IID CloudIID Cloud
/
← Back to home Chapter A — Privacy

Privacy Policy

Kebijakan Privasi

Effective from · 2026-08-24 PT. Indonesia SCM Industrial

This document is a draft and must be reviewed by legal counsel before publication.

1. Who we are

PT. Indonesia SCM Industrial, trading as IID Cloud (“we”, “us”, “our”), operates the GPU rental cloud at iidevcloud.com. For personal data processed through this website and through our commercial relationship with you, we act as the data controller.

Email: kei_hu@iidevcloud.com

2. Scope of this policy

This policy explains how we collect, use, share, retain and protect personal data, and what rights you have. It is written against Law of the Republic of Indonesia No. 27 of 2022 on Personal Data Protection (the “PDP Law”) and its implementing regulations.

It applies to:

  • visitors to iidevcloud.com;
  • people who send us an inquiry, a quote request or a custom-solution request;
  • employees, contractors and administrators of our business customers who interact with us or with the service;
  • suppliers and other business contacts.

It does not apply to the data you store or process yourself inside the GPU Nodes you rent. For that data you remain the controller and we act as processor on your instructions — see section 10.

3. Definitions

Personal data
Any information about an identified or identifiable natural person, whether alone or combined with other information.
Controller
The party that determines the purposes and means of processing personal data.
Processor
The party that processes personal data on behalf of, and under the instructions of, a controller.
Data subject
The natural person to whom personal data relates.
Node
One GPU server unit rented under an Order, as described in our Terms of Service.
Order
Our written confirmation of a customer’s request, setting out configuration, price and duration.

4. Personal data we collect

4.1 Data you provide in inquiries and orders

When you press “Confirm Rental” or “Send Request” on this website, the page composes a message in your own email client and you send it. Nothing is transmitted to our servers by the website itself. The message you send may contain your name, job title, company name, email address, telephone number, the configuration you selected, and any free-text description of your workload.

4.2 Account and administrator data

If you become a customer, we process the names, business email addresses, telephone numbers and roles of the people you nominate as administrators or technical contacts, together with the access credentials and permission sets assigned to them.

4.3 Billing and tax data

To invoice you and to meet Indonesian accounting and tax obligations, we process company name and address, taxpayer identification, purchase-order references, invoice and payment records, and the bank details used for settlement or refunds.

4.4 Support and correspondence

We keep the email threads, tickets and call notes generated when you contact us, including any technical detail you choose to share.

4.5 Technical and log data

This website is a static site served through our hosting and content-delivery provider. As is normal for any web service, that provider processes IP addresses, browser and device type, request time, requested paths and referrer for content delivery, security and abuse prevention. Our control plane and the infrastructure supporting your Nodes generate operational logs — administrative actions, authentication events, resource usage and quota records.

4.6 Browser storage on this website

We store exactly one value in your browser: your language choice, under the key iid-lang. It never leaves your device and is never sent to us. It is not used for tracking and it does not identify you.

4.7 Data we do not collect

We do not seek and do not want:

  • payment card numbers — we do not accept card payments through this website and we do not store card data;
  • special-category data such as health, religion, political opinion, biometric or genetic data;
  • government identity documents, except where a bank or a tax authority obliges us to verify a company signatory;
  • data about children.

If you send us any of the above unprompted, we will delete it once we have dealt with your inquiry.

5. Where the data comes from

Almost all of the personal data we hold comes directly from you or from the business you represent. In addition we may receive:

  • operational and log data generated automatically by our infrastructure and by our hosting provider;
  • company registration and taxpayer details from public registers, where we need to verify a counterparty;
  • contact details passed to us by a colleague at your organization, for example when a technical contact is nominated.

We do not buy personal data, and we do not use data brokers or advertising-network profiles.

6. Purposes and legal bases

PurposeDataLegal basis under the PDP Law
Responding to an inquiry, preparing a quote and negotiating an Order4.1Steps taken at your request prior to a contract
Provisioning nodes, administering access, operating and supporting the service4.2, 4.4, 4.5Performance of the contract
Invoicing, collection, refunds and accounting4.3Performance of the contract; legal obligation
Security monitoring, abuse prevention, incident investigation, capacity planning4.5Legitimate interests in keeping the platform secure and available
Meeting tax, bookkeeping, audit and regulatory duties4.3, 4.4Legal obligation
Establishing, exercising or defending legal claimsas relevantLegitimate interests; legal obligation

Where we rely on legitimate interests, we have considered your interests and rights and limit the processing to what is necessary. You may object — see section 13.

We do not use your personal data for advertising, and we do not send marketing email unless you have asked us to contact you.

7. Cookies and similar technologies

This website sets no cookies. It loads no third-party analytics, no advertising or social pixels, no chat widget, no session recording and no fingerprinting script. There is no consent banner because there is nothing to consent to.

The only client-side storage is the language preference described in section 4.6. Web fonts are loaded from our font providers; that request necessarily discloses your IP address to them, as it would on any website that uses hosted fonts.

8. Who we share personal data with

We do not sell personal data, we do not rent it, and we do not share it for anyone else’s marketing. We disclose it only to:

  • Hosting and content delivery — the provider that serves this website;
  • Data-center partners — the operators of the facilities in the region where your Nodes run (Indonesia, Malaysia, Thailand);
  • Business systems suppliers — the email, ticketing, accounting and invoicing tools used to run the company;
  • Payment and banking providers — to collect payment and to issue refunds;
  • Professional advisers — lawyers, auditors and tax advisers, under duties of confidentiality;
  • Authorities and courts — where we are legally obliged to disclose, or where disclosure is necessary to establish or defend a legal claim;
  • An acquirer — if the business or part of it is transferred, subject to this policy continuing to apply.

