Privacy Policy

PRIVACY POLICY

ARSA Technology

Last Updated: January 9, 2026
Effective Date: January 9, 2026


INTRODUCTION

PT Trisaka Arsa Caraka, operating as ARSA Technology (“we,” “us,” “our,” or “ARSA”), respects your privacy and is committed to protecting your personal data. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you visit our website at shop.arsa.technology and arsa.technology (collectively, the “Website”), purchase our products, or use our services.

Please read this Privacy Policy carefully. By using our Website, purchasing products, or engaging with our services, you consent to the data practices described in this policy.


1. INFORMATION WE COLLECT

We collect different types of information to provide and improve our services to you.

1.1 Personal Information You Provide

When you interact with our Website or purchase products, you may provide us with:

Account Information:

  • Name (first and last)
  • Email address
  • Phone number
  • Password (encrypted and hashed)
  • Company name (for business accounts)
  • Job title or role

Billing and Payment Information:

  • Billing address
  • Shipping address
  • Payment information (processed securely by PayPal – we do not store credit card details)
  • Tax identification number (NPWP for Indonesian customers)
  • Purchase order numbers (for corporate accounts)

Order Information:

  • Products purchased
  • Order history and transaction records
  • Delivery preferences
  • Special instructions or customization requests

Customer Support Information:

  • Support ticket communications
  • Phone call recordings (for quality and training purposes, with notice)
  • Chat transcripts
  • Product feedback and reviews
  • Warranty claim information

Business Information (for Corporate Customers):

  • Company registration documents
  • Business license numbers
  • Trade references
  • Credit application information

Technical and Professional Information:

  • Technical requirements and specifications
  • Site assessment data (for installation planning)
  • Infrastructure details (network, CCTV, etc.)
  • Use case descriptions

1.2 Information Automatically Collected

When you visit our Website, we automatically collect certain information:

Device and Browser Information:

  • IP address
  • Browser type and version
  • Operating system
  • Device type (desktop, mobile, tablet)
  • Screen resolution
  • Unique device identifiers

Website Usage Information:

  • Pages visited
  • Time spent on pages
  • Click behavior
  • Referring/exit pages
  • Date and time stamps
  • Search queries on our Website

Location Information:

  • Country, region, and city (based on IP address)
  • Time zone
  • Language preference

Cookies and Similar Technologies:

  • See Section 8 for detailed information about cookies

1.3 Information from Third Parties

We may receive information about you from third parties:

Payment Processors:

  • Payment verification status from PayPal
  • Transaction completion confirmations
  • Fraud detection indicators

Shipping Providers:

  • Delivery status updates
  • Tracking information
  • Delivery confirmations

Business Partners:

  • Referral information (if you came through a partner)
  • Co-marketing program data

Publicly Available Sources:

  • Company information for B2B verification
  • Business registration validation

1.4 Product Usage Data (Optional)

For customers who opt in, we may collect:

System Performance Data:

  • Uptime statistics
  • Error logs and diagnostic information
  • Software version and update status
  • Feature usage analytics (anonymized)

Note: ARSA AI Box products process all video and analytics data locally on your premises. We do not receive or have access to your video footage, detected faces, or analytics results. See Section 12 for details.


2. HOW WE COLLECT YOUR INFORMATION

We collect information through various methods:

2.1 Direct Collection

You provide information directly when you:

  • Create an account on our Website
  • Place an order or make a purchase
  • Fill out contact forms
  • Subscribe to newsletters or marketing communications
  • Contact customer support
  • Request a quote or consultation
  • Participate in surveys or feedback programs
  • Apply for corporate credit terms
  • Register products for warranty

2.2 Automatic Collection

Information is automatically collected through:

  • Cookies and similar tracking technologies
  • Web server logs
  • Analytics tools (Google Analytics, etc.)
  • Website interaction tracking
  • Email open and click tracking (for marketing emails)

2.3 Third-Party Collection

We receive information from:

  • PayPal (payment processing and verification)
  • Shipping carriers (delivery tracking and confirmation)
  • Email service providers (engagement metrics)
  • Advertising platforms (campaign performance)
  • Business verification services (company validation)

