Skip to main content
A second Jakarta region (jkt-2) is now available.See the region list

Privacy and Personal Data Protection Policy

What personal data we collect, on what legal basis we process it, how long we keep it, who we disclose it to, and your nine rights under Indonesian Law No. 27 of 2022.

Last updated Effective

This is a translation provided for convenience. The document is made in the Indonesian language, and under Law No. 24 of 2009 the Indonesian version prevails in the event of any difference in interpretation.

Part I — General provisions

1 — Introduction and scope

  1. PT Levia Cloud Indonesia ("Levia Cloud", "we") respects everyone’s privacy and is committed to protecting personal data in accordance with Law No. 27 of 2022 on Personal Data Protection (the "PDP Law") and its implementing regulations.
  2. This Privacy Policy (the "Policy") explains what personal data we collect, what we process it for, on what legal basis, to whom we disclose it, how long we keep it, and what rights you have and how to use them.
  3. This Policy applies to: (a) registered Levia Cloud customers, whether individuals or business entities and their designated personnel; (b) prospective customers who register, request a quote, or use a trial; (c) visitors to leviacloud.com and its subdomains; and (d) partners, suppliers, and job applicants so far as relevant.
  4. This Policy is an inseparable part of the Levia Cloud Terms of Service. Where the two conflict on personal data processing, this Policy prevails.
  5. This Policy does not govern the privacy practices of third parties, including applications, sites, or services you run yourself on Levia Cloud infrastructure, or third-party sites linked from ours.
  6. By registering, using the Services, or accessing our site, you confirm that you have read and understood this Policy.

2 — Definitions

Personal Data
Data about an identified or identifiable individual, alone or combined with other information, directly or indirectly, through electronic or non-electronic systems.
General Personal Data
Including full name, sex, nationality, religion, marital status, and personal data combined to identify a person (Article 4, PDP Law).
Specific Personal Data
Health data and information, biometric data, genetic data, criminal records, children’s data, personal financial data, and other data designated by law (Article 4, PDP Law).
Personal Data Subject
The individual to whom Personal Data attaches — also referred to in this Policy as "you".
Personal Data Controller
The party that determines the purposes of, and exercises control over, the processing of Personal Data.
Personal Data Processor
The party that processes Personal Data on behalf of and on the instructions of the Controller.
Processing
Obtaining, collecting, handling, analysing, storing, correcting, updating, displaying, announcing, transferring, disseminating, disclosing, deleting, or destroying Personal Data.
Customer Data
All data, content, configuration, images, snapshots, and backups the Customer uploads, creates, or stores on the Levia Cloud Services.
Services
The Levia Cloud cloud computing services as defined in the Terms of Service.
Sub-Processor
A third party engaged by Levia Cloud to process Personal Data in delivering the Services.
Protection Failure
An event resulting in the unlawful disclosure, loss, alteration, or access of Personal Data.
Authority
The body responsible for personal data protection affairs under the PDP Law.
Business Day
Monday to Friday, 08:00–18:00 WIB, excluding Indonesian national public holidays.

3 — Levia Cloud’s two roles over personal data

As a cloud infrastructure provider, Levia Cloud holds two legally distinct roles. Telling them apart matters, because the rights and obligations attached to each are not the same.

AspectRole 1 — ControllerRole 2 — Processor
What dataPersonal data we collect ourselves to run the business relationship: registration, account, billing, technical support, security, and the website.Personal data contained within Customer Data — the contents of the Customer’s virtual machines, storage, databases, and backups.
Who sets the purposeLevia Cloud.The Customer. Levia Cloud processes only on the Customer’s instructions.
ExamplesAccount registrant name and email, business tax number, payment history, console access logs, support ticket contents.Your end customers’ data in your database, files in your object storage, your application logs.
Do we see the contentsYes, so far as needed for the purposes described in Part II.No. We do not access Customer Data contents except at your request, to address an urgent incident, or where required by law.
Governed byPart II of this Policy.Part III of this Policy and Appendix B (DPA).
Where the Data Subject complainsDirectly to Levia Cloud at [email protected].To the Customer as Controller. Levia Cloud forwards any request it receives to the Customer.
  1. Where the Customer is a business entity, that entity acts as Personal Data Controller over both its own personnel data and its end-customer data, and is responsible for ensuring a lawful basis for processing exists.
  2. Levia Cloud does not determine what Personal Data the Customer stores on the Services, does not determine the purpose of its processing, and does not use it for its own ends in any form — including for training artificial intelligence models, advertising, or commercial analytics.

