Overview & ; Introduction
This Privacy Policy ("Policy") governs the collection, processing, storage, and disclosure of personal data by qq801 (referred to throughout as "qq801", "we", "us", or "our") in connection with the operation of the qq801 online gaming platform accessible at qq801.club and all associated subdomains, mobile interfaces, and API endpoints.
qq801 is an internationally licensed gaming platform serving Members primarily across Indonesia — including Jakarta, Surabaya, Medan, Bandung, Bali, Yogyakarta, Semarang, and Makassar — as well as other permitted jurisdictions. This Policy applies to all individuals who access or interact with the qq801 platform in any capacity, including registered Members, prospective Members who begin but do not complete registration, and anonymous visitors to the qq801.club website.
This Policy is incorporated by reference into qq801's Terms & Conditions and forms part of the binding agreement between qq801 and each Member. Capitalised terms used but not defined in this Policy carry the meanings assigned to them in the Terms & Conditions.
If you do not agree with the practices described in this Policy, you must not create an account or continue using the qq801 platform. Continued use of the platform following any update to this Policy constitutes your acceptance of the revised version.
Personal Data We Collect
qq801 collects the minimum personal data necessary to deliver its services safely, comply with applicable regulatory obligations, prevent fraud, and maintain a fair gaming environment. The categories of personal data we may collect are set out in the table below:
| Data Category | Specific Data Points | Collected At |
|---|---|---|
| Identity Data | Full legal name, date of birth, nationality, government-issued ID number (KTP / passport / SIM number) | Registration; KYC verification |
| Contact Data | Email address, mobile phone number, city and province of residence (e.g., Jakarta, Surabaya, Bali) | Registration; account updates |
| Financial Data | Bank account name and number (BCA, BRI, BNI, Mandiri, CIMB Niaga, OCBC NISP); e-wallet identifiers (OVO, DANA, GoPay, ShopeePay, LinkAja); deposit and withdrawal history in IDR | First deposit; KYC verification; each transaction |
| KYC Documentation | Scanned or photographed copy of national ID (KTP), passport, or other government-issued document; proof of address; selfie with ID (where requested) | KYC verification process |
| Technical & Device Data | IP address, browser type and version, operating system, device identifiers, screen resolution, time zone (WIB / WITA / WIT), session tokens | Every platform visit |
| Behavioural & Usage Data | Pages visited, games played (slots, live casino, sportsbook), bet amounts and outcomes, session duration, click-path data, search queries within platform | During active sessions |
| Communication Data | Content of live chat transcripts, emails, and support ticket exchanges between you and qq801 support agents | Each support interaction |
| Responsible Gaming Data | Self-imposed deposit limits, loss limits, session reminders, self-exclusion periods and their durations | When tools are activated via account dashboard |
How We Collect Your Data
qq801 collects personal data through the following means:
- Direct submission: Data you actively provide when registering an account, completing KYC verification, making a deposit or withdrawal, contacting support, or updating your account profile.
- Automated technical collection: Data collected automatically as you interact with the qq801 platform — including IP addresses, device identifiers, session logs, and in-game activity — via server logs, cookies, web beacons, and similar tracking technologies. See Section 09 — Cookies & Tracking for full details.
- Third-party sources: Data received from authorised third parties who assist qq801 in delivering its services, including:
- KYC and identity verification service providers who cross-reference your submitted documents against official databases.
- Payment processors and banking partners (BCA, BRI, BNI, Mandiri, CIMB Niaga, OVO, DANA, GoPay, ShopeePay, LinkAja) who confirm transaction outcomes.
- Fraud prevention and anti-money laundering (AML) screening services that flag high-risk transaction patterns.
- Game studios (e.g., Pragmatic Play, Evolution Gaming, NetEnt, Microgaming, Pocket Games Soft, Spribe) whose platforms log in-game activity at the studio level under their own privacy frameworks.
