1 Who we are
This Privacy Policy is issued by PT Solusi Data Diawan ("Diawan", "we", "us", "our"), a limited liability company incorporated in the Republic of Indonesia, with its principal place of business at Jl. Raya Puputan No 142, Denpasar, Bali, Indonesia.
For questions about this policy or about how we handle personal data, contact our privacy team at privacy@diawan.id.
2 Scope of this policy
This policy applies to all personal data we process across the Diawan group of websites, services and software-as-a-service ("SaaS") applications, including:
- our corporate website at diawan.id and any of its subdomains;
- our SaaS applications and internal business platforms made available at diawan.id subdomains — covering, among others, professional-services and project management, finance and billing, notifications, talent sourcing and placement, identity and single sign-on, and reporting and overview tools;
- staging, sandbox, preview and demonstration environments of any of the above;
- our marketing, sales, recruitment and support activities, including email, forms and other channels through which you contact us.
We refer to all of these collectively as the "Services". Where an individual Service has additional privacy terms — for example, terms agreed in a customer contract or a Data Processing Agreement — those additional terms apply to that Service alongside this policy, and prevail over this policy to the extent of any inconsistency.
This policy does not apply to third-party websites or services that we link to but do not operate. Their own privacy notices govern your use of them.
3 Our role: controller and processor
Depending on the situation, we act in one of two capacities under applicable data protection law.
As a data controller
We decide why and how personal data is processed when we operate our own website, market and sell our Services, manage our own accounts and contracts, recruit staff and contractors, and secure and administer our platforms. This policy describes that processing.
As a data processor
When a customer organisation uses our SaaS applications, that organisation decides what personal data it uploads and why. We process that data on the customer's instructions, under our agreement with them. In that case the customer is the controller, its own privacy notice governs the processing, and requests to access or delete data should be directed to the customer. We will support our customers in responding to such requests as required by law and by our agreement with them.
4 Personal data we collect
We collect the categories of personal data set out below. Not every category applies to every Service or every individual.
| Category | Examples |
|---|---|
| Identity and account data | Name, username, email address, password (stored only in hashed form), job title, employer or organisation, profile photo, language and locale preferences. |
| Contact data | Business email address, telephone number, postal or office address, and the content of enquiries you send us. |
| Professional and talent data | Where you apply for work or are presented as a candidate: curriculum vitae, work history, skills, certifications, portfolio links, availability, rate expectations, assessment and interview notes, and references. |
| Customer content | Records you or your organisation create in our applications, such as projects, tasks, timesheets, documents, notes, messages and attachments. These may contain personal data about you or about third parties. |
| Transaction and billing data | Billing contact details, tax identifiers such as NPWP, invoices, purchase orders, payment status and payout records. We do not store full payment card numbers; card payments are handled by our payment providers. |
| Technical and usage data | IP address, device and browser type, operating system, time zone, referring pages, pages and features viewed, timestamps, session identifiers, and diagnostic and error logs. |
| Authentication and security data | Login timestamps and outcomes, session and refresh tokens, multi-factor authentication status, audit trails of significant actions taken in our applications. |
Where the data comes from
- Directly from you — when you register, complete a form, upload content, apply for a role, or contact us.
- Automatically — when you use the Services, through server logs, cookies and similar technologies.
- From your organisation — where your employer, client or agency creates an account for you or submits your details to us.
- From third parties — identity providers used for single sign-on, payment and accounting providers, background or reference checks where you have consented, and publicly available professional sources.
Sensitive personal data
We do not seek to collect sensitive or specific personal data — such as health data, biometric data, religious belief or political opinion — and ask that you do not submit it to us unless we have specifically requested it for a lawful purpose and, where required, obtained your explicit consent.
5 How we use personal data
We use personal data for the following purposes:
- Providing the Services — creating and administering accounts, authenticating users, enabling the features you or your organisation have subscribed to, and storing and processing your content.
- Talent sourcing and placement — assessing candidates, matching them to roles and engagements, presenting candidate profiles to prospective clients, and administering placements.
- Billing and finance — issuing quotations and invoices, collecting payment, processing payouts, and maintaining accounting and tax records.
