Last updated 16 July 2026
Terms of Service
Draft — pending legal review. This document describes how Protocol operates today, but it has not yet been reviewed by counsel. Do not rely on it as final; the published version may differ.
1. Who we are
Protocol is the central payment tunnel operated by PT Soember Djaya Masyarakat (“Soedja”, “we”, “us”). It lets companies in the Soedja ecosystem (each a “Merchant”) accept payments from their customers through a single merchant of record held with our payment processing provider (currently Midtrans), and receive signed notifications when a payment settles. These Terms govern a Merchant’s use of Protocol.
By creating an account, requesting credentials, or calling the API, you agree to these Terms on behalf of the Merchant you represent.
2. Accounts and approval
- A Merchant signs up with an email address and provides its business name, a website or social profile, and (for payouts) a bank account.
- Sandbox access is granted automatically. No real money moves in sandbox, and it exists so you can build and test end to end.
- Production access requires human approval. We review each Merchant before issuing live credentials, and we may decline or delay approval at our discretion.
- You are responsible for the accuracy of the information you provide and for all activity under your account.
3. API keys and security
- Your API key authenticates charges as you. Keep it on your server; never embed it in client-side code, a mobile app, or a public repository.
- Your webhook secret verifies that a notification genuinely came from Protocol. Keep it equally private.
- You may reveal or rotate your credentials from your dashboard at any time. Rotating invalidates the previous key immediately.
- You are responsible for any activity performed with your credentials until you rotate them. Tell us promptly if you believe they are compromised.
4. Payments and card data
- Protocol never receives raw card numbers. Card details are tokenised in the customer’s browser directly by our payment processing provider; QRIS, virtual accounts, and e-wallets carry no card data at all.
- You must present accurate order information on each charge, and must not use Protocol for anything unlawful, fraudulent, or prohibited by our payment processing provider or the relevant payment networks.
- Chargebacks, refunds, and disputes are governed by our payment processing provider and the payment networks. A refunded transaction is removed from your balance.
5. Fees
Your payable balance is the amount you receive net of fees: the payment fee charged by the payment method, and a flat Protocol platform fee per successful transaction. Fees are calculated and fixed at the moment a transaction settles, and shown on each transaction in your dashboard.
6. Balance and payouts
- Funds from a paid transaction become available four business days after the customer pays. This holding period lets refunds and disputes settle before money leaves.
- Payouts are made manually by the Protocol team to your verified bank account. You request an amount up to your available balance; we transfer it and record the bank reference.
- Changing your bank details requires re-verification, and payouts to that account pause until an administrator approves the change. This protects you against account takeover.
- We may withhold or delay a payout where we reasonably suspect fraud, a dispute, or a breach of these Terms.
7. Webhooks and idempotency
Protocol posts a signed notification to your webhook URL when a payment changes state. You must verify the signature, reject stale timestamps, and fulfil idempotently keyed on order_id — Protocol may legitimately re-deliver the same event, and your system must not double-fulfil.
8. Suspension and termination
We may suspend or terminate a Merchant’s access — including refusing charges and pausing payouts — if we reasonably believe the Merchant has breached these Terms, poses a fraud or compliance risk, or on instruction from our payment processing provider or a payment network. You may stop using Protocol at any time.
9. Disclaimers and liability
Protocol is provided “as is”. To the maximum extent permitted by law, we disclaim implied warranties and are not liable for indirect, incidental, or consequential losses. Protocol depends on our payment processing provider and the payment networks; we are not responsible for their outages, decisions, or fees beyond passing them through as described.
10. Changes and governing law
We may update these Terms; material changes will be communicated to Merchants. These Terms are governed by the laws of the Republic of Indonesia, and disputes are subject to the jurisdiction of the competent courts in Indonesia.
Questions: agie@soemberdjaya.com.