Last Updated: January 2026

mbakd2 Privacy Policy

Your privacy matters to us. This Privacy Policy explains exactly what personal data mbakd2 collects from members and visitors, how that data is used, how long it is retained, with whom it may be shared, and what rights you have over your own information. By accessing the mbakd2 platform and completing account registration, you confirm that you have read and accepted this policy.

256-bit SSL Encryption No Data Selling Strict Access Controls 21+ Only

How We Protect Your Privacy

mbakd2 is built on a foundation of transparency and trust. Here is a summary of the six core commitments that govern how we handle every member's personal data.

Encrypted at Every Step

Every piece of data transmitted between your browser or mobile device and the mbakd2 servers is protected by 256-bit SSL/TLS encryption. Data stored on our servers — including payment details, KYC documents, and account credentials — is encrypted at rest using AES-256.

We Never Sell Your Data

mbakd2 does not sell, rent, or trade your personal information to third-party marketers under any circumstances. Data shared with our certified partners — payment processors, KYC verification providers, and game studios — is strictly limited to what is necessary to deliver the Services.

Purpose Limitation

We collect only the data we genuinely need. Every category of personal data we process has a defined, documented purpose. If we wish to use your data for a new purpose that was not disclosed at the time of collection, we will seek your explicit consent before doing so.

Defined Retention Periods

Personal data is not held indefinitely. We publish clear retention schedules for each data category and automatically delete or anonymize data once the retention period expires, unless a legal or regulatory obligation requires us to retain it for longer.

Your Rights Are Respected

You have the right to access, correct, export, and request erasure of your personal data at any time. Requests are handled by our dedicated data privacy team and responded to within 30 calendar days. See Section 8 of this policy for the full list of your rights and how to exercise them.

International Standards

Our data protection practices are aligned with internationally recognized standards. Where data is transferred outside Indonesia to our service providers, we ensure that appropriate contractual safeguards are in place to maintain the same level of protection that applies on the mbakd2 platform.

1

Who We Are

1.1 Data Controller. mbakd2 (referred to in this policy as "mbakd2", "we", "us", or "our") is the data controller responsible for the personal data of members and visitors who interact with the online gaming platform accessible at https://mbakd2.net and all associated subdomains and mobile-optimized versions thereof.

1.2 Platform Scope. This Privacy Policy applies to all personal data collected through: the mbakd2 website; our mobile-optimized web application; account registration and login flows; customer support interactions via live chat or email; and any promotional or marketing communications you opt into.

1.3 Contact. For all data privacy enquiries, including the exercise of your rights under Section 8, please contact our Data Protection Officer (DPO) at: [email protected]. Please include "Privacy Request" in the subject line of your email so that your query is routed directly to the DPO team.

mbakd2 operates as an internationally licensed and regulated gaming platform. References to Indonesian residents in this policy reflect the primary member demographic we serve and the Indonesian market context in which our Services are offered.
2

Data We Collect

2.1 Registration Data. When you create an mbakd2 account, we collect: your full legal name; date of birth; email address; chosen username; city and province of residence within Indonesia; and your preferred primary payment method (e.g., BCA, BRI, BNI, Mandiri, OVO, DANA, GoPay, ShopeePay, or LinkAja).

2.2 KYC Identity Data. Prior to processing your first withdrawal, we require identity verification documents. These typically include: a scan or photograph of your government-issued photo ID (e.g., Indonesian KTP — Kartu Tanda Penduduk); proof of residential address; and, where applicable, a selfie photograph alongside your identity document.

2.3 Financial Transaction Data. We record all deposit and withdrawal transactions, including: transaction amounts in IDR (Rp); timestamps; payment method identifiers (e.g., masked bank account number or e-wallet reference); and transaction status. We do not store full bank account credentials or card numbers on our servers — these are handled exclusively by our PCI-DSS-certified payment processing partners.

2.4 Gameplay and Betting Data. We collect records of all bets placed, games played, wager amounts, results, session durations, and bonus redemptions. This data is used for account management, dispute resolution, fraud detection, and responsible gaming monitoring.

2.5 Device and Technical Data. When you access the platform, our servers automatically log: your IP address; browser type and version; operating system; device type; screen resolution; referring URL; pages visited; and session timestamps. This data is collected via server logs and analytics cookies.

2.6 Communications Data. If you contact our support team via live chat or email, we retain records of those communications, including the content of messages, timestamps, and the resolution reached, for quality assurance and dispute resolution purposes.

