Legal · Approved 26 August 2025
Privacy Policy
How PT Mars Bumi Indonesia (Zentara) collects, uses, stores, and protects your personal data under Indonesia's Law No. 27 of 2022 (UU PDP), ISO 27701 PIMS, and the GDPR.
Thank you for choosing and using PT MARS BUMI INDONESIA and/or our related affiliates (“Zentara” or “We” or “Ours”) to provide Our Services to you.
Our website (https://zentara.co/ and its derivative sites) (“Site”) is operated by PT MARS BUMI INDONESIA and its affiliates, through which we offer certain products and services. In order to perform the Services, Zentara may collect and process the personal data of users of our Site and applications (“User”, “you”, “your”).
This Privacy Policy (“Privacy Policy”) are guidelines set by us regarding the use of information under ISO 27701 PIMS and GDPR. Zentara acts as the Personal Data Controller (PII Controller) for data collected through this Site. Where we provide cybersecurity services to corporate clients, we act as a Personal Data Processor (PII Processor) on their behalf. This Privacy Policy sets out the categories of personal data we may collect or hold about you, and how we obtain, collect, store, control, use, process, analyze, correct, update, display, announce, transfer, assign, disclose and protect your Personal Data (“Processing Personal Data” or conducting “Personal Data Processing”) when you use our products or Services. This Privacy Policy applies to all Users, unless set out in a separate privacy policy.
Our Services include but are not limited to Zentara Cyber Security, Zentara Cyber Intelligence, Zentara Enterprise Solutions, Zentara Defence, Zentara Labs, and any other services that we may offer from time to time (hereinafter referred to as “Services”).
This Privacy Policy shall also apply to all our business activities in Indonesia and/or other countries in which Zentara operates its office/affiliates.
What kind of Personal Data do we collect from you?
The Personal Data we collect varies based on the collection situation and the type of service or transaction used. For the avoidance of doubt, Personal Data means data of an identified or identifiable natural person individually or in combination with other information either directly or indirectly through electronic or non-electronic systems. In accordance with Indonesia’s Law No. 27 of 2022 (UU PDP) and international standards like ISO 27701, we categorize the Personal Data we process into two categories:
- General Personal Data: full name, gender, nationality, religion, marital status, identification numbers (such as KTP, NRIC, or Passport), photos, contacts, personal profiles, unique identifiers, and any other data that can identify an individual.
- Specific (Sensitive) Personal Data: health data and information, biometric data (such as fingerprints or facial recognition), genetic data, criminal records, data of children, and personal financial data.
We apply enhanced security controls and conduct mandatory Data Protection Impact Assessments (DPIA) before processing any Specific Personal Data to ensure your most sensitive information is protected against unauthorized access or leakage.
By reading and understanding this Privacy Policy and referring to applicable laws and regulations, User hereby agrees that we can Process Personal Data of the User, both general and specific, as follows:
- 01Identity Data — information used to specifically identify a person such as name, Identity Card (KTP), Driving License (SIM), Taxpayer Identification Number (NPWP), Passport, Limited Stay Permit Card (KITAS), Family Card (KK), user identity or other identifiers, date of birth, gender, place of birth, nationality, income, position, and/or photo;
- 02Contact Data — information used to contact a person such as service installation address including postal code and city name, document delivery or billing address, electronic mail address (e-mail), and telephone number;
- 03Eligibility Data — information we need to verify your new service installation application, business license, registered certificate, taxable entrepreneur confirmation letter (if any) or company deed document;
- 04Biometric Data — biometric information such as fingerprints, faces and others used as authentication to use our Services;
- 05Credential Data — such as passwords, hints, and similar security information used for authentication and access to our accounts and Services;
- 06Payment Data — such as payment method, payment amount, payment time, and information about payments such as credit card information, debit cards, bank account numbers, electronic money and other financial information;
- 07Account Data — transaction history such as subscription packages, account numbers, initials, nicknames, credit information, and billing information;
- 08History Data — your contact with us, such as telephone recordings between you and one of our Contact Centers, live chat on the website, electronic mail, and messages through other communication media that we provide;
