AlurTEN Business Solutions
ProductsGuidesSupport
English
Back to home
Draft for legal review before production

Data Processing Notice

Customer and provider roles, product scope, providers, security, incidents and exit arrangements. Input for a formal DPA, not evidence of a signed agreement or verified security controls.

Draft date
2026-09-12
Operating entity
To be confirmed before production release
Contact email
support@alur-ten.com
01

Relationship to the policy and DPA

The Privacy Policy explains individual information and rights. This notice addresses the relationship between a customer controller and service-provider processor. Customers normally determine purposes and means for business data; the operator processes on written instructions. Enquiries, orders and necessary security administration require role assessment for each actual activity; labels alone do not decide roles. Identify both legal entities and execute an appropriate Data Processing Agreement (DPA) before formal use of real business data.

02

Products, individuals and data

These are possible business processing scopes, not a statement that every feature is enabled. Each product’s order and processing schedule must define the actual scope.

  • Trade: customer, supplier and staff contact details; purchasing, sales, delivery, receivable, payable and related payment records.
  • Service: store staff, members and customers; consumption, stored value, points and service records. Health or biometric collection is not a default.
  • Project: participants, contacts, contracts, purchasing, progress and costs; site-personnel information must be limited to what is necessary.
  • HR: identity, employment, attendance, leave, payroll and payment information. Personal financial and medical records need stronger protection. Proposed GPS, biometric or other high-risk functions require separate assessment, notice and lawful grounds, not general authorisation by this notice.
03

Activities, duration and instructions

Activities may include collection, entry, storage, queries, calculation, display, authorised import/export, backup and deletion, limited to enabled features, the contract term and exit arrangements. The customer determines lawful sources, necessity, access and retention requirements. The provider must flag clearly unlawful or out-of-scope instructions and suspend relevant processing where required. Unrelated advertising, sale, cross-product profiling and general-purpose AI training are not permitted purposes. New purposes, categories or recipients are not implicitly authorised.

04

Product and tenant isolation

Products have separate registration, authentication and tenants; the same individual’s multiple registrations do not share accounts or business data. Required boundaries cover databases, files, caches, jobs, search, import/export, logs and backups, with tenant restrictions inside each product. Website enquiries only record the selected product and necessary contact information, not authority for business access. Implementation requires security acceptance; a webpage is not evidence of verified technical isolation.

05

Confidentiality, access and support

The production baseline should include least privilege, strong administrative authentication, transmission protection, key management, audit, patches and recovery tests. A security schedule must identify implemented controls. Personnel owe confidentiality. Prefer de-identified troubleshooting; access to business data requires verified customer authority, product and tenant limits, approval and activity records, and removal of temporary access afterwards. Customers manage their endpoints, internal permissions and credentials; the provider remains responsible within its control.

06

Providers, authorisation and changes

Planned providers are Alibaba Cloud infrastructure in Indonesia and Alibaba Cloud email and SMS. Contracting entities, services, purposes, data categories and locations still require confirmation. Before launch, disclose the list, obtain legally required written controller approval for further processors and impose corresponding confidentiality, security and deletion duties. Changes require advance impact disclosure and a reasonable objection and resolution mechanism; emergency replacement is not unlimited authorisation. WhatsApp is an optional external contact channel; its actual role must be assessed rather than automatically treated as our instructed subprocessor.

07

Locations and international transfers

An Indonesian server does not establish that email, SMS, remote support and backups stay in Indonesia. Before enabling processing, identify storage, access and transfer locations, assess overseas recipient protection and implement applicable safeguards. Where consent is required, obtain it separately and validly. Location changes require prior notice and necessary procedures. Selecting an international communication channel does not authorise export of all product databases.

08

Rights, risk assessment and assurance

Identify the relevant product and customer when receiving requests from employees, members or others; promptly forward and assist with access, correction, deletion, restriction and other applicable rights. Do not disclose customer data without authority unless law requires it. Assist, within the provider’s knowledge, with high-risk assessments, regulatory communications and compliance checks. The DPA must specify audit scope, frequency, costs and evidence while protecting other customers and security, without excluding statutory supervision.

09

Incident response and notification

Potential incidents involving customer personal data require immediate response, evidence protection and prompt customer notification, with staged details of data, timing, impact and remediation. Do not wait for the complete investigation. The DPA must establish internal reporting deadlines and responsibility that permit statutory compliance. Controllers notify individuals and competent institutions as required, including the applicable no-later-than-3 × 24-hour written notice under PDP Article 46. Internal agreements cannot extend legal deadlines or remove the provider’s own duties.

10

Export, exit, retention and deletion

Before contracting, agree exportable records and attachments, formats, request and verification methods, deadlines and any costs. Do not promise unavailable automatic migration. Return or delete on lawful instructions after service ends; disabling an account is not deletion. Backup rotation, legal retention and dispute evidence require limited periods and isolated access, not renewed routine use. Apply applicable deletion instructions again after restoration. Production needs a retention schedule and deletion-confirmation method; no unverified 30- or 90-day promise is made.

11

Schedules required before formal service

This notice is not a complete DPA or security certification. Confirm parties and addresses, per-product categories and instructions, specific-data conditions, retention and export schedules, providers and locations, transfer safeguards, verified controls, incident deadlines, rights assistance and audit arrangements. Contact support@alur-ten.com for data matters and sales@alur-ten.com for commercial arrangements. Unconfirmed terms are not deemed accepted through this draft.

AlurTEN Business Solutions

Clear, traceable industry SaaS for businesses in Indonesia.

Business enquiriessales@alur-ten.com
Customer supportsupport@alur-ten.com
Privacy PolicyTerms of ServiceData Processing Notice
© 2026 AlurTEN by TENetwork