Data Privacy & Compliance

Data Processing Addendum (DPA)

Last updated: August 30, 2026 • Compliant with Indonesian PDP Law (UU No. 27/2022) & GDPR

1. Scope and Applicability

This Data Processing Addendum ("DPA") supplements the Borobudur.ai Terms of Service when Borobudur.ai processes Personal Data on behalf of the Customer in connection with the provision of the Services.

2. Roles of the Parties

The Customer acts as the Data Controller (or Data Controller representative) and Borobudur.ai acts as the Data Processor with respect to customer messaging contacts, chat transcripts, and audience data.

3. Processing Instructions

Borobudur.ai shall process Customer Personal Data only on documented instructions from the Customer, including with respect to transfers of data, unless required to do so by applicable law.

4. Technical and Organizational Security

Borobudur.ai implements and maintains comprehensive technical and organizational security measures designed to protect Customer Personal Data against unauthorized access, destruction, loss, or alteration:

  • End-to-end encryption in transit (TLS 1.3) and AES-256 at rest.
  • Strict multi-tenant tenant isolation and scoped database queries.
  • Granular role-based access control (RBAC) and multi-factor authentication (MFA).
  • Regular automated vulnerability scans, patch management, and audit logging.

5. Sub-processors

Customer grants general authorization for Borobudur.ai to engage sub-processors (including Google Cloud Platform and Meta Platforms, Inc.) necessary to fulfill the Services. We maintain written agreements ensuring that each sub-processor meets equivalent data protection obligations.

6. Data Deletion and Return

Upon termination of the agreement, Borobudur.ai shall, at Customer's written request, delete or return all Customer Personal Data within 30 calendar days, unless applicable statutory regulations mandate longer retention.