Part II — Levia Cloud as controller

4 — Personal data we collect

4.1 Data categories

CategoryDetailSource
IdentityFull name, date of birth, identity number (national ID/passport) for verification. For business entities: entity name, tax number, deed of establishment, business identification number, and the identity of authorised officers.Directly from you
ContactEmail address, phone number, billing address, correspondence address.Directly from you
AccountUsername, hashed password, two-factor authentication status, API and SSH key fingerprints, roles and access rights, language and region preferences.You and our systems
Personal financialPayment method, last four digits of the card, bank name and account number for refunds, transaction history, invoice status, and arrears history.You and the payment provider
Technical usageResource identifiers, specifications, hours used, traffic volume, capacity metrics, and quotas.Our systems
Access and security logsIP address, browser and operating system type, sign-in and sign-out times, console and API actions, failed sign-in attempts.Our systems
Technical supportTicket contents, attachments you send, email and chat correspondence records, emergency call notes.Directly from you
WebsitePages visited, visit duration, referral source, and cookie identifiers.Cookies and analytics tools
MarketingSubscription preferences, marketing email open and click history, webinar or event participation.Our systems

4.2 Specific personal data

4.3 What we do not collect

  • We do not store full credit card numbers, expiry dates, or CVV codes. That data is processed directly by a PCI DSS-certified payment gateway provider.
  • We do not carry out cross-site tracking for behavioural advertising.
  • We do not buy personal data lists from third parties for marketing.
  • We do not make automated decisions with legal effect on you without human involvement, except the automated billing process under Article 7 of the Terms of Service, whose timeline is notified in advance and can be stopped by payment.

5 — Purposes and legal basis for processing

Every processing activity we carry out rests on a lawful basis under Article 20(2) of the PDP Law. The table below maps purpose, data used, and legal basis.

Processing purposeData usedLegal basis — Article 20(2)
Creating and managing accountsIdentity, contact, accountPoint b — performance of contractual obligations
Providing, operating, and maintaining the ServicesAccount, technical usage, logsPoint b — performance of contractual obligations
Invoicing, receiving payment, and refundsIdentity, personal financialPoint b — performance of contractual obligations
Issuing tax invoices and tax reportingIdentity, tax number, transactionsPoint c — compliance with legal obligations
Identity verification and account abuse preventionIdentity, corporate documents, logsPoints c and f — legal obligation and legitimate interest
Billing, suspension, and deletion notices under Article 7 of the TermsContact, personal financialPoint b — performance of contractual obligations
Technical support and incident handlingTechnical support, account, logsPoint b — performance of contractual obligations
System security, attack detection, and fraud preventionAccess and security logsPoint f — legitimate interest of Levia Cloud and other customers
Service quality improvement and capacity planningTechnical usage in aggregate or anonymised formPoint f — legitimate interest
Meeting lawful requests from competent authoritiesAs scoped by the requestPoint c — compliance with legal obligations
Legal defence and dispute resolutionAs the matter requiresPoint f — legitimate interest
Sending marketing communications, newsletters, and event invitationsContact, marketing preferencesPoint a — consent, withdrawable at any time
Non-essential cookies and site analyticsWebsite dataPoint a — consent via the cookie banner

6 — Disclosure to third parties

We may disclose Personal Data on a limited basis to the following recipients, so far as necessary and with adequate safeguards.

