Suova

Legal & governance

Privacy Policy

Learn how PT Suova Technology Indonesia collects, uses, shares, stores, and protects personal data, and understand your privacy rights when interacting with Suova.

This Privacy Policy explains how PT Suova Technology Indonesia (“Suova”, “we”, “us”, or “our”) collects, uses, shares, stores, and protects personal data when you visit our website, contact us, apply for opportunities, or otherwise interact with us.

1. About This Privacy Policy

PT Suova Technology Indonesia respects your privacy and is committed to processing personal data responsibly, transparently, securely, and in accordance with applicable data protection laws.

This Privacy Policy applies to personal data processed through suova.co.id, its localized versions and related pages, as well as through business inquiries, project discussions, partnership requests, recruitment activities, events, communications, and other direct interactions with Suova.

This Policy is primarily intended to explain how Suova processes personal data for its own corporate and business purposes.

Where Suova processes personal data on behalf of a client as part of a software project, platform, application, managed service, or other engagement, Suova may act as a data processor or service provider. In those circumstances, the relevant client agreement, data processing agreement, privacy notice, or instructions of the relevant client may apply instead.

2. Data Controller

For personal data processed by Suova for its own purposes through this website and related business activities, the responsible organization is:

PT Suova Technology Indonesia
Website: suova.co.id
Privacy contact: [email protected] (mailto:[email protected])
Phone: +62 851-3485-3769
Address: Jl. Jenderal Gatot Subroto, Times Square Paramount No. 87125, Kabupaten Tangerang, Banten 15810, Indonesia

Depending on the circumstances, Suova may act as a Personal Data Controller, Personal Data Processor, or other equivalent role recognized under applicable data protection law.

3. Personal Data We Collect

The personal data we collect depends on how you interact with Suova.

Information you provide directly

We may collect information that you voluntarily provide to us, including:

  • full name;
  • email address;
  • telephone or WhatsApp number;
  • company or organization name;
  • job title and professional information;
  • country or region;
  • business requirements;
  • project requirements and objectives;
  • estimated budget and timeline;
  • messages, inquiries, and correspondence;
  • meeting information;
  • partnership or supplier information;
  • billing and administrative information where applicable;
  • feedback or survey responses;
  • CV, résumé, portfolio, employment history, qualifications, and other recruitment information; and
  • any other information that you choose to provide.

Please avoid providing sensitive or specific-category personal data unless it is necessary for a legitimate purpose and has been requested or is otherwise appropriate for the relevant interaction.

Information collected automatically

When you access or use our website, we may automatically collect certain technical and usage information, including:

  • IP address;
  • browser type and version;
  • device type;
  • operating system;
  • language settings;
  • referring URL;
  • pages viewed;
  • date and time of access;
  • session and interaction information;
  • approximate location derived from technical information;
  • performance and diagnostic information;
  • security and anti-abuse signals;
  • cookie identifiers; and
  • information collected through cookies or similar technologies.

The exact information collected may depend on the technologies and services enabled on our website.

Information obtained from other sources

Where lawful and appropriate, we may receive professional or business-related information from other sources, including:

  • referrals;
  • existing clients;
  • business partners;
  • professional networks;
  • recruitment platforms;
  • event organizers;
  • service providers; and
  • publicly available professional or business sources.

We will process such information only for legitimate and appropriate purposes.

4. How We Use Personal Data

We may use personal data to:

  • respond to inquiries and communications;
  • understand your business or project requirements;
  • prepare proposals, quotations, scopes of work, or other commercial documents;
  • arrange meetings and consultations;
  • evaluate potential projects and business opportunities;
  • enter into and perform contracts;
  • provide, manage, support, and improve our services;
  • maintain client, vendor, and partnership relationships;
  • manage billing, accounting, taxation, and corporate administration;
  • process recruitment applications;
  • communicate regarding employment or collaboration opportunities;
  • operate, maintain, and improve our website;
  • analyze website usage and performance;
  • remember user preferences;
  • prevent spam, abuse, fraud, and security incidents;
  • detect and investigate technical or security issues;
  • protect our systems, users, personnel, clients, and business;
  • comply with applicable laws and regulatory requirements;
  • establish, exercise, or defend legal claims;
  • maintain records where required;
  • conduct business analytics and internal planning; and
  • send marketing or business communications where permitted by applicable law.

