Privacy Policy

PT. Gavriel Kairos Indonesia · Effective 12 August 2026

Draft, not legal advice. This document is a serviceable first draft prepared by Gavriel Studio to meet general privacy-policy expectations and align with Indonesia's UU No. 27/2022 on Personal Data Protection (UU PDP). It is not a substitute for review by qualified legal counsel. Before relying on this policy in a dispute, audit, or regulator engagement, have a lawyer review it against your actual operations and the contracts you sign with customers and subprocessors.

Contents

  1. Who we are
  2. Scope of this policy
  3. What personal data we collect
  4. How we use personal data
  5. Legal bases for processing
  6. Agent-specific handling (Personal Agent, Multi-Agent Workspace)
  7. Multi-SaaS Bundle handling
  8. AI Audit & Security handling
  9. Workshops handling
  10. Subprocessors and third parties
  11. Data retention
  12. International data transfers
  13. Security measures
  14. Your rights as a data subject
  15. Children's data
  16. Changes to this policy
  17. Contact us

1. Who we are

For the purposes of this Privacy Policy, the data controller is:

PT. Gavriel Kairos Indonesia
Menara Aria Office Tower Lt 7 Unit 11
Komplek Harbour Bay Downtown, Jl. Duyung
Kel. Sungai Jodoh, Kec. Batu Ampar
Kota Batam, Indonesia
Established 2026 · NIB: 0109260049967

Trading as Gavriel Studio. Operated by a single founder (Erwin Gavriel) supported by a fleet of AI agents and a small number of interns. Fully-remote operating model with a registered virtual office in Batam.

2. Scope of this policy

This policy applies to personal data we process when you:

  • Visit or interact with this website (gavrielstudio.com);
  • Contact us via WhatsApp, Telegram, email, or any other channel;
  • Subscribe to or use our Personal Agent, Multi-Agent Workspace, or Multi-SaaS Bundle services;
  • Engage us for AI Audit & Security or Workshops services;
  • Apply to work with us or are listed as a reference contact.

3. What personal data we collect

The categories of personal data we collect depend on the service, but typically include:

  • Identity & contact data: name, email, phone number (often via WhatsApp), Telegram handle, business name, role, country.
  • Communications data: the content of messages you send us and to our agents, including WhatsApp / Telegram / Slack / Discord / email content.
  • Business data: information about your company, your team, your workflows, and the data you choose to share with the agent (e.g. calendar entries, customer orders, internal documents).
  • Technical data: IP address, browser type, device type, pages visited, referral source, basic analytics.
  • Payment data: handled by our payment processor; we do not store full card numbers on our systems.
  • Audit & workshop data: for AI Audit engagements, data you provide about your AI systems, controls, evidence, and personnel. For workshops, attendee names, employers, and any assessments.

We do not knowingly collect special-category data (health, religion, biometrics, etc.) unless you explicitly provide it as part of a service engagement.

4. How we use personal data

We use personal data to:

  • Provide, operate, maintain, and improve the services you subscribe to or engage us for;
  • Configure and run the agents you have authorised us to deploy;
  • Communicate with you about the services, including onboarding, support, and updates;
  • Process payments, issue invoices, and meet our tax and accounting obligations;
  • Maintain the security and integrity of our systems;
  • Comply with applicable law, regulation, audit, or court order;
  • With your consent, send you marketing or service announcements (you can opt out at any time).

5. Legal bases for processing

Under Indonesia's UU No. 27/2022 (UU PDP), we rely on one or more of the following legal bases:

  • Explicit consent — for processing that requires it under UU PDP Article 20, including processing of sensitive personal data, processing for marketing, and processing of data of children;
  • Performance of a contract — where processing is necessary to deliver the service you have engaged us to provide;
  • Compliance with legal obligations — where processing is required by Indonesian tax, corporate, or regulatory law;
  • Legitimate interests — for purposes such as security, fraud prevention, and service improvement, where our interests are not overridden by your rights.

