ina77 is committed to protecting the privacy of every member. This Privacy Policy explains precisely what personal data we collect, why we collect it, how we use and protect it, and what rights you hold over your own information.
For the purposes of this Privacy Policy, the following terms have the meanings set out below:
ina77 collects Personal Data across the following categories. We apply a data minimisation principle: we collect only what is genuinely necessary for the stated purpose.
| Category | Examples | Mandatory? |
|---|---|---|
| Identity Data | Full legal name, date of birth, nationality, KTP number or passport number | Yes — for KYC verification |
| Contact Data | Email address, Indonesian mobile number (+62 format), registered city or province | Yes — for account communication |
| Financial Data | Bank account name and number (BCA, BRI, BNI, Mandiri, etc.), e-wallet identifier (OVO, DANA, GoPay, ShopeePay, LinkAja), transaction history, deposit and withdrawal amounts in Rupiah | Yes — for payment processing |
| Account Data | Username, encrypted password hash, account creation timestamp (WIB), login history, session activity logs | Yes — for account security |
| Gaming Activity Data | Games played, wagers placed, outcomes, bonus usage, game session durations, responsible gaming tool settings | Yes — for regulatory compliance and responsible gaming |
| Technical Data | IP address, device type and OS, browser type and version, screen resolution, time zone (WIB/WITA/WIT), session cookie tokens | Yes — for platform security and fraud detection |
| Communications Data | Support chat transcripts, email correspondence with ina77, WhatsApp message logs where initiated by the member | Optional — generated by member-initiated contact |
| KYC Document Data | Scanned or photographed copy of government-issued KTP or passport (image file), selfie verification image where required | Yes — for withdrawal eligibility |
We do not collect special categories of sensitive personal data (as defined under applicable data protection law) — including health data, biometric data used for unique identification, political opinions, or religious beliefs — except where a member voluntarily discloses such information in the context of a responsible gaming assessment or support interaction, and where such disclosure is strictly necessary for providing the requested support.
ina77 collects Personal Data through three primary channels:
ina77 processes your Personal Data under one or more of the following legal bases, applied on a purpose-by-purpose basis:
ina77 uses the Personal Data we collect for the following purposes:
ina77 does not sell, rent, or trade your Personal Data to any third party. We share Personal Data only in the following strictly defined circumstances:
ina77 operates infrastructure across multiple jurisdictions to ensure platform availability, redundancy, and performance for members accessing the Platform from across Indonesia — including Jakarta, Surabaya, Medan, Bandung, Bali, Yogyakarta, Semarang, and all other regions. As a consequence, your Personal Data may be transferred to and stored on servers located outside of Indonesia.
Where such international transfers occur, ina77 ensures that equivalent data protection standards apply by implementing one or more of the following safeguards: binding contractual clauses with the receiving party that impose data handling obligations no less protective than those required under applicable data protection standards; restricted transfers limited to countries with independently assessed adequate data protection frameworks; or, where neither of the above applies, processing the transfer on the basis of your explicit consent following disclosure of the associated risks.
Members who wish to obtain information about the specific safeguards applied to any international transfer of their Personal Data may submit a request to our Data Protection Officer at the contact details set out in Section 14.
ina77 retains Personal Data only for as long as necessary to fulfil the purpose for which it was collected or to comply with applicable legal, regulatory, or licensing obligations. The following general retention periods apply:
| Data Category | Retention Period | Basis |
|---|---|---|
| Active account data | Duration of account + 5 years post-closure | AML/KYC regulatory obligation |
| Transaction records (deposits/withdrawals) | 7 years from transaction date | Financial record-keeping obligation |
| KYC document copies | 5 years post account closure | AML regulatory obligation |
| Gaming activity logs | 3 years from log creation | Licensing obligation; responsible gaming |
| Support interaction records | 3 years from interaction date | Legitimate interest; dispute resolution |
| Technical / server access logs | 12 months from log creation | Legitimate interest; security monitoring |
| Self-exclusion records | Indefinite (or statutory minimum if longer) | Responsible gaming compliance |
| Marketing consent records | Duration of consent + 3 years | Demonstration of lawful basis |
At the end of the applicable retention period, Personal Data is securely deleted or anonymised in accordance with our internal data destruction procedures. Anonymised or aggregated data sets — from which no individual can be identified — may be retained indefinitely for analytical purposes.
The ina77 Platform uses first-party cookies and similar tracking technologies to deliver a functional, secure, and personalised experience. We use the following categories of cookies:
ina77 does not use third-party advertising cookies, retargeting pixels, or cross-site tracking technologies that would allow external advertising networks to build profiles of your behaviour across websites other than ina77.club. You may manage cookie preferences for non-essential categories via your browser settings. Note that disabling functional or security cookies may degrade your Platform experience or prevent certain features from operating correctly.
ina77 implements a layered technical and organisational security framework to protect Personal Data against unauthorised access, disclosure, alteration, loss, or destruction. Our core security measures include:
No data security system is impenetrable. In the event of a data breach that presents a material risk to the rights and freedoms of affected members, ina77 will notify impacted members and, where required by applicable law, the relevant supervisory authority within the timeframe prescribed by the applicable regulation.
