This Privacy Policy forms an integral part of the jw001 Terms & Conditions. By creating an account on jw001 or by continuing to use the Platform, you acknowledge that you have read and understood this policy and consent to the processing of your personal data as described herein.
jw001 ("we", "us", "our", or "the Platform") operates the online casino and sportsbook accessible at https://jw001.ws. We are committed to handling your personal data responsibly, transparently, and in accordance with internationally recognised data protection principles. This Privacy Policy applies to all Members, visitors, and any other individuals whose personal data jw001 processes in connection with the operation of the Platform.
jw001 primarily serves players based in Indonesia. All amounts referenced on the Platform are denominated in Indonesian Rupiah (IDR / Rp). Where this policy references Indonesian-specific services — including local bank transfers via BCA, BRI, BNI, Mandiri, and CIMB Niaga, and e-wallet services OVO, DANA, GoPay, ShopeePay, and LinkAja — those references relate directly to the personal data collected and processed in connection with those payment channels.
If you have any questions about this policy or wish to exercise your data rights, please contact our Data Protection Officer (DPO) at [email protected] with the subject line "Privacy — Data Rights Request".
The following terms have the meanings given below throughout this Privacy Policy:
- "Personal Data" means any information relating to an identified or identifiable natural person. This includes, but is not limited to, names, email addresses, phone numbers, bank account details, IP addresses, and device identifiers.
- "Processing" means any operation performed on Personal Data, including collection, recording, storage, use, disclosure, erasure, or destruction.
- "Controller" means jw001, the entity that determines the purposes and means of processing your Personal Data.
- "Processor" means a third party that processes Personal Data on behalf of jw001 under a contractual agreement (e.g., payment processors, KYC verification providers, cloud hosting partners).
- "Member" means any individual who has completed registration and holds an active account on the jw001 Platform.
- "KYC" means Know Your Customer — the identity verification process jw001 uses to confirm a Member's identity, age, and payment method ownership before processing withdrawals or at any other point deemed necessary by our compliance team.
- "Cookies" means small text files placed on your device by the Platform to facilitate session management, analytics, and personalisation.
- "Sensitive Data" means a subset of Personal Data warranting heightened protection, including financial account details, government-issued ID numbers, and biometric data submitted as part of the KYC process.
jw001 collects only the data that is necessary to operate the Platform securely, comply with our legal and regulatory obligations, and deliver a high-quality experience to our Members. The categories of Personal Data we collect are as follows:
| Category |
Examples |
Purpose |
| Identity Data |
Full legal name, date of birth, nationality, government-issued ID number (KTP for Indonesian nationals), selfie photograph |
KYC verification, age check (21+), fraud prevention |
| Contact Data |
Email address, mobile phone number, residential address (including city: Jakarta, Surabaya, Bandung, Medan, Bali, Semarang, etc.) |
Account communication, support, regulatory correspondence |
| Financial Data |
Bank account name and number (BCA, BRI, BNI, Mandiri, CIMB Niaga, Bank Permata, BSI, OCBC NISP), e-wallet ID (OVO, DANA, GoPay, ShopeePay, LinkAja), transaction history, deposit and withdrawal amounts in IDR |
Payment processing, AML compliance, fraud detection |
| Technical Data |
IP address, browser type and version, device type and operating system, session duration, time zone (WIB/WITA/WIT), cookie identifiers |
Platform security, fraud prevention, service optimisation |
| Usage Data |
Games played, bet amounts and outcomes, pages visited, bonus offers viewed, session timestamps |
Personalisation, responsible gaming monitoring, product improvement |
| Communications Data |
Content of support chat transcripts, email correspondence, and any information you voluntarily provide when contacting our team |
Support delivery, complaint resolution, quality assurance |
| Marketing Preferences |
Email and notification opt-in/opt-out status, preferred promotional categories |
Targeted promotions (with consent), communication preference management |
jw001 does not collect or store complete credit or debit card numbers. Payment card transactions, where applicable, are handled entirely by our PCI-DSS-compliant payment processor partners. jw001 receives only a tokenised reference for reconciliation purposes.
jw001 collects Personal Data through the following means:
- Direct Submission: Data you provide when registering an account, completing KYC verification, making a deposit or withdrawal, contacting support, or participating in promotions.
