Reference

Our Legal Terms for koinbola Accounts

koinbola operates under a clear legal framework designed to protect your account, your data, and your rights as a user in Indonesia — where local law permits.

Account Terms & ConditionsPrivacy & Data PolicyDANA, OVO, GoPay, QRIS Usage RulesJurisdiction: IndonesiaUser Rights & Contact Paths
koinbola Our Legal Terms for koinbola Accounts
LEGAL CONTACT PATHS

Reach Our Legal and Compliance Team

If you have a question about our terms, want to request a copy of your data, or need to raise a legal concern, we keep three direct contact paths open. Our compliance team handles formal requests separately from general customer support so your legal query reaches the right person without delay.

Team online

Live Chat — Legal Queries

Open a live-chat session labelled 'Legal / Compliance' from the Help menu on your account dashboard. Available 09:00–23:00 WIB daily; a compliance agent joins within ten minutes during those hours.

Email — Data & Policy Requests

Send formal data-access or account-deletion requests to our compliance mailbox. We acknowledge every email within 24 hours and deliver a full response within seven working days, in line with our data-retention policy.

In-Account Help Centre

Navigate to Settings › Legal & Privacy on desktop or mobile to download the current terms PDF, submit a data-portability request, or flag a policy concern — no need to leave your account dashboard.

DATA AND SECURITY PRACTICES

How koinbola Protects Your Account and Data

We apply concrete security and data-handling measures across every layer of your account — from the moment you register to every DANA or GoPay transaction you make.

Encrypted Data Storage

All personally identifiable information — name, registered mobile number, email — is stored using AES-256 encryption. Only authorised compliance personnel can access raw records, and access logs are reviewed every 30 days.

Cookie Policy

We use session cookies to keep you logged in and analytics cookies to measure page performance. You can review and withdraw cookie consent at any time through the Cookie Preferences panel in your account settings.

Account Security Layers

Two-factor authentication via SMS OTP is available on every account. We also enforce automatic session logout after 30 minutes of inactivity on desktop and 15 minutes on mobile to reduce unauthorised-access risk.

Data Retention Schedule

Transaction records are kept for five years; account-activity logs for two years; marketing-preference data until you withdraw consent. After retention periods expire, data is deleted from live servers within 90 days.

Third-Party Data Sharing

We share data only with payment processors — DANA, OVO, GoPay, QRIS — and identity-verification partners required for account opening. We do not sell your data to advertising networks or unaffiliated third parties.

Rights Requests and Response Times

You may request data access, correction, or deletion at any time via email or the in-account Legal Centre. We complete access requests within seven working days and deletion requests within fourteen, subject to retention obligations.

Answers to Common Legal Questions

The questions below come directly from account holders asking about their rights, our policies, and how we handle specific legal situations. Each answer is specific to how koinbola operates in Indonesia.

Access to koinbola depends on local law. Where local law permits, you may open and use an account fully. If your region imposes specific restrictions, those rules apply to you and override our platform-level terms — please verify your local regulations before registering.

Submit a data-access request via your account's Settings › Legal & Privacy panel or email our compliance team directly. We acknowledge the request within 24 hours and deliver a full data export in a machine-readable format within seven working days.

Yes. Send a deletion request through the in-account Legal Centre or our compliance email. We action account closure within 14 days. Transaction records required for audit purposes are retained for five years as required by our data-retention schedule, then permanently deleted.

Payment-gateway data — including DANA and OVO transaction references — is stored encrypted for five years to support dispute resolution and audits. We do not store full card or wallet credentials; tokenised references handled by each payment provider remain under their own security policy.

We send an email to your registered address at least 14 days before any policy update takes effect. A notice banner also appears on your account dashboard during the notice period. Continuing to use the platform after the effective date means you accept the updated terms.

Open a live-chat session labelled 'Legal / Compliance' between 09:00 and 23:00 WIB, or email our compliance mailbox with a written summary of your concern. We acknowledge formal disputes within 24 hours and aim to resolve them within 10 working days.

We share data only with the payment processors needed to complete your DANA, OVO, GoPay or QRIS transactions and with identity-verification services required at account opening. We do not share or sell your data to advertising networks or unaffiliated commercial partners.