ciatoto link Platform Privacy Notice

This page describes what we collect when you use ciatoto link and how we keep that data protected. We collect personal information to verify your identity, process payments via DANA, e-wallet, mobile banking, local payment, online payment, e-wallet, mobile banking, local payment, online payment, and e-wallet, detect fraud, and provide customer support. Your data is encrypted, stored securely, and shared only with authorized processors and regulators.

Our privacy practices comply with data-protection principles: we collect only what is necessary, use data only for stated purposes, and retain it only as long as required by law or our legitimate business needs. We do not sell or rent your personal information to third parties for marketing.

Read this policy to understand your rights, how to request access to your data, and how to contact us with privacy concerns.

What Data We Collect on ciatoto link

When you register on ciatoto link, we collect your email address and a password you create. If you proceed to real-money play, we require identity verification (KYC). At that point, we collect:

  • Full legal name, date of birth, and government ID number (KTP, passport, or driver's licence).
  • Proof of residence (utility bill, bank statement, or rental agreement dated within three months).
  • Phone number for SMS-based two-factor authentication (2FA) and account recovery.
  • Residential address and, optionally, workplace information.
  • Photographs (of your ID and a selfie) for identity verification.

We also collect interaction data automatically: your IP address, browser type, device identifier (IMEI, Android ID, or iOS IDFA), operating system, login times, games played, bets placed, deposits and withdrawals, support tickets, and communication logs. We use cookies and similar tracking technologies to remember your preferences and detect fraudulent activity.

We collect data to comply with anti-money-laundering (AML) law

Our identity verification, transaction monitoring, and record-keeping practices on ciatoto link are required by financial-crime regulations. We cannot process deposits or withdrawals without completing KYC.

How We Use Your Data on ciatoto link

We use the data we collect on ciatoto link for the following purposes:

  • Account verification and KYC: We verify your identity to comply with AML and counter-terrorist-financing (CTF) regulations.
  • Payment processing: We share your name, ID, and transaction details with payment processors (DANA, e-wallet, mobile banking, local payment, online payment, e-wallet providers, and mobile banking, local payment, online payment, e-wallet banks) to execute deposits and withdrawals.
  • Fraud prevention: We analyze transaction patterns, device data, and IP addresses to detect suspicious activity, unauthorized access, and cheating.
  • Customer support: We use your contact details and account history to respond to queries, resolve disputes, and handle account issues.
  • Legal compliance: We retain records for tax purposes, respond to court orders and regulatory subpoenas, and comply with anti-money-laundering requirements.
  • Service improvement: We analyze usage patterns to improve ciatoto link features, security, and user experience.

Who We Share Your Data With

We share your personal data only with authorized partners and when required by law:

  • Payment processors: We share your name, ID, bank account details, and transaction amounts with mobile banking, local payment, online payment, e-wallet, mobile banking, local payment, online payment, e-wallet, mobile banking, local payment providers to execute transfers.
  • Identity-verification vendors: We share photos and ID numbers with third-party companies that verify identities using facial recognition, database checks, and document validation.
  • Fraud-detection services: We share transaction data and device information with vendors that flag suspicious patterns and detect money laundering.
  • Regulators and law enforcement: We comply with court orders, government subpoenas, and AML/CTF reporting requirements. We may not be able to inform you of such requests.
  • Service providers: We use third-party cloud hosting, customer-support platforms, and analytics tools. These vendors are contractually bound to protect your data.
Note: We do not sell your data to marketers or advertisers. Our service vendors are used only to provide ciatoto link functionality and comply with law.

Data Storage and International Transfer

ciatoto link servers may be located outside your jurisdiction (e.g., in Singapore, South Korea, or Europe). By using ciatoto link, you consent to the transfer of your data to these locations. We encrypt all data in transit (TLS 1.3) and at rest (AES-256) to protect against unauthorized access during storage and transmission.

We retain your personal data as follows: account details (email, password hash) are retained for as long as your account is active plus seven years thereafter for tax and compliance purposes. Transaction records are retained for five to seven years per financial-crime regulations. Photos and identity documents are archived after verification and may be deleted after seven years unless a legal hold applies.

Cookies and Tracking on ciatoto link

We use cookies and similar technologies (local storage, pixels, web beacons) to:

  • Remember your login session and preferences.
  • Detect and prevent fraud and account takeover.
  • Track which games you play to improve recommendations.
  • Measure analytics (pages visited, time spent, conversion events).

Most cookies expire after 30 days of inactivity. You can disable cookies in your browser settings, but this may limit ciatoto link functionality. Third-party cookies (from analytics, ads, or fraud vendors) may also be placed; you can manage these via your browser's privacy settings or the "Do Not Track" header.