- Automated Technical Collection: Data collected automatically when you access the Platform, including IP addresses, device identifiers, browser fingerprints, and session activity logs gathered via server logs and cookies.
- Payment Processors: Confirmation data received from our partner payment gateways when you complete a deposit or withdrawal transaction via a local bank or e-wallet. This confirmation typically includes transaction reference numbers, timestamps, and the registered name on the originating account.
- KYC Verification Partners: Where jw001 employs a third-party identity verification provider to authenticate submitted documents, that provider returns a structured verification result (pass/fail/refer) along with extracted identity fields that are stored against your account record.
- Responsible Gaming Monitoring: Behavioural data automatically generated through your gaming activity — including session length, bet frequency, deposit velocity, and loss patterns — is collected and analysed by our responsible gaming system to identify members who may need intervention or support.
- Referral and Affiliate Channels: If you arrived at jw001 via an affiliate or referral link, we may receive a referral identifier from that partner. We do not receive any Personal Data about you from the affiliate; only a session token indicating the referral source.
jw001 uses your Personal Data for the specific, limited purposes described below. We do not use your data for any purpose that is incompatible with these stated purposes without first obtaining your explicit consent.
- Account Management: To create, maintain, and administer your jw001 Member account, including processing login sessions, managing account settings, and responding to account-related queries.
- Identity and Age Verification: To confirm that you are at least 21 years of age and are eligible to use the Platform in accordance with our Terms & Conditions. jw001 strictly enforces its 21+ policy across all markets, including Indonesia.
- Payment Processing: To facilitate deposits and withdrawals via your nominated local bank account or e-wallet, reconcile transaction records, and investigate payment disputes.
- Fraud Prevention and AML Compliance: To detect, investigate, and prevent fraudulent activity, money laundering, and other financial crime. This includes automated screening of transaction patterns against risk models and, where required, reporting to relevant regulatory or law enforcement bodies.
- Regulatory Compliance: To meet our obligations under applicable international licensing requirements, including record-keeping, audit trail maintenance, and cooperation with regulatory investigations.
- Responsible Gaming: To monitor your gaming behaviour for indicators of problem gambling, apply self-imposed limits and self-exclusion instructions, and proactively reach out where our systems flag a concern about your wellbeing. For full details, see our Responsible Gaming page.
- Customer Support: To respond to your queries, resolve complaints, and maintain a record of support interactions for quality and training purposes.
- Marketing and Promotions: To send you promotional communications about bonuses, seasonal offers (including those tied to Ramadhan, Idul Fitri, Chinese New Year, and Indonesian Independence Day), and new product launches — but only where you have provided your consent to receive such communications and have not subsequently withdrawn it.
- Platform Improvement: To analyse aggregated, anonymised usage data to improve the performance, stability, and feature set of the Platform. Anonymised analytical data cannot be used to identify you.
- Security: To protect the Platform and its Members from unauthorised access, data breaches, and other security threats through real-time monitoring, intrusion detection, and access controls.
jw001 processes your Personal Data on one or more of the following legal bases, depending on the specific processing activity:
- Contractual Necessity: Processing is necessary to perform the contract between you and jw001 (i.e., to operate your account, process transactions, and deliver the gaming and betting services you have requested). Without this processing, jw001 cannot provide the Platform to you.
- Legal Obligation: Processing is required to comply with our obligations under applicable international gaming regulations, anti-money laundering laws, and financial crime prevention frameworks. This includes mandatory KYC procedures and transaction monitoring.
