Orionex General Privacy Policy
Version
1.6
Status
Effective Date
2026-04-01
Last Revision
2026-03-28
Introduction and Scope
PT Orionex Solusi Digital ("Orionex Solutions," "Orionex," "we," "us," or "our"), located at Gedung Wirausaha, Jalan H. R. Rasuna Said Kav. C No. 5, Setiabudi, Jakarta Selatan, 12920, Indonesia, is committed to handling Personal Data transparently and in accordance with applicable law.
This Privacy Policy explains how Orionex collects, uses, stores, discloses, transfers, and deletes Personal Data in connection with Orionex's current shared corporate services, including:
- Orionex websites and lead-capture channels;
- Orionex Identity;
- Orionex Pay;
- IT Consulting services;
- Custom Software Development services; and
- Luncurin.
Not every category of Personal Data described in this Policy applies to every Service.
Use of the Services is also governed by our Terms of Service and any applicable product-specific addendum or product-specific privacy notice. For Luncurin, the Luncurin Privacy Policy and the Luncurin Product Terms and Data Addendum supplement this Policy. If there is a direct conflict for Luncurin-specific Processing, the more product-specific Luncurin privacy document controls for that product, provided it does not reduce the data-protection standards established in this Policy. For browser cookies, local storage, analytics tags, and similar website technologies, the Cookie Policy supplements the Privacy Policy.
Categories of Personal Data We Process
We may process the following categories of Personal Data, depending on the Service used and the role Orionex performs. Orionex collects only the Personal Data that is adequate, relevant, and limited to what is necessary for the purposes described in this Policy.
Under UU No. 27 Tahun 2022 (Pelindungan Data Pribadi), Personal Data is classified as either general Personal Data (data pribadi yang bersifat umum) or specific Personal Data (data pribadi yang bersifat spesifik). Of the categories below, Billing and Transaction Data — including NPWP and financial transaction records — may constitute specific Personal Data (financial data) under UU PDP and is subject to heightened protection requirements accordingly.
(a) Lead and Business Contact Data
Examples include:
- full name;
- business email address;
- phone number;
- company name;
- job title;
- inquiry type;
- message content;
- company size;
- project timeline;
- budget range;
- technical context;
- Consent and marketing preference fields; and
- related submission metadata.
(b) Account and Identity Data
Examples include:
- name;
- email address;
- phone number;
- company or organization name;
- Orionex user ID or similar account identifier;
- profile picture;
- role or permission assignments;
- authentication and verification status;
- identity-provider metadata received from shared identity services.
(c) Billing and Transaction Data
Examples include:
- customer name;
- email address;
- phone number;
- company name;
- billing address;
- NPWP or other tax identifier where required;
- invoice items;
- order, invoice, and payment metadata;
- amounts and payment status; and
- reference and callback fields associated with payment flows.
(d) Service and Project Data
Examples include:
- project instructions;
- uploaded files and assets;
- website drafts and configuration data;
- support messages;
- implementation materials;
- business content submitted for a project or product workflow; and
- other content processed through Orionex services.
(e) Technical, Security, and Audit Data
Examples include:
- IP address;
- browser, operating system, and device information;
- user agent;
- session identifiers;
- login verification records;
- token, auth-code, or refresh metadata;
- request and audit logs;
- fraud and abuse indicators; and
- approximate (non-precise) location derived from IP address.
(f) Cookies, Local Storage, and Similar Technologies
We may process data through cookies, local storage, session storage, analytics identifiers, and similar technologies used for authentication, fraud prevention, preferences, session continuity, and analytics.
(g) AI Interaction Data
Where AI-assisted features are enabled, we may process:
- prompts;
- outputs;
- extracted business or configuration data;
- trace identifiers; and
- related usage or audit information.
Orionex uses API-based integrations with AI providers (currently OpenAI and Google Gemini) and has configured those integrations to opt out of provider-side model training for input and output data. Orionex does not use AI interaction data to train or fine-tune its own or third-party AI models unless you have separately and expressly authorized that use.
(h) Data Received from Third Parties and Shared Orionex Services
We may receive relevant data from:
- shared Orionex services such as Orionex Identity and Orionex Pay;
- upstream identity providers such as Firebase Authentication;
- payment callbacks and reconciliation flows;
- email delivery services;
- analytics or geolocation services; and
- other providers listed in Section 4.
(i) Approved Publicity and Reference Data
Where Orionex has prior written approval or contractual permission to refer to a customer as a reference, relevant data may include:
- customer or company name;
- logo or brand assets;
- approved project description, case-study summary, or reference statement; and
- approval records or contractual permissions relating to that customer-reference use.