RecipientPurpose of disclosureSafeguards
Payment gateway providers and banksPayment processing, transaction verification, and refunds.Data processing agreement; PCI DSS certification on the provider.
Data centre infrastructure providersHardware placement and connectivity within Indonesia.Service level and confidentiality agreements; controlled physical access.
Operational tooling providersTicketing, transactional email delivery, monitoring, and analytics.Data processing agreement; data minimisation.
Professional advisersAccountants, auditors, tax consultants, and lawyers for compliance and legal defence.Professional confidentiality obligations.
Competent authoritiesCompliance with valid written orders from law enforcement, tax authorities, or the Authority.Validity reviewed; scope kept to the minimum.
Parties to a corporate actionMerger, acquisition, or business transfer.Confidentiality agreement; notice to you before the transfer takes effect.
  1. The current Sub-Processor list is set out in Appendix A and published on the privacy policy page of our site.
  2. Before engaging a new Sub-Processor that will process Customer Data, we notify the Customer at least 30 calendar days in advance. The Customer may raise a reasoned objection as set out in Appendix B.
  3. Where we receive a data access request from law enforcement, we will: (a) check the validity and authority of the request; (b) limit the scope of disclosure to what is expressly requested; and (c) inform you, unless doing so is prohibited by law or court order.

7 — Data retention periods

We keep Personal Data only as long as needed for the processing purpose, or as long as the law requires, whichever is longer.

Data categoryPeriodReason
Account and profile dataWhile the account is active, plus 30 calendar days after closureAllows account recovery and settlement of final obligations
Invoices, tax invoices, and payment records10 years from the end of the financial yearLaw No. 8 of 1997 on Company Documents and tax rules
Transaction history and invoice status10 years from the transactionBookkeeping and evidentiary obligations
Identity verification documents (KYC)5 years from account closureAbuse prevention and legal defence
Support tickets and correspondence3 years from ticket closureReference for recurring issues and dispute resolution
Delivery records for billing, suspension, and deletion notices3 years from sendingEvidence of compliance with Article 7 of the Terms
Console and API access logs12 monthsSecurity, audit, and incident investigation
Network and security logs12 monthsAttack detection and investigation
Marketing data and subscription preferencesUntil consent is withdrawn, plus 30 calendar daysEnsures the withdrawal is actually executed
Analytics cookie dataAt most 14 monthsPeriod-over-period visit trend analysis
Customer Data (Processor role)Per the Customer’s instructions and Articles 7 and 10 of the Terms of ServiceThe Customer is the Controller of that data
  1. Once the retention period ends, Personal Data is deleted or destroyed by methods that make recovery impossible, or permanently anonymised so that it can no longer be linked to an individual.
  2. Data that is the subject of a legal dispute, an authority’s examination, or a law enforcement request is retained until the matter is finally resolved, even where the normal retention period has ended.

Part III — Levia Cloud as processor

9 — Customer Data on the Services

When you run a virtual machine, store files in object storage, or operate a database on the Levia Cloud Services, everything inside is Customer Data and is entirely under your control.

Over that Customer Data you act as Personal Data Controller and Levia Cloud acts as Personal Data Processor. The consequences are:

  • You decide what Personal Data is stored, for what purpose, and for how long.
  • You are responsible for ensuring a lawful basis exists for processing that Personal Data.
  • You are responsible for responding to requests from your own Personal Data Subjects.
  • You are responsible for security at the operating system and application layers, content encryption, and your own user access control.
  • We provide secure infrastructure and tooling, and process Customer Data only on your instructions.
  1. We do not scan, analyse, index, or exploit the contents of Customer Data for our own ends, including for training artificial intelligence models, cross-selling, advertising, or profiling.
  2. The detailed Controller–Processor terms are set out in the Data Processing Agreement at Appendix B, which can be signed separately if you need it for audit, tender, or internal compliance purposes.

