By using Cloudsphere services, you agree to the data collection and use practices described in this policy. This policy applies to our website, SaaS platform, and consulting services, and is intended for data subjects in Indonesia (subject to UU PDP No. 27/2022) as well as in the European Economic Area (EEA) and the United Kingdom (subject to the GDPR / UK GDPR).
1. Information We Collect
We collect information you provide directly and information collected automatically:
Identity Information
- Full name and job title
- Company or organization name
- ID number (if relevant for agreement purposes)
Contact Information
- Business email address
- Phone number or WhatsApp
- Mailing address
Technical Information
- IP address and approximate geographic location
- Browser type and operating system
- Pages visited and session duration
- Referral source (where you accessed our website from)
Service Information
- Data you enter into our SaaS platform (compliance, risk, asset data)
- Communication history with our team
- Documents you upload in the context of an engagement
2. How We Use Your Information
The information we collect is used solely for the following purposes:
- Providing, operating, and improving Cloudsphere services in accordance with the agreed contract
- Responding to inquiries, information requests, and business communications
- Sending service updates, policy changes, and important notifications
- Analyzing platform usage patterns to improve features and user experience
- Detecting, preventing, and responding to security incidents or abuse
- Fulfilling legal and regulatory obligations applicable in Indonesia and other relevant jurisdictions
- Billing and financial administration related to services provided
We do not use your data for third-party marketing purposes or sell it to anyone.
3. Legal Basis for Processing Data
We process your personal data based on Law Number 27 of 2022 on Personal Data Protection (UU PDP) with a clear legal basis:
Consent
For processing not required by contract, we request your explicit consent in advance.
Contract Performance
Processing necessary to fulfill the service agreement between you and Cloudsphere.
Legitimate Interest
Processing necessary for our business operations, including platform security and service improvement.
Legal Obligation
Processing required by applicable laws and regulations.
For data subjects in the European Economic Area (EEA) and the United Kingdom, we process personal data under Article 6 of the GDPR, relying on the equivalent legal bases above. Where we rely on consent, you may withdraw it at any time; where we rely on legitimate interest, we have performed a balancing test to ensure your rights and freedoms are not overridden.
4. Sharing Information with Third Parties
We do not sell, rent, or trade your personal data. Information is only shared under the following conditions:
- Infrastructure Service Providers — hosting, database, email, and analytics partners (data processors) bound by data processing agreements (DPAs) and prohibited from using your data for other purposes
- Legal Obligations — if required by law, court order, or authorized regulatory authority
- Rights Protection — to protect the safety of users, platform integrity, or Cloudsphere's legal rights
- Your Consent — in any other situation, only with your explicit consent
Every third-party service provider we use is rigorously vetted and bound by data protection obligations equivalent to our standards, including a Data Processing Agreement as required by Article 28 of the GDPR.
Key Sub-Processors
We currently rely on the following key sub-processors to operate our services:
Amazon Web Services (AWS)
Cloud infrastructure, compute, and data storage
Vercel
Web application hosting and deployment
Cloudflare
CDN, DNS, and network security protection (WAF)
The current list of sub-processors and their roles is available on our Trust Center page. Material changes to this list will be communicated in accordance with Section 10.
5. International Data Transfers
Your personal data may be stored or processed on servers and service providers located outside your country of residence — including Indonesia and other jurisdictions where our infrastructure partners operate. Any such transfer is protected by one of the following mechanisms:
Standard Contractual Clauses (SCCs)
European Commission-approved contractual clauses for transfers to countries outside the EEA
Adequacy Decisions
transfers to jurisdictions recognized as providing an adequate level of data protection
Technical & Organizational Safeguards
in-transit and at-rest encryption, data minimization, and need-to-know access restrictions
Explicit Consent
in certain cases, transfers are carried out only after obtaining your consent
For data subjects in the EEA and the UK, transfers outside those regions only take place with appropriate safeguards under Chapter V of the GDPR. You may request a copy of the safeguards we apply by contacting our privacy team.
6. Data Security
As a company operating in the information security field, we apply the highest data protection standards:
Transit Encryption
TLS 1.2+ for all data communications
Storage Encryption
AES-256 for data at rest
Access Control
RBAC with least privilege principle
Authentication
MFA required for internal system access
Monitoring
Continuous security monitoring 24/7
Regular Audits
Annual penetration testing and audits
That said, no system is completely immune. In the event of a personal data breach that poses a risk to your rights, we will notify you and the competent authorities within the timeframes set out by UU PDP and the GDPR (within 72 hours of becoming aware, as required by the GDPR). If you suspect a security vulnerability, please report it to [email protected].
7. Data Retention
We retain your personal data only as long as necessary to fulfill the processing purpose or as required by applicable legal obligations:
- Active account data — retained for the duration of the business relationship and up to 12 months after it ends
- Consulting engagement data — minimum 3 years per ISO 27001 audit requirements
- Financial records and invoices — 5 years per Indonesian tax regulations
- Security logs and audit trails — minimum 1 year for incident investigation needs
After the retention period ends, data will be securely deleted or anonymized so it can no longer be linked to your identity.
8. Your Rights as a Data Subject
Under UU PDP No. 27/2022 and the GDPR, you have the following rights over your personal data:
Right of Access
Request confirmation of whether we process your data and obtain a copy of it.
Right to Rectification
Update or correct data that is inaccurate, incomplete, or outdated.
Right to Erasure
Request deletion of your data under certain conditions (right to erasure).
Right to Restriction
Limit how or for what purpose we process your data on a temporary basis.
Right to Portability
Receive your data in a structured, machine-readable format.
Right to Object
Object to data processing for specific purposes, including direct marketing.
Right to Withdraw Consent
Withdraw consent at any time without affecting the lawfulness of prior processing.
Right to Lodge a Complaint
File a complaint with the competent data protection supervisory authority (for EEA/UK users, your local Data Protection Authority).
How to submit a request:
Send your request in writing to [email protected]. We will respond within 3 x 24 hours under UU PDP and within one month under the GDPR (extendable where necessary, with notice).
10. Policy Changes
We may update this policy periodically to reflect changes in our services, technology, or regulations. For material changes, we will:
- Notify you by email to your registered address at least 30 days before the change takes effect
- Display a clear notice on our platform
- Update the “Last updated” date at the top of this document
Continued use of the service after a change takes effect constitutes acceptance of the revised policy. If you disagree with a change, you have the right to stop using the service and request deletion of your data.
11. Contact Us
For questions, data subject rights requests, or privacy concerns, please contact our Data Controller at:
PT Cloudsphere Digital Indonesia
Jl. Haji Salim, Gang Haji Musa 1 RT 006/RW 010
Cimanggis, Tugu, Kota Depok 16451
Privacy Email: [email protected]
Data Protection Officer (DPO): [email protected]
General Email: [email protected]
Response: Within 3 x 24 hours (UU PDP) / one month (GDPR) for data subject rights requests
You also have the right to lodge a complaint with the competent data protection supervisory authority in your jurisdiction if you believe your rights have not been upheld.
For specific security questions, please visit our Trust Center page.