OCTONEXUS PRIVACY POLICY

Effective Date: July 21st 2026
Last Updated: July 21st 2026

1. Introduction

This Privacy Policy explains how PT Gerbang Teknologi Digital, operating under the brand OctoNexus (“OctoNexus,” “we,” “us,” or “our”) collects, uses, stores, discloses, transfers, and protects Personal Data through our websites, platforms, mobile applications, application programming interfaces, and related support services.

This Privacy Policy applies to the following OctoNexus products and services:

  1. NexVoucher – a digital voucher requisition, approval, issuance, delivery, redemption, and management platform;
  2. NexHourlyAid – a workforce requisition, scheduling, attendance, biometric verification, payroll-support, and daily-worker management platform;
  3. NexTagTrack – an asset, inventory, tag, RFID, barcode, location, assignment, and tracking platform;
  4. NexSign – a digital form, document workflow, electronic signature, approval, audit-trail, and document-management platform;
  5. NexContract – a proposal, quotation, contract, agreement, invoice, approval, and commercial-document management platform; and
  6. any associated OctoNexus websites, dashboards, integrations, APIs, support channels, and services collectively referred to as the “Services.”

This Privacy Policy is intended to support compliance with applicable data-protection laws, including Indonesia’s Law No. 27 of 2022 concerning Personal Data Protection (“Indonesia PDP Law”) and, where applicable, the European Union General Data Protection Regulation, Regulation (EU) 2016/679 (“GDPR”). The Indonesia PDP Law regulates, among other matters, the rights of Personal Data Subjects, lawful processing, controller and processor obligations, data transfers, dispute resolution, and sanctions. The GDPR regulates the processing and transfer of Personal Data relating to individuals in the European Union and European Economic Area.

2. Scope of This Privacy Policy

This Privacy Policy applies to Personal Data processed when:

  • a business subscribes to, purchases, evaluates, or uses the Services;
  • an authorized user creates or accesses an OctoNexus account;
  • an organization enters employee, contractor, customer, guest, supplier, asset-holder, signatory, or other individual information into the Services;
  • an individual receives a voucher, document, contract, approval request, notification, or electronic-signature request through the Services;
  • a user contacts OctoNexus for technical support, training, billing, implementation, or other assistance;
  • an individual visits an OctoNexus website or interacts with our communications; or
  • the Services exchange information with an authorized third-party integration.

This Privacy Policy does not govern the independent privacy practices of our business customers, external websites, third-party applications, payment providers, messaging platforms, biometric-device manufacturers, cloud-service providers acting independently, or other parties outside OctoNexus’s control.

3. Definitions

For purposes of this Privacy Policy:

“Customer” means the hotel, company, organization, institution, property, employer, or other legal entity that subscribes to or uses the Services.

“Authorized User” means an employee, contractor, administrator, approver, manager, operator, or other person authorized by a Customer to access the Services.

“Personal Data” means information relating to an identified or identifiable natural person, whether identified directly or indirectly, separately or in combination with other information.

“Data Subject” means the individual to whom Personal Data relates.

“Processing” means any operation performed on Personal Data, including collection, recording, organization, storage, adaptation, retrieval, consultation, use, disclosure, transfer, restriction, deletion, or destruction.

“Controller” means the party that determines the purposes and means of Processing Personal Data.

“Processor” means the party that Processes Personal Data on behalf of a Controller.

“Sensitive Personal Data” means Personal Data that receives enhanced protection under applicable law, which may include biometric, health, financial, identification, criminal, genetic, or other specially protected information.

4. Our Role as Controller or Processor

4.1 Customer Data

For Personal Data entered into or generated through the Services by or on behalf of a Customer, the Customer will ordinarily act as the Controller, and OctoNexus will ordinarily act as its Processor or service provider.

Examples include:

  • employee data entered into NexHourlyAid;
  • guest or recipient information entered into NexVoucher;
  • employee, custodian, or asset-holder information entered into NexTagTrack;
  • signatory, approver, and document-recipient information entered into NexSign;
  • customer, supplier, client, signatory, and contact information entered into NexContract.