10 — Processing limits and customer instructions

Levia Cloud processes Customer Data solely on the Customer’s documented instructions, expressed through: (a) the Terms of Service; (b) this Policy and Appendix B; (c) the configuration you set yourself in the console and API; and (d) written requests through the official ticket portal.

Levia Cloud personnel may access Customer Data only in the three circumstances below.

CircumstanceExplanationControl
At your requestYou request technical assistance that requires our engineers to access your resources.Written consent on the ticket; time-bound access; every session logged.
Urgent incidentNecessary to address a disruption or attack affecting the Services or other customers.Approval by an authorised internal officer; notice to you within 1 x 24 hours.
Legal obligationA valid written order from a competent authority.Validity check; minimum scope; notice to you unless prohibited.
  1. Every personnel access to Customer Data is recorded in an immutable audit trail carrying the officer’s identity, time, scope, and reason for access. You may request that record at any time.
  2. If in our assessment a Customer instruction conflicts with the PDP Law or other legislation, we will notify the Customer and may suspend execution of that instruction.

11 — Sub-processors and assistance to customers

11.1 Sub-processors

  1. Levia Cloud may engage Sub-Processors to support delivery of the Services. Every Sub-Processor is bound by data protection obligations no less strict than Levia Cloud’s own under this Policy.
  2. Levia Cloud remains fully liable to the Customer for processing carried out by its Sub-Processors.
  3. The current Sub-Processor list is at Appendix A. Changes are notified at least 30 calendar days before they take effect, and the Customer may raise a reasoned objection within 14 calendar days of the notice.

11.2 Assistance to customers

As Processor, we help the Customer meet its own obligations as Controller through:

Data Subject rights tooling
Export, correction, and deletion features in the console and API, so the Customer can respond to its own Personal Data Subjects independently.
Request forwarding
Where we receive a request from a Personal Data Subject relating to Customer Data, we do not respond substantively but forward it to the Customer within 3 Business Days.
Incident notification
Notice of a Protection Failure affecting Customer Data within 1 x 24 hours of our becoming aware, so the Customer can meet its own 3 x 24 hour obligation to Data Subjects and the Authority.
Compliance documentation
Summaries of ISO/IEC 27001 and ISO 9001 certification, descriptions of security measures, and answers to customer compliance questionnaires.
Impact assessment support
Reasonable technical information to help the Customer prepare a personal data protection impact assessment.
Audit
Audit facilitation under Appendix B, Section B.10.

Part IV — Rights, security, and compliance

12 — Your rights as a personal data subject

The PDP Law gives you the following rights. All of them are free to exercise.

BasisRightWhat it means in practice
Article 5Right to informationTo be told our identity, the legal basis, the purpose, and the accountability of processing. This Policy discharges that right.
Article 6Right to complete and correctTo correct data that is wrong or incomplete. Most of this you can do yourself in the console profile settings.
Article 7Right of access and copyTo obtain information about the Personal Data of yours that we process, and a copy of it.
Article 8Right to end, erase, and destroyTo request that processing stop and that your Personal Data be erased or destroyed, so far as this does not conflict with statutory retention obligations.
Article 9Right to withdraw consentTo withdraw consent previously given, for example for marketing and non-essential cookies. Withdrawal is not retroactive.
Article 10Right regarding automated decisionsTo object to a decision based solely on automated processing that produces legal effects or significantly affects you.
Article 11Right to delay and restrictTo request proportionate delay or restriction of processing, for example while the accuracy of data is disputed.
Article 12Right to compensationTo claim and receive compensation for unlawful processing of your Personal Data.
Article 13Right to portabilityTo obtain and transmit your Personal Data to another controller in a commonly used, machine-readable format.

12.1 How to submit a request

  1. Requests are submitted by email to [email protected], through the official ticket portal, or by completing the form at Appendix C.
  2. To protect you against fraudulent requests, we verify the requester’s identity first. Verification is carried out proportionately and without excess.

