Legal

Privacy policy

What we collect when you contact us, why we need it, and what we will never do with it.

This site is operated by PT Asa Digital Global, trading as Certify Indonesia, at Ciputra International, Office Tower 3, Level 16 Suite 39, West Jakarta 11740, Indonesia. In this policy, "we" means that company, and "you" means anyone who visits this site or contacts us.

We handle personal data under Indonesian Law No. 27 of 2022 on Personal Data Protection. Where you write to us from the European Union or the United Kingdom, we also apply the standards of the GDPR.

What we collect

When you send the assessment form, we receive what you type into it: your name, work email, company, country, phone number if you give one, the schemes you selected, and your message. Our server also records the page you sent it from, your IP address and your browser's user-agent string, which help us tell genuine enquiries from automated spam.

We do not ask for, and you should not send us, government identity numbers, payment card details or passwords through this form.

Product information you send us

Assessments usually involve specifications, drawings, formulations or test reports. We treat these as confidential business information, not marketing material. We do not publish them, sell them, or use them as case studies without asking you first in writing.

Why we use it

We use what you send to answer your enquiry, prepare your assessment, quote the work, and — if you appoint us — carry out the engagement. We may email you about that specific enquiry. We do not add you to a marketing list because you asked a question.

Who else sees it

Delivering a certification or licensing engagement means filing with other parties. Depending on the scheme, that can include Indonesian regulators such as DJID under Komdigi, BSN and an accredited LSPro, BPOM, BPJPH, and customs authorities, as well as testing laboratories and, where relevant, the importer named on the application.

We share only what a given filing actually requires, and we tell you before a disclosure that goes beyond what you would reasonably expect. We do not sell personal data to anyone, for any purpose.

Cookies and third parties

This site sets one cookie of its own: a session cookie that protects the contact form against forged submissions. It carries no advertising or tracking identifier and expires when you close your browser.

The site loads its typeface from Google Fonts, which means your IP address reaches Google's servers when a page loads. If we later add analytics, it will be listed here before it goes live.

How long we keep it

Enquiries that do not become engagements are kept while they may still be useful to you and to us, and reviewed periodically. Records tied to a filing are kept as long as the certificate, registration or licence remains relevant, and for as long afterwards as Indonesian record-keeping rules require.

Your rights

You can ask us what we hold about you, ask for it to be corrected, ask for it to be deleted, or withdraw consent for uses that rely on it. Write to hello@certifyindonesia.com and we will reply within a reasonable period.

Where a filing is already in progress, some information cannot be deleted without ending the engagement, because the regulator's own record depends on it. We will tell you plainly when that is the case.

Security

The site is served over HTTPS and the panel behind it requires a password. No system is perfect; if a breach ever affects your data, we will tell you and the relevant authority as the law requires, rather than quietly.

Changes

If this policy changes, the revised version appears here with a new review date. Material changes to how we use existing data will be raised with you directly, not just posted.

Last reviewed . Indonesian requirements change; we confirm the current position in every assessment.