neobiz Back to home →

Legal

Country
IndonesiaWorldwide
Language
EnglishBahasa Indonesia
Terms of ServicePrivacy PolicyData Processing AgreementAcceptable Use PolicyAI TermsMessaging PolicySubprocessors

Neobiz Privacy Policy — Global

Applies to: merchants registered outside Indonesia. Drafted to GDPR / UK GDPR standard, the strictest regime among the markets we serve.

Version: global-2026-07-1 · Effective date: 27 July 2026

This policy has two parts, because Neobiz holds two different roles:

  • §A — Neobiz as Controller. Data about merchants and their operators (account, billing, support, website). We decide how this is used, and this policy governs it.
  • §B — Member-facing notice base. Data about your customers/members. You are the controller; Neobiz is your processor under the DPA. §B is a template for the notice you must give your own members.

§A — Neobiz as Controller (merchants, operators, billing, website)

A1. Who we are

PT Neobiz Global Technology, Roseville SOHO and Suite Unit 06-10, Sunburst CBD BSD Lot. I.8, Jl. Kapten Soebianto Djojohadikusumo, Kelurahan Lengkong Gudang, Kecamatan Serpong, Kota Tangerang Selatan, Banten 15321, Indonesia, is the controller of the data described in this Part A. Contact: hello@neobiz.id.

A2. Data we process and why

Category Examples Purpose Lawful basis (GDPR Art. 6)
Account & identity Name, business name, email, phone, role Provide and secure the Service; authenticate operators Contract
Billing Plan, invoices, payment method token, tax IDs Take payment; comply with tax and accounting law Contract; legal obligation
Usage & telemetry Feature usage, logs, device/browser, IP Operate, secure, troubleshoot and improve the Service Legitimate interests
Support Tickets, correspondence, diagnostics Provide support Contract; legitimate interests
Audit & compliance Terms-acceptance records, operator action logs, consent-attestation records Evidence of agreement and of compliance; dispute defence Legal obligation; legitimate interests
Marketing Contact details, preferences Send product and marketing communications Consent, or legitimate interests where permitted

Where we rely on legitimate interests, we have assessed that our interest in operating, securing and improving the Service is not overridden by your rights. You may object — see §A6.

A3. Sharing and subprocessors

We share Account Data with service providers who help us run the Service (hosting, email, messaging, analytics, payment processing, AI providers, support tooling), listed at ../subprocessors.md. We also disclose where required by law, to protect rights and safety, and in connection with a merger, acquisition or sale of assets.

We do not sell or share Account Data for cross-context behavioural advertising.

A4. International transfers

Member Data is hosted in the Azure Indonesia Central region is our primary hosting region. Where we transfer personal data internationally, we rely on an adequacy decision or, where none applies, the Standard Contractual Clauses (and the UK Addendum for UK transfers), together with any additional safeguards the transfer requires. You may request a copy of the relevant mechanism at hello@neobiz.id.

A5. Retention

We keep Account Data for the term of the agreement and then for twenty-four (24) months, except where longer retention is required for tax, accounting, legal-hold or dispute purposes. Terms-acceptance and consent-attestation records are retained for the period necessary to evidence the agreement, which may outlast the account.

A6. Your rights

Subject to applicable law, you may request access, rectification, erasure, restriction, portability, and objection to processing based on legitimate interests or to direct marketing, and may withdraw consent at any time without affecting prior processing. Marketing emails carry an unsubscribe link.

To exercise these rights, contact hello@neobiz.id. We respond within the period required by applicable law (one month under GDPR, extendable where permitted). You may also complain to your local supervisory authority.

If you are in the EEA or UK, your supervisory authority is the one for your country. If you are in a US state with a privacy law, you may additionally have rights to know, delete, correct and opt out of sale/sharing and targeted advertising, and to appeal a refusal — contact us at the same address.

A7. Security

We maintain technical and organisational measures appropriate to the risk — see DPA Annex B. No system is perfectly secure; we will notify you of a breach affecting your data where required by law.

A8. Cookies and the website

We use only cookies and similar technologies that are strictly necessary to operate the Service, keep you signed in, and maintain security. We do not use advertising cookies or third-party analytics on the Service. If that changes, we will update this policy and, where required, obtain your consent first.

A9. Children

The Service is for businesses and is not directed to children. We do not knowingly collect data from children through the merchant-facing Service.

A10. Changes

We may update this policy. Material changes will be notified and, where required, we will seek fresh consent. The version and effective date appear at the top.


§B — Member-facing notice base (you are the Controller)

This part is a template for you, the merchant, to publish to your own customers. Neobiz does not publish it on your behalf. Under the DPA §3.5 you must use this base — retaining the clauses marked [CORE — required] — or an equivalent notice that meets applicable law.

Why the core clauses are locked: they are the ones that make your processing lawful and that our processor position depends on. You may add to this notice, adapt tone, and include your own branding — but removing a core clause exposes both of us.


{{MERCHANT_BUSINESS_NAME}} — Privacy Notice

[CORE — required] Who we are. {{MERCHANT_BUSINESS_NAME}}, {{MERCHANT_ADDRESS}}, is the controller of your personal data. Contact: {{MERCHANT_CONTACT}}.

[CORE — required] What we collect and why. We process your name, contact details, booking/order history, loyalty activity, and the content of messages you exchange with us, in order to provide our services, manage your bookings and orders, operate our loyalty programme, and — where you have agreed — send you marketing.

[CORE — required] Lawful basis. We rely on performance of a contract with you, our legitimate interests in operating our business, compliance with legal obligations, and — for marketing — your consent.

[CORE — required] Who we share it with. We use Neobiz as our technology provider, which processes your data on our instructions. We also use messaging providers to deliver messages, and a payment provider to take payment.

[CORE — required] Your choices. You can withdraw consent to marketing at any time — reply STOP to a message, use the unsubscribe link, or contact us. This does not affect service messages about your bookings or orders.

[CORE — required] Your rights. You may request access to, correction of, or deletion of your data, and may object to or restrict certain processing. Contact us at {{MERCHANT_CONTACT}}. You may complain to your local data protection authority.

Retention. We keep your data for {{MERCHANT_RETENTION}} unless a longer period is required by law.

International transfers. Your data may be processed outside your country by our providers, under appropriate safeguards.

Changes. We will notify you of material changes to this notice.



Contact: hello@neobiz.id · PT Neobiz Global Technology, Roseville SOHO and Suite Unit 06-10, Sunburst CBD BSD Lot. I.8, Jl. Kapten Soebianto Djojohadikusumo, Kelurahan Lengkong Gudang, Kecamatan Serpong, Kota Tangerang Selatan, Banten 15321, Indonesia.

© 2026 PT Neobiz Global Technology