This Privacy Policy ("Policy") describes how aha4d ("we", "us", "our") collects, uses, stores, shares, and protects personal data submitted by individuals ("you", "your") who register for or otherwise interact with the aha4d Platform at https://aha4d.pro. By creating an account or using the Platform, you confirm that you have read and understood this Policy in full. This Policy forms an integral part of aha4d's Terms & Conditions.
1 Definitions
Throughout this Policy, the following terms carry the meanings set out below:
- "Personal Data" — any information that identifies or can reasonably be used to identify a living natural person, including names, identification numbers, contact details, location data, and online identifiers.
- "Processing" — any operation performed on Personal Data, whether automated or manual, including collection, recording, storage, alteration, retrieval, use, disclosure, transmission, restriction, or deletion.
- "Data Controller" — aha4d, the entity that determines the purposes and means of processing your Personal Data.
- "Data Processor" — a third party that processes Personal Data on behalf of aha4d in accordance with written instructions and contractual data-protection obligations.
- "Member" — any individual who has completed aha4d's account registration process and holds an active or previously active account on the Platform.
- "Platform" — the aha4d website at https://aha4d.pro, including all sub-pages, services, and associated applications.
- "KYC" — Know Your Customer identity and address verification procedures required prior to withdrawal processing or at aha4d's compliance team's request.
- "Cookies" — small text files placed on your device by the Platform's server to store session state, preferences, and analytical data.
- "IDR" — Indonesian Rupiah, the exclusive currency in which aha4d processes all financial transactions.
2 Personal Data We Collect
aha4d collects only the data that is genuinely necessary to operate your account, process transactions, and comply with applicable legal obligations. The categories of Personal Data we collect are set out in the table below.
| Category |
Examples |
When Collected |
| Identity Data |
Full legal name, date of birth, nationality, government-issued ID number (KTP, passport, SIM) |
Registration & KYC verification |
| Contact Data |
Email address, phone number, residential address (city, province) |
Registration & account updates |
| Financial Data |
Bank account name and number (BCA, BRI, BNI, Mandiri, CIMB Niaga, BSI), e-wallet account identifiers (OVO, DANA, GoPay, ShopeePay, LinkAja), deposit and withdrawal transaction records in IDR |
Deposit / withdrawal requests & KYC |
| Account Data |
Username, encrypted password hash, account balance history, bonus credit records, wagering activity logs |
Ongoing platform use |
| Technical Data |
IP address, device type, operating system, browser type and version, screen resolution, session timestamps |
Every platform visit |
| Behavioural Data |
Pages visited, games played (slots, togel, live Dragon Tiger, sportsbook markets), session duration, click-path analytics |
Ongoing platform use |
| Communication Data |
Live chat transcripts, support ticket content, email correspondence with aha4d support |
When you contact support |
| Compliance Data |
KYC document scans (ID card, proof of address, payment method proof), AML risk-scoring outputs, self-exclusion status records |
KYC & regulatory compliance checks |
Note on Sensitive Data: aha4d does not intentionally collect special-category sensitive data (racial or ethnic origin, religious beliefs, health data, biometric data) as part of its standard registration or operational processes. Where a government-issued ID document submitted for KYC happens to contain such information, it is stored solely in its original document form and is not processed separately for any purpose other than identity verification.
3 How Personal Data Is Collected
aha4d collects Personal Data through the following channels:
3.1 Directly From You
The majority of the Personal Data we hold is provided directly by you when you:
- Complete the aha4d account registration form (Identity Data and Contact Data).
- Submit KYC documentation via the secure upload facility within your account (Identity Data and Compliance Data).
- Initiate a deposit or withdrawal transaction (Financial Data).
- Contact our customer support team via live chat or email (Communication Data).
- Participate in promotions, tournaments, or surveys where you voluntarily provide additional information.
- Update your account profile or notification preferences.
3.2 Automatically From Your Device
When you visit or interact with the Platform, our servers and analytics tools automatically collect Technical Data and Behavioural Data via:
- Server access logs that record your IP address, request timestamps, and HTTP status codes.
- Session cookies that maintain your logged-in state and track navigation within a single browsing session.
- Analytics cookies that aggregate anonymized click-path and session-duration data to help us identify usability issues and improve platform performance.
3.3 From Third-Party Sources
In limited circumstances, aha4d may receive Personal Data from third-party sources, including:
- KYC Verification Providers: Identity verification bureaus that cross-check document authenticity and screen against sanctions and politically exposed persons (PEP) lists.
- Payment Processors: Bank and e-wallet payment gateways that confirm transaction status and return transaction reference identifiers.
- Fraud Prevention Services: Third-party fraud-scoring engines that flag high-risk behavioral signals based on device fingerprinting and IP reputation data.
