1. Scope of this policy
This policy covers personal data we process when you visit our website, create an account, or use Erza AI (the “Service”). It applies alongside our Terms of Service.
It does not cover the practices of third-party sites or services you reach through links from ours, which have their own policies.
2. Who we are and how to reach us
Erza AI is the data controller for the personal data described here. We operate from Yudistiro St., Palgading, Sinduharjo, Ngaglik District, Sleman Regency, Special Region of Yogyakarta 55581, Indonesia.
For any privacy question, request, or complaint, write to hello@erza.ai with “Privacy” in the subject line, or call +62 851-1132-9511.
3. Data we collect
We collect only what we need to run the Service, and we group it as follows.
- Account data: your name, email address, password hash, optional phone number, profile picture, language and appearance preferences, and two-factor authentication settings.
- Content data: the prompts, documents, drafts, uploads, imported URLs, and generated output you create in the Service, plus the collections and templates you organise them into.
- Usage data: features used, credits consumed, generation history, timestamps, and interaction logs we use to operate quotas and improve the product.
- Technical data: IP address, browser and device type, operating system, referring page, session identifiers, and error diagnostics.
- Billing data: your plan, transaction history, and invoice details. Card numbers are handled by our payment processor and never reach or get stored on our servers.
- Communication data: messages you send to support, and your preferences for product and marketing email.
- Authentication data from third-party sign-in: if you sign in with a provider such as Google, we receive the basic profile and email address that provider releases to us.
4. How we use your data
We use personal data for these purposes and no others.
- Providing the Service: creating your account, generating and storing content, and syncing your workspace across devices.
- Billing: processing subscriptions and credits, issuing invoices, and preventing payment fraud.
- Security: authenticating you, detecting abuse or unauthorised access, and keeping audit and session records.
- Support: answering your questions and diagnosing faults you report.
- Improving the Service: understanding aggregate usage patterns, measuring performance, and prioritising what to build next.
- Communication: sending service notices you cannot opt out of, such as security alerts and billing receipts, and product or marketing email you can opt out of at any time.
- Legal compliance: meeting tax, accounting, and regulatory obligations, and responding to lawful requests.
5. Legal basis for processing
We process personal data under Law No. 27 of 2022 on Personal Data Protection (UU PDP) and, where it applies to you, the GDPR.
- Performance of a contract: everything needed to deliver the Service you signed up for.
- Consent: marketing email, non-essential cookies, and any optional processing. You can withdraw consent at any time without affecting processing already carried out.
- Legitimate interests: security, abuse prevention, and aggregate product analytics, balanced against your rights and freedoms.
- Legal obligation: retaining financial records and responding to lawful authority requests.
6. How your content is processed by AI
When you use a generative feature, your prompt and the surrounding context are transmitted to the AI model provider serving that feature, processed to produce a response, and returned to you. The result is stored in your workspace.
We do not sell your content, and we do not use your content to train our own models. We select providers that contractually commit not to train their models on data submitted through their business APIs, but we cannot guarantee the internal practices of every provider — so please avoid submitting credentials, government identity numbers, health records, or other sensitive data you would not want leaving your organisation.
9. How long we keep data
We keep personal data only as long as we need it for the purpose we collected it, then delete or anonymise it.
- Account and content data: for as long as your account is open, and for 30 days after you delete it so that an accidental deletion can be reversed.
- Backups: encrypted backups age out on a rolling 90-day cycle, after which deleted data is gone from them too.
- Billing records: retained for 10 years, as Indonesian tax and accounting rules require.
- Security and access logs: retained for 12 months.
- Support conversations: retained for 24 months after the case is closed.
10. How we protect your data
We apply technical and organisational measures proportionate to the risk: encryption in transit with TLS and at rest, hashed passwords, optional two-factor authentication, role-based access control, session management with revocation, isolated environments, and regular dependency and infrastructure patching.
No system is perfectly secure. If a breach occurs that is likely to create a risk to your rights, we will notify you and the relevant authority within 72 hours of becoming aware of it, as UU PDP requires.
11. Your rights
You have the following rights over your personal data. Write to hello@erza.ai to exercise any of them; we will respond within 30 days and will not charge you unless a request is manifestly excessive.
- Access: get a copy of the personal data we hold about you.
- Rectification: correct data that is inaccurate or incomplete.
- Erasure: have your data deleted, subject to records we must keep by law.
- Restriction and objection: limit or object to processing based on legitimate interests.
- Portability: receive your data in a structured, machine-readable format, or have it sent to another provider.
- Withdraw consent: at any time, for anything based on consent.
- Complain: to us first, and to Indonesia's personal data protection authority — or your local supervisory authority — if you remain unsatisfied.
12. International transfers
Our providers operate data centres outside Indonesia, so your data may be processed abroad. Where that happens we rely on the safeguards UU PDP and the GDPR recognise: an adequacy finding for the destination country, or contractual clauses that hold the recipient to an equivalent standard of protection.
You can ask us for details of the safeguards that apply to a specific transfer.
13. Children
Erza AI is not directed at children under 17, and we do not knowingly collect their personal data. If you believe a child has given us personal data, contact hello@erza.ai and we will delete the account and its data promptly.
14. Third-party links
The Service may contain links to third-party sites, and content you import may reference them. We do not control those sites and are not responsible for their content or privacy practices. Read their policies before you share personal data with them.
15. Changes to this policy
We will update this policy when our practices or the law change. The date at the top of this page always shows the current version, and we keep it accurate rather than backdated.
Where a change materially affects how we handle your data, we will give at least 30 days notice by email or an in-product notice before it takes effect, and where the law requires it we will ask for your consent again.
16. Contact and complaints
We would rather hear from you than have you wonder.
Email: hello@erza.ai — Phone: +62 851-1132-9511 — Address: Yudistiro St., Palgading, Sinduharjo, Ngaglik District, Sleman Regency, Special Region of Yogyakarta 55581, Indonesia.