If Orionex processes Client Project Data for IT Consulting or Custom Software Development, Orionex processes that data as a Processor unless the applicable contract states otherwise.
Roles, Purposes, and Legal Bases
(a) Orionex Roles
Orionex generally acts as:
- Controller for Orionex's own sales, contact, account, authentication, billing, support, administrative, security, fraud-prevention, and compliance data; and
- Processor for client project or service data handled in IT Consulting and Custom Software Development, unless the applicable contract states otherwise.
Product-specific addendums may clarify how this allocation works for a specific product.
(b) Purposes and Legal Bases
| Purpose | Typical Description | Orionex Role | Legal Basis / Basis for Processing |
|---|---|---|---|
| Lead Capture and Business Discussions | Handling inquiries, proposals, demos, and business communication | Controller | Pre-contract steps, Legitimate Interests, and Consent where required for marketing follow-up |
| Account, Identity, and Access Management | Creating and managing accounts, authentication, session continuity, and verification | Controller | Performance of contract and Legitimate Interests for service security |
| Service Delivery | Providing Orionex services, including Luncurin, consulting, and custom development | Controller or Processor depending on service | Performance of contract and, where Orionex acts as Processor, documented client instructions |
| Billing and Payment Administration | Issuing invoices, Processing payments, preventing payment abuse, and meeting accounting/tax obligations | Controller | Performance of contract, legal obligation, and Legitimate Interests for fraud prevention |
| Support and Service Communications | Responding to support inquiries, service updates, and operational notices | Controller | Performance of contract and Legitimate Interests |
| Security, Audit, and Fraud Prevention | Detecting abuse, verifying devices, protecting systems, and maintaining audit trails | Controller | Legitimate interests and legal obligation where applicable |
| Service Improvement and Analytics | Using aggregated, de-identified, or anonymized information (such that it no longer constitutes Personal Data under applicable law) to measure, maintain, improve, and develop Orionex services, workflows, analytics, and security controls | Controller or Processor depending on the source data and applicable contract | Legitimate interests, performance of contract, or documented client instructions where Orionex acts as a Processor |
| AI-Assisted Features | Running AI-enabled workflows, generating suggestions, and Processing AI inputs where enabled | Controller or Processor depending on the workflow | Performance of contract, Legitimate Interests, or documented client instructions |
| Marketing and Newsletter Communications | Sending promotional messages, updates, and campaigns where the user has provided affirmative Consent through the applicable sign-up or preference mechanism | Controller | Consent |
| Approved Customer References and Publicity | Referring to a customer, company, logo, or approved project reference in case studies, proposals, website materials, or business-development materials where Orionex has prior written approval or contractual permission | Controller | Legitimate interests, Consent, or contractual authorization where applicable |
| Client Project Data Processing | Carrying out implementation, maintenance, or delivery work for a client project | Processor unless contract says otherwise | Documented client instructions and the applicable service contract |
(c) Consent Collection
Where Orionex relies on Consent as a legal basis, Consent is obtained through affirmative action such as checking a Consent box during account registration, sign-up, or checkout. Consent is recorded and can be verified. You may withdraw that Consent at any time without affecting prior lawful Processing. To withdraw Consent, contact Orionex using the channels described in Section 8.
(d) Legitimate Interest Assessments
Where Orionex relies on Legitimate Interests as a legal basis, Orionex has assessed that its interests do not override your fundamental rights and freedoms. You may request information about a specific Legitimate Interest assessment by contacting Orionex using the channels described in Section 8.
Disclosure of Information, Shared Orionex Services, and Service Providers
We do not sell your Personal Data.
We may disclose Personal Data to:
- Orionex personnel who need access for their job responsibilities;
- shared Orionex services used across multiple products or services;
- third-party service providers that help us operate the Services;
- prospects, customers, website visitors, or business counterparties where you have approved customer-reference or publicity use;
- professional advisers and auditors where needed;
- payment and banking channels used to process or verify transactions;
- competent authorities, regulators, courts, or law-enforcement bodies where legally required; and
- counterparties involved in a merger, acquisition, financing, or asset transfer, in which case Orionex will notify affected Data Subjects where required by applicable law.
(a) Shared Orionex Services
Certain Orionex services are shared across products and business lines, including:
- Orionex Identity, which supports account, authentication, session, and security workflows; and
- Orionex Pay, which supports invoicing, payment flows, and billing orchestration.