- Game Content Providers: Licensed third-party studios (including Pragmatic Play, Evolution Gaming, NetEnt, Microgaming, Spribe, and Pocket Games Soft) that return game-session results, win/loss outcomes, and RNG certification data to our platform in real time.
4 Purposes of Processing
aha4d processes your Personal Data for the specific, limited purposes described below. We do not process Personal Data for any purpose that is incompatible with the purposes listed here without first obtaining your explicit consent or establishing a separate lawful basis.
- Account Creation and Management: To register your account, maintain your profile, authenticate your identity at login, and allow you to access Gaming Products on the Platform.
- Transaction Processing: To process deposits in IDR via BCA, BRI, BNI, Mandiri, CIMB Niaga, OCBC NISP, Bank Permata, BSI, OVO, DANA, GoPay, ShopeePay, and LinkAja; to process withdrawal requests to your registered payment method; and to maintain accurate financial records of all account activity.
- Identity Verification (KYC): To verify that you are who you claim to be, that you satisfy the 21+ age requirement, that you are not on any sanctions list, and that the payment methods you use are registered in your own name.
- Fraud Prevention and Security: To detect, investigate, and prevent fraudulent activity, money laundering, unauthorized account access, bonus abuse, and other forms of financial crime or Platform misuse.
- Legal and Regulatory Compliance: To comply with applicable anti-money laundering (AML) regulations, international gaming licensing requirements, court orders, and lawful requests from regulatory or law-enforcement authorities.
- Customer Support: To respond to your inquiries, resolve disputes, process complaints, and deliver service updates. aha4d's support team provides 24/7 Indonesian-speaking support (native-language agents available at all hours, including during Indonesian public holidays such as Idul Fitri, Lebaran, and Nyepi).
- Responsible Gaming: To monitor betting patterns for signs of problem gambling behavior, enforce self-exclusion and cooling-off requests, manage deposit and loss limits, and deliver responsible gaming messaging as required.
- Platform Improvement and Analytics: To analyze aggregated and anonymized Behavioural Data for the purpose of improving platform usability, optimizing game content offerings, and identifying technical issues.
- Marketing Communications: To send you promotional emails about bonuses, tournaments, and new game launches — but only where you have opted in to receive such communications. You may withdraw marketing consent at any time via the unsubscribe link in any email or by contacting support.
5 Legal Basis for Processing
aha4d processes your Personal Data on the following legal bases, consistent with internationally recognized data protection principles:
- Contractual Necessity: Processing that is required to perform the contract between you and aha4d (account management, transaction processing, KYC, customer support).
- Legal Obligation: Processing required to comply with applicable legal and regulatory obligations (AML compliance, regulatory reporting, law-enforcement requests).
- Legitimate Interests: Processing that serves aha4d's legitimate business interests in a manner that does not override your fundamental privacy rights (fraud prevention, platform security, aggregated analytics).
- Consent: Processing that is based on your freely given, specific, informed consent (marketing communications, optional analytics features). You may withdraw consent at any time without affecting the lawfulness of processing carried out prior to withdrawal.
Your right to object: Where processing is based on legitimate interests, you have the right to object to that processing at any time. aha4d will cease the relevant processing unless it can demonstrate compelling legitimate grounds that override your interests, rights, and freedoms.
6 Data Sharing & Disclosure
aha4d does not sell, rent, or trade your Personal Data to unaffiliated third parties for their own marketing purposes. We share Personal Data only in the limited circumstances described below, and only to the extent strictly necessary for the stated purpose.
6.1 Service Providers (Data Processors)
We engage carefully selected, contractually bound Data Processors to assist with the technical and operational delivery of the Platform, including:
- KYC and identity verification services.
- Payment processing gateways (bank transfer and e-wallet intermediaries).
- Fraud detection and anti-money laundering screening tools.
- Cloud hosting and content delivery infrastructure.
- Customer support platform providers (live chat technology).
- Email delivery services (for transactional and, where consented, marketing communications).
All Data Processors are bound by written data-processing agreements that prohibit them from using your Personal Data for any purpose other than delivering the specified service to aha4d.
6.2 Game Content Providers
Third-party game studios (including Pragmatic Play, Evolution Gaming, NetEnt, Microgaming, Spribe, and Pocket Games Soft) receive a pseudonymous player session token — not your full identity details — sufficient to authenticate your game session, record your game-level wagering activity, and return results to the Platform. These studios operate under their own data-processing agreements with aha4d and are not authorized to use session tokens to identify you outside the context of game delivery.
6.3 Regulatory and Law Enforcement Disclosure
aha4d may disclose Personal Data to regulatory authorities, law enforcement agencies, courts, or government bodies where required to do so by applicable law, court order, or lawful regulatory demand. Where permitted by law, aha4d will endeavour to notify you of such a disclosure request before complying.
