Menu
Apexsoft Digital Agency

Legal

Data Protection

Updated August 21, 2026

This page sets out how we meet our obligations under Undang-Undang No. 27 Tahun 2022 tentang Pelindungan Data Pribadi (UU PDP) and, where our clients or their users are in Europe, the General Data Protection Regulation.

The Privacy Policy covers what we do with your data as a visitor or client. This page covers how we handle data inside the systems we build and operate.

  1. Controller and processor
  2. Our commitments as processor
  3. Rights of data subjects
  4. Cross-border transfers
  5. Security measures
  6. Breach notification
  7. Retention
  8. Getting in touch

Controller and processor

For this website and our own client records, Apexsoft is the data controller.

For a system we build, host or maintain for a client, that client is the controller and Apexsoft is the processor. In that role we act only on the client’s documented instructions, and the arrangement is governed by a written data processing agreement signed before we are given access to production data.

Our commitments as processor

We process personal data only on the controller’s documented instructions, and we tell them if we believe an instruction breaks the law.

Everyone with access is bound by confidentiality. Access to production data is granted individually, reviewed quarterly, and revoked the day someone leaves the project.

We do not engage a sub-processor without the controller’s prior written approval, and we flow the same obligations down to that sub-processor. A current list is provided to every client on request.

We help the controller answer data subject requests and meet their own obligations for breach notification, impact assessments and prior consultation.

At the end of an engagement we delete or return personal data at the controller’s choice, except where Indonesian law requires us to retain it.

We accept audits and provide the information needed to demonstrate compliance.

Rights of data subjects

UU PDP grants the right to be informed; to access and obtain a copy; to correct inaccurate data; to erase or destroy; to withdraw consent; to object to automated decision-making; to restrict and to delay processing; to portability; and to claim compensation for a violation.

The GDPR grants a closely equivalent set. Where both apply we follow whichever gives the stronger protection.

Requests reach us at info@apexsoftdigital.com. If we hold the data as processor we pass the request to the controller without delay and assist them in answering it.

Cross-border transfers

Article 56 of UU PDP permits transfer abroad where the receiving country provides protection at least equal to Indonesia’s, or where adequate binding safeguards exist, or with the data subject’s consent.

Our infrastructure providers are selected on that basis. Where a provider falls under the GDPR we additionally rely on standard contractual clauses. Where a client requires data to remain inside Indonesia, we can host entirely on Indonesian infrastructure — say so during discovery, because it shapes the architecture.

Security measures

Encryption in transit as standard, and at rest for backups and sensitive fields. Role-based access control with least privilege. Individually attributable credentials — no shared accounts. Multi-factor authentication on every administrative system. Encrypted, regularly restore-tested backups. Dependency scanning in CI and a documented patching cadence. Audit logging of administrative actions. Separate production, staging and development environments, with no production personal data in the lower environments.

Breach notification

On becoming aware of a personal data breach we notify the controller without undue delay and in any case within 24 hours, so that they can meet the 72-hour deadline set by Article 46 of UU PDP and Article 33 of the GDPR.

Where Apexsoft is the controller we notify the supervisory authority and, where the breach is likely to result in a high risk, the affected individuals, within 72 hours.

Retention

We keep personal data only as long as the purpose requires or the law demands. Retention schedules are agreed per project and written into the processing agreement rather than left to habit.

Getting in touch

Data protection enquiries: info@apexsoftdigital.com. For a copy of our standard data processing agreement or our current sub-processor list, ask and we will send them.


This page describes our practices. It is not legal advice, and it does not replace the specific data processing agreement signed for your project.

WhatsApp: +62 851-6897-6447