At paso77, your personal data is treated with the same seriousness as your funds. This policy explains exactly what we collect, why we collect it, how we protect it, and the rights you hold over it.
paso77 has built data privacy into the architecture of its platform — not as a regulatory afterthought, but as a foundational trust commitment to every member.
Every data transmission between your device and paso77's servers is protected by 256-bit SSL/TLS encryption. Account credentials, payment details, and personal information are never transmitted in plain text under any circumstances.
paso77 does not sell, rent, or trade your personal data to third-party advertisers or data brokers. Your information is used exclusively to operate your account, process payments, comply with licensing obligations, and improve platform performance.
paso77 enforces strict internal access controls — only authorised personnel with a demonstrable operational need may access member data. Two-factor authentication (2FA) is available to all members and is strongly recommended as an additional account protection layer.
paso77 collects only the personal data that is strictly necessary for the purposes described in this policy. We do not collect data speculatively or beyond what is required to provide Services, comply with licensing requirements, and protect the platform.
Personal data is not retained indefinitely. paso77 applies defined retention periods to each data category, after which data is securely deleted or anonymised. Transaction records are retained for the minimum period required by our licensing authority.
As a paso77 member, you have the right to access, correct, and request deletion of your personal data. You may also object to certain processing activities or request a portable copy of your data. All requests are handled within 30 days of receipt.
paso77 collects personal data in four principal categories. Each category is collected for a specific, disclosed purpose — never beyond what is operationally necessary.
You retain meaningful control over your personal data at all times. The following rights may be exercised by contacting our Data Protection team at [email protected].
Request a full copy of the personal data paso77 holds about you, along with information on how it is being processed.
Request correction of any inaccurate or incomplete personal data held in your paso77 account profile.
Request deletion of your personal data where there is no compelling legitimate reason for paso77 to continue processing it.
Request that paso77 temporarily restrict processing of your personal data while a rectification or objection request is being reviewed.
Receive a structured, machine-readable copy of the personal data you provided to paso77, for transfer to another service.
Object to paso77 processing your personal data for direct marketing or other purposes based on legitimate interests.
For the purposes of this Privacy Policy, the following definitions apply:
paso77 is an internationally licensed offshore gaming platform operating at paso77.net, serving members across Indonesia including Jakarta, Surabaya, Medan, Bandung, Bali, Yogyakarta, and other cities. paso77 acts as the Data Controller in respect of all personal data collected through its platform and is responsible for ensuring that such data is processed lawfully, fairly, and transparently.
All data-related enquiries, access requests, and complaints should be directed to our support team using the contact details provided in Section 14 of this policy.
When you register an account with paso77, we collect your full legal name, date of birth, email address, and country/city of residence. This information is required to open and maintain your account, verify your age (21+ requirement), and communicate with you regarding your account activity.
To comply with our licensing obligations and prevent financial crime, paso77 may request copies of:
paso77 collects transaction data including deposit amounts, withdrawal requests, payment method identifiers (bank account numbers associated with BCA, BRI, BNI, Mandiri, CIMB Niaga, OCBC NISP, BSI, Bank Permata), and e-wallet identifiers (OVO, DANA, GoPay, ShopeePay, LinkAja). Full card numbers and full bank account numbers are never stored on paso77 servers; only masked identifiers are retained for transaction matching purposes.
paso77 automatically collects technical data when you access the Platform, including your IP address, device type, operating system, browser type and version, referring URL, pages viewed, session duration, and login timestamps. This data is used for security monitoring, fraud detection, platform optimisation, and responsible gaming analytics.
If you contact paso77 via live chat, email, or any other support channel, we retain records of that communication including the content of messages, timestamps, and the resolution outcome. This data is used to manage support requests and to improve service quality.
paso77 collects personal data through the following channels:
paso77 processes personal data only where a lawful basis exists. The table below sets out the primary purposes for which personal data is processed and the corresponding legal basis:
| Purpose | Data Categories Used | Legal Basis |
|---|---|---|
| Account registration and management | Identity, Contact | Performance of contract |
| Age and identity verification (KYC) | Identity, KYC documents | Legal obligation / Licensing requirement |
| Processing deposits and withdrawals | Financial, Identity | Performance of contract |
| Fraud prevention and security monitoring | Usage, Financial, Identity | Legitimate interests |
| Responsible gaming monitoring | Usage, Financial | Legal obligation / Legitimate interests |
| Customer support and dispute resolution | Identity, Communications | Performance of contract |
| Platform analytics and improvement | Usage (anonymised) | Legitimate interests |
| Regulatory compliance and audit | All categories | Legal obligation |
| Direct marketing communications | Contact, Usage | Consent (opt-in only) |
paso77 does not sell personal data. We may share personal data with the following categories of recipients, strictly on a need-to-know basis and subject to contractual data protection obligations:
To process deposits and withdrawals via Indonesian bank channels (BCA, BRI, BNI, Mandiri, and others) and e-wallets (OVO, DANA, GoPay, ShopeePay, LinkAja), paso77 shares the minimum financial data necessary with licensed payment processors. These processors are bound by strict confidentiality and data security obligations.
paso77 may share identity documents with licensed KYC and anti-money-laundering (AML) service providers for the purpose of verifying member identity and screening against sanctions lists and fraud databases. These providers act as Data Processors under written agreements with paso77.
