Privacy and Personal Data Protection Policy
What personal data we collect, on what legal basis we process it, how long we keep it, who we disclose it to, and your nine rights under Indonesian Law No. 27 of 2022.
Last updated Effective
This is a translation provided for convenience. The document is made in the Indonesian language, and under Law No. 24 of 2009 the Indonesian version prevails in the event of any difference in interpretation.
Part I — General provisions
1 — Introduction and scope
- PT Levia Cloud Indonesia ("Levia Cloud", "we") respects everyone’s privacy and is committed to protecting personal data in accordance with Law No. 27 of 2022 on Personal Data Protection (the "PDP Law") and its implementing regulations.
- This Privacy Policy (the "Policy") explains what personal data we collect, what we process it for, on what legal basis, to whom we disclose it, how long we keep it, and what rights you have and how to use them.
- This Policy applies to: (a) registered Levia Cloud customers, whether individuals or business entities and their designated personnel; (b) prospective customers who register, request a quote, or use a trial; (c) visitors to leviacloud.com and its subdomains; and (d) partners, suppliers, and job applicants so far as relevant.
- This Policy is an inseparable part of the Levia Cloud Terms of Service. Where the two conflict on personal data processing, this Policy prevails.
- This Policy does not govern the privacy practices of third parties, including applications, sites, or services you run yourself on Levia Cloud infrastructure, or third-party sites linked from ours.
- By registering, using the Services, or accessing our site, you confirm that you have read and understood this Policy.
2 — Definitions
- Personal Data
- Data about an identified or identifiable individual, alone or combined with other information, directly or indirectly, through electronic or non-electronic systems.
- General Personal Data
- Including full name, sex, nationality, religion, marital status, and personal data combined to identify a person (Article 4, PDP Law).
- Specific Personal Data
- Health data and information, biometric data, genetic data, criminal records, children’s data, personal financial data, and other data designated by law (Article 4, PDP Law).
- Personal Data Subject
- The individual to whom Personal Data attaches — also referred to in this Policy as "you".
- Personal Data Controller
- The party that determines the purposes of, and exercises control over, the processing of Personal Data.
- Personal Data Processor
- The party that processes Personal Data on behalf of and on the instructions of the Controller.
- Processing
- Obtaining, collecting, handling, analysing, storing, correcting, updating, displaying, announcing, transferring, disseminating, disclosing, deleting, or destroying Personal Data.
- Customer Data
- All data, content, configuration, images, snapshots, and backups the Customer uploads, creates, or stores on the Levia Cloud Services.
- Services
- The Levia Cloud cloud computing services as defined in the Terms of Service.
- Sub-Processor
- A third party engaged by Levia Cloud to process Personal Data in delivering the Services.
- Protection Failure
- An event resulting in the unlawful disclosure, loss, alteration, or access of Personal Data.
- Authority
- The body responsible for personal data protection affairs under the PDP Law.
- Business Day
- Monday to Friday, 08:00–18:00 WIB, excluding Indonesian national public holidays.
3 — Levia Cloud’s two roles over personal data
As a cloud infrastructure provider, Levia Cloud holds two legally distinct roles. Telling them apart matters, because the rights and obligations attached to each are not the same.
| Aspect | Role 1 — Controller | Role 2 — Processor |
|---|---|---|
| What data | Personal data we collect ourselves to run the business relationship: registration, account, billing, technical support, security, and the website. | Personal data contained within Customer Data — the contents of the Customer’s virtual machines, storage, databases, and backups. |
| Who sets the purpose | Levia Cloud. | The Customer. Levia Cloud processes only on the Customer’s instructions. |
| Examples | Account registrant name and email, business tax number, payment history, console access logs, support ticket contents. | Your end customers’ data in your database, files in your object storage, your application logs. |
| Do we see the contents | Yes, so far as needed for the purposes described in Part II. | No. We do not access Customer Data contents except at your request, to address an urgent incident, or where required by law. |
| Governed by | Part II of this Policy. | Part III of this Policy and Appendix B (DPA). |
| Where the Data Subject complains | Directly to Levia Cloud at [email protected]. | To the Customer as Controller. Levia Cloud forwards any request it receives to the Customer. |
- Where the Customer is a business entity, that entity acts as Personal Data Controller over both its own personnel data and its end-customer data, and is responsible for ensuring a lawful basis for processing exists.
