Legal

Privacy Policy

At au328, your personal data is handled with the same care and precision we apply to every transaction on our platform. This Privacy Policy explains exactly what information we collect, why we collect it, how it is stored and protected, and the rights you hold as an au328 account holder in Indonesia.

Effective Date: 1 January 2026  |  Last Reviewed: 1 January 2026
256-bit SSL Encryption
No Data Sold to Third Parties
KYC Data Stored Securely
GDPR-Aligned Practices
Right to Erasure Honoured
Opt-Out Marketing Respected
♠ ♥ ♦ ♣

Six Rights au328 Upholds for Every Player


These are not abstract legal provisions — they are active rights you can exercise at any time by contacting au328 support. Here is what each right means in practice.

Right of Access

Request a full copy of every piece of personal data au328 holds about you — including your registration details, KYC documents, transaction history, and support correspondence — delivered within 30 days.

Right to Rectification

If any personal data au328 holds about you is inaccurate or out of date, you can request a correction at any time. Name changes may require updated KYC documents to maintain account security.

Right to Erasure

Request deletion of your personal data when it is no longer needed, when you withdraw consent, or when processing was unlawful. Legal retention obligations (such as 7-year financial records) may limit the scope of erasure.

Right to Restrict Processing

Ask au328 to pause active processing of your data — keeping it stored but unused — while a data accuracy dispute or objection is being resolved. Processing resumes only when the matter is settled.

Right to Data Portability

Request a structured, machine-readable export of the personal data you have provided to au328, in a format you can transfer to another service. This covers account data, transaction history, and preference settings.

Right to Object

Object to processing based on legitimate interests or to all direct marketing at any time. Marketing opt-outs take effect within 48 hours. Objections to legitimate-interest processing are assessed individually and actioned promptly.

How au328 Protects Your Personal Data


Security is not a checkbox at au328 — it is a layered, continuously reviewed system designed to keep your identity, financial, and gaming data safe at every stage of its lifecycle.

256-bit SSL Encryption

Every connection between your browser or mobile device and the au328 platform is secured with 256-bit SSL/TLS encryption — the same standard used by BCA and Mandiri internet banking. Your login credentials, deposit requests, and KYC documents cannot be read in transit by any third party.

Encrypted Data Storage

Personal data and identity documents stored on au328 infrastructure are encrypted at rest using industry-standard AES-256 encryption. Encryption keys are stored separately from the data they protect and rotated on a scheduled basis to minimise exposure in the event of a key compromise.

Strict Access Controls

Access to player personal data within au328's internal systems is governed by role-based access control. Every staff member and contractor is granted only the minimum data access their specific function requires. All internal access events are logged, timestamped, and reviewed periodically by the security team.

Regular Penetration Testing

au328 engages qualified third-party security specialists to conduct regular penetration tests against the platform's web application, payment integrations, and data storage systems. Identified vulnerabilities are triaged and remediated before they can be exploited by malicious actors.

Two-Factor Authentication

All au328 internal systems that handle personal data require multi-factor authentication for staff login. Players are strongly encouraged to enable two-factor authentication on their own au328 accounts for an additional layer of protection against unauthorised access, particularly from shared devices in Jakarta, Surabaya, or Bali internet cafés.

Breach Notification

In the event of a personal data breach that presents a material risk to your rights, au328 will notify affected players within 72 hours of identifying the incident. Notifications will describe the nature of the breach, the categories of data affected, the likely consequences, and the steps au328 has taken to contain and remediate it.

Your Privacy is in Safe Hands at au328

Your data is protected by industry-leading encryption, strict access controls, and a team that takes your rights seriously. Explore the full au328 platform with confidence — or reach out to our support team if you have any questions about this Policy.

Visit the FAQ Responsible Gaming Login to au328