DPA

Data Processing Agreement

Data processing terms for customers that use API Indonesia as a data processor.

Last updated
July 5, 2026
Summary
  • This page explains roles, processing instructions, subprocessors, security, and data deletion.
  • For custom contract terms, contact hello@apiindonesia.id.

Roles

For account and billing data, API Indonesia usually acts as a data controller. For personal data that customers send through the service on behalf of their end users, the customer acts as controller and API Indonesia acts as processor according to customer instructions.

Processing instructions

  • Provide APIs, dashboard, authentication, billing, support, and security.
  • Keep technical logs needed for operations, audit, and incident handling.
  • Delete or return data according to valid requests and service capability.

Subprocessors

We may use hosting, database, email, payment, monitoring, technical analytics, and customer support providers. Categories and processing purposes are listed on the Subprocessors page.

Data transfers

Data may be processed in Indonesia or other places where our infrastructure providers operate. If the law requires extra safeguards, we will use an appropriate transfer basis.

Audit and compliance assistance

We may provide reasonable security and processing information to support customer compliance needs. Direct audits require a written agreement and an agreed schedule.