Privacy & Policy
Durianpay Privacy Notice
Please read this Privacy Notice carefully to ensure that You understand the provisions surrounding Durianpay’s processing of Your Personal Data.
We believe that You should be able to make informed decisions about Your personal data. We created this privacy notice (previously referred to as Privacy Policy) (hereinafter referred to as “Privacy Notice”) to inform and explain to You how we, PT Durian Pay Indonesia, an entity duly established in Indonesia with office in Equity Tower Lantai 28, Unit H, Jalan Jendral Sudirman Kav.52-53, SCBD, Senayan, Kebayoran Baru, Jakarta Selatan, Provinsi DKI Jakarta, which is the controller that processes Personal Data as described in this Privacy Notice and Our affiliates and wholly owned subsidiaries (collectively “Durianpay”, “We”, “us”, “Our”, or “Ours”) obtain, collect, store, control, use, process, analyze, correct, update, display, announce, transfer, disclose, and protect the Personal Data (altogether “Processing” Personal Data or carrying out “Personal Data Processing”) that You provide to Us.
This Privacy Notice applies to all users, merchants, business partners (such as payment processors, acquiring banks, issuing banks, payment gateways, card networks, and other financial institutions), agents, vendors, suppliers, service providers, and contractors (collectively referred to as “You” or “Your”), except as provided in a separate privacy notice.
This Privacy Notice is an inseparable part of Durianpay Terms and Conditions. We recommend that You read this Privacy Notice in conjunction with any of Our product or Service terms and conditions as they may contain product or service-specific information about how We Process Your Personal Data.
The use of the Durianpay platform, including any of Our features, services, and/or products related to payment processing (the “Services”), constitutes Your agreement to the Terms of Use and this Privacy Notice. Therefore, You need to read this Privacy Notice carefully to ensure that You fully understand it before registering, accessing, and/or using Our Platform (including any Services thereof).
Privacy Notice also has the same meaning as the privacy policy as stated in the Terms of Use and each Service on Our Platform.
01
02
03
04
05
Personal Data refers to any and all information, data, and/or details in any form that can be used to identify You, which from time to time You provide to Us or that You include or submit, whether directly or indirectly, in, on, and/or through the Platform in connection with Your personal or business identity.
Personal Data includes, but is not limited to, Your full name, identification number (including those stated on passport, national identity card, tax identification number/NPWP, or other government-issued identification), address, date of birth, email address, mobile phone number, financial information, payment account details, billing details, transaction data, device information, geolocation data, and any other data categorized as Personal Data under the Applicable Laws and Regulations.
For the avoidance of doubt, Applicable Laws and Regulations shall mean all applicable laws, statutes, regulations, regulatory guidelines, ordinances, protocols, industry codes, licenses, requirements from courts, tribunals, or any governmental or supervisory authority, that are in force from time to time during the validity of this Privacy Notice.
In addition, other data such as behavioral profiles, online identifiers, cookies or device identifiers, fraud signals, and/or transaction patterns that are linked or combined with Your Personal Data shall also be considered as Personal Data.
Please note that Personal Data does not include any information that has already been made available in the public domain.
In accordance with the provisions of Applicable Laws and Regulations, Durianpay Processes Your Personal Data based on:
01
02
03
04
05
Personal Data collected when You use the Platform, receive, or provide Our payment services (“Services”), includes the following:
01
02
a. Partner:
Personal Data may be collected during the course of business partnership engagement, including at the stage of Non-Disclosure Agreement (NDA) signing or execution of cooperation agreements, for the purposes of due diligence, verification, business alignment, and contract administration. Personal Data collected may include:
The timing and scope of Personal Data collection may vary depending on Durianpay’s business engagement process and the specific requirements of each partner. Durianpay ensures that all such Processing is carried out in accordance with Applicable Laws and Regulations.
b. Vendor:
Personal Data collected during vendor registration and procurement processes, including but not limited to:
Such Personal Data is collected and processed for the purposes of vendor due diligence, registration, payment processing, and contract administration.
c. Other communications:
03
Partners and service providers who assist Us in providing payment and financial services on the Platform under controller-to-controller or controller-to-processor arrangements, including but not limited to acquiring banks, payment processors, card networks, e-wallet providers, KYC/AML verification vendors, risk and fraud detection providers, and logistics or accounting service providers;
Third parties or integration platforms that You use to create or access a Durianpay account, including but not limited to e-commerce platforms, accounting tools, or systems that connect to the Durianpay API;
Regulatory or government databases used to verify identity, licensing, tax information, or sanction status, as required by Applicable Laws and Regulations. This may include verification through systems or databases maintained by government authorities or financial intelligence units (e.g., PPATK, Bank Indonesia) for the purposes of Customer or Business Due Diligence (CDD/EDD), sanction list checks, and compliance monitoring
Marketing and analytics service providers that assist Us in delivering relevant offers and improving Our Services, where applicable; and/or
Publicly available sources, such as company registries, professional networks, or public records.