Subject to applicable data protection law and the limitations that may apply under our regulatory obligations (including AML record-keeping requirements), you hold the following rights over your Personal Data held by ina77:
Request a copy of the Personal Data ina77 holds about you, together with information about how it is processed and under what legal basis.
Request correction of any inaccurate or incomplete Personal Data we hold about you. Certain corrections (e.g., name changes) may require supporting documentation.
Request deletion of your Personal Data where it is no longer necessary for the purpose for which it was collected, subject to our legal retention obligations under AML and licensing regulations.
Request that we restrict the processing of your Personal Data to storage only — for example, while the accuracy of your data is contested or while you are exercising your right to object.
Request a machine-readable export of the Personal Data you have provided to ina77 — covering account data, transaction history, and gaming activity logs — in CSV or JSON format.
Object to processing carried out on the basis of ina77's legitimate interests, including direct marketing communications. Objections to marketing are actioned immediately upon receipt.
To exercise any of the above rights, submit a written request to our Data Protection Officer at the contact details in Section 14. We will acknowledge your request within 5 business days and provide a substantive response within 30 calendar days. Complex requests may require an extension of up to a further 60 days, in which case you will be notified of the extension and the reason for it before the initial 30-day period expires.
The ina77 Platform is strictly intended for adults aged 21 and above. ina77 does not knowingly collect Personal Data from individuals under the age of 21, and registration is not permitted for individuals below that age threshold.
Where ina77 becomes aware — through KYC verification, age estimation signals, or a third-party report — that an account has been registered by an individual under the age of 21, ina77 will immediately suspend the account, initiate a review, and permanently close the account upon confirmation of the age breach. Any deposited funds held in such an account will be returned to the original payment source following the completion of the account closure process. The Personal Data associated with the minor's account will be deleted as promptly as legally permissible, subject to any minimum retention period required by applicable law for fraud and AML record-keeping purposes.
If you believe that a person under the age of 21 has registered an account on the ina77 Platform, please contact our support team immediately via live chat or at the email address in Section 14.
ina77 reserves the right to amend this Privacy Policy at any time. Material amendments — meaning those that significantly affect your privacy rights or the purposes for which your data is used — will be communicated to all registered members via email notification to the registered address on file, with a minimum of 14 days' advance notice before the amended policy takes effect.
Non-material amendments — such as clarifications of existing practices, updated examples, or corrections of typographical errors — may be applied without advance notice, with the updated effective date published at the top of this page. We recommend reviewing this page periodically to remain informed of our current privacy practices.
Your continued use of the ina77 Platform after the effective date of any amendment constitutes acceptance of the revised policy. If you do not agree with a material amendment and you are unable to resolve your concern by contacting our Data Protection Officer, you may close your account in accordance with the procedure described in our Terms & Conditions.
ina77 has appointed a Data Protection Officer (DPO) responsible for overseeing compliance with this Privacy Policy and responding to member data rights requests. You may contact the DPO or our general support team using the following details:
For formal data rights requests (access, rectification, erasure, portability, objection, restriction), written requests submitted by email receive priority handling and generate an automated acknowledgement within 24 hours. WhatsApp and live chat channels are appropriate for initial enquiries; formal written requests should be directed to the email address above to ensure a complete audit trail.
Six concrete practices that back our privacy commitments — not just policy language.
Every connection to ina77.club runs over TLS 1.3 with AES-256-GCM encryption. Your login credentials, KYC documents, and Rupiah transaction data travel over a channel that meets the same encryption standard used by Indonesia's leading internet banking platforms.
ina77 has never sold member Personal Data to an advertising network, data broker, or third-party marketing company. Your data is used exclusively to operate the Platform, process your payments, and comply with our licensing obligations.
Internally, ina77 staff access only the data categories strictly required for their specific role. No employee has standing access to all member data. All privileged access is logged, reviewed quarterly, and revoked immediately upon role change or departure.
ina77 collects only the Personal Data that is genuinely necessary for a specific, stated purpose. We do not pre-collect data "in case it becomes useful later." Each data element collected has a defined purpose, legal basis, and retention period before collection begins.
ina77 acknowledges data rights requests within 5 business days and provides a full response within 30 calendar days. Access requests are fulfilled as a machine-readable export (CSV or JSON) covering your account data, transaction history, and gaming logs.
The ina77 Platform undergoes scheduled third-party penetration testing and independent security audits. Critical vulnerabilities are remediated under a mandatory timeline. ina77 operates a responsible disclosure programme for external security researchers who report vulnerabilities in good faith.
If you have questions about this Privacy Policy, want to exercise your data rights, or simply want to learn more about how ina77 operates, our 24/7 support team is ready to help. You can also explore our FAQ for quick answers.
21+ only. Licensed and Regulated Internationally. SSL Encrypted. Provably Fair.