In these circumstances, the Customer determines why the Personal Data is processed, which individuals are included, how long information should be retained, which users may access it, and which lawful basis applies.

Requests concerning Customer Data should normally be submitted first to the relevant Customer. We will reasonably assist Customers in responding to valid Data Subject requests, subject to applicable law and our contractual arrangements.

4.2 OctoNexus Account and Operational Data

OctoNexus may act as a Controller for Personal Data that we process for our own legitimate business purposes, including:

  • account registration and authentication;
  • subscription administration;
  • customer relationship management;
  • service security and fraud prevention;
  • system monitoring;
  • billing and payment administration;
  • support communications;
  • legal compliance;
  • service analytics; and
  • product and service improvement.

4.3 Joint or Separate Responsibilities

In limited circumstances, OctoNexus and a Customer or third party may each act as an independent Controller or, where agreed in writing and required by law, as joint Controllers. The applicable agreement will determine the parties’ respective responsibilities.

5. Personal Data We Collect

Depending on the Services used and the Customer’s configuration, we may process the following categories of Personal Data.

5.1 Identity and Profile Information

This may include:

  • full name;
  • username;
  • profile photograph;
  • employee or personnel number;
  • national identification number or other identification information;
  • job title;
  • department;
  • employer or property;
  • signature;
  • date of birth, where required;
  • gender, where lawfully required;
  • nationality; and
  • other profile or identification details entered by the Customer.

Customers should avoid entering national identification numbers or other Sensitive Personal Data unless they have a valid legal basis and such information is genuinely necessary.

5.2 Contact Information

This may include:

  • business or personal email address;
  • telephone or mobile number;
  • postal address;
  • company address;
  • messaging-platform identifier; and
  • emergency or alternative contact details.

5.3 Employment and Workforce Information

NexHourlyAid may process:

  • employee or daily-worker status;
  • department and section;
  • position or title;
  • work schedule;
  • roster;
  • working hours;
  • attendance;
  • overtime;
  • leave or absence information;
  • check-in and check-out records;
  • payroll-support calculations;
  • rate or compensation information;
  • joining date;
  • employment status;
  • bank-account information, where configured by the Customer; and
  • managerial approvals and comments.

5.4 Biometric and Attendance Information

Where NexHourlyAid is integrated with biometric attendance devices, the Services may process:

  • biometric-template identifiers;
  • facial-recognition or fingerprint-template references;
  • device enrollment status;
  • attendance-verification results;
  • device identifiers;
  • timestamped attendance records; and
  • related verification logs.

Unless expressly agreed otherwise, OctoNexus does not need to receive or store raw fingerprint images. Customers must configure biometric integrations in accordance with applicable law, provide required notices, establish a valid lawful basis, and implement appropriate safeguards.

5.5 Voucher and Guest Information

NexVoucher may process:

  • voucher-recipient name;
  • guest name;
  • email address;
  • telephone number;
  • reservation or stay information;
  • voucher number or code;
  • voucher type;
  • benefit or entitlement;
  • validity period;
  • redemption status;
  • outlet or redemption location;
  • approver information;
  • approval history;
  • notes;
  • delivery records; and
  • transaction and audit information.

5.6 Asset and Tracking Information

NexTagTrack may process:

  • assigned employee or custodian;
  • asset owner or responsible person;
  • asset serial number;
  • barcode, RFID, NFC, QR-code, or tag identifier;
  • asset description;
  • asset photograph;
  • department;
  • property;
  • physical location;
  • movement history;
  • handover details;
  • maintenance or inspection information;
  • registration and verification logs; and
  • date, time, and user information associated with asset actions.

Asset-location information generally relates to assets. However, it may constitute Personal Data where it identifies or can reasonably be associated with an individual.

