PRIVACY POLICY

Effective Date: October 16, 2025

This Privacy Policy ("Policy") explains how PT VERITAS INTELEGENSIA TEKNOLOGI ("We", "Us", "the Company") as the Data Controller, collects, processes, uses, discloses, and protects Data that we obtain from customers, members, and visitors ("Users", "You") in connection with the use of our website https://veritask.ai/ and all its subdomains ("Site") and AI-based software services ("Services").

We are committed to protecting your Data in accordance with applicable laws and regulations on data protection. This Policy applies to the Site and all products and Services We provide.

DEFINITIONS

The following are definitions of terms used in this Policy:

Data

Data refers to any information, in any form, whether related to an individual person or to data owned by or related to the business operations of a company or a legal entity that is identified or can be identified, either on its own or in combination with other information, either directly or indirectly, through electronic or non-electronic systems.

Data Controller

The Data Controller is any person, public body, or international organization acting alone or jointly with others in determining the purposes and means of processing Data. In this case, the Data Controller is our Company.

Data Processor

The Data Processor is any person, public body, or international organization that acts alone or jointly in processing Data on behalf of the Data Controller.

Data Subject

The Data Subject is the individual to whom the Data relates, namely you as the User.

Data Processing

Data Processing includes the acquisition, collection, processing, analysis, storage, correction, updating, display, announcement, transfer, dissemination, disclosure, deletion, or destruction of Data.

TYPES OF DATA COLLECTED

To provide our services, Veritask collects data from users through several methods, which can be classified as follows:

1. Data Provided Knowingly by the User

We collect information that you voluntarily submit when performing the following activities:

  • Account Registration and Management: Personal identification data (name, phone number, e-mail address, other contact information) and corporate information (company name, address, NIB/Business Identification Number, position).
  • Use of Services: Supporting data uploaded to the platform.
  • Direct Communication: Information received through interactions with our customer support teams, filling out application forms or surveys, and other correspondence.
  • Financial Transactions: Payment data required to process transactions, including credit card and e-wallet details.
  • Use of AI Features: All data, documents, and information input into Veritask's artificial intelligence features for the purpose of analysis and automated processing.

2. Data Automatically Recorded by the System

While you are using the platform, our system automatically records the following technical data:

  • Activity and Location Data: Platform usage history (login activity, features accessed), location data (IP address, geo-location, GPS), and server logs.
  • Device and Configuration Data: Information about the devices used (hardware type, operating system), as well as your preferences and settings on the platform recorded through technologies such as cookies.
  • Device Access (With Permission): The platform may request permission to access components of your device such as the camera, gallery, and internal storage to enable document upload and download functionality. This access is only granted with your consent and is limited to the files you select.

PURPOSE OF DATA PROCESSING

The purposes of our Data processing are as follows:

  • To verify and manage your account for the use of the Site and Services.
  • To provide, operate, and maintain our AI-based regulatory compliance tracking Services.
  • To process payment transactions and manage your subscriptions.
  • To enhance your experience by personalizing and optimizing the user interface of the Site and Services.
  • To conduct research and analysis to develop and improve the features, security, and quality of the Services.
  • To manage promotions, surveys, or other marketing activities.
  • To facilitate communication between you and our customer support team to resolve issues.
  • To send you marketing information, newsletters, and other publications that may be of interest to you. You can withdraw this consent at any time.
  • To comply with lawful orders from law enforcement officials or authorized authorities.
  • To use data to develop, train, and refine the performance of the AI system based on the principle of data anonymization.

YOUR RIGHTS AS A DATA SUBJECT

As a Data Subject, you have the right to:

  • obtain information about the clarity of our identity, legal basis, purposes, and accountability as a Data Controller.
  • complete, update, and/or correct errors in your Data. We are obliged to correct such errors no later than 3×24 hours after receiving your request.
  • gain access to and obtain a copy of your Data. We will provide such access no later than 3×24 hours after receiving the request.
  • request the termination of processing, deletion, and/or destruction of your Data in accordance with statutory provisions.
  • withdraw the consent for Data processing that you have given us. We will cease processing no later than 3×24 hours after receiving your request.
  • object to decision-making actions based solely on automated processing, including profiling.
  • delay or limit Data processing proportionally to its purpose.
  • sue and receive compensation for violations of your Data processing.

To exercise the above rights, please contact us through the contact information provided at the end of this Policy. The mechanism for exercising your rights is detailed in the appendix to this document. The exercise of these rights will be subject to the exceptions as stipulated in Article 15 of the PDP Law (Personal Data Protection Law), such as for national defense and security interests or law enforcement processes.

DISCLOSURE AND TRANSFER OF DATA

We will not sell or rent your Data. We may only disclose or transfer your Data to third parties under the following conditions:

  • We may share your Data with vendors or third-party service providers (Data Processors) who assist us in providing the Services, such as cloud infrastructure providers, data analytics services, and payment processing. We ensure these third parties are bound by agreements to protect your Data and only process it based on our instructions.
  • We may disclose your Data if required by law or in response to a valid legal process.
  • In the event of a merger, acquisition, or sale of company assets, your Data may be transferred. We will notify you both before and after such a transfer occurs.
  • If we need to transfer your Data outside the territory of Indonesia, we will ensure that the destination country has a level of data protection that is equivalent to or higher than the PDP Law. If not, we will ensure there is adequate and binding protection or request your prior consent.

