Privacy Policy
This Privacy Policy explains how YPYM Company collects, uses, discloses, and safeguards personal data across our digital platforms, engineering services, and venture studio initiatives in full compliance with applicable data protection regulations.
1. Overview
YPYM Company (legally registered as PT ADI TJANDRA TEKNOLOGI, "we," "us," or "our") is committed to protecting your privacy in accordance with Law No. 27 of 2022 on Personal Data Protection ("PDP Law") and other applicable regulations. This Privacy Policy explains how we collect, use, disclose, and safeguard your personal data when you visit our website or use our development and venture studio services.
2. Definitions (Under PDP Law)
- "Personal Data" means any data relating to an identified or identifiable individual, either directly or indirectly.
- "Controller" means the party determining the purposes and means of processing personal data (us).
- "Processor" means the party processing personal data on behalf of the controller.
- "Data Subject" means the individual to whom the personal data relates (you).
3. Types of Personal Data We Collect
We may collect the following categories of personal data:
A. Automatically Collected Information
- IP address
- Browser type and version
- Operating system
- Time and duration of visits
- Pages accessed and referring sources
B. Voluntarily Provided Information
- Full name
- Email address
- Phone number
- Company name and position
- Billing and payment information
- Project requirements and communications
C. Sensitive Data
We do not intentionally collect sensitive personal data (health information, biometrics, criminal records) unless required for specific services with your explicit consent.
4. Purposes of Data Collection and Legal Basis
We process your personal data based on the following lawful grounds under PDP Law:
| Purpose | Legal Basis |
|---|---|
| To provide development and venture studio services | Contract performance |
| To communicate with you about projects | Contract performance / Legitimate interests |
| To improve our website and services | Legitimate interests |
| To comply with legal obligations | Legal compliance |
| To send marketing communications (with opt-out) | Consent |
Figure 1: Legal basis and lawful processing categories for personal data collection under the Indonesian Personal Data Protection (PDP) Law.
5. Third-Party Infrastructure and Sub-Processors
We partner with enterprise infrastructure, analytics, and technology providers under strict Data Processing Agreements (DPAs) and security standards:
| Provider / Service | Purpose & Processing Scope | Legal Basis & Data Transfers |
|---|---|---|
| Cloudflare, Inc. (Global Edge & Security) | Reverse proxy, DDoS mitigation, Web Application Firewall (WAF), bot management, and SSL/TLS termination. Processes connection logs, IP addresses, and essential security cookies. | Legitimate Interest (Security & Network Resilience) / Standard Contractual Clauses (SCCs) |
| Google LLC (Google Analytics 4 & GSC) | Aggregated site traffic analytics, Core Web Vitals measurement (with IP anonymization), and search indexing telemetry via Google Search Console. | Legitimate Interest / Consent Mode v2 / SCCs |
| Microsoft Corporation (Clarity & Bing Webmaster) | Aggregated user experience insights, heatmaps, and search discovery verification. All sensitive form fields and personal inputs are automatically masked. | Legitimate Interest / Performance Consent / SCCs |
| Ahrefs Pte. Ltd. (SEO & Bot Verification) | Technical search optimization, site audit verifications, and crawler index validation. | Legitimate Interest (Platform Health) |
| Meta Platforms, Inc. (Meta Pixel) | Measuring the reach and relevance of B2B publications and enterprise marketing initiatives (only activated upon explicit user marketing consent). | Explicit Consent (Art. 6(1)(a) GDPR / UU PDP) |
Figure 2: Enterprise infrastructure providers, operational scopes, and data transfer safeguards governing platform services.
6. Data Security
We implement administrative, technical, and physical safeguards to protect your personal data, including:
- Data encryption in transit and at rest
- Role-based access controls
- Regular security audits
- Internal staff training on data protection
7. Data Retention
We retain personal data only as long as necessary for its stated purpose and applicable legal requirements. The following schedule applies:
| Data Category | Retention Period | Legal Basis |
|---|---|---|
| Website server logs | 30, 90 days | Operational necessity |
| Security & access logs | Up to 12 months | Security / Legal obligation |
| Contact & inquiry data (no contract formed) | 12 months from last interaction | Legitimate interest |
| Client project files & communications | 5 years after project completion | Indonesian tax & commercial law |
| Invoice, payment & financial records | 10 years | Law No. 28/2007 (Tax), Indonesian commercial law |
| Marketing consent records | Until opt-out + 30 days | Consent / Legal compliance |
| Analytics data | Retained in anonymized aggregate form | Legitimate interest |
Figure 3: Statutory data retention schedule across website connection logs, operational records, and commercial enterprise files.
After the applicable period, data is securely deleted or irreversibly anonymized.
8. Your Rights as Data Subject
Under the PDP Law, you have the following rights:
- Right to access your personal data
- Right to rectify inaccurate or incomplete data
- Right to withdraw consent at any time
- Right to request deletion of your data (Right to be Forgotten)
- Right to restrict processing
- Right to data portability
- Right to object to automated decision-making
To exercise your rights, please contact us at [email protected].
9. International Data Transfers
Your data may be processed outside Indonesia (e.g., cloud servers). We ensure such transfers are protected by appropriate safeguards, such as Standard Contractual Clauses, in compliance with PDP Law.
10. Children's Data
Our Services are not intended for individuals under 18. We do not knowingly collect data from children without parental consent.
11. Changes to This Policy
We may update this Privacy Policy periodically. Changes will be posted here with an updated "Last Updated" date.
12. Contact Us and Data Protection Officer
If you have questions, concerns, or formal data subject requests regarding this Privacy Policy or our personal data handling practices, please contact our Data Protection team:
YPYM Company (PT ADI TJANDRA TEKNOLOGI)
Nomor Induk Berusaha (NIB): 1003260083966
Data Protection Officer (DPO) Email: [email protected]
Corporate Address: Indonesia Stock Exchange Tower 1 Level 3, Unit 304, Jl. Jendral Sudirman Kav. 52-53, Senayan, Kebayoran Baru, Jakarta Selatan, DKI Jakarta 12190, Indonesia
Ready to expand your organic market presence?
© 2026 YPYM Company, all rights reserved.