Scope of This Policy: This Privacy Policy applies to all personal data collected and processed by gg382 in connection with its online gaming platform at https://gg382.net. It applies to all Members who have registered accounts, to visitors who browse the site without registering, and to any individual who contacts gg382 customer support. By using the gg382 platform, you consent to the practices described in this policy.
1 Definitions
For the purposes of this Privacy Policy, the following terms carry the meanings set out below:
- "gg382", "we", "us", or "our" refers to the operator of the online gaming platform accessible at https://gg382.net and all associated subdomains and services.
- "You", "the Member", or "the User" refers to any natural person who accesses, browses, registers on, or otherwise interacts with the gg382 platform.
- "Personal Data" refers to any information that identifies or could reasonably be used to identify a living natural person, including but not limited to name, date of birth, email address, phone number, IP address, device identifier, bank account number, and transaction history.
- "Processing" refers to any operation performed on Personal Data, including collection, storage, retrieval, use, disclosure, transmission, erasure, or destruction.
- "Data Controller" refers to gg382 as the entity that determines the purposes and means of processing your Personal Data.
- "Data Processor" refers to any third party that processes Personal Data on behalf of gg382, including payment processors, KYC verification providers, and cloud infrastructure providers.
- "KYC" (Know Your Customer) refers to the identity verification process required to confirm the identity, age, and residency of Members prior to processing withdrawal transactions above specified thresholds.
- "Cookies" refers to small text files stored on your device by the gg382 platform, used to maintain session state, remember preferences, and analyze platform usage.
2 Data We Collect
gg382 collects Personal Data across several categories, depending on the nature of your interaction with the platform. The following table summarizes the categories of data we collect and the typical source of each:
| Data Category |
Examples |
Source |
| Identity Data |
Full legal name, date of birth, gender, nationality |
Provided by you during registration or KYC |
| Contact Data |
Email address, Indonesian mobile phone number, city of residence |
Provided by you during registration |
| Financial Data |
Bank account name and number (BCA, BRI, BNI, Mandiri, etc.), e-wallet identifiers (OVO, DANA, GoPay, ShopeePay, LinkAja), deposit and withdrawal amounts |
Provided by you during deposit/withdrawal transactions |
| Identity Verification Data |
Government-issued ID document (KTP), selfie photograph for liveness check |
Provided by you during KYC verification |
| Transaction Data |
Bet history, game session records, win/loss records, bonus usage history, deposit and withdrawal records |
Generated automatically through platform use |
| Technical Data |
IP address, browser type and version, device type, operating system, screen resolution, time zone (WIB/WITA/WIT) |
Collected automatically via cookies and server logs |
| Usage Data |
Pages visited, games played, session duration, click patterns, referral source |
Collected automatically via platform analytics |
| Communications Data |
Records of live chat conversations, support email correspondence, complaint submissions |
Generated when you contact gg382 customer support |
| Marketing Preference Data |
Promotional opt-in or opt-out status, preferred contact channel, bonus preference history |
Provided by you or inferred from platform interactions |
We do not intentionally collect special categories of sensitive data such as racial or ethnic origin, political opinions, religious beliefs, biometric data (beyond the liveness photograph required for KYC), or health data, unless you choose to disclose such information voluntarily in a support communication.
3 How We Collect Your Data
gg382 collects your Personal Data through the following mechanisms:
- Direct submission: Data you actively provide when completing the registration form, submitting a KYC document, making a deposit or withdrawal request, filling in a support query, or updating your account profile.
- Automated collection: Technical and Usage Data collected automatically when you visit or interact with the gg382 platform, via server logs, session cookies, and analytics tools operated by gg382.
- Third-party sources: In limited circumstances, we may receive data from our payment processing partners (e.g., confirmation that a bank transfer from a named BCA or Mandiri account was completed) or from our KYC verification service providers (e.g., identity document authentication results). We do not purchase personal data from data brokers.
