neobiz Back to home →

Legal

Country
IndonesiaWorldwide
Language
Bahasa IndonesiaEnglish
Terms of ServicePrivacy PolicyData Processing AgreementAcceptable Use PolicyAI TermsMessaging PolicySubprocessors

Neobiz Data Processing Agreement (DPA) — Indonesia (English)

English version. In the event of any inconsistency between the two versions, the Indonesian version prevails — see §13 (Language). Both versions are of equal date.

Version: id-2026-07-1 · Forms part of the Terms of Service.


1. Definitions

  • "Personal Data" (Data Pribadi), "Data Subject" (Subjek Data Pribadi), "Data Controller" (Pengendali Data Pribadi), "Data Processor" (Prosesor Data Pribadi) — as defined in the PDP Law (Law No. 27 of 2022).
  • "Specific Personal Data" (data pribadi yang bersifat spesifik) — as defined in PDP Law Article 4, including health data, biometric data, genetic data, criminal records, children's data, personal financial data, and other data designated by law.
  • "Member Data" — Personal Data about your customers/members processed by Neobiz on your behalf.
  • "Personal Data Breach" (kegagalan pelindungan Data Pribadi) — as contemplated by PDP Law Article 46.
  • "Authority" — the supervisory body designated under the PDP Law and, pending its establishment, the Ministry of Communication and Digital (Komdigi) and any relevant sectoral regulator.

2. Roles and scope

2.1 Allocation. For Member Data, you are the Data Controller (Pengendali) and Neobiz is the Data Processor (Prosesor). For Account Data, Neobiz is the Data Controller.

2.2 Written processing agreement. This DPA constitutes the written agreement between Controller and Processor required by the PDP Law, and specifies the scope, method, duration, supervision and communication procedure for the processing.

2.3 Scope of instructions. Neobiz processes Member Data only to provide, secure and support the Service, and only on your documented instructions. The Terms, this DPA, and your configuration and use of the Service constitute your complete documented instructions.

2.4 The consequence of the allocation. As Controller, you determine the purposes of processing, decide who is contacted and through which channel, and bear responsibility for the lawful basis under PDP Law Article 20. Neobiz does not review, verify or approve your lawful basis. Where you import contacts or send campaigns, you make the Controller's decision.

2.5 Details of processing. Set out in Annex A.

2.6 Unlawful instruction. Neobiz will inform you if, in its opinion, an instruction infringes the PDP Law, and may suspend that instruction until confirmed or amended.

2.7 No independent-controller use. Neobiz does not use Member Data for its own purposes, does not sell it, and does not use it to train AI models except as expressly permitted by the AI Terms and any setting you enable.

3. Your obligations as Controller

3.1 You warrant a valid lawful basis under PDP Law Article 20 for all Member Data you provide or instruct us to process.

3.2 You are responsible for the accuracy, quality and legality of Member Data and the means by which you acquired it.

3.3 You will not provide Specific Personal Data except where the Service is designed for it, you have a lawful basis, and the law permits. See the Messaging Policy for categories prohibited from Messaging Channels entirely.

3.4 You will fulfil the Controller's own obligations under the PDP Law, including providing privacy notices, honouring Data Subject rights, and making the notifications required by Article 46 (see §7.3).

3.5 You will use the member-facing privacy notice base we make available, retaining its required core clauses, or an equivalent notice that meets the PDP Law.

4. Neobiz's obligations as Processor

Neobiz will: (4.1) process Member Data only on your documented instructions; (4.2) ensure authorised personnel are bound by confidentiality; (4.3) implement the measures in Annex B; (4.4) respect §6 for Subprocessors; (4.5) assist you with Data Subject rights (§5); (4.6) assist with impact assessments; (4.7) notify you of a Personal Data Breach per §7; (4.8) delete or return Member Data per §8; and (4.9) make available information necessary to demonstrate compliance and allow audits per §9.

5. Data Subject rights

5.1 The Service provides features enabling you to fulfil the rights under PDP Law Chapter V, including the rights to information, access, rectification, erasure, withdrawal of consent, objection to automated decision-making, restriction, portability, and redress. Where those features are insufficient, Neobiz will provide reasonable assistance.

5.2 If Neobiz receives a request directly from one of your members, it will (unless legally required otherwise) refer the person to you and notify you promptly.

5.3 Current state. Full self-service member export and erasure tooling is on the roadmap; until it ships, Neobiz will assist you manually to fulfil verified requests within the statutory window.

6. Subprocessors

6.1 You authorise Neobiz to engage the Subprocessors listed at ../subprocessors.md.

6.2 Neobiz imposes data-protection obligations on each Subprocessor substantially as protective as this DPA, and remains fully liable for their performance.

6.3 Neobiz will give at least thirty (30) days' notice of intended additions or replacements. You may object on reasonable data-protection grounds; if unresolved, you may terminate the affected part of the Service without penalty for the unused prepaid term.

