Orionex General Privacy Policy

Version

1.6

Status

published

Effective Date

2026-04-01

Last Revision

2026-03-28

Introduction and Scope

PT Orionex Solusi Digital ("Orionex Solutions," "Orionex," "we," "us," or "our"), located at Gedung Wirausaha, Jalan H. R. Rasuna Said Kav. C No. 5, Setiabudi, Jakarta Selatan, 12920, Indonesia, is committed to handling Personal Data transparently and in accordance with applicable law.

This Privacy Policy explains how Orionex collects, uses, stores, discloses, transfers, and deletes Personal Data in connection with Orionex's current shared corporate services, including:

  • Orionex websites and lead-capture channels;
  • Orionex Identity;
  • Orionex Pay;
  • IT Consulting services;
  • Custom Software Development services; and
  • Luncurin.

Not every category of Personal Data described in this Policy applies to every Service.

Use of the Services is also governed by our Terms of Service and any applicable product-specific addendum or product-specific privacy notice. For Luncurin, the Luncurin Privacy Policy and the Luncurin Product Terms and Data Addendum supplement this Policy. If there is a direct conflict for Luncurin-specific Processing, the more product-specific Luncurin privacy document controls for that product, provided it does not reduce the data-protection standards established in this Policy. For browser cookies, local storage, analytics tags, and similar website technologies, the Cookie Policy supplements the Privacy Policy.

Categories of Personal Data We Process

We may process the following categories of Personal Data, depending on the Service used and the role Orionex performs. Orionex collects only the Personal Data that is adequate, relevant, and limited to what is necessary for the purposes described in this Policy.

Under UU No. 27 Tahun 2022 (Pelindungan Data Pribadi), Personal Data is classified as either general Personal Data (data pribadi yang bersifat umum) or specific Personal Data (data pribadi yang bersifat spesifik). Of the categories below, Billing and Transaction Data — including NPWP and financial transaction records — may constitute specific Personal Data (financial data) under UU PDP and is subject to heightened protection requirements accordingly.

(a) Lead and Business Contact Data

Examples include:

  • full name;
  • business email address;
  • phone number;
  • company name;
  • job title;
  • inquiry type;
  • message content;
  • company size;
  • project timeline;
  • budget range;
  • technical context;
  • Consent and marketing preference fields; and
  • related submission metadata.

(b) Account and Identity Data

Examples include:

  • name;
  • email address;
  • phone number;
  • company or organization name;
  • Orionex user ID or similar account identifier;
  • profile picture;
  • role or permission assignments;
  • authentication and verification status;
  • identity-provider metadata received from shared identity services.

(c) Billing and Transaction Data

Examples include:

  • customer name;
  • email address;
  • phone number;
  • company name;
  • billing address;
  • NPWP or other tax identifier where required;
  • invoice items;
  • order, invoice, and payment metadata;
  • amounts and payment status; and
  • reference and callback fields associated with payment flows.

(d) Service and Project Data

Examples include:

  • project instructions;
  • uploaded files and assets;
  • website drafts and configuration data;
  • support messages;
  • implementation materials;
  • business content submitted for a project or product workflow; and
  • other content processed through Orionex services.

(e) Technical, Security, and Audit Data

Examples include:

  • IP address;
  • browser, operating system, and device information;
  • user agent;
  • session identifiers;
  • login verification records;
  • token, auth-code, or refresh metadata;
  • request and audit logs;
  • fraud and abuse indicators; and
  • approximate (non-precise) location derived from IP address.

(f) Cookies, Local Storage, and Similar Technologies

We may process data through cookies, local storage, session storage, analytics identifiers, and similar technologies used for authentication, fraud prevention, preferences, session continuity, and analytics.

(g) AI Interaction Data

Where AI-assisted features are enabled, we may process:

  • prompts;
  • outputs;
  • extracted business or configuration data;
  • trace identifiers; and
  • related usage or audit information.

Orionex uses API-based integrations with AI providers (currently OpenAI and Google Gemini) and has configured those integrations to opt out of provider-side model training for input and output data. Orionex does not use AI interaction data to train or fine-tune its own or third-party AI models unless you have separately and expressly authorized that use.

(h) Data Received from Third Parties and Shared Orionex Services

We may receive relevant data from:

  • shared Orionex services such as Orionex Identity and Orionex Pay;
  • upstream identity providers such as Firebase Authentication;
  • payment callbacks and reconciliation flows;
  • email delivery services;
  • analytics or geolocation services; and
  • other providers listed in Section 4.

(i) Approved Publicity and Reference Data

Where Orionex has prior written approval or contractual permission to refer to a customer as a reference, relevant data may include:

  • customer or company name;
  • logo or brand assets;
  • approved project description, case-study summary, or reference statement; and
  • approval records or contractual permissions relating to that customer-reference use.