3. HOW WE USE YOUR INFORMATION

We use your personal information for the following purposes:

3.1 Order Processing and Fulfillment

  • Process and complete your orders
  • Arrange product delivery and installation
  • Send order confirmations and shipping notifications
  • Provide invoices and receipts
  • Handle returns, refunds, and warranty claims
  • Verify payment and prevent fraud

3.2 Customer Service and Support

  • Respond to your inquiries and requests
  • Provide technical support and troubleshooting
  • Assist with product setup and configuration
  • Process warranty claims
  • Resolve disputes or complaints
  • Improve customer service quality

3.3 Product Improvement and Development

  • Analyze product usage patterns (anonymized data)
  • Identify bugs and performance issues
  • Develop new features and products
  • Improve user experience
  • Conduct research and development
  • Test new technologies

3.4 Marketing and Communications

With Your Consent:

  • Send promotional emails and newsletters
  • Notify you about new products and services
  • Share special offers and discounts
  • Conduct customer surveys
  • Send educational content and resources
  • Invite you to events or webinars

You can opt out at any time (see Section 6.3)

3.5 Legal and Compliance

  • Comply with Indonesian laws and regulations
  • Respond to legal requests and court orders
  • Protect against fraud and unauthorized transactions
  • Enforce our Terms and Conditions
  • Maintain accounting and tax records (7-year retention required by Indonesian law)
  • Protect our legal rights and interests

3.6 Website Optimization

  • Analyze Website traffic and user behavior
  • Improve Website performance and functionality
  • Personalize your browsing experience
  • Optimize content and layout
  • A/B testing and experimentation
  • Security monitoring and threat detection

3.7 Business Operations

  • Manage business relationships
  • Process credit applications (corporate customers)
  • Maintain customer accounts
  • Generate reports and analytics
  • Strategic planning and forecasting
  • Merger and acquisition activities (if applicable)

4. HOW WE SHARE YOUR INFORMATION

We do not sell, rent, or trade your personal information to third parties.

We may share your information only in the following circumstances:

4.1 Service Providers

We share information with trusted third-party service providers who assist us in operating our business:

Payment Processing:

  • PayPal – Processes all payments securely
  • We do not store credit card information

Shipping and Logistics:

  • JNE, J&T Express, SiCepat (Indonesia)
  • DHL, FedEx, TNT Express (International)
  • Receive: Name, address, phone number for delivery

Email Communications:

  • Email service providers for transactional and marketing emails
  • Receive: Name, email address, communication preferences

Cloud Hosting and Infrastructure:

  • Amazon Web Services (AWS) or Google Cloud Platform
  • Servers located in Indonesia and Singapore
  • Subject to strict data processing agreements

Analytics and Advertising:

  • Google Analytics – Website traffic analysis (anonymized data)
  • Advertising platforms for campaign performance tracking

All service providers:

  • Bound by confidentiality agreements
  • Process data only as instructed by ARSA
  • Subject to GDPR-compliant data processing agreements
  • Required to implement appropriate security measures

4.2 Business Transfers

In the event of:

  • Merger or acquisition of ARSA Technology
  • Sale of assets or business divisions
  • Bankruptcy or insolvency proceedings

Your information may be transferred to the acquiring entity. We will:

  • Notify you 30 days in advance
  • Ensure successor is bound by this Privacy Policy
  • Give you opportunity to opt out or delete data

4.3 Legal Requirements

We may disclose your information when required by law:

To Comply With:

  • Indonesian government authorities (tax, customs, law enforcement)
  • Court orders, subpoenas, or legal processes
  • Regulatory investigations or audits
  • National security or public safety requirements

To Protect:

  • Our legal rights and property
  • Safety of our employees, customers, or public
  • Against fraud, abuse, or unauthorized access
  • Enforcement of our Terms and Conditions

4.4 With Your Consent

We may share information for other purposes with your explicit consent:

  • Customer testimonials or case studies (with your permission)
  • Partnership or integration contexts (with approval)
  • Marketing collaborations (opt-in only)
  • Industry research or publications (anonymized)

4.5 Aggregated and Anonymized Data

We may share aggregated, anonymized data that cannot identify you:

  • Industry reports and benchmarks
  • Product usage statistics
  • Market trends and insights
  • Academic or research purposes

Example: “ARSA AI Box systems collectively processed 10 million video frames this month with 99.5% average accuracy across all deployments”


5. DATA RETENTION

We retain your personal information only as long as necessary for the purposes outlined in this Privacy Policy.

