Skip to main content
FISETRA
FeaturesPricingFAQAbout On-Premise Start Free
Bahasa Indonesia English✓
Start Free

FISETRA Privacy Policy

Last updatedJuly 24, 2026

1. Introduction

This Privacy Policy explains how PT Idemas Solusindo Sentosa ("FISETRA", "we") collects, uses, stores, discloses, and protects Personal Data in connection with the use of the FISETRA asset management platform, which includes:

  • the web application available at https://fisetra.com;
  • FISETRA mobile application for Android and iOS;
  • application programming interfaces (APIs) and supporting services; and
  • Tokenized Public Pages, such as approval confirmation pages (approval) and Self Monitoring reporting which can be accessed without signing in.

Collectively, these are referred to as the "Service".

This Privacy Policy is a notice regarding Personal Data processing practices in the Service. By creating or activating an account after having the opportunity to read this Privacy Policy, you acknowledge that you understand these practices. Processing of Personal Data is not always based on consent, but may be based on the performance of an agreement, legal obligations, legitimate interests, or other processing grounds permitted by law.

Recipients who only use Tokenized Public Pages without having an account will obtain relevant information regarding the data processed for the response. Use of the page does not automatically make the recipient a Customer or registered User.

This policy was prepared with reference to:

  • Law Number 27 of 2022 concerning Protection of Personal Data ("PDP Law");
  • Law Number 11 of 2008 as last amended by Law Number 1 of 2024 concerning Electronic Information and Transactions ("ITE Law"); and
  • Government Regulation Number 71 of 2019 concerning Implementation of Electronic Systems and Transactions.

2. Definitions

TermDefinition
Personal DataData relating to an identified or identifiable natural person, either on its own or in combination with other information, directly or indirectly through electronic or non-electronic systems.
Customer / CompanyBusiness entities or organizations that create, manage, or use one or more company workspaces within FISETRA, either in trial, free or paid packages.
UserIndividuals who have accounts and access the Service, including Company Admins, operators, approvers, and field officers.
Company AdminA User granted administrative authority by a Customer to manage company settings, team members, roles, permissions, and workspaces.
Customer ContentAll data, documents, files, images, configurations and information entered, uploaded or generated by Customers and their Users through the Service.
Tokenized Public PagesPages that can be accessed without signing in through tokenized links, including approval and Self Monitoring reporting pages.
Personal Data ControllerThe party that determines the purposes and exercises control over the processing of Personal Data.
Personal Data ProcessorThe party that processes Personal Data on behalf of the Personal Data Controller.

3. Roles of the Parties in Data Processing

FISETRA is a multi-tenant Software-as-a-Service (SaaS) platform for business needs. Our role depends on the type of data and the purposes for which it is processed.

3.1 FISETRA as Controller of Personal Data

We act as a Personal Data Controller for the data we need to provide, manage, secure, and support the Service and maintain relationships with Customers and Users, including:

  • User account data, such as name, email address, username, password in the form of hash, and email verification status;
  • User profile data, such as telephone number, address, city, province, postal code, country, and profile photo;
  • technical and security data, such as IP addresses, user agent, session, activity logs, and security logs;
  • mobile device data, such as device installation identifiers, device information, and notification tokens; and
  • support communications, complaints, and information necessary to manage service relationships.

3.2 FISETRA as Personal Data Processor

We act as a Personal Data Processor for Customer Content entered into a company workspace. In this relationship, the Customer acts as the Personal Data Controller, and we process data based on the Customer's instructions through the use of Service features, the Terms of Use, and settings selected by the Customer.

Customer Content that may contain Personal Data includes:

  • employee data registered as person in charge or PIC of assets;
  • name of the person responsible, maker, examiner and approver on the transaction document;
  • email addresses of notification recipients, copy recipients, user invitations, Self Monitoring requests, and approval requests;
  • notes, comments, and photo or document attachments; and
  • attributes defined by the Customer through the Custom Fields feature.

The Customer is responsible for ensuring that it has the right, authority, and lawful basis to enter the Personal Data of employees, vendors, and third parties into the Service and to provide any required notices to those parties.

If your account was created by or through an invitation from the company where you work, requests relating to Personal Data in Customer Content should first be submitted to the Company Admin as the representative of the Personal Data Controller. We will assist the Customer as necessary, based on valid instructions and available technical capabilities.

