Privacy vs Terms
Our terms cover the contract between you and hokipalace; this privacy policy covers data only. The two documents reference each other but never contradict on retention or consent.
This is our privacy policy — the plain-English version of how we collect, store and protect the data tied to your hokipalace account. We wrote it for you...
We process your personal data where local law permits and only inside supported regions. When you open an account with hokipalace, we collect your name, contact details, device identifiers and wallet references tied to DANA, OVO, GoPay or QRIS so we can route deposits and withdrawals correctly. We store transactional logs for the period our licensing framework requires, then archive or purge
them. We never sell your data to third-party advertisers. You can request access, correction or deletion through the contact paths listed further down this page, and we respond inside the windows our jurisdiction sets out.
Service availability is jurisdiction-dependent. Users are responsible for checking local law before access.
Our policy is reviewed by qualified counsel familiar with Indonesia's data protection framework. Every revision is logged with a date stamp so you can see when wording changed and which clauses were updated.
A named data protection officer signs off on every change. Their remit covers access requests, breach handling and the retention schedule we apply to your wallet and identity records.
Account credentials, KYC documents and wallet identifiers are stored encrypted at rest. Decryption keys are rotated and access is logged so we can audit who viewed your record and when.
Independent assessors review our handling of personal data on a fixed schedule. Their findings feed directly into the next revision of this privacy policy and any process changes we publish.
We deliberately avoid legalese where we can. The policy is drafted to be read by you, not just by lawyers, so consent choices are obvious and your rights are stated up front.
When clauses that affect your rights are updated, we notify you by email and surface a banner inside your account before the new version takes effect.
Our terms cover the contract between you and hokipalace; this privacy policy covers data only. The two documents reference each other but never contradict on retention or consent.
The cookies notice expands on browser-side tracking. This page covers the wider data picture, including server logs, KYC files and wallet references that cookies alone never touch.
KYC rules sit inside our compliance page. Here we explain what happens to the documents after verification — how long we keep them and who inside hokipalace can view them.
Marketing consent is opt-in and managed separately in your account settings. This policy describes what marketing data we process, never the promotional content itself.
Our payments page lists DANA, OVO, GoPay and QRIS flows. This policy covers the data those flows generate — wallet references, transaction IDs, timestamps.
Security pages describe controls; the privacy policy describes purpose. Both reference the same encryption and access logging, written for different audiences.
Every sibling policy carries a version stamp. When one document changes, we cross-check the others to keep wording about retention and your rights perfectly aligned.
A clear opening that names exactly which hokipalace properties this policy applies to, so you know whether the lobby, the mobile flow and our communications are covered under one document.
A categorised breakdown of personal data we collect: identity fields, device signals, wallet references and behavioural records, each tied to a stated purpose you can verify against the consent boxes.
A table-style retention schedule showing how long each data category lives in our systems before it's archived or destroyed, written so you can match it against your own record-keeping needs.
A dedicated rights block covering access, correction, portability, withdrawal of consent and deletion. Each right is paired with the contact path you use to exercise it.
Our incident response wording explains what we do if your data is exposed, how quickly we notify you and the regulator, and the remediation steps you can expect from us.
A visible version history at the foot of the page so you can confirm when the policy was last revised and which sections changed since you signed up.