At au328, your personal data is handled with the same care and precision we apply to every transaction on our platform. This Privacy Policy explains exactly what information we collect, why we collect it, how it is stored and protected, and the rights you hold as an au328 account holder in Indonesia.
au328 is an internationally operated online casino and sportsbook platform accessible at https://au328.onl. For the purposes of this Privacy Policy, au328 acts as the data controller — that is, the entity that determines the purposes and means by which your personal data is processed.
au328 is designed and operated primarily for players based in Indonesia, offering gaming services including live casino, slots, sportsbook wagering, crash games, and live blackjack. All personal data collected through the au328 platform is processed in accordance with internationally recognised data-protection principles, including those reflected in the EU General Data Protection Regulation (GDPR) as a benchmark standard, adapted to the context of Indonesian players and the international gaming environment.
If you have any questions about how au328 handles your personal data, or wish to exercise any right described in this Policy, please contact our Data Protection team at [email protected] (plain text — not a clickable link).
au328 collects the minimum personal data necessary to provide you with a safe, verified, and personalised gaming experience. The categories of data we collect are set out in the table below:
| Category | Examples | Purpose |
|---|---|---|
| Identity Data | Full name, date of birth, nationality, KTP/Passport/SIM number | KYC verification; age confirmation (21+); fraud prevention |
| Contact Data | Email address, Indonesian mobile number, residential address | Account communication; support responses; promotional messaging (where consented) |
| Financial Data | Bank account details (BCA, BRI, BNI, Mandiri, CIMB Niaga), e-wallet identifiers (OVO, DANA, GoPay, ShopeePay, LinkAja), transaction history | Processing deposits and withdrawals; anti-money-laundering checks; payment method verification |
| Identity Documents | Scanned or photographed copies of KTP, Passport, SIM; proof of address; bank statements | KYC compliance; age and identity verification prior to withdrawal |
| Technical Data | IP address, device type, browser type and version, operating system, time zone, screen resolution | Platform security; fraud detection; geolocation verification; session management |
| Usage Data | Pages visited, game sessions, bet amounts, session duration, login timestamps, feature interactions | Platform improvement; responsible gaming monitoring; personalised experience |
| Marketing Preferences | Communication channel preferences; opted-in or opted-out status for email, SMS, and in-platform notifications | Ensuring promotional messages are sent only where consented |
| Support Correspondence | Live chat transcripts, email threads, complaint records | Quality assurance; dispute resolution; regulatory compliance |
Sensitive Data: au328 does not intentionally collect sensitive personal data such as racial or ethnic origin, religious beliefs, political opinions, health data, or biometric data beyond what is strictly necessary for identity verification. If an identity document you submit incidentally contains such information (for example, a KTP that records religion), that data is used solely for identity confirmation and is not stored, processed, or shared for any other purpose.
au328 collects personal data through several direct and indirect channels:
You provide data directly to au328 when you: complete the account registration form; submit KYC identity documents; make a deposit or withdrawal request; contact customer support via live chat or email; respond to a survey or promotion; or update your account profile settings.
When you access and navigate the au328 platform, our systems automatically collect technical and usage data including your IP address, browser fingerprint, device identifiers, pages visited, time on site, and game interaction data. This collection is facilitated by server logs, session cookies, and first-party analytics tools. See Section 9 (Cookies & Tracking) for full details.
au328 may receive data about you from the following third-party sources:
au328 processes your personal data only for clearly defined, legitimate purposes. We do not use your data for undisclosed secondary purposes. The primary purposes of processing are:
au328 relies on the following legal bases to process your personal data, consistent with internationally recognised data protection frameworks:
| Legal Basis | When It Applies |
|---|---|
| Contractual Necessity | Processing required to perform our contract with you — including account creation, payment processing, game access, and withdrawal execution. Without this processing, we cannot provide the service. |
| Legal Obligation | Processing required to comply with applicable anti-money-laundering rules, KYC regulations, and any lawful requests from competent authorities. |
| Legitimate Interests | Processing for fraud detection, platform security, multi-account prevention, and aggregate analytics — where our legitimate interest in operating a secure and fair platform does not override your privacy rights. |
| Consent | Processing for direct marketing communications, personalised promotions, and optional cookies. You may withdraw consent at any time without affecting the lawfulness of prior processing. |
au328 does not sell, rent, or trade your personal data to third parties for their own commercial purposes. We share data only to the extent necessary to operate the platform and fulfil our legal obligations, with the following categories of recipient:
Third-party vendors engaged by au328 to provide specific operational services, including: KYC and identity verification technology providers; payment gateway processors connecting to Indonesian banks and e-wallets; cloud hosting and data centre providers; fraud detection and risk-scoring services; and customer support platform providers. All service providers are contractually bound to process your data solely on au328's instructions and to maintain security standards consistent with this Policy.
