Privacy Policy

Last Updated: March 6, 2024
Last Reviewed: March 6, 2024

Privacy and online safety are important to Us. PT Sumber Digital Teknologi, a limited liability company established under the laws of Indonesia ("Iluma", " We", "Us" or "Our") provides identity verification services as well as fraud detections services for users. We collect data about businesses and their customers (“Data") when they use the platform, our data products, identity and information services, and Our websites (collectively, “ Services”). This Privacy Policy is intended to provide information to Users regarding how We conduct collection, processing, management, disclosure, storage, securing, analysis, and disposal while still taking into account and with reference to Law Number 27 of 2022 regarding Personal Data Protection an as such this privacy policy may be updated in accordance with applicable regulations in the Republic of Indonesia ("Indonesia").

In this Privacy Policy, we sometimes refer to "You". " You" may be a visitor to one of our websites, a user of one or more of our Services (" User"), or a customer of a User ("Customer "). We'll do our best to clarify who we are referring to at various points in the policy. This policy does not apply to third-party websites, products, or services even if they link to our Services, and You should consider the privacy practices of those third-parties carefully. If You disagree with the practices described in this Privacy Policy, You should immediately discontinue Your use of Our Services and take necessary steps to remove cookies from Your computer after leaving Our website.

  1. Overview
  2. The Data we collect depends on how Our Services are used. Sometimes we receive Data directly, such as when actual or test transactions are submitted through Our API, or we receive an email. Other times, we get Data by recording interactions with Our Services by, for example, using technologies like cookies and web beacons. We also get Data from third parties, like Our financial partners or identity verification services.

    The collection and use of data from a variety of sources is essential to Our ability to provide Our Services – and to help keep the Services safe. Data is critical in helping Us to increase the safety of Your transactions, and reduce the risk of fraud, money laundering and other harmful activity.

  3. Data We Collect
    1. Personal Data. We call Data that (individually or when read with other data) identifies, or that could reasonably be used to identify, You as an individual " Personal Data ". We collect Personal Data in different ways. For example, we collect Personal Data when you submit documents to Us for verification purposes or you submit queries to Us in relation to Our Services. We also receive Personal Data from other sources, such as our partners, financial service providers, identity verification services, and publicly available sources. Personal Data does not include Data that has been aggregated or made anonymous such that it can no longer be reasonably associated with a specific person. The Personal Data that we may collect includes:
      • Contact details, such as name, postal address, telephone number, email address;
      • Financial and transaction Data, such as credit or debit card information, and bank account information; and
      • Other Personal Data, such as date of birth, government issued identifiers
    2. Other Data. We call Data other than Personal Data " Other Data ". We collect Other Data through a variety of sources. One of our sources for Other Data is cookies and other technologies that record Data about the use of our websites, websites that implement our Services, other platform that implement our Service and the use of our Services generally. Other Data that we may collect include:
      • Browser and device data, such as IP address, device type, operating system and Internet browser type, screen resolution, operating system name and version, device manufacturer and model, language, plug-ins, add-ons and the version of the Services You are using;
      • Cookie and tracking technology data, such as time spent on the Services, pages visited, language preferences, and other anonymous traffic data; and
      • Company data, such as a company’s legal structure, product and service offerings, jurisdiction, company records, and information submitted through the Iluma Atlas service.

      (Personal Data and Other Data shall be collectively referred to as “ Data ”)

    3. Should You wish to additionally avail of the services provided by Our Affiliates (as defined below) whether in the same or other jurisdiction, We may collect, request and/or ask from You additional Personal Data and/or Other Data for and on behalf of Our respective Affiliate(s) in the said jurisdiction for the conduct of customer due diligence required by applicable laws, regulations, the contractual commitments of such Affiliate with their respective bank and payment channel partners, and, in accordance with any terms and conditions and privacy policies of said Affiliate(s). Please note that once Your Data is received (collected) by our Affiliate(s), the use and processing of the Your Data shall be for such purposes as may be set out in Your relevant agreement with the Affiliate, or the Affiliate’s privacy policy or equivalent document which has been or will be communicated to You.
  4. How We Use Data
    1. Personal Data. We, Our Affiliates, and/or Our service providers use Personal Data to: (i) provide the Services; (ii) detect and prevent fraud; (iii) mitigate financial loss or other harm to Users, Customers, and Iluma; and (iv) promote, analyze and improve Our products, systems, and tools. Examples of how we may use Personal Data include:
      • To verify an identity for compliance purposes;
      • To evaluate an application to use Our Services;
      • To conduct manual or systematic monitoring for fraud and other harmful activity;
      • To respond to inquiries, send service notices and provide customer support;
      • For audits, regulatory purposes, and compliance with industry standards;
      • To develop new products;
      • To send marketing communications;
      • To improve or modify our Services; and
      • To conduct analysis and aggregations that enable Us to operate, protect, make informed decisions, and report on the performance of Our business.
    2. Other Data. We may use Other Data for a range of different purposes, provided we comply with applicable law and Our contractual commitments. Where relevant, local regulations may require Us to treat some or all of Other Data as “Personal Data” under applicable data protection laws. Where this is the case, we will process Other Data only for the same purposes as Personal Data under this Privacy Policy.