Your Rights Regarding Your ciatoto link Data

Depending on your jurisdiction, you may have the following rights:

  • Right of access: You can request a copy of all personal data we hold about you.
  • Right of correction: You can request that we correct inaccurate or incomplete data.
  • Right of erasure: You can request deletion of your data, subject to legal retention requirements (tax, AML, dispute resolution).
  • Right to restrict processing: You can ask us to limit how we use your data (though core functions like fraud prevention may continue).
  • Right to portability: You can request your data in a portable format (e.g., CSV).
  • Right to object: You can object to certain uses, such as analytics or communications.

To exercise these rights, email [email protected] with your request and account details. We respond within 30 days. We may ask for additional information to verify your identity before processing your request.

Data Breach and Security

We employ industry-standard security measures: encryption, firewalls, intrusion detection, access controls, and regular security audits. However, no system is entirely secure. If a data breach occurs, we will notify affected users and relevant authorities as required by law within a reasonable timeframe (typically 30 days).

If you suspect unauthorized access to your ciatoto link account, change your password immediately, enable 2FA if available, and contact our support team. We investigate breaches and, if necessary, reset compromised accounts and offer credit monitoring where applicable.

Children and ciatoto link

ciatoto link is not intended for children or minors. We do not knowingly collect data from individuals below the age of majority in their jurisdiction. If we discover that a minor has registered, we close the account and delete their personal data (except where legally required to retain records). If you are aware of a minor using ciatoto link, contact us immediately at [email protected].

Policy Updates

We may update this privacy policy at any time. Material changes are communicated via email or in-app notification. Continued use of ciatoto link after changes are posted constitutes acceptance of the updated policy. We encourage you to review this policy periodically, especially before major events like Liga 1, Piala Indonesia, or major holidays (Idul Fitri, Idul Adha, Imlek, Nyepi), when usage may spike and our data practices may expand.

Contact Us About Your Privacy

If you have questions about our privacy practices, want to exercise your data rights, or have a privacy complaint, reach out to our data protection team:

  • Email: [email protected]
  • Postal address: Available upon request to [email protected]
  • Response time: We aim to respond within 30 business days. Responses may be delayed during public holidays.

For legal inquiries, data breach reports, or regulatory complaints, contact our legal team at [email protected]. For general support, use the in-app chat or SMS.

ciatoto link is committed to protecting your privacy and complying with applicable data-protection law. We collect data only as necessary, process it transparently, and give you control over your information. Your trust is important to us, and we take that responsibility seriously.

Legal and Jurisdiction Information

Service availability

Service availability

ciatoto link is available only in jurisdictions where local law permits the provision and use of our platform for online gaming and sports wagering. We do not operate in jurisdictions where online gambling or wagering is prohibited by law. Availability varies by country, territory, and municipality; we do not publicly list specific regions as "legal" or "illegal." Instead, users are entirely responsible for verifying the legal status of ciatoto link in their own location before creating an account or depositing funds. Our terms of service and this privacy notice explicitly place this responsibility on users. If you are uncertain about your jurisdiction's laws regarding online gaming or the use of ciatoto link, we recommend consulting a qualified legal advisor or your local regulatory authority for guidance. We monitor major regulatory and legal changes affecting our service in key markets and may restrict or suspend service to any region at any time if we determine that local law requires it. Service interruptions due to regulatory changes, legal orders, or government intervention may occur with minimal notice, and we do not guarantee service continuity in any jurisdiction. We reserve the right to exit any market with reasonable notice (typically 30 days). If regulatory restrictions are imposed on your region or jurisdiction after you have created an account, we may freeze your account, limit access to funds, or facilitate withdrawal of remaining account balance according to applicable law. Funds may be withheld or delayed pending legal resolution if authorities intervene or impose restrictions. We comply with all lawful legal processes, including court orders, regulatory subpoenas, and law-enforcement requests. We may not be able to inform affected users of such legal requests due to confidentiality restrictions imposed by law or government directive.

Account eligibility

Account eligibility

To create and maintain an account on ciatoto link, you must comply with all applicable laws in your jurisdiction governing age of majority, legal capacity, and eligibility to enter into binding contracts with online gaming platforms. We do not specify a fixed age threshold (such as "") because age-of-majority and gaming-eligibility laws differ significantly by jurisdiction. You are solely and entirely responsible for ensuring you meet your own jurisdiction's legal requirements before registering on ciatoto link or depositing funds. During account creation, you confirm and warrant that you satisfy all applicable legal criteria. When you proceed to real-money play, we conduct identity verification (KYC) and compliance checks to satisfy anti-money-laundering (AML) and counter-terrorist-financing (CTF) regulatory requirements. If we later determine that your account violates local law, our terms of service, or our policies, we may suspend or permanently close your account without advance notice, subject to any mandatory local due-process requirements or legal obligations. All account holders must provide truthful, complete, and accurate identity information and keep contact details current. Failure to provide accurate information, or if we cannot verify your identity through our KYC process within a reasonable timeframe, may result in account activation delays, suspension of deposit and withdrawal features, or account closure. Minors and individuals lacking legal capacity in their jurisdiction are strictly prohibited from using ciatoto link. Users with criminal convictions for fraud, money laundering, terrorist financing, or other financial crimes may be denied account creation or have existing accounts closed. We reserve the right to deny account access, refuse service, or close accounts if we have reasonable suspicion of non-compliance with law, regulatory breach, policy violation, suspicious transaction patterns, use of third-party funding sources, or multiple account creation.

