How dokter303 Handles Your Account Data
This is the privacy policy page for dokter303. We've written it in plain English so you know exactly what we collect when you open an account, how we...
Our Data Posture and Your Rights
We collect the minimum needed to run your dokter303 account: your registered name, contact handle, payment reference, login timestamps and the device you're signing in from. Where local law permits in Indonesia, we keep this on encrypted servers and share it only with the payment partners that move your DANA, OVO, GoPay and QRIS transactions. You can request a copy of your
record, ask us to correct something, or close the account entirely — we action requests within the windows our jurisdiction sets. We never sell your contact details to third-party marketers, and our staff access logs are reviewed monthly so nothing leaves the brand without a paper trail you could see if you asked.
Service availability is jurisdiction-dependent. Users are responsible for checking local law before access.
Privacy Contact Paths
If anything in this policy isn't clear, reach us through the channels below. Our privacy desk is separate from general account support so your request lands with the team who can actually...
How We Keep This Policy Honest
Trust on a privacy page comes from process, not promises. Here's what sits behind every line above.
Internal Review Cadence
Our compliance lead re-reads this page every quarter and after any change to how we route DANA, OVO, GoPay or QRIS data. Version stamps sit at the foot of the document.
Named Data Owner
One person on our side owns the data register. That means when you write in, a real human signs the response — not an autoresponder pretending to be a department.
Encrypted Storage
Account fields and payment references sit behind transport and at-rest encryption. Staff access is keyed to role, and every read is logged against a named account on our admin layer.
Partner Vetting
Before any payment partner touches your data, we check their handling standards. If a provider can't meet our floor for Indonesia accounts, they don't appear in the chip row.
Retention Limits
We don't hoard. Closed accounts have personal fields purged after the legal retention window, and only the minimum transaction record stays for audit obligations our jurisdiction requires.
Breach Protocol
If something goes wrong, we tell affected account holders directly and notify the relevant Indonesia authority within the statutory window. No hiding behind vague status pages.
Consistency Across Our Policy Pages
This page lines up with our terms, cookie notice and account closure rules so you don't read conflicting promises across the site.
What Defines This Policy Layout
A few editorial choices shape how this privacy page reads. They're the same choices we apply across every legal document on dokter303.
Section Anchors
Each block on this page has a stable anchor link so you can deep-link to a specific clause when you write in. Useful when you want to quote a precise paragraph back at us.
Last-Updated Stamp
The footer of the policy carries the date of our most recent edit. If the stamp moves, something material changed — scan the diff summary we publish alongside it.
Plain-Language Floor
We strip legal jargon wherever it isn't load-bearing. Where a term has to stay, we explain it in the line that follows so the page reads at a normal pace.
Mobile-Readable Layout
Headings, short paragraphs and clear item rows render cleanly on phone screens. You shouldn't need to pinch-zoom to read your own data rights on the train.
Cross-Linked Clauses
Where a clause leans on another document — terms, closure flow, cookie notice — we link directly to that page. No hunting through a sitemap to find the matching rule.
Quiet Tone
No banners, no countdowns, no upsell on a legal page. The policy reads like a contract you'd actually sign, not a landing page wearing a legal mask.