- Levia Cloud does not determine what Personal Data the Customer stores on the Services, does not determine the purpose of its processing, and does not use it for its own ends in any form — including for training artificial intelligence models, advertising, or commercial analytics.
Part II — Levia Cloud as controller
4 — Personal data we collect
4.1 Data categories
| Category | Detail | Source |
|---|---|---|
| Identity | Full name, date of birth, identity number (national ID/passport) for verification. For business entities: entity name, tax number, deed of establishment, business identification number, and the identity of authorised officers. | Directly from you |
| Contact | Email address, phone number, billing address, correspondence address. | Directly from you |
| Account | Username, hashed password, two-factor authentication status, API and SSH key fingerprints, roles and access rights, language and region preferences. | You and our systems |
| Personal financial | Payment method, last four digits of the card, bank name and account number for refunds, transaction history, invoice status, and arrears history. | You and the payment provider |
| Technical usage | Resource identifiers, specifications, hours used, traffic volume, capacity metrics, and quotas. | Our systems |
| Access and security logs | IP address, browser and operating system type, sign-in and sign-out times, console and API actions, failed sign-in attempts. | Our systems |
| Technical support | Ticket contents, attachments you send, email and chat correspondence records, emergency call notes. | Directly from you |
| Website | Pages visited, visit duration, referral source, and cookie identifiers. | Cookies and analytics tools |
| Marketing | Subscription preferences, marketing email open and click history, webinar or event participation. | Our systems |
4.2 Specific personal data
4.3 What we do not collect
- We do not store full credit card numbers, expiry dates, or CVV codes. That data is processed directly by a PCI DSS-certified payment gateway provider.
- We do not carry out cross-site tracking for behavioural advertising.
- We do not buy personal data lists from third parties for marketing.
- We do not make automated decisions with legal effect on you without human involvement, except the automated billing process under Article 7 of the Terms of Service, whose timeline is notified in advance and can be stopped by payment.
5 — Purposes and legal basis for processing
Every processing activity we carry out rests on a lawful basis under Article 20(2) of the PDP Law. The table below maps purpose, data used, and legal basis.
| Processing purpose | Data used | Legal basis — Article 20(2) |
|---|---|---|
| Creating and managing accounts | Identity, contact, account | Point b — performance of contractual obligations |
| Providing, operating, and maintaining the Services | Account, technical usage, logs | Point b — performance of contractual obligations |
| Invoicing, receiving payment, and refunds | Identity, personal financial | Point b — performance of contractual obligations |
| Issuing tax invoices and tax reporting | Identity, tax number, transactions | Point c — compliance with legal obligations |
| Identity verification and account abuse prevention | Identity, corporate documents, logs | Points c and f — legal obligation and legitimate interest |
| Billing, suspension, and deletion notices under Article 7 of the Terms | Contact, personal financial | Point b — performance of contractual obligations |
| Technical support and incident handling | Technical support, account, logs | Point b — performance of contractual obligations |
| System security, attack detection, and fraud prevention | Access and security logs | Point f — legitimate interest of Levia Cloud and other customers |
| Service quality improvement and capacity planning | Technical usage in aggregate or anonymised form | Point f — legitimate interest |
| Meeting lawful requests from competent authorities | As scoped by the request | Point c — compliance with legal obligations |
| Legal defence and dispute resolution | As the matter requires | Point f — legitimate interest |
| Sending marketing communications, newsletters, and event invitations | Contact, marketing preferences | Point a — consent, withdrawable at any time |
| Non-essential cookies and site analytics | Website data | Point a — consent via the cookie banner |
6 — Disclosure to third parties
We may disclose Personal Data on a limited basis to the following recipients, so far as necessary and with adequate safeguards.