- 09Log Data — a record on our system that obtains information such as the device’s IP address, date and time of access, application features or pages viewed/browsing history, application work processes and other system activities, browser type, and third-party sites or services you use before interacting with our Services;
- 10Device Data — information about the device you use, such as device type, hardware model, operating system and version, software, IMEI number, file name and version, language selection, unique device identifier, advertising identifier, serial number, device location identifier, network and device performance, browser type, language, digital rights management information, camera access, and/or cellular network information;
- 11Location Data — your real-time geographic location data, location coordinates in the form of longitude latitude, and Wi-Fi location;
- 12Cookies Data — files with small amounts of data commonly used as anonymous unique identifiers. Cookies are sent to your browser from the websites you visit and stored on your device’s internal memory, as referred to in our Cookies Policy. We use the AdOpt Consent Management Platform (CMP) so you can manage your preferences or ‘Reject All’ non-essential cookies via our Cookie Consent Banner, while using similar tracking technologies to ensure site security and analyze traffic;
- 13Your preferences for our products and Services and specific activities when you tell us such information, or our assumptions about your preferences based on how you use our products and Services;
- 14Advertising Services (Advertising ID) used by us to conduct advertising and promotional activities;
- 15Metadata of your usage activities — data usage, activation of Additional Services (“Add-ons”), prepaid deposit amounts, advance bill payments, prepaid deposit transfers, content and package purchases, and your profile and segmentation; and/or
- 16Information we obtain from other sources, such as credit agencies, fraud prevention agencies, and other data providers, including demographic data, interest-based data, and internet browsing behavior.
Additional information and data may be collected from you from time to time. In such cases, we will provide notice to you or through other mechanisms in accordance with laws and regulations and continue to ensure the protection of your personal data under this Privacy Policy.
How do we collect your Personal Data?
We collect your Personal Data under the following conditions:
- 01You apply for a new Services installation;
- 02You use our network or Services, not limited to internet services we provide including free Wi-Fi, websites, and applications, including our social media such as Facebook, Instagram, X, LinkedIn, and others;
- 03You contact and use the Services of all our communication channels such as, but not limited to, Contact Center, live chat, electronic mail and other communication media messages provided by us;
- 04You participate in our promotional activities, events, marketing, loyalty programs, certain surveys and other activities;
- 05You are a User of a company involved in corporate actions (mergers and acquisitions) with us in accordance with applicable laws and regulations;
- 06You visit our office area where CCTV devices are installed;
- 07Information comes from third parties who have a basis for processing your Personal Data, to the extent that we also have a basis for processing your Personal Data; and/or
- 08Your information has been made publicly available.
We collect your Personal Data only for the needs of the service process. Therefore, if you choose not to provide, or provide incompletely, your Personal Data to us, we may not be able to provide Services to you.
We process your personal data based on Law Number 27 of 2022 concerning Personal Data Protection (including all amendments from time to time) as follows:
- 01Your explicit valid consent for the purposes stated by us in this Privacy Policy;
- 02Fulfillment of agreement obligations in fulfilling your request for Services;
- 03Fulfillment of our legal obligations in accordance with the provisions of laws and regulations;
- 04Fulfillment of the protection of your vital interests, in the event of a threat to your life, physical, and/or property/assets or other third parties;
- 05Implementation of duties in the context of public interest, public services, or the implementation of our authority based on laws and regulations; and/or
- 06Fulfillment of other legitimate interests by taking into account the objectives, needs, and balance of our interests and yours.
What are we doing with your Personal Data?
The Personal Data and other information that you provide — including any additional information you further provide when you use, subscribe, or purchase — may be used and processed by us for the purposes below. For each purpose, Zentara relies on one or more of the lawful bases (Consent, Contract, Legal Obligation, etc.) detailed in the preceding section to ensure all processing is lawful and transparent.