Game studios such as Pragmatic Play, Evolution Gaming, NetEnt, Microgaming, Spribe, and Pocket Games Soft may receive limited usage data (e.g., session identifiers) necessary to deliver their game content. These studios do not receive personally identifiable information beyond what is strictly necessary for game delivery and RNG certification.
paso77 may disclose personal data to regulatory authorities, law enforcement agencies, or courts where required by law, court order, or our licensing obligations. paso77 will notify affected members of any such disclosure to the extent permitted by law.
In the event of a merger, acquisition, or sale of all or part of paso77's business, member personal data may be transferred to the acquiring entity as part of that transaction. Affected members will be notified of any change in Data Controller prior to the transfer taking effect.
paso77 operates internationally, and your personal data may be processed on servers located outside Indonesia. Where data is transferred to a jurisdiction that does not provide an equivalent level of data protection, paso77 implements appropriate safeguards including standard contractual clauses and data processing agreements to ensure your data remains protected to the standards described in this policy.
paso77 retains personal data only for as long as is necessary for the purposes for which it was collected, or as required by applicable law and licensing obligations. The following indicative retention periods apply:
| Data Category | Retention Period | Basis |
|---|---|---|
| Account and identity data | Duration of account + 5 years post-closure | Licensing / AML obligation |
| KYC documents | Duration of account + 5 years post-closure | Licensing / AML obligation |
| Financial transaction records | Duration of account + 5 years post-closure | Licensing / AML obligation |
| Betting and gaming history | Duration of account + 2 years post-closure | Dispute resolution / Legitimate interests |
| Customer support communications | 3 years from last interaction | Legitimate interests |
| Usage and technical logs | 13 months from collection | Security / Fraud prevention |
| Marketing consent records | Until consent is withdrawn + 1 year | Legal obligation (consent evidence) |
Upon expiry of the applicable retention period, personal data is securely deleted or irreversibly anonymised so that it can no longer be associated with any individual member.
paso77 implements a comprehensive suite of technical and organisational security measures to protect personal data against unauthorised access, loss, destruction, or alteration. These measures include:
paso77 uses the following categories of cookies and similar technologies when you access the Platform:
You may configure your browser to refuse non-essential cookies or to alert you when cookies are being set. Please note that disabling certain cookies may affect the functionality of the Platform, including your ability to log in or access certain game features. Instructions for managing cookies are available in your browser's help documentation.
The paso77 platform is strictly intended for adults aged 21 and over. paso77 does not knowingly collect personal data from anyone under the age of 21. If paso77 becomes aware that personal data has been collected from a person under the minimum age, that data will be deleted immediately and the associated account will be closed. If you believe a minor has registered on paso77, please contact us immediately at [email protected].
To exercise any of the rights described in this policy — including access, rectification, erasure, restriction, portability, or objection — please submit a written request to [email protected] with the subject line "Data Rights Request". You will need to verify your identity before your request can be processed.
paso77 will acknowledge your request within 5 business days and provide a substantive response within 30 calendar days of receipt. Where a request is complex or involves a large volume of data, this period may be extended by a further 30 days, and you will be notified of the extension with reasons.
There is no charge for exercising your data rights unless requests are manifestly unfounded or excessive, in which case paso77 reserves the right to charge a reasonable administrative fee or decline to act on the request.
paso77 reserves the right to update this Privacy Policy at any time to reflect changes in our data practices, operational requirements, or applicable law. Material changes will be communicated to registered members via email to the address on file and via a prominent notice on the Platform no less than seven (7) days before the changes take effect. The "Last Updated" date at the top of this document will be revised accordingly.
Your continued use of the Platform after the effective date of any amendment constitutes your acceptance of the revised Privacy Policy. If you do not accept the revised policy, you must close your account before the amendment takes effect.
For all privacy-related enquiries, data rights requests, or complaints regarding paso77's handling of your personal data, please contact us through the following channels:
paso77 aims to acknowledge all privacy-related enquiries within 24 hours (WIB, UTC+7) and to resolve complaints fully within 30 calendar days. If you are not satisfied with paso77's response, you may escalate the matter to the data protection authority or dispute resolution body associated with paso77's licensing jurisdiction.