Privacy Policy
DRAFT โ this document is pending legal review and is not yet in effect.
Last updated: 2026-07-24
Privacy Policy
Draft โ pending legal review. This policy describes how PaySwitch processes personal data under Indonesia's PDP Law (Law 27/2022) and in alignment with GDPR for EU data subjects.
1. Data processed
Transaction metadata, customer email/name (when sent by a product), IP address, and technical data. PaySwitch does not store card data (gateway hosted checkout/tokenization, PCI DSS SAQ-A).
2. Legal basis
Contract performance, legal obligation, and legitimate interest (fraud prevention). For GDPR subjects: Art. 6(1)(b), (c), (f).
3. Minimization & retention
Personal data is minimized and retained per the retention policy; afterwards data is anonymized (see retention & erasure mechanisms).
4. Data subject rights
Access, rectification, erasure, restriction, and portability. Erasure requests are honored, including deletion by email.
5. Breach notification
Impactful incidents are notified to the authority and data subjects within 3ร24 hours per the PDP Law.
6. Third-party processing
Payment gateways and sub-processors process data under the DPA; a sub-processor list is on the trust page.
7. Cross-border transfers
Transfers use adequate safeguards per the PDP Law and GDPR.
8. Contact
Privacy questions: privacy@efolusi.com. Note (ยง10): legal consultation required before go-live.