- Inferred data: Where permitted, we may infer certain preferences or risk indicators from your platform behavior (e.g., game category preferences, responsible gaming risk signals) to provide you with a safer and more relevant experience.
4 Legal Basis for Processing
gg382 processes your Personal Data on one or more of the following legal bases:
- Contractual necessity: Processing required to fulfill the contractual obligations created when you register an account and agree to our Terms & Conditions — including identity verification, transaction processing, and account management.
- Legal obligation: Processing required to comply with applicable laws and regulations, including anti-money laundering (AML) obligations, record-keeping requirements, and fraud prevention measures mandated by the jurisdiction under which gg382 holds its international gaming license.
- Legitimate interests: Processing undertaken to pursue gg382's legitimate business interests where those interests are not overridden by your rights — including platform security monitoring, fraud detection, responsible gaming analytics, and product improvement.
- Consent: Where we rely on your consent (e.g., for marketing communications or non-essential cookies), you may withdraw that consent at any time without affecting the lawfulness of processing carried out prior to withdrawal. Withdrawal of consent does not affect your ability to maintain and use your gg382 account.
5 How We Use Your Data
gg382 uses your Personal Data for the following purposes:
- Account creation and management: To register your account, verify your identity and age (21+ requirement), and maintain your account profile throughout your membership.
- Transaction processing: To process deposits and withdrawals via BCA, BRI, BNI, Mandiri, CIMB Niaga, Bank Permata, OVO, DANA, GoPay, ShopeePay, and LinkAja, and to maintain accurate financial records of all transactions.
- KYC verification: To verify that you meet the eligibility requirements set out in our Terms & Conditions, including age, identity, and residency, before processing high-value or first-time withdrawal requests.
- Fraud prevention and security: To detect, investigate, and prevent fraudulent activity, money laundering, multi-accounting, bonus abuse, and unauthorized account access.
- Customer support: To respond to your queries, resolve disputes, process complaints, and provide assistance through our 24/7 Indonesian-speaking support team.
- Responsible gaming: To monitor account activity for signs of problem gambling behavior and to enforce deposit limits, cooling-off periods, and self-exclusion requests in accordance with our Responsible Gaming policy.
- Platform improvement: To analyze usage patterns, identify technical issues, and improve the performance, stability, and user experience of the gg382 platform.
- Marketing communications: Where you have opted in, to send you promotional offers, bonus notifications, and updates about new games or features relevant to your interests. You may opt out at any time.
- Legal compliance: To comply with applicable laws, respond to lawful requests from competent authorities, and enforce our Terms & Conditions.
No Automated Decision-Making: gg382 does not use fully automated decision-making processes that produce legal or similarly significant effects on individual Members without human review. Where automated tools assist in fraud detection or responsible gaming risk assessment, a trained team member reviews any resulting action before it is applied to your account.
6 Data Sharing & Disclosure
gg382 does not sell, rent, or trade your Personal Data to third parties for their own commercial purposes. We share your data only in the following limited circumstances:
- Payment processors: Your financial data (bank account details, transaction amounts) is shared with our payment gateway partners — including processors that facilitate transfers via BCA, BRI, BNI, and Mandiri — strictly to execute deposit and withdrawal transactions on your behalf.
- KYC and identity verification providers: Identity and document data submitted during KYC is shared with our contracted identity verification service provider, which authenticates documents and performs liveness checks on our behalf under strict data processing agreements.
- Fraud prevention and AML partners: We may share Technical Data and transaction patterns with specialist fraud prevention and anti-money laundering screening services to protect the platform and comply with legal obligations.
- Cloud infrastructure providers: Personal Data is stored on servers operated by our contracted cloud hosting provider. This provider acts as a Data Processor and is bound by a data processing agreement that prohibits it from accessing or using your data for any purpose other than infrastructure provision.
- Game software providers: Limited Technical Data (e.g., session tokens and game result logs) may be shared with our licensed game studios — including Pragmatic Play, Evolution Gaming, and Pocket Games Soft — solely for the purpose of delivering and auditing game outcomes. These providers do not receive your identity or financial data.
