Our Privacy Commitments
We handle your personal information with the same care we apply to your funds — securely, transparently, and strictly on a need-to-know basis.
Every data exchange between your browser and the sa365 platform is protected by industry-standard TLS/SSL encryption. Your login credentials, payment details, and personal information travel across our network in fully encrypted form at all times.
sa365 collects only the data that is strictly necessary to deliver a safe, compliant, and personalised experience. We do not harvest data for resale to advertisers, and we do not build behavioural profiles beyond what is required for responsible gaming controls and anti-fraud measures.
You hold clear rights over your personal data — including the right to access, correct, restrict processing of, and request deletion of your information. Exercise any of these rights at any time by contacting our support team at [email protected].
sa365 does not sell, rent, or trade your personal data to any third-party marketing company. Data shared with our technology partners — payment processors, game studios, KYC providers — is strictly limited to the minimum needed to fulfil the service you have requested.
We retain your personal data only for as long as is necessary to fulfil the purposes for which it was collected — including legal, regulatory, and anti-money-laundering obligations. Once the retention period expires, data is securely deleted or anonymised.
In the unlikely event of a personal data breach affecting your information, sa365 will notify you directly via your registered email address within 72 hours of becoming aware of the incident, consistent with internationally recognised data-protection standards.
Clause 1
This Privacy Policy is issued by the legal entity operating the sa365 online betting and gaming platform, accessible at https://sa365.bio ("sa365", "we", "us", or "our"). It applies to all personal data collected through the sa365 website, any associated mobile interfaces, and all communications between sa365 and its registered members.
sa365 is committed to protecting your personal data and to being fully transparent about how that data is handled. We process personal information strictly in accordance with internationally recognised data-protection principles, including lawfulness, fairness, transparency, purpose limitation, data minimisation, accuracy, storage limitation, integrity, and accountability.
By registering an Account on sa365 or by continuing to use the platform after this policy has been updated, you acknowledge that you have read and understood this Privacy Policy and consent to the processing of your personal data as described herein. If you do not agree with any part of this policy, you must discontinue use of the platform immediately and contact us to close your account.
This Privacy Policy should be read alongside the sa365 Terms & Conditions and the Responsible Gaming Policy, both of which are incorporated by reference. Capitalized terms used but not defined here carry the meaning assigned to them in the Terms & Conditions.
Clause 2
sa365 collects personal data through several channels: directly from you when you register or use the platform, automatically through your device and browser as you interact with the site, and from trusted third-party sources where this is necessary for identity verification or fraud prevention. The categories of data we collect are set out in the table below.
| Data Category | Specific Data Points |
|---|---|
| Identity Data | Full legal name, date of birth, gender, nationality, government-issued ID number (KTP, passport, or driver's licence number), and a copy of the identity document submitted for KYC verification. |
| Contact Data | Email address, mobile phone number (Indonesian registered), and, where provided, a residential address in Indonesia (city, province). |
| Account Data | Username, hashed password, account creation date, login history, active session data, and account status (active, suspended, self-excluded, or closed). |
| Financial Data | Bank account details (BCA, BRI, BNI, Mandiri, CIMB Niaga) and e-wallet identifiers (OVO, DANA, GoPay, ShopeePay, LinkAja) used for deposits and withdrawals. We do not store full card numbers or payment credentials — these are handled directly by PCI-DSS-compliant payment processors. |
| Transaction Data | Deposit history, withdrawal history, bet records (including amount, market, odds, and outcome), bonus claims, and Wallet balance snapshots. |
| Technical Data | IP address, browser type and version, operating system, device type, screen resolution, time zone setting (WIB/WITA/WIT), referring URL, and session duration. |
| Behavioural Data | Pages visited, game categories accessed, search queries within the platform, click-path data, and session frequency — used for personalisation and responsible gaming monitoring. |
| Communications Data | Content of support tickets, live chat transcripts, email correspondence, and any documentation submitted in relation to disputes or KYC requests. |
Sensitive Data: sa365 does not intentionally collect special categories of sensitive personal data (such as health data, religious beliefs, or political opinions). If you voluntarily disclose sensitive information — for example, in a responsible gaming self-assessment — it will be used solely for the purpose of providing appropriate support and will not be used for any other purpose.
Clause 3
sa365 processes your personal data only where we have a lawful basis for doing so. The primary lawful bases we rely on are: contract performance (processing necessary to deliver the services you have signed up for), legal obligation (processing required to comply with applicable laws and regulatory requirements), legitimate interests (processing for fraud prevention, security, and platform improvement), and consent (processing for marketing communications, which you may withdraw at any time).
The specific purposes for which we use your data are as follows:
Clause 4
sa365 does not sell your personal data to any third party for commercial or marketing purposes. We share personal data only in the limited circumstances described below, and only to the extent strictly necessary for the stated purpose.
