1. Introduction
This Privacy Policy explains how PT Idemas Solusindo Sentosa ("FISETRA", "we") collects, uses, stores, discloses, and protects Personal Data in connection with the use of the FISETRA asset management platform, which includes:
- the web application available at https://fisetra.com;
- FISETRA mobile application for Android and iOS;
- application programming interfaces (APIs) and supporting services; and
- Tokenized Public Pages, such as approval confirmation pages (approval) and Self Monitoring reporting which can be accessed without signing in.
Collectively, these are referred to as the "Service".
This Privacy Policy is a notice regarding Personal Data processing practices in the Service. By creating or activating an account after having the opportunity to read this Privacy Policy, you acknowledge that you understand these practices. Processing of Personal Data is not always based on consent, but may be based on the performance of an agreement, legal obligations, legitimate interests, or other processing grounds permitted by law.
Recipients who only use Tokenized Public Pages without having an account will obtain relevant information regarding the data processed for the response. Use of the page does not automatically make the recipient a Customer or registered User.
This policy was prepared with reference to:
- Law Number 27 of 2022 concerning Protection of Personal Data ("PDP Law");
- Law Number 11 of 2008 as last amended by Law Number 1 of 2024 concerning Electronic Information and Transactions ("ITE Law"); and
- Government Regulation Number 71 of 2019 concerning Implementation of Electronic Systems and Transactions.
2. Definitions
| Term | Definition |
|---|---|
| Personal Data | Data relating to an identified or identifiable natural person, either on its own or in combination with other information, directly or indirectly through electronic or non-electronic systems. |
| Customer / Company | Business entities or organizations that create, manage, or use one or more company workspaces within FISETRA, either in trial, free or paid packages. |
| User | Individuals who have accounts and access the Service, including Company Admins, operators, approvers, and field officers. |
| Company Admin | A User granted administrative authority by a Customer to manage company settings, team members, roles, permissions, and workspaces. |
| Customer Content | All data, documents, files, images, configurations and information entered, uploaded or generated by Customers and their Users through the Service. |
| Tokenized Public Pages | Pages that can be accessed without signing in through tokenized links, including approval and Self Monitoring reporting pages. |
| Personal Data Controller | The party that determines the purposes and exercises control over the processing of Personal Data. |
| Personal Data Processor | The party that processes Personal Data on behalf of the Personal Data Controller. |
3. Roles of the Parties in Data Processing
FISETRA is a multi-tenant Software-as-a-Service (SaaS) platform for business needs. Our role depends on the type of data and the purposes for which it is processed.
3.1 FISETRA as Controller of Personal Data
We act as a Personal Data Controller for the data we need to provide, manage, secure, and support the Service and maintain relationships with Customers and Users, including:
- User account data, such as name, email address, username, password in the form of hash, and email verification status;
- User profile data, such as telephone number, address, city, province, postal code, country, and profile photo;
- technical and security data, such as IP addresses, user agent, session, activity logs, and security logs;
- mobile device data, such as device installation identifiers, device information, and notification tokens; and
- support communications, complaints, and information necessary to manage service relationships.
3.2 FISETRA as Personal Data Processor
We act as a Personal Data Processor for Customer Content entered into a company workspace. In this relationship, the Customer acts as the Personal Data Controller, and we process data based on the Customer's instructions through the use of Service features, the Terms of Use, and settings selected by the Customer.
Customer Content that may contain Personal Data includes:
- employee data registered as person in charge or PIC of assets;
- name of the person responsible, maker, examiner and approver on the transaction document;
- email addresses of notification recipients, copy recipients, user invitations, Self Monitoring requests, and approval requests;
- notes, comments, and photo or document attachments; and
- attributes defined by the Customer through the Custom Fields feature.
The Customer is responsible for ensuring that it has the right, authority, and lawful basis to enter the Personal Data of employees, vendors, and third parties into the Service and to provide any required notices to those parties.
If your account was created by or through an invitation from the company where you work, requests relating to Personal Data in Customer Content should first be submitted to the Company Admin as the representative of the Personal Data Controller. We will assist the Customer as necessary, based on valid instructions and available technical capabilities.
