Your Privacy, Our Commitment
sm065 applies six core data-protection principles across every system, process, and team that handles Member information. These principles are non-negotiable and form the foundation of everything described in this policy.
Full Transparency
We tell you exactly what data we collect, why we collect it, and who we share it with — before we collect it, not after. No hidden data practices, no buried disclosures.
Purpose Limitation
Data collected for account registration is never repurposed for unrelated marketing. Data collected for KYC verification is never used for profiling. Each data type has a single, declared purpose.
Data Minimisation
sm065 collects only the minimum data necessary to deliver each service. We do not request information we do not need. Surplus data is promptly deleted once its purpose is fulfilled.
Robust Security
All Member data is stored on encrypted servers protected by 256-bit SSL, multi-factor access controls, and continuous intrusion monitoring. KYC documents are isolated in a dedicated secure vault.
Member Rights First
You can request access to, correction of, or deletion of your personal data at any time. sm065 responds to all verified data requests within 30 calendar days with no charge to the Member.
No Data Sales
sm065 has never sold, rented, or auctioned Member personal data to any third party, and never will. Your information is used solely to operate, improve, and secure the sm065 platform.
Definitions
For the purposes of this Privacy Policy, the following terms carry the meanings set out below:
| Term | Meaning |
|---|---|
| "Personal Data" | Any information that directly or indirectly identifies a living individual — including name, National Identity Card (KTP) number, email address, IP address, device identifier, financial account details, and behavioral data tied to an identifiable person. |
| "Processing" | Any operation performed on Personal Data, including collection, storage, retrieval, use, disclosure, transmission, restriction, erasure, or destruction. |
| "Data Controller" | The entity that determines the purposes and means of processing Personal Data. For the purposes of this policy, the Data Controller is sm065 and its operating entity. |
| "Data Processor" | A third party that processes Personal Data on behalf of the Data Controller under a binding contractual agreement — for example, a payment gateway or a cloud infrastructure provider. |
| "Member" / "You" | Any individual who has registered an account on sm065 or who accesses the sm065 platform in any capacity. |
| "KYC" | Know Your Customer — the mandatory identity and document verification process required before a Member may withdraw funds or access higher account tiers. |
| "Cookie" | A small text file placed on your device by the sm065 platform for the purposes of session management, analytics, preference storage, or targeted content delivery. |
Data Controller
sm065 acts as the Data Controller for all Personal Data collected through the platform at https://sm065.org. As Data Controller, sm065 is responsible for ensuring that all Personal Data is processed in a lawful, fair, and transparent manner consistent with internationally recognised data-protection principles and the applicable regulatory framework under which sm065 holds its international gaming licence.
Where sm065 engages third-party Data Processors — such as payment gateway providers (BCA, BRI, BNI, Mandiri, OVO, DANA, GoPay, ShopeePay, LinkAja), cloud hosting infrastructure providers, or identity-verification service providers — those processors operate under binding contractual data-processing agreements that impose data-security and confidentiality obligations no less stringent than those described in this policy.
All inquiries, access requests, and complaints regarding the processing of your Personal Data by sm065 should be directed to our Data Protection contact as described in Clause 15 of this policy.
Data We Collect
sm065 collects Personal Data across several categories depending on how you interact with the platform. The following table summarises the categories of data we collect, along with examples of specific data points within each category:
| Category | Examples of Data Collected |
|---|---|
| Identity Data | Full legal name, date of birth, nationality, Indonesian National Identity Card (KTP) number, passport number, driver's licence number. |
| Contact Data | Email address, mobile phone number, residential address (city, province — e.g., Jakarta, Surabaya, Bandung, Bali, Yogyakarta). |
| Financial Data | Bank account name and number (BCA, BRI, BNI, Mandiri, CIMB Niaga, BSI, Bank Permata), e-wallet identifiers (OVO, DANA, GoPay, ShopeePay, LinkAja), transaction history, deposit and withdrawal amounts in IDR. |
| Account Data | Registered username, encrypted password hash, account registration date, account status, responsible gaming limits set by the Member. |
| Transactional Data | Betting history, casino game records, wager amounts, outcomes, bonus claims, wagering requirement progress. |
| Technical Data | IP address, device type and operating system, browser type and version, session timestamps, referring URL, geolocation data (country/region level). |
| Communication Data | Live chat transcripts, support ticket content, email correspondence with sm065 customer support, voluntary survey responses. |
| KYC Document Data | Scanned or photographed copies of government-issued identity documents submitted for account verification. |
How We Collect Data
sm065 collects Personal Data through the following channels:
- Direct Collection — Registration: When you create an account on sm065, you provide Identity Data and Contact Data directly via the registration form.
