Loading...
Schedule 1
This Data Processing Agreement (“DPA”) forms part of the IngestX Master SaaS & Data Protection Agreement (“Agreement”) between PT Immenzo Jaya International (“IngestX”, “Provider”, “we”, “us” or “our”) and the customer identified in the applicable Order Form (“Customer”).
This DPA governs the Processing of Customer Personal Data by Provider on behalf of Customer.
This DPA applies where Provider Processes Customer Personal Data as a Processor or Sub-Processor in connection with the Services.
It does not apply to Personal Data for which Provider independently determines the purposes and means of Processing, including certain:
Such independent Controller Processing is governed by Provider's Privacy Policy and applicable law.
This DPA is incorporated into and forms part of the Agreement.
If there is a conflict concerning Processing of Customer Personal Data:
The Standard Contractual Clauses, UK Addendum, or other mandatory transfer clauses prevail to the extent that their terms cannot lawfully be modified.
This DPA begins when Provider first Processes Customer Personal Data under the Agreement and continues until Provider has ceased Processing Customer Personal Data, except for provisions that by their nature survive deletion or termination.
For purposes of this DPA:
“Applicable Data Protection Law” or “Data Protection Laws” means privacy, Personal Data, data-protection, and similar laws applicable to the Processing governed by this DPA, including where applicable:
“Controller” means a person or entity that determines the purposes and means of Processing Personal Data, including a “Personal Data Controller” under UU PDP.
“Customer Personal Data” means Personal Data contained in Customer Content that Provider Processes on behalf of Customer.
“Data Subject” means the identified or identifiable individual to whom Personal Data relates.
“European Data” means Customer Personal Data subject to the EU GDPR, UK GDPR, or Swiss data-protection law.
“Instructions” means Customer's documented instructions regarding Processing of Customer Personal Data.
“Personal Data” includes information protected as personal data, personal information, personally identifiable information, or equivalent terminology under Applicable Data Protection Law.
“Processing” or “Process” means any operation performed on Personal Data, including:
“Processor” means a person or entity that Processes Personal Data on behalf of a Controller, including a “Personal Data Processor” under UU PDP.
“Restricted Transfer” means a transfer of Personal Data requiring a legally recognized transfer safeguard under Applicable Data Protection Law.
“Security Incident” means a confirmed breach of security leading to accidental or unlawful:
Customer Personal Data Processed by Provider or its Sub-Processors.
A Security Incident does not include unsuccessful activity that does not compromise Customer Personal Data, such as unsuccessful:
“Standard Contractual Clauses” or “SCCs” means the European Commission standard contractual clauses for international transfers adopted under Commission Implementing Decision (EU) 2021/914, as amended, replaced, or superseded.
“Sub-Processor” means another Processor engaged by Provider to Process Customer Personal Data in connection with the Services.
“UK Addendum” means the International Data Transfer Addendum to the EU Commission Standard Contractual Clauses issued by the UK Information Commissioner's Office, as amended, replaced, or superseded.
Capitalized terms not defined in this DPA have the meanings provided in the Agreement.
Where Customer determines the purposes and means of Processing Customer Personal Data:
Customer may itself Process Personal Data on behalf of another Controller.
In that situation:
Customer represents that it has authority from the relevant Controller to appoint Provider and issue the Instructions contained in the Agreement and this DPA.
If Provider determines independent purposes and means for particular Personal Data rather than Processing that Personal Data on Customer's behalf, Provider acts as Controller for that separate Processing and this DPA does not apply to that independent Processing.
Provider will not characterize Customer Personal Data as independently controlled data merely to avoid its Processor obligations.
Customer is responsible for complying with Data Protection Laws applicable to Customer's Processing.
Customer is responsible for:
Customer will notify Provider without undue delay if Customer determines that its Instructions or use of the Services can no longer comply with Applicable Data Protection Law.
Customer must evaluate whether the Services are appropriate before submitting:
Customer will not submit categories of Personal Data expressly prohibited by the applicable Service documentation or Order Form.
Where Customer lawfully submits permitted sensitive Personal Data, Customer is responsible for establishing any heightened lawful basis, notice, consent, authorization, or assessment legally required for that Processing.
Provider will apply the safeguards required under this DPA and Schedule 3 to Customer Personal Data regardless of whether Customer Personal Data is ordinary or sensitive, subject to any additional safeguards expressly agreed for particular sensitive-data categories.