We do not use personal data for purposes that are materially incompatible with the purposes for which the information was originally collected unless permitted by law or we provide appropriate notice.

Where applicable law requires us to identify a legal basis for processing personal data, we may rely on one or more of the following:

We may process personal data where you have provided valid consent for a specific purpose.

Where processing is based on consent, you may withdraw that consent in accordance with applicable law.

Contractual necessity

We may process information where necessary to:

  • perform a contract with you;
  • manage an existing contractual relationship; or
  • take steps at your request before entering into a contract.

We may process personal data where necessary to comply with applicable legal, regulatory, accounting, taxation, employment, or other obligations.

Legitimate interests

Where permitted by applicable law, we may process personal data where necessary for legitimate business interests, including:

  • responding to business inquiries;
  • managing client relationships;
  • securing our website and systems;
  • preventing abuse and fraud;
  • improving our operations and services;
  • maintaining business records; and
  • establishing or defending legal rights.

Where we rely on legitimate interests, we consider whether those interests are appropriate and balanced against the rights and interests of affected individuals.

Other lawful bases

We may rely on another lawful basis permitted under applicable data protection legislation where appropriate.

6. Whether Providing Personal Data Is Required

In many circumstances, providing personal data is voluntary.

However, certain information may be necessary for us to:

  • respond to an inquiry;
  • evaluate a project;
  • prepare a proposal;
  • establish or perform a contract;
  • process a recruitment application;
  • meet legal or regulatory requirements; or
  • provide a requested service.

Where information is mandatory, this will generally be indicated in the relevant form, agreement, or communication.

If required information is not provided, we may be unable to process your request or provide the relevant service.

7. Cookies and Similar Technologies

We may use cookies and similar technologies for website functionality, security, preference management, analytics, performance measurement, and, where enabled, marketing purposes.

Strictly necessary technologies may be used to operate and secure the website.

Where applicable law requires consent, optional analytics, advertising, or other non-essential technologies will be activated only after appropriate consent has been obtained.

More information about these technologies and your choices is available in our Cookie Policy.

8. Marketing Communications

Where permitted by applicable law, we may use your business contact information to communicate with you regarding:

  • Suova services;
  • relevant business opportunities;
  • events;
  • insights;
  • company updates; or
  • other professional communications.

Where consent is required, we will obtain the appropriate consent before sending such communications.

You may unsubscribe or object to marketing communications at any time through an available unsubscribe mechanism or by contacting us.

Operational, contractual, security, legal, or service-related communications may still be sent where necessary even if you opt out of marketing communications.

9. How We Share Personal Data

We do not sell personal data.

We may disclose personal data where reasonably necessary to:

  • hosting and cloud infrastructure providers;
  • website and content management providers;
  • email and communication providers;
  • analytics providers;
  • cybersecurity and anti-abuse providers;
  • software and business system providers;
  • payment or financial service providers where applicable;
  • recruitment service providers;
  • professional advisers;
  • lawyers;
  • auditors;
  • accountants;
  • insurers;
  • clients or business partners where relevant to an authorized engagement;
  • government authorities;
  • regulators;
  • courts; or
  • law enforcement authorities where legally required.

We may also disclose information in connection with a corporate restructuring, merger, acquisition, financing, investment, sale of assets, or similar transaction, subject to appropriate confidentiality and legal safeguards.

Service providers that process personal data on our behalf are expected to process it only for authorized purposes and in accordance with appropriate confidentiality, security, and contractual obligations.

10. International Data Transfers

Suova is based in Indonesia, but some technology, infrastructure, communication, analytics, or other service providers we use may process information in other countries or regions.

As a result, personal data may be transferred to or processed outside the country where it was originally collected.

Where applicable law requires safeguards for international transfers, we will take reasonable measures to use an appropriate transfer mechanism and level of protection.

For transfers governed by Indonesian data protection requirements, we will apply the safeguards required by applicable Indonesian law.

Where the General Data Protection Regulation (“GDPR”) applies, appropriate safeguards may include an adequacy decision, Standard Contractual Clauses, or another legally recognized transfer mechanism.

11. Data Retention

We retain personal data only for as long as reasonably necessary for the purposes for which it was collected and as required or permitted by applicable law.

Retention periods may depend on:

  • the nature of the information;
  • the purpose of processing;
  • the duration of a client or business relationship;
  • contractual requirements;
  • recruitment requirements;
  • legal and regulatory obligations;
  • accounting and taxation requirements;
  • security and fraud prevention needs;
  • applicable limitation periods; and
  • the need to establish, exercise, or defend legal claims.