4. Data We Collect

4.1 Data You Provide Directly

a. Registration and account creation

DataInformation
Full nameRequired for account identity
Email addressRequired and used as an account identifier or login
UsernameMay be optional, depending on the Service configuration
PasswordStored as a one-way hash, not as readable plain text
Email verification statusVerification time and status can be logged to activate or secure the account

b. User Profile

Telephone number, address, city, province, postal code, country, and profile photo if you choose or are asked to complete it.

c. Company invitation

Email address of the recipient of the invitation, status of the invitation, validity period, and identity of the party sending the invitation.

d. Use of operational features

Data entered into Service modules includes asset data, categories, departments, locations, employees, status, currency, transaction documents, movements, asset write-offs, audits, capitalization, maintenance schedules, Self Monitoring campaigns, depreciation configurations, document numbering, as well as communication templates.

e. Uploaded files

Asset attachments, minutes, photos of asset conditions, transaction supporting documents, and data import files. We may store metadata such as file name, size, file type, upload time, and identity of the uploader.

f. Support and complaints

Information you send when requesting support or submitting a complaint, including a description of the problem, supporting evidence, the estimated time of the incident, and related correspondence. Do not send passwords or OTP codes to us.

4.2 Automatically Collected Data

CategoryExample dataSource
Session data and securityIP Address, user agent, session identifier, activity time, and authentication recordWeb, mobile and API
Authentication tokenAccess token, session token, OTP, and password verification or reset token and their validity periodWeb, mobile and API
Audit trailThe identity of the data creator or modifier, the time of the action, and the history of changes available to the related featureService
Application logsError logs, process queues, notification delivery logs, and technical information for maintenance or investigationsService Infrastructure
Mobile device dataInstallation identifier, device type, operating system, application version, and notification tokenMobile application
Field audit activitiesCheck-in or check-out status, barcode scan results, scan time, and location or department discrepanciesMobile application

4.3 Data from Tokenized Public Pages

Some features can be accessed without signing in via a tokenized link sent to an email address, including:

  • Self Monitoring, to select asset conditions, add notes, and upload attachments if necessary; and
  • Approval confirmation, to respond to submitted documents.

For these features, we may process destination email addresses, related documents or assets, response content, attachments, timestamps, and available technical information for security and audit trails. Recipients must keep the link confidential and ensure that they are authorized to respond.

4.4 Device Access on Mobile Applications

Mobile apps may request the following permissions when related features are used:

PermissionObjectiveNotes
CameraScan an asset's barcode or QR and take a photo of the attachmentThe camera stream can be processed on the device to read the code. Images are sent to the server only when selected or attached by the User.
Gallery or filesSelect a photo or document as an attachmentOnly files selected by the User are processed.
NotificationsDisplay notifications about approvals, maintenance, and invitationsNotifications can be disabled in the device settings, although doing so may prevent some notifications from being received.
Local storageStore sessions, preferences, and copies of certain data to support work when connectivity is limitedWhen a User signs out, the application deletes or disables credentials and active-access data to the extent supported by the system. Some cached data or temporary files may remain until deleted by the operating system or until the application is removed.

4.5 Data We Do Not Collect as a Standard Feature

In its standard configuration, the Service:

  • does not request or use the device's GPS geographic location data;
  • does not access your contact list, SMS, call history, or list of installed applications;
  • does not use advertising cookies or third-party tracking to create marketing profiles; and
  • does not request specific Personal Data, such as health data, biometrics, genetics, criminal records, political views or beliefs, as part of standard functions.

Customers may not enter specific Personal Data through Custom Fields, notes, or attachments unless doing so is strictly necessary, supported by a lawful basis for processing, and protected by appropriate safeguards. If a Customer enters such data, FISETRA processes it as part of Customer Content based on the Customer's instructions.

5. Purpose and Legal Basis for Processing

We process Personal Data based on the purposes and lawful bases described below, including:

Processing PurposesProcessing Basis
Create and manage accounts, verify email, and authenticateImplementation of the agreement
Provide asset management, transaction, approval, maintenance, audit, and depreciation functionsPerformance of the Customer agreement or implementation of Customer instructions
Implement access controls based on roles, departments, locations, and categoriesImplementation of agreements and legitimate interests
Send transactional emails, push notifications, and in-app notificationsImplementation of the agreement and provision of Service functions
Maintain security, prevent abuse, detect intrusions, and investigate incidentsLegitimate interests and legal obligations
Maintain an audit trail and change historyImplementation of agreements, legitimate interests, and legal obligations where applicable
Provides technical support and responds to complaintsImplementation of agreements and legitimate interests
Maintain and improve the quality, reliability and performance of the ServiceLegitimate interests
Fulfill legal obligations and requests of lawful authoritiesLegal obligations
Send marketing communications, if usedConsent or other basis permitted by law

When we act as a Personal Data Processor, the basis for processing Customer Content is determined by the Customer as the Personal Data Controller.

We do not sell Personal Data or Customer Content and do not use Customer Content to train artificial intelligence models.

