Privacy vs Cookies
This page covers personal data overall; the cookie notice handles browser storage specifics. Consent choices flow between both, so a cookie opt-out also updates the marketing flag on your account profile.
This is the presidentoto privacy policy in plain language. We explain what account data we collect when you open a profile, why we hold it, how long it...
We process your personal data under the privacy rules of the jurisdictions where local law permits us to operate. That means your identity details, contact records, device fingerprints and transaction logs are held under encryption, accessed only by staff with a documented reason, and disclosed to third parties solely when a supported-region regulator compels it. We never sell your data. Marketing consent
is opt-in, revocable from your account page, and tracked with a timestamp so we can prove what you agreed to and when. Cross-border transfers between our processors stay inside contracts that mirror the protections you read here.
Service availability is jurisdiction-dependent. Users are responsible for checking local law before access.
If something in this policy is unclear, or you want to exercise a data right, these are the channels our privacy desk monitors.
Email our data team directly with subject-line tags like ACCESS, DELETE or CORRECT. We acknowledge within one working day and resolve substantive requests inside the statutory window.
Sign in, open the privacy panel and file a ticket. This route attaches your verified identity automatically, so we skip extra checks and process your request faster than email.
Our chat agents triage privacy questions around the clock. They can answer cookie, consent and retention queries directly, or escalate sensitive deletion requests to the named data protection contact.
This policy isn't a template. Real people review and sign off on it on a fixed cadence.
Every revision carries a date and a short change note at the foot of the page. You can scroll through prior versions to see what wording shifted and which clause was tightened.
Indonesian-qualified counsel reviews the policy twice a year, plus any time regulation shifts. Their sign-off is logged internally so we can show regulators which lawyer cleared which clause.
Our security team feeds in the encryption, access-control and retention specifics. The wording you read matches what's actually configured in our production systems, not an aspirational draft.
After legal sign-off, an editor strips jargon so clauses read at a normal reading level. If something still sounds like boilerplate, flag it to our privacy inbox and we'll reword it.
Questions raised through chat and the privacy inbox get logged. Recurring confusion drives the next revision, so the policy evolves with what you actually ask us about.
A real person is named as our data protection point. Their role, not a personal address, is published so requests survive staff changes without breaking the contact chain.
Our privacy policy lines up with the cookie, terms and account-closure pages. Here's how the pieces fit.
This page covers personal data overall; the cookie notice handles browser storage specifics. Consent choices flow between both, so a cookie opt-out also updates the marketing flag on your account profile.
Terms govern the service contract; privacy governs the data inside it. Where the two overlap — for example KYC — the privacy policy wording takes precedence on data handling.
KYC explains which documents we ask for; privacy explains how long we hold them, who sees them, and when they're purged. Read them together before you upload identity files.
Marketing preferences sit in your account panel. This policy explains the legal basis (consent) and your right to withdraw, which the preference toggles enforce on the messaging side.
Payment screens collect DANA, OVO, GoPay and QRIS references. This policy explains the retention of those references and which processors see them under contract.
Closing your account triggers the retention schedule described here. Some records survive closure because tax and anti-fraud law require it; the schedule lists exactly which.
If a privacy request stalls, the complaints page tells you how to escalate to the named contact and, where local law permits, to the supervisory authority in your region.
The layout of this policy is built for scanning. Here's what each block on the page is for.