| Recipient | Purpose of disclosure | Safeguards |
|---|---|---|
| Payment gateway providers and banks | Payment processing, transaction verification, and refunds. | Data processing agreement; PCI DSS certification on the provider. |
| Data centre infrastructure providers | Hardware placement and connectivity within Indonesia. | Service level and confidentiality agreements; controlled physical access. |
| Operational tooling providers | Ticketing, transactional email delivery, monitoring, and analytics. | Data processing agreement; data minimisation. |
| Professional advisers | Accountants, auditors, tax consultants, and lawyers for compliance and legal defence. | Professional confidentiality obligations. |
| Competent authorities | Compliance with valid written orders from law enforcement, tax authorities, or the Authority. | Validity reviewed; scope kept to the minimum. |
| Parties to a corporate action | Merger, acquisition, or business transfer. | Confidentiality agreement; notice to you before the transfer takes effect. |
- The current Sub-Processor list is set out in Appendix A and published on the privacy policy page of our site.
- Before engaging a new Sub-Processor that will process Customer Data, we notify the Customer at least 30 calendar days in advance. The Customer may raise a reasoned objection as set out in Appendix B.
- Where we receive a data access request from law enforcement, we will: (a) check the validity and authority of the request; (b) limit the scope of disclosure to what is expressly requested; and (c) inform you, unless doing so is prohibited by law or court order.
7 — Data retention periods
We keep Personal Data only as long as needed for the processing purpose, or as long as the law requires, whichever is longer.
| Data category | Period | Reason |
|---|---|---|
| Account and profile data | While the account is active, plus 30 calendar days after closure | Allows account recovery and settlement of final obligations |
| Invoices, tax invoices, and payment records | 10 years from the end of the financial year | Law No. 8 of 1997 on Company Documents and tax rules |
| Transaction history and invoice status | 10 years from the transaction | Bookkeeping and evidentiary obligations |
| Identity verification documents (KYC) | 5 years from account closure | Abuse prevention and legal defence |
| Support tickets and correspondence | 3 years from ticket closure | Reference for recurring issues and dispute resolution |
| Delivery records for billing, suspension, and deletion notices | 3 years from sending | Evidence of compliance with Article 7 of the Terms |
| Console and API access logs | 12 months | Security, audit, and incident investigation |
| Network and security logs | 12 months | Attack detection and investigation |
| Marketing data and subscription preferences | Until consent is withdrawn, plus 30 calendar days | Ensures the withdrawal is actually executed |
| Analytics cookie data | At most 14 months | Period-over-period visit trend analysis |
| Customer Data (Processor role) | Per the Customer’s instructions and Articles 7 and 10 of the Terms of Service | The Customer is the Controller of that data |
- Once the retention period ends, Personal Data is deleted or destroyed by methods that make recovery impossible, or permanently anonymised so that it can no longer be linked to an individual.
- Data that is the subject of a legal dispute, an authority’s examination, or a law enforcement request is retained until the matter is finally resolved, even where the normal retention period has ended.
Part III — Levia Cloud as processor
9 — Customer Data on the Services
When you run a virtual machine, store files in object storage, or operate a database on the Levia Cloud Services, everything inside is Customer Data and is entirely under your control.
Over that Customer Data you act as Personal Data Controller and Levia Cloud acts as Personal Data Processor. The consequences are:
- You decide what Personal Data is stored, for what purpose, and for how long.
- You are responsible for ensuring a lawful basis exists for processing that Personal Data.
- You are responsible for responding to requests from your own Personal Data Subjects.
- You are responsible for security at the operating system and application layers, content encryption, and your own user access control.
- We provide secure infrastructure and tooling, and process Customer Data only on your instructions.
- We do not scan, analyse, index, or exploit the contents of Customer Data for our own ends, including for training artificial intelligence models, cross-selling, advertising, or profiling.
- The detailed Controller–Processor terms are set out in the Data Processing Agreement at Appendix B, which can be signed separately if you need it for audit, tender, or internal compliance purposes.