6.4 Business Transfers
In the event of a merger, acquisition, asset sale, or corporate restructuring involving aha4d, Personal Data held by aha4d may be transferred to the acquiring entity as part of the transaction. You will be notified of any such transfer and the identity of the new data controller via in-platform notification and email prior to the transfer taking effect.
⚠️ We will never: sell your data to advertising networks; share your full bank account details with game studios; disclose your personally identifiable information to other Members; or provide data to third parties for their own unsolicited marketing without your explicit prior consent.
7 International Data Transfers
aha4d operates as an internationally licensed platform and may transfer your Personal Data to, or process it in, countries outside Indonesia. Where such transfers occur, aha4d ensures that appropriate safeguards are in place to protect your data to a standard at least equivalent to that provided under internationally recognized data protection principles, including:
- Standard contractual clauses incorporated into Data Processor agreements.
- Transfer to recipients in jurisdictions recognized as providing an adequate level of data protection by relevant international standards.
- Binding corporate rules where applicable within affiliated entity groups.
You may request further information about the specific safeguards applicable to any international transfer of your Personal Data by contacting our Data Protection team at [email protected].
8 Data Retention
aha4d retains Personal Data for as long as is necessary to fulfil the purposes for which it was collected, subject to the following retention principles:
- Active Account Data: Retained for the full duration of your membership plus a minimum post-closure period required for legal and financial record-keeping.
- Financial Transaction Records: Retained for a minimum of five (5) years following the date of the transaction, in compliance with AML regulations applicable to internationally licensed gaming operators.
- KYC Documentation: Retained for a minimum of five (5) years following account closure or the completion of the KYC process, whichever is later.
- Support Communication Logs: Retained for a minimum of three (3) years from the date of the communication, to facilitate dispute resolution and service quality improvement.
- Marketing Consent Records: Retained for three (3) years from the date of your most recent consent interaction, to demonstrate compliance with consent requirements.
- Technical and Analytical Logs: Anonymized and aggregated within 90 days of collection; anonymized data may be retained indefinitely for statistical analysis.
Upon the expiry of the applicable retention period, Personal Data is securely deleted from aha4d's systems or irreversibly anonymized. Where deletion is not immediately technically feasible (for example, where data exists in encrypted backup archives), aha4d will implement appropriate access restrictions until deletion can be performed.
9 Security Measures
aha4d implements a comprehensive set of technical and organizational security measures designed to protect your Personal Data against unauthorized access, accidental loss, destruction, alteration, or disclosure. These measures include:
- Encryption in Transit: All data transmitted between your device and aha4d's servers is encrypted using TLS 1.2 or higher (256-bit encryption).
- Encryption at Rest: Sensitive data fields stored in aha4d's databases — including password hashes and KYC document references — are encrypted at rest using AES-256.
- Access Controls: Access to Personal Data within aha4d's systems is restricted on a strict need-to-know basis, with role-based access controls, multi-factor authentication requirements for privileged accounts, and comprehensive access audit logging.
- Penetration Testing: aha4d's platform undergoes regular security penetration testing by qualified third-party security professionals to identify and remediate vulnerabilities before they can be exploited.
- Incident Response: aha4d maintains a documented data security incident response plan. In the event of a data breach that poses a high risk to your rights and freedoms, aha4d will notify affected Members without undue delay and in accordance with applicable breach notification requirements.
- Staff Training: All aha4d staff with access to Personal Data undergo mandatory data protection and security awareness training on joining and annually thereafter.
Your responsibility: While aha4d takes all reasonable technical and organizational steps to protect your data, the security of your account also depends on you. You are responsible for maintaining the confidentiality of your username and password and for logging out of shared devices. If you believe your account has been compromised, contact aha4d support immediately via live chat.
10 Cookies & Tracking Technologies
10.1 What Are Cookies?
Cookies are small text files stored on your device by a web server when you visit a website. They allow the Platform to recognize your device on subsequent visits, maintain session state across page loads, and collect aggregated usage statistics.
10.2 Cookies Used by aha4d
| Cookie Type |
Purpose |
Duration |
| Strictly Necessary |
Maintain your logged-in session, store your account authentication token, enable secure financial transaction flows. Cannot be disabled without breaking core platform functionality. |
Session / up to 30 days |
| Functional |
Remember your display preferences, language settings, and responsible gaming notification configurations between sessions. |
Up to 12 months |
| Analytical |
Collect anonymized data on page views, session durations, game category popularity, and technical error rates to help aha4d improve platform performance. Data is aggregated and cannot be used to identify individual users. |
Up to 24 months |
10.3 Managing Cookies
You may manage or disable cookies through your browser settings at any time. Most modern browsers allow you to view, block, or delete individual cookies. Please note that disabling strictly necessary cookies will prevent you from logging in or using core platform features. Disabling functional cookies will reset your preferences on each visit. Disabling analytical cookies will not affect your ability to use the Platform.
