Your Privacy Matters: mg525 does not sell, rent, or trade your personal data to third-party marketers. We process your data only for the purposes described in this policy and only to the extent necessary to deliver our services, comply with legal obligations, and protect the security of the platform and its users.
This Privacy Policy applies to all users of the mg525 platform, accessible at mg525.bio and any associated mirror domains, mobile-optimised pages, or subdomains operated by us. It covers every interaction you have with mg525 — including browsing the site as a guest, registering an account, making deposits and withdrawals, placing bets, contacting support, or participating in promotions.
By accessing the mg525 platform or creating an account, you acknowledge that you have read and understood this Privacy Policy and consent to the processing of your personal data as described herein. If you do not agree with any part of this policy, you should not use our services.
For the purposes of this policy, "personal data" means any information that identifies or can be used to identify you as an individual, including your name, email address, date of birth, financial account details, and IP address. "Processing" means any operation performed on personal data, including collection, storage, use, disclosure, and deletion.
We collect different categories of personal data depending on how you interact with mg525. The table below summarises the main data categories and examples:
| Data Category |
Examples |
When Collected |
| Identity Data |
Full name, date of birth, gender, nationality, government-issued ID number |
Account registration; KYC verification |
| Contact Data |
Email address, phone number, city and province (e.g., Jakarta, Surabaya, Bali) |
Account registration; support requests |
| Financial Data |
Bank account details (BCA, BRI, BNI, Mandiri, CIMB Ni
aga, BSI), e-wallet identifiers (OVO, DANA, GoPay, ShopeePay, LinkAja), crypto wallet addresses (USDT, BTC), transaction history |
Deposit/withdrawal processing; KYC verification |
| Technical Data |
IP address, browser type and version, device type, operating system, time zone, screen resolution |
Automatically on site visit |
| Usage Data |
Pages visited, games played, bets placed, session duration, click-path, feature interactions |
Automatically during platform use |
| Communications Data |
Live chat transcripts, email correspondence, support ticket content, WhatsApp message records |
When you contact support |
| Marketing Data |
Promotion opt-in preferences, bonus redemption history, communication preferences |
Account settings; promotion participation |
| KYC Documents |
Scanned or photographed government-issued ID (KTP, passport, SIM), selfie verification images, proof of address documents |
Identity verification process |
Sensitive Data: mg525 does not intentionally collect special-category sensitive data such as racial or ethnic origin, political opinions, religious beliefs, or health data. If you voluntarily disclose such information (for example, in a support message), we will handle it with enhanced care and will not use it for profiling or marketing purposes.
mg525 collects your personal data through the following methods:
- Directly from you: When you complete the registration form, submit a KYC verification request, make a deposit or withdrawal, contact our support team, or participate in a promotion or survey.
- Automatically: When you visit mg525.bio, our servers and analytics tools automatically log technical data and usage data including your IP address, device identifiers, and browsing behaviour on the platform.
- Via cookies and similar technologies: We use first-party cookies, session tokens, and analytics scripts to track your interactions with the platform. See Section 7 for full details on our cookie practices.
- From payment processors: When you initiate a deposit or withdrawal, your payment provider (BCA, BRI, BNI, Mandiri, CIMB Niaga, BSI, OVO, DANA, GoPay, ShopeePay, LinkAja, or crypto network operators) shares transaction confirmation data with us to reconcile your account balance.
- From identity verification providers: During the KYC process, we may use a licensed third-party identity verification service to cross-reference the documents you submit against official databases. These providers return a verification result to us; they do not store your data on our behalf beyond their contractual obligations.
- From fraud-prevention and security partners: We receive signals from anti-fraud and device-fingerprinting services that help us detect suspicious account activity, unauthorised logins, and potential bonus abuse patterns.
mg525 uses the personal data we hold about you for the following purposes:
- Account creation and management: To register your account, verify your identity, maintain your account preferences, process your KYC documentation, and communicate account-related notifications.