Game providers (including Evolution Gaming, Pragmatic Play, PGSoft, Microgaming, NetEnt, and Spribe) receive the minimum player-session data necessary to operate their games within the au328 platform environment. Game providers do not receive your full identity or financial data unless required for a specific dispute or RNG audit investigation.
au328 will disclose personal data to competent law enforcement agencies, regulatory authorities, or courts where we are legally compelled to do so, or where disclosure is necessary to protect the safety of players or the integrity of the platform. au328 will, where legally permissible, notify you of such disclosure.
In the event that au328 undergoes a merger, acquisition, or sale of substantially all of its assets, your personal data may be transferred to the acquiring entity as part of that transaction. You will be notified of any such transfer and your rights under this Policy will be preserved.
No Data Sales: au328 will never sell your personal data — including your name, contact details, financial information, or gaming history — to advertising networks, data brokers, or any third party for marketing or profiling purposes. This is an unconditional commitment.
au328 retains personal data only for as long as is necessary for the purposes for which it was collected, subject to any legal retention obligations. Our standard retention periods are:
| Data Category | Retention Period |
|---|---|
| Account and Identity Data | Duration of account plus 5 years after account closure, to satisfy AML and audit obligations. |
| Financial Transaction Records | 7 years from the date of each transaction, consistent with standard financial record-keeping requirements. |
| KYC Documents | 5 years after account closure or the last financial transaction, whichever is later. |
| Support Correspondence | 3 years from the date of the most recent interaction in a given support thread. |
| Marketing Preferences and Consent Records | Duration of account plus 2 years, to demonstrate compliance with consent obligations. |
| Technical / Log Data | 90 days for routine server logs; up to 12 months for security-incident-related logs. |
| Self-Exclusion Records | Minimum 7 years, to prevent re-registration during and after the exclusion period. |
Upon expiry of the applicable retention period, data is securely deleted or anonymised such that it can no longer be attributed to an identifiable individual. Anonymised aggregate data may be retained indefinitely for statistical and platform improvement purposes.
au328 implements a layered security architecture to protect your personal data against unauthorised access, disclosure, alteration, or destruction. Our technical and organisational security measures include:
Your Role in Security: While au328 maintains robust technical safeguards, the security of your account also depends on keeping your login credentials private. Never share your au328 password with anyone — including individuals claiming to be au328 support agents. au328 staff will never ask for your password via any channel.
au328 uses cookies and similar tracking technologies to operate core platform functionality, maintain your session, detect fraud, and (where you have consented) improve your experience through personalisation. The types of cookies used on the au328 platform are:
| Cookie Type | Purpose | Consent Required? |
|---|---|---|
| Strictly Necessary | Session management, login authentication, security tokens, shopping cart equivalents (wallet balance display). The platform cannot function without these. | No — these are essential to service operation. |
| Functional | Remembering your language preference, preferred game lobby view, and responsible gaming alert settings. | No — these enhance usability without tracking. |
| Analytics | First-party analytics measuring page performance, navigation paths, and feature usage to improve the platform. Data is aggregated and anonymised. | Yes — consent required on first visit. |
| Marketing / Personalisation | Delivering personalised bonus offers and promotional messaging based on your game preferences and session history. | Yes — explicit opt-in required. |
You can manage your cookie preferences at any time through your au328 account settings. Withdrawing consent for analytics or marketing cookies will not affect your ability to access any core platform feature. Note that blocking strictly necessary cookies may prevent certain platform functions from operating correctly.
As an au328 account holder, you hold the following rights with respect to your personal data. To exercise any of these rights, contact au328 at [email protected]. Requests will be acknowledged within 24 hours and fulfilled within 30 calendar days. Complex requests may take up to 60 days, in which case you will be notified of the extension.
The au328 platform is strictly intended for adults aged 21 and above. au328 does not knowingly collect personal data from individuals under the age of 21. The registration process requires date-of-birth confirmation, and KYC verification confirms age through government-issued identity documents prior to withdrawal of any funds.
If au328 discovers that personal data has been collected from an individual who is under 21 at the time of registration, that account will be immediately suspended, all pending wagers voided, any net deposit balance returned to the originating payment method, and all associated personal data deleted within 30 days of discovery — except where retention is required to evidence the age-verification failure for compliance purposes.