7. Personal Data Breach

7.1 Neobiz will notify you without undue delay and in any event within 24 hours after becoming aware of a Personal Data Breach affecting Member Data.

7.2 The notice will include the information reasonably available to help you meet your obligations under PDP Law Article 46 — the Personal Data disclosed, when and how the breach occurred, and the handling and recovery efforts undertaken.

7.3 Your notification duty. You remain responsible, as Controller, for notifying affected Data Subjects and the Authority within the statutory period, and for any public notification required where public services or the public interest are materially affected.

7.4 Neobiz will take reasonable steps to mitigate and remediate, and will keep you informed.

7.5 Notification is not an acknowledgement of fault or liability.

8. Term, deletion and return

8.1 This DPA runs for as long as Neobiz processes Member Data.

8.2 On termination, Neobiz will make Member Data available for export for thirty (30) days, then delete it within the period in the retention schedule, subject to routine backup cycles and any legal-hold or retention required by law.

8.3 Liability. Liability under this DPA is subject to the limitations in Terms §12, including the carve-out preserving your indemnification obligations. Consistent with §2.4, Controller obligations and the consequences of breaching them rest with you.

9. Audit

9.1 Neobiz will make available information necessary to demonstrate compliance.

9.2 Audits are satisfied in the first instance by Neobiz providing current third-party audit reports, penetration-test summaries and completed security questionnaires.

9.3 Where demonstrably insufficient, you may audit no more than once per year (unless required by the Authority or following a Personal Data Breach), on reasonable prior written notice, during business hours, subject to confidentiality, at your cost, and not requiring disclosure that would compromise other merchants' data or Neobiz's security.

10. Data location and transfers

10.1 Location. Member Data is hosted in Indonesia.

10.2 AI processing. Managed-AI model calls may egress to the United States (Azure East US 2) under provider agreements including zero-retention and no-training terms; such egress is logged. See the subprocessor list.

10.3 Transfer basis. Any transfer of Personal Data outside Indonesia is made only on a basis permitted by the PDP Law — an adequacy determination, an appropriate binding instrument (including standard contractual clauses issued by the Authority once available), or the consent of the Data Subject.

10.4 Reporting. Neobiz will provide the information you require to make any transfer report to the Authority.

11. Electronic system operation

11.1 Neobiz operates as a private-scope Electronic System Operator (PSE Lingkup Privat) and is completing its registration.

11.2 Neobiz will handle lawful access requests from authorities in accordance with applicable law and will notify you where permitted.

12. General

12.1 This DPA is governed by Indonesian law and incorporates the Terms' governing-law, dispute-resolution (good-faith deliberation then BANI arbitration seated in Jakarta — Terms §18), notice and order-of-precedence provisions.

12.2 In case of conflict between this DPA and the Terms regarding the processing of Member Data, this DPA controls.

13. Language

13.1 This DPA is executed in both the Indonesian and English languages in accordance with Law No. 24 of 2009, simultaneously and of equal date.

13.2 In the event of inconsistency between the two versions, the Indonesian (Bahasa Indonesia) version prevails.


Annex A — Details of processing

Item Detail
Subject matter Provision of the Neobiz platform to the Controller
Duration The term of the Terms, plus the deletion window in §8.2
Nature and purpose Hosting, storage, retrieval, organisation, transmission and deletion of Member Data to operate booking/scheduling, ordering, loyalty, CRM, messaging campaigns, payments and AI-assisted features
Categories of Data Subjects The Controller's customers and members; recipients the Controller elects to message
Categories of Personal Data Identifiers (name, phone, email); communication content and history; booking, order and transaction records; loyalty balances; consent records and provenance; device/push tokens; other data the Controller stores in member profiles or notes
Specific Personal Data Not intended — see §3.3
Recipients The Subprocessors at ../subprocessors.md
Retention Per the retention schedule and §8.2

Annex B — Security measures

Area Measure
Tenant isolation Per-TenantId scoping enforced at the data layer; control-plane and tenant databases segregated
Encryption In transit (TLS); at rest Azure Premium SSD managed disks with platform-managed encryption at rest, with OS-level disk encryption additionally enabled on the database host
Access control Role-based access; least privilege; unique operator accounts; multi-factor authentication available to all operator accounts (authenticator app + recovery codes); not currently enforced
Audit logging Operator actions logged, including consent and acceptance events
Resilience Backups per schedule; restoration procedures restore procedures tested quarterly
Vulnerability management Dependency scanning on each build; security patches reviewed and applied weekly, with critical advisories expedited
Personnel Confidentiality obligations; security and data-protection awareness training delivered as part of the SecOps programme, on onboarding and periodically thereafter
Subprocessor management Contractual flow-down; list maintained publicly
Incident response Documented process with the notification clock in §7.1

Contact for data-protection matters: hello@neobiz.id · PT Neobiz Global Technology.

© 2026 PT Neobiz Global Technology