- 01to use your information to carry out our business and help us improve your experience with our products;
- 02to communicate and implement Know Your User (KYC) with you;
- 03to notify you about the products and Services available to you;
- 04to provide selections as to the function of our information that is suitable for you and to improve our Services for you;
- 05to provide transparent and clear explanation as to how we use the information;
- 06to publish or share the information which has been combined with several Users, in a manner that avoids you or others being identified;
- 07to aggregate your non-personal account data with the data of other Users to improve the quality of Services, design a promotion, or provide a way for you to compare business practices with other Users;
- 08to train our employees and to train you as to how to maintain the security and protection of your information;
- 09to obtain and collect your Personal Data, and to store it in an electronic system owned by Zentara or third parties;
- 10to review and process the User’s request in relation to the Services;
- 11to verify and validate the User’s identity and background;
- 12to build communication between the User and Zentara;
- 13to process payment transactions of the User in relation to the Services;
- 14to answer questions, complaints, or comments from the User;
- 15to manage the User’s participation in an event or program held by Zentara;
- 16to process and analyze your Personal Data, including market analysis, whether performed by Zentara or third parties;
- 17to share your Personal Data with Zentara’s subsidiaries, affiliates, related companies, license holders, business partners and/or service providers (list of business partners available upon request);
- 18to analyze data, build algorithms, and create databases for rating systems;
- 19to carry out internal activities, including internal investigation, compliance, audit, and other internal security purposes;
- 20to provide you with the latest security, versions, features, options, and controls related to your system or device;
- 21to use your information to participate in surveys or User meetings;
- 22to send you information via electronic mail, telecommunications (phone calls or text messages) or social media about products and Services offered by selected third parties that we think may be of interest to you;
- 23for business operations to conduct accounting, auditing, billing, reconciliation, and collection activities, including monitoring and preventing crime or fraud, protecting our legal rights, and carrying out obligations under an agreement/contract;
- 24for other legal business activities of Zentara;
- 25to use the physical location of your device, combined with information about advertisements you view, to provide personalized content and study the effectiveness of advertising and marketing campaigns; and/or
- 26you may choose to allow or decline subscriptions or sharing of your device location by changing your device settings
(collectively, “Purposes”).
With whom do we share or disclose your Personal Data?
Zentara is a global company and may access or store Personal Data in various countries, including but not limited to Singapore, Indonesia and/or other countries in which Zentara operates its office/affiliates. In accordance with Article 56 of the Data Protection Law and Article 46 of the GDPR, we may: (i) transfer Personal Data outside the jurisdiction of Indonesia with the approval of the User and in accordance with the Data Protection Law; and/or (ii) access or store Personal Data in countries that do not benefit from an adequacy decision of the European Commission, where Zentara has implemented appropriate safeguards. Your Personal Data will not be deliberately transferred outside Indonesia, Singapore and/or other countries in which Zentara operates, or deliberately disclosed to third parties, except in the cases listed below:
- 01to perform the Purposes specified above, we may provide and/or disclose your Personal Data to our subsidiaries, affiliates, related companies, license holders, business partners, service providers, professional advisors and external auditors, including legal counsels, financial advisors and consultants, as well as other third parties, which may be located within or outside Indonesia;
- 02we may offer a feature that connects you to our business partners, service providers or other third parties, and give limited information related to your Personal Data only to carry out such feature, including for promotions, marketing, loyalty programs, events, offering Company products or Services, and billing;
- 03we may share your Personal Data with third parties who assist us in providing information for authentication and due diligence purposes, including credit references, fraud prevention or business assessment agencies, or other credit assessment agencies, including banks;
- 04we may share your Personal Data with Public Accounting Firms and other Audit Institutions;
- 05we may engage or employ other companies or individuals to facilitate or provide certain Services on our behalf, and provide and/or disclose your Personal Data to these companies or individuals;
- 06in the event of a corporate transaction — including sale of subsidiaries or divisions, merger, consolidation, financing, sale of assets, or other transfer of business assets — we may disclose your Personal Data to parties involved in the negotiation or transfer;
- 07we may disclose your Personal Data if required by law, or necessary to comply with laws, regulations and government, or in case of dispute or any kind of legal process, or in an emergency related to your health and/or security;
- 08at the order of an authorized law enforcement agency or government institution pursuant to prevailing laws and regulations, we may provide access to carry out search or seizure on your data stored electronically in Zentara’s servers;
- 09we may share aggregated or anonymized information that does not directly identify you;
- 10we will disclose information to protect us from fraud, defend our rights or assets, or protect the interests of our Users, and to comply with obligations in responding to legal demands or for legitimate interests in national security, law enforcement, litigation, criminal investigations, or preventing emergencies declared by the Government — only where we, in good faith, believe we are required to do so.