5.7 Electronic Signature and Document Information

NexSign may process:

  • document contents;
  • form responses;
  • signatures or signature images;
  • initials;
  • signatory and approver identity;
  • email address;
  • telephone number;
  • job title and department;
  • approval decision;
  • comments;
  • attachments;
  • date and time of signing;
  • IP address;
  • device information;
  • browser information;
  • approximate location, where enabled and permitted;
  • authentication records;
  • document hash or verification data; and
  • audit-trail information.

5.8 Contract and Commercial Information

NexContract may process:

  • company and contact details;
  • proposal and quotation information;
  • contractual terms;
  • purchase-order references;
  • product and service information;
  • pricing;
  • tax or billing information;
  • invoices;
  • payment status;
  • approval information;
  • signatory information;
  • correspondence;
  • attachments; and
  • document history.

5.9 Account and Authentication Information

This may include:

  • account identifier;
  • username;
  • encrypted or hashed password;
  • role and permission;
  • organization or tenant identifier;
  • authentication token;
  • login history;
  • failed-login attempts;
  • password-reset status;
  • session information;
  • multi-factor authentication information;
  • device fingerprint or device-session details; and
  • account activity.

We do not store passwords in readable plain-text form.

5.10 Device and Technical Information

We may automatically collect:

  • IP address;
  • browser type;
  • operating system;
  • device type;
  • mobile-device identifier;
  • screen or application version;
  • language;
  • time zone;
  • referring URL;
  • access date and time;
  • API request information;
  • error reports;
  • application logs;
  • performance data;
  • crash information; and
  • security-event information.

5.11 Support and Communication Information

When users contact us, we may process:

  • name and contact details;
  • company or property;
  • support-ticket content;
  • chat or email correspondence;
  • screenshots;
  • uploaded files;
  • call notes;
  • issue history;
  • training records; and
  • feedback.

Users should remove unnecessary Personal Data from support materials before submitting them.

5.12 Billing and Subscription Information

This may include:

  • billing contact;
  • billing address;
  • tax information;
  • invoice details;
  • payment status;
  • bank-transfer reference;
  • subscription package;
  • transaction history; and
  • purchase-order information.

Where payment is processed by an independent payment provider or bank, OctoNexus may receive confirmation and transaction-reference information without receiving complete payment-card credentials.

5.13 Cookies and Similar Technologies

Our websites and web applications may use:

  • strictly necessary cookies;
  • session cookies;
  • authentication cookies;
  • security cookies;
  • preference cookies;
  • analytics technologies; and
  • local storage.

Where required by law, non-essential cookies will be used only after obtaining appropriate consent.

6. Sources of Personal Data

We may obtain Personal Data:

  • directly from the Data Subject;
  • from the Customer;
  • from an Authorized User or administrator;
  • from the Data Subject’s employer;
  • from another user involved in a workflow;
  • from integrated property-management, human-resources, payroll, messaging, identity, biometric, document, or asset-management systems;
  • from devices connected to the Services;
  • from publicly available company information;
  • from service providers acting on our behalf; and
  • automatically through the use of the Services.

Where a Customer provides Personal Data concerning another individual, the Customer is responsible for ensuring that the collection and disclosure are lawful and that any required privacy notice has been provided.

7. Purposes of Processing

We may process Personal Data for the following purposes:

7.1 Providing the Services

To:

  • create and manage accounts;
  • authenticate users;
  • configure Customer environments;
  • provide product functionality;
  • process workflows;
  • issue, deliver, validate, and redeem vouchers;
  • manage workforce requisitions, rosters, attendance, and payroll-support calculations;
  • register, identify, assign, locate, and track assets;
  • create, route, approve, sign, verify, and store documents;
  • prepare and manage proposals, contracts, quotations, and invoices;
  • send operational notifications;
  • maintain audit trails; and
  • integrate with authorized third-party systems.

7.2 Security and Fraud Prevention

To:

  • verify identity and access;
  • prevent unauthorized access;
  • detect fraud or misuse;
  • investigate suspicious activity;
  • monitor system integrity;
  • enforce permissions;
  • maintain security logs;
  • protect accounts and data;
  • prevent duplicate or invalid transactions; and
  • respond to security incidents.