2.7 Marketing Preferences. If you opt into promotional communications, we record your consent, the date it was given, and your channel preferences (email, in-app notification).

We do not knowingly collect sensitive personal data beyond what is strictly required for KYC identity verification. We do not collect data relating to racial or ethnic origin, political opinions, religious beliefs, or health conditions, except where you voluntarily disclose such information in a support communication.

2.8 Summary of Data Categories

Data Category Examples Source
Registration Data Name, email, date of birth, city Provided by you at registration
KYC / Identity Data KTP scan, selfie, proof of address Provided by you during KYC
Financial Data Deposit/withdrawal amounts, masked account refs Generated by your transactions
Gameplay Data Bets placed, games played, session durations Generated by your platform activity
Technical / Device Data IP address, browser, OS, pages visited Collected automatically via logs & cookies
Communications Data Live chat and email records Provided by you when contacting support
Marketing Preferences Consent records, channel preferences Provided by you via account settings
3

How We Use Your Data

mbakd2 processes your personal data for the following specific purposes:

  • Account Management: To create, maintain, and administer your member account, including processing login requests, password resets, and account settings changes.
  • Identity Verification (KYC): To confirm your identity and age (21+) as required under our international gaming license conditions and responsible gaming obligations prior to processing your first withdrawal.
  • Payment Processing: To process deposit and withdrawal transactions via your chosen local payment method — including bank transfer via BCA, BRI, BNI, Mandiri, CIMB Niaga, BSI, and Bank Permata, and e-wallet transfers via OVO, DANA, GoPay, ShopeePay, and LinkAja — and to maintain accurate financial records.
  • Service Delivery: To provide access to all mbakd2 gaming products, including the Sportsbook, live casino, slots, and all other platform features, and to personalize the experience based on your preferences and history.
  • Fraud Prevention and Security: To detect and prevent unauthorized account access, bonus abuse, identity fraud, money laundering, and other prohibited conduct as defined in our Terms & Conditions.
  • Responsible Gaming: To monitor gameplay patterns for indicators of problem gambling behavior, enforce self-imposed deposit limits and self-exclusion requests, and proactively reach out to members who may be displaying signs of harmful play.
  • Customer Support: To respond to enquiries, resolve complaints, and maintain records of communications for quality assurance and dispute resolution.
  • Legal and Regulatory Compliance: To meet our obligations under our international gaming license, including record-keeping, audit cooperation, and reporting requirements.
  • Marketing Communications (with consent): To send promotional offers, bonus notifications, and seasonal campaign updates to members who have opted in. Marketing communications may reference Indonesian occasions such as Ramadhan, Idul Fitri, and Chinese New Year (Imlek) where relevant.
  • Platform Improvement: To analyze aggregated, anonymized usage data to identify technical issues, improve the user interface, and develop new features.
4

Legal Basis for Processing

For each processing purpose described in Section 3, mbakd2 relies on one or more of the following legal bases:

Processing Purpose Legal Basis
Account creation and management Performance of a contract (the membership agreement between you and mbakd2)
KYC identity verification Legal obligation (licensing conditions); Legitimate interest (age verification, fraud prevention)
Payment processing Performance of a contract
Fraud prevention and security Legitimate interest (protecting members and the platform from financial crime)
Responsible gaming monitoring Legal obligation (licensing conditions); Legitimate interest (member welfare)
Customer support Performance of a contract; Legitimate interest (service quality)
Legal and regulatory compliance Legal obligation
Marketing communications Consent (opt-in only; withdrawable at any time)
Platform analytics and improvement Legitimate interest (improving the product using anonymized data)
Where we rely on legitimate interest as our legal basis, we have conducted a balancing assessment and determined that our interest does not override your fundamental rights and freedoms. You may request a copy of any such assessment by contacting our DPO at [email protected].
5

Sharing Your Data

5.1 We Do Not Sell Your Data. mbakd2 does not sell, rent, or otherwise commercially exploit your personal data to any third party for their own marketing or commercial purposes.