5.1 Retention Periods

Active Accounts:

  • Retained as long as account is active
  • Plus 3 years after last activity (for inactive accounts)
  • 90-day notice before deletion of inactive accounts

Order and Transaction Data:

  • 7 years – Required by Indonesian tax law
  • Includes orders, invoices, payments, shipping records

Customer Support Records:

  • 5 years – Support tickets, communications, warranty claims
  • 2 years – Technical logs and diagnostics

Marketing Data:

  • Until you unsubscribe or opt out
  • Unsubscribed contacts deleted within 30 days
  • Marketing analytics anonymized after 2 years

Website Analytics:

  • 2 years – Aggregate website usage data
  • Anonymized after retention period

Security Logs:

  • 1 year – Access logs, security events
  • Extended retention for ongoing investigations

5.2 Legal Hold

Data may be retained longer if:

  • Subject to legal proceedings or investigation
  • Required by court order
  • Part of ongoing dispute or claim
  • Retained until matter is fully resolved

5.3 Data Deletion

After retention period expires:

  • Data securely deleted or anonymized
  • Backups purged within 90 days
  • Physical media destroyed per security protocols

6. YOUR PRIVACY RIGHTS

Under Indonesian Law No. 27 of 2022 on Personal Data Protection (UU PDP) and other applicable laws, you have the following rights:

6.1 Right to Access

You have the right to:

  • Request a copy of personal data we hold about you
  • Receive data in portable, machine-readable format (CSV, JSON)
  • Understand how your data is being used

How to Exercise:

  • Email: [email protected]
  • Specify: Type of data you want to access
  • We respond within 30 days

6.2 Right to Rectification

You have the right to:

  • Correct inaccurate or incomplete personal data
  • Update your information at any time

How to Exercise:

  • Log into your account and update information directly
  • Email: [email protected] for data you cannot change yourself
  • We update within 15 days

6.3 Right to Erasure (“Right to be Forgotten”)

You have the right to:

  • Request deletion of your personal data
  • Close your account permanently

When Applicable:

  • Data no longer necessary for original purpose
  • You withdraw consent (for consent-based processing)
  • Data processed unlawfully
  • Required by legal obligation

Exceptions (We Cannot Delete If):

  • Required by Indonesian law (e.g., 7-year tax record retention)
  • Needed to fulfill contractual obligations
  • Required for legal claims or defense
  • Needed for warranty support (during warranty period)

How to Exercise:

  • Email: [email protected] with “Data Deletion Request”
  • We confirm deletion within 30 days

6.4 Right to Restriction of Processing

You have the right to:

  • Limit how we process your data in certain circumstances
  • Object to specific processing activities

How to Exercise:

6.5 Right to Data Portability

You have the right to:

  • Receive your data in structured, commonly used format
  • Transfer data to another service provider

How to Exercise:

  • Email: [email protected]
  • Specify format preference (CSV, JSON, XML)
  • We provide within 30 days

6.6 Right to Object

You have the right to object to:

  • Marketing communications (opt-out anytime)
  • Automated decision-making or profiling
  • Processing based on legitimate interests

How to Exercise:

  • Marketing Emails: Click “Unsubscribe” in any email
  • Other Objections: Email [email protected]

6.7 Right to Withdraw Consent

You have the right to:

  • Withdraw consent at any time (for consent-based processing)
  • No negative consequences for withdrawal

How to Exercise:

6.8 Right to Lodge a Complaint

You have the right to:

  • File complaint with Indonesian Data Protection Authority
  • Seek legal remedies if rights violated

Indonesian Data Protection Authority:

  • Per UU PDP No. 27 of 2022

7. DATA SECURITY

We implement industry-standard security measures to protect your personal information.