Purpose of Processing
qq801 processes personal data only for specific, documented purposes. The table below maps each processing purpose to the data categories it relies on:
| Processing Purpose | Data Categories Used |
|---|---|
| Account creation and management | Identity, Contact |
| Age verification (21+ enforcement) | Identity, KYC Documentation |
| Payment processing (deposits and withdrawals in IDR) | Identity, Financial, KYC Documentation |
| KYC / AML compliance and fraud prevention | Identity, Financial, KYC Documentation, Technical & Device |
| Delivering and personalising gaming services | Behavioural & Usage, Technical & Device |
| Customer support and dispute resolution | Identity, Contact, Financial, Communication |
| Bonus and promotion administration | Identity, Financial, Behavioural & Usage |
| Responsible gaming tool operation | Responsible Gaming, Behavioural & Usage |
| Platform security, abuse prevention, and integrity monitoring | Technical & Device, Behavioural & Usage, Financial |
| Marketing communications (where consent is given) | Contact, Behavioural & Usage |
| Legal compliance and regulatory reporting | All categories as required by applicable law |
qq801 does not use your personal data for any purpose beyond those listed above without first obtaining your explicit consent or establishing a separate lawful basis for the new processing activity.
Legal Basis for Processing
qq801 relies on the following lawful bases when processing your personal data:
- Contractual necessity: Processing required to provide you with the qq801 platform services under our Terms & Conditions — including account creation, payment processing, game access, and customer support. Without this processing, we cannot deliver the service to you.
- Legal obligation: Processing required to comply with applicable laws and regulatory requirements, including anti-money laundering (AML) obligations, age verification mandates, financial record-keeping requirements, and responses to lawful requests from competent authorities.
- Legitimate interests: Processing undertaken to protect qq801's security, detect and prevent fraud, maintain platform integrity, and improve our services — provided those interests are not overridden by your fundamental privacy rights. Where we rely on legitimate interests, we document and review that balancing assessment.
- Consent: Processing for marketing communications, optional analytics, and any other purpose where consent is the appropriate basis. You may withdraw consent at any time by updating your communication preferences in your account dashboard or by contacting support at [email protected]. Withdrawal of consent does not affect the lawfulness of processing carried out before the withdrawal.
Data Sharing & Disclosure
qq801 may share your personal data with the following categories of recipients:
- Payment service providers: Banks and e-wallet operators (BCA, BRI, BNI, Mandiri, CIMB Niaga, OCBC NISP, OVO, DANA, GoPay, ShopeePay, LinkAja) receive your financial details and transaction data solely to process deposits and withdrawals in IDR on your behalf. These providers are bound by their own regulatory obligations and PCI-DSS standards.
- KYC and identity verification providers: Authorised third-party services that verify your identity documents and check your details against official registers and AML screening databases. These providers operate under strict confidentiality and data processing agreements.
- Game content studios: Studios such as Pragmatic Play, Evolution Gaming, NetEnt, Microgaming, Pocket Games Soft, and Spribe may receive anonymised player identifiers and game session data necessary to deliver their games within the qq801 platform. Full identity data is not transmitted to game studios.
- Platform technology and hosting providers: Cloud infrastructure, security, analytics, and customer support software providers who process data on qq801's behalf under data processor agreements that restrict their use of your data to performing services for qq801 only.
- Regulatory and law enforcement authorities: qq801 will disclose personal data to competent courts, regulators, or law enforcement agencies where required by a legally binding order, warrant, or regulatory mandate — or where disclosure is necessary to prevent imminent harm, fraud, or criminal activity.
- Business transfers: In the event of a merger, acquisition, or sale of all or a substantial portion of qq801's assets, your personal data may be transferred to the successor entity as part of that transaction. qq801 will notify affected Members of any such transfer and the applicable privacy terms of the successor entity prior to your data being subject to a different privacy policy.
Data Retention
qq801 retains personal data only for as long as necessary to fulfil the purposes for which it was collected, to comply with applicable legal retention obligations, and to resolve any disputes or enforce agreements. The following retention periods apply as standard minimums:
| Data Category | Standard Retention Period | Basis |
|---|---|---|
| Account and identity data | Duration of membership + 5 years after account closure | AML and regulatory compliance |
| KYC documentation | Duration of membership + 5 years after account closure | Legal obligation (AML/KYC regulations) |
| Financial transaction records | Duration of membership + 7 years after last transaction | Financial record-keeping requirements |
| Technical and device data | 13 months from collection date | Security and fraud prevention (legitimate interests) |
| Communication and support records | 3 years from date of last interaction | Dispute resolution and quality assurance |
| Marketing consent records | Until consent is withdrawn + 2 years | Proof of consent (legal obligation) |
| Self-exclusion records | Duration of exclusion + 5 years | Responsible gaming regulatory requirements |
Upon expiry of the applicable retention period, qq801 will securely delete or irreversibly anonymise the relevant personal data. Where anonymisation is performed, the resulting data set no longer constitutes personal data and may be retained indefinitely for statistical and product improvement purposes.