7.3 Customer Support and Implementation

To:

  • implement and configure the Services;
  • migrate authorized Customer data;
  • provide training;
  • troubleshoot errors;
  • answer questions;
  • respond to support requests;
  • test fixes;
  • manage service incidents; and
  • communicate scheduled maintenance or material service changes.

7.4 Administration and Billing

To:

  • manage subscriptions;
  • prepare quotations and invoices;
  • process and reconcile payments;
  • manage renewals;
  • administer agreements;
  • maintain business records; and
  • communicate with Customer representatives.

7.5 Service Improvement

To:

  • analyze system performance;
  • understand feature usage;
  • identify errors;
  • improve usability;
  • develop new features;
  • perform testing;
  • generate aggregated statistics; and
  • improve security and reliability.

Where reasonably possible, information used for analytics and improvement will be aggregated, anonymized, or de-identified.

7.6 Legal and Regulatory Compliance

To:

  • comply with applicable laws;
  • respond to lawful government or court requests;
  • establish, exercise, or defend legal claims;
  • enforce contractual rights;
  • maintain legally required records;
  • investigate violations; and
  • protect the rights, safety, and property of OctoNexus, Customers, users, and others.

7.7 Business Communications

We may communicate with Customer contacts concerning:

  • subscriptions;
  • renewals;
  • service updates;
  • product announcements;
  • training;
  • relevant OctoNexus services; and
  • events or promotions.

Recipients may opt out of non-essential marketing communications. Service, security, billing, contractual, and administrative communications may continue where necessary.

8. Lawful Bases for Processing

Where the GDPR or another law requiring a lawful basis applies, we rely on one or more of the following:

8.1 Performance of a Contract

Processing necessary to:

  • provide the Services;
  • create and manage accounts;
  • fulfill subscription obligations;
  • provide requested support; and
  • administer contractual relationships.

8.2 Legitimate Interests

Processing necessary for our or a third party’s legitimate interests, including:

  • protecting the Services;
  • preventing fraud;
  • maintaining operational security;
  • improving service performance;
  • administering customer relationships;
  • enforcing agreements;
  • maintaining audit records; and
  • conducting proportionate business analytics.

We consider the potential effect on individuals before relying on legitimate interests.

8.3 Consent

We may rely on consent where required, including for:

  • certain marketing activities;
  • non-essential cookies;
  • optional device permissions;
  • certain biometric processing;
  • optional location collection; or
  • other processing for which applicable law requires consent.

Consent may be withdrawn at any time, without affecting the lawfulness of processing carried out before withdrawal.

8.4 Legal Obligation

We may process Personal Data where necessary to comply with legal, tax, accounting, security, regulatory, or judicial obligations.

8.5 Protection of Vital Interests

In exceptional circumstances, we may process Personal Data where necessary to protect an individual’s life, health, or safety.

8.6 Legal Claims and Other Permitted Grounds

We may process Personal Data where necessary for legal claims or where another lawful ground is available under applicable law.

For Customer Data, the Customer is responsible for selecting and documenting the appropriate lawful basis unless otherwise agreed in writing.

9. Sensitive Personal Data

Certain Services may process Sensitive Personal Data, particularly biometric, financial, identification, employment, or signature-related information.

We process Sensitive Personal Data only where:

  • the Customer has authorized the processing;
  • the information is necessary for the configured functionality;
  • an appropriate lawful basis or exception applies;
  • required notices or consents have been obtained;
  • access is appropriately restricted; and
  • enhanced security measures are implemented.

Customers must not use the Services to collect Sensitive Personal Data that is excessive, irrelevant, unlawful, or unnecessary for the intended business purpose.

10. Biometric Data

Where a Customer enables biometric attendance or identity-verification features:

  1. the Customer is responsible for determining whether biometric processing is necessary and proportionate;
  2. the Customer must provide all notices required by applicable law;
  3. the Customer must obtain explicit consent where consent is the required legal basis;
  4. the Customer must provide a lawful alternative where required;
  5. biometric information must not be used for unrelated purposes;
  6. access must be limited to authorized personnel;
  7. biometric information must be retained only for as long as necessary; and
  8. biometric templates must be deleted or deactivated when the applicable purpose ends, subject to legal-retention obligations.