- Communication — sending transactional and service messages such as account confirmations, password resets, notifications, and notices about changes to the Services or these terms.
- Support — responding to enquiries, investigating issues and providing technical assistance.
- Security and abuse prevention — monitoring for unauthorised access, detecting and investigating fraud or misuse, maintaining audit logs, and enforcing our Terms of Service.
- Improving the Services — understanding how features are used, diagnosing faults, and developing and testing improvements. Where practicable we use aggregated or de-identified data for this purpose.
- Marketing — sending information about our Services to business contacts, where permitted by law. You can opt out at any time using the unsubscribe link in any marketing email or by writing to us.
- Legal and regulatory compliance — meeting obligations under Indonesian and other applicable law, responding to lawful requests from authorities, and establishing, exercising or defending legal claims.
Automated decision-making
We do not make decisions producing legal or similarly significant effects about you based solely on automated processing without human involvement. Where we use automated tools to help screen, rank or shortlist candidates, the output is reviewed by a person before any decision is taken.
6 Legal basis for processing
We rely on the following lawful bases, as recognised under Law No. 27 of 2022 on Personal Data Protection of the Republic of Indonesia ("UU PDP") and, where it applies to you, the EU and UK General Data Protection Regulation:
- Performance of a contract — to provide the Services to you or to the organisation you represent, and to take steps at your request before entering into a contract.
- Legitimate interests — to secure and improve the Services, prevent fraud and abuse, conduct business-to-business marketing, and manage our business, provided those interests are not overridden by your rights and interests.
- Consent — where we ask for it, for example for certain cookies, optional marketing communications, or background and reference checks. You may withdraw consent at any time, without affecting processing already carried out.
- Legal obligation — to comply with tax, accounting, employment, anti-money-laundering and other statutory requirements.
- Vital interests and public interest — in the rare circumstances where processing is necessary to protect someone's life or safety, or to carry out a task in the public interest.
7 Cookies and similar technologies
We and our providers use cookies, local storage and similar technologies to operate and improve the Services. We use them for the following purposes:
- Strictly necessary — to keep you signed in, maintain your session, balance load and protect against cross-site request forgery. The Services cannot function without these.
- Preferences — to remember choices such as language, time zone and interface settings.
- Analytics and performance — to understand aggregate usage, measure performance and diagnose errors.
You can block or delete cookies through your browser settings. If you block strictly necessary cookies, parts of the Services will not work. Where required by law, we ask for your consent before setting non-essential cookies, and you can change or withdraw that choice at any time.
8 How we share personal data
We do not sell personal data, and we do not share it for third-party advertising. We disclose personal data only in the circumstances below.
- Within your organisation — other authorised users of your organisation's account may see content and activity you create in our applications, according to the permissions your administrators configure.
- Between clients and talent — where you participate in a placement, we share the profile information necessary for the client and the candidate to evaluate and manage the engagement.
- Service providers — vendors who process data on our behalf under written contract and on our instructions, including cloud hosting and infrastructure, email delivery, error monitoring and analytics, customer support tooling, payment processing, and accounting providers.
- Professional advisers — lawyers, auditors, accountants and insurers, where necessary and subject to confidentiality.
- Corporate transactions — if we are involved in a merger, acquisition, financing or sale of assets, data may be transferred as part of that transaction, subject to the receiving party honouring commitments materially consistent with this policy.
- Legal and safety — where we are required to do so by law, court order or a valid request from a competent authority, or where disclosure is necessary to enforce our agreements, investigate suspected fraud or abuse, or protect the rights, property or safety of any person.
We require our service providers to apply appropriate confidentiality and security measures and to process personal data only as we direct.
9 International transfers
We are based in Indonesia and our primary infrastructure is operated in Indonesia. Some of our service providers operate outside Indonesia, which means personal data may be transferred to and processed in other countries whose data protection laws differ from those of your own country.
Where we transfer personal data internationally, we do so in accordance with Article 56 of UU PDP — that is, where the receiving country provides an adequate level of protection, or where adequate and binding safeguards are in place, or with your consent. For transfers subject to the GDPR we rely on adequacy decisions or Standard Contractual Clauses, together with supplementary measures where appropriate. You may request further information about these safeguards using the contact details below.