Data Security
qq801 implements a comprehensive set of technical and organisational security measures to protect your personal data against unauthorised access, accidental loss, destruction, alteration, or disclosure:
- Encryption at rest: Sensitive stored data — including KYC documents, financial records, and identity data — is encrypted at the database level using AES-256 encryption. Passwords are stored as salted cryptographic hashes and are never accessible in plaintext, even to qq801 employees.
- Access controls: Access to personal data is restricted on a strict need-to-know basis. qq801 staff access is governed by role-based permissions, multi-factor authentication (MFA) requirements, and comprehensive audit logging. Data access is reviewed and revalidated on a regular schedule.
- Network security: The qq801 platform is protected by enterprise-grade firewalls, web application firewall (WAF) filters, distributed denial-of-service (DDoS) mitigation, and real-time intrusion detection systems.
- Fraud and anomaly detection: Automated systems monitor transaction patterns, login behaviour, and in-game activity in real time to detect suspicious activity consistent with account takeover, identity fraud, or money laundering. Alerts trigger immediate review by the security team.
- Third-party security assessments: qq801 engages independent security professionals to conduct periodic penetration tests and vulnerability assessments of the platform infrastructure. Critical findings are remediated on a priority basis.
- Incident response: qq801 maintains a documented data breach response procedure. In the event of a confirmed breach materially affecting your personal data, qq801 will notify affected Members and relevant authorities within the timeframes required by applicable law.
While qq801 takes all reasonable technical and organisational measures to protect your data, no system is entirely immune to risk. You are responsible for maintaining the confidentiality of your qq801 account password and for logging out of your account on shared devices. Never share your password with any person, including qq801 support agents.
Cookies & Tracking Technologies
qq801 uses cookies and similar tracking technologies to operate and improve the platform, maintain your session state, and — where you have consented — to deliver personalised content and promotional communications. The following categories of cookies are deployed on the qq801 platform:
9.1 Strictly Necessary Cookies
These cookies are essential for the platform to function. They maintain your login session, preserve your language and currency preferences, and ensure security tokens are valid throughout your session. These cookies cannot be disabled without rendering the platform inoperable, and no consent is required for their use.
9.2 Functional Cookies
Functional cookies remember your account preferences — such as your preferred game lobby layout, responsible gaming settings, and notification preferences — across sessions. These cookies improve your experience but are not strictly required for platform operation. You may disable them via your browser settings, though doing so may affect platform functionality.
9.3 Analytics Cookies
With your consent, qq801 uses analytics cookies to measure platform usage — including pages visited, games played, session duration, and error events. This data is collected in aggregated, anonymised form and is used solely to understand and improve platform performance. Analytics data is never linked back to individual Member identities for marketing purposes.
9.4 Marketing Cookies
With your explicit consent, qq801 may deploy marketing cookies that allow us to deliver targeted promotional communications relevant to your gaming interests and activity patterns on the platform. You may withdraw consent for marketing cookies at any time by updating your preferences in the account dashboard or by contacting support.
Your Data Rights
As a Member of the qq801 platform, you hold the following rights in respect of your personal data. To exercise any of these rights, contact qq801's data protection team at [email protected] with your registered email address and a description of your request. qq801 will acknowledge your request within 5 business days and complete it within 30 calendar days, subject to verification of your identity.
- Right of Access: You may request a copy of all personal data that qq801 holds about you, along with information about how that data is processed, the purposes for which it is used, and with whom it has been shared.
- Right to Rectification: If any personal data held by qq801 about you is inaccurate or incomplete, you may request that it be corrected. Basic profile data (email address, phone number) can be updated directly from your account dashboard without contacting support.
- Right to Erasure ("Right to Be Forgotten"): You may request deletion of your personal data where it is no longer necessary for the purpose for which it was collected, where you have withdrawn consent and no other lawful basis applies, or where the data has been unlawfully processed. Note that certain data must be retained for mandatory legal periods (see Section 07) and cannot be erased upon request during those periods.
