nota4d Platform — Privacy Policy
This Privacy Policy ("Policy") describes how nota4d ("Company", "we", "us", "our"), the operator of the online gaming platform at https://nota4d.cam ("Platform"), collects, uses, stores, and discloses personal data relating to individuals who visit, register on, or otherwise interact with the Platform ("Users", "you", "your"). This Policy forms part of our broader Terms & Conditions and should be read alongside that document.
Your Consent: By accessing or using the Platform, you acknowledge that you have read and understood this Policy. Where we rely on your consent as the legal basis for processing your data, you may withdraw that consent at any time by contacting us at [email protected].
01 Definitions
| Term | Meaning |
|---|---|
| "Personal Data" | Any information that identifies or can reasonably be used to identify a living individual, directly or in combination with other data. |
| "Processing" | Any operation performed on Personal Data — including collection, storage, use, disclosure, transfer, or deletion. |
| "Data Controller" | nota4d, in its capacity as the entity that determines the purposes and means of processing Personal Data. |
| "Data Processor" | A third party that processes Personal Data on nota4d's behalf pursuant to a written data-processing agreement. |
| "Cookies" | Small text files placed on a User's device by the Platform to store session information and usage preferences. |
| "KYC" | Know Your Customer — the identity-verification process required before processing withdrawals or upon reasonable suspicion of fraud. |
02 Data We Collect
nota4d collects Personal Data through several channels. The categories of data we collect, and the circumstances under which we collect them, are set out below.
Data you provide directly:
- Registration data: full legal name, date of birth, residential address (including city — e.g., Jakarta, Surabaya, Bandung, Bali), email address, phone number, and chosen username.
- KYC documents: government-issued identity documents (national ID, passport, or driving licence), proof of residential address (utility bill, bank statement dated within 90 days), and — where required — payment-method verification documents.
- Financial data: bank account numbers or e-wallet identifiers (BCA, BRI, BNI, Mandiri, CIMB Niaga, OVO, DANA, GoPay, ShopeePay, LinkAja) used for deposits and withdrawals. We store only the minimum identifiers necessary to process and reconcile transactions; full payment credentials are handled exclusively by our approved payment processors.
- Communications: content of messages, emails, and chat transcripts exchanged with our support team. li>
Data collected automatically:
- Technical data: IP address, browser type and version, operating system, device identifiers, screen resolution, and language settings.
- Usage data: pages visited, session duration, clicks, scroll depth, search queries entered on the Platform, and navigation paths.
- Transaction data: deposit and withdrawal history, wager amounts, game selections, bet outcomes, bonus redemptions, and account balance changes.
- Cookie data: session tokens, preference settings, and analytics identifiers as described in Section 6 below.
Data from third parties:
- Payment providers: transaction confirmation references and fraud-screening signals from BCA, BRI, BNI, Mandiri, OVO, DANA, GoPay, ShopeePay, LinkAja, and other approved processors.
- Identity verification services: results of automated document checks performed by our KYC partners when verifying the authenticity of identity documents.
- Fraud prevention databases: watchlist results from anti-money-laundering and sanctions-screening services where we are legally required to check.
03 How We Use Your Data
nota4d uses the Personal Data we collect for the following specific purposes:
- Account management: to create, maintain, verify, and close your account on the Platform, including enforcing eligibility requirements (21+ age restriction, single-account rule).
- Service delivery: to process your deposits and withdrawals in Indonesian Rupiah (IDR/Rp), settle wagers, apply bonuses, and deliver all other Platform services.
- Identity verification (KYC): to confirm your identity, verify your age, and screen for fraud, money laundering, and sanctions-list matches as required by applicable law and our licensing obligations.
- Customer support: to respond to your queries, investigate complaints, and resolve disputes in a timely and accurate manner.
- Security and fraud prevention: to detect and prevent unauthorized access to your account, identify suspicious patterns of activity, and protect the integrity of the Platform.
