Privacy Policy
How SUMS handles account, workspace, billing, security and customer-provided data.
1. Scope and operator
This Privacy Policy applies to SUMS Executive websites, client workspaces, account administration, subscriptions, support and related services. “SUMS”, “we”, “us” and “our” refer to the operator identified in the applicable Order Form or invoice. The final legal operator identity and service address will be published before commercial Production launch.
For customer business data, the customer may act as the controller and SUMS may act as a processor or service provider depending on the data and purpose. Customers are responsible for ensuring they have lawful authority to upload and use personal data in SUMS.
2. Data we process
- Account data: name, work email, organization, role, account identifiers, authentication and MFA status.
- Workspace and business data: business/property names, operational-unit settings, imported reports, planning data, performance metrics and customer-provided content.
- Team-access data: invitations, role assignments, unit access, acceptance and removal events.
- Billing data: plan, billing cycle, order amount, payment status and provider transaction references. Payment-card credentials are entered with the payment provider and are not stored directly by SUMS.
- Security and technical data: session/authentication events, security rate-limit records, browser/device information, request metadata and operational logs where needed to protect the service.
- Communications: support requests, private-pilot requests and other messages sent to SUMS.
3. Purposes and legal bases
We process data to provide the contracted service, authenticate users, enforce workspace permissions, process payments, operate support, secure the platform, maintain backups, investigate abuse, improve reliability and meet legal obligations. Depending on context, processing may rely on contract performance, legal obligations, consent, and legitimate interests permitted by applicable law.
4. Service providers and subprocessors
SUMS uses specialist infrastructure and service providers to operate the platform. Current categories include database/authentication and storage infrastructure, CDN/security services, transactional email, source/deployment infrastructure and payment processing. Current providers include Supabase, Cloudflare, Resend and Midtrans where applicable. AI/analytics providers may be added for specific features and will be documented before customer data is sent to them.
Providers may process data in jurisdictions outside Indonesia. Where cross-border processing occurs, SUMS will apply contractual and technical safeguards required by applicable law.
5. Security
SUMS uses layered controls including tenant isolation, row-level security, server-side authorization, privileged MFA, rate limiting, encryption in transit, restricted service credentials, payment-webhook verification, audit events and encrypted backup/restore procedures. No internet service can guarantee absolute security.
6. Retention
We retain personal data only for as long as reasonably necessary for the service, security, billing, legal, tax, backup and dispute-resolution purposes. Retention may differ by data category. Backups and security logs may persist for limited additional periods before rotation or deletion.
7. Data-subject rights
Subject to applicable law, individuals may request information about their personal data, access or correction, deletion or termination of processing where applicable, withdrawal of consent where processing relies on consent, objection to certain processing, and other rights available under Indonesia’s personal-data framework. Some requests may be limited where retention or processing is required by law or necessary for security, contractual or legal claims.
8. Customer responsibilities
Customers must not upload personal data they are not authorized to process. Where customer datasets contain guest, employee, contractor or other third-party data, the customer is responsible for appropriate notices, lawful basis, minimization and instructions to SUMS.
9. Cookies and local storage
SUMS may use strictly necessary browser storage for authentication, session security, UI state and service operation. If non-essential analytics, advertising or similar tracking technologies are introduced, SUMS will provide appropriate notice and consent controls before using them where required.
10. Incidents and changes
If a personal-data incident triggers notification obligations, SUMS will act in accordance with applicable law and contractual commitments. We may update this Policy when the product, providers or legal requirements change. Material changes will receive a new policy version and, where appropriate, renewed acceptance.
11. Contact
Privacy enquiries: sumsstudio.id@gmail.com.