- Transaction processing: To accept deposits via BCA, BRI, BNI, Mandiri, CIMB Niaga, BSI, OVO, DANA, GoPay, ShopeePay, LinkAja, USDT, and BTC; to process withdrawal requests; to maintain an auditable transaction history accessible from your account dashboard.
- Service delivery: To provide access to all mg525 products including the sportsbook, live casino, slots, Dragon Tiger, and Bingo Online; to record bet placements and game results; and to settle wagers accurately in accordance with our Terms & Conditions.
- Customer support: To respond to your enquiries, resolve disputes, process complaints, and provide assistance via live chat, WhatsApp, and email during our published support hours (07:00–24:00 WIB).
- Fraud prevention and security: To detect and prevent fraudulent activity, multi-accounting, money laundering, bonus abuse, and unauthorised account access. We use automated systems and human review to flag and investigate suspicious patterns.
- Legal and regulatory compliance: To meet our anti-money-laundering (AML) obligations, retain records as required by our international operating licence, and respond to lawful requests from competent authorities.
- Marketing communications: To send you promotional offers, bonus notifications, and updates about new games or features — but only where you have given explicit consent or where we have a legitimate interest in doing so. You may withdraw marketing consent at any time from your account settings or by emailing [email protected].
- Platform improvement: To analyse aggregated usage patterns, identify bugs and performance issues, test new features, and improve the overall quality and reliability of the mg525 platform.
- Responsible gaming: To monitor betting patterns that may indicate problem gambling, enforce deposit limits and self-exclusion requests, and send responsible gaming notifications where appropriate.
Every processing activity carried out by mg525 rests on one or more of the following legal bases:
- Contractual necessity: Processing required to fulfil our contract with you — including account management, transaction processing, game delivery, and customer support — is carried out on the basis that it is necessary to perform the services you have requested.
- Legal obligation: Processing required to comply with applicable laws and our international licence conditions — including KYC verification, AML record-keeping, and responding to lawful authority requests — is carried out on the basis of legal obligation.
- Legitimate interests: Processing carried out for fraud prevention, platform security, abuse detection, and aggregate analytics is based on our legitimate interest in operating a safe and commercially viable platform, balanced against your privacy rights. We conduct legitimate-interest assessments before relying on this basis.
- Consent: Processing for marketing communications and the use of non-essential cookies is carried out only with your explicit prior consent. You may withdraw consent at any time without affecting the lawfulness of prior processing.
mg525 does not sell your personal data. We share it only in the following controlled circumstances:
- Payment processors: We share the minimum financial data necessary with your chosen payment provider (e.g., BCA, BRI, OVO, DANA, GoPay, ShopeePay, LinkAja, or crypto network operators) to execute your deposit or withdrawal transaction. These providers are contractually prohibited from using your data for any purpose other than processing the relevant transaction.
- Identity verification providers: During the KYC process, we share your submitted documents with a licensed verification partner. This partner processes your data solely to return a verification status to mg525 and is bound by strict data processing agreements.
- Game content providers: When you play a game delivered by a third-party studio (such as Evolution Gaming, Pragmatic Play, NetEnt, Microgaming, Spribe, or Pocket Games Soft), your session data — including stake amounts and game outcomes — is shared with that studio's platform for the purpose of game operation and RNG certification. These providers do not receive your identity documents or payment details.
- Fraud and security partners: We share device fingerprint data, IP addresses, and behavioural signals with anti-fraud service providers to protect the platform and our users against malicious activity.
- Legal authorities: We may disclose personal data to government bodies, law enforcement agencies, or regulatory authorities where we are legally required to do so or where disclosure is necessary to protect the rights, property, or safety of mg525, its users, or the public.
- Group companies and successors: In the event of a merger, acquisition, or restructuring of mg525's operating entity, your personal data may be transferred to the acquiring entity, subject to equivalent privacy protections.