Biometric functionality may depend on third-party devices or systems. The Customer should separately review the privacy and security terms applicable to those devices and providers.

11. Automated Processing

The Services may automate administrative functions such as:

  • routing approvals;
  • calculating attendance duration;
  • calculating payroll-support values;
  • identifying pending tasks;
  • validating voucher status;
  • matching user roles;
  • generating document numbers;
  • detecting duplicate activity;
  • producing reminders; and
  • applying workflow rules configured by the Customer.

Unless expressly stated otherwise, OctoNexus does not use Customer Data to make solely automated decisions that produce legal or similarly significant effects on individuals without meaningful human involvement.

Customers are responsible for reviewing automated outputs before relying on them for employment, payroll, disciplinary, contractual, financial, or other significant decisions.

12. How We Disclose Personal Data

We may disclose Personal Data to the following recipients.

12.1 Customers and Authorized Users

Personal Data may be visible to Customer administrators, approvers, managers, human-resources personnel, finance personnel, department representatives, auditors, or other users according to configured roles and permissions.

12.2 Service Providers and Subprocessors

We may use third parties to provide:

  • cloud infrastructure;
  • database hosting;
  • file storage;
  • email delivery;
  • messaging delivery;
  • monitoring;
  • analytics;
  • error tracking;
  • cybersecurity;
  • customer support;
  • backup;
  • document processing;
  • identity verification; and
  • professional services.

These providers may process Personal Data only for authorized purposes and subject to contractual confidentiality, security, and data-protection obligations.

A current list of material subprocessors may be made available at [SUBPROCESSOR PAGE URL] or upon written request.

12.3 Customer-Authorized Integrations

We may disclose Personal Data to third-party systems when:

  • the Customer enables an integration;
  • a user initiates a transfer;
  • the disclosure is needed to perform a requested workflow; or
  • the Customer instructs us to do so.

Examples may include hotel systems, human-resources systems, payroll systems, biometric devices, email services, messaging platforms, cloud storage, or identity providers.

The third party’s own privacy terms may apply after data is transferred to it.

12.4 Professional Advisers

We may disclose Personal Data to lawyers, auditors, accountants, insurers, consultants, and other professional advisers where reasonably necessary and subject to confidentiality obligations.

12.5 Authorities and Legal Recipients

We may disclose Personal Data where reasonably necessary to:

  • comply with applicable law;
  • respond to a valid court order, warrant, subpoena, or government request;
  • investigate fraud, abuse, or security incidents;
  • protect legal rights;
  • protect the safety of individuals; or
  • establish, exercise, or defend legal claims.

Where legally permitted, we will seek to ensure that requests are valid, proportionate, and appropriately limited.

12.6 Corporate Transactions

Personal Data may be disclosed as part of a merger, acquisition, financing, restructuring, asset sale, due diligence process, insolvency, or similar corporate transaction. We will take reasonable steps to require continued protection of the information.

12.7 Aggregated or De-identified Information

We may disclose information that has been aggregated or de-identified so that it no longer reasonably identifies an individual.

13. International Data Transfers

OctoNexus, its Customers, and its service providers may process Personal Data in Indonesia, Singapore, the European Union, the United States, or other countries in which approved infrastructure or service providers operate.

Where Personal Data is transferred internationally, we will implement safeguards required by applicable law. Depending on the circumstances, these safeguards may include:

  • a legally recognized adequacy mechanism;
  • contractual data-protection clauses;
  • the European Commission’s Standard Contractual Clauses;
  • supplementary technical and organizational measures;
  • binding corporate rules, where applicable;
  • consent, where legally permitted; or
  • another valid transfer mechanism.

