Privacy Policy
This Privacy Policy explains how CV. Aksara Karya Digital collects, uses, stores, and protects your personal data. It is written to align with Indonesian Law No. 27 of 2022 on Personal Data Protection.
Table of Contents
- 1.Introduction and Scope
- 2.Personal Data You Provide to Us
- 3.Data Collected Automatically
- 4.Legal Bases for Processing
- 5.Purposes of Processing
- 6.Cookies and Tracking Technologies
- 7.Sharing Data with Third Parties
- 8.Transfers Outside Indonesia
- 9.Storage and Retention
- 10.Data Security
- 11.Your Rights as a Personal Data Subject
- 12.How to Exercise Your Rights
- 13.Children's Data and Minimum Age
- 14.Links to Third-Party Sites
- 15.Changes to This Policy
- 16.Contact Us
1.Introduction and Scope
CV. Aksara Karya Digital (business registration number / NIB 2202260001844) is a company based in Karawang, West Java, Indonesia, engaged in software, website, and application development. In this policy, we refers to CV. Aksara Karya Digital, and you refers to visitors of our site, prospective clients, clients, and any other individual whose personal data we process.
This Privacy Policy explains how we collect, use, store, share, and protect your personal data when you access our site, submit any form on it, or communicate with us through our official channels. It is drafted with reference to Indonesian Law No. 27 of 2022 on Personal Data Protection (the PDP Law) and its implementing regulations.
When we market and offer our own services, we act as a Personal Data Controller. When we build systems for clients, we generally act as a Personal Data Processor, processing data on the client's instructions. This policy does not apply to third-party sites, applications, or services that we do not control, including client systems that have been handed over and are operated entirely by the client.
2.Personal Data You Provide to Us
We obtain part of your personal data directly from you, for example when you complete our contact form, fill in a requirements survey, request a quotation, or reach us by email or WhatsApp.
We only ask for data that is genuinely needed to respond to your request. You are not obliged to complete fields that are not marked as required, although providing less information may limit our ability to follow up on your request.
- Full name or preferred name
- Email address and telephone or WhatsApp number
- Company name, job title, and industry, where you choose to provide them
- The content of your message, project requirements, indicative budget, and target timeline
- Files, links, or supporting materials you send to us
- Client contact and operational data arising during a project, including correspondence, quotation documents, and invoices
3.Data Collected Automatically
When you access our site, certain technical data is collected automatically by our server and by the analytics services we use. We need this data to keep the site functioning and secure, and to diagnose problems when they occur.
Most of this technical data is aggregated and is not used to identify you personally. Even so, IP addresses and device identifiers may qualify as personal data under the PDP Law, so we treat them in accordance with this policy.
- IP address and approximate location at city or country level
- Browser type, operating system, and device type
- Pages viewed, time of visit, session duration, and referring page
- Server log records, including status codes and errors
- Session identifiers and display preferences such as language and light or dark mode
4.Legal Bases for Processing
The PDP Law requires every act of personal data processing to rest on a lawful basis. We process your personal data only where at least one of the bases set out below applies.
Where processing relies on your consent, you may withdraw that consent at any time. Withdrawal does not affect the lawfulness of processing carried out before we received the withdrawal.
- Your valid consent, for example when you submit our contact form or requirements survey
- Performance of a contract, including pre-contractual steps taken at your request, such as preparing a quotation and delivering a project
- Compliance with our legal obligations, such as bookkeeping, tax, and corporate record-keeping requirements
- Our legitimate interests, such as securing our systems, preventing misuse, and measuring site performance, provided these do not override your rights and interests
5.Purposes of Processing
We process personal data only for the purposes we have defined and communicated to you. We do not use your personal data for unrelated purposes without first informing you and, where required, obtaining your consent.
We do not carry out solely automated decision-making that produces legal effects concerning you or similarly significantly affects you.
