Privacy Policy
PT BEYOND TRADING INTERNASIONAL
Effective Date: July 12, 2026
This Privacy Policy applies to all services provided by PT BEYOND TRADING INTERNASIONAL (“BTI”, “we”, “us”, “our”), including data center leasing, GPU-as-a-Service (GaaS), proprietary AI applications (OpenI AI Assistant, GenPic E-commerce Visual Assistant), high-performance computing, cloud infrastructure, and all websites operated by BTI, primarily https://www.beyondtrading.id.
This Policy complies with Indonesia Law No. 27/2022 on Personal Data Protection (PDP Law), Electronic Information and Transactions Law No. 11/2008, ISO 27001, ISO 27017, ISO 27701, ISO 22301, and SOC 2 Type II standards. It describes how we collect, use, store, share, protect and delete personal data and business data, and sets forth your legal rights as a data subject or enterprise customer.
1. Definitions
1.1 Personal Data: Any information that identifies or can identify a natural person, including name, email, phone number, company contact details, biometric information, payment credentials, location data, account login credentials, and sensitive personal data such as financial records.
1.2 Customer Business Data: All datasets, model weights, images, texts, training materials, e-commerce assets, enterprise documents, and workload content uploaded, stored or processed by Customers via BTI’s GPU clusters, data centers and AI platforms. Business Data may contain Personal Data at your sole responsibility.
1.3 Data Subject: Natural person whose Personal Data is processed by BTI.
1.4 Customer / Off-Taker: Enterprise, organization, developer or merchant subscribing to BTI computing infrastructure and AI services.
1.5 Processing: Any operation on data, including collection, storage, usage, transmission, disclosure, archiving, deletion and destruction.
1.6 SI Partner: PT Digital Integrasi Nusantara, our authorized system integrator providing deployment, network and on-site maintenance services.
2. Data We Collect
2.1 Personal Data We Collect Directly
We collect Personal Data you voluntarily provide when registering accounts, signing service agreements, contacting sales, submitting support tickets, or completing deployment documentation:
- Corporate contact information: Full name, job title, business email, mobile phone, company name, tax ID, registered address
- Account credentials: Username, encrypted passwords, API access keys, VPN authentication information
- Payment data: Invoicing details, bank account information, billing addresses
- Communication records: Emails, support chat logs, meeting records, contract documents
- On-site access data: Biometric records, RFID access logs, two-factor authentication logs for data center cage entry
2.2 Automatically Collected Technical Data
When you access our website, GaaS console or AI applications, we automatically collect non-identifiable technical logs for platform stability and security monitoring:
- Device information, browser type, IP address, access timestamp, page access records
- GPU workload metrics, server runtime logs, auto-scaling event data, network traffic statistics
- System telemetry data for cooling, power and cluster performance monitoring (no embedded personal identifiers)
2.3 Customer Business Data
All content uploaded to our infrastructure by you, including LLM training datasets, product images, 3D rendering files, enterprise internal documents, cross-border e-commerce materials, and data processed via OpenI / GenPic AI tools. You retain full ownership of all Business Data.
3. Purpose of Data Processing
We only process your data for legitimate, stated business purposes and will not repurpose data without your explicit consent:
3.1 To deliver contracted services: Data center hosting, GPU cluster allocation, serverless inference, AI application operation, network deployment, and 7×24 technical support.
3.2 Account & identity management: User authentication, access control, steel cage physical security management, and prevention of unauthorized cluster access.
3.3 Billing, invoicing and payment reconciliation, including audit records for network procurement and deployment projects.
3.4 Platform maintenance, fault diagnosis, performance optimization, security threat detection and zero-trust cluster protection.
3.5 Compliance obligations: Fulfill Indonesian PDP Law, ISO/SOC 2 audit requirements, respond to legal, judicial or regulatory authority requests.
3.6 Service communication: Send maintenance alerts, SLA notifications, contract updates, and technical upgrade announcements.
3.7 Safety incident response: Data breach investigation, risk remediation and mandatory regulatory notification under PDP Law.
3.8 Limited marketing: Only send service updates to customers who opt in; you may unsubscribe at any time.
4. Data Storage & Security Measures
4.1 Storage Location
All data (Personal Data and Customer Business Data) is primarily stored within BTI’s Indonesia domestic data center facilities, in accordance with Indonesian cross-border data transfer restrictions. Cross-border data transmission will only occur with your written consent and full compliance with PDP Law offshore transfer safeguards.
4.2 Industry-Leading Security Controls (Aligned with Website Infrastructure Introduction)
- Physical Security: Isolated steel cage clusters, multi-stage access control with biometrics, RFID and 2FA; 24/7 on-site security patrols.
- Network & Logical Security: Zero-trust architecture, IPsec VPN isolated access, VLAN hardware segmentation, full end-to-end storage encryption, DDoS cleaning clusters.
- Infrastructure Redundancy: N+1 to N+N redundant liquid & air cooling systems, uninterrupted power supply, multi-backup persistent storage to prevent data loss.
- Access Governance: Strict least-privilege staff access; all internal data access logged and audited; non-disclosure agreements mandatory for all employees and SI partners.
- Compliance Certifications: Full adherence to ISO 27001, ISO 27017, ISO 27701, ISO 22301, SOC 2 Type II.
- Data Erasure: Secure cryptographic wiping of all storage media before hardware recycling or redeployment.