- Direct Collection — KYC Submission: When you submit identity documents to complete KYC verification, you provide Identity Data and KYC Document Data directly.
- Direct Collection — Deposits and Withdrawals: When you initiate a financial transaction, you provide Financial Data including your bank account or e-wallet details.
- Direct Collection — Customer Support: When you contact sm065 via live chat or email, you provide Communication Data voluntarily as part of the support interaction.
- Automated Collection — Platform Usage: When you browse or use the sm065 platform, Technical Data (IP address, device identifiers, session data) is collected automatically through server logs and cookies. See Clause 10 for full details on cookie usage.
- Automated Collection — Gameplay: All betting and gaming activity on sm065 is automatically logged as Transactional Data for game integrity, dispute resolution, responsible gaming monitoring, and regulatory purposes.
- Third-Party Sources: sm065 may receive limited identity or fraud-risk data from third-party KYC verification providers and payment processors where such data is necessary to complete a transaction or comply with anti-money-laundering obligations.
Purposes of Processing
sm065 processes Personal Data only for the specific, declared purposes listed below. We do not process Personal Data in any manner incompatible with these stated purposes:
| Purpose | Data Categories Used |
|---|---|
| Account creation and management | Identity Data, Contact Data, Account Data |
| Identity and age verification (KYC) | Identity Data, KYC Document Data |
| Processing deposits and withdrawals | Financial Data, Identity Data |
| Delivering sportsbook, casino, and slot services | Account Data, Transactional Data, Technical Data |
| Fraud prevention and security monitoring | Technical Data, Financial Data, Transactional Data |
| Responsible gaming monitoring and enforcement | Account Data, Transactional Data, Communication Data |
| Customer support | Identity Data, Account Data, Communication Data |
| Compliance with anti-money laundering (AML) obligations | Identity Data, Financial Data, KYC Document Data |
| Platform analytics and improvement | Technical Data, Transactional Data (aggregated/anonymised) |
| Promotional communications (where consent is given) | Contact Data, Account Data |
Legal Basis for Processing
sm065 relies on the following legal bases for processing Personal Data, as recognised under internationally accepted data-protection frameworks:
- Contractual Necessity: Processing required to perform the contract between sm065 and the Member — including account management, KYC verification, deposit and withdrawal processing, and game delivery. Without this processing, sm065 cannot provide its services.
- Legal Obligation: Processing required to comply with applicable law, including anti-money laundering (AML) regulations, fraud prevention obligations, and any lawful request from a competent regulatory authority or court.
- Legitimate Interests: Processing necessary for the legitimate interests pursued by sm065, where those interests are not overridden by the Member's fundamental rights — including fraud detection, platform security monitoring, and aggregate analytics used to improve sm065 services.
- Consent: Processing carried out on the basis of the Member's freely given, specific, and informed consent — primarily for direct marketing communications such as promotional emails and bonus notifications. Members may withdraw consent at any time by contacting customer support or by using the communication preferences settings within their account dashboard.
Data Sharing
sm065 does not sell, rent, or trade your Personal Data. We share Personal Data only with the categories of third parties listed below, and only to the extent strictly necessary for the stated purpose:
- Payment Processors: Bank transfer and e-wallet providers (BCA, BRI, BNI, Mandiri, CIMB Niaga, BSI, Bank Permata, OVO, DANA, GoPay, ShopeePay, LinkAja) receive Financial Data and Identity Data solely to process deposits and withdrawals on your behalf.
- KYC Verification Providers: Third-party identity-verification services receive KYC Document Data solely to authenticate identity documents and perform age and sanction-list checks.
- Game Studios and Platform Providers: Licensed game studios (including Evolution Gaming, Pragmatic Play, NetEnt, Microgaming, Pocket Games Soft, and Spribe) receive a minimum pseudonymous session token necessary to launch game instances. No full Personal Data is transmitted to game studios.
- Cloud Infrastructure Providers: Data hosting, backup, and content delivery network partners process Technical Data and stored Personal Data as part of platform infrastructure. These providers operate under strict data-processing agreements.
- Regulatory and Law-Enforcement Bodies: sm065 will disclose Personal Data to competent regulatory authorities, law enforcement agencies, or courts where required to do so by a valid legal obligation, court order, or regulatory direction.
- Fraud Prevention Networks: In cases of suspected fraud, money laundering, or match-fixing, sm065 may share relevant Transactional Data and Identity Data with fraud prevention consortia or gaming integrity bodies.