4. Data We Collect
4.1 Data You Provide Directly
a. Registration and account creation
| Data | Information |
|---|---|
| Full name | Required for account identity |
| Email address | Required and used as an account identifier or login |
| Username | May be optional, depending on the Service configuration |
| Password | Stored as a one-way hash, not as readable plain text |
| Email verification status | Verification time and status can be logged to activate or secure the account |
b. User Profile
Telephone number, address, city, province, postal code, country, and profile photo if you choose or are asked to complete it.
c. Company invitation
Email address of the recipient of the invitation, status of the invitation, validity period, and identity of the party sending the invitation.
d. Use of operational features
Data entered into Service modules includes asset data, categories, departments, locations, employees, status, currency, transaction documents, movements, asset write-offs, audits, capitalization, maintenance schedules, Self Monitoring campaigns, depreciation configurations, document numbering, as well as communication templates.
e. Uploaded files
Asset attachments, minutes, photos of asset conditions, transaction supporting documents, and data import files. We may store metadata such as file name, size, file type, upload time, and identity of the uploader.
f. Support and complaints
Information you send when requesting support or submitting a complaint, including a description of the problem, supporting evidence, the estimated time of the incident, and related correspondence. Do not send passwords or OTP codes to us.
4.2 Automatically Collected Data
| Category | Example data | Source |
|---|---|---|
| Session data and security | IP Address, user agent, session identifier, activity time, and authentication record | Web, mobile and API |
| Authentication token | Access token, session token, OTP, and password verification or reset token and their validity period | Web, mobile and API |
| Audit trail | The identity of the data creator or modifier, the time of the action, and the history of changes available to the related feature | Service |
| Application logs | Error logs, process queues, notification delivery logs, and technical information for maintenance or investigations | Service Infrastructure |
| Mobile device data | Installation identifier, device type, operating system, application version, and notification token | Mobile application |
| Field audit activities | Check-in or check-out status, barcode scan results, scan time, and location or department discrepancies | Mobile application |
4.3 Data from Tokenized Public Pages
Some features can be accessed without signing in via a tokenized link sent to an email address, including:
- Self Monitoring, to select asset conditions, add notes, and upload attachments if necessary; and
- Approval confirmation, to respond to submitted documents.
For these features, we may process destination email addresses, related documents or assets, response content, attachments, timestamps, and available technical information for security and audit trails. Recipients must keep the link confidential and ensure that they are authorized to respond.
4.4 Device Access on Mobile Applications
Mobile apps may request the following permissions when related features are used:
| Permission | Objective | Notes |
|---|---|---|
| Camera | Scan an asset's barcode or QR and take a photo of the attachment | The camera stream can be processed on the device to read the code. Images are sent to the server only when selected or attached by the User. |
| Gallery or files | Select a photo or document as an attachment | Only files selected by the User are processed. |
| Notifications | Display notifications about approvals, maintenance, and invitations | Notifications can be disabled in the device settings, although doing so may prevent some notifications from being received. |
| Local storage | Store sessions, preferences, and copies of certain data to support work when connectivity is limited | When a User signs out, the application deletes or disables credentials and active-access data to the extent supported by the system. Some cached data or temporary files may remain until deleted by the operating system or until the application is removed. |
4.5 Data We Do Not Collect as a Standard Feature
In its standard configuration, the Service:
- does not request or use the device's GPS geographic location data;
- does not access your contact list, SMS, call history, or list of installed applications;
- does not use advertising cookies or third-party tracking to create marketing profiles; and
- does not request specific Personal Data, such as health data, biometrics, genetics, criminal records, political views or beliefs, as part of standard functions.
Customers may not enter specific Personal Data through Custom Fields, notes, or attachments unless doing so is strictly necessary, supported by a lawful basis for processing, and protected by appropriate safeguards. If a Customer enters such data, FISETRA processes it as part of Customer Content based on the Customer's instructions.
5. Purpose and Legal Basis for Processing
We process Personal Data based on the purposes and lawful bases described below, including:
| Processing Purposes | Processing Basis |
|---|---|
| Create and manage accounts, verify email, and authenticate | Implementation of the agreement |
| Provide asset management, transaction, approval, maintenance, audit, and depreciation functions | Performance of the Customer agreement or implementation of Customer instructions |
| Implement access controls based on roles, departments, locations, and categories | Implementation of agreements and legitimate interests |
| Send transactional emails, push notifications, and in-app notifications | Implementation of the agreement and provision of Service functions |
| Maintain security, prevent abuse, detect intrusions, and investigate incidents | Legitimate interests and legal obligations |
| Maintain an audit trail and change history | Implementation of agreements, legitimate interests, and legal obligations where applicable |
| Provides technical support and responds to complaints | Implementation of agreements and legitimate interests |
| Maintain and improve the quality, reliability and performance of the Service | Legitimate interests |
| Fulfill legal obligations and requests of lawful authorities | Legal obligations |
| Send marketing communications, if used | Consent or other basis permitted by law |
When we act as a Personal Data Processor, the basis for processing Customer Content is determined by the Customer as the Personal Data Controller.
We do not sell Personal Data or Customer Content and do not use Customer Content to train artificial intelligence models.