10.4 No Third-Party Advertising Cookies
aha4d does not deploy third-party advertising cookies, retargeting pixels, or any tracking technology that monitors your browsing behavior on websites outside of the aha4d Platform. We do not participate in cross-site behavioral advertising networks.
11 Your Data Rights
Subject to applicable law and any overriding legal obligations aha4d may be subject to (such as AML record-keeping requirements), you hold the following rights in respect of your Personal Data:
- Right of Access: You may request a copy of all Personal Data that aha4d holds about you. We will provide this in a structured, commonly used format within 30 calendar days of a verified request.
- Right to Rectification: You may request that any inaccurate or incomplete Personal Data we hold about you be corrected or completed without undue delay.
- Right to Erasure ("Right to Be Forgotten"): You may request deletion of your Personal Data where it is no longer necessary for the purposes for which it was collected, where you have withdrawn consent, or where processing was unlawful. This right is subject to aha4d's legal obligations to retain certain financial and KYC records.
- Right to Restriction: You may request that processing of your Personal Data be restricted in certain circumstances — for example, while the accuracy of data is being contested or while an objection is being assessed.
- Right to Data Portability: Where processing is based on your consent or on contractual necessity and is carried out by automated means, you may request that your Personal Data be provided to you in a machine-readable format or transmitted directly to another data controller where technically feasible.
- Right to Object: You may object to processing based on aha4d's legitimate interests at any time. You also have an unconditional right to object to the use of your Personal Data for direct marketing purposes.
- Right to Withdraw Consent: Where processing is based on your consent, you may withdraw that consent at any time. Withdrawal of consent does not affect the lawfulness of processing carried out prior to withdrawal.
To exercise any of the above rights, please submit a written request to [email protected] with the subject line "Data Rights Request", your registered username, and a description of the right you wish to exercise. aha4d may request additional verification of your identity before processing a data rights request. Requests are handled free of charge and responded to within 30 calendar days; complex or high-volume requests may take up to 60 days, in which case you will be notified of the extension within the initial 30-day window.
Complaints: If you are not satisfied with aha4d's handling of your Personal Data or your data rights request, you have the right to lodge a complaint with the relevant data protection supervisory authority in your jurisdiction. aha4d encourages you to contact us first so that we have the opportunity to resolve your concern directly before escalation.
12 Minors
The aha4d Platform is strictly for adults aged 21 years and over. aha4d does not knowingly collect Personal Data from any individual under the age of 21. All new account registrations are subject to age verification as part of the KYC process. If aha4d discovers that Personal Data has been collected from a person under 21, that data will be deleted immediately, the account will be closed, any funds held will be returned after identity verification, and the matter may be referred to the appropriate authorities where required by law.
If you are a parent or guardian and have reason to believe that a minor in your care has registered on the aha4d Platform, please contact us immediately at [email protected] so that we can take prompt remedial action.
🔞 21+ Only: aha4d actively enforces the 21+ age restriction across all Gaming Products, including sports betting, live casino, togel (Indonesia's traditional numbers lottery), and slot gacor (high-RTP slot games). Age verification is mandatory before any withdrawal request is honoured.
13 Third-Party Services & Links
The aha4d Platform may contain references to, or embed content from, third-party game studios and payment processing services. These third parties operate under their own, independent privacy policies and data handling practices, for which aha4d accepts no responsibility. We encourage you to review the privacy policies of any third-party service providers whose services you access in connection with the Platform.
aha4d does not include outbound links to unaffiliated external websites on the Platform. All navigation links on aha4d.pro direct users to internal Platform pages only. If you arrive at an external website from a source that claims to be affiliated with aha4d, exercise caution and verify the domain before submitting any personal information.
14 Policy Amendments
aha4d reserves the right to update this Privacy Policy at any time to reflect changes in our data processing practices, applicable law, or regulatory requirements. When material changes are made — affecting your rights, the categories of data collected, the purposes of processing, or the parties with whom data is shared — aha4d will provide at least seven (7) calendar days' advance notice via in-platform notification and/or email to your registered address before the revised Policy takes effect.
For non-material clarifications or editorial corrections, aha4d may update the Policy without prior notice; the "Last Reviewed" date at the top of the document will be updated to reflect all revisions. Continued use of the Platform after the effective date of a revised Policy constitutes your acknowledgement of the updated terms. If you do not agree to a revised Policy, you must cease using the Platform and close your account before the effective date.
Stay informed: We recommend bookmarking this page and reviewing it whenever you receive a policy-change notification. We will never retroactively change the legal basis or purpose of processing for data already collected without your explicit consent.