7.1 Technical Safeguards

Encryption:

  • SSL/TLS encryption for all data transmission (HTTPS)
  • AES-256 encryption for data at rest
  • Encrypted database storage
  • Secure API communications

Access Controls:

  • Role-based access control (RBAC)
  • Multi-factor authentication (MFA) for employee access
  • Principle of least privilege
  • Regular access reviews and audits

Network Security:

  • Firewall protection
  • Intrusion detection and prevention systems (IDS/IPS)
  • DDoS protection
  • Virtual Private Networks (VPN) for remote access

Application Security:

  • Secure coding practices
  • Regular security code reviews
  • Vulnerability scanning and penetration testing
  • Web application firewall (WAF)

7.2 Organizational Safeguards

Employee Training:

  • Mandatory privacy and security training for all staff
  • Regular refresher courses
  • Incident response training
  • Confidentiality agreements

Access Management:

  • Limited employee access to personal data
  • Audit logs of all data access
  • Background checks for employees with data access
  • Immediate access revocation upon termination

Vendor Management:

  • Security assessments of all third-party vendors
  • Data processing agreements with strict requirements
  • Regular vendor audits
  • SOC 2 or ISO 27001 certification required for critical vendors

7.3 Physical Security

Data Center Security:

  • Servers hosted in SOC 2 compliant data centers
  • 24/7 security monitoring and surveillance
  • Biometric access controls
  • Environmental controls (fire suppression, climate control)

Office Security:

  • Secure facilities with access control
  • Visitor management systems
  • Secure disposal of physical documents (shredding)
  • Clean desk policy

7.4 Incident Response

Security Incident Management:

  • 24-hour security incident response team
  • Defined incident response procedures
  • Forensic investigation capabilities
  • Coordination with law enforcement when necessary

Data Breach Notification:

  • Within 72 hours of discovery (per UU PDP requirements)
  • Notification to affected individuals
  • Notification to Indonesian Data Protection Authority
  • Public disclosure if required by law

Incident Prevention:

  • Regular security audits and assessments
  • Continuous monitoring and alerting
  • Threat intelligence integration
  • Proactive vulnerability management

7.5 Your Responsibilities

You must also protect your information:

  • Keep your account password secure and confidential
  • Use strong, unique passwords
  • Enable two-factor authentication (if available)
  • Log out of account on shared devices
  • Do not share account credentials
  • Report suspicious activity immediately: [email protected]
  • Keep software and systems updated

We will never ask for your password via email, phone, or any other communication method.


8. COOKIES AND TRACKING TECHNOLOGIES

8.1 What Are Cookies?

Cookies are small text files placed on your device when you visit our Website. They help us provide a better user experience and understand how our Website is used.

8.2 Types of Cookies We Use

Essential Cookies (Cannot Be Disabled):

  • Session Management: Keep you logged in during your visit
  • Shopping Cart: Remember items in your cart
  • Security: Protect against fraud and unauthorized access
  • Load Balancing: Ensure Website performance

Analytics Cookies (Can Opt Out):

  • Google Analytics: Website traffic and user behavior analysis
  • Anonymized IP addresses to protect privacy
  • Help us improve Website performance and content

Preference Cookies (Can Opt Out):

  • Language Settings: Remember your preferred language
  • Currency Settings: Remember your currency preference
  • UI Preferences: Remember display preferences

Marketing Cookies (Can Opt Out):

  • Advertising Platforms: Track ad campaign effectiveness
  • Remarketing: Show relevant ads on other websites
  • Conversion Tracking: Measure marketing ROI

8.3 Third-Party Cookies

We use third-party services that may set cookies:

Google Analytics:

  • Purpose: Website analytics and reporting
  • Privacy Policy: https://policies.google.com/privacy
  • Opt-out: https://tools.google.com/dlpage/gaoptout

PayPal:

  • Purpose: Payment processing and fraud prevention
  • Privacy Policy: https://www.paypal.com/privacy
  • Required for checkout functionality

Social Media Plugins:

  • LinkedIn, Instagram, YouTube (if embedded)
  • Subject to their respective privacy policies

8.4 Managing Cookies

Browser Settings:

  • Most browsers allow you to control cookies
  • Chrome: Settings > Privacy and security > Cookies
  • Firefox: Options > Privacy & Security > Cookies
  • Safari: Preferences > Privacy > Cookies
  • Edge: Settings > Cookies and site permissions

Cookie Preference Center:

  • Manage cookie preferences on our Website: [Link to cookie settings]
  • Available in Website footer

Note: Disabling cookies may affect Website functionality (e.g., you may not be able to add items to cart or complete checkout).