How do we store your Personal Data?
The Personal Data we collect is stored in a data center that we manage ourselves and/or that is managed by a third party located within or outside the jurisdiction of Indonesia. All facilities, infrastructure, and data storage systems, whether managed by us or a third party, are equipped with security controls to protect your Personal Data.
This Personal Data may be stored in hard copy or electronic format. The storage period varies based on the processing purposes stated above — such as providing the Services you request, complying with our legal obligations, resolving disputes, and implementing our policies. We store your Personal Data as long as:
- 01you are still using the Services; and/or
- 02your use of the Services has passed, with a maximum storage period of 5 (five) years for specific data related to your taxation and 10 (ten) years for other specific and general data, to comply with statutory limitation periods for legal claims or relevant Indonesian and Singaporean commercial regulations; and/or
- 03in accordance with applicable laws and regulations.
How do we maintain the security of your Personal Data?
In maintaining the security of your Personal Data, we have:
- 01used the best methods that have been tested to protect your information;
- 02carefully reviewed our security procedures;
- 03complied with the applicable law and security standard;
- 04ensured that your Personal Data is securely transmitted and encrypted; and
- 05ensured that our employees are trained and required to participate in securing your information.
To protect your Personal Data, we implement international standards for Information Security Management Systems based on ISO ISMS 27001:2022 and ISO PIMS 27701:2019 for data confidentiality, integrity, and availability. Our employees are trained to understand and follow ISO ISMS 27001:2022 and ISO PIMS 27701:2019 when processing your Personal Data. These systems apply to all our business activities in Singapore and Indonesia.
We will take all measures necessary to maintain the privacy and security of all Personal Data you provide. We will notify you if any third party (such as hackers) hacks or attempts to hack our security measures or obtains unauthorized access to our data center or device that contains your Personal Data. Zentara shall not be liable for damage that is not attributable to it. You should be aware that use of the internet is not entirely secure, and we cannot guarantee the security or integrity of any personal data transferred via the internet.
What rights do you have over your Personal Data?
In accordance with the applicable laws and regulations on the protection of personal data, you benefit from a number of rights relating to your data, namely:
- 01the right of access and information — to be informed in a concise, transparent, intelligible and easily accessible manner of how your Personal Data is processed, to obtain confirmation that data concerning you is being processed and, where appropriate, to access it and obtain a copy. Zentara will only limit this access in exceptional circumstances defined by law;
- 02the right of rectification — to obtain the rectification of inaccurate data and to complete incomplete data by an additional declaration; where you exercise this right we will communicate any rectification to all recipients of your data;
- 03the right of end processing, deletion and/or destruction — to terminate the processing we carry out or delete your data we control, and to destroy your data where doing so does not violate the law and there is no other obligation to retain it (this does not apply to data fully controlled by partners such as the Directorate General of Taxes or the Population and Civil Registration Service);
- 04the right to delay or limitation of processing — in certain cases, to delay or obtain a limitation of the processing of your data;
- 05the right to portability and interoperability — to obtain and use your Personal Data in a commonly used, machine-readable format, and to send it to other Personal Data controllers where systems can communicate securely;
- 06the right to object to the processing — to object at any time to processing based on our legitimate interest and to commercial prospecting; this is not an absolute right and we may refuse for legal or legitimate reasons;
- 07the right to withdraw your consent at any time — where processing is based on consent; withdrawal does not affect the lawfulness of processing carried out before withdrawal;
- 08the right to complain to a supervisory authority — to contact your data protection authority to complain about our practices;
- 09the right to send the personal data to other personal data controller(s) — as long as the systems used can communicate securely and in accordance with personal data protection principles; and
- 10the right to opt-out from marketing information — to withdraw your consent to the processing of marketing-related Personal Data; you will still receive service-related information and can still use our Services.
To exercise these rights, you can contact us at [email protected]. We may require proof of your identity and may charge a reasonable administrative fee for this service.