- Responding to enquiries, quotation requests, and consultation requests
- Preparing, issuing, and following up on quotation documents and invoices
- Carrying out development, testing, delivery, and maintenance of client systems
- Managing our commercial relationship, billing, and financial records
- Keeping the site secure, and detecting and handling disruption or misuse
- Analysing site usage in aggregate to improve our content and services
6.Cookies and Tracking Technologies
Our site uses a limited number of cookies and browser local storage entries. Some are functional and necessary for the site to work as intended, for example storing your language and display preferences and maintaining a signed-in session in restricted areas.
For visitor measurement we use Umami Analytics and Google Analytics. Umami is our primary analytics tool because it can operate without tracking cookies and without building cross-site profiles. Google Analytics, where enabled, may set cookies and process visit data on infrastructure operated by Google.
You can block or delete cookies through your browser settings, and you may use any tracking-prevention features your browser offers. Blocking functional cookies may cause parts of the site to stop working properly.
- Functional cookies for language preference, light or dark mode, and authentication sessions in restricted areas
- Umami Analytics for aggregate visit statistics without tracking cookies
- Google Analytics for visit statistics, which may use cookies and device identifiers
7.Sharing Data with Third Parties
We do not sell your personal data and we do not trade it for the marketing purposes of others. We share personal data only with the third parties we engage to operate our services, and only to the extent necessary for that purpose.
Some of these parties act as processors: they process the data on our instructions under the applicable service terms and data processing agreement, and are bound to keep it confidential. Others are third-party platforms that process data under their own terms and privacy policies as independent controllers, including for their own purposes such as measurement, security, and service development. We have no right to direct how those platforms process data, so a request concerning data held on them must be made to the platform directly; we will assist as far as we are able.
Separately, we may disclose personal data where required by law or in response to a lawful request from law enforcement authorities or the courts.
- Processors acting on our instructions — hosting and cloud infrastructure providers that run our site and database
- Processors acting on our instructions — object storage providers (S3 or equivalent) for media files and attachments
- Processors acting on our instructions — Ghost as the content management system behind our blog
- Platforms operating under their own terms — Google Analytics for site visit measurement, which also processes data for Google's own purposes
- Platforms operating under their own terms — WhatsApp (Meta) as a communication channel between you and us
- Platforms operating under their own terms — Discord as an internal notification channel for messages and requests submitted through the site
- Umami Analytics, which we operate for aggregate visit statistics without tracking cookies
- Legal counsel, accountants, or auditors where necessary and subject to confidentiality obligations
8.Transfers Outside Indonesia
Some of the service providers we use operate servers outside the territory of the Republic of Indonesia. As a result, your personal data may be stored or processed in another jurisdiction.
In line with the PDP Law provisions on cross-border transfers, we satisfy ourselves that the destination country provides a level of personal data protection equal to or higher than Indonesian law. Where that is not the case, for providers acting as processors we rely on adequate and binding safeguards through a data processing agreement with that provider. For platforms that process under their own terms, protection follows that platform's own privacy policy and data transfer commitments, and your use of such a channel is a choice you make yourself.
9.Storage and Retention
We retain personal data only for as long as it is needed to fulfil the purpose of processing, or for as long as applicable laws and regulations require.
Once that period ends, we delete the personal data or anonymise it so that it can no longer be linked to you. Backup copies containing the data may persist for a limited time until they are overwritten by the next backup cycle.
- Contact form and survey data is kept for up to 24 months from the last communication, unless it develops into a project engagement
- Client data and project documents are kept for the duration of the engagement and for up to 5 years afterwards for warranty, dispute resolution, and audit purposes
- Quotations, invoices, and financial records are kept for the periods required by tax and corporate record-keeping rules
- Server log records are kept for up to 12 months
10.Data Security
We apply technical and organisational safeguards that are reasonable and proportionate to the risk, including transmission over encrypted HTTPS connections, access restricted on a need-to-know basis, storage of credentials and access keys in encrypted or masked form, separation of development from production environments, and regular updates to software components.