8.5 Do Not Track

Our Website does not currently respond to “Do Not Track” (DNT) browser signals. You can control tracking through cookie settings and opt-out tools.


9. INTERNATIONAL DATA TRANSFERS

9.1 Data Storage Locations

Your personal information may be stored and processed in:

Primary Locations:

  • Indonesia – Primary data center and servers
  • Singapore – Backup and disaster recovery servers

Service Providers:

  • Cloud hosting providers (AWS, Google Cloud) with data centers in Asia-Pacific region
  • Email service providers with global infrastructure

9.2 Transfers Outside Indonesia

For international customers, data may be transferred to Indonesia for order processing and fulfillment.

Safeguards for International Transfers:

  • Standard Contractual Clauses (SCCs): EU-approved data transfer mechanisms
  • Adequate Safeguards: As required by GDPR and UU PDP
  • Service Provider Agreements: Binding data protection obligations

9.3 Data Protection Standards

We ensure that any international data transfer maintains the same level of protection as required by Indonesian and EU law:

  • Secure transmission protocols
  • Encryption at rest and in transit
  • Access controls and authentication
  • Regular security audits
  • Compliance with destination country regulations

9.4 Your Rights

If your data is transferred internationally:

  • You retain all privacy rights outlined in Section 6
  • You can request information about transfer safeguards
  • You can object to transfers in certain circumstances

10. CHILDREN’S PRIVACY

10.1 Age Restriction

Our Website and products are not intended for children under 13 years of age.

We do not knowingly collect personal information from children under 13. If you are under 13, do not:

  • Use our Website or services
  • Create an account
  • Make purchases
  • Provide any personal information

10.2 Parental Consent

If we learn that we have collected personal information from a child under 13 without parental consent:

  • We will delete that information immediately
  • We will close any associated account
  • We will notify parents if contact information is available

10.3 Parents and Guardians

If you believe your child has provided personal information to us:

  • Contact us immediately: [email protected]
  • Provide: Child’s name, email, and account information
  • We will verify and delete within 48 hours

11. THIRD-PARTY LINKS

11.1 External Websites

Our Website may contain links to third-party websites, including:

  • Business partners and integration providers
  • Industry resources and publications
  • Social media platforms
  • Payment processors (PayPal)

We are not responsible for:

  • Privacy practices of third-party websites
  • Content on external sites
  • Data collection by third parties
  • Security of third-party services

11.2 Your Responsibility

When you click a link to a third-party website:

  • You leave our Website
  • You are subject to that website’s privacy policy
  • We encourage you to review their privacy practices
  • We are not liable for their actions or policies

11.3 Third-Party Services

We use third-party services (PayPal, shipping carriers, etc.):

  • These services have their own privacy policies
  • You agree to their terms when using their services
  • Review their policies before providing information

12. ARSA PRODUCTS AND PRIVACY-FIRST ARCHITECTURE

12.1 Edge Computing = Maximum Privacy

ARSA AI Box products are designed with privacy by design principles:

Local Processing:

  • All video analytics processing occurs locally on-device
  • No video footage transmitted to cloud servers
  • No video footage transmitted to ARSA’s systems
  • All AI computations happen on your premises

What Stays Local:

  • CCTV camera streams and video footage
  • Face recognition embeddings and biometric data
  • Analytics results and detection data
  • Dashboard data and configurations
  • All personally identifiable information (PII)

Internet Connection:

  • Not required for core AI Box functionality
  • Optional for remote dashboard access (encrypted)
  • Used only for software updates (customer-initiated)
  • Remote support access (explicitly granted by customer)

12.2 ARSA Does Not Access

We do NOT have access to:

  • Your video streams or CCTV footage
  • Analytics data or reports generated by AI Box
  • Detected faces, people, or vehicles
  • Your dashboard or system configurations
  • Any data processed by AI Box on your premises

Optional Cloud Features:

  • Remote Dashboard Access: Encrypted connection initiated and controlled by you
  • Software Updates: Device connects to ARSA servers only to check/download updates
  • Remote Support: Access granted explicitly by you on case-by-case basis for troubleshooting

12.3 Health Kiosk Data

ARSA Self-Check Health Kiosk:

  • Health data stored locally on kiosk or your server
  • ARSA does not receive or access health measurements
  • ARSA does not access patient records or personal health information
  • Customer is the data controller for all health data
  • Compliance with health data regulations is customer’s responsibility

12.4 API Services

ARSA AI API Suites:

  • API processes data you send (images, audio, documents)
  • Processed data not stored permanently (temporary processing only)
  • API responses delivered and then purged
  • No long-term retention of customer API data
  • API keys unique and confidential (do not share)

12.5 Product Telemetry (Optional)

With Your Consent Only:

  • System performance metrics (uptime, CPU usage)
  • Error logs (anonymized, no PII)
  • Software version and update status
  • Feature usage statistics (aggregated)

You Can:

  • Opt out at any time via device settings
  • Request deletion of collected telemetry
  • Disable all telemetry transmission

13. YOUR RESPONSIBILITIES AS DATA CONTROLLER

13.1 When You Are the Data Controller

If you use ARSA products to collect or process personal data (video surveillance, health data), you are the data controller and have legal obligations:

Your Responsibilities:

  • Comply with Indonesian PDP Law (UU No. 27/2022) and other applicable laws
  • Obtain necessary consents from individuals being monitored
  • Post clear privacy notices and signage
  • Implement appropriate data security measures
  • Respond to data subject rights requests
  • Conduct Data Protection Impact Assessments (DPIA) if required
  • Appoint Data Protection Officer (DPO) if required by law

ARSA’s Role:

  • ARSA is the equipment/technology provider
  • ARSA is not the data controller for data you collect
  • You are solely responsible for lawful use of ARSA products

13.2 Video Surveillance Compliance

If using AI Box for video surveillance:

Legal Requirements:

  • Post clear, visible signage: “Area Under Video Surveillance”
  • Inform individuals about purpose and scope of monitoring
  • Limit recording to necessary areas (avoid private spaces like restrooms)
  • Secure video data with access controls and encryption
  • Retain footage only as long as necessary
  • Comply with data subject access requests (individuals can request their footage)
  • Register with Data Protection Authority if required

Best Practices:

  • Conduct privacy impact assessment before deployment
  • Document legitimate purpose for surveillance
  • Train staff on privacy and data handling
  • Regularly review and delete old footage
  • Implement audit logs for access to footage

13.3 Health Data Compliance

If using Health Kiosk:

Legal Requirements:

  • Health data is “sensitive personal data” under PDP Law
  • Obtain explicit consent from individuals before collecting health data
  • Implement strict security and access controls
  • Comply with Ministry of Health regulations
  • Ensure confidentiality of health information
  • Appoint healthcare data protection officer if required
  • Secure transmission if data sent to healthcare providers

HIPAA/GDPR Compliance (if applicable):

  • If serving international patients, additional regulations may apply
  • Consult legal counsel for cross-border health data

13.4 Resources for Compliance

ARSA Provides:

  • Privacy notice templates (available upon request)
  • Technical documentation on data flows
  • Security specifications and certifications
  • GDPR/PDP compliance guides
  • Training materials for staff

You Must Consult:

  • Legal counsel for specific compliance requirements
  • Data protection officers or consultants
  • Industry regulators (for healthcare, finance, etc.)