The handling deadlines we commit to:

StageDeadline
Acknowledgement of the requestWithin 3 Business Days
Verification of the requester’s identityWithin 5 Business Days of the request
Fulfilment of the requestWithin 14 Business Days of identity being verified
Extension for complex requestsExtendable once by up to 14 Business Days, with written reasons
Refusal of a requestGiven in writing with reasons and the procedure for objecting
  1. We may refuse or limit a request in the cases excepted by Article 15 of the PDP Law — including national defence and security, law enforcement processes, the public interest in the administration of the state, financial services supervision, and statistical and scientific research purposes. A refusal always comes with written reasons.
  2. Where your request concerns Customer Data belonging to another Levia Cloud customer — for example where you are an end user of an application running on our infrastructure — we forward it to that customer as Controller, and tell you that we have done so.

12.2 Objections and complaints

  1. If you are not satisfied with how a request was handled, you may object to [email protected]. The objection is reviewed by an officer other than the one who handled it first, with a response within 10 Business Days.
  2. You are also entitled to complain to the Authority responsible for personal data protection, and to seek legal remedies through the courts under Article 12 of the PDP Law.

13 — Personal data security

We apply adequate technical and organisational measures to protect Personal Data against unauthorised access, disclosure, alteration, and destruction.

Encryption
All traffic encrypted in transit using TLS 1.2 or higher. Encryption at rest is available for volumes and object storage. Passwords are stored hashed with a strong algorithm.
Access control
Role-based access on a least-privilege principle, mandatory multi-factor authentication for all internal personnel, and periodic access rights reviews.
Network security
Network segmentation, firewalls and security groups, automatic layer 3 and 4 DDoS mitigation, and tenant isolation.
Monitoring
24/7 security monitoring by the Network Operations Center, immutable audit logging, and automatic anomaly alerts.
Testing
Periodic vulnerability scanning, CIS Benchmark hardening, and critical patches applied within 72 hours of vendor release.
Physical security
Data centres with layered access control, video surveillance, redundant power, and fire suppression.
Personnel
Confidentiality agreements for all personnel, background checks for sensitive roles, and periodic data protection training.
Certification
ISO/IEC 27001 for Information Security Management and ISO 9001 for Quality Management. The infrastructure is prepared to PCI DSS requirements.
Business continuity
Internal system backups, a disaster recovery plan, and periodic recovery testing.
  1. Even so, no method of electronic transmission or storage is entirely free of risk. We cannot guarantee absolute security, but we are committed to reviewing and updating our safeguards continuously.
  2. Security responsibility is shared. You are responsible for keeping credentials confidential, enabling two-factor authentication, and securing the operating systems and applications you run yourself.

14 — Personal data protection failures

  1. In the event of a Personal Data Protection Failure, we give written notice within 3 x 24 hours of becoming aware to the affected Personal Data Subjects and to the Authority, in accordance with Article 46 of the PDP Law.
  2. The notice states at minimum: (a) the Personal Data exposed; (b) when and how it was exposed; and (c) the handling and recovery steps Levia Cloud has taken.
  3. Where the failure affects Customer Data for which Levia Cloud acts as Processor, we notify the Customer as Controller within 1 x 24 hours of becoming aware, so the Customer has enough time to meet its own 3 x 24 hour obligation to its Personal Data Subjects and to the Authority.
  4. We provide reasonable technical support and information to the Customer for investigation, notification, and recovery.
  5. Every incident is analysed for root cause, and the result is set out in a report with preventive actions so the same event does not recur.

15 — Transfers outside Indonesia

  1. As a principle, all Personal Data and Customer Data is stored and processed in data centres within the Republic of Indonesia — the Jakarta (JKT-1, JKT-2) and Surabaya (SBY-1) regions.
  2. We do not move Customer Data outside the Republic of Indonesia.
  3. In certain cases, limited operational data — for example metadata in transactional email tooling or the ticket system — may be processed by a provider established abroad. In that case we ensure one of the conditions in Article 56 of the PDP Law is met.
  • The recipient’s country of establishment has a level of personal data protection equal to or higher than that under the PDP Law; or
  • There is adequate and binding personal data protection, set out in a data processing agreement with standard clauses; or
  • The Personal Data Subject has given explicit consent.