No third-party marketing: Your personal data is never sold or provided to third-party advertisers or data brokers for their own marketing purposes. Any promotional communications you receive will be from mg525 directly and only where you have consented or where we have a legitimate interest in sending them.
mg525 uses cookies and similar technologies to operate the platform, maintain your session, prevent fraud, and analyse usage. The cookies we use fall into the following categories:
- Strictly necessary cookies: These are essential for the platform to function. They maintain your login session, store your account preferences (such as currency and language settings), and enable secure navigation between pages. You cannot opt out of strictly necessary cookies while using mg525.
- Security cookies: Used to detect and prevent fraudulent login attempts, session hijacking, and automated abuse. These cookies store encrypted session tokens and device-fingerprint identifiers.
- Analytics cookies: We use first-party analytics to understand how users navigate the platform — which pages they visit, where they drop off, and which features they use most. This data is aggregated and anonymised before analysis. We do not use Google Analytics or other third-party analytics services that export your data to external servers.
- Marketing and preference cookies: Where you have consented, we may set cookies that record your promotional preferences and help us display relevant bonus offers during your session. You may withdraw consent for these cookies at any time by clearing your browser cookies or updating your account preferences.
Most web browsers allow you to control cookie behaviour through your browser settings, including the ability to delete existing cookies and block new ones. Please note that disabling cookies may affect the functionality of the mg525 platform — in particular, disabling strictly necessary cookies will prevent you from logging in.
mg525 retains personal data only for as long as necessary to fulfil the purposes for which it was collected, or as required by applicable legal and regulatory obligations. The following retention periods apply:
- Account data and transaction records: Retained for a minimum of five years from the date of account closure, in compliance with anti-money-laundering record-keeping requirements under our international operating licence.
- KYC documents: Retained for a minimum of five years from the date of verification or account closure, whichever is later. After this period, documents are securely destroyed unless a longer retention period is required by law.
- Communications data: Live chat transcripts, support emails, and WhatsApp records are retained for up to two years to enable dispute resolution and quality assurance review.
- Technical and usage data: Server logs and session data are retained for up to 12 months. Aggregated, anonymised analytics data may be retained indefinitely as it cannot be used to identify individuals.
- Marketing preference data: Retained for as long as your account is active and for up to 12 months after account closure, after which marketing preferences are deleted. Suppression records (recording that you opted out) are retained indefinitely to prevent accidental re-contact.
At the end of the applicable retention period, personal data is securely deleted or anonymised so that it can no longer be linked to you as an individual.
mg525 implements a comprehensive set of technical and organisational security measures to protect your personal data against unauthorised access, disclosure, alteration, and destruction:
- TLS encryption: All data transmitted between your browser or device and the mg525 platform is encrypted using 256-bit TLS (Transport Layer Security). Look for the padlock icon in your browser's address bar to confirm that your connection is secure.
- Encrypted data storage: Sensitive data fields — including financial account details, identity document records, and password hashes — are encrypted at rest using AES-256 encryption. Plain-text passwords are never stored.
- Access controls: Access to systems containing personal data is restricted to authorised personnel on a strict need-to-know basis. All internal access is logged and subject to regular audit review.
- Two-factor authentication: We strongly recommend that all players enable 2FA on their mg525 accounts. Our support staff will never ask for your password or 2FA code via any communication channel.
- Penetration testing and audits: The mg525 platform undergoes regular independent security assessments, including penetration testing and code reviews, to identify and remediate vulnerabilities before they can be exploited.
- Incident response: In the event of a data breach that is likely to result in a risk to your rights and freedoms, mg525 will notify affected users without undue delay and will take immediate steps to contain and investigate the incident.
Your responsibility: While mg525 takes extensive measures to protect your data, account security also depends on you. Use a strong, unique password for your mg525 account, enable 2FA, do not share your credentials with anyone, and contact support immediately at [email protected] if you suspect your account has been compromised.
You have the following rights with respect to the personal data mg525 holds about you. To exercise any of these rights, contact us at [email protected] with the subject line "Data Rights Request":
Right of Access
Request a copy of all personal data we hold about you (Subject Access Request). We will respond within 30 days.