For example, project inquiry information may be retained for a reasonable period to manage follow-up communications and potential business relationships.

Information associated with an active client relationship may be retained for the duration of the relationship and for an appropriate period afterward where required for contractual, accounting, legal, or compliance purposes.

Recruitment information may be retained for the relevant recruitment process and, where permitted, for a reasonable period for future opportunities.

When personal data is no longer required, we will take reasonable steps to delete, destroy, anonymize, or otherwise securely dispose of it.

12. How We Protect Personal Data

We use reasonable technical and organizational measures designed to protect personal data against:

  • unauthorized access;
  • unlawful processing;
  • accidental loss;
  • unauthorized disclosure;
  • misuse;
  • alteration;
  • destruction; and
  • other security risks.

Depending on the nature of the processing, these measures may include:

  • access controls;
  • authentication measures;
  • secure communications;
  • encryption where appropriate;
  • network and infrastructure security;
  • security monitoring;
  • access restrictions;
  • backups;
  • logging;
  • software updates;
  • anti-abuse mechanisms;
  • confidentiality requirements; and
  • internal security procedures.

No website, transmission method, or storage system can be guaranteed to be completely secure. We therefore cannot guarantee absolute security, but we continuously seek to apply protections appropriate to the nature and risks of the processing.

13. Personal Data Breaches

If we become aware of a personal data breach, we will assess the nature, scope, and potential impact of the incident.

Where required by applicable law, we will take appropriate measures which may include:

  • containing the incident;
  • investigating its cause;
  • mitigating potential harm;
  • documenting the incident;
  • notifying affected individuals; and
  • notifying the competent authority.

Notifications will be provided within the timeframe and in the manner required by applicable law.

14. Your Privacy Rights

Depending on applicable law and the circumstances of the processing, you may have rights relating to your personal data.

These may include the right to:

  • obtain information about how your personal data is processed;
  • request access to your personal data;
  • obtain a copy of your personal data;
  • request correction or completion of inaccurate or incomplete information;
  • request deletion or destruction of personal data;
  • withdraw consent where processing is based on consent;
  • request restriction or suspension of certain processing;
  • object to certain processing;
  • object to certain solely automated decisions;
  • request data portability where applicable;
  • submit complaints to an appropriate authority; and
  • exercise other rights provided by applicable law.

Certain rights may be subject to legal conditions, limitations, exemptions, identity verification requirements, or competing legal obligations.

We will not unlawfully discriminate against you because you exercise your privacy rights.

15. Rights Under Indonesian Personal Data Protection Law

Where Indonesia's personal data protection legislation applies, data subjects may exercise rights provided under applicable Indonesian law, including rights concerning:

  • transparency regarding the identity and accountability of the data controller;
  • information regarding the purpose and legal basis of processing;
  • correction and updating of personal data;
  • access to personal data;
  • obtaining copies of personal data;
  • deletion or destruction of personal data in applicable circumstances;
  • withdrawal of consent;
  • objection to certain automated decision-making;
  • restriction or suspension of processing;
  • portability of personal data where applicable; and
  • remedies available under applicable law.

Requests may be subject to conditions and exceptions established by applicable legislation.

16. Rights Under the GDPR

If the GDPR applies to our processing of your personal data, you may, subject to applicable conditions and exceptions, have rights including:

  • the right of access;
  • the right to rectification;
  • the right to erasure;
  • the right to restriction of processing;
  • the right to data portability;
  • the right to object;
  • the right to withdraw consent;
  • rights relating to certain automated decision-making; and
  • the right to lodge a complaint with a competent supervisory authority.

The GDPR does not necessarily apply to every interaction with Suova. These rights apply only where the relevant legal requirements are met.

17. Exercising Your Rights

To exercise a privacy right or submit a privacy-related request, contact us at:

[email protected] (mailto:[email protected])

We may need to verify your identity before completing a request in order to protect personal data from unauthorized access or disclosure.

Depending on the request, we may ask for information reasonably necessary to:

  • confirm your identity;
  • locate the relevant personal data;
  • understand your request; or
  • establish your authority to act on behalf of another individual.

We will respond within the timeframe required by applicable law.

Where we are legally permitted to refuse or limit a request, we will provide appropriate information regarding that decision where required.

