01 Introduction
Five Cloud AI (“we,” “us,” or “the Company”) is committed to protecting the privacy of the individuals and organizations we serve. This Privacy Policy describes the categories of information we collect, the purposes for which we process it, and the rights you have as a data subject.
This policy applies to all interactions with our website, hosted applications, communication channels, and client engagements unless a separate written agreement (such as a Master Services Agreement or Data Processing Addendum) states otherwise.
02 Information We Collect
We collect only the data necessary to deliver our services and operate our business responsibly. The categories include:
- Identification data: name, business email, phone number, company name, and role.
- Engagement data: project briefs, requirements documentation, and correspondence necessary to scope and execute work.
- Technical data: IP address, browser type, device identifiers, and access logs collected automatically through standard web analytics and security monitoring.
- Payment data: invoicing information and transaction references. We do not store full card data; payments are processed by regulated third-party processors.
- System data (where applicable): for systems we build and host on your behalf, we may process the operational data residing in those systems strictly as a processor under your instructions.
03 How We Use Information
We use the data we collect to:
- Provide, operate, and maintain our products and services;
- Communicate with clients regarding active engagements, support, billing, and contractual matters;
- Improve and develop new features, with a focus on the legitimate interest of operating a sustainable business;
- Comply with legal obligations, including tax, regulatory, and audit requirements applicable in the Republic of Indonesia;
- Detect and prevent fraud, abuse, and unauthorized access to systems we operate.
We do not sell personal data. We do not use client engagement data to train general-purpose AI models without explicit written consent.
04 Data Sharing & Disclosure
We disclose information only when necessary and only to recipients bound by appropriate confidentiality obligations:
- Service providers: reputable infrastructure providers (cloud hosting, monitoring, communication, payments) that act under contract and process data on our behalf.
- Legal requirements: where compelled by valid court orders, lawful government requests, or applicable regulation.
- Business transfers: in the event of a merger, acquisition, or sale of assets, subject to continued protection commitments.
05 Data Retention
We retain personal data only as long as necessary to fulfil the purposes outlined in this policy or to comply with legal, accounting, and reporting obligations. Engagement records are typically retained for up to seven years after the conclusion of the relationship, in line with Indonesian tax and commercial record-keeping requirements. Upon written request and where no overriding legal obligation exists, we will delete or anonymize personal data within a reasonable timeframe.
06 Security Practices
We implement technical and organizational measures appropriate to the sensitivity of the data we handle, including encrypted transport (TLS), encrypted backups, principle-of-least-privilege access controls, multi-factor authentication for administrative access, and continuous monitoring of production systems. No method of transmission or storage is perfectly secure; we therefore design systems to minimize the impact of any single failure.
07 Your Rights
Subject to applicable law, you may request to:
- Access the personal data we hold about you;
- Correct or update inaccurate or incomplete information;
- Request deletion of your data, where no overriding legal obligation requires retention;
- Withdraw consent where processing relies on consent;
- Object to or restrict certain processing activities.
Requests should be directed to the contact address in Section 10. We will respond within a reasonable timeframe and may verify your identity before acting on the request.
08 International Transfers
We are based in the Republic of Indonesia. Some of the service providers we rely on (cloud infrastructure, communication, and analytics) are headquartered abroad and may process data outside Indonesia. Where this is the case, we ensure that recipients are bound by contractual protections substantially equivalent to those required under applicable Indonesian data protection law.
09 Policy Updates
We may amend this policy from time to time to reflect changes in our practices, the services we provide, or the legal landscape. Material changes will be communicated through prominent notice on this page or, where appropriate, direct notification. The “Effective” date at the top of this page indicates the most recent revision.
10 Contact
Questions, requests, or complaints regarding this policy may be addressed to:
Five Cloud AI
Email: information.fikri@gmail.com
WhatsApp: +62 853-4817-3761