5.2 Service Providers. We share necessary personal data with carefully selected third-party service providers who assist us in operating the platform. All service providers are bound by data processing agreements that restrict their use of your data to the specific services they perform for mbakd2. These providers include:

  • Payment Processors: Certified payment processing companies that facilitate bank transfers (BCA, BRI, BNI, Mandiri, CIMB Niaga, BSI, Bank Permata) and e-wallet transactions (OVO, DANA, GoPay, ShopeePay, LinkAja).
  • KYC / Identity Verification Providers: Specialist third-party identity verification platforms used to authenticate government-issued documents and perform age verification.
  • Game Studio Partners: Licensed game content providers including Pragmatic Play, Evolution Gaming, NetEnt, Microgaming, Pocket Games Soft, and Spribe. These providers may receive session tokens and anonymized gameplay identifiers to enable game functionality but do not receive your full identity data.
  • Fraud Detection and Analytics Providers: Specialized services that analyze behavioral and technical data to identify unusual patterns indicative of fraud or prohibited conduct.
  • Cloud Infrastructure Providers: Hosting and server infrastructure providers on whose platforms mbakd2 data is stored and processed, subject to enterprise-grade security agreements.
  • Customer Support Platforms: Live chat and ticketing systems that facilitate communication between members and our support team.

5.3 Legal Disclosures. mbakd2 may disclose personal data to competent authorities, courts, or regulators where required by law, by a valid court order, or where necessary to investigate suspected financial crime, fraud, or other illegal conduct. We will notify you of any such disclosure where we are legally permitted to do so.

5.4 Business Transfers. In the event of a merger, acquisition, or sale of all or a substantial portion of mbakd2's assets, your personal data may be transferred to the acquiring entity. You will be notified via your registered email address at least 30 days prior to any such transfer, and you will have the right to request deletion of your data before the transfer takes effect.

Every third-party service provider with access to mbakd2 member data is required to sign a Data Processing Agreement (DPA) that prohibits secondary use of your data, mandates equivalent security standards, and limits data retention to what is strictly necessary for the contracted service.
6

Cookies & Tracking Technologies

6.1 What Are Cookies. Cookies are small text files placed on your device by a website when you visit it. mbakd2 uses cookies and similar tracking technologies (including local storage and session tokens) to operate the platform, remember your preferences, and analyze usage patterns.

6.2 Types of Cookies We Use.

Cookie Type Purpose Duration
Strictly Necessary Session management, authentication tokens, security (CSRF protection). Cannot be disabled without breaking core functionality. Session / Up to 24 hours
Functional Remembering your language preference, game lobby layout settings, and responsible gaming tool configuration. Up to 12 months
Analytics Aggregated, anonymized data on pages visited, features used, and session duration to help us improve the platform. Up to 12 months
Marketing / Retargeting Used only where you have provided explicit consent to receive personalized promotional content. Up to 90 days

6.3 Managing Cookies. You may manage your cookie preferences at any time through your browser settings. Disabling strictly necessary cookies will impair your ability to log in and use core platform features. Disabling analytics or marketing cookies will not affect your ability to play. Please note that clearing your browser cookies will also clear your mbakd2 session, requiring you to log in again.

For instructions on managing cookies in your specific browser (Chrome, Firefox, Safari, Samsung Internet), please refer to your browser's official help documentation. mbakd2 does not control third-party browser cookie management interfaces.
7

Data Retention

7.1 Retention Principles. mbakd2 retains personal data only for as long as is necessary to fulfill the purpose for which it was collected, or as required by applicable legal or regulatory obligations. Once the applicable retention period expires, data is securely deleted or anonymized.

7.2 Retention Schedule.

Data Category Retention Period Basis for Retention
Account Registration Data Duration of membership + 5 years after account closure Legal obligation (licensing audit requirements)
KYC Identity Documents Duration of membership + 5 years after account closure Legal obligation (AML/KYC regulatory requirements)
Financial Transaction Records 7 years from transaction date Legal obligation (financial record-keeping standards)
Gameplay and Betting Records 3 years from date of activity Legitimate interest (dispute resolution, responsible gaming)
Customer Support Communications 2 years from date of communication Legitimate interest (quality assurance, dispute resolution)
Technical / Server Log Data 90 days Legitimate interest (security monitoring, fraud detection)
Marketing Consent Records Duration of consent + 3 years after withdrawal Legal obligation (demonstrating compliance with consent rules)
Analytics Cookies (anonymized) Up to 12 months Legitimate interest (platform improvement)

7.3 Early Deletion. You may request early deletion of your personal data by submitting a Data Erasure Request under Section 8.4. Deletion requests are subject to any overriding legal retention obligations — for example, financial transaction records required to be held for 7 years under international anti-money-laundering standards cannot be deleted early.