6. Agent-specific handling (Personal Agent & Multi-Agent Workspace)

Our Personal Agent and Multi-Agent Workspace services are built on third-party AI model providers and run on infrastructure we operate. Because these agents handle the messages, calendar entries, and business data you choose to share with them, several specific commitments apply:

  • Data minimisation. We configure each agent to access only the data sources you have explicitly authorised (e.g. a specific WhatsApp number, a specific calendar, a specific document set).
  • Prompt and message logging. We log agent interactions for the purposes of debugging, quality assurance, audit, and abuse prevention. Logs are retained for a defined period (see section 10) and access is restricted to authorised personnel.
  • Model providers as subprocessors. Prompts and context you send to the agent are sent to the underlying AI model provider (currently OpenAI, Anthropic, or other providers as configured) for inference. See section 9 for the list.
  • No training on your data. We configure our use of model providers under terms that prohibit training on customer data. We do not use your data to train our own models.
  • Workspace governance. For Multi-Agent Workspace deployments, every agent action is logged. Role-based access controls, escalation paths, and kill switches are configured per engagement.

7. Multi-SaaS Bundle handling

The Multi-SaaS Bundle gives you access to a set of internal SaaS tools (order and inventory, customer comms, bookings, reporting) on a single subscription. Data you enter into these tools is stored in our infrastructure and processed to provide the service. The same data minimisation, retention, and security principles apply as for the agent services.

Customer data collected through the Bundle (e.g. end-customers placing orders or bookings through your tenant) is processed on your behalf. You are the data controller for that end-customer data; we act as data processor. A data processing addendum (DPA) is available on request.

8. AI Audit & Security handling

AI Audit engagements involve access to your AI systems, controls, evidence, and personnel. We treat all audit-related data as confidential by default and apply the following:

  • Confidentiality. All audit findings, evidence, and reports are confidential to you. We do not share them with third parties except where required by law or with your explicit written consent.
  • Scoped access. Audit work is performed on the data and systems you have explicitly authorised. We do not access systems or data outside the agreed scope.
  • Retention. Audit workpapers and findings are retained for a defined period (see section 10) and then securely destroyed or returned to you, per the engagement terms.
  • ISO 42001 alignment. We are working toward ISO 42001 certification ourselves. Our internal audit and security practices are designed to align with ISO 42001 controls, and we apply the same standards we help our clients achieve.

9. Workshops handling

For workshop and seminar engagements (schools, universities, corporate), we collect attendee names, employer or institution, and any pre-work or assessments you submit. Workshop materials and recordings (where produced) are retained for a defined period and then deleted. If you do not want your name or employer to appear in workshop materials or certificates, tell us before the engagement starts.

10. Subprocessors and third parties

We use the following categories of subprocessors to deliver our services. A current, dated list is also published at gavrielstudio.com/legal/subprocessors and updated at least 30 days before any change.

  • Cloud infrastructure: providers we use to host services and data (e.g. Cloudflare, Amazon Web Services, or comparable providers).
  • AI model providers: providers we use for inference (e.g. OpenAI, Anthropic, Google, Mistral, or comparable providers).
  • Messaging platforms: WhatsApp (Meta), Telegram, Slack, Discord, Microsoft Teams — used as the channels our agents operate on.
  • Payment processors: to process subscription and invoice payments.
  • Analytics: privacy-respecting website analytics. We do not use third-party advertising trackers.
  • Email and document services: to communicate and to draft documents on your behalf.

Each subprocessor is engaged under a data processing agreement that includes obligations no less protective than those in this policy.