- Responsible gaming: to monitor gameplay patterns that may indicate problem gambling and to apply deposit limits, session time-outs, or self-exclusion measures where required or requested.
- Legal compliance: to meet our obligations under applicable anti-financial-crime, data protection, and gaming regulations, and to respond to lawful requests from law-enforcement or regulatory authorities.
- Service improvement: to analyze aggregated usage data for the purpose of improving Platform performance, user experience, and the relevance of game offerings.
- Marketing communications: to send you promotional offers, bonus notifications, and event announcements by email or in-platform message — only where you have opted in to receive such communications and only in relation to nota4d services.
Marketing Opt-Out: You may withdraw consent to marketing communications at any time by clicking "Unsubscribe" in any marketing email or by contacting support at [email protected]. Withdrawal of marketing consent does not affect your ability to use the Platform.
04 Legal Basis for Processing
For each category of processing described in Section 3, nota4d relies on one or more of the following legal bases:
- Contract performance: processing that is necessary to deliver the services described in our Terms & Conditions — including account management, transaction processing, and customer support.
- Legal obligation: processing required to comply with applicable anti-money-laundering law, KYC regulations, sanctions screening, and lawful requests from competent authorities.
- Legitimate interests: processing for fraud prevention, security monitoring, Platform improvement, and responsible-gaming interventions — provided these interests are not overridden by your fundamental rights and freedoms.
- Consent: processing for direct marketing communications and the use of non-essential cookies — both of which require your active opt-in and may be withdrawn at any time.
05 Data Sharing & Disclosure
nota4d does not sell, rent, or trade your Personal Data to third parties for their own commercial purposes. We may, however, share your Personal Data with the following categories of recipient in the circumstances described below:
- Payment processors and banking partners: BCA, BRI, BNI, Mandiri, CIMB Niaga, BSI, Bank Permata, OVO, DANA, GoPay, ShopeePay, and LinkAja — strictly to process deposits and withdrawals and reconcile transaction records.
- KYC and identity-verification providers: third-party services that perform automated document authenticity checks and database screening on our behalf under a binding data-processing agreement.
- Game studios and software providers: Pragmatic Play, Evolution Gaming, Microgaming, Pocket Games Soft, Spribe, and similar certified studios receive only the minimum session data required to operate their games securely on our Platform.
- Fraud prevention and AML services: screening databases and risk-scoring engines used to detect financial crime. Data shared with these services is handled under strict contractual confidentiality obligations.
- Professional advisors: lawyers, auditors, and insurers who are bound by confidentiality obligations and require access to specific data to provide their services to nota4d.
- Law enforcement and regulators: where nota4d is required by law, court order, or regulatory instruction to disclose your data. We will notify you of such disclosure to the extent we are legally permitted to do so.
- Business transfers: in the event of a merger, acquisition, or sale of substantially all of nota4d's assets, your Personal Data may be transferred to the acquiring entity, subject to the same protections described in this Policy.
All third-party Data Processors engaged by nota4d are required to enter into a written data-processing agreement that imposes obligations at least equivalent to those in this Policy. nota4d remains responsible for ensuring that any Data Processor handles your data lawfully.
06 Cookies & Tracking Technologies
nota4d uses cookies and similar tracking technologies on the Platform. These technologies fall into the following categories:
- Essential cookies: strictly necessary for the Platform to function — they manage your login session, store your account preferences, and maintain the security of your connection. These cannot be disabled without impairing Platform functionality.
- Analytics cookies: help us understand how Users navigate the Platform by collecting aggregated, anonymized data about page views, session durations, and feature usage. We use this data solely to improve Platform performance.
- Preference cookies: remember choices you have made — such as your preferred language display or notification settings — so you do not need to re-enter them on each visit.
- Marketing cookies: used only where you have provided explicit consent. These may help us understand whether you engaged with a promotional communication and reached the Platform as a result.
You may manage cookie preferences through your browser settings. Most modern browsers allow you to refuse all non-essential cookies or to delete existing cookies at any time. Please note that disabling essential cookies will affect your ability to log in and use the Platform. For detailed browser-specific instructions, refer to your browser's help documentation.