6. Notifications and Communication
The Service may send the following communications:
a. Transactional emails, such as email verification, user invitations, password resets, approval requests, response confirmations, maintenance reminders, Self Monitoring requests, and security notifications. Some emails are required to run workflows and cannot be disabled while the account or associated feature is in use.
b. Push notifications, which can be sent via Google's Firebase Cloud Messaging. For this purpose, device tokens can be stored and used to deliver notifications. Users can disable notifications via device settings.
c. In-app notifications, including notification content, read status, and read time.
A Company Admin can manage or change some communication templates sent on behalf of the company. The Customer is responsible for content it creates or customizes.
7. Disclosure and Sharing of Data
We may disclose or provide access to Personal Data in the following circumstances.
7.1 Within a company workspace
Data in Customer Content can be viewed and managed by other Users within the same company according to the roles, permissions, and departmental, location, category, and configuration restrictions set by the Company Admin. Company Admins can view, change, delete or revoke access according to their authority.
7.2 To third-party service providers
| Provider category | Function | Data that can be processed |
|---|---|---|
| Infrastructure, hosting, and database providers | Run the Service and store Service data | Service data required for operation |
| Email service provider | Send transactional emails | Email address, name, notification content, and delivery metadata |
| Firebase Cloud Messaging | Send push notifications | Device token and notification summary |
| Object storage provider, if used | Store attachments and media | Files and associated metadata |
| Google Play and Apple App Store | Application distribution and updates | The data is processed based on the policies of each app store |
| Technical support or monitoring provider, if used | Assists with maintenance, security, and troubleshooting | Limited technical data or other data required |
We limit service providers' access as necessary and strive to ensure that such providers comply with confidentiality, security and processing obligations appropriate to the services provided.
7.3 To public authorities
We may disclose data when required by applicable laws and regulations, court orders, or official requests from public authorities. To the extent permitted by law, we will notify the Customer before disclosing Customer Content.
7.4 Corporate actions
In the event of a merger, separation, takeover, restructuring, dissolution or sale of the business, data can be transferred to the successor party in accordance with applicable law. Notice will be provided when required or when data would be subject to materially different privacy practices.
8. Cross-Border Data Storage and Transfer
Data may be stored or processed on infrastructure in Indonesia and/or other jurisdictions where our service providers operate. Some providers, including notification, email, application distribution or infrastructure providers, may process data outside Indonesia.
If Personal Data is transferred outside Indonesia, we will implement the mechanisms and safeguards required by applicable laws and regulations. These may include an assessment of the level of protection, a data protection agreement, contractual safeguards, and/or consent where required.
9. Data Security
We employ reasonable technical and organizational measures based on the nature of the data and the risks of processing. These steps may include:
- password storage using a one-way hash;
- authentication, session management, and tokens with expiry or revocation mechanisms;
- access control based on roles, permissions, and corporate workspaces;
- separation and validation of access between company workspaces;
- communication protection via HTTPS/TLS;
- internal access restrictions based on need;
- activity logging and audit trails on features that support it;
- monitoring, error logging, and interference investigation; and
- certain backups for the purposes of system recovery and continuity of the Service.
No electronic system is completely risk-free. Customers and Users are responsible for safeguarding passwords, OTPs, devices, email accounts, and Tokenized Public Pages and for immediately reporting suspected unauthorized access through our support channels.
10. Data Retention and Deletion
We retain data for as long as necessary for processing, providing the Service, maintaining security, complying with legal obligations, or resolving disputes. The retention criteria include:
| Data type | Retention criteria |
|---|---|
| Account and profile data | As long as the account is active and as long as it remains necessary for security, support, legal obligations, audits, or dispute resolution after the account is closed |
| Customer Content | For as long as the Service relationship is active, plus 30 calendar days after the subscription ends for retrieval of technically available data, unless otherwise agreed or required by law |
| Audit trail and change history | As long as the relevant data is retained or as long as necessary for data integrity, security, audit, compliance or dispute resolution |
| Logically deleted data (soft delete) | As long as it is necessary to maintain ties to historical documents, system integrity, audits, or legal obligations |
| Technical and security logs | As long as is reasonably necessary for security, maintenance, tampering, auditing, abuse prevention, or legal obligations |
| Authentication token and public token | Until it expires, is revoked, is no longer needed, or is stored in a limited way as part of the security log |
| Import and export files | For as long as needed to complete a process, provide results, handle failures, or provide support, after which the files are deleted according to the operational cycle |
| System backup | Until replaced or deleted according to the backup retention cycle. Backup data is not used for normal operations unless necessary for system recovery |
During the 30-day grace period, Customers can export data through available features or request data retrieval assistance that can reasonably and technically be provided. This assistance is available only to the Company Admin or another party whose authority to represent the Customer can be verified. Exports may not include all attachments, history, configurations, or internal system data.