Data Retention
sm065 retains Personal Data for no longer than is necessary to fulfil the purpose for which it was collected, or as required by applicable legal and regulatory obligations. The following retention periods apply:
| Data Category | Retention Period |
|---|---|
| Account and Identity Data | For the duration of the active account relationship, plus 5 years following account closure — to meet AML record-keeping requirements. |
| KYC Document Data | 5 years from the date of verification, or 5 years from account closure, whichever is later. |
| Financial Transaction Data | 5 years from the date of each transaction, in compliance with financial record-keeping obligations. |
| Transactional / Gameplay Data | 3 years from the date of each recorded session, used for dispute resolution and responsible gaming review. |
| Technical / Log Data | 12 months from collection, unless retained longer in connection with an active fraud or security investigation. |
| Communication / Support Data | 3 years from the date of the support interaction, used for service quality review and dispute resolution. |
| Marketing Consent Records | Until consent is withdrawn, plus 2 years thereafter as a record of the consent lifecycle. |
Upon expiry of the applicable retention period, Personal Data is securely deleted or anonymised in accordance with sm065's internal data-destruction procedures. Anonymised aggregate data (containing no individually identifiable information) may be retained indefinitely for statistical and platform-improvement purposes.
Data Security
sm065 implements a multi-layered security architecture designed to protect Personal Data against unauthorised access, accidental loss, alteration, or disclosure. Key security measures include:
- Encryption in Transit: All data exchanged between your device and sm065 servers is encrypted using TLS 1.2 or higher (256-bit SSL). This applies to all page loads, API calls, deposit flows, and live chat sessions.
- Encryption at Rest: Personal Data and KYC documents stored on sm065 servers are encrypted at rest using AES-256 encryption. KYC documents are stored in an isolated vault with restricted access.
- Access Controls: Access to Personal Data within sm065's internal systems is restricted on a strict need-to-know basis, enforced through role-based access control (RBAC), multi-factor authentication (MFA) for all privileged accounts, and comprehensive access logging.
- Intrusion Detection: sm065 operates continuous intrusion detection and anomaly monitoring systems that alert the security team to unusual access patterns, potential data exfiltration attempts, and credential-stuffing attacks.
- Vulnerability Management: The sm065 platform undergoes regular penetration testing and security audits by qualified third-party security professionals. Critical vulnerabilities are remediated within 72 hours of discovery.
- Data Breach Response: In the event of a confirmed Personal Data breach that presents a material risk to affected Members, sm065 will notify impacted Members without undue delay and will take immediate remediation steps. A full incident report will be made available upon request.
Cookies & Tracking Technologies
sm065 uses cookies and similar tracking technologies to operate the platform effectively, personalise your experience, and analyse platform performance. The following categories of cookies are used:
| Cookie Type | Purpose |
|---|---|
| Strictly Necessary | Required for core platform functionality — login session management, security tokens, load balancing. These cookies cannot be disabled without breaking platform functionality. |
| Functional | Store your preferences such as language settings, display options, and responsible gaming limit configurations so that they persist between sessions. |
| Analytical / Performance | Collect aggregated, anonymised data about how Members navigate the platform — which pages are visited most, where sessions end, and how long game sessions last. Used solely to improve sm065 platform performance and user experience. |
| Security / Fraud Detection | Collect device fingerprint and behavioral signals used to detect fraudulent login attempts, bot activity, and account-takeover attacks. |
Managing Cookies: You may control cookie settings through your browser preferences. Note that disabling Strictly Necessary cookies will prevent you from logging in to your sm065 account and using core platform features. Disabling Functional or Analytical cookies will not prevent platform access but may affect your personalized experience.
sm065 does not use advertising cookies or share cookie data with third-party ad networks. No cross-site tracking for advertising purposes is conducted on the sm065 platform.
Your Rights
As a Member of sm065, you hold the following rights with respect to your Personal Data. sm065 will respond to all verified rights requests within 30 calendar days at no charge:
Right of Access
Request a copy of all Personal Data sm065 holds about you, together with a description of how it is being used and with whom it has been shared.
Right of Rectification
Request correction of any inaccurate or incomplete Personal Data held in your account. For KYC data, corrections require re-submission of valid documents.
Right to Erasure
Request deletion of your Personal Data where it is no longer necessary for the purposes for which it was collected, subject to legal retention obligations under AML and financial regulations.
Right to Restriction
Request that sm065 restricts processing of your Personal Data — for example, while the accuracy of data is being contested or while an objection to processing is being assessed.
Right to Portability
Request that sm065 provides your Personal Data in a structured, machine-readable format (CSV or JSON) so that it can be transferred to another platform or service provider.
Right to Object
Object to processing of your Personal Data carried out on the basis of legitimate interests or for direct marketing purposes. sm065 will cease such processing unless compelling legitimate grounds can be demonstrated.