6. Notifications and Communication

The Service may send the following communications:

a. Transactional emails, such as email verification, user invitations, password resets, approval requests, response confirmations, maintenance reminders, Self Monitoring requests, and security notifications. Some emails are required to run workflows and cannot be disabled while the account or associated feature is in use.

b. Push notifications, which can be sent via Google's Firebase Cloud Messaging. For this purpose, device tokens can be stored and used to deliver notifications. Users can disable notifications via device settings.

c. In-app notifications, including notification content, read status, and read time.

A Company Admin can manage or change some communication templates sent on behalf of the company. The Customer is responsible for content it creates or customizes.

7. Disclosure and Sharing of Data

We may disclose or provide access to Personal Data in the following circumstances.

7.1 Within a company workspace

Data in Customer Content can be viewed and managed by other Users within the same company according to the roles, permissions, and departmental, location, category, and configuration restrictions set by the Company Admin. Company Admins can view, change, delete or revoke access according to their authority.

7.2 To third-party service providers

Provider categoryFunctionData that can be processed
Infrastructure, hosting, and database providersRun the Service and store Service dataService data required for operation
Email service providerSend transactional emailsEmail address, name, notification content, and delivery metadata
Firebase Cloud MessagingSend push notificationsDevice token and notification summary
Object storage provider, if usedStore attachments and mediaFiles and associated metadata
Google Play and Apple App StoreApplication distribution and updatesThe data is processed based on the policies of each app store
Technical support or monitoring provider, if usedAssists with maintenance, security, and troubleshootingLimited technical data or other data required

We limit service providers' access as necessary and strive to ensure that such providers comply with confidentiality, security and processing obligations appropriate to the services provided.

7.3 To public authorities

We may disclose data when required by applicable laws and regulations, court orders, or official requests from public authorities. To the extent permitted by law, we will notify the Customer before disclosing Customer Content.

7.4 Corporate actions

In the event of a merger, separation, takeover, restructuring, dissolution or sale of the business, data can be transferred to the successor party in accordance with applicable law. Notice will be provided when required or when data would be subject to materially different privacy practices.

8. Cross-Border Data Storage and Transfer

Data may be stored or processed on infrastructure in Indonesia and/or other jurisdictions where our service providers operate. Some providers, including notification, email, application distribution or infrastructure providers, may process data outside Indonesia.

If Personal Data is transferred outside Indonesia, we will implement the mechanisms and safeguards required by applicable laws and regulations. These may include an assessment of the level of protection, a data protection agreement, contractual safeguards, and/or consent where required.

9. Data Security

We employ reasonable technical and organizational measures based on the nature of the data and the risks of processing. These steps may include:

  • password storage using a one-way hash;
  • authentication, session management, and tokens with expiry or revocation mechanisms;
  • access control based on roles, permissions, and corporate workspaces;
  • separation and validation of access between company workspaces;
  • communication protection via HTTPS/TLS;
  • internal access restrictions based on need;
  • activity logging and audit trails on features that support it;
  • monitoring, error logging, and interference investigation; and
  • certain backups for the purposes of system recovery and continuity of the Service.

No electronic system is completely risk-free. Customers and Users are responsible for safeguarding passwords, OTPs, devices, email accounts, and Tokenized Public Pages and for immediately reporting suspected unauthorized access through our support channels.

10. Data Retention and Deletion

We retain data for as long as necessary for processing, providing the Service, maintaining security, complying with legal obligations, or resolving disputes. The retention criteria include:

Data typeRetention criteria
Account and profile dataAs long as the account is active and as long as it remains necessary for security, support, legal obligations, audits, or dispute resolution after the account is closed
Customer ContentFor as long as the Service relationship is active, plus 30 calendar days after the subscription ends for retrieval of technically available data, unless otherwise agreed or required by law
Audit trail and change historyAs long as the relevant data is retained or as long as necessary for data integrity, security, audit, compliance or dispute resolution
Logically deleted data (soft delete)As long as it is necessary to maintain ties to historical documents, system integrity, audits, or legal obligations
Technical and security logsAs long as is reasonably necessary for security, maintenance, tampering, auditing, abuse prevention, or legal obligations
Authentication token and public tokenUntil it expires, is revoked, is no longer needed, or is stored in a limited way as part of the security log
Import and export filesFor as long as needed to complete a process, provide results, handle failures, or provide support, after which the files are deleted according to the operational cycle
System backupUntil replaced or deleted according to the backup retention cycle. Backup data is not used for normal operations unless necessary for system recovery

During the 30-day grace period, Customers can export data through available features or request data retrieval assistance that can reasonably and technically be provided. This assistance is available only to the Company Admin or another party whose authority to represent the Customer can be verified. Exports may not include all attachments, history, configurations, or internal system data.

After the grace period, Customer Content may be deleted or anonymized from active systems according to operational deletion cycles, unless it remains necessary for legal obligations, security, investigations, backups, or dispute resolution. Deletion from active systems may not immediately remove every backup copy. Backup copies expire according to the backup retention cycle and are not used for normal operations except for system recovery.