- Legitimate Interests: Processing is necessary for jw001's legitimate business interests — including fraud prevention, Platform security, responsible gaming monitoring, and improving our services — where those interests are not overridden by your fundamental rights and freedoms.
- Consent: Where jw001 relies on your consent as the legal basis for processing (principally for direct marketing communications), you have the right to withdraw that consent at any time by updating your communication preferences in account settings or by contacting support. Withdrawal of consent does not affect the lawfulness of processing carried out before the withdrawal.
jw001 does not sell, rent, or trade your Personal Data to any third party. We share your data only in the following limited and controlled circumstances:
- Payment Processors and Banking Partners: We share the minimum necessary financial data with our partner payment gateways, local banks (BCA, BRI, BNI, Mandiri, CIMB Niaga, BSI, Bank Permata, OCBC NISP), and e-wallet providers (OVO, DANA, GoPay, ShopeePay, LinkAja) to execute deposit and withdrawal instructions. These partners are contractually bound to use your data solely for payment processing purposes.
- KYC and Identity Verification Providers: We share identity documents and photographs submitted during KYC with our accredited third-party verification partners. These providers are contractually restricted from using your data for any purpose other than completing the verification request submitted by jw001.
- Cloud Infrastructure and Hosting Providers: Your data is stored on encrypted servers operated by enterprise-grade cloud infrastructure providers. These providers act as data processors under binding data processing agreements and have no independent access to your Personal Data for their own purposes.
- Game Studio Content Providers: When you play a game powered by a third-party studio (such as Pragmatic Play, Evolution Gaming, NetEnt, Microgaming, Spribe, or Pocket Games Soft), limited technical session data (such as a session token, game round ID, and stake amount) is transmitted to that provider's game server to facilitate gameplay. No personally identifiable information beyond a pseudonymous session reference is shared with game studios.
- Regulatory Authorities and Law Enforcement: We may disclose your Personal Data to competent regulatory authorities, law enforcement agencies, or courts where we are legally required to do so, or where disclosure is necessary to prevent or detect crime, protect national security, or enforce our legal rights. We will notify you of any such disclosure where we are legally permitted to do so.
- Fraud Prevention Networks: We may share flagged account data (excluding financial details) with recognised fraud prevention organisations and shared intelligence networks used by the international gaming industry to identify and block bad actors across platforms.
- Corporate Transactions: In the event of a merger, acquisition, restructuring, or sale of all or part of jw001's business, your Personal Data may be transferred to the acquiring or merged entity, subject to that entity assuming all obligations under this Privacy Policy. You will be notified of any such transfer in advance.
jw001 will never sell your Personal Data to advertisers, data brokers, or any unrelated third-party commercial entity. Data sharing is strictly limited to the service-delivery and compliance purposes described above.
jw001 uses cookies and similar tracking technologies to operate core Platform functions, enhance your experience, and gather analytical data. The following categories of cookies are used:
| Cookie Type |
Purpose |
Retention |
| Strictly Necessary |
Session management, authentication tokens, security tokens, load balancing. Cannot be disabled — the Platform will not function without these. |
Session / up to 24 hours |
| Functional |
Remembering your language and display preferences, storing your last-visited game lobby, and maintaining your responsible gaming settings between sessions. |
Up to 90 days |
| Analytical |
Aggregated, anonymised data on how Members navigate the Platform — page views, session duration, click paths, error rates — used to improve performance and UX. |
Up to 12 months |
| Affiliate & Referral |
Tracking which referral source or affiliate partner directed you to jw001, to enable correct commission attribution. No Personal Data is shared with affiliates. |
Up to 30 days |
You can manage your cookie preferences at any time through your browser settings. Disabling functional or analytical cookies will not prevent you from using the Platform but may affect your experience. Strictly necessary cookies cannot be disabled via browser settings without preventing the Platform from functioning.
jw001 does not use third-party advertising cookies or retargeting pixels. We do not share your browsing behaviour with social media platforms, ad networks, or any external marketing technology providers.
jw001 retains your Personal Data only for as long as is necessary to fulfil the purposes for which it was collected, or as required by applicable law and regulatory obligations. The following retention periods apply:
- Active Account Data: Retained for the duration of your membership plus a minimum period of five years following account closure, to meet AML and gaming regulatory record-keeping requirements.