Even so, no method of transmission over the internet or of electronic storage is entirely free of risk. We cannot guarantee absolute security, but we are committed to treating every indication of an incident seriously and without delay.
If a personal data protection failure occurs, we will notify you and the competent authority in writing no later than 3x24 hours after becoming aware of it, as required by the PDP Law, describing the personal data exposed, when and how the exposure occurred, and the handling and recovery measures we have taken.
11.Your Rights as a Personal Data Subject
The PDP Law grants you a number of rights over your personal data. We respect those rights and provide a clear route for exercising them.
Some rights may be excluded or limited where they relate to national defence and security, law enforcement processes, supervision of the financial services sector, or other legal obligations binding on us. If we refuse or limit your request, we will explain the reasons in writing.
- The right to information about our identity, the legal basis, the purposes, and the accountability of the processing
- The right to access and obtain a copy of the personal data we process about you
- The right to update and correct personal data that is inaccurate or incomplete
- The right to end the processing of, delete, and destroy your personal data
- The right to withdraw your consent to processing
- The right to object to certain processing, including automated decision-making
- The right to postpone or restrict processing in a proportionate manner
- The right to receive your personal data in a commonly used, machine-readable format and to transmit it to another controller where systems allow
- The right to claim and receive compensation for unlawful processing of personal data
- The right to lodge a complaint with the authority competent for personal data protection
12.How to Exercise Your Rights
You can exercise your rights by emailing aksr.kry@gmail.com with the subject line Personal Data Subject Request. Please state which right you wish to exercise and describe the data or correspondence involved so that we can locate it.
We will acknowledge receipt within 3x24 hours and complete your request within 14 working days of receiving it in full. If the request is complex or spans a large number of records, we will notify you of an extension and the reasons for it before that deadline expires.
To protect your data, we may ask for reasonable identity verification before acting on a request, for example by asking that it be sent from the same email address you used previously. There is no charge for this, unless a request is excessively repetitive or manifestly unfounded.
13.Children's Data and Minimum Age
Our services and site are intended for business purposes and are not directed at children. We assume that anyone submitting a form on our site is at least 18 years old or has been married, and we do not knowingly collect children's personal data through our site.
Under the PDP Law, processing of a child's personal data requires the consent of a parent or guardian. If you are a parent or guardian and become aware that your child has provided personal data to us without such consent, please contact us and we will delete it.
14.Links to Third-Party Sites
Our site contains links to third-party sites and services, including social media channels, WhatsApp, mapping services, and portfolio links pointing to systems owned by our clients. These links are provided for your convenience.
We do not control and are not responsible for the privacy practices or content of third-party sites. We recommend reading the privacy policy of every site you visit through those links.
15.Changes to This Policy
We may update this Privacy Policy from time to time, for example because our services change, we change a third-party provider, or the applicable regulations change.
The version in force is the one published on this page, with the effective date shown at the top of the page. We maintain an internal record of previous versions. If a change is material and affects your rights, we will give reasonable notice through the site, or by email to those whose personal data we are actively processing.
By continuing to use our site after the effective date of the latest version, you are taken to have read and understood the changes.
16.Contact Us
If you have questions, requests, or objections regarding this policy or the way we process your personal data, please contact us using the details below. We accept enquiries in Indonesian and in English.
If you consider that we have not handled your matter adequately, you have the right to lodge a complaint with the authority competent for personal data protection under the PDP Law.
- Personal Data Controller: CV. Aksara Karya Digital
- NIB: 2202260001844
- Address: Perumnas BTJ, Jl. Abimanyu VII No.150 Blok W, Sukaharja, Telukjambe Timur, Karawang, West Java 41361, Indonesia
- Email: aksr.kry@gmail.com
- WhatsApp: +62 857-7628-4849
- Website: aksarakarya.id
Ready to Join Our Success Stories?
Contact us today for a special offer and free website audit.

