Loading...
IngestX by PT Immenzo Jaya International
This Privacy Policy explains how PT Immenzo Jaya International, operating the IngestX service (“IngestX”, “Immenzo”, “we”, “us”, or “our”), collects, uses, stores, discloses, transfers, retains, and protects Personal Data.
This Policy applies to Personal Data processed in connection with:
This Policy is intended to provide transparency concerning our processing of Personal Data. Mandatory rights and obligations under applicable data-protection law continue to apply regardless of this Policy.
The entity responsible for this Policy is:
PT Immenzo Jaya International
Menara Cakrawala #12th-5A Jalan M.H. Thamrin No. Kav. 9 Menteng Jakarta 10340 Indonesia
Privacy and Data Protection: [email protected]
Support: [email protected]
The privacy address is our central request channel. The address alone does not represent that a formal Data Protection Officer has been appointed where a particular processing activity would legally require one.
Our role depends on the circumstances in which Personal Data is processed.
We generally act as a Personal Data Controller where we determine the purposes and means of processing, including for:
Where a business customer submits documents or data to IngestX and determines why and how that information is processed for its business purposes, the customer generally acts as the Personal Data Controller and IngestX acts as its Personal Data Processor.
When acting as a Processor, we process Personal Data:
Customers are responsible for ensuring that they have a lawful basis and appropriate authority to submit Personal Data to IngestX.
The information we collect depends on the manner in which a person or organization interacts with IngestX.
We may process:
We may process:
Payment-card information may be processed directly by authorized payment providers. IngestX does not intentionally store complete payment-card numbers.
We may collect information contained in:
“Customer Content” means documents, files, data, images, fields, records, or other information submitted to or processed through IngestX by or on behalf of a customer.
Customer Content may include:
Customer Content may contain Personal Data relating to employees, suppliers, customers, contractors, representatives, or other individuals.
We may automatically collect information such as:
We may receive Personal Data from:
IngestX does not intentionally request Sensitive or Specific Personal Data for unrelated internal purposes.
Customer Content may nevertheless contain Personal Data that receives heightened protection under applicable law.
Where a customer submits such information, the customer is responsible for determining that:
IngestX will apply appropriate technical and organizational safeguards to such information where it is processed through the Services.
Where applicable law requires a legal basis, we process Personal Data based on one or more legally recognized grounds, which may include:
The applicable basis depends on the particular processing activity.
Where processing is based on consent, consent may be withdrawn subject to applicable law.
We may process Personal Data to:
We do not process Personal Data in a manner materially incompatible with the purpose for which it was collected unless permitted by applicable law.
IngestX uses automated systems and artificial-intelligence technologies to support functions such as:
Unless a customer separately gives express authorization for a specific purpose, IngestX does not use identifiable Customer Content to:
We may use aggregated, statistical, telemetry, or appropriately de-identified information for legitimate operational purposes such as:
We take reasonable measures intended to prevent such information from being used in a manner that reasonably identifies an individual or customer.
Automated extraction, classification, validation, or generated outputs may be incomplete or inaccurate.
Where appropriate to the context, outputs should be reviewed by an authorized person before being relied upon for decisions that may create legal, financial, safety, employment, regulatory, or similarly significant consequences.
We may disclose Personal Data only where reasonably necessary and legally permitted.
Recipients may include:
Providers supporting functions such as:
A provider is a Sub-Processor only when it processes Personal Data on our behalf in the relevant context. A provider may instead act as an independent Controller for purposes and means it determines, including its own legal or security obligations.
Where instructed by a customer, information may be transmitted to systems designated by that customer, including:
A customer-designated system or recipient is not automatically an IngestX Sub-Processor.
We may disclose information where reasonably necessary to:
Information may be disclosed under appropriate safeguards in connection with a proposed or completed:
We do not sell Personal Data for monetary payment.
IngestX may engage Sub-Processors to perform limited services on our behalf.
We require Sub-Processors processing Personal Data for IngestX to be subject to appropriate obligations concerning:
Where IngestX acts as a Processor for a customer, additional processors are engaged only in accordance with applicable data-protection requirements and required customer authorization.
A current list of material Sub-Processors may be made available through an IngestX Trust or compliance resource or upon appropriate customer request.
Third-party AI service providers that process Customer Content on our behalf are treated as Sub-Processors where legally applicable.