If Orionex processes Client Project Data for IT Consulting or Custom Software Development, Orionex processes that data as a Processor unless the applicable contract states otherwise.

Roles, Purposes, and Legal Bases

(a) Orionex Roles

Orionex generally acts as:

  • Controller for Orionex's own sales, contact, account, authentication, billing, support, administrative, security, fraud-prevention, and compliance data; and
  • Processor for client project or service data handled in IT Consulting and Custom Software Development, unless the applicable contract states otherwise.

Product-specific addendums may clarify how this allocation works for a specific product.

(b) Purposes and Legal Bases

PurposeTypical DescriptionOrionex RoleLegal Basis / Basis for Processing
Lead Capture and Business DiscussionsHandling inquiries, proposals, demos, and business communicationControllerPre-contract steps, Legitimate Interests, and Consent where required for marketing follow-up
Account, Identity, and Access ManagementCreating and managing accounts, authentication, session continuity, and verificationControllerPerformance of contract and Legitimate Interests for service security
Service DeliveryProviding Orionex services, including Luncurin, consulting, and custom developmentController or Processor depending on servicePerformance of contract and, where Orionex acts as Processor, documented client instructions
Billing and Payment AdministrationIssuing invoices, Processing payments, preventing payment abuse, and meeting accounting/tax obligationsControllerPerformance of contract, legal obligation, and Legitimate Interests for fraud prevention
Support and Service CommunicationsResponding to support inquiries, service updates, and operational noticesControllerPerformance of contract and Legitimate Interests
Security, Audit, and Fraud PreventionDetecting abuse, verifying devices, protecting systems, and maintaining audit trailsControllerLegitimate interests and legal obligation where applicable
Service Improvement and AnalyticsUsing aggregated, de-identified, or anonymized information (such that it no longer constitutes Personal Data under applicable law) to measure, maintain, improve, and develop Orionex services, workflows, analytics, and security controlsController or Processor depending on the source data and applicable contractLegitimate interests, performance of contract, or documented client instructions where Orionex acts as a Processor
AI-Assisted FeaturesRunning AI-enabled workflows, generating suggestions, and Processing AI inputs where enabledController or Processor depending on the workflowPerformance of contract, Legitimate Interests, or documented client instructions
Marketing and Newsletter CommunicationsSending promotional messages, updates, and campaigns where the user has provided affirmative Consent through the applicable sign-up or preference mechanismControllerConsent
Approved Customer References and PublicityReferring to a customer, company, logo, or approved project reference in case studies, proposals, website materials, or business-development materials where Orionex has prior written approval or contractual permissionControllerLegitimate interests, Consent, or contractual authorization where applicable
Client Project Data ProcessingCarrying out implementation, maintenance, or delivery work for a client projectProcessor unless contract says otherwiseDocumented client instructions and the applicable service contract

(c) Consent Collection

Where Orionex relies on Consent as a legal basis, Consent is obtained through affirmative action such as checking a Consent box during account registration, sign-up, or checkout. Consent is recorded and can be verified. You may withdraw that Consent at any time without affecting prior lawful Processing. To withdraw Consent, contact Orionex using the channels described in Section 8.

(d) Legitimate Interest Assessments

Where Orionex relies on Legitimate Interests as a legal basis, Orionex has assessed that its interests do not override your fundamental rights and freedoms. You may request information about a specific Legitimate Interest assessment by contacting Orionex using the channels described in Section 8.

Disclosure of Information, Shared Orionex Services, and Service Providers

We do not sell your Personal Data.

We may disclose Personal Data to:

  • Orionex personnel who need access for their job responsibilities;
  • shared Orionex services used across multiple products or services;
  • third-party service providers that help us operate the Services;
  • prospects, customers, website visitors, or business counterparties where you have approved customer-reference or publicity use;
  • professional advisers and auditors where needed;
  • payment and banking channels used to process or verify transactions;
  • competent authorities, regulators, courts, or law-enforcement bodies where legally required; and
  • counterparties involved in a merger, acquisition, financing, or asset transfer, in which case Orionex will notify affected Data Subjects where required by applicable law.

(a) Shared Orionex Services

Certain Orionex services are shared across products and business lines, including:

  • Orionex Identity, which supports account, authentication, session, and security workflows; and
  • Orionex Pay, which supports invoicing, payment flows, and billing orchestration.