10 — Processing limits and customer instructions
Levia Cloud processes Customer Data solely on the Customer’s documented instructions, expressed through: (a) the Terms of Service; (b) this Policy and Appendix B; (c) the configuration you set yourself in the console and API; and (d) written requests through the official ticket portal.
Levia Cloud personnel may access Customer Data only in the three circumstances below.
| Circumstance | Explanation | Control |
|---|---|---|
| At your request | You request technical assistance that requires our engineers to access your resources. | Written consent on the ticket; time-bound access; every session logged. |
| Urgent incident | Necessary to address a disruption or attack affecting the Services or other customers. | Approval by an authorised internal officer; notice to you within 1 x 24 hours. |
| Legal obligation | A valid written order from a competent authority. | Validity check; minimum scope; notice to you unless prohibited. |
- Every personnel access to Customer Data is recorded in an immutable audit trail carrying the officer’s identity, time, scope, and reason for access. You may request that record at any time.
- If in our assessment a Customer instruction conflicts with the PDP Law or other legislation, we will notify the Customer and may suspend execution of that instruction.
11 — Sub-processors and assistance to customers
11.1 Sub-processors
- Levia Cloud may engage Sub-Processors to support delivery of the Services. Every Sub-Processor is bound by data protection obligations no less strict than Levia Cloud’s own under this Policy.
- Levia Cloud remains fully liable to the Customer for processing carried out by its Sub-Processors.
- The current Sub-Processor list is at Appendix A. Changes are notified at least 30 calendar days before they take effect, and the Customer may raise a reasoned objection within 14 calendar days of the notice.
11.2 Assistance to customers
As Processor, we help the Customer meet its own obligations as Controller through:
- Data Subject rights tooling
- Export, correction, and deletion features in the console and API, so the Customer can respond to its own Personal Data Subjects independently.
- Request forwarding
- Where we receive a request from a Personal Data Subject relating to Customer Data, we do not respond substantively but forward it to the Customer within 3 Business Days.
- Incident notification
- Notice of a Protection Failure affecting Customer Data within 1 x 24 hours of our becoming aware, so the Customer can meet its own 3 x 24 hour obligation to Data Subjects and the Authority.
- Compliance documentation
- Summaries of ISO/IEC 27001 and ISO 9001 certification, descriptions of security measures, and answers to customer compliance questionnaires.
- Impact assessment support
- Reasonable technical information to help the Customer prepare a personal data protection impact assessment.
- Audit
- Audit facilitation under Appendix B, Section B.10.
Part IV — Rights, security, and compliance
12 — Your rights as a personal data subject
The PDP Law gives you the following rights. All of them are free to exercise.
| Basis | Right | What it means in practice |
|---|---|---|
| Article 5 | Right to information | To be told our identity, the legal basis, the purpose, and the accountability of processing. This Policy discharges that right. |
| Article 6 | Right to complete and correct | To correct data that is wrong or incomplete. Most of this you can do yourself in the console profile settings. |
| Article 7 | Right of access and copy | To obtain information about the Personal Data of yours that we process, and a copy of it. |
| Article 8 | Right to end, erase, and destroy | To request that processing stop and that your Personal Data be erased or destroyed, so far as this does not conflict with statutory retention obligations. |
| Article 9 | Right to withdraw consent | To withdraw consent previously given, for example for marketing and non-essential cookies. Withdrawal is not retroactive. |
| Article 10 | Right regarding automated decisions | To object to a decision based solely on automated processing that produces legal effects or significantly affects you. |
| Article 11 | Right to delay and restrict | To request proportionate delay or restriction of processing, for example while the accuracy of data is disputed. |
| Article 12 | Right to compensation | To claim and receive compensation for unlawful processing of your Personal Data. |
| Article 13 | Right to portability | To obtain and transmit your Personal Data to another controller in a commonly used, machine-readable format. |
12.1 How to submit a request
- Requests are submitted by email to [email protected], through the official ticket portal, or by completing the form at Appendix C.
