1. Introduction, Confidentiality Commitment, and Scope of the Policy
PT Inovasi Pembayaran Digital (hereinafter referred to as "Ayolinx" or the "Company") fully recognizes and upholds the fundamental importance of personal data protection, financial information integrity, and the absolute privacy of every User. This Privacy Policy constitutes a legally binding instrument and forms an integral part of the Ayolinx Payment Services Terms and Conditions. This document is designed to comprehensively regulate the procedures, limitations, and commitments of the Company in collecting, processing, storing, securing, and disclosing User data when accessing payment interfaces and using our payment gateway transmission infrastructure.
Ayolinx provides the highest level of assurance and commitment that all transaction data traffic passing through our system infrastructure is classified as highly confidential information. All data is transmitted through HTTPS/TLS encryption, stored using data encryption mechanisms, and processed through the encrypted server domain: https://merchant-backend-new.ayolinx.id/.
By initiating a payment transaction, transmitting financial data, or clicking the consent button on a platform facilitated by Ayolinx, the User expressly, knowingly, and voluntarily acknowledges that they have read, fully understood, and legally consented to the Company's processing of their personal and financial data solely based on the principles of fairness, proportionality, and the requirements mandated by the Indonesian Personal Data Protection Law (PDP Law) and applicable banking regulations.
2. Categories of Personal Data and Financial Information Collected
In its specific capacity as a Category 2 Payment Service Provider (PJP) supervised by Bank Indonesia, Ayolinx strictly applies the principle of data minimization, whereby the collection and extraction of information are limited exclusively to data elements that are relevant and absolutely necessary to accurately and securely execute payment instructions. The data collected and processed by the Company's systems includes, but is not limited to:
- Basic identity data, such as the User's full name;
- Company address (where applicable for corporate entities);
- Privacy contact email address;
- Customer service telephone number or other consultation channels;
- Mobile phone number of the responsible person; and
- Email address.
All categories of collected data are specified clearly and explicitly; no vague or ambiguous terminology is used.
The Company also collects transactional order details such as order reference numbers and payment amounts. Financial instrument data may include Virtual Account numbers, e-wallet token IDs, or credit/debit card identification numbers, which are processed solely in encrypted and tokenized formats.
Furthermore, for the essential purposes of fraud risk mitigation and cybersecurity anomaly detection, Ayolinx's infrastructure systems automatically and accurately record Users' technical activity logs. Such information includes, but is not limited to:
- Internet Protocol (IP) addresses;
- Device and browser identification;
- Operating system information;
- Approximate geolocation data;
- Transaction navigation logs; and
- Processing timestamps.
The Company expressly affirms that Ayolinx never requests, records, or stores highly sensitive authentication data such as Personal Identification Numbers (PINs), Card Verification Values/Codes (CVV/CVC), or One-Time Passwords (OTPs) in plain-text format, thereby ensuring the highest level of security for Users' payment instruments.
3. Purpose of Processing, Limited Use, and Transaction Confidentiality Assurance
The Company provides an irrevocable legal assurance that all personal and financial data collected by Ayolinx is used exclusively for operational payment processing, transaction authorization, and compliance with banking regulations.
Ayolinx guarantees complete transaction confidentiality. User data will never be misused, exploited, rented, distributed, or sold to third parties, data brokers, or affiliated entities for commercial purposes, consumer profiling, cross-marketing campaigns, or targeted advertising.
The purposes of data processing by Ayolinx are strictly limited to:
- Executing real-time fund transfers;
- Validating and authorizing transactions with banking institutions;
- Conducting financial settlement processes for Merchants;
- Handling technical complaints and troubleshooting; and
- Managing chargeback processes.
In addition, data processing and analysis are strictly conducted to fulfill mandatory regulatory obligations, including:
- Operating Fraud Detection Systems;
- Performing Customer Due Diligence (CDD);
- Preventing Money Laundering (AML);
- Preventing Terrorism Financing; and
- Meeting the highest operational risk management compliance standards required by monetary authorities.
4. Limited Disclosure and Need-to-Know Data Sharing
The confidential nature of User transactions remains protected even when Ayolinx interacts with external infrastructure during payment settlement processes.
To ensure the successful, secure, and lawful authorization of fund transfers, Users grant Ayolinx limited authority to disclose and transmit transactional data only to third parties that directly facilitate the payment ecosystem, strictly on a need-to-know basis.
Such third parties are limited to:
- Acquiring and issuing partner banks;
- Payment network principals (such as international card networks, Indonesia's National Payment Gateway operators, or switching operators);
- Electronic wallet providers; and
- Enterprise-grade cloud infrastructure providers.
All such third parties are legally bound by strict Non-Disclosure Agreements (NDAs) and are required to maintain data protection standards equivalent to or higher than those maintained by Ayolinx.
Outside operational transaction requirements, User confidentiality may only be breached where Ayolinx is legally required to disclose data to authorized law enforcement agencies, the Indonesian Financial Transaction Reports and Analysis Center (PPATK), Bank Indonesia, the Financial Services Authority (OJK), or competent judicial authorities. Such disclosure must be based on an official request letter, lawful search warrant, court order, or formal investigation procedure relating to suspected criminal offenses, terrorism, or large-scale financial fraud.
5. High-Level Cryptographic Security Standards and Data Retention Obligations
Ayolinx maintains a substantial commitment and investment in technology to protect the integrity, availability, and confidentiality of User data against unauthorized access, modification, leakage, or destruction.
The Company implements layered information security and infrastructure standards aligned with stringent global financial industry standards.
With respect to data lifecycle management and retention periods, Ayolinx is subject to mandatory legal obligations under Anti-Money Laundering and Counter-Terrorism Financing regulations, central bank payment system regulations, and Indonesian tax laws.
Accordingly, the Company is legally required to securely store transactional records and related personal data within encrypted Company servers for a minimum retention period of five (5) to ten (10) years from the date of transaction execution or service termination, regardless of any future data deletion requests submitted by Users.
6. Data Subject Rights and Absolute Legal Exceptions
Subject to and in accordance with the Indonesian Personal Data Protection Law (PDP Law), Users, as data subjects, possess legally protected rights to:
- Request access to their information;
- Request updates or corrections to inaccurate data; and
- Request deletion or anonymization of personal data stored within Ayolinx systems.
However, the Company emphasizes that the right to data deletion is not absolute and cannot be exercised immediately where legal exceptions apply.
User data cannot be deleted where:
- It remains within a mandatory statutory retention period;
- It is suspended due to an ongoing suspicious transaction investigation by fraud monitoring systems;
- It is involved in an active chargeback dispute; or
- It is required as historical legal evidence to protect the Company's legal rights in unresolved judicial proceedings.
All administrative requests relating to privacy rights, as well as reports concerning suspected breaches of data confidentiality, must be submitted formally and in writing through the dedicated customer service communication channels via the official email address published within the Ayolinx payment system interface.
7. Contact Us
If you have any questions about this Privacy Policy, your personal data, or would like to exercise your rights under applicable data protection laws, please contact us:
PT Inovasi Pembayaran Digital (Ayolinx)
We will respond to your inquiries and requests within a reasonable timeframe in accordance with applicable laws and regulations.