Cloudsphere

Privacy Policy

Your Privacy is Our Priority

Last updated: 25 July 2026  ·  Applies to users in Indonesia (UU PDP) as well as the European Economic Area & United Kingdom (GDPR)

By using Cloudsphere services, you agree to the data collection and use practices described in this policy. This policy applies to our website, SaaS platform, and consulting services, and is intended for data subjects in Indonesia (subject to UU PDP No. 27/2022) as well as in the European Economic Area (EEA) and the United Kingdom (subject to the GDPR / UK GDPR).

1. Information We Collect

We collect information you provide directly and information collected automatically:

Identity Information

  • Full name and job title
  • Company or organization name
  • ID number (if relevant for agreement purposes)

Contact Information

  • Business email address
  • Phone number or WhatsApp
  • Mailing address

Technical Information

  • IP address and approximate geographic location
  • Browser type and operating system
  • Pages visited and session duration
  • Referral source (where you accessed our website from)

Service Information

  • Data you enter into our SaaS platform (compliance, risk, asset data)
  • Communication history with our team
  • Documents you upload in the context of an engagement

2. How We Use Your Information

The information we collect is used solely for the following purposes:

  • Providing, operating, and improving Cloudsphere services in accordance with the agreed contract
  • Responding to inquiries, information requests, and business communications
  • Sending service updates, policy changes, and important notifications
  • Analyzing platform usage patterns to improve features and user experience
  • Detecting, preventing, and responding to security incidents or abuse
  • Fulfilling legal and regulatory obligations applicable in Indonesia and other relevant jurisdictions
  • Billing and financial administration related to services provided

We do not use your data for third-party marketing purposes or sell it to anyone.

3. Legal Basis for Processing Data

We process your personal data based on Law Number 27 of 2022 on Personal Data Protection (UU PDP) with a clear legal basis:

Consent

For processing not required by contract, we request your explicit consent in advance.

Contract Performance

Processing necessary to fulfill the service agreement between you and Cloudsphere.

Legitimate Interest

Processing necessary for our business operations, including platform security and service improvement.

Legal Obligation

Processing required by applicable laws and regulations.

For data subjects in the European Economic Area (EEA) and the United Kingdom, we process personal data under Article 6 of the GDPR, relying on the equivalent legal bases above. Where we rely on consent, you may withdraw it at any time; where we rely on legitimate interest, we have performed a balancing test to ensure your rights and freedoms are not overridden.

4. Sharing Information with Third Parties

We do not sell, rent, or trade your personal data. Information is only shared under the following conditions:

  • Infrastructure Service Providershosting, database, email, and analytics partners (data processors) bound by data processing agreements (DPAs) and prohibited from using your data for other purposes
  • Legal Obligationsif required by law, court order, or authorized regulatory authority
  • Rights Protectionto protect the safety of users, platform integrity, or Cloudsphere's legal rights
  • Your Consentin any other situation, only with your explicit consent

Every third-party service provider we use is rigorously vetted and bound by data protection obligations equivalent to our standards, including a Data Processing Agreement as required by Article 28 of the GDPR.

Key Sub-Processors

We currently rely on the following key sub-processors to operate our services:

Amazon Web Services (AWS)

Cloud infrastructure, compute, and data storage

Vercel

Web application hosting and deployment

Cloudflare

CDN, DNS, and network security protection (WAF)

The current list of sub-processors and their roles is available on our Trust Center page. Material changes to this list will be communicated in accordance with Section 10.

5. International Data Transfers

Your personal data may be stored or processed on servers and service providers located outside your country of residence — including Indonesia and other jurisdictions where our infrastructure partners operate. Any such transfer is protected by one of the following mechanisms:

Standard Contractual Clauses (SCCs)

European Commission-approved contractual clauses for transfers to countries outside the EEA

Adequacy Decisions

transfers to jurisdictions recognized as providing an adequate level of data protection

Technical & Organizational Safeguards

in-transit and at-rest encryption, data minimization, and need-to-know access restrictions

Explicit Consent

in certain cases, transfers are carried out only after obtaining your consent

For data subjects in the EEA and the UK, transfers outside those regions only take place with appropriate safeguards under Chapter V of the GDPR. You may request a copy of the safeguards we apply by contacting our privacy team.

6. Data Security

As a company operating in the information security field, we apply the highest data protection standards:

Transit Encryption

TLS 1.2+ for all data communications

Storage Encryption

AES-256 for data at rest

Access Control

RBAC with least privilege principle

Authentication

MFA required for internal system access

Monitoring

Continuous security monitoring 24/7

Regular Audits

Annual penetration testing and audits

That said, no system is completely immune. In the event of a personal data breach that poses a risk to your rights, we will notify you and the competent authorities within the timeframes set out by UU PDP and the GDPR (within 72 hours of becoming aware, as required by the GDPR). If you suspect a security vulnerability, please report it to [email protected].

7. Data Retention

We retain your personal data only as long as necessary to fulfill the processing purpose or as required by applicable legal obligations:

  • Active account dataretained for the duration of the business relationship and up to 12 months after it ends
  • Consulting engagement dataminimum 3 years per ISO 27001 audit requirements
  • Financial records and invoices5 years per Indonesian tax regulations
  • Security logs and audit trailsminimum 1 year for incident investigation needs

After the retention period ends, data will be securely deleted or anonymized so it can no longer be linked to your identity.

8. Your Rights as a Data Subject

Under UU PDP No. 27/2022 and the GDPR, you have the following rights over your personal data:

Right of Access

Request confirmation of whether we process your data and obtain a copy of it.

Right to Rectification

Update or correct data that is inaccurate, incomplete, or outdated.

Right to Erasure

Request deletion of your data under certain conditions (right to erasure).

Right to Restriction

Limit how or for what purpose we process your data on a temporary basis.

Right to Portability

Receive your data in a structured, machine-readable format.

Right to Object

Object to data processing for specific purposes, including direct marketing.

Right to Withdraw Consent

Withdraw consent at any time without affecting the lawfulness of prior processing.

Right to Lodge a Complaint

File a complaint with the competent data protection supervisory authority (for EEA/UK users, your local Data Protection Authority).

How to submit a request:

Send your request in writing to [email protected]. We will respond within 3 x 24 hours under UU PDP and within one month under the GDPR (extendable where necessary, with notice).

10. Policy Changes

We may update this policy periodically to reflect changes in our services, technology, or regulations. For material changes, we will:

  • Notify you by email to your registered address at least 30 days before the change takes effect
  • Display a clear notice on our platform
  • Update the “Last updated” date at the top of this document

Continued use of the service after a change takes effect constitutes acceptance of the revised policy. If you disagree with a change, you have the right to stop using the service and request deletion of your data.

11. Contact Us

For questions, data subject rights requests, or privacy concerns, please contact our Data Controller at:

PT Cloudsphere Digital Indonesia

Jl. Haji Salim, Gang Haji Musa 1 RT 006/RW 010

Cimanggis, Tugu, Kota Depok 16451

Privacy Email: [email protected]

Data Protection Officer (DPO): [email protected]

General Email: [email protected]

Response: Within 3 x 24 hours (UU PDP) / one month (GDPR) for data subject rights requests

You also have the right to lodge a complaint with the competent data protection supervisory authority in your jurisdiction if you believe your rights have not been upheld.

For specific security questions, please visit our Trust Center page.