- To protect you against fraudulent requests, we verify the requester’s identity first. Verification is carried out proportionately and without excess.
The handling deadlines we commit to:
| Stage | Deadline |
|---|---|
| Acknowledgement of the request | Within 3 Business Days |
| Verification of the requester’s identity | Within 5 Business Days of the request |
| Fulfilment of the request | Within 14 Business Days of identity being verified |
| Extension for complex requests | Extendable once by up to 14 Business Days, with written reasons |
| Refusal of a request | Given in writing with reasons and the procedure for objecting |
- We may refuse or limit a request in the cases excepted by Article 15 of the PDP Law — including national defence and security, law enforcement processes, the public interest in the administration of the state, financial services supervision, and statistical and scientific research purposes. A refusal always comes with written reasons.
- Where your request concerns Customer Data belonging to another Levia Cloud customer — for example where you are an end user of an application running on our infrastructure — we forward it to that customer as Controller, and tell you that we have done so.
12.2 Objections and complaints
- If you are not satisfied with how a request was handled, you may object to [email protected]. The objection is reviewed by an officer other than the one who handled it first, with a response within 10 Business Days.
- You are also entitled to complain to the Authority responsible for personal data protection, and to seek legal remedies through the courts under Article 12 of the PDP Law.
13 — Personal data security
We apply adequate technical and organisational measures to protect Personal Data against unauthorised access, disclosure, alteration, and destruction.
- Encryption
- All traffic encrypted in transit using TLS 1.2 or higher. Encryption at rest is available for volumes and object storage. Passwords are stored hashed with a strong algorithm.
- Access control
- Role-based access on a least-privilege principle, mandatory multi-factor authentication for all internal personnel, and periodic access rights reviews.
- Network security
- Network segmentation, firewalls and security groups, automatic layer 3 and 4 DDoS mitigation, and tenant isolation.
- Monitoring
- 24/7 security monitoring by the Network Operations Center, immutable audit logging, and automatic anomaly alerts.
- Testing
- Periodic vulnerability scanning, CIS Benchmark hardening, and critical patches applied within 72 hours of vendor release.
- Physical security
- Data centres with layered access control, video surveillance, redundant power, and fire suppression.
- Personnel
- Confidentiality agreements for all personnel, background checks for sensitive roles, and periodic data protection training.
- Certification
- ISO/IEC 27001 for Information Security Management and ISO 9001 for Quality Management. The infrastructure is prepared to PCI DSS requirements.
- Business continuity
- Internal system backups, a disaster recovery plan, and periodic recovery testing.
- Even so, no method of electronic transmission or storage is entirely free of risk. We cannot guarantee absolute security, but we are committed to reviewing and updating our safeguards continuously.
- Security responsibility is shared. You are responsible for keeping credentials confidential, enabling two-factor authentication, and securing the operating systems and applications you run yourself.
14 — Personal data protection failures
- In the event of a Personal Data Protection Failure, we give written notice within 3 x 24 hours of becoming aware to the affected Personal Data Subjects and to the Authority, in accordance with Article 46 of the PDP Law.
- The notice states at minimum: (a) the Personal Data exposed; (b) when and how it was exposed; and (c) the handling and recovery steps Levia Cloud has taken.
- Where the failure affects Customer Data for which Levia Cloud acts as Processor, we notify the Customer as Controller within 1 x 24 hours of becoming aware, so the Customer has enough time to meet its own 3 x 24 hour obligation to its Personal Data Subjects and to the Authority.
- We provide reasonable technical support and information to the Customer for investigation, notification, and recovery.
- Every incident is analysed for root cause, and the result is set out in a report with preventive actions so the same event does not recur.
15 — Transfers outside Indonesia
- As a principle, all Personal Data and Customer Data is stored and processed in data centres within the Republic of Indonesia — the Jakarta (JKT-1, JKT-2) and Surabaya (SBY-1) regions.
- We do not move Customer Data outside the Republic of Indonesia.
- In certain cases, limited operational data — for example metadata in transactional email tooling or the ticket system — may be processed by a provider established abroad. In that case we ensure one of the conditions in Article 56 of the PDP Law is met.