For transfers subject to the GDPR, the GDPR regulates transfers of Personal Data outside the EU or EEA and provides mechanisms intended to preserve an appropriate level of protection.

Customers are responsible for ensuring that their instructions to transfer or disclose Personal Data internationally comply with applicable law.

14. Data Retention

We retain Personal Data only for as long as reasonably necessary for the purposes described in this Privacy Policy, including to:

  • provide the Services;
  • fulfill Customer instructions;
  • maintain security and audit records;
  • comply with legal, tax, accounting, and regulatory obligations;
  • resolve disputes;
  • enforce agreements;
  • maintain backups; and
  • establish, exercise, or defend legal claims.

Retention periods may vary according to:

  • the relevant OctoNexus product;
  • Customer configuration;
  • contractual requirements;
  • the type and sensitivity of data;
  • applicable laws;
  • the duration of the Customer relationship;
  • active disputes or investigations; and
  • technical backup cycles.

Unless a different period is agreed:

  • active Customer Data is generally retained for the duration of the subscription;
  • account and security logs may be retained for [12–24 months];
  • support records may be retained for [3–5 years];
  • billing and contractual records may be retained for the legally required accounting or tax period;
  • deleted production data may remain in restricted backups for up to [30–90 days]; and
  • Customer Data may be deleted or returned within [30–90 days] following termination, subject to legal obligations, backup cycles, and written contractual terms.

Customers are responsible for configuring appropriate retention periods within the Services where retention controls are available.

15. Data Security

We implement reasonable and appropriate technical and organizational safeguards designed to protect Personal Data against:

  • unauthorized access;
  • unlawful processing;
  • accidental loss;
  • destruction;
  • alteration;
  • disclosure;
  • misuse; and
  • unavailability.

Depending on the Service and risk level, these measures may include:

  • encrypted network communications;
  • encryption at rest where supported;
  • password hashing;
  • role-based access controls;
  • tenant or Customer data separation;
  • least-privilege access;
  • session controls;
  • audit and activity logs;
  • authentication controls;
  • security monitoring;
  • backup and recovery procedures;
  • secure software-development practices;
  • vulnerability remediation;
  • restricted production access;
  • confidentiality obligations;
  • incident-response procedures; and
  • service-provider risk management.

The GDPR requires controllers and processors to implement security appropriate to the risk, taking into account factors such as available technology, implementation costs, the nature and scope of processing, and risks to individuals.

No electronic system is completely secure. Customers and users must also protect their credentials, use secure devices, apply appropriate permissions, and immediately report suspected unauthorized access.

16. Personal Data Breaches

A Personal Data breach may include accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to Personal Data.

When we become aware of a confirmed Personal Data breach affecting Customer Data, we will:

  • investigate the incident;
  • take reasonable steps to contain and mitigate it;
  • preserve relevant evidence;
  • assess the nature and potential impact;
  • notify the affected Customer without undue delay where required;
  • provide reasonably available information to support the Customer’s legal obligations; and
  • notify authorities or Data Subjects where OctoNexus is legally responsible for doing so.

Customers remain responsible for regulatory and Data Subject notifications where they act as Controller, unless otherwise required by law or agreed in writing.

17. Data Subject Rights

Subject to applicable law, a Data Subject may have rights to:

  • receive information about the Processing of Personal Data;
  • obtain confirmation whether Personal Data is being processed;
  • access Personal Data;
  • obtain a copy of Personal Data;
  • correct inaccurate or incomplete Personal Data;
  • request deletion or erasure;
  • withdraw consent;
  • object to certain Processing;
  • request restriction or suspension of Processing;
  • request data portability;
  • object to direct marketing;
  • request review of certain automated decisions;
  • lodge a complaint with a competent authority;
  • seek compensation or other remedies; and
  • exercise other rights available under applicable law.

Indonesia’s PDP Law provides rights relating to information, access, correction, deletion, withdrawal of consent, objection to certain automated decisions, restriction or postponement of processing, compensation, and obtaining Personal Data in a commonly readable electronic form.