POLICY ON COOKIES AND TRACKING TECHNOLOGIES

1. Definition and Function of Cookies

Our platform utilizes cookies, which are small text files automatically stored on your device. The primary function of cookies is to record and retain your preferences and configurations during a visit session, in order to provide an improved user experience. We guarantee that cookies are not used to access other information beyond the data you have agreed to share.

2. Management and Control of Cookies

You have full control to manage cookies through your browser settings. Although cookie acceptances are generally enabled by default, you can modify these settings to refuse them. However, this option may cause some Veritask services and features to not operate optimally.

3. Use of Google Analytics

In the context of platform development, we use Google Analytics services to analyze user data, such as demographics and interests. This data is used as a basis for improving the quality of features and content. Users who do not wish for their data to be processed by Google Analytics can use the Google Analytics Opt-Out Add-On available for their browser.

4. Third-Party Advertising

Veritask may collaborate with third-party service providers for the purpose of customizing and presenting relevant advertisements based on your browsing history or interests. You can manage preferences regarding these personalized advertisements through your browser settings.

PROTECTION AND SECURITY OF YOUR DATA

1. Primary Commitment and Our Protective Measures

Veritask places the confidentiality of your personal data as our highest priority. We guarantee that all information you submit will be kept confidential and will not be disclosed, except for the purposes described and agreed to by you in this Privacy Policy.

2. Security Limitations and Your Responsibilities

Although we make our best efforts, it is important to understand that no data transmission over the internet is completely secure. Therefore, Veritask cannot provide an absolute (100%) security guarantee for the data you transmit. You acknowledge that providing this information is done at your own risk.

You also hold fundamental responsibility in maintaining the security of your account, which includes:

  • Account Confidentiality: You must maintain the confidentiality of your account details, including your email and password, and not share them with anyone.
  • Device Security: You are fully responsible for the security of the device you use to access our services.

By this, you agree to release Veritask from any claims or losses arising from your negligence in maintaining the confidentiality of your account or the security of your device.

3. Storage, Deletion, and Confidentiality Exceptions

Storage Period: We will store your data only for as long as necessary to fulfill the purposes of its processing, for as long as your subscription is active, or according to the retention period required by law. After that period ends, we will delete or destroy the data.

AI Data Deletion Request: Any request to delete personal data that has been processed by our AI system will be followed up in accordance with the procedures applicable on the platform.

Confidentiality Obligation Exceptions: Our obligation to maintain confidentiality does not apply to data that:

  • Has become public information not due to our negligence;
  • We lawfully obtain from a third party who is not bound by a confidentiality obligation;
  • You have authorized to be disclosed; or
  • Must be disclosed by law, court order, or an order from a legitimate government authority.

CHANGES TO THE PRIVACY POLICY

We may update or modify this Privacy Policy from time to time. If there are any changes, we will notify you before the changes take effect. We encourage you to review this page periodically.

CONTACT US

If you have questions regarding this Privacy Policy or wish to exercise your rights as a Data Subject, please contact us via:

Email: partnership@veritask.ai

Through the "Contact Us" feature available within the Platform.

By using our Site and Services, you acknowledge that you have read, understood, and agreed to the collection and processing of your Data as set out in this Privacy Policy.

APPENDIX I - MECHANISM FOR FULFILLING THE RIGHTS OF PERSONAL DATA SUBJECTS

We are committed to facilitating your rights as a Data Subject. To exercise your rights in accordance with applicable regulations, please follow the mechanism below.

General Request Procedure

For security and validity, all requests follow the standard procedure below:

Written Submission

Submit a written request to our privacy email at: partnership@veritask.ai. Please include your full name, registered email/phone number, and specific details of your request to expedite the process.

Identity Verification

Upon receiving the request, we will verify your identity and confirm receipt of the request via your registered email/phone number. For sensitive requests (such as data deletion), additional verification may be required. We will never ask for your password.

Processing & Notification

After successful verification, we will process your request in accordance with the timeframe stipulated by the PDP Law and send a confirmation notification upon completion.

Exercise of Specific Rights

Updating and Correcting Data

You can update most of your data independently through "Account Settings". For data that cannot be changed, submit a request and we will process it within 3×24 hours.

Accessing and Obtaining a Copy of Data

To access or obtain copies of your data, submit a specific request. We will provide the data in a common format (e.g., PDF) within 3×24 hours.

Withdrawing Consent and Deleting Data

Submit a request to withdraw consent or delete data. Please be aware that this action may result in you losing access to our Services. The request will be processed within 3×24 hours.

Other Rights (Objection, Postponement, Restriction)

For other rights, submit a request with a clear explanation of the basis for your request.

Exceptions

In accordance with applicable law (including Article 15 of the PDP Law), we may refuse a request for specific reasons such as law enforcement interests. If the request is refused, we will provide a written explanation of the basis for the refusal.

Record-Keeping

All requests, verification processes, and actions we take will be documented for compliance purposes.

Have questions about Veritask?

Contact us now!

Privacy Policy - Veritask Legal AI | Veritask