(b) Current Service Providers and Subprocessors

ProviderTypical PurposeTypical Services CoveredTypical Location
Google Cloud Platform (GCP)Cloud infrastructure, hosting, storage, buckets, and related servicesOrionex general services, Luncurin, and infrastructure workloadsJakarta, Singapore, or other configured regions
AivenManaged SQL database services where usedOrionex services where configuredAsia & Oceania
MongoDB AtlasManaged NoSQL database services where usedOrionex services where configuredJakarta, Singapore, or other configured regions
VercelFrontend and static-site hostingOrionex and Luncurin frontend workloadsSingapore / Global
GreenCloudVPSVPS and supplementary infrastructureOrionex and Luncurin workloadsSingapore / Global
WhplusVPS and supplementary infrastructure where usedOrionex workloads where configuredJakarta
SMTP2GOTransactional email delivery and mail servicesOrionex Identity, lead notifications, and product mail flowsEU, New Zealand, and other SMTP2GO-operated regions
DewawebDomain registration, renewal, and related domain-management services where usedOrionex and Luncurin domain services where configuredJakarta
IDWebhostDomain registration, renewal, and related domain-management services where usedOrionex and Luncurin domain services where configuredIndonesia / as operated by provider
Domain Name API (Atakonline Domain Hosting Internet and Information Technologies LTD)Domain registration, transfer, and domain-service API workflows where configuredLuncurin and Orionex domain services where configuredGlobal / as operated by provider
Openprovider (Hosting Concepts B.V.)Domain registration, transfer, registry access, and related domain-service workflows where configuredLuncurin and Orionex domain services where configuredGlobal / as operated by provider
CloudflareCDN, DNS, WAF, and network-security servicesOrionex and LuncurinGlobal / USA
XenditBackend payment Processing behind Orionex PayOrionex payment flows and products using Orionex PayIndonesia and/or other locations used by Xendit
Firebase Authentication (Google)Upstream authentication and identity-provider servicesOrionex IdentityGlobal / USA
ipapi.coIP-based geolocation and device-trust enrichment where enabledOrionex IdentityGlobal
OpenAIAI/LLM Processing where enabled (API-only, opted out of model training)Orionex services where configuredUSA / Global
Gemini (Google)AI/LLM Processing where enabled (API-only, opted out of model training)Orionex and Luncurin workflows where configuredUSA / Global
SentryError monitoring, performance tracking, and application diagnosticsOrionex services (development, staging, and early access environments)USA / Global
PikaPods / UmamiHosted analytics infrastructure where usedLuncurin analyticsGlobal / as configured
Let's EncryptCertificate issuance and renewal where usedOrionex and Luncurin infrastructureGlobal
Google Analytics (Google LLC)Website analytics and measurement where enabled and, where applicable, consented to through website cookie preferencesOrionex websitesUSA / Global

(c) Changes to Service Providers

Orionex will update the service provider list in this Section when providers are added, removed, or materially change. Where a change involves a new Sub-processor for an existing Service, Orionex may provide notice through the Privacy Policy page, service communications, or another reasonable channel.

International Transfers

Orionex's primary infrastructure is currently centered in Indonesia and Singapore, but some services and providers may process Personal Data outside Indonesia or through global networks.

Depending on the Service used, relevant data may be processed by providers such as Firebase Authentication, SMTP2GO, Cloudflare, Vercel, OpenAI, Gemini, Sentry, PikaPods/Umami, Domain Name API, Openprovider, and ipapi.co.

Transfer Safeguards

Where Orionex transfers Personal Data across borders, Orionex relies on the data-protection commitments and standard terms of the receiving provider, including their published data Processing terms, privacy policies, and security commitments. Where a provider's standard terms include standard contractual clauses or equivalent data-protection commitments, those protections apply to the relevant transfer.

For transfers to providers located in jurisdictions that do not have data-protection laws recognized as equivalent to UU No. 27 Tahun 2022 (including certain USA-based providers), Orionex ensures that the provider's contractual commitments, security measures, and Processing restrictions provide an adequate level of protection for the transferred Personal Data, as assessed by Orionex.

Where Orionex acts as a Processor for Client Project Data, Orionex will support the transfer structure required by the applicable client contract or law.

Orionex will reassess its transfer safeguards if and when the implementing regulations for UU PDP prescribe specific transfer mechanisms or adequacy determinations.

Retention and Deletion

We retain Personal Data only for as long as reasonably necessary for the purposes described in this Policy, subject to legal, tax, audit, fraud-prevention, dispute, and security requirements.