- Legal and regulatory authorities: We may disclose Personal Data to competent government authorities or law enforcement agencies when required to do so by applicable law, court order, or lawful regulatory request.
- Business succession: In the event of a merger, acquisition, or sale of substantially all assets of gg382, your Personal Data may be transferred to the acquiring entity, subject to the same privacy protections described in this policy. We will notify affected Members before any such transfer takes effect.
7 International Data Transfers
gg382 operates internationally and some of our Data Processors are located outside Indonesia. When your Personal Data is transferred to a country that does not provide the same level of data protection as the jurisdiction under which gg382 is licensed, we ensure that appropriate safeguards are in place, including:
- Contractual data transfer agreements between gg382 and the receiving processor that impose data protection obligations equivalent to those described in this policy.
- Selection of processors that maintain internationally recognized security certifications (e.g., ISO/IEC 27001) and comply with applicable data protection frameworks.
- Regular review of our processor relationships to confirm that adequate protections remain in place.
By using the gg382 platform, you acknowledge that your Personal Data may be transferred to and processed in countries outside Indonesia as described above.
8 Data Retention
gg382 retains your Personal Data for no longer than is necessary for the purposes for which it was collected, subject to the following retention periods:
| Data Category |
Retention Period |
Basis |
| Identity & Contact Data |
Duration of account plus 5 years after closure |
AML record-keeping obligation |
| Financial & Transaction Data |
Duration of account plus 5 years after closure |
AML and financial audit obligation |
| KYC Verification Data |
Duration of account plus 5 years after closure |
Regulatory compliance |
| Technical & Usage Data |
13 months from collection date |
Fraud detection and platform analytics |
| Customer Support Records |
3 years from the date of the last interaction |
Dispute resolution and quality assurance |
| Marketing Preference Data |
Until consent is withdrawn or account is closed |
Consent |
| Cookie Data (non-essential) |
Up to 12 months from placement |
Consent |
Upon expiry of the relevant retention period, Personal Data is securely deleted or anonymized such that it can no longer be attributed to an identifiable individual. Anonymized aggregate data (e.g., statistical reports on platform usage) may be retained indefinitely.
9 Cookies & Tracking Technologies
gg382 uses the following categories of cookies on the platform:
- Strictly Necessary Cookies: Required for the platform to function correctly. These include session authentication cookies, security tokens, and load-balancing cookies. They cannot be disabled without impairing platform functionality.
- Functional Cookies: Used to remember your preferences, such as your preferred language setting or recently viewed game categories. These improve your experience but are not essential for basic operation.
- Analytics Cookies: Used by gg382's internal analytics tools to measure how Members navigate and use the platform. This data helps us improve the layout, performance, and content of the site. We use first-party analytics only; we do not embed third-party advertising analytics networks.
gg382 does not use advertising cookies, behavioral profiling cookies, or social media tracking pixels. You can manage or disable non-essential cookies through your browser's privacy settings. Disabling analytics cookies will not affect your ability to use any core platform feature.
No Third-Party Ad Networks: gg382 does not share your browsing behavior with advertising networks or data brokers. The cookies placed on your device by gg382 are operated by gg382 directly and serve only the purposes described above.
10 Your Rights as a Data Subject
As a Member of gg382, you hold the following rights with respect to your Personal Data. To exercise any of these rights, please submit a written request to [email protected] from the email address registered to your account.
Right of Access
Request a copy of all Personal Data we hold about you and information about how it is being processed.
Right to Rectification
Request correction of any inaccurate or incomplete Personal Data held in your account.
Right to Erasure
Request deletion of your Personal Data where it is no longer necessary for the purpose for which it was collected, subject to legal retention obligations.
Right to Restrict Processing
Request that we limit how we use your data in certain circumstances, for example while a rectification request is being assessed.
Right to Data Portability
Receive a copy of your Personal Data in a structured, machine-readable format for transfer to another service provider.