We will name our current processors on request. Every processor is bound by a written agreement limiting it to our instructions.

9. Processors and international transfers

Nodes are available in Indonesia, Malaysia and Thailand, and you choose the region in which your workload runs. Our own business systems and our hosting provider may process data outside Indonesia.

Where personal data leaves Indonesian territory we satisfy ourselves, in line with the PDP Law, that the destination provides an adequate level of protection or that appropriate safeguards are in place — normally a written data-processing agreement covering confidentiality, security, sub-processing and restrictions on onward transfer.

If you have specific data-residency requirements, raise them before an Order is confirmed so that we can record them in the Order.

10. Personal data inside your workloads

You decide what data you bring into the Nodes you rent. In relation to that data:

  • you are the controller and we are your processor;
  • we process it only to provide the service, and only on your instructions;
  • we do not access the contents of your workloads, models or datasets, except (a) at your request for technical support, (b) where strictly necessary to contain a genuine security incident, or (c) where required by law;
  • you are responsible for having a lawful basis for any third-party personal data you upload, and for informing the data subjects concerned;
  • you are responsible for your own backups, and for retrieving your data before an Order expires — see our Terms of Service;
  • if you need a separate data-processing agreement, contact us and we will put one in place.

Please do not place special-category or heavily regulated personal data into the service without agreeing the arrangements with us in writing first.

11. How long we keep data

CategoryRetention
Inquiries that do not become customersUp to 24 months from the last contact
Customer contact and administrator recordsFor the duration of the relationship, then up to 24 months
Invoices, payment and accounting recordsFor the period required by Indonesian tax and company law
Support correspondenceUp to 24 months after the ticket is closed
Security, authentication and administrative logsUp to 12 months; longer where an incident or investigation is open
Web server and CDN logsPer our hosting provider’s retention policy
Data inside your NodesDeleted after the Order ends, as set out in the Terms

When a retention period ends we delete the data or irreversibly anonymise it. Where deletion is not immediately possible — for example within a backup set — we isolate the data and delete it on that backup’s own cycle.

12. How we protect data

We apply technical and organisational measures proportionate to the risk, including tenant isolation, role-based access control, multi-factor authentication for administrative access, encryption in transit, logging and audit trails, and least-privilege handling of internal access. The controls are described on our Security page.

No system is perfectly secure. If a personal data breach occurs that is likely to harm you, we will notify you and the competent authority within the period required by the PDP Law, and tell you what happened and what we are doing about it.

13. Your rights

Under the PDP Law you have the right to:

  • be informed about the processing, its purpose and its legal basis;
  • access your personal data and obtain a copy of it;
  • have inaccurate or incomplete data corrected or updated;
  • have your data erased, where the law allows;
  • withdraw consent, where processing was based on consent;
  • object to processing, including processing based on legitimate interests;
  • restrict or postpone processing while a dispute is being resolved;
  • object to a decision made solely by automated means that affects you;
  • receive your data in a commonly used, machine-readable format and have it transmitted to another controller where technically feasible;
  • claim compensation for a breach of the PDP Law;
  • lodge a complaint with the competent supervisory authority.

Some of these rights are qualified. We may be unable to erase data we are legally required to keep, such as issued invoices, and we may retain what we need in order to establish or defend a legal claim.

14. How to exercise your rights

Send your request to kei_hu@iidevcloud.com. Please tell us which right you are exercising and give us enough detail to locate your records.

  • We will acknowledge your request and, where necessary, ask you to confirm your identity — we ask only for what is needed to be sure we are dealing with the right person.
  • We aim to respond within the period set by the PDP Law and its implementing regulations. If a request is complex we will tell you and explain the delay.
  • Exercising your rights is free. We may charge a reasonable fee only for manifestly excessive or repetitive requests.
  • If we cannot act on a request, we will tell you why and how to challenge that decision.

If you are an employee or contractor of one of our business customers and your request concerns data inside that customer’s workloads, please contact your own organization — for that data they are the controller and we can act only on their instructions.

15. Customers and users outside Indonesia

We serve business customers in Southeast Asia and beyond. Where the General Data Protection Regulation or a comparable law applies to our processing of your data, we will honour equivalent rights — access, rectification, erasure, restriction, portability and objection — through the same channel as section 14, and you may complain to your local supervisory authority. Nothing in this policy limits a right you have under the law that applies to you.

16. Automated decision-making and profiling

We do not make decisions about you solely by automated means, and we do not profile you for marketing or for credit scoring. Quotas, rate limits and abuse controls are applied to accounts and workloads, not to individuals as a form of evaluation.

17. Children

The service is sold to businesses and is not directed at children. We do not knowingly collect children’s personal data. If you believe a child has provided us with personal data, contact us and we will delete it.

18. Third-party websites

Our documents link to a small number of external resources, such as our providers’ own pages. This policy does not cover those sites; their operators are responsible for their own processing.

19. Changes to this policy

We may update this policy as the service, our suppliers or the law changes. The effective date at the top of this page always reflects the current version. Where a change materially affects how we handle your personal data, we will notify active customers by email before it takes effect.

20. Contact and complaints

For any question about this policy, or to raise a concern about how we handle personal data, write to kei_hu@iidevcloud.com. We would like the chance to put things right; you may also complain directly to the competent supervisory authority in Indonesia at any time.