- KYC Documents: Identity documents, verification photographs, and associated compliance records are retained for a minimum of five years from the date of submission or from the date of account closure, whichever is later. This retention period reflects standard international AML compliance requirements.
- Financial Transaction Records: Deposit, withdrawal, and betting transaction records are retained for a minimum of five years from the date of each transaction, consistent with financial record-keeping obligations.
- Support Communications: Chat transcripts and email correspondence are retained for three years from the date of each interaction, for complaint resolution and quality assurance purposes.
- Marketing Consent Records: Records of marketing opt-in and opt-out events are retained for the duration of your membership and for three years following account closure, to demonstrate compliance with consent obligations.
- Technical and Log Data: Server logs, IP address records, and session data are retained for 12 months, after which they are permanently deleted or anonymised.
Upon expiry of the applicable retention period, your Personal Data will be securely and permanently deleted from jw001's systems, unless we are required by law to retain it for a longer period. Where data is anonymised rather than deleted, it can no longer be attributed to you and is no longer considered Personal Data.
jw001 applies a comprehensive, multi-layered security framework to protect your Personal Data against unauthorised access, disclosure, alteration, and destruction. Our security measures include, but are not limited to, the following:
- 256-Bit SSL Encryption: All data transmitted between your device and the jw001 Platform is encrypted using industry-standard 256-bit SSL/TLS encryption. This ensures that your login credentials, financial data, and personal information cannot be intercepted in transit.
- Encrypted Data Storage: Personal Data and Sensitive Data stored on jw001's servers are encrypted at rest using AES-256 encryption. Database-level encryption ensures that even in the unlikely event of a server compromise, data cannot be read without the corresponding encryption keys.
- Access Controls: Access to Personal Data within jw001's internal systems is granted on a strict need-to-know basis. Staff members are assigned role-based access permissions commensurate with their job function. Administrative access to production data requires multi-factor authentication.
- Intrusion Detection and Monitoring: jw001's infrastructure is protected by real-time intrusion detection systems, web application firewalls, and 24/7 security monitoring. Suspicious activity triggers automated alerts and immediate investigation by our security team.
- Third-Party Security Audits: jw001 engages independent security auditors on a regular basis to conduct penetration testing and vulnerability assessments of the Platform. Critical findings are remediated within 48 hours of disclosure.
- Incident Response: In the event of a confirmed data breach that is likely to result in a risk to your rights or freedoms, jw001 will notify affected Members without undue delay, providing details of the nature of the breach, the data involved, and the steps taken to contain and remediate it.
No online system is entirely immune to security risks. jw001 strongly recommends that Members use a strong, unique password for their account and enable two-factor authentication (2FA) in account settings to add a critical second layer of protection against unauthorised access.
As a data subject, you hold a number of rights with respect to your Personal Data held by jw001. These rights are described below. To exercise any of these rights, please contact our Data Protection Officer at [email protected] with the subject line "Privacy — Data Rights Request". We will respond within 30 days of receiving a valid request.
Right of Access
You have the right to request a copy of the Personal Data we hold about you, along with information about how it is processed. We will provide this in a structured, commonly used format.
Right to Rectification
You have the right to request correction of inaccurate or incomplete Personal Data held about you. You may also update many details directly in your account settings.
Right to Erasure
You may request deletion of your Personal Data where it is no longer necessary for the purposes for which it was collected, subject to overriding legal retention obligations (see Clause 9).
