Privacy Policy

DRAFT โ€” this document is pending legal review and is not yet in effect.

Last updated: 2026-07-24

Privacy Policy

Draft โ€” pending legal review. This policy describes how PaySwitch processes personal data under Indonesia's PDP Law (Law 27/2022) and in alignment with GDPR for EU data subjects.

1. Data processed

Transaction metadata, customer email/name (when sent by a product), IP address, and technical data. PaySwitch does not store card data (gateway hosted checkout/tokenization, PCI DSS SAQ-A).

2. Legal basis

Contract performance, legal obligation, and legitimate interest (fraud prevention). For GDPR subjects: Art. 6(1)(b), (c), (f).

3. Minimization & retention

Personal data is minimized and retained per the retention policy; afterwards data is anonymized (see retention & erasure mechanisms).

4. Data subject rights

Access, rectification, erasure, restriction, and portability. Erasure requests are honored, including deletion by email.

5. Breach notification

Impactful incidents are notified to the authority and data subjects within 3ร—24 hours per the PDP Law.

6. Third-party processing

Payment gateways and sub-processors process data under the DPA; a sub-processor list is on the trust page.

7. Cross-border transfers

Transfers use adequate safeguards per the PDP Law and GDPR.

8. Contact

Privacy questions: privacy@efolusi.com. Note (ยง10): legal consultation required before go-live.