After the grace period, Customer Content may be deleted or anonymized from active systems according to operational deletion cycles, unless it remains necessary for legal obligations, security, investigations, backups, or dispute resolution. Deletion from active systems may not immediately remove every backup copy. Backup copies expire according to the backup retention cycle and are not used for normal operations except for system recovery.
11. Rights of Personal Data Subjects
In accordance with statutory provisions, Personal Data Subjects may have the right to:
- obtain information regarding the identity of the Controller, the basis of the processing, the purpose and accountability of the processing;
- access and obtain a copy of Personal Data;
- update or correct inaccurate Personal Data;
- terminate processing, request deletion, or request destruction of Personal Data in accordance with legal requirements;
- withdraw consent to processing based on consent;
- raise objections to decision making that is fully automated and gives rise to legal consequences or significant impacts;
- request a proportional delay or restriction of processing;
- obtain Personal Data in a format that is commonly used and can be read by electronic systems, if applicable;
- submit a claim for compensation in accordance with legal provisions; and
- submit a complaint to the authorized institution or forum.
How to exercise your rights
- Account and profile data: use the account settings, if available, or contact us using the details in Section 16.
- Customer Content: because the Customer acts as a Personal Data Controller, submit a request first to the Company Admin. We will assist based on valid Customer instructions.
- Data on Tokenized Public Pages: You can contact the company that sent the link or contact us with sufficient information to verify.
We may request verification of identity, authority, and additional information before processing a request. For certain rights, the PDP Law sets a maximum period of 3 x 24 hours, including for updates or corrections, access, withdrawal of consent, and delays or restrictions on processing. The applicable period and procedure will depend on the type of request, completeness of verification, our role as Controller or Processor, and applicable legal provisions.
Requests may be denied, limited, or delayed to the extent permitted by law, including when necessary to protect another party's rights, security, legal obligations, audit trail integrity, or dispute resolution. If the request relates to Customer Content, the ultimate decision rests with the Customer as the Personal Data Controller.
12. Cookies and Similar Technologies
The web application uses cookies and browser local storage on a limited basis for the functionality of the Service:
| Type | Function | Characteristic |
|---|---|---|
| Authentication session cookie | Maintain and secure login sessions | Required |
| Cookies or preference data | Save language, theme, and layout options | Functional |
| Local storage | Saves active company context and display preferences | Functional |
We do not use advertising cookies or third-party tracking to create marketing profiles. Deleting cookies or local storage may terminate a login session or prevent some functions from working properly.
In mobile applications, similar functions can be executed via local storage and offline databases as explained in Section 4.4.
13. Child Data
The Service is intended for business use and is not intended for minors. We do not knowingly request children's Personal Data as part of the standard functionality. If you become aware that a child's Personal Data has been entered without an appropriate legal basis or authorization, contact us or the Company Admin so the matter can be verified and addressed.
14. Personal Data Protection Failures
If a Personal Data protection failure affects data under our control, we will respond, investigate, recover, and provide notifications in accordance with applicable law. If required by the PDP Law, written notification will be provided to the affected Personal Data Subject and the authorized institution no later than 3 x 24 hours. The notification will include at least the type of Personal Data disclosed, when and how the incident occurred, and the response and recovery measures taken.
If an incident relates to Customer Content and we act as a Personal Data Processor, we will notify the Customer without unreasonable delay and provide the available information so that the Customer can fulfill its obligations as a Personal Data Controller. We will also provide direct notification when required by law.
15. Privacy Policy Changes
We may update this Privacy Policy to reflect changes in features, processing practices, security, service providers, or legal requirements.
To the extent possible, we will provide notice of material changes by email, through the application, or on the website within a reasonable period before they take effect. Changes do not apply retroactively unless required by law or necessary to address security risks. If a change in processing requires new consent under applicable law, we will request that consent through an appropriate mechanism.
The "Last updated" date at the top will be adjusted when the Privacy Policy is changed.
16. Contact Us
For inquiries, requests for the exercise of the rights of Personal Data Subjects, or complaints regarding data protection:
| Name of legal entity | PT Idemas Solusindo Sentosa |
| Address | Level 23, Plaza Marein, Jl. Jend. Sudirman Kav. 76–78, Jakarta |
| Data protection and legal email | [email protected] |
| Support email | [email protected] |
| Telephone | (021) 3440-592 and (021) 2120-2041 |
| FISETRA website | https://fisetra.com |
In order for the request to be handled, include enough information to verify the identity, company involved, data type, and details of the request. Do not send passwords or OTP codes.
If you feel that your complaint has not been followed up adequately, you can submit a complaint to the authorized institution or forum in accordance with statutory provisions.