Data Protection

  • 30 Sep 2025
  • 0 Comments

Scope and Controller

This Data Protection Notice describes how personal data is collected, used, disclosed, and protected by Toto Prayogo Alpha (totoprayogo.com) in the United States of America and, where applicable, in the European Economic Area (EEA), the United Kingdom (UK), and Switzerland. It is designed to align with the General Data Protection Regulation (GDPR) and relevant U.S. privacy laws, including the California Consumer Privacy Act as amended by the CPRA (CCPA/CPRA) and similar state laws.

The data controller is Cambrielle Montero, 4001 N Lamar Blvd, Austin, TX 78756, United States. You may contact the controller at [email protected].

Categories of Personal Data We Process

Data you provide directly

  • Identifiers and contact details: name, email address, postal address, telephone number, and similar information when you contact us, subscribe to communications, or request market insights.
  • Account or subscription data: credentials, preferences, watchlists, or alert settings if you choose to create an account or subscribe to premium content.
  • Transactional data: purchase history, billing address, last four digits of payment card (payment processing is handled by third-party processors; full card data is not stored by us).
  • Communications: content of messages, support requests, survey responses, and feedback.

Data collected automatically

  • Device and usage data: IP address, device identifiers, browser type, settings, pages viewed, referring/exit pages, timestamps, and interactions with our content.
  • Cookies and similar technologies: pixels, tags, SDKs, and local storage used for site functionality, analytics, personalization, and, where permitted, advertising measurement.

Data from third parties

  • Service providers and partners: analytics metrics, email delivery status, and anti-fraud signals.
  • Public and professional sources: business contact information if you represent an organization engaging with us.

Sensitive data

We do not seek to collect sensitive personal data (e.g., government IDs, precise geolocation, health, biometric, or financial account credentials). If such data is provided inadvertently, we will process it only as necessary and in accordance with applicable law.

Purposes and Legal Bases (EEA/UK/CH)

  • Service delivery and account administration: to provide market analysis content, manage accounts and subscriptions, and respond to inquiries. Legal bases: performance of a contract or steps prior to entering a contract; legitimate interests in operating a professional service.
  • Communications: to send newsletters, market updates, and service notices. Legal bases: consent for marketing communications; legitimate interests for service/transactional messages.
  • Analytics and improvement: to measure performance, debug issues, and enhance features. Legal bases: legitimate interests; consent where required for non-essential cookies.
  • Personalization and advertising measurement: to tailor content and assess marketing effectiveness. Legal bases: consent where required; legitimate interests otherwise.
  • Fraud prevention, security, and compliance: to protect our services, enforce terms, and comply with legal obligations. Legal bases: legitimate interests; legal obligation.
  • Corporate transactions: in connection with mergers, acquisitions, or reorganization. Legal bases: legitimate interests; legal obligation where applicable.

Processing for United States Compliance

For U.S. residents, we process personal information for the business purposes described above, including to operate the site, provide requested services, conduct analytics, secure our systems, and comply with law. We may disclose personal information to service providers and contractors under written contracts that restrict their use to specified business purposes. We do not sell personal information for monetary consideration. We may "share" personal information for cross-context behavioral advertising as defined under certain state laws; you may opt out as described below.

California Privacy Disclosures (CCPA/CPRA)

  • Categories collected: identifiers (e.g., name, email, IP), commercial information (e.g., subscription history), internet or network activity (e.g., usage data), geolocation approximated from IP, and in limited circumstances professional or employment-related information. We do not intentionally collect sensitive personal information and do not use it to infer characteristics.
  • Sources: directly from you, automatically from your device, and from service providers or public sources.
  • Purposes: provisioning services, communications, analytics, personalization, security, and compliance.
  • Disclosures to: service providers/contractors (hosting, analytics, email delivery, customer support, payment processing), professional advisors, and as legally required.
  • Sale/Share: we do not sell for money; we may share identifiers and internet activity for cross-context behavioral advertising. You may opt out of sale/share as described in the Opt-Out section.
  • Retention: retained only as long as reasonably necessary for the purposes described, considering legal, security, and operational requirements.
  • Rights: to know/access, delete, correct, opt out of sale/share and targeted advertising, limit use of sensitive PI (not applicable as we do not use sensitive PI in a manner triggering this right), and non-discrimination.
  • How to exercise: email [email protected] with your request and state "California Request" in the subject line. We will verify requests as described below. Authorized agents may submit requests with proof of authority and, if required, consumer verification.

