Privacy & Policy

Effective date: 1 January 2024

General Information Security Policy

PT Amboro Integrasi Teknologi Inovasi is committed to safeguarding information security as one of the organisation’s principal assets by operating an Information Security Management System (ISMS) based on ISO/IEC 27001:2022 and the applicable laws and regulations.

In applying it, PT Amboro Integrasi Teknologi Inovasi establishes the following principles:

1. Protection of Information

CATEGORY

Maintaining the confidentiality, integrity, and availability of the information and information assets managed by the organisation.

2. Compliance and Governance

CATEGORY

Operating the ISMS in accordance with ISO/IEC 27001:2022, the applicable laws and regulations, and the information security policies and procedures in force.

3. Management Commitment

CATEGORY

Top Management demonstrates leadership and commitment in implementing and continually developing the ISMS.

4. Awareness and Responsibility

CATEGORY

Raising information security awareness, knowledge, and skills among employees and related parties. All parties are responsible for safeguarding information assets and complying with the information security provisions in force.

5. Risk Management

CATEGORY

Identifying, assessing, and managing information security risks, taking into account the vulnerabilities and threats to the organisation’s assets and processes.

6. Security Incident Reporting

CATEGORY

Any vulnerability or threat with the potential to disrupt information security must be reported to the Chief Information Security Officer (CISO) or the ISMS Team.

7. Monitoring and Evaluation

CATEGORY

Leaders are responsible for monitoring and evaluating the effectiveness of the information security policy within their respective work units.

8. Enforcement and Continual Improvement

CATEGORY

Breaches of the information security policy may be subject to action under the provisions in force. The organisation is committed to continually improving its implementation of the ISMS.

Technical policies and procedures relating to information security are established separately, with reference to the principles set out in this policy.

Introduction

Welcome to the official website of PT Amboro Integrasi Teknologi Inovasi!

This Privacy Policy explains how we, PT Amboro Integrasi Teknologi Inovasi ("We"), collect, store, use, process, control, transfer, disclose, and/or protect your Personal Information. It applies to all users of aiti.id and any derivative sites we manage together with the content we provide (collectively, the "Website"), as well as to the services available on the Website (the "Services"), unless governed by a separate privacy policy. Please read this Privacy Policy carefully so that you understand how we process your data.

1. Personal Information We Collect

CATEGORY

We collect information that identifies and/or may be used to identify, contact, and/or locate the person and/or device related to that information ("Personal Information"). Personal Information includes, but is not limited to, full name, date of birth, gender, e-mail address, and identity details such as a national identity number and/or employee identification number (if you are a civil servant). We may collect information in various forms and for various purposes, including purposes permitted under the applicable laws and regulations.

2. How We Use the Personal Information We Collect

CATEGORY

We may use the Personal Information we collect for the purposes below, as well as for other purposes permitted by the applicable laws and regulations (the "Purposes"). In every case we will act reasonably and will not use your Personal Information beyond what those Purposes require:

  • To identify and register you as a user, and to administer, verify, deactivate, and/or manage your account.
  • To facilitate or enable any verification we consider necessary before providing services to you.
  • To communicate with you and/or send you information regarding your use of the Website.
  • To notify you of updates to the Website and/or changes to the services provided.
  • To process and/or respond to questions and suggestions we receive from you.
  • To maintain, develop, test, improve, and/or personalise the Website so that it meets your needs and preferences as a user.
  • To monitor and/or analyse user activity, behaviour, and/or demographic data, including habits and use of the various services available on the Website.
  • To carry out the related service processes and/or functions.
  • To manage and support the Website and to improve its performance efficiency, development, user experience, and/or functionality.
  • To provide assistance with and/or resolve technical difficulties and operational issues on the Website and/or the services.
  • To produce statistical information and/or analytical data for testing, research, analysis, service development, and/or collaboration.
  • To prevent, detect, and/or investigate any prohibited, illegal, unauthorised, and/or fraudulent activity.
  • To comply with all obligations under the applicable laws and regulations, including responding to regulatory requests, investigations, and/or directives, meeting archiving, reporting, and licensing requirements, and conducting audits, due diligence, and investigations.

3. Disclosure of the Personal Information We Collect

CATEGORY

We may disclose or share your Personal Information with our affiliates and other parties for the purposes below, as well as for other purposes permitted by the applicable laws and regulations:

  • Where required or authorised by the applicable laws and regulations, including responding to regulatory queries, investigations, or guidance, and/or meeting statutory archiving and reporting obligations.
  • Where instructed, requested, required, and/or permitted by the competent Government, for the purposes set out in Government policy and the applicable laws and regulations.
  • Where legal proceedings of any kind arise between you and us, or between you and another party in connection with the services, for the purposes of those proceedings.
  • In connection with any verification we and/or a third party require before providing services to you and/or registering you as a user.
  • In an emergency concerning your safety, for the purpose of handling that emergency.
  • In situations concerning your health or the public interest, we may share your Personal Information with the competent Government and/or institutions appointed by or working with us, for contact tracing, supporting Government initiatives or programmes, public health, and/or other reasonably necessary purposes.
  • We will not sell or rent your Personal Information. Where Personal Information does not need to be associated with you, we will make reasonable efforts to remove that association before disclosing or sharing it. Beyond what this Privacy Policy provides, we disclose or share your Personal Information only after notifying you and/or obtaining your consent.