Exceptional circumstances (to the extent allowable under applicable law) include where an investigating authority or government institution objects to Zentara complying with your request, or where information is collected in connection with an investigation of a breach of contract, suspicion of fraudulent activities, or contravention of law. Zentara shall also not provide access to your Personal Data if it could reasonably be expected to threaten or cause grave harm to another individual, reveal personal data about another individual, reveal the identity of an individual who provided data about another without consent, be irrelevant to you or the processing we undertake, or be contrary to the national interest.
Transfer of Personal Data abroad
We may need to transfer your information outside the jurisdiction of Indonesia to store data whose storage infrastructure (data center) is outside Indonesia and managed by a third-party partner. We always maintain the security of your data by ensuring that:
- 01the country where the third-party partner receiving the data transfer is domiciled has a level of personal data protection equal to or higher than Indonesia; or
- 02there is adequate and binding personal data protection; or
- 03you agree to the transfer of Personal Data abroad that we carry out; or
- 04for users in Singapore, all transfers of personal data outside Singapore are conducted in compliance with the PDPA, ensuring the recipient organization provides comparable protection.
Automated Resolution
In analyzing new installation requests, providing promotions or offers, and preventing fraud, we use automated decision-making (without human involvement), including profiling, which may have legal consequences or otherwise significantly impact you. You have the right to object to decisions based solely on automated processing through the objection mechanism in this Privacy Policy.
Provisions Concerning Persons with Disabilities
If you are categorized as a person with disabilities, you are required to ensure that you have obtained approval from your parents (father or mother) and/or guardian in accordance with the regulations in force in Indonesia.
Personal Data Breach Notification
In the event of a leak of your personal data, we will immediately provide written notification to you no later than 3 x 24 hours via registered email, including the type of personal data disclosed and efforts to handle and restore said personal data.
Amendment to Privacy Policy
We reserve the right to amend this Policy as necessary, particularly to comply with regulatory, editorial or technical changes. We will update the “last update” date to indicate when the changes were made. We encourage users to check this policy regularly. You acknowledge and agree that it is your responsibility to review this Policy periodically and become aware of modifications.
Language
This Privacy Policy is prepared in both Indonesian and English. In case of discrepancy or conflict between the Indonesian and English texts, the Indonesian text shall prevail, and the English text shall be deemed automatically amended to conform. For Data Subjects located in the European Union, the English version shall be considered equally authoritative to ensure the clear communication of rights and information required by the GDPR.
Governing Law and Jurisdiction
This Privacy Policy, its subject matter and its formation (and any non-contractual disputes or claims) are governed by the laws of the Republic of Indonesia. We both agree to the exclusive jurisdiction of the Indonesian National Arbitration Board (Badan Arbitrase Nasional Indonesia or “BANI”).
Acknowledgement and Agreement
Processing of your Personal Data is based on the explicit consent you provide when submitting forms on our Site, or as necessary for the fulfillment of a contract. You may withdraw your consent at any time by contacting [email protected].
Contact
If you have any questions about this Privacy Policy or requests relating to your data, you can contact our Data Protection Officer at [email protected]. Phone: 0812 9495 7450.
Marketing or Publication of Services
By accepting the terms of this Privacy Policy, you understand that we may send material for marketing or publicizing our Services (such as newsletters, advertisements or short message services) via our website, electronic mail or third-party media platforms. If you do not wish to receive marketing material, you can stop it at any time by contacting us or selecting the “berhenti berlangganan / unsubscribe” option on the relevant marketing material.
Disclaimer
Our Site may contain links to another website. Please note that we are not responsible for the privacy practices or policy of those websites.
Cookie Inventory & Management
Zentara uses the AdOpt Consent Management Platform (CMP) to manage cookies and provide transparency. A real-time, categorized list of all cookies used on this website — including their provider, purpose, and expiration — is available through our Cookie Preference Center. You can view the full list and adjust your consent at any time by clicking the “Manage Cookies / Cookie Settings” button on our site.
Approved by Director / CEO, PT Mars Bumi Indonesia (Zentara) · 26 August 2025
PT Mars Bumi Indonesia · Registered PSE No. 020644.01/DJAI.PSE/11/2025
More legal & compliance