14. CHANGES TO THIS PRIVACY POLICY

14.1 Right to Modify

ARSA reserves the right to modify this Privacy Policy at any time to reflect:

  • Changes in Indonesian law or regulations
  • New products or services
  • Changes in data processing practices
  • Enhanced privacy or security measures
  • Industry best practices

14.2 Notification of Changes

For Minor Changes:

  • Updated policy posted on Website
  • “Last Updated” date revised at top of policy
  • No individual notification required

For Material Changes: Changes that significantly affect your rights or how we process data:

  • Prominent Website Notice: Banner on homepage for 30 days
  • Email Notification: Sent to all registered customers
  • Account Dashboard Alert: In-app notification
  • 30-Day Advance Notice: Material changes effective 30 days after notification

Material Changes Include:

  • New types of data collected
  • New purposes for data use
  • Changes to data sharing practices
  • Changes to data retention periods
  • Reductions in your privacy rights
  • Changes to international data transfers

14.3 Your Acceptance

Continued Use = Acceptance:

  • If you continue using our Website/services after changes take effect
  • You are deemed to have accepted the modified Privacy Policy

If You Don’t Accept Changes:

  • Stop using our Website and services
  • Request account deletion and data erasure
  • Contact us: [email protected]

15. CONTACT US

15.1 Data Protection Officer

For all privacy-related inquiries, concerns, or requests:

๐Ÿ“ง Email: [email protected]
๐Ÿ“ž Whatsapp: +62 851-6862-3493

Business Hours:
Monday-Friday: 09:00-17:00 WIB
Saturday: 09:00-13:00 WIB

15.2 Privacy Requests

For Privacy Rights Requests:

  • Data access, rectification, erasure
  • Data portability
  • Objection to processing
  • Consent withdrawal
  • Cookie preferences

Response Time: Within 30 days of receiving valid request

15.3 Security Incidents

For Security Concerns:
Email: [email protected]
Emergency: Use subject line “URGENT – Security Incident”

24-Hour Response for critical security matters

15.4 General Inquiries

For General Questions:
Email: [email protected]
Whatsapp: +62 851-6862-3493
Website: https://arsa.technology

15.5 Complaints

If You’re Not Satisfied:

Step 1: Contact our Data Protection Officer (above)
Step 2: Escalate to management: [email protected]
Step 3: File complaint with Indonesian Data Protection Authority

We commit to:

  • Investigate all privacy complaints thoroughly
  • Respond within 15 business days
  • Take corrective action if needed
  • Keep you informed throughout process

LEGAL COMPLIANCE

This Privacy Policy complies with:

โœ“ Indonesian Law No. 27 of 2022 on Personal Data Protection (UU PDP)
โœ“ Indonesian Law No. 11 of 2008 on Electronic Information and Transactions (UU ITE)
โœ“ Indonesian Law No. 8 of 1999 on Consumer Protection
โœ“ General Data Protection Regulation (GDPR) – for EU customers
โœ“ ISO 27001 information security standards
โœ“ Industry best practices for data protection


ACKNOWLEDGMENT

By using our Website or services, you acknowledge that:

โœ“ You have read and understood this Privacy Policy
โœ“ You consent to the collection and use of information as described
โœ“ You understand your privacy rights
โœ“ You agree to the practices outlined in this policy
โœ“ You are at least 13 years of age
โœ“ You will comply with applicable laws if you collect data using ARSA products


IMPORTANT REMINDERS

Privacy-First Philosophy:

  • ARSA products designed with privacy by design
  • Edge computing keeps your data on your premises
  • We collect only what’s necessary for service
  • You control your data and privacy settings

Your Rights Matter:

  • You have extensive rights over your personal data
  • We honor all legitimate privacy rights requests
  • Contact us anytime with privacy concerns
  • We’re committed to transparency and accountability

Data Security:

  • We invest in robust security measures
  • Your data is encrypted and protected
  • We regularly audit our security practices
  • Report any security concerns immediately

Questions? We’re Here to Help:

  • Email: [email protected]
  • Whatsapp: +62 851-6862-3493
  • We’re committed to protecting your privacy

Version: 1.0
Last Updated: January 9, 2026
Effective Date: January 9, 2026

ยฉ 2026 PT Trisaka Arsa Caraka (ARSA Technology). All rights reserved.

For the latest version of this Privacy Policy:
https://shop.arsa.technology/privacy-policy


END OF PRIVACY POLICY