4. Retention of Personal Information

CATEGORY

Your Personal Information will be retained only for as long as it is needed to fulfil the purpose of its collection, and/or for as long as that retention is required or permitted by the applicable laws and regulations. We will stop retaining Personal Information and/or remove its association with you as an individual as soon as the purpose of collection is no longer required and retention is no longer legally necessary. Please note that some of your Personal Information may be held by other parties, including certain Government institutions, in which case retention follows each institution’s own data retention policy. We are not responsible for the retention of your Personal Information carried out outside the Website.

5. Access to and Correction of Personal Information

CATEGORY

Subject to the applicable laws and regulations, you may ask us to access and/or correct the Personal Information about you that is in our possession and control by contacting us using the details below. We reserve the right to refuse a request to access or correct some or all of your Personal Information where permitted and/or required by the applicable laws and regulations. This includes circumstances where the Personal Information contains references to other people, or where we consider the request irrelevant, frivolous, and/or vexatious.

6. Where We Store Your Personal Information

CATEGORY

When you use our Website and services in another country where the Website is accessible (the "Destination Country"), we may transfer your Personal Information from your country of origin (the "Country of Origin") to the Destination Country so that you can access the Website and enjoy a seamless customer experience. In that case, we will request your consent to transfer your Personal Data from the Country of Origin to the Destination Country in order to ensure compliance with the applicable laws and regulations. We will comply with all applicable laws and regulations and/or use our best efforts to ensure a level of protection equivalent to our commitments in this Privacy Policy.

7. Security of Your Personal Information

CATEGORY

The confidentiality of your Personal Information is of the utmost importance to us. We apply our best efforts to protect and secure your data and/or Personal Information against unauthorised access, collection, use, and/or disclosure, against unlawful processing, and against accidental loss, destruction, damage, or similar risks. However, transmitting information over the internet is not entirely secure. You acknowledge that we cannot guarantee that Personal Information you send over the internet will not be intercepted, accessed, disclosed, altered, and/or destroyed by unauthorised third parties, due to factors beyond our control. You are responsible for keeping your account details confidential, including your password, and for the security of the devices you use.

8. Changes to This Privacy Policy

CATEGORY

We may review and amend this Privacy Policy at our own discretion from time to time, to keep it consistent with our future development and/or with changes in legal or regulatory requirements. If we decide to change this Privacy Policy, we will notify you through a general notice published on the Website and/or sent to the e-mail address recorded in your account. You are responsible for reviewing this Privacy Policy regularly for the latest information on our data processing and protection practices. Your continued use of the Website or our services after any change takes effect will be treated as your acceptance of this Privacy Policy and any amendments to it.

9. Acknowledgement and Consent

CATEGORY

By accepting this Privacy Policy, you acknowledge that you have read and understood it and that you agree to all of its terms:

  • You consent to us collecting, using, sharing, disclosing, storing, transferring, and/or processing your Personal Information in accordance with this Privacy Policy.
  • Where you provide us with Personal Information relating to another individual (such as your spouse, family members, friends, and/or other parties), you represent and warrant that you have obtained that individual’s consent and hereby consent on their behalf to our collection, use, disclosure, and/or processing of their Personal Information.
  • You may withdraw your consent at any time by giving us reasonable written notice using the contact details below. Depending on the nature of the consent withdrawn, you may no longer be able to use the Website and/or the services, and your account may be terminated.

10. Anonymised Data

CATEGORY

We may create, use, license, and/or disclose the Personal Information available to us, provided that:

  • All identifying elements have been removed, so that the data — whether on its own or combined with other available data — cannot be linked to or identify an individual; and
  • Similar data has been aggregated, so that the original data forms part of a larger data set.

11. Third-Party Platforms

CATEGORY

When you use our Website and enable fingerprint and/or facial recognition features on your mobile device for authentication, please note that we do not store that biometric data. Unless notified otherwise, the data is held on your mobile device and/or may be held by a third party such as your device manufacturer. You agree and acknowledge that we are not responsible for any unauthorised access to, or any loss of, the biometric data stored on your mobile device.

12. How to Contact Us

CATEGORY

If you have questions about this Privacy Policy and/or any other complaint, please contact us at info[at]aiti.id. All of your correspondence will be logged, recorded, and stored for our records.