Personal Data Protection

Privacy Policy

Effective as of January 1, 2026 Estimated reading time: 10 minutes
Right to Access
Right to Rectification
Right to Erasure
Right to Data Portability
Right to Object
Right to Restriction of Processing
This Document Is Important
This Privacy Policy explains how NobiPlay collects, uses, and protects your personal data in accordance with Personal Data Protection Law No. 27 of 2022. We encourage you to read it thoroughly. Questions? Contact our DPO at [email protected].
Never Sold
Your personal data is never sold to third parties for commercial purposes.
Encrypted
All data transmissions are protected with TLS 1.3 encryption, and sensitive data is stored in encrypted form.
Full Control
You have 6 rights over your personal data that you can exercise at any time.
01

Introduction

Who we are and why this policy exists

PT Indotech Digital Group ("NobiPlay", "we", "us") is the data controller responsible for processing your personal data in connection with NobiPlay's streaming services. This Privacy Policy applies to all NobiPlay products and services, including the nobiplay.id website, mobile applications, and Smart TV applications.

This policy is drafted and updated in accordance with:

  • Law No. 27 of 2022 on Personal Data Protection (PDP Law)
  • Law No. 11 of 2008 on Electronic Information and Transactions (EIT Law), as amended
  • Government Regulation No. 71 of 2019 on the Implementation of Electronic Systems and Transactions
  • International industry best practices, including GDPR principles
Data Protection Officer (DPO): NobiPlay has appointed a Data Protection Officer who can be reached at [email protected] for questions or complaints regarding privacy.
02

Data We Collect

The types of personal data we process

We collect the following categories of personal data, each with its own basis and purpose:

Data CategoryDetailsType
Identity Data Full name, username, date of birth, gender, profile photo Required
Contact Data Email address, phone number, address (optional) Required
Authentication Data Password hash, session tokens, 2FA data, login history Required
Payment Data Last 4 digits of card, bank/e-wallet name, transaction history (full card data is not stored โ€” it is processed by a third-party payment gateway) Required Legal
Usage Data Viewing history, watch duration, liked/saved content, searches, ratings, comments Automatic
Device & Technical Data IP address, device type, operating system, browser/app version, device identifier (Device ID) Automatic
Location Data Approximate location based on IP address (country/city) to determine content availability. Precise GPS location only if you grant permission Automatic Optional
Communication Data Customer support messages, feedback, surveys you submit Optional
Inferred Data Content preferences, interest profiles, and user segments we generate based on analysis of usage behavior Automatic
We do not collect sensitive personal data such as racial/ethnic data, religious beliefs, biometric data, health data, or criminal records, except explicitly and with your specific consent.
03

How We Collect Data

Sources and methods of data collection

3.1 Data you provide directly when registering an account, completing your profile, making a payment, contacting our support team, filling out a survey, or interacting with the Platform's social features.

3.2 Data collected automatically when you use the Platform, including through cookies, web beacons, mobile app SDKs, and similar tracking technologies. See Section 7 for further details.

3.3 Data from third parties, including:

  • Social Login: If you sign in using Google, Facebook, or Apple, we receive basic profile data (name, email, photo) from that provider in accordance with the permissions you grant.
  • Payment Partners: Payment service providers share transaction confirmations and payment status with us.
  • Analytics Partners: Third-party analytics services provide us with aggregated data on how users interact with our Platform.
  • Public Sources: Publicly available information relevant for verification or fraud prevention purposes.
04

Purpose of Data Use

How and why we process your data
PurposeProcessing Details
Service ProvisionCreating and managing accounts, processing payments, enabling streaming and downloads, managing profile preferences.
PersonalizationGenerating personalized content recommendations based on viewing history, preferences, and usage behavior.
Service CommunicationsSending transaction confirmations, account notifications, policy updates, and important technical information.
Marketing CommunicationsWith your consent, sending promotional offers, new content, and product information. You may unsubscribe at any time.
Security & Fraud PreventionDetecting, investigating, and preventing fraudulent activity, unauthorized use, or violations of the Terms of Service.
Analytics & Service ImprovementUnderstanding how the Platform is used, identifying technical issues, measuring feature effectiveness, and improving user experience.
Legal ComplianceFulfilling legal obligations, responding to lawful requests from law enforcement, and protecting NobiPlay's rights.
Customer SupportHandling inquiries, complaints, and requests for technical assistance.
05

