Roles
For account and billing data, API Indonesia usually acts as a data controller. For personal data that customers send through the service on behalf of their end users, the customer acts as controller and API Indonesia acts as processor according to customer instructions.
Processing instructions
- Provide APIs, dashboard, authentication, billing, support, and security.
- Keep technical logs needed for operations, audit, and incident handling.
- Delete or return data according to valid requests and service capability.
Subprocessors
We may use hosting, database, email, payment, monitoring, technical analytics, and customer support providers. Categories and processing purposes are listed on the Subprocessors page.
Data transfers
Data may be processed in Indonesia or other places where our infrastructure providers operate. If the law requires extra safeguards, we will use an appropriate transfer basis.
Audit and compliance assistance
We may provide reasonable security and processing information to support customer compliance needs. Direct audits require a written agreement and an agreed schedule.