      (the data processing purposes set out in this Privacy Policy shall be referred to as the “ Data Processing Purposes ”)

      We may, from time to time, appoint a data processor and/or sub-processor (including but not limited to Our Affiliates) to carry out certain parts of the Data collection, processing, and storage in accordance with the Data Processing Purposes.

  5. How We Disclose Data
  6. Iluma does not sell or rent Personal Data to marketers or unaffiliated third parties. We share Your Personal Data with trusted third parties, including, with:

    1. Affiliates. We share Data with entities worldwide that control us, are controlled by Us, or are under Our common control (" Affiliates "), to provide Our Services.
    2. Service Providers. We share Data with service providers who help Us provide the Services to you (" Service Providers "). Service Providers help Us with things like identity verification (e.g., provider of data sources and/or electronic certificates), website hosting, data analysis, information technology and related infrastructure, customer service, email delivery, Atlas, and auditing, among others. Service providers includes data partners who help us fulfill data service requests for our Identity, Fraud and Credit products;
    3. Our Users. We share Data with Users (such as merchants and application providers) as necessary to provide the Services;
    4. Authorized Third Parties. We share data with parties directly authorized by a User to receive Data, such as when a User authorizes a third party application provider to access the User’s Iluma account. The use of Data by an authorized third party is subject to the third party’s privacy policy;
    5. Third Parties. We will share Data with third parties (on a need-to-know basis) in the event of any reorganization, merger, sale, joint venture, assignment, transfer or other disposition of all or any portion of Our business, assets or stock (including in connection with any bankruptcy or similar proceedings); and
    6. For Safety, Legal Purposes and Law Enforcement purposes. We use and disclose Data as We believe necessary: (i) under applicable law, or payment method rules; (ii) to enforce Our terms and conditions; (iii) to protect Our rights, privacy, safety or property, and/or that of Our affiliates, You or others; and (iv) to respond to requests from courts, law enforcement agencies, regulatory agencies, and other public and government authorities, which may include authorities outside Your country of residence.

    Should You wish to additionally avail the services provided by Our Affiliates whether in the same or other jurisdiction, We will share Your Personal Data to such Affiliate(s), and such Affiliate will store and process such documents, information and/or data for the purpose of providing the requested services and in accordance with any terms and conditions and privacy policies of said Affiliate. Please note that once Your Data is received (collected) by our Affiliate(s), the use and processing of the Your Data shall be for such purposes as may be set out in Your relevant agreement with the Affiliate, or the Affiliate’s privacy policy or equivalent document which has been or will be communicated to You.

    You hereby acknowledge that some of our Affiliates and/or Service Providers to whom we disclose your Data for the Data Processing Purposes may be deemed as personal data controller under prevailing laws and regulations for the relevant data processing (including but not limited to, our partners providing data sources and electronic certificates). By agreeing to this T&C and continuing the use of the Service, you are deemed to have consented to any terms and conditions and privacy policy of such Affiliates and/or partner with respect to the processing of your Data for such purposes determined by the relevant Affiliates and/or partner.

  7. Security
  8. We store all customer data encrypted in the database. Sensitive systems are physically and logically isolated to restrict access to authorized personnel only. We limit access to data based on job function and tiered approval.

    We use reasonable organizational, technical and administrative measures to protect Personal Data within Our organization. Unfortunately, no data transmission or storage system can be guaranteed to be 100% secure. If You have reason to believe that Your interaction with Us is no longer secure (for example, if You feel that the security of Your account has been compromised), please stop using Our Services and contact Us immediately.