Right to Object
Object to processing based on legitimate interests, including the use of your data for marketing communications or certain analytics activities.
gg382 will respond to all data subject requests within 30 calendar days of receipt. Where a request is complex or involves a large volume of data, we may extend this period by a further 30 days, in which case we will notify you of the extension and the reason for it. There is no charge for exercising your rights, except where requests are manifestly unfounded or excessive.
11 Data Security
gg382 implements a comprehensive set of technical and organizational security measures to protect your Personal Data against unauthorized access, disclosure, alteration, or destruction. These measures include:
- Transport Layer Security (TLS): All data transmitted between your device and the gg382 platform is encrypted using 256-bit SSL/TLS protocols, preventing interception in transit.
- Encryption at rest: Sensitive data fields — including financial account numbers and identity document references — are encrypted at rest in our database systems using industry-standard encryption algorithms.
- Access controls: Access to Personal Data is restricted to gg382 employees and contractors on a strict need-to-know basis. Role-based access controls, multi-factor authentication, and audit logging are enforced on all systems that process Personal Data.
- Security monitoring: gg382 operates continuous security monitoring and intrusion detection systems. All access to production systems is logged and reviewed for anomalous activity.
- Third-party audits: We conduct periodic penetration testing and security audits conducted by independent third parties to identify and remediate vulnerabilities in our infrastructure.
- Incident response: In the event of a confirmed data security incident that poses a risk to your rights, gg382 will notify affected Members without undue delay and take all reasonable steps to contain and remediate the breach.
While gg382 takes all reasonable precautions to protect your data, no internet-based platform can guarantee absolute security. You are responsible for maintaining the confidentiality of your account credentials and for ensuring that your own device and network connection are adequately secured.
12 Children & Minors
The gg382 platform is strictly intended for adults aged 21 years and above. We do not knowingly collect Personal Data from individuals under the age of 21. If we discover that Personal Data belonging to a person under 21 has been collected — whether through registration with a false date of birth or any other means — we will immediately:
- Suspend and close the account in question.
- Void all wagers placed and forfeit any associated funds in accordance with our Terms & Conditions.
- Permanently delete all Personal Data associated with the underage account as quickly as technically feasible, subject to any overriding legal retention obligation.
Parents and guardians who have reason to believe that a minor has accessed gg382 using falsified information are encouraged to contact our support team immediately at [email protected] so that the matter can be addressed without delay.
13 Amendments to This Policy
gg382 reserves the right to update this Privacy Policy at any time to reflect changes in our data practices, legal obligations, or platform features. When material changes are made, we will provide notice by one or more of the following methods:
- Publishing the updated Privacy Policy on this page with a revised "Last Updated" date.
- Sending a notification to the email address registered to your gg382 account.
- Displaying an in-platform notice upon your next login following the amendment.
Your continued use of the gg382 platform after notification of an amendment constitutes your acceptance of the updated Privacy Policy. We encourage you to review this page periodically so that you remain informed about how we protect your data.
14 Contact & Complaints
If you have any questions about this Privacy Policy, wish to exercise your data subject rights, or want to raise a privacy-related concern, please contact the gg382 privacy team using the details below. All formal privacy communications must be submitted in writing.
gg382 Privacy & Support Contact:
[email protected]
Response Time: Data subject rights requests are acknowledged within 3 business days and resolved within 30 calendar days of receipt. General privacy queries are typically answered within 24–48 hours (WIB).
Support Hours: 24 hours a day, 7 days a week, including Indonesian public holidays such as Idul Fitri, Nyepi, and Idul Adha.
gg382 takes all privacy complaints seriously. If you are not satisfied with our response to a complaint, you may escalate the matter through the dispute resolution process described in our Terms & Conditions. Please note that gg382 will make every reasonable effort to resolve privacy disputes directly before any escalation to an external body is required.
For account-specific requests such as data access, correction, or deletion, please include your registered username and a description of your request when contacting us, so that we can verify your identity and process your request efficiently.