Last updated 16 July 2026
Privacy Policy
Draft — pending legal review. This document describes how Protocol operates today, but it has not yet been reviewed by counsel. Do not rely on it as final; the published version may differ.
1. Scope
This policy explains how PT Soember Djaya Masyarakat (“Soedja”) handles data in Protocol, the payment tunnel for the Soedja ecosystem. It covers two kinds of people: the Merchants who hold Protocol accounts, and the customers whose payments flow through it.
For a customer’s personal data, the Merchant is the controller and Protocol acts on the Merchant’s behalf as a processor. For a Merchant’s own account data, Soedja is the controller.
2. What we collect
- Merchant account — email address, business name, a website or social profile, an optional logo, and (for payouts) bank name, account number, and account holder name.
- Transactions — the order reference, product name, and amount you send us on a charge, plus any customer details you choose to pass (first name and, optionally, email and phone).
- Technical — request metadata, IP address, and logs needed to operate, secure, and audit the service.
- No card data. We never receive raw card numbers. Cards are tokenised in the browser directly by our payment processing provider; other methods carry no card data at all.
3. How we use it
- To create and settle payments, and to notify your server of the result.
- To compute your balance, verify bank accounts, and make payouts.
- To secure the service, prevent fraud and abuse, and keep an audit trail.
- To send transactional email about your account, payouts, and bank status.
We do not sell personal data, and we do not use customer payment data for our own marketing.
5. How we protect it
- API keys are stored as a one-way hash plus an encrypted copy; webhook secrets and stored keys are encrypted at rest (AES-256-GCM).
- Every Merchant’s data is isolated at the database layer — one Merchant can never read another’s transactions, balance, bank details, or credentials.
- Sandbox and production are separated so test data and real money never share a table.
- Access to the underlying systems is limited and audited.
6. Retention
We keep transaction and payout records for as long as needed to operate the service and to meet legal, tax, accounting, and audit obligations. Account data is kept while your account is active and for a reasonable period afterwards.
7. Your rights and choices
Subject to applicable law, you may request access to, correction of, or deletion of your Merchant account data, and you can update most of it directly in your dashboard. Requests about a customer’s personal data should be directed to the Merchant that collected it; we will assist that Merchant as their processor.
9. Changes and contact
We may update this policy; material changes will be communicated. Questions or requests: agie@soemberdjaya.com.