10 How long we keep data
We keep personal data only for as long as necessary for the purposes described in this policy, and then delete or irreversibly anonymise it. In determining retention periods we consider the amount and sensitivity of the data, the risk of harm from unauthorised use, the purposes for which we process it, and applicable legal requirements.
As general guidance:
- Account and customer content — for the duration of the account, and then for a limited wind-down period after closure to allow for export and dispute resolution, unless a longer period is required by law or agreed in a customer contract.
- Financial and tax records — for the period required under Indonesian accounting and tax legislation.
- Candidate and talent records — for as long as needed for the engagement and for a reasonable period afterwards to consider you for future opportunities, unless you ask us to remove them sooner.
- Security and audit logs — for a limited period appropriate to investigating security incidents.
- Marketing contact data — until you opt out or the contact becomes inactive.
Backups are retained on a rolling cycle and are overwritten in the ordinary course. Data deleted from the live Services may persist in backups for a short period before being cycled out.
11 How we protect data
We maintain technical and organisational measures designed to protect personal data against unauthorised access, alteration, disclosure, loss or destruction. These include encryption of traffic in transit using TLS, hashing of passwords, role-based access control and least-privilege administration, network and host hardening, audit logging, regular patching and backups, and confidentiality obligations for personnel and vendors.
No method of transmission or storage is completely secure, and we cannot guarantee absolute security. You are responsible for keeping your credentials confidential and for notifying us promptly if you believe your account has been compromised.
Where a personal data breach occurs that poses a risk to affected individuals, we will notify the relevant individuals and the competent authority within the timeframes required by applicable law, including the 72-hour notification requirement under UU PDP.
12 Your rights
Subject to applicable law and to verification of your identity, you have the right to:
- Be informed about the personal data we hold and how we process it;
- Access a copy of your personal data;
- Correct or update data that is inaccurate, incomplete or out of date;
- Delete your personal data where it is no longer necessary, or where processing was based on consent that you have withdrawn;
- Restrict or object to certain processing, including processing based on our legitimate interests, and to opt out of direct marketing at any time;
- Withdraw consent where processing is based on consent;
- Data portability — to receive your data in a structured, commonly used and machine-readable format, and to have it transmitted to another controller where technically feasible;
- Not be subject to a decision based solely on automated processing that produces legal or similarly significant effects;
- Claim compensation for damage caused by a breach of applicable data protection law; and
- Lodge a complaint with a supervisory authority.
To exercise any of these rights, write to privacy@diawan.id. We will respond within the period required by applicable law, and in any event without undue delay. We may ask you for information to verify your identity before acting, and we may decline a request where an exemption applies — for example where the data must be retained to comply with a legal obligation or to establish or defend a legal claim. We will explain our reasons if we do.
If your data is held in one of our applications on behalf of a customer organisation, please direct your request to that organisation. If you contact us instead, we will refer your request to them.
13 Children's privacy
Our Services are intended for businesses and for individuals aged 18 or over, and are not directed at children. We do not knowingly collect personal data from children. Where the personal data of a child is processed, it requires the verified consent of a parent or guardian in accordance with UU PDP. If you believe we hold data about a child without that consent, contact us and we will delete it promptly.
14 Changes to this policy
We may update this policy from time to time to reflect changes to our Services, our practices, or legal requirements. The "Last updated" date at the top of this page shows when the current version took effect, and superseded versions are available on request.
Where changes are material, we will provide reasonable advance notice — by email to account holders, by a notice within the Services, or both — before they take effect. Continuing to use the Services after the effective date means you accept the updated policy.
15 Contact and complaints
For any question, request or complaint about privacy, contact us at:
Jl. Raya Puputan No 142, Denpasar, Bali, Indonesia
Privacy enquiries: privacy@diawan.id
General legal: legal@diawan.id
We take complaints seriously and will work with you to resolve them. If you are not satisfied with our response, you may lodge a complaint with the competent Indonesian data protection authority, or with the supervisory authority in your country of residence or workplace where that authority has jurisdiction.
See also our Terms of Service.