LEGAL / PRIVACY
Privacy Policy
Last updated: [Last updated]
Template — review with qualified legal counsel before launch. Bracketed fields must be completed, and the content adapted to your entity and jurisdiction.
This Privacy Policy explains how Quantume collects, uses and protects personal data when you visit this website or contact us. We are committed to handling personal data in line with the EU General Data Protection Regulation (GDPR) and Indonesia's Personal Data Protection Law (Undang-Undang No. 27 Tahun 2022 / UU PDP), and, in our banking context, in alignment with applicable OJK data-protection expectations.
1. Who we are
For the purposes of this website, the data controller is [Legal Entity Name], with registered office at [Registered Address, Indonesia] and registration number [company registration / NIB]. This policy covers personal data processed through this website only. When Quantume processes data on behalf of a bank using the platform, the bank is the controller and Quantume acts as a processor under a separate agreement.
2. Information we collect
We collect personal data that you provide directly and certain data collected automatically when you use the website:
- Contact details you submit through forms or by email — such as your name, work email, organisation and message;
- Website usage and analytics data — such as pages viewed and approximate location derived from your IP address, collected only with your consent;
- Cookie and similar-technology data, as described in our Cookie Policy;
- Any other information you choose to share when you communicate with us.
3. How we use information and our legal basis
We use personal data for the following purposes, relying on the legal bases noted:
- To respond to your enquiries and provide requested information — based on your consent or our legitimate interest in answering you;
- To operate, secure and improve the website — based on our legitimate interest in running a safe and effective site;
- To measure website performance through analytics — based on your consent;
- To comply with legal obligations — where processing is required by applicable law.
4. Cookies
We use cookies and similar technologies as described in our Cookie Policy. Non-essential cookies are only set after you opt in, and you can change your choices at any time using the "Cookie settings" control in the footer.
5. Sharing and processors
We do not sell personal data. We may share it with service providers who process it on our behalf — for example hosting, email or analytics providers — under contracts that require them to protect it and use it only for the purposes we specify. We may also disclose data where required by law or competent authority.
6. International transfers
Where personal data is transferred outside Indonesia or the EU/EEA, we take steps to ensure an adequate level of protection — for example through appropriate safeguards such as standard contractual clauses — consistent with GDPR and UU PDP requirements.
7. Data retention
We keep personal data only for as long as necessary for the purposes described in this policy, or as required by applicable law, after which it is deleted or anonymised.
8. Your rights
Subject to applicable law, you have rights over your personal data, including the right to:
- Access the personal data we hold about you;
- Request correction of inaccurate or incomplete data;
- Request erasure of your data in certain circumstances;
- Restrict or object to certain processing;
- Request portability of data you have provided to us;
- Withdraw consent at any time, without affecting processing already carried out;
- Lodge a complaint with the competent supervisory authority.
9. Security
We apply technical and organisational measures designed to protect personal data against unauthorised access, loss or misuse. Further detail on our platform safeguards is set out on our Security page.
10. Children
This website is intended for a professional, business audience and is not directed at children. We do not knowingly collect personal data from children.
11. GDPR and UU PDP alignment
We process personal data in accordance with the principles of the GDPR and UU PDP — including lawfulness, fairness and transparency, purpose limitation, data minimisation, accuracy, storage limitation, integrity and confidentiality, and accountability. In the banking context, our handling is designed to align with applicable OJK data-protection requirements.
12. Contact and Data Protection Officer
For privacy questions or to exercise your rights, contact [email protected], or write to the Data Protection Officer at [Legal Entity Name], [Registered Address, Indonesia].