Parent or Guardian Alert: If you believe a minor in your care has registered an au328 account, contact au328 immediately at [email protected]. au328 will investigate and act on credible reports within 24 hours. Protecting minors from exposure to gambling is a non-negotiable platform priority, not a legal formality.
As an internationally operated platform serving Indonesian players, au328 may transfer personal data to third-party service providers located outside Indonesia, including cloud infrastructure providers and KYC technology vendors. Where such transfers occur, au328 ensures that appropriate safeguards are in place to protect your data to the same standard as this Policy, including:
au328 does not transfer personal data to jurisdictions that do not provide an adequate level of data protection without implementing the contractual safeguards described above.
au328 reserves the right to amend this Privacy Policy at any time to reflect changes in our data practices, legal obligations, or platform features. When material changes are made — that is, changes that affect your rights or the way we use your data in a significant way — au328 will notify active account holders via email and/or a prominent notice on the au328 platform at least 7 days before the updated Policy takes effect.
Non-material changes (such as typographical corrections, structural reorganisation for clarity, or updates to contact information) may take effect immediately upon publication. The "Last Reviewed" date at the top of this Policy will always reflect the date of the most recent revision. Your continued use of the au328 platform after the effective date of any amendment constitutes your acceptance of the updated Privacy Policy. If you do not agree with the revised Policy, you must discontinue use of the platform and request account closure.
For all privacy-related queries, data subject rights requests, or concerns about how au328 handles your personal data, please contact us through the following channels:
au328 support operates in both English and Indonesian, 24 hours a day, 7 days a week, including all Indonesian public holidays. All times reference Western Indonesia Time (WIB, UTC+7) as the default operational time zone.
Response Commitment: au328 acknowledges all privacy queries within 24 hours and resolves standard data subject rights requests within 30 calendar days. Complex erasure or portability requests that require coordination across multiple data systems may take up to 60 days; you will be notified proactively if an extension is needed.
These are not abstract legal provisions — they are active rights you can exercise at any time by contacting au328 support. Here is what each right means in practice.
Request a full copy of every piece of personal data au328 holds about you — including your registration details, KYC documents, transaction history, and support correspondence — delivered within 30 days.
If any personal data au328 holds about you is inaccurate or out of date, you can request a correction at any time. Name changes may require updated KYC documents to maintain account security.
Request deletion of your personal data when it is no longer needed, when you withdraw consent, or when processing was unlawful. Legal retention obligations (such as 7-year financial records) may limit the scope of erasure.
Ask au328 to pause active processing of your data — keeping it stored but unused — while a data accuracy dispute or objection is being resolved. Processing resumes only when the matter is settled.
Request a structured, machine-readable export of the personal data you have provided to au328, in a format you can transfer to another service. This covers account data, transaction history, and preference settings.
Object to processing based on legitimate interests or to all direct marketing at any time. Marketing opt-outs take effect within 48 hours. Objections to legitimate-interest processing are assessed individually and actioned promptly.
Security is not a checkbox at au328 — it is a layered, continuously reviewed system designed to keep your identity, financial, and gaming data safe at every stage of its lifecycle.
Every connection between your browser or mobile device and the au328 platform is secured with 256-bit SSL/TLS encryption — the same standard used by BCA and Mandiri internet banking. Your login credentials, deposit requests, and KYC documents cannot be read in transit by any third party.
Personal data and identity documents stored on au328 infrastructure are encrypted at rest using industry-standard AES-256 encryption. Encryption keys are stored separately from the data they protect and rotated on a scheduled basis to minimise exposure in the event of a key compromise.
Access to player personal data within au328's internal systems is governed by role-based access control. Every staff member and contractor is granted only the minimum data access their specific function requires. All internal access events are logged, timestamped, and reviewed periodically by the security team.
au328 engages qualified third-party security specialists to conduct regular penetration tests against the platform's web application, payment integrations, and data storage systems. Identified vulnerabilities are triaged and remediated before they can be exploited by malicious actors.
All au328 internal systems that handle personal data require multi-factor authentication for staff login. Players are strongly encouraged to enable two-factor authentication on their own au328 accounts for an additional layer of protection against unauthorised access, particularly from shared devices in Jakarta, Surabaya, or Bali internet cafés.
In the event of a personal data breach that presents a material risk to your rights, au328 will notify affected players within 72 hours of identifying the incident. Notifications will describe the nature of the breach, the categories of data affected, the likely consequences, and the steps au328 has taken to contain and remediate it.
Your data is protected by industry-leading encryption, strict access controls, and a team that takes your rights seriously. Explore the full au328 platform with confidence — or reach out to our support team if you have any questions about this Policy.
Visit the FAQ Responsible Gaming Login to au328