- The recipient’s country of establishment has a level of personal data protection equal to or higher than that under the PDP Law; or
- There is adequate and binding personal data protection, set out in a data processing agreement with standard clauses; or
- The Personal Data Subject has given explicit consent.
The list of providers with cross-border processing and the basis of protection for each is in Appendix A, updated whenever it changes.
16 — Children’s and specific data
- The Levia Cloud Services are intended for users at least 18 years old, or legal entities. We do not knowingly collect children’s Personal Data.
- If we learn that children’s Personal Data has been collected without valid parental or guardian consent, we delete it as soon as possible. You can report such a case to [email protected].
- If you as a Customer intend to store Specific Personal Data — including health, biometric, genetic, or children’s data — on our Services, you are responsible for ensuring a lawful basis exists and that appropriate additional safeguards are applied. We recommend contacting us first so that adequate technical and contractual arrangements can be put in place.
17 — Data Protection Officer
- Levia Cloud has appointed a Data Protection Officer as contemplated by Article 53 of the PDP Law, given that our core activity involves large-scale, systematic processing of Personal Data.
- The Data Protection Officer’s duties include: advising management on PDP Law compliance, monitoring implementation of data protection policy, advising on data protection impact assessments, acting as the contact point for Personal Data Subjects and the Authority, and coordinating the handling of Protection Failures.
- The Data Protection Officer can be reached at [email protected] or through the correspondence address of PT Levia Cloud Indonesia.
18 — Policy changes, contact, and complaints
18.1 Policy changes
- We may update this Policy to keep pace with the Services, technology, and the law.
- Material changes — including adding a new processing purpose, changing the legal basis, adding a category of recipient, or extending a retention period — are notified by email to the registered address and by console notification at least 30 calendar days before they take effect.
- Where a change requires your consent under the PDP Law, the new processing does not begin until consent is obtained. If you do not accept another material change, you may terminate the Services under Article 15 of the Terms of Service.
- We keep an archive of every version of this Policy with its effective date, and make it available on request.
18.2 Contact
| Purpose | Contact |
|---|---|
| Data Protection Officer, Data Subject rights requests, and reports of suspected data misuse | [email protected] |
| Objections and complaints | [email protected] |
| Technical support and security incidents | [email protected] · +62 21 5099 0000 (24/7) |
| Billing and data export requests | [email protected] |
| Correspondence address | PT Levia Cloud Indonesia, Jakarta, Indonesia |
18.3 Complaints to the authority
Without prejudice to your right to complain directly to us, you may complain to the Authority responsible for personal data protection, and seek legal remedies through the courts under Article 12 of the PDP Law. Breaches of the PDP Law may attract administrative sanctions ranging from written warning, temporary suspension of processing, and erasure or destruction of Personal Data, up to an administrative fine of at most 2% of annual revenue.
Appendices
Appendix A — Sub-processors and third parties
| Category | Provider | Data processed | Processing location |
|---|---|---|---|
| Payment gateway | [●] | Billing identity, transaction metadata | Indonesia |
| Data centre / colocation | [●] | All data on the infrastructure | Jakarta & Surabaya, Indonesia |
| Support ticketing system | [●] | Contact, ticket contents, attachments | [●] |
| Transactional email | [●] | Email address, notification contents | [●] |
| SMS delivery | [●] | Phone number, message contents | Indonesia |
| Website analytics | [●] | Cookie identifiers, visit data | [●] |
| Internal monitoring & observability | [●] | Metrics, operational logs | Indonesia |
| Email marketing tooling | [●] | Contact, subscription preferences | [●] |
For every provider that processes data outside the Republic of Indonesia, the last column must be completed with the basis of protection under Article 56 of the PDP Law — equivalence of protection level, an agreement with standard clauses, or the Data Subject’s explicit consent.
