Skip to main content
TARG Systems

Legal & Commercial · Legal

Data Processing Agreement.

Last updated 29 August 2026. This Data Processing Agreement governs how TARG Systems processes personal data contained in Customer Data on behalf of its customers in the TARG ONE platform.

Data Processing Agreement details

Introduction and scope

This Data Processing Agreement (the "DPA") forms part of the agreement between PT Targ Systems Indonesia ("TARG Systems", the "Processor") and the customer identified in the applicable Order Form or account registration (the "Controller") for the provision of the TARG ONE platform and related services (the "Services"), whether that agreement is the Terms of Service or a signed Master Services Agreement (the "Agreement").

This DPA applies to the extent TARG Systems processes personal data contained in Customer Data on behalf of the Controller in the course of providing the Services. Terms not defined in this DPA have the meaning given in the Agreement. "Data Protection Laws" means the data protection and privacy laws applicable to the processing under the Agreement, including Indonesian Law No. 27 of 2022 on Personal Data Protection and, where applicable, the EU General Data Protection Regulation.

In the event of a conflict between this DPA and the Agreement regarding the processing of personal data, this DPA prevails.

Roles and instructions

The parties acknowledge that, for personal data contained in Customer Data, the Customer acts as controller and TARG Systems acts as processor. TARG Systems will process such personal data only on documented instructions from the Controller, including the Agreement, this DPA, the Controller's configuration and use of the Services, and other written instructions agreed by the parties, unless processing is required by applicable law, in which case TARG Systems will inform the Controller of that legal requirement before processing, unless the law prohibits such information on important grounds of public interest.

TARG Systems will promptly inform the Controller if, in its opinion, an instruction infringes Data Protection Laws. The Controller is responsible for the lawfulness of the personal data it submits to the Services, including establishing a lawful basis and providing any required notices to data subjects.

Details of processing

  • Subject matter: provision of the TARG ONE platform and related services under the Agreement.
  • Duration: the term of the Agreement, plus the post-termination export and deletion period described below.
  • Nature and purpose: hosting, storage, computation, display, transmission, backup, support, and related processing needed to deliver the Services.
  • Categories of data subjects: the Controller's employees, contractors, and other personnel; the Controller's customers, suppliers, and business partners and their personnel; and other individuals whose data the Controller submits to the Services.
  • Categories of personal data: identification and contact details, employment and role information, commercial and transactional records, financial data relating to business dealings, and other personal data the Controller chooses to submit to the Services.
  • Special categories of data: the Services are not designed for special categories of personal data, and the Controller agrees not to submit such data unless the parties have agreed additional safeguards in writing.

Confidentiality of processing

TARG Systems will ensure that persons authorized to process personal data are bound by confidentiality obligations, whether contractual or statutory, and process personal data only as needed to provide the Services.

Security measures

Taking into account the state of the art, the costs of implementation, and the nature, scope, context, and purposes of processing, TARG Systems will implement and maintain appropriate technical and organizational measures to protect personal data against accidental or unlawful destruction, loss, alteration, unauthorized disclosure, or access. These measures include, at a minimum, the measures described in the Annex to this DPA.

TARG Systems may update its security measures from time to time, provided that updates do not materially reduce the overall level of protection during the term of the Agreement.

Sub-processors

The Controller provides general authorization for TARG Systems to engage sub-processors to support the provision of the Services, such as cloud infrastructure and communications providers. TARG Systems will maintain a current list of sub-processors and make it available to the Controller on request, and will impose on each sub-processor data protection obligations that are materially no less protective than those in this DPA.

TARG Systems will notify the Controller in advance of the addition or replacement of a sub-processor. The Controller may object on reasonable data protection grounds within fourteen (14) days of the notice. If the parties cannot resolve the objection, the Controller may terminate the affected Services and receive a pro-rata refund of prepaid, unused fees for the terminated portion. TARG Systems remains responsible for the performance of its sub-processors' obligations.

International transfers

TARG Systems will not transfer personal data to a country other than the country in which it was collected unless the transfer complies with Data Protection Laws, including, where required, ensuring an adequate level of protection in the receiving jurisdiction, implementing appropriate safeguards such as approved contractual clauses, or relying on another lawful transfer mechanism.

Assistance to the Controller

Taking into account the nature of the processing, TARG Systems will assist the Controller by appropriate technical and organizational measures, insofar as this is possible, in fulfilling the Controller's obligations to respond to data subject requests, such as access, correction, deletion, restriction, objection, and portability. If TARG Systems receives a request directly from a data subject relating to Customer Data, it will, to the extent legally permitted, refer the data subject to the Controller and notify the Controller of the request.

TARG Systems will also provide reasonable assistance to the Controller with data protection impact assessments and consultations with supervisory authorities, to the extent required by Data Protection Laws and related to the Services, taking into account the information available to TARG Systems.

Personal data breach notification

TARG Systems will notify the Controller without undue delay after becoming aware of a personal data breach affecting Customer Data. The notification will describe, to the extent known, the nature of the breach, the categories and approximate volumes of data and data subjects concerned, the likely consequences, and the measures taken or proposed to address the breach and mitigate its effects. TARG Systems will provide timely updates as further information becomes available and will reasonably cooperate with the Controller's own notification obligations. Notification of a breach is not an acknowledgment of fault or liability.

Audits and information

TARG Systems will make available to the Controller information reasonably necessary to demonstrate compliance with this DPA, including summaries of relevant security documentation and, where available, third-party assessment reports. Where such information is insufficient to demonstrate compliance, the Controller may conduct, at its own cost, an audit of TARG Systems' processing of Customer Data, no more than once per twelve (12) month period unless required by a supervisory authority or following a personal data breach, on at least thirty (30) days' written notice, during business hours, subject to reasonable confidentiality and security requirements, and without unreasonable disruption to TARG Systems' operations.

Return and deletion of data

Upon termination or expiry of the Agreement, TARG Systems will, at the Controller's choice communicated in writing within thirty (30) days, return Customer Data in a commonly used, machine-readable format or delete it, and will delete remaining copies after the export window closes, unless applicable law requires continued storage. Data in backup systems will be deleted in accordance with TARG Systems' backup rotation schedule and remains protected by this DPA until deletion.

Liability and order of precedence

Each party's liability under this DPA is subject to the limitations and exclusions of liability set out in the Agreement, except to the extent liability cannot be limited under Data Protection Laws. This DPA replaces any prior data processing terms between the parties for the Services.

Annex: technical and organizational measures

Access control

  • Role-based access controls within the platform, configurable by the Controller.
  • Authentication requirements for all users, with support for strong password policies.
  • Internal access to production systems restricted to authorized personnel on a need-to-know basis, with logging of administrative access.

Encryption and network security

  • Encryption of data in transit using industry-standard protocols.
  • Encryption at rest for production data stores where supported by the hosting infrastructure.
  • Network segmentation, firewalls, and hardened configurations for production environments.

Availability and resilience

  • Regular backups of production data with defined retention and restoration procedures.
  • Monitoring and alerting for availability, capacity, and anomalous behavior.
  • Documented incident response procedures with defined roles and escalation paths.

Organizational measures

  • Confidentiality commitments for personnel and security awareness practices.
  • Change management and code review practices for changes to production systems.
  • Vendor evaluation for sub-processors, including review of their security practices.
  • Periodic review of security measures and of this Annex.