8

Your Privacy Rights

As an mbakd2 member or platform visitor, you have the following rights in relation to your personal data. To exercise any of these rights, please contact our DPO at [email protected] with the subject line "Privacy Request — [Right Type]". We will respond within 30 calendar days of receiving a valid request.

Right of Access Request a copy of all personal data we hold about you, along with information on how it is being used.
Right to Rectification Request correction of any inaccurate or incomplete personal data we hold about you.
Right to Erasure Request deletion of your personal data where it is no longer necessary for the purpose it was collected, subject to legal retention obligations.
Right to Restrict Processing Request that we temporarily suspend processing of your data while a rectification or objection request is being considered.
Right to Data Portability Request your personal data in a structured, machine-readable format for transfer to another service provider.
Right to Object Object to processing based on legitimate interest, including direct marketing. We will cease processing unless we can demonstrate compelling grounds.
Withdraw Consent Where processing is based on consent (e.g., marketing emails), withdraw that consent at any time via account settings or by contacting support.
Right to Complain Lodge a complaint with the relevant supervisory authority if you believe your data rights have been violated. We encourage you to contact us first.
We may need to verify your identity before processing a data rights request to ensure we do not disclose or delete another person's data in error. Verification is typically completed by confirming your registered email address and one additional account identifier.
9

Security Measures

9.1 Technical Safeguards. mbakd2 employs a comprehensive set of technical security controls to protect your personal data against unauthorized access, disclosure, alteration, or destruction. These include:

  • Transport Layer Security: All data transmitted between your device and our servers is encrypted using TLS 1.2 or higher, enforced via 256-bit SSL certificates.
  • Encryption at Rest: Sensitive data stored on mbakd2 servers — including identity documents, account credentials, and financial records — is encrypted at rest using AES-256 encryption.
  • Firewalls and Intrusion Detection: Enterprise-grade perimeter firewalls and real-time intrusion detection systems monitor all network traffic for anomalous activity.
  • Two-Factor Authentication (2FA): Members are strongly encouraged to enable 2FA on their accounts. Administrative staff with access to member data are required to use 2FA without exception.
  • Access Control: Personal data is accessible only to mbakd2 staff and authorized service providers who have a specific, documented need. Role-based access controls are enforced at the system level, and all access events are logged for audit purposes.
  • Penetration Testing: Our platform undergoes regular independent security assessments and penetration tests conducted by certified cybersecurity professionals to identify and remediate vulnerabilities proactively.

9.2 Organizational Safeguards. In addition to technical controls, mbakd2 maintains the following organizational security practices:

  • All staff with access to personal data receive mandatory data protection and security training upon onboarding and at least annually thereafter.
  • Data processing agreements are in place with all third-party service providers, requiring them to maintain equivalent security standards.
  • A documented incident response plan is maintained and tested regularly to ensure rapid and effective response to any security breach.

9.3 Data Breach Notification. In the event of a personal data breach that is likely to result in a risk to your rights and freedoms, mbakd2 will notify affected members without undue delay — and in any case within 72 hours of becoming aware of the breach — via your registered email address. The notification will describe the nature of the breach, the categories and approximate number of records affected, the likely consequences, and the steps mbakd2 is taking to address it.

While mbakd2 takes all reasonable measures to protect your data, no system connected to the internet can be guaranteed to be 100% secure. You are responsible for keeping your account password confidential and for notifying us immediately at [email protected] if you suspect unauthorized access to your account.
10

Children's Privacy

10.1 Age Restriction. The mbakd2 platform is strictly for adults. You must be at least 21 years of age to register and use the Services. This requirement reflects both our international licensing conditions and the age restriction standard applicable to our primary market. We do not knowingly collect, process, or store personal data belonging to individuals under the age of 21.

10.2 Age Verification. We verify the age of all members as part of our KYC process prior to approving any withdrawal request. In cases where we have reason to suspect that a member may be under 21, we reserve the right to suspend the account and require additional age verification documentation before any further activity is permitted.

10.3 Parental Controls. If you are a parent or guardian and you believe that a person under 21 has registered an account on the mbakd2 platform using false information, please contact us immediately at [email protected]. We will investigate the matter promptly, suspend the account pending verification, and permanently delete any data associated with the underage individual once the matter is confirmed.