Local-law responsibility

Local-law responsibility

Users acknowledge and fully agree that they are solely responsible for understanding and complying with all laws, regulations, tax obligations, and legal requirements applicable to them in their own jurisdiction. ciatoto link does not provide legal advice, and we make no representations or warranties about whether our services are lawful in any specific location. Before accessing or using ciatoto link, you must independently verify that such access and use are permitted under the laws of your country, state, province, municipality, or other applicable jurisdiction. Laws governing online wagering, gaming, gambling, and betting vary widely across the world and change frequently. Your jurisdiction may restrict or prohibit online gambling, ban use by non-residents, restrict certain payment methods, prohibit specific game types, or require licensing not held by ciatoto link. Taxes on gaming winnings or other ciatoto link earnings may apply in your location; you are solely responsible for calculating, reporting, and paying any such taxes. We do not withhold taxes on your behalf unless explicitly required by local law to do so. If your jurisdiction later restricts or prohibits our services, or if local law requires us to cease operations or modify our service model, you accept the risk that your account may be frozen, funds may be withheld pending legal resolution, access may be terminated without liability, or service may be discontinued with reasonable notice. We do not guarantee uninterrupted service and reserve the right to exit any market with reasonable notice. Your account data, records, and transaction history related to users in restricted jurisdictions may be archived, retained for regulatory purposes, or deleted per applicable law and our data retention policies. You waive and release ciatoto link from any and all claims related to service interruptions, account restrictions, or access terminations resulting from legal changes or jurisdictional restrictions.

Data and privacy scope

Data and privacy scope

ciatoto link collects and processes personal data to fulfill legal obligations, provide our services, and protect against fraud and financial crime. For basic accounts (Free Play), we collect minimal data: email address and optional phone number. For real-money accounts, we collect comprehensive data: full legal name, date of birth, government ID number or passport details, residential address, photographs (ID and selfie), proof of residence, and complete transaction history including all deposits, withdrawals, bets, and game activity. We also collect device information (IP address, browser type, device identifiers, operating system, mobile network) and detailed interaction logs (login timestamps, session duration, games played, bets placed, affiliate codes, support interactions). This data is used for account verification and KYC compliance, payment processing and settlement, fraud prevention and financial-crime detection, customer support and dispute resolution, legal compliance (tax, AML, CTF), service improvements, and (where permitted by law) communications and service updates. We share data with payment processors, identity-verification vendors, fraud-detection services, cloud infrastructure providers, and regulatory authorities as required by law or contract. Our full data-handling practices are detailed in our main privacy policy. We employ encryption (TLS 1.3 in transit, AES-256 at rest), access controls, firewalls, intrusion detection, and regular security audits to protect data. However, no system is entirely secure; we cannot guarantee absolute protection against unauthorized access. If a data breach occurs, we will notify affected users and relevant authorities as required by law. You have the right to request access to your data, correct inaccuracies, request deletion (subject to legal retention), restrict processing, and object to certain uses. Contact [email protected] to exercise these rights. Data retention periods vary: transactional records are retained for five to seven years per tax and AML regulations; account details for seven years after account closure; and identity documents may be archived for seven years unless a legal hold applies.

Contact for legal inquiries

Contact for legal inquiries

If you have legal questions, data-protection concerns, privacy complaints, or wish to contact our legal and compliance team, you may reach us through multiple channels. Email [email protected] for formal legal inquiries or legal notices. Email [email protected] for privacy-related concerns, data-access requests, deletion requests, or data-protection complaints. Email [email protected] for AML/CTF compliance matters, suspicious transaction reports, or regulatory inquiries. Please include a clear description of your issue, any relevant account information or transaction details, your preferred contact method, supporting documentation if applicable, and specific details about what you are requesting. We aim to respond to legal and privacy enquiries within five to seven business days during Indonesian business hours (Monday to Friday, 08:00–17:00 Western Indonesia Time). Responses may be delayed during public holidays (Idul Fitri, Idul Adha, Imlek, Nyepi, and others) or during high-volume periods. We will confirm receipt of your enquiry and provide an estimated response timeline. For urgent matters such as account compromise, fraud reports, security breaches, or data-protection emergencies, use our priority support channel (in-app alert or SMS) and clearly mark your communication as urgent. We maintain a data-protection officer who oversees regulatory adherence, data-processing governance, and compliance audits. We comply with valid legal process, including court orders, regulatory subpoenas, government warrants, and law-enforcement requests, as required by applicable law. We may not be able to inform you of such legal requests due to confidentiality restrictions imposed by law or government directive. Our legal team does not provide personal legal advice; for jurisdiction-specific guidance on gaming laws or data protection, consult a qualified attorney. All enquiries are handled confidentially to the extent permitted by law and necessary for service delivery.