11. Data retention

We retain personal data only as long as necessary for the purposes described in this policy, or as required by law. Specific retention windows:

  • Website and contact data: 24 months from last interaction, unless a longer period is required by law.
  • Agent interaction logs: 90 days for active subscriptions, extendable to 12 months for paid audit / enterprise tiers. You can request earlier deletion.
  • Bundle SaaS data: for the duration of the subscription plus 30 days for offboarding, after which data is permanently deleted within a further 30 days.
  • Audit workpapers and findings: per the engagement terms, typically 7 years for certification-aligned engagements.
  • Financial records (invoices, payments): 10 years, per Indonesian tax law (UU KUP).
  • WhatsApp message content: message bodies and media exchanged with our agents are retained in audit logs for 90 days after the last interaction, then automatically deleted. Earlier deletion can be requested at any time via the contact in section 17. We respond to deletion requests within the timeframes required by UU PDP. WhatsApp message metadata (timestamps, sender identifiers, delivery status) may be retained for up to 12 months for security, fraud-prevention, and abuse-detection purposes, then deleted.

12. International data transfers

Our infrastructure and many of our subprocessors are located outside Indonesia, including in the United States, the European Union, and Singapore. When personal data is transferred outside Indonesia, we rely on the transfer mechanisms recognised under UU PDP Article 56, including adequate protection levels, contractual safeguards, or your explicit consent. We maintain a current list of destination countries and safeguards in our subprocessor list.

13. Security measures

We apply technical and organisational measures designed to protect personal data against unauthorised or unlawful processing, accidental loss, destruction, or damage. These include:

  • Encryption in transit (TLS 1.2+) and at rest;
  • Access controls based on role and least-privilege;
  • Logging of access to production data;
  • Regular review of subprocessors and their security posture;
  • Incident response procedures, with notification to affected data subjects and the relevant authority within the timeframes required by UU PDP (no later than 3×24 hours for breaches involving personal data).

Our security practices are designed to align with ISO 42001 controls and are reviewed periodically as part of our certification roadmap.

14. Your rights as a data subject

Under UU PDP, you have the right to:

  • Access the personal data we hold about you;
  • Correct inaccurate or incomplete data;
  • Delete your data, subject to legal retention obligations;
  • Restrict or object to certain processing;
  • Withdraw consent at any time, where processing is based on consent;
  • Data portability — receive your data in a structured, commonly-used format;
  • Lodge a complaint with the relevant Indonesian authority (the Ministry of Communication and Informatics, currently).

To exercise any of these rights, contact us at the address in section 17. We will respond within the timeframes required by UU PDP (no later than 30 days, extendable for complex requests).

15. Children's data

Our services are not directed to children under 17. We do not knowingly collect personal data from children. If you believe a child has provided us with personal data, contact us so we can delete it. Workshop programs for school-age students are operated under a separate consent regime with the school or guardian.

16. Changes to this policy

We may update this policy from time to time. The "Effective" date at the top of this page shows when the current version came into force. Material changes will be communicated by email to active subscribers and by a notice on this page at least 14 days before they take effect. The previous version of this policy is available on request.

17. Contact us

For any questions about this policy, to exercise your rights, or to lodge a complaint, contact us:

PT. Gavriel Kairos Indonesia (trading as Gavriel Studio)
Menara Aria Office Tower Lt 7 Unit 11
Komplek Harbour Bay Downtown, Jl. Duyung
Kel. Sungai Jodoh, Kec. Batu Ampar
Kota Batam, Indonesia
WhatsApp: +62 821-7310-7809
Email: [email protected]

Gavriel Studio Batam · Singapore · Remote
PT GAVRIEL KAIROS INDONESIA Menara Aria Office Tower Lt 7 Unit 11, Komplek Harbour Bay Downtown, Jl. Duyung, Kel. Sungai Jodoh, Kec. Batu Ampar, Kota Batam
NIB: 0109260049967 Established 2026
ISO 42001 in progress Agents · Audit · Software
About WhatsApp use case Privacy Policy Terms of Service Subprocessors
© 2026 PT GAVRIEL KAIROS INDONESIA. All rights reserved.