21+ Only. Underage gambling is illegal and harmful. mbakd2 takes its age restriction obligations seriously. For guidance on parental controls and tools to prevent underage access to gambling websites, please visit our Responsible Gaming page.
11

International Data Transfers

11.1 Cross-Border Processing. As an internationally operated platform, mbakd2 may transfer your personal data to service providers and infrastructure partners located outside of Indonesia. These transfers may involve countries that do not have data protection laws equivalent to those in Indonesia's regulatory framework.

11.2 Safeguards for International Transfers. Wherever personal data is transferred to a country without an equivalent level of data protection, mbakd2 ensures that appropriate safeguards are in place, including:

  • Standard Contractual Clauses: Legally binding contractual obligations imposed on the receiving party that require them to protect personal data to a standard equivalent to that required under applicable data protection law.
  • Data Processing Agreements: Comprehensive DPAs with all third-party processors that restrict the scope, purpose, and duration of data processing and impose security requirements consistent with Section 9 of this policy.
  • Adequacy Assessments: Before transferring data to a new international partner, our DPO team conducts a transfer impact assessment to evaluate the risks involved and confirm that the safeguards are adequate.

11.3 Your Rights in Transfers. You have the right to request information about the specific safeguards in place for any international transfer of your personal data. Please contact our DPO at [email protected] to make such a request.

The primary data center hosting mbakd2 member data is located in the Asia-Pacific region to minimize latency for users based in Indonesia (Jakarta, Surabaya, Medan, Bandung, Bali, and other cities). Secondary disaster-recovery infrastructure may be located in a different jurisdiction with equivalent security standards.
12

Updates to This Privacy Policy

12.1 Right to Amend. mbakd2 reserves the right to update or amend this Privacy Policy at any time to reflect changes in our data processing practices, applicable law, or our platform's features and services. The most current version of this policy will always be available at https://mbakd2.net/privacy-policy.

12.2 Notification of Material Changes. If we make a material change to this Privacy Policy — meaning a change that significantly affects how we process your personal data or your rights under this policy — we will notify you by email to your registered address at least 14 days before the change takes effect. The notification will summarize the key changes and link to the full updated policy.

12.3 Continued Use as Acceptance. Your continued use of the mbakd2 platform after the effective date of any updated Privacy Policy constitutes your acceptance of the revised terms. If you do not agree with the updated policy, you should cease using the platform and may request account closure and data deletion under Section 8.4.

12.4 Version History. The "Last Updated" date displayed at the top of this page indicates when the current version of this policy was published. Prior versions of this Privacy Policy are available upon request by contacting our DPO at [email protected].

We recommend reviewing this Privacy Policy periodically, especially if you have recently made a deposit, completed KYC verification, or changed your marketing preferences. Staying informed about how your data is handled helps you make confident decisions about your use of the mbakd2 platform.
13

Contact & Data Protection Officer

13.1 Data Protection Officer. mbakd2 has appointed a dedicated Data Protection Officer (DPO) responsible for overseeing compliance with this Privacy Policy and applicable data protection obligations. The DPO serves as the primary point of contact for all member privacy enquiries, data rights requests, and regulatory matters.

13.2 How to Reach Us. You may contact our DPO and privacy team through the following channels:

  • Email: [email protected] — please include "Privacy Request" in the subject line for all data protection matters.
  • Live Chat: Available 24 hours a day, 7 days a week via the in-app messenger on the mbakd2 platform. Ask the agent to escalate your query to the Data Privacy team.
  • Indonesian-Speaking Agents: Available 08:00 – 24:00 WIB (Western Indonesia Time, UTC+7) daily for members who prefer to communicate in Bahasa Indonesia.

13.3 Response Times. We aim to acknowledge all privacy-related enquiries within 2 business days and to provide a substantive response within 30 calendar days. For complex requests, we may extend the response period by a further 30 days, in which case we will notify you of the extension and the reason for it.

13.4 Supervisory Authority. If you are not satisfied with our response to a privacy complaint, you have the right to escalate the matter to the supervisory authority responsible for data protection in the jurisdiction under which mbakd2 operates its international gaming license. Details of the applicable supervisory authority will be provided upon request.

mbakd2 is committed to resolving all privacy concerns fairly and transparently. We encourage you to contact us directly before escalating to a supervisory authority — the vast majority of privacy concerns are resolved quickly through our internal process.

Explore mbakd2 with Confidence

Now that you understand exactly how mbakd2 protects your personal data, you can enjoy our full range of gaming products with complete peace of mind. Your data is safe — your game is on.

21+ only. Gambling involves financial risk. Please play responsibly. See our Responsible Gaming page for tools and support.