| Recipient Category | Purpose & Scope |
|---|---|
| Payment Processors | BCA, BRI, BNI, Mandiri, CIMB Niaga, OVO, DANA, GoPay, ShopeePay, and LinkAja receive the minimum data required to execute deposit and withdrawal transactions on your behalf. All payment partners are subject to contractual data-protection obligations. |
| KYC & Identity Verification Providers | Third-party identity verification services receive copies of your identity documents and biometric data (where applicable) solely for the purpose of confirming your age, identity, and Indonesian residency. These providers are bound by strict confidentiality agreements. |
| Game Content Providers | Studios such as Evolution Gaming, Pragmatic Play, NetEnt, Microgaming, Spribe, and Pocket Games Soft may receive a pseudonymous player identifier and session token to enable game delivery and to calculate game outcomes. They do not receive your full name, contact details, or financial data. |
| Anti-Fraud & AML Services | Specialist fraud-detection and anti-money-laundering screening providers receive transaction data and technical identifiers (IP address, device fingerprint) to assess risk and flag suspicious activity. |
| Legal & Regulatory Authorities | sa365 will disclose personal data to law enforcement agencies, regulatory bodies, or courts where required by a valid legal obligation, court order, or regulatory direction — and only to the extent mandated by that obligation. |
| Corporate Successors | In the event of a merger, acquisition, or sale of all or part of the sa365 business, your personal data may be transferred to the acquiring entity, which will be required to honour the terms of this Privacy Policy. |
All third parties with whom sa365 shares personal data are required to enter into a data-processing agreement that mandates they process your data only for the specified purpose, apply appropriate technical and organisational security measures, and refrain from any onward disclosure without sa365's prior written consent.
Clause 5
sa365 uses cookies and similar tracking technologies (including local storage objects and session tokens) to operate the platform, maintain your login session, remember your preferences, and gather analytics data. The categories of cookies we deploy are described below.
sa365 does not deploy third-party advertising cookies or retargeting pixels that share your browsing behaviour with external advertising networks. You may manage cookie preferences through your browser settings; however, disabling strictly necessary cookies will prevent you from logging in to your Account.
Clause 6
sa365 retains personal data for as long as is necessary to fulfil the purposes for which it was collected, having regard to applicable legal and regulatory retention obligations. The following retention periods apply as a general guide.
| Data Category | Retention Period |
|---|---|
| Account and Identity Data | For the duration of your active Account, plus a minimum of five years after account closure, to satisfy AML and regulatory record-keeping obligations. |
| KYC Documents | Five years from the date of submission, or longer where required by applicable AML regulations. |
| Transaction and Bet Records | Five years from the date of the transaction, consistent with standard financial record-keeping requirements. |
| Support Correspondence | Three years from the date of the last communication in the thread, or until the resolution of any related dispute — whichever is later. |
| Technical and Log Data | Twelve months on active systems; up to three years in secure, access-restricted archive storage for fraud and security investigations. |
| Marketing Consent Records | For the duration of your Account, plus two years after account closure, to demonstrate consent compliance in the event of a regulatory audit. |
Upon expiry of the applicable retention period, personal data is permanently deleted from active systems and any archive storage, or irreversibly anonymised so that it can no longer be associated with your identity.
Clause 7
sa365 implements a comprehensive set of technical and organisational security measures designed to protect your personal data against unauthorised access, accidental loss, destruction, or disclosure. Our security framework includes the following controls.
Your Role in Security: Technical controls can only go so far. You play an equally important role in protecting your Account. Use a strong, unique password for sa365, never share your credentials with anyone, log out after each session especially on shared devices, and contact support immediately at [email protected] if you suspect unauthorised access to your Account.
Clause 8
You hold the following rights with respect to your personal data held by sa365. To exercise any of these rights, submit a written request to [email protected] with the subject line "Data Rights Request" and your Account username. We will acknowledge your request within 48 hours and provide a full response within 30 calendar days.
Please note that certain rights — particularly erasure and data portability — may be limited where sa365 is required to retain data to comply with AML regulations, respond to a live dispute, or fulfil a legal obligation. We will always explain clearly if a limitation applies to your specific request.
Clause 9
The sa365 platform is strictly for adults aged 21 years and over. sa365 does not knowingly collect or process personal data belonging to any person under the age of 21. Our registration process includes an age declaration, and all accounts are subject to KYC age verification before withdrawals are permitted.
If sa365 discovers — through KYC, a third-party report, or any other means — that an Account holder is under 21 years of age, the following actions will be taken immediately:
Parents and guardians who believe a minor may have accessed sa365 without authorisation are encouraged to contact us immediately at [email protected] so that the account can be closed without delay. We also strongly recommend using parental control software to restrict access to gambling websites for minors in your household.
Clause 10
sa365 reserves the right to update or amend this Privacy Policy at any time to reflect changes in our data-processing practices, applicable law, regulatory guidance, or the services we offer. When a material change is made, we will notify registered users via email to their registered address and by displaying a prominent notice on the sa365 platform for a minimum of 14 days before the change takes effect.
The version number and "Last Updated" date at the top of this document will always reflect the most current version. Where the change is non-material (for example, a correction to a typographical error or a clarification that does not alter your rights or our obligations), we may update the document without prior notification, but the version date will still be revised.
Your continued use of the sa365 platform after the effective date of any updated Privacy Policy constitutes your acceptance of the revised terms. If you do not agree with the changes, you must stop using the platform and contact us to close your Account.
Clause 11
For any questions, concerns, or requests relating to this Privacy Policy or the personal data sa365 holds about you, please contact our data protection team using the details below. All privacy-related inquiries are handled by a dedicated compliance officer.
| Contact Channel | Details |
|---|---|
| Data Rights Email | [email protected] — use the subject line "Privacy / Data Rights Request" and include your Account username for faster routing. This address is plain text only and is not a clickable mailto link. |
| General Support | Live chat is available 24/7 within your sa365 Account dashboard after login. For privacy-specific matters, live chat agents will escalate your query to the compliance team within one business day. |
| Response Time | Privacy and data rights requests: acknowledgement within 48 hours; full written response within 30 calendar days. Urgent Account security matters (suspected data breach): within one hour via live chat. |