Legal Basis for Processing

The legal grounds that justify our processing of data

In accordance with Article 20 of the PDP Law, we process your personal data based on one of the following legal grounds:

  • Performance of a contract: Processing necessary to provide NobiPlay's services in accordance with the Terms and Conditions you have agreed to (account, payment, streaming).
  • Consent: For optional processing such as marketing communications, advanced analytics, and data sharing with certain partners โ€” we request your explicit consent, which may be withdrawn at any time.
  • Legitimate interest: For account security, fraud prevention, and service improvement, where our interests do not override your rights.
  • Legal obligation: Where processing is required under applicable Indonesian law, including tax, cybersecurity, and law enforcement obligations.
You may withdraw previously given consent at any time via Profile โ†’ Settings โ†’ Privacy & Consent without affecting the lawfulness of processing carried out before the withdrawal.
06

Data Sharing & Disclosure

Who we may share your data with

NobiPlay does not sell your personal data. We may only share data in the following situations:

RecipientData SharedBasis
Cloud Infrastructure ProvidersData stored on encrypted cloud servers (AWS, GCP) operating under strict data processing agreementsAgreement
Payment GatewaysData required to process transactions (name, email, amount). Full card data never passes through our serversAgreement
Content Partners & StudiosAggregated and anonymized data on viewing patterns for licensing reports โ€” no personal identity data includedContract
Analytics ServicesPseudonymized usage data for product analytics (Firebase, Mixpanel)Consent
Law EnforcementData requested through lawful legal process, in accordance with Indonesian legal obligationsLegal Obligation
Business SuccessorsIn the event of a merger, acquisition, or corporate restructuring, data may be transferred with notice to youLegitimate Interest

All third-party partners that receive your data are bound by confidentiality and data protection agreements equivalent to our own standards.

08

Data Retention & Deletion

How long we retain your data

We retain personal data only for as long as necessary to fulfill the purpose for which it was collected or to comply with applicable legal obligations:

Data TypeRetention Period
Active account dataFor the duration the account is active, plus 90 days after account closure
Viewing history & preferences3 years from the last interaction, or until the account is closed
Transaction & payment data10 years (in accordance with Indonesian tax and accounting obligations)
Security & access logs2 years for misuse detection and security audits
Customer support communications3 years from ticket resolution
Analytics data (anonymized)Indefinitely (as it cannot be attributed to an individual)
Cookies & session dataSession: deleted when the browser is closed. Persistent: 90 days โ€“ 2 years depending on type

Once the retention period ends, data will be securely deleted or permanently anonymized so that it can no longer be attributed back to you.

09

Data Security

The technical and organizational measures we implement

NobiPlay implements adequate technical and organizational security measures to protect your personal data from unauthorized access, alteration, disclosure, or destruction:

  • Encryption in transit: All communications between your device and our servers are encrypted using TLS 1.3.
  • Encryption at rest: Sensitive data is stored in encrypted form using AES-256.
  • Layered authentication: Our systems support two-factor authentication (2FA) and secure login features.
  • Role-based access: Only personnel who require data access to perform their duties are granted access, following the principle of least privilege.
  • Regular security audits: We conduct penetration testing and security audits regularly through independent third parties.
  • 24/7 monitoring: Intrusion detection and anomaly monitoring systems operate continuously.
  • Incident response plan: Documented security incident response procedures with a clear reporting timeline.
Although we implement the best security measures, no system is ever completely 100% secure. In the event of a data breach affecting your data, we will notify you within 72 hours as required by the PDP Law.
10

Children's Privacy

Special protections for underage users

10.1 Age Restriction. NobiPlay's services are not intended for children under the age of 13. We do not knowingly collect personal data from children under 13. If we become aware that we have collected data from a child under this age without verified parental consent, we will promptly delete that data.

