Legal

Privacy Policy

Last updated: June 29, 2026

This Privacy Policy explains how PT AureX Teknologi Indonesia ("AureX", "we", "us", or "our") collects, uses, discloses, and protects your personal data when you use the AureX platform, and the choices and rights available to you. We are committed to handling your data responsibly and in accordance with applicable data protection laws, including Indonesia's Law No. 27 of 2022 on Personal Data Protection (the "PDP Law").

1. Information We Collect

We collect the following categories of personal data:

  • Account data — your email address, hashed password, and profile or preference settings you provide.
  • Subscription and billing data — plan selection, transaction records, and limited payment metadata. Card and payment details are processed by our payment provider and are not stored by us.
  • Usage data — watchlists, screeners, queries, features used, and interactions with the Service.
  • Technical data — IP address, device and browser type, log data, and approximate location derived from IP.
  • Cookies and similar technologies — used for authentication sessions, preferences, security, and analytics (see Section 7).

2. How We Use Your Information

We use personal data to:

  • Provide, operate, secure, and maintain the Service and your account;
  • Authenticate you and manage sessions and access controls;
  • Process subscriptions, billing, and related communications;
  • Personalise your experience, such as saved watchlists and preferences;
  • Monitor, analyse, and improve the performance, reliability, and features of the Service;
  • Detect, prevent, and address fraud, abuse, security incidents, and violations of our Terms;
  • Comply with legal obligations and enforce our agreements.

3. Legal Bases for Processing

Where the PDP Law or other applicable law requires a legal basis, we rely on: your consent; the performance of a contract with you (providing the Service); compliance with a legal obligation; and our legitimate interests in operating, securing, and improving the Service, provided those interests are not overridden by your rights.

4. How We Share Information

We do not sell your personal data. We share it only as necessary and with appropriate safeguards, including with:

  • Service providers and processors — such as cloud hosting, database, caching, payment processing, and analytics providers acting on our instructions;
  • Professional advisers and authorities — where required to comply with law, regulation, legal process, or a lawful government request;
  • Business transfers — in connection with a merger, acquisition, financing, or sale of assets, subject to confidentiality;
  • With your consent — where you direct us to share your information.

5. Data Retention

We retain personal data for as long as your account is active and as needed to provide the Service, and thereafter as required to comply with legal, accounting, tax, or reporting obligations, resolve disputes, and enforce our agreements. When data is no longer needed, we delete or anonymise it.

6. Data Security

We implement technical and organisational measures designed to protect personal data, including encryption in transit, hashed credentials, access controls, and session management. No method of transmission or storage is completely secure, and we cannot guarantee absolute security. You are responsible for keeping your credentials confidential.

7. Cookies and Similar Technologies

We use cookies and similar technologies that are strictly necessary for authentication and security, as well as cookies that remember your preferences and help us understand how the Service is used. You can control cookies through your browser settings; disabling certain cookies may affect the functionality of the Service, including the ability to stay signed in.

8. International Data Transfers

Your personal data may be processed or stored on servers located outside your country of residence. Where we transfer data internationally, we take steps to ensure an adequate level of protection consistent with applicable law, including the PDP Law.

9. Your Rights

Subject to applicable law, you may have the right to access, correct, update, or delete your personal data; to object to or restrict certain processing; to withdraw consent; to request data portability; and to lodge a complaint with the relevant supervisory authority. To exercise these rights, contact us using the details in Section 12. We may need to verify your identity before responding.

10. Children's Privacy

The Service is not directed to individuals under the age of 18, and we do not knowingly collect personal data from children. If you believe a child has provided us with personal data, please contact us and we will take appropriate steps to delete it.

11. Changes to this Policy

We may update this Privacy Policy from time to time. When we make material changes, we will update the "Last updated" date above and, where appropriate, provide additional notice. Your continued use of the Service after the changes take effect constitutes acceptance of the updated policy.

12. Contact Us

For privacy questions or to exercise your rights, contact our privacy team at privacy@aurex.id or write to PT AureX Teknologi Indonesia, Jakarta, Indonesia. See also our Terms of Service.