Loading...
IngestX by Immenzo
This Privacy Policy explains how PT Immenzo Jaya International (“IngestX”, “we”, “us”, or “our”) collects, uses, discloses, stores, and protects Personal Data in connection with:
This Policy should be read together with our Cookie Policy, Security & Trust page, and any applicable customer agreement or Data Processing Addendum.
This Policy is provided for transparency. It does not create contractual rights beyond those set out in a signed customer agreement or required by applicable law.
We act as a Personal Data Controller when we determine the purposes and means of processing, including for website operation, account administration, sales and customer relationships, billing, service security, direct marketing, recruitment, and our own legal and compliance obligations.
When a business customer submits documents or other data to the IngestX platform and determines the purposes of that processing, the customer acts as the Data Controller and IngestX acts as its Data Processor.
In those circumstances:
The Personal Data we collect depends on how a person interacts with IngestX.
Name, business email, telephone number, company/department/job title, account credentials, billing and transaction information, communications and support requests, survey or product feedback, demonstration and sales-request information, and information submitted through forms or account settings.
Payment-card information is processed by authorized payment providers. IngestX does not store full payment-card numbers.
Documents and data submitted by or for a customer (invoices, purchase orders, delivery documents, tax documents, forms, certificates, correspondence, document images, extracted fields, validation results, and related transaction data). Customer Content may contain Personal Data relating to the customer’s employees, suppliers, customers, or other individuals.
Customers are solely responsible for ensuring they have an appropriate legal basis and authority to submit Customer Content.
IP address, browser and device type, operating system, language and time-zone settings, access dates and times, pages and features viewed, referral information, account and session events, API and system activity, error and diagnostic records, security events, and cookie and consent preferences.
Non-essential analytics or advertising technologies are activated only in accordance with the choices presented through our cookie-consent mechanism.
We may receive information from a person’s employer or organization, authorized customer representatives, authentication providers, implementation partners, payment providers, service providers, publicly available professional sources, and advertising or analytics providers where permitted.
We do not intentionally collect Sensitive Personal Data (as defined under Indonesian law) for our own purposes. If Customer Content contains Sensitive Personal Data, the customer remains responsible for ensuring a valid legal basis and any required safeguards before submission.
We process Personal Data only for specified purposes and on a valid legal basis under applicable law (including the Indonesian Personal Data Protection Law / UU PDP).
Main purposes include: creating and administering accounts; providing the Services; processing payments; providing support; protecting systems and users; detecting abuse, fraud, or security incidents; maintaining records; improving reliability; sending service-related communications; sending optional promotional communications (where permitted); complying with legal obligations; establishing or defending legal claims; and corporate transactions.
Where we rely on legitimate interests, we assess necessity and impact. Where we rely on consent, consent may be withdrawn through the method provided or by contacting us.
IngestX uses automated systems and artificial-intelligence technologies for document classification, text and field extraction, line-item extraction, validation, exception detection, and preparation of structured outputs.
Unless separately agreed in writing, IngestX does not use Customer Content to:
We may use appropriately aggregated or de-identified operational information to maintain security, measure reliability, diagnose technical issues, and improve system performance, provided the information cannot reasonably identify a customer or individual.
Third-party AI providers that process Customer Content on our behalf are treated as Sub-Processors and are subject to contractual data-protection restrictions. We use commercial configurations intended so that Customer Content is not used to train those providers’ public models.
Outputs may require human review. Customers remain responsible for decisions made using extracted or generated information, particularly where a decision may have legal, financial, employment, or similarly significant consequences.
We may disclose Personal Data to:
We may disclose aggregated or de-identified information that cannot reasonably identify an individual.
We do not sell Personal Data for monetary payment.
A current list of material Sub-Processors is available to customers upon request or as described in the applicable agreement.
We use cookies and similar technologies to operate and secure the website, remember choices, understand performance, and measure advertising campaigns.
Strictly necessary technologies may operate without optional consent where permitted. Analytics and advertising technologies are activated only according to the choices presented through our cookie-consent mechanism. Further details are in our Cookie Policy.
Where an Order Form or service specification includes an Indonesia-only processing commitment, we will process the relevant data according to that commitment.
Otherwise, Personal Data may be processed in Indonesia and in other countries where IngestX or its authorized service providers operate.
Before transferring Personal Data outside Indonesia, we apply a transfer mechanism permitted under applicable law (including confirmation of an equivalent or higher level of protection, adequate contractual safeguards, or consent where legally required and no other permitted mechanism is available).
We retain Personal Data only for as long as reasonably necessary for the relevant purpose, contractual requirement, security need, or legal obligation.
When retention is no longer necessary, Personal Data is deleted, destroyed, anonymized, or isolated from ordinary use in accordance with applicable requirements and the customer’s configured settings or instructions.
We implement technical and organizational measures designed to protect Personal Data against unauthorized access, disclosure, alteration, loss, or unlawful processing. These measures may include encryption in transit and at rest, authentication and access controls, logging and monitoring, logical separation, vulnerability management, backup and recovery procedures, incident-response procedures, employee confidentiality obligations, and risk-based review of service providers.
No system is completely secure. Specific security commitments are governed by the applicable customer agreement or Security & Trust page.
Where required by applicable law (including UU PDP), we will notify the competent authority and affected individuals of a personal data breach within the prescribed timeframe (currently 3 × 24 hours from becoming aware of the breach under Indonesian law), and will take reasonable steps to mitigate harm.
Subject to applicable law and permitted exceptions, an individual may have the right to access, correct, delete, restrict, or object to certain processing of their Personal Data; withdraw consent; receive information about processing; and exercise other rights provided by law (including rights related to automated decision-making that produces legal or similarly significant effects).
We will respond to verifiable requests within the timeframe required by applicable law (including the 3 × 24 hour period applicable to certain rights under UU PDP where required).
To submit a request:
Subject: IngestX Privacy Rights Request
Please include sufficient information for us to identify the relevant relationship and verify the request.
Where we process Personal Data solely on behalf of a customer, we may refer the request to that customer or assist the customer in responding. The customer remains responsible for determining whether and how the request should be fulfilled.
Promotional emails may be stopped via the unsubscribe link or by contacting [email protected]. Non-promotional service, security, transactional, and legal communications may continue as necessary.
The Services are intended for businesses and professional users and are not directed to children. We do not knowingly collect Personal Data directly from children for our own advertising purposes. Where a customer lawfully submits children’s Personal Data, that processing must be authorized under the customer agreement and subject to the safeguards required by applicable law.
We may update this Policy to reflect changes in our Services, processing activities, service providers, legal obligations, or practices. The latest revision date will appear at the end of this Policy. Material changes will be notified as appropriate. Where processing depends on consent and the relevant information materially changes, we will seek renewed consent where required.
PT Immenzo Jaya International
Email: [email protected]
Support: [email protected]
Address: Menara Cakrawala #12th-5A, Jalan M.H. Thamrin No. Kav. 9, Menteng, Jakarta 10340, Indonesia
For customer-specific privacy or data-protection reviews, contact [email protected].
Last updated: August 2026