4.3 Data Retention Period
- Contract & billing Personal Data: Retained for 7 years after service termination to satisfy tax and commercial legal requirements.
- Account login & access logs: Retained for 2 years for security audit.
- Customer Business Data: Stored for the duration of your service term. Upon service termination, you have 30 days to export all data; after this period, BTI will permanently delete all Business Data without residual backup, unless legal retention is required.
- Marketing contact records: Retained until you submit an opt-out request.
5. Sharing & Disclosure of Your Data
We will never sell, rent or trade your Personal Data or Business Data to third parties for commercial marketing without your separate written consent. Limited sharing only occurs under the following scenarios:
5.1 Authorized SI Partner (PT Digital Integrasi Nusantara): Only share necessary contact and deployment information required to complete on-site hardware installation, network commissioning and maintenance. The SI is contractually bound to implement equivalent data protection standards and prohibited from secondary disclosure.
5.2 Legal & Regulatory Requests: We may disclose data when compelled by Indonesian government agencies, courts or law enforcement, in strict compliance with PDP Law and judicial procedures. We will notify you of such requests where legally permitted.
5.3 Service Continuity: In case of corporate restructuring, merger or asset transfer, data protection obligations will transfer to the successor entity, and we will notify customers in advance.
5.4 Emergency Risk Mitigation: To protect BTI, customers or third parties from severe safety, cybersecurity or financial harm.
6. Cross-Border Data Transfer
Transferring Personal Data outside Indonesia is restricted under PDP Law. Any offshore transmission of your data will only proceed if:
- You provide explicit, written consent;
- The receiving country implements adequate data protection standards recognized under Indonesian regulation;
- We execute binding data transfer agreements with overseas recipients to enforce equivalent privacy safeguards.
Our global GPU nodes in USA and Europe are separated from Indonesian customer workloads by default; cross-region workload migration requires your formal signed approval.
7. Rights of Data Subjects (Under Indonesia PDP Law No.27/2022)
As a data subject, you hold the following enforceable rights, which you may exercise free of charge by emailing contact@beyondtrading.id:
7.1 Right to Access: Request a full copy of all Personal Data we store about you.
7.2 Right to Rectification: Correct inaccurate, incomplete personal information.
7.3 Right to Erasure (“Right to be Forgotten”): Request permanent deletion of your Personal Data when processing is no longer necessary or you withdraw consent.
7.4 Right to Restrict Processing: Suspend data processing under specific legal grounds.
7.5 Right to Data Portability: Receive your personal data in a machine-readable format for transfer to another service provider.
7.6 Right to Object: Opt out of marketing communications or processing based on legitimate interest.
7.7 Right to Withdraw Consent: Revoke any prior consent for data processing at any time, without penalty.
7.8 Right to Lodge a Complaint: File a privacy complaint with Indonesia’s Personal Data Protection Authority or notify our dedicated data protection contact.
For enterprise Customers requesting deletion or export of Business Data stored on our GPU clusters, submit a formal written request via business email; we will complete data export or secure erasure within 10 working days.
8. Data Breach Notification
If we identify a confirmed Personal Data or Business Data security breach that creates substantial risk to your privacy or assets:
- We will contain and remediate the incident immediately;
- Notify affected data subjects and the Indonesian PDP authority within the mandatory regulatory timeframe;
- Provide full incident details, impact scope and recommended mitigation steps via email and official website announcement.
9. Cookies & Website Tracking
Our website https://www.beyondtrading.id uses functional cookies to maintain session login, load page preferences and analyze anonymous website traffic. We do not use tracking cookies for targeted advertising without your consent.
You may disable cookies via your browser settings at any time, though some website functions may be restricted.
10. Children’s Privacy
BTI’s infrastructure, GaaS and AI services are designed for commercial, enterprise and professional developer use. We do not knowingly collect Personal Data from minors under 18 years old. If you become aware we hold minor data without parental consent, contact us immediately for permanent deletion.
11. Third-Party Links
Our website may contain hyperlinks to partner websites (including SI site https://www.digitalintegrasi.id). This Privacy Policy does not apply to external third-party platforms, and we bear no responsibility for their independent data handling practices. Please review their separate privacy policies before providing personal information.
12. Updates to This Privacy Policy
We reserve the right to revise this Policy to reflect regulatory updates, service expansion or security upgrades. Material changes will be published on our official website with a clear updated effective date, and enterprise customers with active contracts will receive notification via registered business email. Continued use of BTI services after the effective update date constitutes acceptance of the revised Policy.
13. Contact Information for Privacy Inquiries
For all privacy requests, data subject right applications, breach reports or policy clarification:
- Email: contact@beyondtrading.id
- Postal Address: SOHO Capital, Central Park, 32nd Floor, No.7, Jalan Letjen S Parman, Kavling 28, RT.003 RW.005, Tanjung Duren Selatan, Grogol Petamburan, West Jakarta, DKI Jakarta 11470, Indonesia
- Company Entity: PT BEYOND TRADING INTERNASIONAL
- Regulatory Compliance: We maintain internal data protection management processes aligned with Indonesia PDP Law 27/2022.
14. Governing Law
This Privacy Policy is governed exclusively by the laws of the Republic of Indonesia. Any dispute arising from data privacy processing shall be resolved in the competent courts of West Jakarta.