Overview
GDPR Compliance Documentation
PT Divistant Teknologi Indonesia (trading as "Divistant")
Last Updated: February 24, 2026
PT Divistant Teknologi Indonesia ("Divistant") is committed to ensuring compliance with the European Union General Data Protection Regulation (Regulation (EU) 2016/679) ("GDPR") in all aspects of our operations that involve the processing of personal data of individuals located in the European Union (EU) and European Economic Area (EEA).
This document describes how Divistant processes personal data in compliance with GDPR requirements and outlines the rights available to data subjects.
For the purposes of GDPR, the Data Controller is:
Where Divistant processes personal data on behalf of a Client (e.g., through our SaaS platforms or managed services), Divistant acts as a Data Processor and the Client acts as the Data Controller. In such cases, a Data Processing Agreement (DPA) governs the relationship.
Divistant has designated a Data Protection Officer responsible for overseeing GDPR compliance. You may contact our DPO for any data protection inquiries or to exercise your rights:
This GDPR Compliance Documentation applies to the processing of personal data of individuals (data subjects) who are located in the EU/EEA, regardless of whether the processing takes place within or outside the EU/EEA. This includes personal data collected through:
Divistant processes personal data only when there is a valid lawful basis under Article 6 of the GDPR:
For processing of special categories of data (Art. 9), Divistant obtains explicit consent or relies on another specific legal basis as applicable.
We process the following categories of personal data of EU/EEA data subjects:
Personal data of EU/EEA data subjects is processed for the following purposes:
We may share personal data with the following categories of recipients:
All third-party recipients are contractually obligated to process personal data in accordance with GDPR requirements.
As Divistant is headquartered in Indonesia, personal data of EU/EEA data subjects is transferred outside the EEA. We ensure that such transfers are protected by appropriate safeguards as required by GDPR Chapter V:
We retain personal data only for as long as necessary for the purposes for which it was collected. Specific retention periods include:
When the retention period expires, personal data is securely deleted or anonymized in accordance with our data retention procedures.
As a data subject located in the EU/EEA, you have the following rights under GDPR:
a. Right to be Informed (Articles 13-14)
You have the right to receive clear and transparent information about how we collect and use your personal data. This document, along with our Privacy Policy, fulfills this obligation.
b. Right of Access (Article 15)
You have the right to request a copy of the personal data we hold about you and information about how it is being processed. We will provide this information free of charge within 30 days of receiving your request.
c. Right to Rectification (Article 16)
You have the right to request correction of inaccurate personal data and completion of incomplete personal data.
d. Right to Erasure / Right to be Forgotten (Article 17)
You have the right to request the deletion of your personal data when it is no longer necessary for the purpose it was collected, when you withdraw consent, when you object to processing, or when data has been unlawfully processed. This right is subject to legal retention obligations.
e. Right to Restriction of Processing (Article 18)
You have the right to request restriction of processing when you contest the accuracy of data, when processing is unlawful but you prefer restriction over erasure, when we no longer need the data but you need it for legal claims, or when you have objected to processing pending verification.
f. Right to Data Portability (Article 20)
You have the right to receive your personal data in a structured, commonly used, and machine-readable format, and to transmit that data to another controller without hindrance, where processing is based on consent or contract and carried out by automated means.
g. Right to Object (Article 21)
You have the right to object to processing based on legitimate interests or for direct marketing purposes. Where you object to direct marketing, we will cease processing immediately.
h. Rights Related to Automated Decision-Making (Article 22)
You have the right not to be subject to a decision based solely on automated processing, including profiling, which produces legal effects or similarly significant effects. Divistant does not currently engage in solely automated decision-making that produces legal effects.
To exercise any of the rights described above, you may:
When submitting a request, please provide sufficient information for us to verify your identity. We will respond to your request within 30 days. If the request is complex or we receive a large number of requests, we may extend this period by up to two additional months, in which case we will inform you of the extension and the reasons for it within the initial 30-day period.
There is no fee for exercising your rights, except where requests are manifestly unfounded or excessive, in which case a reasonable fee may be charged.
If you believe that our processing of your personal data infringes GDPR, you have the right to lodge a complaint with a supervisory authority, in particular in the EU/EEA Member State of your habitual residence, your place of work, or the place of the alleged infringement.
We would, however, appreciate the opportunity to address your concerns before you approach a supervisory authority. Please contact us first at divistant.com/contacts.
In accordance with Article 32 of the GDPR, Divistant implements appropriate technical and organizational measures to ensure a level of security appropriate to the risk, including:
Divistant has established procedures for detecting, reporting, and investigating personal data breaches:
a. Notification to Supervisory Authority (Art. 33)
In the event of a personal data breach that is likely to result in a risk to the rights and freedoms of data subjects, Divistant will notify the relevant supervisory authority within 72 hours of becoming aware of the breach. The notification will include the nature of the breach, categories and approximate number of data subjects affected, contact details of the DPO, likely consequences, and measures taken or proposed.
b. Notification to Data Subjects (Art. 34)
Where a personal data breach is likely to result in a high risk to the rights and freedoms of data subjects, Divistant will communicate the breach to the affected data subjects without undue delay, describing the breach and the measures taken in clear and plain language.
c. Data Processor Obligations
Where Divistant acts as a Data Processor, we will notify the Data Controller without undue delay upon becoming aware of a personal data breach, enabling the Controller to meet its notification obligations.
In accordance with Article 35 of the GDPR, Divistant conducts Data Protection Impact Assessments (DPIAs) before initiating processing activities that are likely to result in a high risk to data subjects' rights and freedoms. This includes:
We may update this GDPR Compliance Documentation from time to time to reflect changes in our processing activities, applicable laws, or GDPR guidance. We will post the updated document on our website and update the "Last Updated" date. For material changes affecting your rights, we will provide advance notice.
For any questions about this GDPR Compliance Documentation, to exercise your data protection rights, or to raise a concern about our data processing practices, please contact us:
For more information about our general data practices, please see our Privacy Policy. For information about our compliance with Indonesia's data protection law, see our UU PDP Compliance page.