The list of providers with cross-border processing and the basis of protection for each is in Appendix A, updated whenever it changes.

16 — Children’s and specific data

  1. The Levia Cloud Services are intended for users at least 18 years old, or legal entities. We do not knowingly collect children’s Personal Data.
  2. If we learn that children’s Personal Data has been collected without valid parental or guardian consent, we delete it as soon as possible. You can report such a case to [email protected].
  3. If you as a Customer intend to store Specific Personal Data — including health, biometric, genetic, or children’s data — on our Services, you are responsible for ensuring a lawful basis exists and that appropriate additional safeguards are applied. We recommend contacting us first so that adequate technical and contractual arrangements can be put in place.

17 — Data Protection Officer

  1. Levia Cloud has appointed a Data Protection Officer as contemplated by Article 53 of the PDP Law, given that our core activity involves large-scale, systematic processing of Personal Data.
  2. The Data Protection Officer’s duties include: advising management on PDP Law compliance, monitoring implementation of data protection policy, advising on data protection impact assessments, acting as the contact point for Personal Data Subjects and the Authority, and coordinating the handling of Protection Failures.
  3. The Data Protection Officer can be reached at [email protected] or through the correspondence address of PT Levia Cloud Indonesia.

18 — Policy changes, contact, and complaints

18.1 Policy changes

  1. We may update this Policy to keep pace with the Services, technology, and the law.
  2. Material changes — including adding a new processing purpose, changing the legal basis, adding a category of recipient, or extending a retention period — are notified by email to the registered address and by console notification at least 30 calendar days before they take effect.
  3. Where a change requires your consent under the PDP Law, the new processing does not begin until consent is obtained. If you do not accept another material change, you may terminate the Services under Article 15 of the Terms of Service.
  4. We keep an archive of every version of this Policy with its effective date, and make it available on request.

18.2 Contact

PurposeContact
Data Protection Officer, Data Subject rights requests, and reports of suspected data misuse[email protected]
Objections and complaints[email protected]
Technical support and security incidents[email protected] · +62 21 5099 0000 (24/7)
Billing and data export requests[email protected]
Correspondence addressPT Levia Cloud Indonesia, Jakarta, Indonesia

18.3 Complaints to the authority

Without prejudice to your right to complain directly to us, you may complain to the Authority responsible for personal data protection, and seek legal remedies through the courts under Article 12 of the PDP Law. Breaches of the PDP Law may attract administrative sanctions ranging from written warning, temporary suspension of processing, and erasure or destruction of Personal Data, up to an administrative fine of at most 2% of annual revenue.

Appendices

Appendix A — Sub-processors and third parties

CategoryProviderData processedProcessing location
Payment gateway[●]Billing identity, transaction metadataIndonesia
Data centre / colocation[●]All data on the infrastructureJakarta & Surabaya, Indonesia
Support ticketing system[●]Contact, ticket contents, attachments[●]
Transactional email[●]Email address, notification contents[●]
SMS delivery[●]Phone number, message contentsIndonesia
Website analytics[●]Cookie identifiers, visit data[●]
Internal monitoring & observability[●]Metrics, operational logsIndonesia
Email marketing tooling[●]Contact, subscription preferences[●]

For every provider that processes data outside the Republic of Indonesia, the last column must be completed with the basis of protection under Article 56 of the PDP Law — equivalence of protection level, an agreement with standard clauses, or the Data Subject’s explicit consent.

List version
1.0 — 14 August 2026
Publication
leviacloud.com/privacy/subprocessors
Change notice
30 calendar days before taking effect, by email to the registered address and console notification
Customer objection window
14 calendar days from receipt of the notice

Appendix B — Data Processing Agreement (DPA)

Data Processing Agreement — signable separately as an addendum to the Terms of Service. Contact [email protected] for a signable copy.