Durianpay uses the Personal Data collected to verify and onboard merchants and partners, process and reconcile payment transactions, fulfill compliance obligations (including KYC, KYB, and AML/CFT requirements), communicate service updates, improve the Platform’s security and performance, and—where permitted by law—send relevant service or marketing communications based on Your consent.
01
If You are a User or Merchant, to enable Our financial partners and service providers (such as acquiring banks, issuing banks, payment gateways, e-money issuers, and card networks) to process, authorize, settle, and reconcile Your payment transactions made through the Platform.
If You are a Partner or Vendor, to enable Users or Merchants to receive the services You provide to Durianpay under Your agreement with Us.
If required or authorized by Applicable Laws and Regulations —including but not limited to responding to regulatory inquiries, supervisory reviews, reporting obligations to Bank Indonesia, PPATK, or other authorities, or complying with statutory filing and retention requirements.
If instructed, requested, required, or permitted by competent government agencies or law enforcement authorities for purposes stated in Applicable Laws and Regulations, including anti-money-laundering (AML), counter-terrorism financing (CTF), fraud investigation, and consumer-protection matters.
For the purposes of internal investigations of violations of law or company policies within Durianpay and its affiliated companies.
If there is a legal process of any kind between You and Us, or between You and other parties in connection with the Services on the Platform, for the purposes of such legal process and dispute resolution.
To detect and protect against fraud, financial crime, cybersecurity incidents, or technical vulnerabilities, where We may transfer and disclose Your Personal Data to relevant third-party security and fraud-monitoring service providers.
In connection with KYC (Know Your Customer) and KYB (Know Your Business) processes or any other verification activities that We and/or third parties conduct before granting You access to the Services or activating Your merchant account. This may include sharing or reporting of relevant Personal Data to competent authorities such as Bank Indonesia and the Financial Transaction Reports and Analysis Center (PPATK) for purposes of Anti-Money Laundering, Counter-Terrorism Financing, and ongoing regulatory supervision as required by Applicable Laws and Regulations.
In an emergency involving the safety or security of Durianpay, its employees, Users, Merchants, Partners, or the public, to handle such emergency and prevent harm.
In connection with public-interest or financial-system stability matters, where Durianpay may share Personal Data with government agencies or supervisory authorities for purposes of monitoring systemic risk, fraud patterns, or payment system integrity as required by Applicable Laws and Regulations.
In connection with any merger, acquisition, financing, corporate restructuring, or sale of assets involving Durianpay or its affiliates, for the purposes of such transaction (including due diligence). If another entity acquires Durianpay or its assets, Your Personal Data may be transferred as part of that transaction subject to the same protections set forth in this Privacy Notice.
To third-party service providers (including cloud computing, data hosting, infrastructure, IT support, analytics, risk scoring, fraud detection, and payment system integration providers) who assist Us in operating the Platform or performing functions on Our behalf, subject to confidentiality and data-protection obligations.
To Our affiliates or members of Our corporate group (including subsidiaries and the parent company), for purposes of supporting Platform operations, providing back-office and technical services, and ensuring business continuity. All such affiliates are required to Process Personal Data in accordance with this Privacy Notice and Applicable Laws and Regulations.
To financial-sector partners, payment scheme operators, and clearing institutions for purposes of settlement, reconciliation, reporting, or compliance with industry standards (e.g., card network rules, Bank Indonesia regulations).
To marketing and analytics partners only for lawful and limited purposes of improving Our Services, subject to Your consent where required by Applicable Laws and Regulations.
To carry out any other Processing activities for the purposes described in this Privacy Notice, where permitted by Applicable Laws and Regulations. For clarity, Durianpay does not sell, rent, or trade Your Personal Data to any third party.