(b) Current Service Providers and Subprocessors
| Provider | Typical Purpose | Typical Services Covered | Typical Location |
|---|---|---|---|
| Google Cloud Platform (GCP) | Cloud infrastructure, hosting, storage, buckets, and related services | Orionex general services, Luncurin, and infrastructure workloads | Jakarta, Singapore, or other configured regions |
| Aiven | Managed SQL database services where used | Orionex services where configured | Asia & Oceania |
| MongoDB Atlas | Managed NoSQL database services where used | Orionex services where configured | Jakarta, Singapore, or other configured regions |
| Vercel | Frontend and static-site hosting | Orionex and Luncurin frontend workloads | Singapore / Global |
| GreenCloudVPS | VPS and supplementary infrastructure | Orionex and Luncurin workloads | Singapore / Global |
| Whplus | VPS and supplementary infrastructure where used | Orionex workloads where configured | Jakarta |
| SMTP2GO | Transactional email delivery and mail services | Orionex Identity, lead notifications, and product mail flows | EU, New Zealand, and other SMTP2GO-operated regions |
| Dewaweb | Domain registration, renewal, and related domain-management services where used | Orionex and Luncurin domain services where configured | Jakarta |
| IDWebhost | Domain registration, renewal, and related domain-management services where used | Orionex and Luncurin domain services where configured | Indonesia / as operated by provider |
| Domain Name API (Atakonline Domain Hosting Internet and Information Technologies LTD) | Domain registration, transfer, and domain-service API workflows where configured | Luncurin and Orionex domain services where configured | Global / as operated by provider |
| Openprovider (Hosting Concepts B.V.) | Domain registration, transfer, registry access, and related domain-service workflows where configured | Luncurin and Orionex domain services where configured | Global / as operated by provider |
| Cloudflare | CDN, DNS, WAF, and network-security services | Orionex and Luncurin | Global / USA |
| Xendit | Backend payment Processing behind Orionex Pay | Orionex payment flows and products using Orionex Pay | Indonesia and/or other locations used by Xendit |
| Firebase Authentication (Google) | Upstream authentication and identity-provider services | Orionex Identity | Global / USA |
| ipapi.co | IP-based geolocation and device-trust enrichment where enabled | Orionex Identity | Global |
| OpenAI | AI/LLM Processing where enabled (API-only, opted out of model training) | Orionex services where configured | USA / Global |
| Gemini (Google) | AI/LLM Processing where enabled (API-only, opted out of model training) | Orionex and Luncurin workflows where configured | USA / Global |
| Sentry | Error monitoring, performance tracking, and application diagnostics | Orionex services (development, staging, and early access environments) | USA / Global |
| PikaPods / Umami | Hosted analytics infrastructure where used | Luncurin analytics | Global / as configured |
| Let's Encrypt | Certificate issuance and renewal where used | Orionex and Luncurin infrastructure | Global |
| Google Analytics (Google LLC) | Website analytics and measurement where enabled and, where applicable, consented to through website cookie preferences | Orionex websites | USA / Global |
(c) Changes to Service Providers
Orionex will update the service provider list in this Section when providers are added, removed, or materially change. Where a change involves a new Sub-processor for an existing Service, Orionex may provide notice through the Privacy Policy page, service communications, or another reasonable channel.
International Transfers
Orionex's primary infrastructure is currently centered in Indonesia and Singapore, but some services and providers may process Personal Data outside Indonesia or through global networks.
Depending on the Service used, relevant data may be processed by providers such as Firebase Authentication, SMTP2GO, Cloudflare, Vercel, OpenAI, Gemini, Sentry, PikaPods/Umami, Domain Name API, Openprovider, and ipapi.co.
Transfer Safeguards
Where Orionex transfers Personal Data across borders, Orionex relies on the data-protection commitments and standard terms of the receiving provider, including their published data Processing terms, privacy policies, and security commitments. Where a provider's standard terms include standard contractual clauses or equivalent data-protection commitments, those protections apply to the relevant transfer.
For transfers to providers located in jurisdictions that do not have data-protection laws recognized as equivalent to UU No. 27 Tahun 2022 (including certain USA-based providers), Orionex ensures that the provider's contractual commitments, security measures, and Processing restrictions provide an adequate level of protection for the transferred Personal Data, as assessed by Orionex.
Where Orionex acts as a Processor for Client Project Data, Orionex will support the transfer structure required by the applicable client contract or law.
Orionex will reassess its transfer safeguards if and when the implementing regulations for UU PDP prescribe specific transfer mechanisms or adequacy determinations.