10.2 Users Aged 13โ€“17. For users aged 13โ€“17, use of NobiPlay's services requires the consent of a parent or guardian. Certain features, such as adult content and in-app purchases, require parental verification.

10.3 Children's Profiles (Kids Mode). Children's profiles created by parents through the Parental Controls feature can only access age-appropriate content. Usage data from children's profiles is not used for targeted advertising.

If you are a parent who believes your child has created a NobiPlay account without your permission, please contact us immediately at [email protected] to have the account removed.
11

Data Subject Rights

Your rights over your personal data under the PDP Law

Under the PDP Law and international best practices, you have the following rights over your personal data:

Right to Access
You have the right to obtain confirmation of the data we hold and to receive a copy of that data. This can be requested via Profile โ†’ Settings โ†’ Download Data.
Right to Rectification
You have the right to request correction of inaccurate or incomplete data. This can be done directly in Profile โ†’ Edit Profile.
Right to Erasure
You have the right to request the deletion of personal data under certain conditions. Send your request to [email protected].
Right to Data Portability
You have the right to receive your data in a structured, machine-readable format for transfer to another service.
Right to Object
You have the right to object to the processing of data based on legitimate interest, including profiling for direct marketing purposes.
Right to Restriction of Processing
You have the right to request restriction of data processing under certain conditions, for example while the accuracy of the data is being disputed.

To exercise the rights above, send a written request to [email protected]. We will respond within 30 calendar days of receiving the request. For complex requests, this period may be extended by 60 days with notice.

12

International Data Transfers

Cross-border data transfers and their safeguards

Some of our service providers that store or process data are located outside Indonesia. Where an international data transfer occurs, we ensure equivalent protection through:

  • Standard Contractual Clauses that require the data recipient to comply with an equivalent standard of data protection.
  • Protection level verification โ€” we only transfer data to countries or entities that have an adequate level of data protection.
  • Data Processing Agreements with all partners that receive personal data.

Currently, NobiPlay data may be processed at facilities located in: Indonesia (primary servers), Singapore, and the United States (for certain cloud services).

13

Changes to This Policy

How we communicate updates

NobiPlay may update this Privacy Policy from time to time to reflect changes in our practices, regulatory changes, or technological developments. We will notify you through:

  • In-app notifications or pop-ups on the website for material changes.
  • An email to your registered address at least 14 days before the change takes effect.
  • An update to the "Effective as of" date at the top of this document.

Continued use of the service after the effective date of a change indicates your acceptance of the updated Privacy Policy. If you do not agree with a material change, you may close your account before the change takes effect.

Last updated: January 1, 2026 โ€” Version 3.1
14

Contact & Data Protection Officer

How to contact our privacy team and DPO

For questions, objections, or complaints regarding the handling of your personal data, please contact:

Role / ChannelContact Details
Data Protection Officer (DPO)[email protected] โ€” for privacy complaints and data subject rights requests
General Privacy Team[email protected] โ€” for general questions about this policy
Data Security[email protected] โ€” to report security incidents or data breaches
Postal AddressTim Privasi & DPO, PT Indotech Digital Group, Gedung Indotech Tower Lt. 18, Jl. Sudirman Kav. 52โ€“53, Jakarta Selatan 12190
Regulator (BSSN/Kominfo)If you are not satisfied with our response, you may file a complaint with the National Cyber and Crypto Agency (BSSN) or the Ministry of Communication and Informatics (Kominfo)

We are committed to responding to all privacy inquiries within 5 business days and resolving data subject rights requests within 30 calendar days.

Your Privacy, Our Priority

We are committed to protecting your personal data and respecting your rights under PDP Law No. 27 of 2022. If you have any questions, our DPO team is always ready to help.