02
03
04
Your Personal Data that We collect may be stored, transferred, or processed outside Indonesia by Our personnel or by third-party service providers, vendors, suppliers, partners, contractors, or Durianpay affiliates for one or more of the purposes set out in this Privacy Notice — for example, cloud hosting, cross-border payment processing, or fraud monitoring.
Durianpay will comply with all Applicable Laws and Regulations and use reasonable efforts to ensure that countries where Our affiliates or service providers are located maintain a level of Personal Data protection that is equivalent to or higher than that of Indonesia, or that those third parties are bound by adequate and enforceable data-protection agreements (such as standard contractual clauses or binding corporate rules).
Where required by Applicable Laws and Regulations, Durianpay will seek Your explicit consent before transferring Your Personal Data outside Indonesia. You understand and consent to such transfer of Your Personal Data outside Indonesia for the lawful purposes described herein.
Your Personal Data will only be stored as long as necessary to fulfill the purposes for which it was collected, during the applicable retention period, or as otherwise required or permitted by Applicable Laws and Regulations. Personal Data may be retained for up to ten (10) years in accordance with prevailing regulations, or longer if required by Applicable Laws and Regulations.
We will cease storing Personal Data, or remove its association with You as an individual, as soon as it is determined that the purpose for which the Personal Data was collected is no longer necessary, upon Your written request for the deletion and destruction of Your Personal Data, or when retention is no longer required for business, operational, or legal purposes.
Durianpay will delete and/or anonymize User Personal Data under Durianpay’s control if:
the User’s Personal Data is no longer necessary to fulfill the purpose of its collection;
the retention period has expired; and
retention is no longer required to comply with Applicable Laws and Regulations, including but not limited to those issued by Bank Indonesia and other competent financial or data protection authorities
Please note that there may still be instances where some of Your Personal Data is stored or controlled by other parties, including partner financial institutions, payment gateways, card networks, or government authorities, in certain ways. In cases where We share Your Personal Data with such authorized institutions and/or other entities designated by the government or cooperating with Us, You acknowledge and agree that the retention of Your Personal Data by these institutions will follow their respective data retention and compliance policies.
To the extent permitted by Applicable Laws and Regulations, You release Us from and against any and all claims, losses, liabilities, costs, damages, and expenses (including but not limited to legal fees and full compensation costs) directly or indirectly resulting from any Personal Data processing activities conducted outside of Our Platform or Services.
01
02
a. Refuse requests deemed irrelevant, unfounded, excessive, or that may infringe the rights of others; and
b. Charge a reasonable administrative fee for processing data access or copy requests, where permitted by law (such fee will be communicated to You in advance)
03
04
For example, if an account is suspended for fraud, We may retain certain identifiers to prevent the same individual or entity from re-registering under a new account.
We may also retain transaction or audit data as required under Applicable Laws and Regulations, including those issued by Bank Indonesia.
01
01
01
02
03
This Privacy Notice shall be governed by and construed in accordance with the laws of the Republic of Indonesia, including all Applicable Laws and Regulations related to personal data protection, payment systems, financial services, and electronic transactions. You are required to comply with all Applicable Laws and Regulations of the Republic of Indonesia in connection with Your use of the Platform and Services.
This Privacy Notice may be amended or updated from time to time to ensure alignment with developments in Our business operations, technological advancements, or changes in Applicable Laws and Regulations.
Durianpay will notify You of any material changes through reasonable means — including via the Platform, email, or other communication channels — in accordance with legal requirements. However, You are encouraged to review this Privacy Notice periodically to stay informed of the most recent version.
Your continued access or use of the Platform, communication with Us, or utilization of any Services after such amendments will be deemed as Your acknowledgment and acceptance of the updated Privacy Notice.
Contact Us
If you have any questions, comments, complaints, or claims regarding this Privacy Notice, or if you wish to exercise your rights as a Personal Data subject regarding your Personal Data on the Platform, please send an email to privacy@durianpay.id. We will handle your complaint confidentially. We will contact you within a reasonable period after receiving your complaint to discuss it and provide options on how your complaint can be resolved.
I HAVE READ AND UNDERSTAND ALL THE PROVISIONS OF THIS PRIVACY NOTICE AND THEIR CONSEQUENCES, AND I HEREBY ACCEPT AND AGREE TO ALL RIGHTS, OBLIGATIONS, AND TERMS SET FORTH IN THIS PRIVACY NOTICE. THIS STATEMENT IS DEEMED AS MY CONSENT AS THE OWNER AND/OR CONTROLLER OF THE PERSONAL DATA.