The following collectively constitute Customer's documented Instructions:
Customer may issue reasonable additional Instructions that are:
Material custom Processing requested outside normal Service functionality may require:
If Provider reasonably believes that an Instruction violates Applicable Data Protection Law, Provider will:
Provider is not required to perform an Instruction that would require Provider to violate applicable law.
If applicable law requires Provider to Process Customer Personal Data contrary to Customer's Instructions, Provider will notify Customer before that Processing unless applicable law prohibits such notice.
Provider will:
Provider will not retain, use, disclose, or otherwise Process Customer Personal Data for a materially unrelated purpose unless:
Provider will not sell Customer Personal Data.
Provider will not use Customer Personal Data to create advertising profiles for unrelated advertising purposes.
Unless Customer expressly authorizes a specific use in writing, Provider will not use identifiable Customer Personal Data to:
A third-party AI provider that Processes Customer Personal Data on Provider's behalf is treated as a Sub-Processor.
Provider will use contractual terms and available commercial configurations intended to prevent Customer Personal Data from being used to train the third-party provider's publicly available models.
Provider will ensure that persons authorized to Process Customer Personal Data:
Confidentiality obligations continue after a person's access to Customer Personal Data ends.
Provider will implement and maintain appropriate technical and organizational measures designed to protect Customer Personal Data against:
The applicable security measures are described in Schedule 3 — Security Requirements, which is incorporated into this DPA.
Provider may modify individual security technologies or controls as:
provided that Provider will not materially reduce the overall level of protection applicable to Customer Personal Data during the relevant subscription term.
Customer remains responsible for security within Customer's control, including:
Provider will notify Customer without undue delay and, in any event, no later than seventy-two (72) hours after Provider becomes aware of a confirmed Security Incident affecting Customer Personal Data, unless Applicable Data Protection Law or an expressly agreed Order Form requires an earlier notification.
The Parties acknowledge that Provider may notify Customer before Provider has completed its investigation.
To the extent reasonably known at the time, Provider's notification will include available information concerning:
Where complete information is not immediately available, Provider may provide information in phases as its investigation develops.
Provider will take reasonable steps to:
a confirmed Security Incident.
Provider will provide reasonable assistance necessary for Customer to assess and satisfy applicable legal breach-notification duties.
Where Customer is Controller, Customer remains responsible for determining whether Customer must notify:
except to the extent Provider independently has a legal obligation to notify.
Nothing in this Section prevents Provider from fulfilling an independent mandatory notification obligation.
A Security Incident notification does not constitute an admission of fault, negligence, or liability.
Where Customer acts as Controller, Customer is responsible for responding substantively to Data Subject requests.
Where Service functionality permits Customer to:
Customer Personal Data, Customer will ordinarily use that functionality to respond to requests.
If Customer cannot reasonably respond through available functionality, Provider will provide reasonable assistance upon Customer's documented request, taking into account:
If Provider receives a request from a Data Subject concerning Customer Personal Data for which Customer is responsible, Provider will, where appropriate and legally permitted:
Provider will not substantively respond on Customer's behalf unless:
Ordinary assistance reasonably required by Data Protection Law is included in Provider's Processor responsibilities.
Provider may charge reasonable fees for materially excessive, repetitive, custom, or extraordinary assistance outside normal Service functionality where:
Taking into account the nature of Processing and information available to Provider, Provider will reasonably assist Customer with a legally required:
relating specifically to Provider's Processing of Customer Personal Data.
Provider's assistance does not transfer Customer's Controller responsibility for determining whether an assessment is required or for completing Customer-specific portions of the assessment.
Where required by Applicable Data Protection Law, Provider will reasonably assist Customer with prior consultation with a competent data-protection authority concerning Provider's Processing.
If Provider receives a regulatory:
that specifically concerns Customer's Processing of Customer Personal Data, Provider will notify Customer where legally permitted and reasonably cooperate with Customer.
Nothing in this Section requires Provider to:
Provider may use Sub-Processors only in accordance with:
Before execution of this DPA or commencement of relevant Processing, Provider will make available to Customer a current Sub-Processor Register identifying material Sub-Processors that may Process Customer Personal Data.