07 Data Retention
nota4d retains Personal Data only for as long as necessary to fulfill the purposes for which it was collected, or as required by applicable law. Our standard retention periods are as follows:
- Active account data: retained throughout the life of your account and for a minimum of 5 years following account closure, in order to satisfy anti-money-laundering record-keeping requirements.
- KYC documents: retained for a minimum of 5 years from the date of verification or account closure, whichever is later.
- Transaction records: retained for a minimum of 5 years from the date of each transaction to support financial audit and regulatory compliance.
- Support communications: retained for 3 years from the date of closure of the relevant support ticket, unless the content relates to an ongoing legal matter.
- Marketing data: retained until you withdraw consent or for a maximum of 2 years from your last interaction with a marketing communication, whichever is earlier.
- Analytics data: retained in aggregated, anonymized form indefinitely; no personally identifiable information is retained beyond the periods stated above.
Upon expiry of the applicable retention period, nota4d will securely delete or irreversibly anonymize your Personal Data. Where deletion is not immediately practicable due to technical constraints, the data will be isolated from active systems and quarantined pending deletion at the earliest opportunity.
08 Your Data Rights
Subject to applicable law and certain limitations, you have the following rights over your Personal Data held by nota4d:
Right of Access
Request a copy of the Personal Data we hold about you and details of how it is being used.
Right to Rectification
Request correction of inaccurate or incomplete Personal Data without undue delay.
Right to Erasure
Request deletion of your Personal Data where we no longer have a lawful basis to retain it.
Right to Object
Object to processing based on our legitimate interests or for direct marketing purposes.
Right to Restriction
Request that we limit processing of your data while a complaint or accuracy dispute is resolved.
Right to Portability
Receive your data in a structured, machine-readable format and transmit it to another controller.
To exercise any of the above rights, please submit a written request to [email protected] with the subject line "Data Rights Request". We will respond within 30 days of receiving your request. We may need to verify your identity before processing any request. Where a request is complex or numerous, we may extend this period by a further 30 days, of which we will notify you.
Limitations: Your right to erasure and right to portability do not apply where we are required by law to retain data — for example, transaction records held under anti-money-laundering regulations. In such cases we will explain the relevant legal basis when responding to your request.
09 Data Security
nota4d implements a layered set of technical and organizational security measures to protect your Personal Data against unauthorized access, disclosure, alteration, or destruction. These measures include:
- Transport-layer encryption: all data transmitted between your device and the Platform is protected by TLS 1.2 or higher (256-bit SSL).
- Encryption at rest: sensitive data fields — including identity documents, payment identifiers, and KYC records — are encrypted in storage using AES-256 or equivalent standards.
- Access controls: Personal Data is accessible only to nota4d staff and Data Processors who have a legitimate need to process it. All access is subject to role-based authorization, multi-factor authentication, and comprehensive audit logging.
- Password security: user passwords are stored as salted cryptographic hashes. We never store or transmit passwords in plain text.
- Vulnerability management: the Platform is subject to regular penetration testing, code reviews, and patch management processes to minimize the risk of exploitation by malicious actors.
- Incident response: nota4d maintains a documented incident-response procedure. In the event of a data breach that presents a material risk to your rights and freedoms, we will notify affected Users without undue delay.
While we take every reasonable measure to protect your data, no internet-based system can be guaranteed 100% secure. You are also responsible for maintaining the security of your own account credentials and for notifying us promptly at [email protected] if you suspect any unauthorized access to your account.
10 Age Restriction & Minors
The Platform is strictly restricted to individuals who are 21 years of age or older. nota4d does not knowingly collect Personal Data from individuals under 21. If we discover or are notified that we have collected Personal Data from a minor, we will immediately suspend the relevant account, delete all associated Personal Data to the extent permitted by law, and — where applicable — report the matter to the relevant authority.