Right to Restrict Processing
You may request that we restrict processing of your Personal Data in certain circumstances — for example, while a dispute about accuracy is being resolved, or where you have objected to processing based on legitimate interests.
Right to Data Portability
Where processing is based on your consent or contractual necessity, you may request a machine-readable export of the Personal Data you provided to us, suitable for transfer to another service provider.
Right to Object
You may object to processing carried out on the basis of jw001's legitimate interests, or to direct marketing at any time. We will cease that processing unless we can demonstrate compelling legitimate grounds that override your interests.
Right to Withdraw Consent
Where processing is based on your consent, you may withdraw that consent at any time without affecting the lawfulness of prior processing. Update your preferences in account settings or contact our team.
Right to Complain
If you believe jw001 has not handled your Personal Data in accordance with this policy or applicable law, you have the right to lodge a complaint with the relevant supervisory authority in your jurisdiction.
Certain rights are subject to limitations where the data in question is required for AML compliance, fraud investigation, or other regulatory obligations. In such cases, jw001 will explain the specific limitation and retain only the minimum data required to satisfy the legal obligation.
The jw001 Platform is strictly intended for adults aged 21 and over. jw001 does not knowingly collect Personal Data from individuals under the age of 21. Age verification is a mandatory component of our KYC process, and any account found to belong to a person under 21 will be immediately suspended, all balances will be frozen pending investigation, and the relevant data will be retained only for the period required to fulfil our legal reporting obligations before being securely deleted.
If you are a parent or guardian and have reason to believe that a minor in your care has registered an account or submitted Personal Data to jw001, please contact us immediately at [email protected]. We will investigate and take appropriate action, including account closure and data deletion, within 24 hours of receiving a verified report.
21+ strictly enforced. jw001 uses a combination of automated age-check systems and manual document review to identify and prevent underage access to the Platform.
The jw001 Platform may contain links to third-party websites, including game studio interfaces and payment provider portals, which operate under their own independent privacy policies. jw001 is not responsible for the privacy practices or content of any third-party site or service. We recommend that you review the privacy policy of any third-party service you access in connection with using the Platform.
Where a third-party game is embedded within the jw001 Platform interface (for example, a live dealer table powered by Evolution Gaming, or a slot title from Pragmatic Play), the relevant studio's privacy policy governs the processing of any data transmitted directly to their game server. jw001 only shares pseudonymous session tokens with game studios — no full identity or financial data is transmitted.
jw001 reserves the right to update or amend this Privacy Policy at any time to reflect changes in our data processing practices, operational requirements, or applicable law. When material changes are made, we will:
- Update the "Last updated" date displayed at the top of this page.
- Display a prominent notification within the Platform for a minimum of 7 days following the change.
- Send an email notification to all active Members where the changes materially affect how their Personal Data is processed.
Your continued use of the Platform following the effective date of any amendment constitutes your acceptance of the revised Privacy Policy. If you do not agree with any amendment, you should stop using the Platform and may request account closure by contacting our support team at [email protected].
For all privacy-related inquiries, data rights requests, and formal complaints regarding jw001's handling of your Personal Data, please contact our Data Protection Officer using the details below:
- Email: [email protected] — use subject line "Privacy — Data Rights Request" for data rights matters, or "Privacy — Formal Complaint" for complaints.
- Live Chat: Available 24/7 via the chat widget on the Platform. For complex privacy matters, email is preferred to ensure proper routing to the DPO.
- Response Time: We commit to acknowledging all privacy-related requests within 48 hours and to providing a substantive response within 30 calendar days. Where a request is complex or involves a large volume of data, we may extend this period by a further 30 days, with prior notice.
- Language: You may contact our team in English or Indonesian. Our support agents are native Indonesian speakers and will respond in your preferred language.
Our support team is available around the clock, including on Indonesian public holidays. For data rights requests requiring formal processing, email is the recommended channel to ensure your request is correctly logged and tracked by our compliance team.