  9. Choice and Access
  10. You have choices regarding Our use and disclosure of Your Personal Data:

    1. Opting out of receiving electronic communications from Us. If You no longer want to receive marketing-related emails from Us on a going-forward basis, You may opt-out via the unsubscribe link included in such emails. We will try to comply with Your request(s) as soon as reasonably practicable. Please note that if You opt-out of receiving marketing-related emails from us, we may still send You important administrative messages that are required to provide You with Our Services.
    2. How You can access or change Your Personal Data. If You would like to review, correct, update or delete Personal Data that You have previously disclosed to Ss, You may do so by signing in to Your Iluma account or by contacting Us. Please take note that in the event that You request for Us to delete any Personal Data that You have previously disclosed to Us, this may affect Our ability to provide any or all of the Services to You.

    In emailing Us Your request, please make clear in the email what Personal Data You would like to have changed. For Your protection, We may only implement requests with respect to the Personal Data associated with the particular email address that You use to send Us Your request, and We may need to verify Your identity before implementing Your request. We will try to comply with Your request as soon as reasonably practicable.

  11. Retention Period
  12. We emphasize that we do not store the Personal Data of Customers.

    We may conduct storage of Personal Data of Users who sign a Service Agreement with Us. We will retain Personal Data for the period necessary to fulfill the Data Processing Purposes, or upon You sending a written request to Us for the deletion and disposal of Your Data. We may dispose Data by way of deletion, erasure, sanitization and overwriting (subject to the limitations in Our system) followed with a notification of Our completion of satisfying your request. Your written request shall be acknowledgement that You will not hold Us liable or responsible for Our non-ability / non-performance to provide You future Service requests. In any event, we warrant that any Data we dispose of shall be put beyond use for any purpose whatsoever.

  13. Iluma as a Data Processor
  14. We may collect, use and disclose certain Personal Data about Customers when acting as the User’s service provider. Our Users are responsible for making sure that the Customer’s privacy rights are respected, including ensuring appropriate disclosures about Our and third party data collection and use. To the extent that we are acting as a User’s data processor, we will process Personal Data in accordance with the applicable law and/or the terms of Our agreement with the User and the User’s lawful instructions.

  15. Updates to this Privacy Policy and Notifications
  16. We may change this Privacy Policy. The "Last updated " legend at the top of this Privacy Policy indicates when this Privacy Policy was last revised. Any changes are effective within 30 (thirty) working days after the changes are notified to you through your preferred communication channel set out in the Service Agreement. It is your responsibility to periodically review this Privacy Policy as well as the communication channel mentioned above; You are bound by any changes to this Privacy Policy by continuing to use the Service after such changes have been deemed effective

    We may provide You with disclosures and alerts regarding the Privacy Policy or Personal Data We collected by posting them on Our website or, if You are a User, by contacting You through your Iluma Dashboard, email address and/or the physical address listed in Your Iluma account, at Our discretion. You agree that electronic disclosures and notices have the same meaning and effect as if we had provided You with hard copy disclosures. Disclosures and notices in relation to this Privacy Policy or Personal Data shall be considered to be received by You within twenty-four (24) hours of the time they are posted to Our website or, in the case of Users, sent to through one of means listed in this paragraph.

    In the unlikely event of a security incident or Personal Data breach, We shall manage the incident or the breach in accordance with our internal policies consistent with the applicable data protection laws and regulations, and which may include, among others, sending of timely notifications to You and/or the relevant data protection authority.

  17. Consent and Acknowledgement
  18. By accepting the Privacy Policy, You acknowledge that You have read and understood this Privacy Policy and you accept all of its terms. In particular, You agree and consent to Us collecting, using, sharing, disclosing, storing, transferring, or otherwise processing Your Personal Data in accordance with this Privacy Policy. In circumstances where You provide Us with Personal Data relating to other individuals (such as Personal Data relating to Your spouse, family members, friends, or other parties), You represent and warrant that You have obtained such individual's consent for, and hereby consent on behalf of such individual to, the collection, storage, use, disclosure, processing and disposal of his/her Personal Data by Us.

How to contact us

If you have questions or concerns regarding this privacy policy, or any feedback pertaining to Your privacy and the Iluma service that You would like us to consider, please email us at