Reference

Explore Your Legal Rights on nawatoto

nawatoto operates under a clear legal framework designed for Indonesia, where access and eligibility depends on local law.

Jurisdiction-Aware TermsDANA, OVO, GoPay & QRIS CoveredData Privacy ProtectedAccount Security EnforcedDispute Resolution Path Clear
nawatoto Explore Your Legal Rights on nawatoto
LEGAL CONTACT PATHS

Open a Legal Inquiry Through These Channels

If you need clarification on any clause, want to submit a data-access request, or need to raise a dispute about a DANA or OVO transaction, our compliance team is reachable through three…

Live Chat — Legal Queue Available 07:00–23:00 WIB, seven days a week. Select 'Legal & Compliance' from the chat menu to reach the dedicated team, not general support. Response within four business hours for formal queries.
Email — Compliance Desk Send your written request to our compliance address listed in your account dashboard under Settings > Legal Contact. Include your account ID and the specific clause or transaction reference for faster resolution.
Account Portal — Data Request Form Log in, navigate to Settings > Privacy, and submit a data-access or deletion request directly. We process these requests within five business days and confirm completion by email.
HOW WE HANDLE THIS

Switch to Secure Account Practices We Enforce

Every legal and data-handling practice on nawatoto is documented, auditable and explained in plain language.

Data Retention Policy

Transaction records — including all DANA, OVO, GoPay and QRIS activity — are retained for five years as required under applicable Indonesia financial regulation. You may request a summary at any time via the portal.

Cookie Handling

We use session cookies to keep you logged in and functional cookies to remember your preferred language and region. No behavioural tracking cookies are shared with advertising networks without your explicit consent.

Account Security Standards

All account credentials are stored using bcrypt hashing. Two-factor authentication is available and strongly encouraged. Suspicious login attempts trigger an automatic lock and an immediate notification to your registered email.

Who to Contact for Changes

To update personal data — name, email, linked payment method such as GoPay or QRIS — submit a verified request through Settings > Profile. Changes go live within 48 hours after identity confirmation.

Dispute & Appeal Process

Raise a formal dispute within 30 days of the relevant transaction. Our compliance team reviews the payment log, contacts the relevant rail (DANA, OVO, GoPay or QRIS) if needed, and delivers a written outcome within five business days.

Third-Party Data Sharing

We share account data only with payment processors required to clear your transaction and with regulatory bodies where Indonesian law mandates disclosure. No data is sold, rented or passed to marketers.

Discover Answers to Common Legal Queries

These are the questions we hear most often about rights, data, account access and how our policies apply in Indonesia. If your question is not covered here, use the Legal Contact path above to reach our compliance team directly.

Access to certain services and the applicable rules depend on local law. Our terms are written to align with Indonesia regulation, and any feature that depends on local law is clearly flagged inside your account dashboard.

Log in and go to Settings > Privacy, then select 'Request Data Export'. We compile your account history, transaction records and profile data into a downloadable file delivered within five business days.

Yes. Submit a deletion request through Settings > Privacy. We remove personal identifiers within 30 days, retaining only the transaction records legally required under Indonesia financial regulation for the mandatory five-year period.

Submit a dispute within 30 days via the account portal. Our team reviews the payment log, contacts the relevant rail directly, and provides a written resolution within five business days of acknowledgement.

Payment method tokens — not raw card or wallet numbers — are stored using AES-256 encryption. We never store full wallet credentials; the token is used only to initiate the transaction you authorise.

We send a notification to the email address registered to your account at least seven days before any material change takes effect. A banner also appears in your account lobby until you acknowledge the updated terms.

Reach our compliance desk via email or the in-account portal under Settings > Legal Contact. We acknowledge formal complaints within four business hours and aim for a full written response within two business days.