- Right to Restriction of Processing: You may request that qq801 restrict the processing of your personal data in certain circumstances — for example, while an accuracy dispute is being resolved, or pending the outcome of an objection to legitimate-interests processing.
- Right to Data Portability: Where processing is based on consent or contractual necessity and is carried out by automated means, you may request a machine-readable copy of the personal data you have provided to qq801, in a structured, commonly used format (e.g., JSON or CSV).
- Right to Object: You may object at any time to processing of your personal data carried out on the basis of qq801's legitimate interests. qq801 will cease such processing unless it can demonstrate compelling legitimate grounds that override your interests, rights, and freedoms.
- Right to Withdraw Consent: Where processing is based on consent, you may withdraw that consent at any time. Withdrawal does not affect the lawfulness of processing carried out prior to withdrawal.
- Right to Lodge a Complaint: If you believe qq801 has processed your personal data unlawfully or in violation of applicable privacy law, you have the right to lodge a complaint with a competent data protection authority in your jurisdiction.
Minors & Age Restriction Policy
qq801 applies mandatory age verification at account registration. Every Member must confirm their date of birth and consent to a KYC verification process that confirms their age against a government-issued identity document before any withdrawal from the account is permitted.
If qq801 becomes aware or has reasonable grounds to suspect that personal data has been collected from an individual under the age of 21 — whether through a misrepresentation at registration or through any other means — qq801 will:
- Immediately suspend the associated account pending investigation.
- Delete all personal data associated with the underage individual as promptly as is consistent with applicable legal obligations.
- Permanently close the account and forfeit any balance held therein in accordance with the Terms & Conditions.
- Report the matter to relevant authorities where required by applicable law.
If you believe that an individual under 21 has registered on the qq801 platform, please contact us immediately at [email protected] so that we can investigate and take appropriate action without delay.
Third-Party Services & Links
The qq801 platform integrates third-party services — including game studios, payment processors, and analytics providers — whose own privacy policies govern their collection and processing of data at their respective endpoints. qq801 is not responsible for the privacy practices of third-party services operating under their own frameworks, even where those services are embedded within or accessible from the qq801 platform interface.
qq801 selects third-party service providers carefully and requires, as a condition of engagement, that all providers who process personal data on qq801's behalf:
- Enter into a binding data processing agreement (DPA) with qq801 that restricts their use of Member data to providing services to qq801 only.
- Implement security standards equivalent to or exceeding those described in Section 08 of this Policy.
- Notify qq801 promptly of any data breach or security incident that may affect Member personal data processed on qq801's behalf.
- Delete or return all Member personal data upon termination of the service relationship, except where retention is required by applicable law.
qq801 does not permit third-party providers to use Member personal data for their own marketing, analytics, or product development purposes beyond what is explicitly agreed in the applicable DPA.
Updates to This Privacy Policy
qq801 reserves the right to update or revise this Privacy Policy at any time to reflect changes in applicable law, regulatory guidance, platform functionality, or our data processing practices. When material changes are made, qq801 will:
- Update the "Last Updated" date displayed at the top of this page.
- Display a notice within the Member's account dashboard for a minimum of 14 days following the effective date of the change.
- Where the change materially affects how we use your personal data in a way that requires fresh consent, send a notification to your registered email address and request your renewed consent before applying the new processing activity to your data.
Your continued use of the qq801 platform after the effective date of any revision constitutes acceptance of the updated Policy. If you do not agree with any revision, you must cease using the platform and request account closure by contacting [email protected] before the effective date of the change.
We recommend reviewing this Policy at least once every three months. The current version of this Privacy Policy supersedes all prior versions.
Contact & Data Protection Officer
For any questions, concerns, or requests related to this Privacy Policy or the processing of your personal data by qq801, please contact our Data Protection team through the following channels:
- Email: [email protected] — mark your subject line as "Privacy Request" for priority routing to the data protection team.
- Live Chat: Available 24/7 via your logged-in qq801 account dashboard. Indonesian-speaking agents are available on every shift to assist with privacy queries in Bahasa Indonesia or English.
- Response Time: qq801 will acknowledge privacy-related requests within 5 business days (WIB, UTC+7) and complete them within 30 calendar days, subject to identity verification.