By executing the DPA, Customer approves the Sub-Processors specifically identified in the Sub-Processor Register delivered to Customer as of the Effective Date, to the extent such approval satisfies Applicable Data Protection Law.
Where Applicable Data Protection Law permits general written authorization, Customer grants Provider general authorization to appoint replacement or additional Sub-Processors subject to:
Where UU PDP requires Provider to obtain Customer's written approval before appointing another Processor, Provider will obtain the required affirmative written or electronically recorded approval before that Sub-Processor begins Processing the affected Customer Personal Data.
For such Processing, Customer silence will not be treated as affirmative approval where applicable law requires written approval.
Provider will provide Customer reasonable advance notice of a material new Sub-Processor.
Unless:
Provider will provide at least 30 days' advance notice where reasonably practicable.
Customer may object to a proposed Sub-Processor on reasonable and documented grounds relating to protection of Customer Personal Data.
Customer must raise the objection within the notice period.
The Parties will work in good faith toward a commercially reasonable solution, which may include:
If:
either Party may terminate the materially affected Service.
Provider will refund prepaid fees covering the unused terminated period where termination results solely from an unresolved legitimate Sub-Processor objection and Customer has otherwise complied with the Agreement.
Provider will impose written data-protection obligations on its Sub-Processors that provide a level of protection appropriate to the Processing and consistent with Provider's applicable obligations under this DPA.
Provider remains responsible for performance of its DPA obligations where it delegates Processing to a Sub-Processor, subject to the Agreement's applicable liability provisions.
Provider will make available information reasonably necessary to demonstrate Provider's compliance with this DPA where required by Applicable Data Protection Law.
Where available, Provider may initially satisfy Customer's reasonable assurance request through appropriate evidence such as:
Provider will not represent that it maintains a certification, audit opinion, or standard that it does not actually maintain.
If the information supplied is reasonably insufficient to demonstrate compliance with a material obligation under this DPA, Customer may request a reasonable audit.
Unless required otherwise by law, the audit must:
The ordinary annual limit does not apply where:
Unless disclosure is legally required, Provider is not required to provide:
Provider will, where possible, provide alternative evidence sufficient to address the legitimate compliance question.
Each Party bears its ordinary costs associated with routine compliance verification.
Customer will bear commercially reasonable extraordinary costs arising from a Customer-requested custom audit, unless the audit establishes a material Provider breach of this DPA.
Customer may use available Service functionality to retrieve or export Customer Personal Data during the subscription term.
Following expiration or termination, Provider will, subject to Customer's choice where required by Applicable Data Protection Law:
Unless another period is stated in the Order Form, Customer should retrieve Customer Personal Data within the 30-day post-termination retrieval period established under the Agreement.
Following the applicable retrieval period, Provider will delete Customer Personal Data from active systems in accordance with Provider's documented deletion processes unless:
Customer Personal Data may remain in protected backup systems until overwritten or deleted according to Provider's ordinary backup lifecycle.
Such backup data will:
Where Provider is legally required to retain particular Customer Personal Data, Provider will:
Upon reasonable written request, Provider will provide reasonable confirmation when the applicable deletion process has been completed.
Each Party will ensure that Restricted Transfers for which it is legally responsible are conducted in accordance with Applicable Data Protection Law.
Unless an Order Form expressly provides a data-residency commitment, Customer acknowledges that Customer Personal Data may be Processed in jurisdictions in which Provider and its authorized Sub-Processors lawfully operate.
Where an Order Form expressly provides:
Provider will comply with those commitments for the Customer Personal Data covered by the relevant commitment.
Where Indonesian Personal Data is transferred outside the territory of the Republic of Indonesia and UU PDP applies, the Parties will apply the transfer safeguards required by Indonesian law.
Where Customer acts as the relevant Controller, Customer is responsible for satisfying the Controller requirements applicable to that transfer.
The applicable safeguards may include, in the legally prescribed order:
Provider will provide Customer reasonably available information regarding Provider and relevant Sub-Processor Processing locations to support Customer's transfer assessment.
Nothing in this DPA constitutes Data Subject consent.
This Section applies where Customer Personal Data is subject to EU GDPR requirements.
The Parties intend this DPA to satisfy applicable Processor-contract requirements under Article 28 EU GDPR.
Where Customer is Controller and Provider is Processor, Customer is the Controller/data exporter and Provider is the Processor/data importer for applicable Restricted Transfers.
