Hukum
Data Processing Agreement
The data processing terms governing visitor personal data collected through your website: you are the controller, Maleo Sites is the processor.
- Effective
- 23 August 2026
- Version
- 1.0
This Data Processing Agreement ("DPA") forms part of the Terms of Servicebetween Bima Saputra, an individual sole proprietor trading as Maleo Labs ("Maleo Sites", "we", "us", or "Processor") and the customer or organization holding an active account ("Customer","you", or "Controller").
This DPA applies to the extent that Maleo Sites processes Personal Data on behalf of Customer in connection with the provision of the Maleo Sites platform, pursuant to Law No. 27 of 2022 on Personal Data Protection ("UU PDP") and applicable data protection regulations.
1. Purpose and Scope
When you build and publish a website using Maleo Sites, your site may collect information submitted by visitors (for example, through booking forms, inquiry messages, or consultation requests) as well as technical visit logs. This DPA governs the rights and responsibilities of both parties regarding such visitor personal data.
2. Roles of the Parties
- Customer as Data Controller: Customer determines the purposes, means, and lawful basis for processing visitor personal data collected via Customer's website. Customer is solely responsible for obtaining necessary consents, providing privacy notices to visitors, and ensuring compliance with applicable data privacy laws.
- Maleo Sites as Data Processor: Maleo Sites processes visitor personal data solely on behalf of, and in accordance with the documented instructions of, Customer (including as set forth in the Terms of Service and this DPA), and does not process such data for its own independent commercial purposes.
3. Details of Data Processing
| Category | Description |
|---|---|
| Subject Matter | Provision of website hosting, booking submission capture, and pseudonymised traffic analytics. |
| Categories of Data Subjects | Visitors and prospective clients of Customer's website who interact with published pages or submit forms. |
| Types of Personal Data | Name, WhatsApp/phone number, message contents submitted via booking/contact forms, visitor IP address (processed in volatile memory for rate-limiting and salted hashing), browser User-Agent, and country of origin derived from network headers. |
| Special/Sensitive Data | Customer is explicitly prohibited by our Acceptable Use Policy from collecting sensitive personal data (e.g. NIK/KTP numbers, biometric data, payment card details, medical records) through website forms. |
| Duration of Processing | For the duration of Customer's active account, subject to automated retention schedules (e.g., 90days for raw analytics logs, and immediate deletion upon customer request). |
4. Obligations of Maleo Sites
As the Data Processor, Maleo Sites agrees to:
- Process only on instructions: Process Personal Data solely in accordance with Customer's documented instructions, unless required to do so by applicable statutory law or a competent government authority.
- Confidentiality: Ensure that all personnel or contractors who have access to Personal Data are subject to strict confidentiality obligations.
- Security measures: Implement and maintain appropriate technical, physical, and organizational measures to safeguard Personal Data against accidental or unlawful destruction, loss, alteration, or unauthorized disclosure.
- No commercial exploitation: Never sell, rent, lease, or use visitor data collected through Customer's site for advertising, profiling, or direct marketing.
5. Obligations of the Customer
As the Data Controller, Customer agrees and warrants that:
- It has established a valid legal basis (such as explicit consent or performance of a contract) under UU PDP for collecting visitor personal data via its site.
- It provides a clear and accessible privacy disclosure to visitors regarding what data is collected and how it is used.
- It will not use Maleo Sites forms to collect restricted, illegal, or sensitive data.
- It will promptly handle any individual requests (access, rectification, deletion) received from its visitors.
6. Sub-processors
Customer provides general authorization for Maleo Sites to engage third-party sub-processors to assist in delivering the Service (such as cloud hosting, infrastructure, and transactional email).
- Current sub-processors: A complete and transparent list of our sub-processors, their functions, locations, and data handled is maintained at Sub-processors.
- Agreements with sub-processors: Maleo Sites imposes data protection obligations on its sub-processors that are no less restrictive than those set out in this DPA.
- Notification of changes: We will update the Sub-processors page when new entities are engaged. Customers who object to a new sub-processor on reasonable data protection grounds may terminate their subscription.
7. Technical and Security Measures
Maleo Sites maintains modern technical safeguards including, but not limited to:
- Encryption in transit: HTTPS/TLS 1.3 enforced on all published sites, APIs, and dashboards.
- Encryption at rest: Data stored in Cloudflare D1 and object storage in Cloudflare R2 is encrypted at rest using industry-standard AES-256 encryption.
- Privacy-preserving analytics: Visitor telemetry uses daily salted cryptographic hashes instead of persistent tracking cookies or persistent IP storage, preventing long-term visitor tracking.
- Access control: Strict least-privilege administrative access controls and credential management.
8. Personal Data Breach Notification
In the event of a confirmed Personal Data Breach affecting Customer's visitor data, Maleo Sites will:
- Notify Customer without undue delay (and in any event within 72 hours of becoming aware of the breach).
- Provide Customer with reasonable information concerning the nature of the breach, the affected data categories, likely consequences, and remediation measures taken.
- Cooperate with Customer to mitigate the effects and enable Customer to meet its regulatory reporting obligations under UU PDP.
9. Assistance with Data Subject Requests
If a visitor submits a request to exercise their rights under UU PDP (such as deletion, access, or correction) directly to Maleo Sites, we will prompt the requester to contact Customer directly, or forward the request to Customer's registered email address. Maleo Sites provides self-service deletion tools in the dashboard allowing Customers to delete bookings, messages, and site data directly.
10. Return and Deletion of Data
Upon termination of the Service or account deletion:
- Customer's site data, uploaded assets, and booking submissions will be scheduled for permanent deletion following the standard grace period (30 days) as detailed in our Privacy Policy.
- Customer may export or delete their data prior to account termination using platform tools.
11. Governing Law and Jurisdiction
This DPA is governed by and construed in accordance with the laws of the Republic of Indonesia. Any dispute arising out of or in connection with this DPA shall be resolved under the dispute resolution mechanisms set forth in the Terms of Service.
Questions about this document? Write to support@maleosites.com.