Retention and Deletion
We retain Personal Data only for as long as reasonably necessary for the purposes described in this Policy, subject to legal, tax, audit, fraud-prevention, dispute, and security requirements.
| Data Set | Typical Retention Approach |
|---|---|
| Lead Capture Data | Conversational or lead-capture records may be retained for up to 30 days in the current lead flow unless moved into another business record, needed for follow-up, or required longer by law or dispute handling. |
| Account and Identity Data | Retained while the relevant account is active. Upon account closure, account data may be deleted, anonymized, or retained in restricted form to the extent required for legal, tax, audit, fraud-prevention, security, or dispute-resolution obligations. |
| Auth Codes and Verification Records | Short-lived technical records that may expire within minutes or according to service configuration. |
| Billing and Tax Records | Retained for the period required by applicable tax, accounting, and audit obligations, including up to 10 years where required. |
| Luncurin Service Data | Luncurin offboarding may include a 30-day grace period after suspension or non-renewal, with hard deletion at Day 31 if the service is not renewed, subject to backups, legal holds, fraud review, and unresolved billing issues. |
| Cookies and Session Identifiers | Retained according to technical purpose and configuration. Current examples may include session-based storage, 1-day, 30-day, 1-year, and up to 2-year durations for Google Analytics cookies, as further described in the Cookie Policy. |
Security Measures and Incident Response
(a) Security Measures
We use reasonable administrative, technical, and organizational measures to protect Personal Data, including encryption in transit and at rest, access controls, audit logging, and backup processes. Orionex implements data protection by design and by default. If you use an Orionex service in a self-managed environment, you remain responsible for your own devices and infrastructure.
(b) Data Protection Impact Assessments
Orionex conducts Data Protection Impact Assessments (DPIAs) for Processing activities that are likely to result in high risk to Data Subjects, in accordance with applicable law. DPIAs are conducted on request and when introducing new Processing activities involving sensitive data categories or new technologies such as AI.
(c) Incident Response
If Orionex becomes aware of a Personal Data incident that requires notice under applicable law, Orionex will:
- notify affected Data Subjects within 3 x 24 hours as required by UU PDP Article 46;
- notify the relevant supervisory authority within the required timeframe;
- where Orionex acts as a Processor, notify the relevant Controller without undue delay;
- coordinate response through its Data Protection Officer.
Your Rights and How to Exercise Them
Depending on your location and applicable law, you may have rights such as access, correction, deletion, portability, withdrawal of Consent, and objection to Processing.
(a) How to Contact Orionex
For general Orionex privacy requests, contact:
- Email: legal@orionex.id
- Subject line:
[PRIVACY REQUEST]
Orionex has appointed a Data Protection Officer in accordance with UU PDP Article 53(1), reachable at legal@orionex.id. For Luncurin-specific requests, you may also contact support@luncurin.com.
(b) Verification and Handling
To protect Personal Data, Orionex may ask for information to verify your identity. If Orionex is acting as a Processor, Orionex may direct you to the relevant client or Controller.
(c) Response Timeline
Orionex will acknowledge privacy requests within 3 x 24 hours and provide a substantive response within the timeframe required by applicable law (normally not exceeding 30 days).
Minors and Eligibility
Our current Services are intended for users who meet the minimum age and legal-capacity requirements. For users in Indonesia, the applicable Indonesian legal minimum rules apply. For users in the EEA/UK, child-Consent rules apply. Orionex does not knowingly collect data from individuals not permitted to use the Services.
Supplemental Regional Notices
If you are a resident of a jurisdiction that gives you additional privacy rights, Orionex will honor those rights. Orionex does not sell Personal Data and does not use Personal Data for advertising personalization or cross-context behavioral advertising.
Changes to This Policy
Orionex may update this Privacy Policy from time to time. If Orionex makes a material change, notice will be provided through the website, email, or another reasonable channel before the change takes effect.
Governing Law and Dispute Resolution
This Privacy Policy is governed by and construed in accordance with the laws of the Republic of Indonesia, including but not limited to UU No. 27 Tahun 2022 on Personal Data Protection and its implementing regulations. Any dispute arising in connection with this Privacy Policy will first be resolved amicably through good-faith negotiation. If no resolution is reached within 30 (thirty) calendar days, the parties agree to submit the dispute to the exclusive jurisdiction of the South Jakarta District Court (Pengadilan Negeri Jakarta Selatan).
Contact Us
PT Orionex Solusi Digital
Data Protection Officer / General Privacy / Legal Contact: legal@orionex.id
Luncurin Product Privacy Contact: support@luncurin.com
Post: Attention: Data Protection Officer / Legal Department Gedung Wirausaha, Jalan H. R. Rasuna Said Kav. C No. 5, Setiabudi, Jakarta Selatan, 12920, Indonesia.