Privacy Policy

Introduction

This Privacy Notice constitutes the commitment of PT Artajasa Pembayaran Elektronis (“we”, “us”, or “our”), a legal entity established under the laws of the Republic of Indonesia, to comply with applicable personal data protection regulations in Indonesia. This document is prepared in accordance with Law No. 27 of 2022 on Personal Data Protection, as amended, and/or related implementing legislation (PDP Law).

As the Controller of Personal Data, we are responsible for the control of personal data provided by you or collected by us, in accordance with the personal data processing principles under the PDP Law, as set forth below:

1. Legal Bases for Personal Data Processing

We process your personal data based on one or more of the following legal bases under the PDP Law:

  • a. Explicit consent;
  • b. Fulfilment of contractual obligations;
  • c. Compliance with legal obligations;
  • d. Protection of vital interests;
  • e. Performance of tasks in the public interest; and/or
  • f. Other legitimate interests.

2. Personal Data We Collect

a. For the purposes of personal data processing, we may collect information voluntarily provided by you through forms, email, or other contact methods, including but not limited to:

  • i. Full name;
  • ii. Email address;
  • iii. Telephone number; and/or
  • iv. Other information qualifying as personal data under the PDP Law.

b. We may use cookies or other tracking technologies to enhance the user experience and analyse patterns of site usage. You may configure your cookie preferences through your browser settings.

c. When you provide your personal data to us, we expect such personal data to constitute accurate, truthful, and non-misleading information. In the event that the personal data you provide is inaccurate or misleading, you hereby release and indemnify us from any and all claims, demands, lawsuits, damages, and/or liabilities arising from such inaccuracy.

3. Purposes of Personal Data Processing

a. Personal data we collect from you is processed solely for legitimate, specific, and explicitly determined purposes, in accordance with the purpose limitation principle under the PDP Law.

b. We process your personal data for the following purposes (Processing Purposes):

  • i. Provision, management, and maintenance of the Site to ensure it functions effectively, securely, and optimally for all site visitors;
  • ii. Communication or provision of information related to the services we provide;
  • iii. Analysis of site usage and enhancement of the visitor experience;
  • iv. Site security and prevention of misuse; and
  • v. Compliance with applicable legal obligations and regulatory requirements.

4. Disclosure of Personal Data to Third Parties

a. We commit not to sell, rent, or trade your personal data to any third party for purposes beyond the agreed Processing Purposes.

b. In certain legitimate and necessary circumstances to achieve the aforementioned purposes, we may disclose or share your personal data with the following parties:

  • i. Our business partners and affiliates for integrated service provision, ensuring they apply equivalent personal data protection standards;
  • ii. Government authorities, regulators, and law enforcement agencies where required by applicable law or to comply with legitimate legal processes;
  • iii. Other third parties upon obtaining your explicit consent for such sharing.

c. We ensure that every third party receiving your personal data is obligated to maintain confidentiality and implement data security standards in accordance with industry best practices.

5. Storage and Retention of Personal Data

We retain your personal data only for as long as necessary for the processing purposes or as required by applicable law. Personal data shall be destroyed and/or deleted upon expiry of the retention period or at the request of the data subject, unless otherwise stipulated by legislation.

6. Personal Data Protection Measures

We are committed to maintaining your trust by implementing robust technical and organisational security measures to protect personal data against unauthorised access, breaches, or damage, including:

  • i. Data encryption;
  • ii. Role-based access controls;
  • iii. System security audits and monitoring; and
  • iv. Internal training on data protection.

7. Your Rights as a Data Subject

a. Under the PDP Law, as a data subject, you have the following rights:

  • i. Right of access to personal data;
  • ii. Right to rectification of inaccurate personal data;
  • iii. Right to completion and updating of data;
  • iv. Right to withdrawal of consent;
  • v. Right to erasure of personal data;
  • vi. Right to restriction of processing;
  • vii. Right to object to certain processing;
  • viii. Right to obtain a copy or portability of personal data.

b. Requests to exercise the above rights may be submitted to us through the communication channels specified in this Privacy Notice. We will respond within a maximum of three (3) business days from receipt of a complete and verified request, unless otherwise provided by applicable legislation.

8. Notification of Personal Data Protection Failures

In the event of a personal data protection failure that may pose a risk to your rights and freedoms, we commit to notifying you as the affected data subject in writing no later than three times twenty-four (3 x 24) hours from our awareness of such failure.

9. Children's Data Protection

This service is not directed at data subjects under 18 years of age. We do not knowingly collect personal data from children without verifiable parental or guardian consent. If you are a parent or guardian and become aware that your child has provided us with personal data, please contact us immediately.

10. Changes to Privacy Notice

This policy may be updated from time to time to align with developments in law, technology, or our services. Changes will be announced via this channel and effective from the update date. We encourage users to periodically review this Privacy Notice.

11. Contact Us

You may submit questions, complaints, or requests for clarification regarding your rights over personal data we process by contacting the following, including the hashtag #PDP in the email subject line: helpdesk@artajasa.co.id or dataprotection@artajasa.co.id.