- List version
- 1.0 — 14 August 2026
- Publication
- leviacloud.com/privacy/subprocessors
- Change notice
- 30 calendar days before taking effect, by email to the registered address and console notification
- Customer objection window
- 14 calendar days from receipt of the notice
Appendix B — Data Processing Agreement (DPA)
Data Processing Agreement — signable separately as an addendum to the Terms of Service. Contact [email protected] for a signable copy.
- Personal Data Controller
- The Customer, as identified in the signature document.
- Personal Data Processor
- PT Levia Cloud Indonesia.
- Effective date
- The date of signature or the Service effective date, whichever is earlier.
- Master agreement
- Levia Cloud Terms of Service v1.0 and/or the related cooperation agreement.
B.1 Subject matter, nature, and purpose of processing
- The Processor processes Personal Data on the Controller’s behalf solely to deliver the cloud computing Services under the Master Agreement.
- The nature of processing covers storage, hosting, transmission, backup, restoration, and deletion, without content analysis.
- Processing lasts for the term of the Master Agreement, plus the deletion or return period under Section B.12.
B.2 Types of personal data and categories of subject
- The types of Personal Data and categories of Personal Data Subject are determined entirely by the Controller and set out in Annex DPA-1.
- The Controller warrants that it will not store Specific Personal Data on the Services without first notifying the Processor and agreeing additional safeguards.
B.3 Controller obligations
- To ensure a lawful basis under Article 20 of the PDP Law exists for all Personal Data stored on the Services.
- To give the Processor lawful, clear, and documented instructions.
- To respond to Personal Data Subject requests and meet its notification obligations to the Authority.
- To configure the security controls within its own control, including content encryption, key management, user access control, and retention policy.
B.4 Processor obligations
- To process Personal Data only on the Controller’s documented instructions, unless otherwise required by law.
- To notify the Controller where in the Processor’s assessment an instruction conflicts with the PDP Law.
- Not to use Personal Data for its own purposes, including training artificial intelligence models, advertising, profiling, or sale to third parties.
- To apply the security measures in Annex DPA-2 and review them periodically.
B.5 Personnel confidentiality
The Processor ensures every person authorised to access Personal Data is bound by a written confidentiality obligation that survives the end of employment, and receives periodic personal data protection training.
B.6 Security
- The Processor applies the technical and organisational measures set out in Annex DPA-2, covering at minimum encryption in transit, role-based access control, multi-factor authentication for personnel, network segmentation, audit logging, and 24-hour monitoring.
- The Processor maintains ISO/IEC 27001 certification and provides a summary of certification audit results to the Controller on request.
B.7 Sub-processors
- The Controller gives general authorisation for the use of Sub-Processors as listed in Appendix A of the Privacy Policy.
- The Processor notifies any planned addition or replacement of a Sub-Processor at least 30 calendar days before it takes effect.
- The Controller may raise a reasoned objection within 14 calendar days. If the objection cannot be resolved jointly, the Controller may terminate the affected Services without termination penalty.
- The Processor binds every Sub-Processor to data protection obligations no less strict, and remains fully liable to the Controller for the Sub-Processor’s processing.
B.8 Assistance with data subject rights
- The Processor provides technical features in the console and API allowing the Controller to access, correct, export, and delete Personal Data independently.
- Where the Processor receives a request directly from a Personal Data Subject relating to Customer Data, it does not respond substantively but forwards it to the Controller within 3 Business Days.
- The Processor gives the Controller reasonable assistance in preparing a personal data protection impact assessment and in consulting the Authority.
B.9 Personal data protection failures
- The Processor notifies the Controller within 1 x 24 hours of becoming aware of a Protection Failure affecting the Controller’s Personal Data.
- The notice states the nature of the failure, the categories and approximate number of Personal Data Subjects affected, the likely consequences, and the handling and mitigation steps taken.
- The Processor does not notify Personal Data Subjects or the Authority directly on the Controller’s behalf, unless requested in writing by the Controller or required by law.
B.10 Audit and inspection
- The Processor provides reasonable information to demonstrate compliance with this DPA, including the ISO/IEC 27001 certificate, audit report summaries, and security questionnaire responses.
