This notice explains what personal data we process when you visit aegistech.id or contact us, why we process it, who receives it and how you can exercise your rights.
1. Who we are
PT Aegis Technology Solutions (“Aegis”, “we”) is a limited liability company established in Indonesia, Business Registration No. (NIB) 0806260073968, based in South Tangerang, Banten. We are the personal data controller (Pengendali Data Pribadi) for the processing described in this notice, except when we test a client’s systems, where we act as the client’s processor (see section 2).
This notice is issued under Law No. 27 of 2022 on Personal Data Protection (“UU PDP”) and its implementing regulation, Government Regulation No. 33 of 2026 (“PP 33/2026”). Section 11 adds information for visitors in the European Economic Area and the United Kingdom under the General Data Protection Regulation (“GDPR”).
Privacy contact: [email protected].
2. What we process and why
| Activity | Personal data | Purpose | Legal basis (UU PDP Art. 20) | Retention |
|---|---|---|---|---|
| Visiting the website | IP address, browser and device type, pages requested, referring page, date and time | Delivering the website and protecting it against attacks and abuse | Legitimate Interest | Short-term technical and security logs held by our hosting provider; we keep no separate copy |
| Website analytics | Page views, referring site, browser type, country and page performance, measured without cookies or cross-site identifiers | Understanding which pages are useful and keeping the site fast | Legitimate Interest | Aggregated statistics only; no individual profiles |
| Contacting us | Your name, email address, organisation, the content of your message and any attachments | Replying to you, scoping work and preparing a proposal | Legitimate InterestAnswering general enquiriesContractualSteps you ask us to take before an agreement, such as scoping and quoting | Up to 24 months after our last contact if no engagement follows |
| Working with us as a clientEngagement | Contact details and correspondence of your representatives | Delivering the engagement, invoicing and keeping business records | ContractualPerforming our agreement with your organisationComplianceCompany and tax record keeping | For the engagement, then as long as Indonesian company and tax record-keeping law requires |
| Working with us as a clientSecurity testing | Personal data of the client, its staff, or its own customers and users, held in or passing through the systems we are authorised to test. We do not seek it out, but may encounter it. | Carrying out the authorised test and, only where unavoidable, evidencing a finding | ContractualUnder our agreement with the client, we act as its processor (Prosesor Data Pribadi, UU PDP Art. 51); the client is the controller | Not copied out of client systems where avoidable; any evidence is masked and deleted or returned at the end of the engagement |
When we test a client’s systems. Our work does not require real personal data, and we ask clients to provide test environments and accounts populated with dummy or synthetic data wherever possible. Where real data is within scope, we access only what is needed to confirm a vulnerability, never extract records in bulk, mask personal data in our reports, and delete or return any evidence at the end of the engagement. We tell the client promptly if anything puts that data at risk. If you are a client’s customer or user and want to exercise your rights over that data, please contact the client as controller; if your request reaches us, we will pass it on.
We do not ask for specific personal data (such as health, biometric, financial or children’s data). Please do not send it to us unless we have agreed a secure way to receive it as part of an engagement.
3. What we do not do
- We do not use cookies, local storage or advertising trackers on this website.
- We do not sell, rent or trade personal data.
- We do not make decisions about you based solely on automated processing, including profiling.
4. Who receives your data
We use the following service providers to run the website and receive email:
- Cloudflare, Inc. (United States, global network): website hosting, content delivery, DNS, security filtering, email routing and privacy-focused web analytics. Cloudflare acts as our processor (Prosesor Data Pribadi) under its data processing terms.
- Google LLC (United States): the Gmail mailbox that receives messages sent to our addresses, provided under Google’s terms of service.
We may also share personal data with professional advisers under a duty of confidentiality, or with authorities where Indonesian law requires it. We never share it for anyone else’s marketing.
5. Transfers outside Indonesia
Our providers process data outside the jurisdiction of the Republic of Indonesia. In line with Article 56 of UU PDP and PP 33/2026, we transfer personal data only where the recipient country provides an equal or higher level of protection, or where adequate and binding safeguards are in place. For Cloudflare we rely on its data processing terms, which include contractual safeguards for international transfers. Email you send us is stored by Google under its terms of service; we keep only what is needed to reply and delete it in line with section 2.
6. Your rights
Under Articles 5 to 13 of UU PDP you have the right to:
- receive clear information about why and how your data is processed;
- complete, update and correct inaccurate data;
- access your data and obtain a copy;
- end the processing of your data and have it deleted or destroyed;
- withdraw consent where processing is based on consent;
- object to decisions based solely on automated processing, including profiling;
- delay or restrict processing proportionately to its purpose;
- sue and receive compensation for violations of the processing of your data; and
- obtain and use your data in a commonly used, machine-readable format, and have it sent to another controller.
To exercise a right, email [email protected]. We may ask you to verify your identity before acting. We respond within the time limits set by UU PDP and PP 33/2026. For requests to access, correct, restrict or stop processing your data, this is 3 × 24 hours from when we receive the request; if a full copy of your data will take longer to prepare, we will confirm within that time when you will receive it. There is no charge.
If you are not satisfied with our response, you may complain to the personal data protection supervisory institution established under UU PDP.
7. How we protect your data
The website is served only over encrypted connections (TLS with HSTS), its domain is signed with DNSSEC, and a strict content security policy prevents third-party code from running on our pages. Access to our accounts is restricted and protected with multi-factor authentication. If a personal data breach occurs, we will notify affected individuals and the supervisory institution in writing within 3 × 24 hours, as required by Article 46 of UU PDP.
8. Children
This website is intended for businesses and professionals. We do not knowingly collect personal data from children. If you believe a child has sent us personal data, contact us and we will delete it.
9. Links to other websites
Our pages link to other sites, such as LinkedIn. Those sites have their own privacy practices, which this notice does not cover.
10. Changes to this notice
We will update this notice when our processing changes. The date at the top shows when it was last revised. Significant changes will be highlighted on this page.
11. Visitors in the EEA and the United Kingdom (GDPR)
Our website is directed at clients in Indonesia and internationally. Where the GDPR or the UK GDPR applies to our processing of your data, the following also applies:
- Legal bases: legitimate interests (Art. 6(1)(f)) for website delivery, security, analytics and general enquiries; steps taken at your request before entering a contract, and performance of a contract (Art. 6(1)(b)) for enquiries about our services and client work; legal obligation (Art. 6(1)(c)) for record keeping. When we test a client’s systems, we act as the client’s processor under Art. 28.
- Your rights: access, rectification, erasure, restriction, data portability and objection to processing based on legitimate interests (Arts. 15 to 21), and the right not to be subject to solely automated decisions (Art. 22).
- International transfers: Cloudflare transfers data under the European Commission’s Standard Contractual Clauses and the EU–US Data Privacy Framework; Google LLC participates in the EU–US Data Privacy Framework.
- Complaints: you may lodge a complaint with the data protection supervisory authority in your country of residence or work.
12. Contact
PT Aegis Technology Solutions, South Tangerang, Banten, Indonesia. Email [email protected].
This notice is available in English and Bahasa Indonesia. If the two versions differ, the Bahasa Indonesia version prevails.