Privacy Policy
Your privacy is important to us. This policy outlines how we collect, use, and protect your personal information.
Introduction
PT Sentral Mitra Informatika (βwe,β βour,β or βusβ) is committed to protecting your privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you visit our website, use our services, or interact with us.
Please read this privacy policy carefully. If you do not agree with the terms of this privacy policy, please do not access our services or website.
Quick Summary
We collect only the information necessary to provide our services, protect your data with industry-standard security measures, and never sell your personal information to third parties.
Information We Collect
We collect information about you in various ways when you use our services. The information we collect may include:
Personal Information You Provide
- Name, email address, and contact information when you fill out forms or contact us
- Company name, job title, and business information when requesting services
- Account credentials when you create an account on our platforms
- Payment information when you purchase our services (processed securely through third-party payment processors)
- Communication preferences and marketing opt-in/opt-out choices
- Any other information you choose to provide to us
Information Collected Automatically
- IP address, browser type, and operating system
- Pages visited, time spent on pages, and navigation patterns
- Referring website addresses and search terms used to find our website
- Device identifiers and mobile network information
- Cookies and similar tracking technologies (see Cookies section)
Direct Collection
Information you actively provide through forms, emails, or account creation
Automatic Collection
Technical data collected through your use of our website and services
How We Use Your Information
We use the information we collect for various purposes, including:
- Providing, maintaining, and improving our services and website
- Processing transactions and sending related information
- Responding to your inquiries and providing customer support
- Sending you technical notices, updates, security alerts, and administrative messages
- Communicating about products, services, offers, and events we think may interest you
- Monitoring and analyzing usage trends and user behavior
- Detecting, preventing, and addressing technical issues and security threats
- Personalizing your experience and delivering targeted content
- Complying with legal obligations and enforcing our terms and conditions
| Purpose | Legal Basis | Data Types |
|---|---|---|
| Service Delivery | Contract Performance | Contact info, Account data |
| Customer Support | Legitimate Interest | Contact info, Communication history |
| Marketing | Consent | Email, Preferences |
| Analytics | Legitimate Interest | Usage data, Technical data |
Information Sharing and Disclosure
We do not sell, trade, or rent your personal information to third parties. We may share your information in the following circumstances:
Service Providers
We may share your information with third-party vendors, consultants, and service providers who perform services on our behalf, such as:
- Cloud hosting and infrastructure providers
- Payment processing services
- Email delivery and marketing automation platforms
- Analytics and data analysis tools
- Customer relationship management (CRM) systems
Legal Requirements
We may disclose your information if required to do so by law or in response to valid requests by public authorities (e.g., court orders, government regulations).
Business Transfers
If we are involved in a merger, acquisition, or sale of assets, your information may be transferred as part of that transaction.
Important Note
We require all third-party service providers to maintain the confidentiality and security of your personal information and prohibit them from using it for any purpose other than providing services to us.
Data Security
We implement appropriate technical and organizational security measures to protect your personal information against unauthorized access, alteration, disclosure, or destruction.
Security Measures Include:
- Encryption of data in transit and at rest using industry-standard protocols (TLS/SSL)
- Regular security assessments and penetration testing
- Access controls and authentication mechanisms
- Employee training on data protection and confidentiality
- Incident response and breach notification procedures
- Regular backups and disaster recovery planning
ISO 27001 Certified
Our information security management system meets international standards
24/7 Monitoring
Continuous security monitoring and threat detection systems
Data Encryption
All sensitive data encrypted using AES-256 encryption
Regular Audits
Independent security audits conducted annually
While we strive to protect your personal information, no method of transmission over the internet or electronic storage is 100% secure. We cannot guarantee absolute security but will notify you promptly of any security breaches as required by law.
Your Privacy Rights
Depending on your location and applicable laws, you may have certain rights regarding your personal information:
- Right to Access: Request a copy of the personal information we hold about you
- Right to Rectification: Request correction of inaccurate or incomplete information
- Right to Erasure: Request deletion of your personal information (subject to legal obligations)
- Right to Restrict Processing: Request limitation on how we use your information
- Right to Data Portability: Receive your data in a structured, machine-readable format
- Right to Object: Object to processing of your information for certain purposes
- Right to Withdraw Consent: Withdraw consent for data processing at any time
- Right to Lodge a Complaint: File a complaint with a data protection authority
How to Exercise Your Rights
To exercise any of these rights, please contact us at privacy@sentral.co.id. We will respond to your request within 30 days in accordance with applicable laws.
Data Retention
We retain your personal information only for as long as necessary to fulfill the purposes outlined in this Privacy Policy, unless a longer retention period is required or permitted by law.
Retention Periods:
- Account information: Duration of account plus 3 years after closure
- Transaction records: 7 years from transaction date (legal requirement)
- Marketing communications: Until you unsubscribe or 3 years of inactivity
- Website analytics: 26 months from collection
- Customer support records: 3 years from last contact
When we no longer need your personal information, we will securely delete or anonymize it in accordance with our data retention and deletion policies.
Children's Privacy
Our services are not directed to individuals under the age of 18. We do not knowingly collect personal information from children. If you are a parent or guardian and believe your child has provided us with personal information, please contact us immediately.
If we become aware that we have collected personal information from children without verification of parental consent, we will take steps to remove that information from our servers promptly.
International Data Transfers
Your information may be transferred to and maintained on computers located outside of your state, province, country, or other governmental jurisdiction where data protection laws may differ from those in your jurisdiction.
If you are located outside Indonesia and choose to provide information to us, please note that we transfer the data to Indonesia and process it there. We ensure appropriate safeguards are in place for such transfers in accordance with applicable laws.
Standard Contractual Clauses
We use EU-approved contracts for data transfers
Adequacy Decisions
Transfers to countries with adequate protection levels
Changes to This Privacy Policy
We may update our Privacy Policy from time to time to reflect changes in our practices, technology, legal requirements, and other factors. We will notify you of any changes by posting the new Privacy Policy on this page and updating the βLast Updatedβ date.
We encourage you to review this Privacy Policy periodically for any changes. Changes to this Privacy Policy are effective when they are posted on this page.
For material changes, we will provide a more prominent notice (including, for certain services, email notification of privacy policy changes).
Contact Us
If you have any questions, concerns, or requests regarding this Privacy Policy or our data practices, please contact us:
Phone
Address
Jakarta, Indonesia Data Protection Officer
Response Time
We aim to respond within 48 hours