Other U.S. State Privacy Rights

Residents of Virginia, Colorado, Connecticut, Utah, and other states with comprehensive privacy laws may have rights to access, correct, delete, obtain a portable copy, and opt out of targeted advertising, sale of personal data, and certain profiling. To exercise, contact us at [email protected]. If we decline your request, you may appeal by replying to our decision with "Appeal" in the subject line; we will explain our final decision and your options to contact your state Attorney General where applicable.

Cookies and Tracking Technologies

We use essential cookies to operate our site and facilitate security and performance. With your consent where required, we also use analytics and personalization cookies and may use advertising measurement technologies. You can manage cookies through your browser settings by blocking or deleting cookies; some features may not function without essential cookies.

Opt-out mechanisms: You may opt out of cross-context behavioral advertising and targeted advertising by contacting us as described, adjusting your cookie preferences where offered, or by enabling a Global Privacy Control (GPC) signal in your browser; where required by law, we honor GPC as an opt-out of sale/share.

Sharing and Disclosures

  • Service providers/contractors: hosting, cloud infrastructure, analytics, email delivery, customer support, and payment processing under contracts limiting use to our instructions.
  • Business transfers: in connection with mergers, acquisitions, financing, or sale of all or part of our business.
  • Legal and safety: to comply with law, respond to lawful requests, protect rights, property, security, or investigate potential violations.

We do not permit third parties to collect personal data from our services for their own purposes without your consent or a lawful basis.

International Data Transfers

We are based in the United States. Where personal data is transferred from the EEA, UK, or Switzerland to countries without an adequacy decision, we rely on appropriate safeguards, such as the European Commission’s Standard Contractual Clauses and, where necessary, supplementary measures. You may contact us to request more information about these safeguards.

Data Retention

We retain personal data only for as long as necessary to fulfill the purposes described in this Notice, including providing services, complying with legal obligations, resolving disputes, and enforcing agreements. Retention periods are determined by factors such as the type of data, the length of your relationship with us, statutory requirements, and security needs. When data is no longer needed, we will delete, de-identify, or aggregate it.

Security

We implement technical and organizational measures designed to protect personal data against unauthorized access, alteration, disclosure, or destruction. These measures include access controls, encryption in transit where appropriate, network monitoring, and staff confidentiality obligations. No method of transmission or storage is completely secure, and we cannot guarantee absolute security.

Your Rights (EEA/UK/CH)

  • Access: obtain confirmation and a copy of your personal data.
  • Rectification: correct inaccurate or incomplete data.
  • Erasure: request deletion where grounds apply.
  • Restriction: request we limit processing under certain conditions.
  • Portability: receive your data in a structured, commonly used, machine-readable format and transmit it to another controller.
  • Objection: object to processing based on legitimate interests and to direct marketing at any time.
  • Withdraw consent: where processing is based on consent, you may withdraw it at any time without affecting prior lawful processing.

To exercise these rights, contact [email protected]. We may request information necessary to verify your identity and will respond within the timelines required by law.

Exercising Rights and Verification

We will take reasonable steps to verify your identity before fulfilling a request, which may include confirming control of the email address used to interact with us, requesting limited additional information, or, for sensitive requests, requesting a signed declaration. If we cannot verify your identity, we will explain why and may request further information.

Authorized agents (where permitted by law) must provide proof of authorization and, in some cases, we may require direct confirmation from the individual.

Automated Decision-Making and Profiling

We do not engage in solely automated decision-making that produces legal or similarly significant effects. We may conduct limited profiling for personalization and analytics, which you can object to or opt out of where provided by law.

Children's Data

Our services are not directed to children and we do not knowingly collect personal data from individuals under the age of 16. If you believe a child has provided personal data, please contact us so we can take appropriate action.

Changes to This Notice

We may update this Notice from time to time to reflect changes in our practices or legal requirements. The "Effective Date" below indicates the most recent revision. Material changes will be communicated through our services or by direct notice where appropriate.

Contact Information

Controller: Cambrielle Montero

Postal address: 4001 N Lamar Blvd, Austin, TX 78756, United States

Email: [email protected]

Complaints and Supervisory Authorities

If you are in the EEA/UK/CH, you have the right to lodge a complaint with your local data protection authority. We encourage you to contact us first so we can address your concerns promptly.

Effective Date

Last updated: September 30, 2025

Posted By: Cambrielle Montero

Write a comment

Your email address will not be published