GDPR rights include rights concerning transparency, access, correction, erasure, restriction, portability, objection, and certain automated decision-making.

Rights are not absolute and may be limited where an exception applies, including where retention is required by law or necessary for legal claims.

18. How to Exercise Privacy Rights

Where Personal Data was entered into the Services by a Customer, the Data Subject should first contact that Customer. Examples include contacting:

  • the individual’s employer;
  • the relevant hotel or property;
  • the organization that issued the voucher;
  • the organization that requested the signature;
  • the organization that created the contract; or
  • the organization responsible for the relevant asset record.

OctoNexus may forward a request to the relevant Customer or require Customer authorization before making changes to Customer Data.

For Personal Data controlled directly by OctoNexus, requests may be submitted to:

Privacy Contact: [PRIVACY CONTACT OR DATA PROTECTION OFFICER]
Email: [[email protected]]
Address: PT Gerbang Teknologi Digital, Jl. Sukagalih No. 105, Sukajadi, Bandung, Jawa Barat 40162, Indonesia
Telephone: [TELEPHONE NUMBER]

The request should provide enough information to:

  • identify the requester;
  • identify the relevant Customer or account;
  • locate the relevant Personal Data; and
  • understand the requested action.

We may request reasonable identity verification before processing a request. We will respond within the period required by applicable law.

19. Complaints

Individuals may contact us using the details above if they have questions or complaints about our privacy practices.

Where the GDPR applies, an individual may also lodge a complaint with the data-protection supervisory authority in the country where the individual lives, works, or believes an infringement occurred.

Where Indonesia’s PDP Law applies, an individual may exercise complaint, dispute-resolution, or other rights through the competent Indonesian authority or legal process as provided by applicable law.

We encourage individuals to contact us first so that we can attempt to address the concern directly.

20. Children’s Personal Data

The Services are designed primarily for use by businesses and their authorized personnel. They are not intended for independent use by children.

Customers must not submit children’s Personal Data unless:

  • the information is necessary for a lawful business purpose;
  • the Customer has a valid legal basis;
  • any required parental or guardian authorization has been obtained; and
  • appropriate safeguards have been implemented.

Where we learn that children’s Personal Data has been collected unlawfully, we will take reasonable steps to delete or restrict it.

21. User Responsibilities

Customers and Authorized Users must:

  • process Personal Data lawfully, fairly, and transparently;
  • provide required privacy notices;
  • obtain required consent or other lawful authorization;
  • collect only necessary information;
  • maintain accurate records;
  • assign appropriate permissions;
  • protect account credentials;
  • avoid shared user accounts where individual accountability is required;
  • promptly remove access for former personnel;
  • configure retention appropriately;
  • avoid uploading unlawful or irrelevant Sensitive Personal Data;
  • review audit logs and security alerts;
  • comply with Data Subject requests;
  • comply with applicable employment and biometric laws; and
  • notify OctoNexus promptly of suspected security incidents.

Customers must not use the Services to:

  • unlawfully monitor individuals;
  • discriminate against individuals;
  • make unlawful employment decisions;
  • collect excessive biometric information;
  • create unlawful profiles;
  • distribute confidential information without authority;
  • impersonate another person;
  • falsify signatures or approvals;
  • evade legal obligations; or
  • conduct unlawful activities.

22. Third-Party Services and Integrations

The Services may contain links to or integrations with third-party services. These may include:

  • email providers;
  • messaging platforms;
  • cloud-storage providers;
  • biometric attendance devices;
  • property-management systems;
  • payroll systems;
  • human-resources systems;
  • identity providers;
  • analytics providers;
  • electronic-signature technologies;
  • payment services; and
  • document or asset-management systems.

OctoNexus is not responsible for a third party’s independent Processing activities. Customers should review the privacy and security terms of each third-party service before enabling it.