If you are a parent or guardian and believe that a minor has registered on the Platform using your details or their own, please contact us immediately at [email protected] with the subject line "Minor Account Report". We will investigate and act on such reports with the highest priority.
11 International Data Transfers
nota4d operates with the primary goal of serving players in Indonesia (principally those in Jakarta, Surabaya, Bandung, Bali, Medan, Yogyakarta, and other major cities). The majority of data processing is carried out in data centers operating under appropriate security standards.
In some cases, Personal Data may be transferred to or accessed by third-party service providers — such as KYC platforms, cloud infrastructure providers, or game studios — that are located outside Indonesia. Where such transfers occur, nota4d takes appropriate steps to ensure that your data is afforded a level of protection consistent with this Policy, including through:
- Standard contractual clauses or equivalent data-transfer mechanisms incorporated into Data Processor agreements.
- Transfers only to service providers that maintain recognized security certifications (ISO/IEC 27001 or equivalent) and are subject to contractual data-protection obligations.
If you would like further information about the specific safeguards in place for any international transfer of your data, please contact us at [email protected].
12 Changes to This Policy
nota4d reserves the right to update or revise this Privacy Policy at any time to reflect changes in our data practices, regulatory requirements, or Platform features. When material changes are made, we will:
- Update the "Last updated" date at the top of this page.
- Where reasonably practicable, notify registered Users by email or via an in-platform notification prior to the change taking effect.
- For significant changes — such as a new category of data collection or a new purpose — seek fresh consent where our legal basis requires it.
Your continued use of the Platform after the effective date of a revised Policy constitutes your acknowledgment of the updated terms. We recommend bookmarking this page and reviewing it periodically. The current version of this Policy always supersedes all prior versions.
13 Contact & Data Inquiries
For any questions, concerns, or requests relating to this Privacy Policy or the handling of your Personal Data by nota4d, please reach out through the following channel:
- Email: [email protected] (plain text — not a clickable link)
- Subject line for data inquiries: "Privacy / Data Rights Request"
- Response time: Typically within 24 hours; data rights requests fulfilled within 30 days
- Support hours: 24 hours a day, 7 days a week — Indonesian-speaking and English-speaking agents available
- Time zone: Support operations coordinated in WIB (Western Indonesia Time, UTC+7)
If you are not satisfied with our response to a data-rights request, you have the right to escalate your complaint through the applicable dispute-resolution mechanism referenced in our Terms & Conditions.
Privacy in Practice
Six Ways nota4d Protects Your Data
Our Privacy Policy is backed by concrete technical and organizational measures. Here is what that commitment looks like from your perspective as a nota4d player.
256-Bit SSL Encryption
Every byte of data traveling between your browser and nota4d's servers is protected by TLS 1.2 or higher. Whether you are depositing via BCA or checking your account balance, your connection is encrypted end-to-end.
Minimal Data Collection
We collect only the Personal Data that is strictly necessary for the stated purpose. We do not build advertising profiles, sell your data to brokers, or share information with any party beyond those described in this Policy.
Secure KYC Handling
Identity documents submitted for KYC verification are encrypted at rest and accessible only to authorized verification staff. Documents are retained only for the minimum statutory period and then securely deleted.
Your Rights, Actionable
Access, correct, port, or request deletion of your Personal Data by sending a single email to our support team. We respond within 30 days and verify your identity before processing any request — because your rights should be easy to use.
Regular Security Audits
nota4d's Platform undergoes scheduled penetration testing and independent code reviews. Identified vulnerabilities are prioritized and patched before they can be exploited — keeping your account and funds protected around the clock.
Marketing Opt-Out Anytime
We only send promotional emails where you have explicitly opted in. Opting out is instant — one click in any marketing email or a single message to our support team. Your in-game access is never affected by your marketing preferences.
Continue Reading
Questions About nota4d?
Our FAQ covers the most common questions about accounts, payments, security, and game rules. Our Terms & Conditions explain the full legal framework governing your use of the Platform. If you have a specific data request, our support team is available 24/7 — including Indonesian-speaking agents.