Right to Withdraw Consent
Where processing is based on your consent (e.g., promotional emails), you may withdraw that consent at any time. Withdrawal does not affect the lawfulness of processing carried out before withdrawal.
Right to Complain
If you believe sm065 has processed your Personal Data unlawfully, you have the right to lodge a complaint with sm065's Data Protection contact or with the competent supervisory authority in your jurisdiction.
International Data Transfers
sm065 operates with cloud infrastructure and third-party service providers that may be located in jurisdictions outside Indonesia. Where Personal Data is transferred to a country that does not provide an equivalent level of data protection, sm065 ensures that appropriate safeguards are in place prior to any transfer. These safeguards include:
- Contractual Protections: All international data processors operate under binding data-processing agreements that incorporate standard contractual clauses requiring the processor to maintain data-protection standards equivalent to those described in this policy.
- Technical Safeguards: Data transmitted across borders is encrypted in transit using TLS 1.2 or higher, ensuring that the data cannot be intercepted or read in an unencrypted state during transfer.
- Adequacy Assessment: Before engaging any new international processor, sm065 conducts a transfer impact assessment to evaluate the legal and technical data-protection standards of the destination jurisdiction and the specific processor.
By using sm065 and accepting this Privacy Policy, you acknowledge that your Personal Data may be transferred to, stored, and processed in jurisdictions outside Indonesia as described above. sm065 remains fully responsible for your Personal Data regardless of where it is processed.
Minors — 21+ Requirement
During the account registration process, all applicants are required to confirm that they are at least 21 years of age. This declaration is reinforced by the mandatory KYC identity verification process, which requires submission of a government-issued identity document confirming date of birth.
If sm065 discovers — through KYC review, account monitoring, or a third-party report — that Personal Data belonging to an individual under 21 years of age has been collected, sm065 will immediately:
- Suspend the account pending investigation;
- Permanently close the account if the underage status is confirmed;
- Securely delete all Personal Data associated with the underage account within 30 days of confirmation; and
- Void and refund any deposits made, in accordance with sm065's underage gambling policy.
If you have reason to believe that an individual under the age of 21 has registered an account on sm065, please contact us immediately using the details in Clause 15. Reports are treated with strict confidentiality.
Policy Amendments
sm065 reserves the right to update, revise, or replace this Privacy Policy at any time in response to changes in applicable law, regulatory guidance, business operations, or data-processing practices. The following process governs all amendments to this policy:
- Notice of Material Changes: Where an amendment materially affects the rights of Members or introduces a new category of data processing, sm065 will notify all registered Members via email to their registered address at least 14 days prior to the amended policy taking effect.
- Notice of Minor Changes: Where an amendment is minor in nature — such as correcting a typographical error, clarifying existing language, or updating contact information — sm065 will update the "Last Reviewed" date at the top of this policy without separate email notification.
- Continued Use: Your continued use of the sm065 platform following the effective date of any amendment constitutes acceptance of the revised Privacy Policy. If you do not accept the amended terms, you should cease using the sm065 platform and contact support to request account closure.
- Version Archive: Previous versions of this Privacy Policy are available on request by contacting sm065 customer support. Please quote the effective date of the version you wish to review.
sm065 recommends that all Members review this Privacy Policy periodically to stay informed of how their Personal Data is being protected and processed. The current version is always accessible at https://sm065.org/privacy-policy.
Contact & Complaints
For all privacy-related inquiries, data rights requests, or complaints regarding the processing of your Personal Data by sm065, please contact our Data Protection team using the details below. All correspondence must be submitted in English.
| Contact Type | Details |
|---|---|
| Data Protection Email | [email protected] — please use the subject line "Data Rights Request" or "Privacy Complaint" for prioritised handling. |
| Customer Support | 24/7 live chat available via the sm065 platform. Indonesian-speaking support agents are available. For data rights requests, live chat will direct you to the Data Protection email channel for secure processing. |
| Response Time | sm065 will acknowledge all privacy inquiries within 3 business days (WIB, UTC+7) and will provide a substantive response or decision within 30 calendar days of receiving a verified request. |
| Escalation | If you are not satisfied with sm065's response to a privacy complaint, you may escalate your complaint to the competent data protection supervisory authority in your jurisdiction. sm065 will cooperate fully with any such supervisory review. |
Ready to Explore sm065?
Now that you know how sm065 protects your data, explore our sportsbook, casino, and slots — or log in to manage your account and privacy preferences. Adults only — 21+.
Explore Sportsbook Browse Slots Visit sm065 Casino Login to sm065 Read Our FAQ