Where Customer is itself a Processor acting for another Controller, Customer is the Processor/data exporter and Provider is the Sub-Processor/data importer for applicable Restricted Transfers.
If Provider believes a Customer Instruction infringes EU Data Protection Law, Provider will inform Customer without undue delay to the extent legally permitted.
Provider will provide the assistance described in Sections 13 and 14 where required by EU GDPR Articles 35 or 36.
Where European Data is subject to a Restricted Transfer requiring the SCCs, the SCCs are incorporated into this DPA by reference and apply as follows.
Where Customer is Controller and Provider is Processor:
Module Two — Controller to Processor applies.
Where Customer is Processor and Provider acts as Customer's Sub-Processor:
Module Three — Processor to Processor applies.
The optional docking mechanism in Clause 7 applies.
For Clause 9, the general written authorization option applies where legally permissible, with the notice period stated in Section 15.
Where another applicable law requires specific written authorization, that stricter requirement applies.
The optional wording under Clause 11 does not apply unless the Parties expressly agree otherwise.
For purposes of Clause 17, the SCCs will be governed by the law of Ireland, unless mandatory European Data Protection Law requires another eligible EU Member State law.
For purposes of Clause 18, disputes under the SCCs will be resolved by the competent courts of Ireland, unless the SCCs or mandatory law require otherwise.
The competent supervisory authority under Clause 13 will be determined in accordance with the SCCs and EU GDPR.
The Annexes to the SCCs are completed by:
of this DPA.
If a provision of this DPA conflicts with a mandatory provision of the SCCs, the SCCs prevail for the relevant Restricted Transfer.
Provider will make reasonably available information concerning:
to assist Customer with a legally required transfer assessment.
Where UK GDPR applies to a Restricted Transfer:
The Parties will complete or interpret the UK Addendum using:
Where required under UK transfer rules, the Parties will cooperate reasonably regarding the applicable transfer risk assessment or equivalent data-protection test.
If the UK Addendum conflicts with this DPA concerning a UK Restricted Transfer, the mandatory UK transfer terms prevail.
Where Swiss data-protection law applies and the EU SCCs are used as a transfer mechanism:
Nothing in this Section modifies the SCCs in a manner prohibited by applicable Swiss law.
This Section applies where Customer Personal Data constitutes Personal Information subject to the CCPA and Provider acts as a Service Provider or Contractor.
For such Processing:
Customer discloses or makes California Personal Information available to Provider solely for the specific business purposes necessary to operate IngestX, including:
Provider will not Sell or Share California Personal Information as those terms are defined by the CCPA.
Provider will not retain, use, or disclose California Personal Information for a purpose other than:
Provider will not retain, use, or disclose California Personal Information outside the direct business relationship between Provider and Customer except where expressly permitted by the CCPA.
Provider will not combine California Personal Information received from Customer with Personal Information received from another source except where such combination is expressly permitted under the CCPA and applicable regulations.
Provider will provide the level of privacy protection required of a Service Provider or Contractor under applicable CCPA requirements.
Provider will notify Customer if Provider determines that it can no longer comply with an applicable Service Provider or Contractor obligation concerning California Personal Information.
Customer may take reasonable and appropriate steps, consistent with this DPA, to help ensure that Provider uses California Personal Information consistently with applicable CCPA requirements.
Where Customer reasonably identifies unauthorized Processing, Customer may require Provider to take reasonable steps to stop and remediate that Processing.
Provider will reasonably cooperate with Customer regarding valid CCPA consumer requests concerning California Personal Information Processed by Provider.
Provider will require a Sub-Processor handling California Personal Information to comply with contractual obligations necessary for Provider to maintain its status as a Service Provider or Contractor where applicable.
To the extent required by then-applicable CCPA regulations, Provider will make reasonably available information in Provider's possession, custody, or control that Customer reasonably requires from Provider to support Customer's legally required:
subject to reasonable confidentiality, privilege, security, and other-customer protections.
The Parties acknowledge that disclosure of California Personal Information to Provider for the specified business purposes is not intended to constitute a Sale or Share of that Personal Information.
If Provider receives a legally binding governmental or law-enforcement demand specifically seeking Customer Personal Data, Provider will, to the extent legally permitted:
Where notification is legally prohibited, Provider may provide delayed notice if and when that prohibition ceases.
