Audits

The ina77 Platform undergoes scheduled third-party penetration testing and independent security audits. Critical vulnerabilities are remediated under a mandatory timeline. ina77 operates a responsible disclosure programme for external security researchers who report vulnerabilities in good faith.

Your Privacy Is in Safe Hands

If you have questions about this Privacy Policy, want to exercise your data rights, or simply want to learn more about how ina77 operates, our 24/7 support team is ready to help. You can also explore our FAQ for quick answers.

View FAQ Terms & Conditions Access My Account

21+ only. Licensed and Regulated Internationally. SSL Encrypted. Provably Fair.