23. API Use

Customers may use OctoNexus APIs to exchange Personal Data with approved systems. API users must:

  • use secure authentication;
  • maintain the confidentiality of API keys and tokens;
  • restrict access to authorized personnel;
  • transmit only necessary data;
  • validate requests and responses;
  • monitor for misuse;
  • rotate compromised credentials;
  • comply with rate limits and security requirements; and
  • ensure that connected systems provide appropriate protection.

OctoNexus may suspend API access that presents a material security, legal, or operational risk.

24. Artificial Intelligence and Machine Learning

Some OctoNexus services may in the future include artificial-intelligence-assisted functions, such as document classification, message assistance, anomaly detection, workflow recommendations, summarization, or chatbot features.

Unless separately disclosed and contractually agreed:

  • Customer Data will not be used to train a publicly available general-purpose artificial-intelligence model;
  • AI outputs should be reviewed by an authorized human;
  • AI outputs should not be treated as legal, employment, payroll, financial, or professional advice;
  • Customers must not rely solely on AI output for decisions producing legal or similarly significant effects; and
  • additional notices may be provided for particular AI-enabled functionality.

25. Marketing Preferences

Recipients may unsubscribe from non-essential marketing communications by:

  • using the unsubscribe mechanism in the communication;
  • changing available communication preferences; or
  • contacting us at [MARKETING OR PRIVACY EMAIL].

We may continue sending non-promotional communications concerning:

  • account security;
  • billing;
  • contractual matters;
  • system availability;
  • support;
  • privacy changes; and
  • other essential service information.

26. Do Not Sell Personal Data

OctoNexus does not sell Personal Data in exchange for monetary payment.

We also do not disclose Customer Data to third parties for their independent behavioral-advertising purposes unless this is separately disclosed and lawfully authorized.

27. Data Accuracy

Customers and users are responsible for ensuring that Personal Data submitted to the Services is accurate, complete, and current.

Where supported, users may update profile information through the Services. Other corrections may need to be performed by the relevant Customer administrator.

28. Account Closure and Service Termination

Upon account closure or termination:

  • user access may be disabled;
  • active sessions may be revoked;
  • Customer Data may be exported, returned, deleted, or retained according to the applicable agreement;
  • legally required records may be retained;
  • backup copies may remain temporarily until overwritten; and
  • anonymized or aggregated information may be retained where it no longer identifies an individual.

Customers should export required information before the end of the applicable post-termination retrieval period.

29. Changes to This Privacy Policy

We may update this Privacy Policy to reflect:

  • changes to the Services;
  • new products or features;
  • security developments;
  • changes in our Processing practices;
  • changes to service providers;
  • regulatory developments; or
  • legal requirements.

The updated Privacy Policy will state a revised “Last Updated” date. Where required by law or where changes are material, we will provide additional notice through the Services, email, website notice, or another appropriate method.

Continued use of the Services after an update does not replace consent where applicable law specifically requires new consent.

30. Language

This Privacy Policy may be provided in English and Bahasa Indonesia.

Where legally permitted and unless otherwise stated, the English and Bahasa Indonesia versions should be interpreted consistently. In the event of inconsistency, the version specified in the applicable Customer agreement will prevail, subject to mandatory law.

31. Governing Law

This Privacy Policy and OctoNexus’s Processing activities are governed by the laws applicable to the relevant Processing activity.

For Services provided by PT Gerbang Teknologi Digital in Indonesia, Indonesian law will generally apply, including the Indonesia PDP Law.

The GDPR will apply where the relevant Processing falls within its territorial scope, including certain Processing relating to individuals located in the European Union or European Economic Area.

Nothing in this Privacy Policy limits any mandatory rights or protections available to a Data Subject under applicable law.

32. Contact Us

Questions, requests, or complaints concerning this Privacy Policy may be directed to:

PT Gerbang Teknologi Digital
Brand: OctoNexus
Address: Jl. Sukagalih No. 105, Sukajadi, Bandung, Jawa Barat 40162, Indonesia
Email: [email protected]
Telephone: +62 85183006247
Website: https://octonexus.com

For Customer-controlled data, please include the name of the relevant company, hotel, property, or organization so that the request can be directed appropriately.