Before an external AI provider may process Customer Content, the applicable provider terms, account settings, processing locations, retention behavior, and customer authorization must be documented for that deployment. This Policy does not by itself prove a provider's training or retention behavior.
Personal Data may be processed in Indonesia and, where legally permitted, in other jurisdictions in which IngestX or authorized service providers operate.
Where Personal Data is transferred outside Indonesia, we apply the transfer mechanism required by applicable law.
This may include:
Data location may also depend on the infrastructure, integration, region, or service configuration used for a particular customer.
We maintain technical and organizational measures designed to protect Personal Data from:
Depending on the relevant systems and risks, measures may include:
No electronic system can be guaranteed to be completely secure.
Users and customers also have responsibility for securing their credentials, endpoints, integrations, and customer-controlled systems.
IngestX maintains procedures for investigating and responding to suspected Personal Data breaches.
If IngestX acts as a Personal Data Controller and becomes aware of a Personal Data protection failure requiring notification, we will notify affected Data Subjects and the competent institution within the period required by applicable law.
Where Indonesian Personal Data Protection Law applies, required written notification will be made no later than 3 × 24 hours after the relevant awareness threshold prescribed by law.
Required notices will contain the information required by applicable law, which may include:
Where IngestX acts only as a Processor, we will provide the relevant customer with information reasonably necessary for the customer to assess and fulfill its own legal obligations.
We retain Personal Data only for as long as reasonably necessary for the applicable purpose, including:
Different categories of information may have different retention periods.
When Personal Data is no longer required, we will delete, destroy, anonymize, or otherwise restrict it as required by applicable law.
Personal Data may be deleted or destroyed where:
Deletion from live systems may occur before residual copies expire from protected backup systems.
Backup copies may remain until overwritten through the normal backup cycle, provided that they remain appropriately protected and are not used for unrelated purposes.
Information may be retained where preservation is legally required, including for legitimate litigation holds, regulatory requirements, accounting obligations, or other lawful purposes.
Depending on applicable law and permitted exceptions, individuals may have rights to:
Some rights under Indonesian law are subject to specific statutory response periods.
Requests may be submitted to:
We may request reasonable information necessary to:
Where Personal Data is processed by IngestX solely on behalf of a business customer, the request may need to be handled by that customer. IngestX will provide legally required assistance where appropriate.
Where required by applicable law, IngestX will conduct or support a Personal Data protection impact assessment before engaging in processing that presents a legally recognized high risk.
High-risk factors may include, where applicable:
We use cookies and similar technologies for purposes including:
Strictly necessary technologies may operate without optional consent where legally permitted.
Non-essential analytics technologies are activated in accordance with the choice presented through our consent mechanism and applicable law. We do not currently activate advertising technologies or offer advertising as a consent category.
More information may be provided in our Cookie Policy or cookie-preference interface.
Where permitted by law, we may send information about IngestX products, Services, events, or related business content.
Recipients may opt out of promotional email by:
Opting out of promotional messages does not prevent us from sending necessary:
IngestX is primarily designed for businesses and professional users.
Our Services are not intended to encourage children to create independent business accounts.
We do not knowingly collect children's Personal Data directly for behavioral advertising.
If Customer Content lawfully contains Personal Data relating to children, the submitting customer is responsible for ensuring that the processing has the necessary authority, legal basis, notices, permissions, and safeguards.
Where IngestX itself processes children's Personal Data as Controller, we will comply with applicable requirements concerning children's Personal Data.
Where IngestX undergoes a merger, separation, acquisition, consolidation, restructuring, dissolution, or similar change affecting Personal Data, we will handle transfers, retention, deletion, destruction, and required notifications in accordance with applicable law.
We may update this Privacy Policy to reflect changes in:
The effective or last-updated date will be shown at the beginning of this Policy.
Where a change materially affects information that applicable law requires us to provide before processing, we will provide the required notice before the relevant change takes effect.
Where renewed consent is legally required, we will request it rather than treating continued use as consent.
Questions, concerns, complaints, and Personal Data requests may be sent to:
PT Immenzo Jaya International
Privacy / Data Protection: [email protected]
Support: [email protected]
Address: Menara Cakrawala #12th-5A Jalan M.H. Thamrin No. Kav. 9 Menteng Jakarta 10340 Indonesia
Please provide only the information reasonably necessary for us to identify and respond to the request.
Last updated: 4 September 2026