Nothing requires Provider to violate a binding legal obligation.
A Customer Affiliate may receive rights under this DPA where:
Unless otherwise agreed, the Customer entity that entered into the Agreement will:
on behalf of participating Customer Affiliates.
Provider is not required to conduct duplicative audits or materially identical compliance processes separately for multiple Customer Affiliates.
Where a Provider Affiliate Processes Customer Personal Data on Provider's behalf, it will be treated as a Sub-Processor unless applicable law assigns another role.
Provider will maintain records of Processing activities as required by Applicable Data Protection Law.
Such records may include, where legally required:
Liability arising from or relating to this DPA is governed by the liability provisions of the Agreement except where:
Nothing in this DPA limits rights of Data Subjects where such rights cannot legally be limited by agreement between Provider and Customer.
If a change in Applicable Data Protection Law requires modification of this DPA, the Parties will cooperate in good faith to implement the minimum changes reasonably necessary to maintain lawful Processing.
Provider will not use this Section to materially reduce Customer's data-protection rights unrelated to the legal change.
If a provision of this DPA is determined to be invalid or unenforceable, the remaining provisions remain effective.
The invalid provision will be interpreted or modified to the minimum extent reasonably necessary to make it valid while preserving its intended data-protection purpose.
Name: Customer identified in the applicable Order Form.
Address: Customer address stated in the Order Form.
Contact: Customer privacy, security, legal, or administrative contact stated in the Order Form or Customer account.
Role: Controller or Processor, depending on Customer's relationship to the relevant Personal Data.
Name: PT Immenzo Jaya International.
Address: Menara Cakrawala #12th-5A Jalan M.H. Thamrin No. Kav. 9 Menteng Jakarta 10340 Indonesia
Privacy Contact: [email protected]
Role: Processor or Sub-Processor.
Processing of Customer Personal Data in connection with provision of the IngestX document-processing and automation Services.
The applicable subscription term plus:
Processing may occur continuously or intermittently according to:
Processing may include:
Provider Processes Customer Personal Data to:
Depending on the documents Customer submits, Data Subjects may include:
Depending on Customer Content, Personal Data may include:
The Services are not intended by default for unrestricted Processing of highly sensitive or specially regulated Personal Data.
Customer may submit permitted sensitive Personal Data only where:
Customer Personal Data is retained for:
after which it is deleted, destroyed, or otherwise handled under Section 17.
The technical and organizational measures applicable to Customer Personal Data are those described in Schedule 3 — Security Requirements of the Agreement.
For purposes of applicable Article 28 and SCC requirements, those measures include, as appropriate:
Provider may use:
No particular certification is represented by this Annex unless expressly stated by Provider in current official compliance documentation.
This Annex must contain the actual current Sub-Processors before the DPA is executed. Provider must not insert fictional or planned providers.
The register should state, for each material Sub-Processor:
| Sub-Processor | Legal Entity | Service / Processing Purpose | Data Categories | Processing Country/Region | Mandatory or Optional |
|---|---|---|---|---|---|
| To be populated from IngestX's actual production vendor inventory |
The Sub-Processor Register delivered to Customer and identified by its effective date forms part of this Annex.
Provider will update the register only in accordance with Section 15.
Where a legally required transfer mechanism applies:
Customer / Exporter: Customer identified in the Order Form.
Provider / Importer: PT Immenzo Jaya International.
Exporter Role: Controller or Processor, as applicable.
Importer Role: Processor or Sub-Processor.
Relevant Processing: As described in Annex A.
Data Subjects: As described in Annex A.
Personal Data: As described in Annex A.
Sensitive Data: As described in Annex A.
Frequency: Continuous or intermittent according to Customer use.
Duration: As described in Annex A.
Security Measures: Annex B and Schedule 3.
Sub-Processors: Annex C.
For EU Restricted Transfers:
For UK Restricted Transfers, the applicable UK Addendum supplements the SCCs where required.
For Swiss transfers, the SCCs are interpreted with the jurisdictional adaptations stated in Section 23.
PT Immenzo Jaya International
Privacy / Data Protection: [email protected]
Support: [email protected]
Address: Menara Cakrawala #12th-5A Jalan M.H. Thamrin No. Kav. 9 Menteng Jakarta 10340 Indonesia