Right to Rectification
Request correction of any inaccurate or incomplete personal data. Some corrections may require re-verification of identity.
Right to Erasure
Request deletion of your personal data where it is no longer necessary for the purposes it was collected, subject to legal retention obligations.
Right to Restriction
Request that we restrict processing of your data while a dispute about its accuracy or our legal basis for using it is resolved.
Right to Portability
Receive your personal data in a structured, machine-readable format so you can transfer it to another service provider.
Right to Object
Object to processing based on legitimate interests, including profiling for marketing. We will cease processing unless we can demonstrate compelling grounds.
Withdraw Consent
Withdraw consent for marketing communications or non-essential cookies at any time without affecting prior processing.
Right to Complain
Lodge a complaint with the relevant data protection authority in your jurisdiction if you believe your rights have been infringed.
We aim to respond to all data rights requests within 30 calendar days. Complex or multiple requests may require up to 60 days; we will inform you if an extension is necessary. Identity verification may be required before we can fulfil a request to ensure we do not disclose data to an unauthorised party.
mg525 is strictly an adult platform. We do not knowingly collect personal data from any person under the age of 21. Our registration process includes an age declaration requirement, and our KYC process verifies that all account holders meet the minimum age requirement before any real-money activity is permitted.
If you are a parent or guardian and believe that a minor has registered an account or submitted personal data to mg525 without your knowledge, please contact us immediately at [email protected]. We will promptly investigate, close the account, and securely delete any personal data associated with the minor, returning any deposits in accordance with our Terms & Conditions.
mg525 is operated by an internationally licensed entity, and some of the personal data we collect may be stored on or processed by servers located outside Indonesia. Where such transfers occur, we take the following measures to ensure your data remains protected to an equivalent standard:
- Data processing agreements: All third-party processors who receive your personal data are bound by contractual data processing agreements that require them to implement appropriate technical and organisational security measures and to process your data only on our documented instructions.
- Adequacy and safeguards: Where data is transferred to countries without a formal adequacy determination, we rely on standard contractual clauses or equivalent safeguards as the transfer mechanism.
- Minimal cross-border sharing: We limit international data transfers to what is strictly necessary for the delivery of our services. We do not transfer your KYC documents or financial details to any jurisdiction unless required for transaction processing or legal compliance.
The mg525 platform integrates with a number of third-party services to deliver its full range of features. These include:
- Game studios: Evolution Gaming, Pragmatic Play, NetEnt, Microgaming, Spribe, and Pocket Games Soft each operate their own game delivery infrastructure. When you launch a game from one of these studios, your session data is handled by their certified platform. We recommend reviewing the relevant studio's privacy documentation for full details.
- Payment infrastructure: BCA, BRI, BNI, Mandiri, CIMB Niaga, BSI, OVO, DANA, GoPay, ShopeePay, LinkAja, and crypto network operators each process transaction data according to their own privacy policies. mg525 is not responsible for how these providers handle data within their own systems beyond the scope of our data processing agreements.
- Live chat and support tools: Our customer support tools may be provided by a licensed third-party platform. Support conversation data is stored in accordance with our retention schedule described in Section 8.
mg525 does not control the privacy practices of third-party services and is not responsible for their independent data handling. We encourage you to review the privacy policies of any third-party service you interact with independently of mg525.
mg525 reserves the right to update this Privacy Policy at any time to reflect changes in our data practices, applicable law, or platform functionality. When we make material changes, we will:
- Post the updated policy on this page with a revised effective date prominently displayed at the top.
- Display a notice on the mg525 platform for a minimum of 14 days following the change.
- Where possible, send a notification email to the address registered on your account.
Your continued use of mg525 following the effective date of any updated Privacy Policy constitutes your acceptance of the revised terms. If you do not agree with the updated policy, you should cease using the platform and may request account closure in accordance with our Terms & Conditions.
Archived versions: Previous versions of this Privacy Policy are available on request by contacting [email protected] with the subject line "Privacy Policy Archive Request".