Overview

GDPR Compliance Documentation

GDPR Compliance Documentation

PT Divistant Teknologi Indonesia (trading as "Divistant")


Last Updated: February 24, 2026


1. Introduction and Commitment to GDPR


PT Divistant Teknologi Indonesia ("Divistant") is committed to ensuring compliance with the European Union General Data Protection Regulation (Regulation (EU) 2016/679) ("GDPR") in all aspects of our operations that involve the processing of personal data of individuals located in the European Union (EU) and European Economic Area (EEA).


This document describes how Divistant processes personal data in compliance with GDPR requirements and outlines the rights available to data subjects.


2. Data Controller Information


For the purposes of GDPR, the Data Controller is:


  1. Company: PT Divistant Teknologi Indonesia
  2. Trading Name: Divistant
  3. Address: Jakarta, Indonesia
  4. Website: divistant.com
  5. Contact: divistant.com/contacts


Where Divistant processes personal data on behalf of a Client (e.g., through our SaaS platforms or managed services), Divistant acts as a Data Processor and the Client acts as the Data Controller. In such cases, a Data Processing Agreement (DPA) governs the relationship.


3. Data Protection Officer (DPO)


Divistant has designated a Data Protection Officer responsible for overseeing GDPR compliance. You may contact our DPO for any data protection inquiries or to exercise your rights:


  1. DPO Contact: divistant.com/contacts


4. Scope


This GDPR Compliance Documentation applies to the processing of personal data of individuals (data subjects) who are located in the EU/EEA, regardless of whether the processing takes place within or outside the EU/EEA. This includes personal data collected through:

  1. Our website and online platforms
  2. IT consulting and professional services
  3. SaaS products and cloud-based platforms
  4. System integration projects
  5. Managed services
  6. Sales, marketing, and business communications


5. Lawful Bases for Processing (Article 6)


Divistant processes personal data only when there is a valid lawful basis under Article 6 of the GDPR:


  1. Consent (Art. 6(1)(a)): Where the data subject has given clear, informed, and unambiguous consent for specific processing purposes, such as receiving marketing emails or participating in surveys. Consent may be withdrawn at any time.
  2. Performance of a Contract (Art. 6(1)(b)): Where processing is necessary to perform a contract with the data subject, such as providing services, managing accounts, or processing payments.
  3. Legal Obligation (Art. 6(1)(c)): Where processing is required to comply with applicable EU or Member State laws, such as tax regulations, anti-money laundering requirements, or court orders.
  4. Legitimate Interest (Art. 6(1)(f)): Where processing is necessary for our legitimate business interests, provided these interests are not overridden by the data subject's fundamental rights and freedoms. Examples include fraud prevention, network security, and service improvement.


For processing of special categories of data (Art. 9), Divistant obtains explicit consent or relies on another specific legal basis as applicable.


6. Categories of Personal Data Processed


We process the following categories of personal data of EU/EEA data subjects:

  1. Identity Data: Name, job title, company name, professional role
  2. Contact Data: Email address, phone number, business address
  3. Technical Data: IP address, browser type, device information, cookies, login data
  4. Usage Data: Information about how you use our website and services
  5. Transaction Data: Payment and billing information related to our services
  6. Communication Data: Records of correspondence with us, support tickets, feedback


7. Purposes of Processing


Personal data of EU/EEA data subjects is processed for the following purposes:

  1. Providing and managing our IT services (consulting, SaaS, system integration, managed services)
  2. Creating and maintaining user accounts
  3. Processing transactions and billing
  4. Communicating about services, updates, and support
  5. Improving our services through analytics and user research
  6. Ensuring security and preventing fraud
  7. Complying with legal and regulatory obligations
  8. Marketing and promotional activities (with consent)


8. Recipients and Categories of Recipients


We may share personal data with the following categories of recipients:

  1. Cloud Infrastructure Providers: For hosting and computing services (with DPA in place)
  2. Payment Processors: For processing payment transactions securely
  3. Analytics Providers: For website and service analytics (anonymized/pseudonymized where possible)
  4. Communication Platforms: For email services, customer support, and messaging
  5. Professional Advisors: Legal, accounting, and compliance advisors (under professional privilege)
  6. Regulatory Authorities: When required by law or regulation


All third-party recipients are contractually obligated to process personal data in accordance with GDPR requirements.


9. International Data Transfers (Articles 44-49)


As Divistant is headquartered in Indonesia, personal data of EU/EEA data subjects is transferred outside the EEA. We ensure that such transfers are protected by appropriate safeguards as required by GDPR Chapter V:


  1. Standard Contractual Clauses (SCCs): We use EU Commission-approved SCCs (Art. 46(2)(c)) for transfers to countries without an adequacy decision.
  2. Transfer Impact Assessments: We conduct assessments to evaluate the level of data protection in the receiving country and implement supplementary measures where necessary.
  3. Adequacy Decisions: Where applicable, we rely on adequacy decisions issued by the European Commission (Art. 45).
  4. Technical Safeguards: Encryption, pseudonymization, and access controls are applied to data in transit and at rest.


10. Data Retention Periods


We retain personal data only for as long as necessary for the purposes for which it was collected. Specific retention periods include:

  1. Account Data: Duration of the account plus 12 months after closure
  2. Transaction Records: Up to 10 years (to comply with tax and commercial law requirements)
  3. Communication Records: Up to 3 years from the last interaction
  4. Technical/Usage Data: Up to 24 months from collection
  5. Consent Records: Duration of consent plus 3 years after withdrawal
  6. Marketing Data: Until consent is withdrawn or objection is raised


When the retention period expires, personal data is securely deleted or anonymized in accordance with our data retention procedures.