Data SetTypical Retention Approach
Lead Capture DataConversational or lead-capture records may be retained for up to 30 days in the current lead flow unless moved into another business record, needed for follow-up, or required longer by law or dispute handling.
Account and Identity DataRetained while the relevant account is active. Upon account closure, account data may be deleted, anonymized, or retained in restricted form to the extent required for legal, tax, audit, fraud-prevention, security, or dispute-resolution obligations.
Auth Codes and Verification RecordsShort-lived technical records that may expire within minutes or according to service configuration.
Billing and Tax RecordsRetained for the period required by applicable tax, accounting, and audit obligations, including up to 10 years where required.
Luncurin Service DataLuncurin offboarding may include a 30-day grace period after suspension or non-renewal, with hard deletion at Day 31 if the service is not renewed, subject to backups, legal holds, fraud review, and unresolved billing issues.
Cookies and Session IdentifiersRetained according to technical purpose and configuration. Current examples may include session-based storage, 1-day, 30-day, 1-year, and up to 2-year durations for Google Analytics cookies, as further described in the Cookie Policy.

Security Measures and Incident Response

(a) Security Measures

We use reasonable administrative, technical, and organizational measures to protect Personal Data, including encryption in transit and at rest, access controls, audit logging, and backup processes. Orionex implements data protection by design and by default. If you use an Orionex service in a self-managed environment, you remain responsible for your own devices and infrastructure.

(b) Data Protection Impact Assessments

Orionex conducts Data Protection Impact Assessments (DPIAs) for Processing activities that are likely to result in high risk to Data Subjects, in accordance with applicable law. DPIAs are conducted on request and when introducing new Processing activities involving sensitive data categories or new technologies such as AI.

(c) Incident Response

If Orionex becomes aware of a Personal Data incident that requires notice under applicable law, Orionex will:

  • notify affected Data Subjects within 3 x 24 hours as required by UU PDP Article 46;
  • notify the relevant supervisory authority within the required timeframe;
  • where Orionex acts as a Processor, notify the relevant Controller without undue delay;
  • coordinate response through its Data Protection Officer.

Your Rights and How to Exercise Them

Depending on your location and applicable law, you may have rights such as access, correction, deletion, portability, withdrawal of Consent, and objection to Processing.

(a) How to Contact Orionex

For general Orionex privacy requests, contact:

Orionex has appointed a Data Protection Officer in accordance with UU PDP Article 53(1), reachable at legal@orionex.id. For Luncurin-specific requests, you may also contact support@luncurin.com.

(b) Verification and Handling

To protect Personal Data, Orionex may ask for information to verify your identity. If Orionex is acting as a Processor, Orionex may direct you to the relevant client or Controller.

(c) Response Timeline

Orionex will acknowledge privacy requests within 3 x 24 hours and provide a substantive response within the timeframe required by applicable law (normally not exceeding 30 days).

Cookies, Local Storage, and Similar Technologies

Orionex uses cookies and similar technologies for session continuity, fraud prevention, service preferences, analytics, and temporary workflow state.

Examples include:

  • luncurin_session_id (up to 30 days);
  • orionex_session (about 1 day);
  • ornx-theme or similar theme preference storage (up to 1 year or until changed/deleted); and
  • Google Analytics cookies such as _ga and _ga_<container-id> where analytics is enabled.

You can manage cookies through browser settings and, where provided, Orionex website cookie preferences. Orionex currently uses Google Analytics for website analytics and may also use privacy-focused analytics such as Umami.

Minors and Eligibility

Our current Services are intended for users who meet the minimum age and legal-capacity requirements. For users in Indonesia, the applicable Indonesian legal minimum rules apply. For users in the EEA/UK, child-Consent rules apply. Orionex does not knowingly collect data from individuals not permitted to use the Services.

Supplemental Regional Notices

If you are a resident of a jurisdiction that gives you additional privacy rights, Orionex will honor those rights. Orionex does not sell Personal Data and does not use Personal Data for advertising personalization or cross-context behavioral advertising.

Changes to This Policy

Orionex may update this Privacy Policy from time to time. If Orionex makes a material change, notice will be provided through the website, email, or another reasonable channel before the change takes effect.

Governing Law and Dispute Resolution

This Privacy Policy is governed by and construed in accordance with the laws of the Republic of Indonesia, including but not limited to UU No. 27 Tahun 2022 on Personal Data Protection and its implementing regulations. Any dispute arising in connection with this Privacy Policy will first be resolved amicably through good-faith negotiation. If no resolution is reached within 30 (thirty) calendar days, the parties agree to submit the dispute to the exclusive jurisdiction of the South Jakarta District Court (Pengadilan Negeri Jakarta Selatan).

Contact Us

PT Orionex Solusi Digital

Data Protection Officer / General Privacy / Legal Contact: legal@orionex.id

Luncurin Product Privacy Contact: support@luncurin.com

Post: Attention: Data Protection Officer / Legal Department Gedung Wirausaha, Jalan H. R. Rasuna Said Kav. C No. 5, Setiabudi, Jakarta Selatan, 12920, Indonesia.