$ satupintudigital --privacy

Privacy Policy

Last updated: August 23, 2026

1. PT. Satu Pintu Digital's role

On this blog, PT. Satu Pintu Digital acts as a Data Controller for visitor data, prospective client data, and platform account and tenant data. For customer data processed through NalaNiaga stores, each store acts as the Data Controller and we act as a Data Processor.

2. Information we handle

This blog may receive and manage: (a) contact information — name, business name, email address, and phone number when you reach us through the contact form, the AI assistant, or WhatsApp; (b) technical data — device type, operating system, screen size, browser, language, connection type, user agent, cookies, and access logs; (c) behavioural data — the pages you read, how long you stay (dwell time), how far you scroll (scroll depth), and an automatically calculated intent score used to gauge content relevance; (d) conversation data — your questions, the AI assistant's replies, and the page context at the time, stored as a chat log; (e) prospective client data — the name and contact details submitted through lead forms. This data is used to understand our audience, answer your questions, and follow up on the requests you make.

3. Legal basis for processing

Processing is based on: Contract — for service delivery and account management; Legitimate interest — for security, fraud prevention, and service improvement; and Legal obligation — for tax and bookkeeping compliance.

4. Sharing with third parties

Data may be shared with operational support providers such as notification services, couriers, accounting services, and technical infrastructure providers. This blog's infrastructure provider is Cloudflare (hosting, database, and AI processing), which acts as a Data Processor on our instructions and is bound by a data processing agreement. We do not sell personal data.

5. Cross-border transfers

Data is processed and stored within Indonesia. Some supporting services may transit global networks without permanently storing personal data abroad.

6. Data security

We implement role-based access controls, password hashing, input validation, TLS in transit, and regular backups. Security SOPs and incident response procedures are in place.

7. Data retention

Data is retained as long as necessary for communication and service purposes, and to comply with applicable legal and tax obligations. Intent signals (dwell time, intent score, page context) and conversation data are stored for no more than 24 hours after the last visit, then deleted. Prospective client data is kept for as long as needed to follow up, or until you ask us to delete it. Inactive account data is deleted or anonymized after an offboarding transition period.

8. Breach notification

In the event of a personal data protection failure, we notify data subjects and authorities within 3×24 hours of discovery.

9. Data subject rights

You have the right to information, correction, access to data copies, deletion, withdrawal of consent, objection, and data portability. Requests are acknowledged within ≤3 working days and resolved within ≤30 days.

10. Complaints channel and DPO contact

For questions or requests related to personal data, please contact us:

Email: privacy@satupintudigital.co.id
Address: Komplek Green View Sunggal Blok D No. 38, Deli Serdang, Sumatera Utara.
Main site: satupintudigital.co.id.

11. Policy changes

This policy may be updated from time to time. Material changes will be notified. This policy is governed by the laws of the Republic of Indonesia (Law No. 27/2022 on PDP, Government Regulation No. 71/2019 on Electronic Systems).