Privacy Policy
Last updated: August 1, 2026
1. Introduction
PT Cynnex Integrasi Solusi ("Cynnexis", "we", "our") is dedicated to protecting the privacy and security of your personal data. This Privacy Policy describes how we collect, use, store, and safeguard your personal information in compliance with the Personal Data Protection Law of the Republic of Indonesia (Law No. 27 of 2022 / UU PDP).
By accessing our website, engaging our services, or interacting with us, you acknowledge and agree to the collection and handling of information as outlined in this policy.
2. Data We Collect
We may collect and process the following categories of information:
Identity Data: Full name, job title, company or organizational affiliation.
Contact Data: Professional email address, telephone/WhatsApp number, office address.
Website Usage Data: IP address, browser type and version, visited pages, visit duration, and referral sources (via analytical cookies).
Communication Data: Inquiries, requests, messages, or materials submitted through our contact forms or email correspondence.
Contract & Engagement Data: Information strictly necessary to execute cybersecurity engagements (active clients only, governed by separate bilateral agreements).
3. Purposes of Data Processing
We use your personal data for the following legitimate purposes:
- Responding promptly to your consultation requests and technical inquiries
- Preparing tailored cybersecurity service proposals and engagement scopes
- Delivering contracted cybersecurity assessments, defensive operations, or training
- Providing security advisories, newsletters, or educational updates (where consented)
- Satisfying applicable regulatory and statutory compliance obligations
- Continually enhancing our website usability, security, and digital service quality
4. Legal Basis for Processing
Our processing of your personal data rests upon recognized legal grounds:
- Consent: Provided voluntarily when completing inquiries or registering for services
- Contractual Performance: Required to execute agreed cybersecurity scopes and deliverables
- Legitimate Interests: Safeguarding our digital infrastructure and preventing fraudulent activities
- Legal Compliance: Fulfilling binding statutory mandates under Indonesian regulations
5. Third-Party Data Sharing
We DO NOT sell, rent, or trade your personal data to any external parties for commercial marketing purposes.
Your data is disclosed solely to:
- Trusted IT infrastructure and security providers supporting our operations under strict confidentiality agreements
- Authorized judicial or government bodies when mandatory under applicable statutory law
- Certified engagement partners directly involved in delivering authorized scopes (subject to prior client consent)
All third parties handling data on our behalf are contractually bound to equivalent data protection standards.
6. Data Security Measures
As an enterprise cybersecurity firm, information protection is central to our core mission. Key safeguards implemented include:
- Strong data encryption both in transit (TLS 1.3) and at rest (AES-256)
- Principle of least-privilege access controls with multi-factor authentication
- Routine vulnerability assessments, penetration tests, and independent security audits
- Continuous security awareness training across all staff and engineers
- Rigorous, tested incident response and forensic remediation protocols
While robust safeguards are maintained, no digital environment is entirely impenetrable. In the event of a security incident affecting your data, notification will be provided pursuant to UU PDP requirements.
7. Your Statutory Rights
Under Indonesia's UU PDP, you retain meaningful rights regarding your personal data:
- Right of Access: Request details of personal data we retain concerning you
- Right to Rectification: Request correction of incomplete, inaccurate, or outdated records
- Right to Erasure: Request deletion or anonymization of your data under statutory conditions
- Right to Restriction: Request limitation of specific data processing operations
- Right to Portability: Receive your personal records in a structured, machine-readable format
- Right to Object: Object to certain processing activities conducted under legitimate interest
- Right to Withdraw Consent: Withdraw previous processing consent at any time
To exercise any of these rights, please contact our Data Protection team at: info@cynnexis.com
8. Data Retention Periods
We retain personal data only for as long as necessary to achieve the stated purposes or satisfy regulatory requirements:
- General inquiries & lead data: Retained for up to 2 years following last contact
- Active client & contract data: Retained for the engagement duration plus 5 years thereafter
- Billing, tax & accounting records: Retained for 10 years pursuant to statutory tax requirements
- Security telemetry & audit logs: Retained for 12 months
Upon expiration of retention schedules, data is permanently erased or securely irreversibly anonymized.
10. Policy Amendments
We may revise this Privacy Policy periodically to reflect evolving legal standards or operational practices. Material revisions will be highlighted on our website or communicated directly. The "Last updated" date at the top of this document always reflects the current effective version.
We encourage you to review this policy periodically.
11. Contact Information
For inquiries, rights requests, or feedback regarding our privacy practices:
PT Cynnex Integrasi Solusi (Cynnexis) Tania Building 1, Jl. Jeruk Raya No. 1, Jakarta Selatan
Email: info@cynnexis.com Phone/WhatsApp: +62 811-9000-9956 Business Hours: Monday – Friday, 08.00 – 17.00 WIB
We are committed to acknowledging and resolving privacy inquiries within statutory response timelines.
© 2026 PT Cynnex Integrasi Solusi. All rights reserved.
This policy is governed by the laws and regulations of the Republic of Indonesia.