LEGAL REFERENCE

How We Handle Your Account Data

This is the hokimas privacy policy — the page that tells you exactly what we collect when you open an account, why we keep it, and how long...

Account dataCookiesRetentionYour rightsContact us
hokimas How We Handle Your Account Data

Policy Posture and Jurisdiction Scope

Service availability is jurisdiction-dependent. Users are responsible for checking local law before access.

24/7 SUPPORT

Privacy Contact Paths

Privacy inbox Email our privacy desk directly when you want...
In-account chat Open the chat widget once you're signed in...
Written notice Send a formal written notice for legal requests...
EDITORIAL CLARITY

How We Review This Policy

Editorial owner

Our policy team owns this page. They draft the wording, log every change and sign off on each revision before it goes live so you're reading something a real person stands behind.

Legal review

Indonesian counsel reviews the text against current local rules where applicable. Any change in obligation triggers a redraft, not a footnote, so the page stays aligned with the law that touches you.

Security input

Our security lead checks the storage and retention claims against what the systems actually do. If the infrastructure changes, the wording changes with it — never the other way around.

Version history

Each published version carries a date and a short note on what shifted. You can ask us for prior versions if you want to compare what applied when you first opened your account.

Plain language

We rewrite legalese into plain English on purpose. If a clause reads like it needs a lawyer to translate, we send it back to the desk and rework it before publishing.

Reader feedback

When you tell us a section is unclear, we treat that as a defect. Recent rewrites of the cookies and retention paragraphs came directly from questions you sent through chat.

Consistency With Our Other Policy Pages

Terms of Service
Our terms describe the rules for using the lobby; this privacy page describes the data side. The two are written together so definitions and contact paths line up across both.
Cookie Notice
The cookie notice expands the short cookies paragraph here into a full table of categories, lifetimes and toggles you can flip from the preference centre.
Account Closure
Closing your account triggers the deletion path described in this policy. The closure page walks you through the steps; this page tells you what happens to the data afterwards.
KYC Notice
Identity checks are summarised here and detailed on the KYC notice. Both pages reference the same retention windows so you don't get conflicting timelines.
Marketing Preferences
Opt-ins and opt-outs for messages live on the preferences page. This policy explains the legal basis we rely on when those toggles are set.
Complaints Path
If you're unhappy with how we handled a privacy request, the complaints page tells you where to escalate next, including the regulator route.
Data Processors
The processor list page names the third parties who touch your data. This policy explains the categories; that page names the vendors behind each one.
SERVICE CONTEXT

What This Policy Page Includes

01
Scope statement A clear opening that tells you which products and which account flows the policy covers, so you know upfront whether the page applies to the part of hokimas you're using.
02
Data categories A breakdown of the categories we hold — identity, contact, device, transaction metadata — written without jargon. Each category links to why we collect it rather than leaving you to guess.
03
Retention windows Specific timeframes for how long each category sits with us, with the legal or operational reason attached. No vague phrasing about keeping things 'as long as necessary'.
04
Your rights panel A panel that lists what you can ask for: access, correction, deletion, export, objection. Each right has the contact path and the response window we commit to next to it.
05
Sharing map A short map of who else sees your data and why — payment routers, fraud screens, hosting. The processor list page carries the names; this page carries the categories.
06
Update log A dated log at the foot of the page showing the last revision and a short note on what changed, so you can tell at a glance whether anything material has shifted recently.

Privacy Policy Questions

We collect the identity and contact details needed to verify you, the device fingerprint we use for fraud screening, and the wallet reference tied to your DANA, OVO, GoPay or QRIS payment route.

Active accounts keep their records as long as the account stays open. After closure, we hold the minimum that financial and regulatory rules require, then run a deletion pass once the legal hold expires.

Yes. Email the privacy desk or raise it through in-account chat. We confirm your identity, gather the record across our systems and send you an export within the window stated in the policy.

We share with processors who help run the lobby — payment routing, fraud checks, hosting and customer support tools. We do not sell your data and we do not pass it to advertisers outside our own marketing.

Open the preferences page in your account and flip the toggles for email, SMS or push. The change takes effect on the next send cycle and your transactional messages keep coming as normal.

Closure triggers a staged deletion. We remove what we can immediately, retain what financial rules require for the holding period, and purge the rest once the clock runs out on each category.

Material changes are announced in-account and by email before they take effect. The dated log at the foot of the page records every revision so you can check what shifted and when.