18. Automated Decision-Making and Profiling

Suova does not generally use personal data collected through its corporate website to make decisions based solely on automated processing that produce legal effects or similarly significant effects on individuals.

If this practice changes and applicable law requires additional transparency, consent, or safeguards, we will provide appropriate information and protections.

We may use automated tools for purposes such as security monitoring, spam prevention, analytics, or website performance without using them to make legally significant decisions about individuals.

19. Recruitment

If you apply for employment, internship, freelance, contractor, or other professional opportunities with Suova, we may process information such as:

  • your name and contact details;
  • CV or résumé;
  • portfolio;
  • employment history;
  • education;
  • qualifications;
  • skills;
  • expected compensation where relevant;
  • interview notes;
  • professional references where appropriate; and
  • other information submitted during the recruitment process.

We use this information to:

  • evaluate applications;
  • communicate with candidates;
  • conduct interviews and assessments;
  • verify relevant information where lawful;
  • make recruitment decisions; and
  • comply with employment-related obligations.

Where appropriate and legally permitted, we may retain candidate information for consideration for future opportunities.

20. Client and Project Data

During software development, consulting, implementation, maintenance, or other client engagements, Suova may receive access to personal data contained within a client's systems, applications, databases, test environments, or project materials.

In such circumstances, responsibility for determining the purposes and means of processing may remain with the relevant client, and Suova may process information only according to:

  • the client's documented instructions;
  • applicable agreements;
  • data processing terms; and
  • applicable law.

This Privacy Policy does not replace a client-specific privacy notice or data processing agreement where one is required.

21. Sensitive Personal Data

We generally do not seek to collect sensitive or specific-category personal data through our corporate website unless it is necessary for an appropriate and lawful purpose.

Please do not voluntarily submit information such as health data, biometric data, financial credentials, government identification numbers, criminal records, or other sensitive information unless it is specifically necessary and appropriate for the relevant interaction.

Where sensitive personal data must be processed, we will apply additional safeguards where required by applicable law.

22. Children's Privacy

Our corporate website and professional technology services are primarily intended for businesses, organizations, professionals, and individuals seeking technology-related services.

They are not primarily directed toward children.

We do not knowingly seek to collect personal data from children through our corporate website for marketing or profiling purposes.

Where we become aware that children's personal data has been processed in circumstances requiring consent or authorization from a parent or legal guardian, we will take appropriate steps in accordance with applicable law.

23. Third-Party Websites and Services

Our website may contain links to, integrations with, or content provided by third-party websites and services.

Suova does not control the privacy practices of independent third parties.

Information you provide directly to a third party is generally governed by that third party's privacy policy and terms.

We encourage you to review the relevant privacy policies before providing personal data to third-party services.

24. Social Media and External Platforms

If you interact with Suova through social media, messaging platforms, professional networks, marketplaces, or other external platforms, both Suova and the relevant platform may process information relating to your interaction.

The relevant third party's processing is governed by its own privacy policies and terms.

We recommend reviewing the privacy settings and policies of any external platform you use.

25. Data Protection Officer and Representatives

Suova will appoint a data protection officer, privacy function, representative, or equivalent role where required by applicable law.

If Suova becomes legally required to appoint a Data Protection Officer or designate a representative in another jurisdiction, the relevant contact information will be published through this Privacy Policy or another appropriate notice.

Privacy inquiries may currently be directed to:

[email protected] (mailto:[email protected])

26. Changes to This Privacy Policy

We may update this Privacy Policy from time to time to reflect changes in:

  • our services;
  • business practices;
  • website functionality;
  • technologies;
  • service providers;
  • security practices; or
  • applicable legal and regulatory requirements.

When we make material changes, we will update the “Last updated” date at the top of this Policy and may provide additional notice where appropriate.

We encourage you to review this Privacy Policy periodically.

27. Contact Us and Complaints

If you have questions, concerns, complaints, or requests regarding this Privacy Policy or our processing of personal data, please contact:

PT Suova Technology Indonesia
Email: [email protected]
Website: suova.co.id
Phone: +62 851-3485-3769
Address: Jl. Jenderal Gatot Subroto, Times Square Paramount No. 87125, Kabupaten Tangerang, Banten 15810, Indonesia

Where applicable, you may also have the right to submit a complaint to the competent personal data protection, supervisory, regulatory, or other authorized government authority.