11. Rights of Personal Data Subjects

In accordance with statutory provisions, Personal Data Subjects may have the right to:

  1. obtain information regarding the identity of the Controller, the basis of the processing, the purpose and accountability of the processing;
  2. access and obtain a copy of Personal Data;
  3. update or correct inaccurate Personal Data;
  4. terminate processing, request deletion, or request destruction of Personal Data in accordance with legal requirements;
  5. withdraw consent to processing based on consent;
  6. raise objections to decision making that is fully automated and gives rise to legal consequences or significant impacts;
  7. request a proportional delay or restriction of processing;
  8. obtain Personal Data in a format that is commonly used and can be read by electronic systems, if applicable;
  9. submit a claim for compensation in accordance with legal provisions; and
  10. submit a complaint to the authorized institution or forum.

How to exercise your rights

  • Account and profile data: use the account settings, if available, or contact us using the details in Section 16.
  • Customer Content: because the Customer acts as a Personal Data Controller, submit a request first to the Company Admin. We will assist based on valid Customer instructions.
  • Data on Tokenized Public Pages: You can contact the company that sent the link or contact us with sufficient information to verify.

We may request verification of identity, authority, and additional information before processing a request. For certain rights, the PDP Law sets a maximum period of 3 x 24 hours, including for updates or corrections, access, withdrawal of consent, and delays or restrictions on processing. The applicable period and procedure will depend on the type of request, completeness of verification, our role as Controller or Processor, and applicable legal provisions.

Requests may be denied, limited, or delayed to the extent permitted by law, including when necessary to protect another party's rights, security, legal obligations, audit trail integrity, or dispute resolution. If the request relates to Customer Content, the ultimate decision rests with the Customer as the Personal Data Controller.

12. Cookies and Similar Technologies

The web application uses cookies and browser local storage on a limited basis for the functionality of the Service:

TypeFunctionCharacteristic
Authentication session cookieMaintain and secure login sessionsRequired
Cookies or preference dataSave language, theme, and layout optionsFunctional
Local storageSaves active company context and display preferencesFunctional

We do not use advertising cookies or third-party tracking to create marketing profiles. Deleting cookies or local storage may terminate a login session or prevent some functions from working properly.

In mobile applications, similar functions can be executed via local storage and offline databases as explained in Section 4.4.

13. Child Data

The Service is intended for business use and is not intended for minors. We do not knowingly request children's Personal Data as part of the standard functionality. If you become aware that a child's Personal Data has been entered without an appropriate legal basis or authorization, contact us or the Company Admin so the matter can be verified and addressed.

14. Personal Data Protection Failures

If a Personal Data protection failure affects data under our control, we will respond, investigate, recover, and provide notifications in accordance with applicable law. If required by the PDP Law, written notification will be provided to the affected Personal Data Subject and the authorized institution no later than 3 x 24 hours. The notification will include at least the type of Personal Data disclosed, when and how the incident occurred, and the response and recovery measures taken.

If an incident relates to Customer Content and we act as a Personal Data Processor, we will notify the Customer without unreasonable delay and provide the available information so that the Customer can fulfill its obligations as a Personal Data Controller. We will also provide direct notification when required by law.

15. Privacy Policy Changes

We may update this Privacy Policy to reflect changes in features, processing practices, security, service providers, or legal requirements.

To the extent possible, we will provide notice of material changes by email, through the application, or on the website within a reasonable period before they take effect. Changes do not apply retroactively unless required by law or necessary to address security risks. If a change in processing requires new consent under applicable law, we will request that consent through an appropriate mechanism.

The "Last updated" date at the top will be adjusted when the Privacy Policy is changed.

16. Contact Us

For inquiries, requests for the exercise of the rights of Personal Data Subjects, or complaints regarding data protection:

Name of legal entityPT Idemas Solusindo Sentosa
AddressLevel 23, Plaza Marein, Jl. Jend. Sudirman Kav. 76–78, Jakarta
Data protection and legal email[email protected]
Support email[email protected]
Telephone(021) 3440-592 and (021) 2120-2041
FISETRA websitehttps://fisetra.com

In order for the request to be handled, include enough information to verify the identity, company involved, data type, and details of the request. Do not send passwords or OTP codes.

If you feel that your complaint has not been followed up adequately, you can submit a complaint to the authorized institution or forum in accordance with statutory provisions.

FISETRA

A fixed asset management platform that connects data, activities, and asset history.

PT Idemas Solusindo SentosaLevel 23, Plaza MareinJl. Jend. Sudirman Kav. 76–78Jakarta 12910, Indonesia

Product

Features Pricing On-Premise

Help

FAQ

Company

About Us Contact Privacy Policy Terms & Conditions

Jakarta, Indonesia

© 2026 FISETRA · PT Idemas Solusindo Sentosa