- The Controller may audit at most once in any 12 months, on 30 calendar days’ written notice, on Business Days, and without disrupting the Processor’s operations or other customers’ confidentiality.
- Additional audits may be carried out following a material Protection Failure or where ordered by a competent authority.
- Audit costs are borne by the Controller, unless the audit establishes material non-compliance on the Processor’s side.
B.11 Cross-border transfers
The Processor does not move Customer Data outside the Republic of Indonesia. Any exception requires the Controller’s prior written consent and compliance with Article 56 of the PDP Law.
B.12 Deletion or return of data
- On termination at the Controller’s initiative, the Processor provides a 30-calendar-day window for the Controller to export Personal Data, after which the data is permanently deleted.
- On termination arising from payment arrears, the specific terms of Article 7 of the Terms of Service apply — permanent deletion 30 calendar days after the suspension date.
- The Processor issues written confirmation that deletion has been carried out, if the Controller requests it.
- Data that must be retained by law is excepted from the deletion obligation, and remains subject to confidentiality and security obligations for as long as it is held.
B.13 Final provisions
- This DPA is an inseparable part of the Master Agreement. Where the two conflict on Personal Data processing, this DPA prevails.
- This DPA is governed by the laws of the Republic of Indonesia, with disputes resolved as provided in the Master Agreement.
Annex DPA-1 — Processing details
Completed by the Controller before signature:
- Categories of Personal Data Subject — for example end customers, employees, suppliers, application users
- Types of General Personal Data — for example name, email, phone number, address
- Types of Specific Personal Data — for example personal financial data, or "none"
- Approximate number of Data Subjects
- Purpose of processing by the Controller
- Levia Cloud Services used — for example Virtual Machine, Managed Database, Object Storage
- Regions used — JKT-1, JKT-2, or SBY-1
- Retention policy set by the Controller
- Data protection contact at the Controller — name, email, and phone
Annex DPA-2 — Technical and organisational security measures
- Pseudonymisation & encryption
- TLS 1.2+ for all data in transit; encryption at rest available for block and object storage; password hashing with a strong algorithm.
- Confidentiality
- Role-based access control, least privilege, mandatory multi-factor authentication for personnel, periodic access rights reviews.
- Integrity
- Immutable audit logging, change management, separation of production and non-production environments.
- Availability
- Redundant power and network, High Availability configurations, internal system backups, a periodically tested disaster recovery plan.
- Resilience
- Automatic L3/L4 DDoS mitigation, network segmentation, tenant isolation, CIS Benchmark hardening.
- Testing & evaluation
- Periodic vulnerability scanning, critical patches within 72 hours, annual ISO/IEC 27001 certification audit.
- Physical security
- Layered data centre access control, video surveillance, visit logging, fire suppression.
- Personnel management
- Confidentiality agreements, background checks for sensitive roles, periodic data protection training, access revocation procedures on termination.
- Incident management
- Documented incident response procedures, 24/7 NOC, 1 x 24 hour notice to the Controller, root cause analysis.
Appendix C — Data subject rights request form
Send the following to [email protected] or through the official ticket portal. Requests are free of charge.
Part A — Requester identity
- Full name
- Registered email address
- Phone number
- Levia Cloud account number, if any
- Relationship to Levia Cloud — customer, prospective customer, site visitor, or other
- Acting for yourself or on behalf of another — attach a power of attorney if acting for another
Part B — Right being exercised
Select one or more:
- Information about processing (Article 5)
- Correction or completion of data (Article 6)
- Access and a copy of the data (Article 7)
- Cessation, erasure, destruction (Article 8)
- Withdrawal of consent (Article 9)
- Objection to an automated decision (Article 10)
- Delay or restriction of processing (Article 11)
- Data portability (Article 13)
Also include a description of the request, the data period concerned if applicable, and the output format you want — PDF, CSV, JSON, or other.
Part C — Verification and declaration
- Attach an identity document — national ID, passport, or equivalent
- A statement that the information given is true and that you are entitled to make the request
- Name, signature, and date