Personal Data Controller
The Customer, as identified in the signature document.
Personal Data Processor
PT Levia Cloud Indonesia.
Effective date
The date of signature or the Service effective date, whichever is earlier.
Master agreement
Levia Cloud Terms of Service v1.0 and/or the related cooperation agreement.

B.1 Subject matter, nature, and purpose of processing

  1. The Processor processes Personal Data on the Controller’s behalf solely to deliver the cloud computing Services under the Master Agreement.
  2. The nature of processing covers storage, hosting, transmission, backup, restoration, and deletion, without content analysis.
  3. Processing lasts for the term of the Master Agreement, plus the deletion or return period under Section B.12.

B.2 Types of personal data and categories of subject

  1. The types of Personal Data and categories of Personal Data Subject are determined entirely by the Controller and set out in Annex DPA-1.
  2. The Controller warrants that it will not store Specific Personal Data on the Services without first notifying the Processor and agreeing additional safeguards.

B.3 Controller obligations

  • To ensure a lawful basis under Article 20 of the PDP Law exists for all Personal Data stored on the Services.
  • To give the Processor lawful, clear, and documented instructions.
  • To respond to Personal Data Subject requests and meet its notification obligations to the Authority.
  • To configure the security controls within its own control, including content encryption, key management, user access control, and retention policy.

B.4 Processor obligations

  • To process Personal Data only on the Controller’s documented instructions, unless otherwise required by law.
  • To notify the Controller where in the Processor’s assessment an instruction conflicts with the PDP Law.
  • Not to use Personal Data for its own purposes, including training artificial intelligence models, advertising, profiling, or sale to third parties.
  • To apply the security measures in Annex DPA-2 and review them periodically.

B.5 Personnel confidentiality

The Processor ensures every person authorised to access Personal Data is bound by a written confidentiality obligation that survives the end of employment, and receives periodic personal data protection training.

B.6 Security

  1. The Processor applies the technical and organisational measures set out in Annex DPA-2, covering at minimum encryption in transit, role-based access control, multi-factor authentication for personnel, network segmentation, audit logging, and 24-hour monitoring.
  2. The Processor maintains ISO/IEC 27001 certification and provides a summary of certification audit results to the Controller on request.

B.7 Sub-processors

  1. The Controller gives general authorisation for the use of Sub-Processors as listed in Appendix A of the Privacy Policy.
  2. The Processor notifies any planned addition or replacement of a Sub-Processor at least 30 calendar days before it takes effect.
  3. The Controller may raise a reasoned objection within 14 calendar days. If the objection cannot be resolved jointly, the Controller may terminate the affected Services without termination penalty.
  4. The Processor binds every Sub-Processor to data protection obligations no less strict, and remains fully liable to the Controller for the Sub-Processor’s processing.

B.8 Assistance with data subject rights

  1. The Processor provides technical features in the console and API allowing the Controller to access, correct, export, and delete Personal Data independently.
  2. Where the Processor receives a request directly from a Personal Data Subject relating to Customer Data, it does not respond substantively but forwards it to the Controller within 3 Business Days.
  3. The Processor gives the Controller reasonable assistance in preparing a personal data protection impact assessment and in consulting the Authority.

B.9 Personal data protection failures

  1. The Processor notifies the Controller within 1 x 24 hours of becoming aware of a Protection Failure affecting the Controller’s Personal Data.
  2. The notice states the nature of the failure, the categories and approximate number of Personal Data Subjects affected, the likely consequences, and the handling and mitigation steps taken.
  3. The Processor does not notify Personal Data Subjects or the Authority directly on the Controller’s behalf, unless requested in writing by the Controller or required by law.

B.10 Audit and inspection

  1. The Processor provides reasonable information to demonstrate compliance with this DPA, including the ISO/IEC 27001 certificate, audit report summaries, and security questionnaire responses.
  2. The Controller may audit at most once in any 12 months, on 30 calendar days’ written notice, on Business Days, and without disrupting the Processor’s operations or other customers’ confidentiality.
  3. Additional audits may be carried out following a material Protection Failure or where ordered by a competent authority.
  4. Audit costs are borne by the Controller, unless the audit establishes material non-compliance on the Processor’s side.