11. Your Rights Under GDPR


As a data subject located in the EU/EEA, you have the following rights under GDPR:


a. Right to be Informed (Articles 13-14)

You have the right to receive clear and transparent information about how we collect and use your personal data. This document, along with our Privacy Policy, fulfills this obligation.


b. Right of Access (Article 15)

You have the right to request a copy of the personal data we hold about you and information about how it is being processed. We will provide this information free of charge within 30 days of receiving your request.


c. Right to Rectification (Article 16)

You have the right to request correction of inaccurate personal data and completion of incomplete personal data.


d. Right to Erasure / Right to be Forgotten (Article 17)

You have the right to request the deletion of your personal data when it is no longer necessary for the purpose it was collected, when you withdraw consent, when you object to processing, or when data has been unlawfully processed. This right is subject to legal retention obligations.


e. Right to Restriction of Processing (Article 18)

You have the right to request restriction of processing when you contest the accuracy of data, when processing is unlawful but you prefer restriction over erasure, when we no longer need the data but you need it for legal claims, or when you have objected to processing pending verification.


f. Right to Data Portability (Article 20)

You have the right to receive your personal data in a structured, commonly used, and machine-readable format, and to transmit that data to another controller without hindrance, where processing is based on consent or contract and carried out by automated means.


g. Right to Object (Article 21)

You have the right to object to processing based on legitimate interests or for direct marketing purposes. Where you object to direct marketing, we will cease processing immediately.


h. Rights Related to Automated Decision-Making (Article 22)

You have the right not to be subject to a decision based solely on automated processing, including profiling, which produces legal effects or similarly significant effects. Divistant does not currently engage in solely automated decision-making that produces legal effects.


12. How to Exercise Your Rights


To exercise any of the rights described above, you may:

  1. Contact us at divistant.com/contacts
  2. Email our Data Protection Officer directly


When submitting a request, please provide sufficient information for us to verify your identity. We will respond to your request within 30 days. If the request is complex or we receive a large number of requests, we may extend this period by up to two additional months, in which case we will inform you of the extension and the reasons for it within the initial 30-day period.


There is no fee for exercising your rights, except where requests are manifestly unfounded or excessive, in which case a reasonable fee may be charged.


13. Right to Lodge a Complaint


If you believe that our processing of your personal data infringes GDPR, you have the right to lodge a complaint with a supervisory authority, in particular in the EU/EEA Member State of your habitual residence, your place of work, or the place of the alleged infringement.


We would, however, appreciate the opportunity to address your concerns before you approach a supervisory authority. Please contact us first at divistant.com/contacts.


14. Data Security Measures


In accordance with Article 32 of the GDPR, Divistant implements appropriate technical and organizational measures to ensure a level of security appropriate to the risk, including:

  1. Encryption: Data encryption in transit (TLS 1.2+) and at rest (AES-256)
  2. Access Controls: Role-based access, least privilege principle, multi-factor authentication
  3. Monitoring: Continuous security monitoring, intrusion detection, and logging
  4. Assessment: Regular security assessments, penetration testing, and vulnerability management
  5. Training: Regular data protection and security awareness training for all employees
  6. Vendor Management: Due diligence and ongoing assessment of third-party processors
  7. Pseudonymization: Where appropriate, data is pseudonymized to reduce risk


15. Data Breach Notification (Articles 33-34)


Divistant has established procedures for detecting, reporting, and investigating personal data breaches:


a. Notification to Supervisory Authority (Art. 33)

In the event of a personal data breach that is likely to result in a risk to the rights and freedoms of data subjects, Divistant will notify the relevant supervisory authority within 72 hours of becoming aware of the breach. The notification will include the nature of the breach, categories and approximate number of data subjects affected, contact details of the DPO, likely consequences, and measures taken or proposed.


b. Notification to Data Subjects (Art. 34)

Where a personal data breach is likely to result in a high risk to the rights and freedoms of data subjects, Divistant will communicate the breach to the affected data subjects without undue delay, describing the breach and the measures taken in clear and plain language.


c. Data Processor Obligations

Where Divistant acts as a Data Processor, we will notify the Data Controller without undue delay upon becoming aware of a personal data breach, enabling the Controller to meet its notification obligations.


16. Data Protection Impact Assessment (DPIA)


In accordance with Article 35 of the GDPR, Divistant conducts Data Protection Impact Assessments (DPIAs) before initiating processing activities that are likely to result in a high risk to data subjects' rights and freedoms. This includes:

  1. Systematic and extensive profiling with significant effects
  2. Large-scale processing of special categories of data
  3. Systematic monitoring of publicly accessible areas
  4. New technologies or innovative data processing methods


17. Changes to This Document


We may update this GDPR Compliance Documentation from time to time to reflect changes in our processing activities, applicable laws, or GDPR guidance. We will post the updated document on our website and update the "Last Updated" date. For material changes affecting your rights, we will provide advance notice.


18. Contact Information


For any questions about this GDPR Compliance Documentation, to exercise your data protection rights, or to raise a concern about our data processing practices, please contact us:


  1. Data Protection Officer: divistant.com/contacts
  2. General Inquiries: divistant.com/contacts
  3. Company: PT Divistant Teknologi Indonesia, Jakarta, Indonesia


For more information about our general data practices, please see our Privacy Policy. For information about our compliance with Indonesia's data protection law, see our UU PDP Compliance page.