B.11 Cross-border transfers

The Processor does not move Customer Data outside the Republic of Indonesia. Any exception requires the Controller’s prior written consent and compliance with Article 56 of the PDP Law.

B.12 Deletion or return of data

  1. On termination at the Controller’s initiative, the Processor provides a 30-calendar-day window for the Controller to export Personal Data, after which the data is permanently deleted.
  2. On termination arising from payment arrears, the specific terms of Article 7 of the Terms of Service apply — permanent deletion 30 calendar days after the suspension date.
  3. The Processor issues written confirmation that deletion has been carried out, if the Controller requests it.
  4. Data that must be retained by law is excepted from the deletion obligation, and remains subject to confidentiality and security obligations for as long as it is held.

B.13 Final provisions

  1. This DPA is an inseparable part of the Master Agreement. Where the two conflict on Personal Data processing, this DPA prevails.
  2. This DPA is governed by the laws of the Republic of Indonesia, with disputes resolved as provided in the Master Agreement.

Annex DPA-1 — Processing details

Completed by the Controller before signature:

  • Categories of Personal Data Subject — for example end customers, employees, suppliers, application users
  • Types of General Personal Data — for example name, email, phone number, address
  • Types of Specific Personal Data — for example personal financial data, or "none"
  • Approximate number of Data Subjects
  • Purpose of processing by the Controller
  • Levia Cloud Services used — for example Virtual Machine, Managed Database, Object Storage
  • Regions used — JKT-1, JKT-2, or SBY-1
  • Retention policy set by the Controller
  • Data protection contact at the Controller — name, email, and phone

Annex DPA-2 — Technical and organisational security measures

Pseudonymisation & encryption
TLS 1.2+ for all data in transit; encryption at rest available for block and object storage; password hashing with a strong algorithm.
Confidentiality
Role-based access control, least privilege, mandatory multi-factor authentication for personnel, periodic access rights reviews.
Integrity
Immutable audit logging, change management, separation of production and non-production environments.
Availability
Redundant power and network, High Availability configurations, internal system backups, a periodically tested disaster recovery plan.
Resilience
Automatic L3/L4 DDoS mitigation, network segmentation, tenant isolation, CIS Benchmark hardening.
Testing & evaluation
Periodic vulnerability scanning, critical patches within 72 hours, annual ISO/IEC 27001 certification audit.
Physical security
Layered data centre access control, video surveillance, visit logging, fire suppression.
Personnel management
Confidentiality agreements, background checks for sensitive roles, periodic data protection training, access revocation procedures on termination.
Incident management
Documented incident response procedures, 24/7 NOC, 1 x 24 hour notice to the Controller, root cause analysis.

Appendix C — Data subject rights request form

Send the following to [email protected] or through the official ticket portal. Requests are free of charge.

Part A — Requester identity

  • Full name
  • Registered email address
  • Phone number
  • Levia Cloud account number, if any
  • Relationship to Levia Cloud — customer, prospective customer, site visitor, or other
  • Acting for yourself or on behalf of another — attach a power of attorney if acting for another

Part B — Right being exercised

Select one or more:

  • Information about processing (Article 5)
  • Correction or completion of data (Article 6)
  • Access and a copy of the data (Article 7)
  • Cessation, erasure, destruction (Article 8)
  • Withdrawal of consent (Article 9)
  • Objection to an automated decision (Article 10)
  • Delay or restriction of processing (Article 11)
  • Data portability (Article 13)

Also include a description of the request, the data period concerned if applicable, and the output format you want — PDF, CSV, JSON, or other.

Part C — Verification and declaration

  • Attach an identity document — national ID, passport, or equivalent
  • A statement that the information given is true and that you are entitled to make the request
  • Name, signature, and date