Legal
ProfileMU Privacy Policy
In effect since: January 1, 2026 · Version 1.0
ProfileMU ("we") is committed to protecting the privacy of personal data of users of our website builder service. This policy explains what data we collect, why, and how you can control it. Drafted in alignment with Indonesia's Law No. 27 of 2022 on Personal Data Protection (UU PDP).
1. Data We Collect
1.1 Data you provide directly
- Account: name, email, WhatsApp number, password (hashed)
- Business profile: business name, category, address, contact, logo, description
- Website content: text, images, videos, files you upload to the builder
- Payment data: not stored directly — processed by Xendit/Midtrans (PCI DSS compliant)
1.2 Data collected automatically
- Access logs: IP address, user agent, timestamp, accessed pages
- Cookies: session authentication (necessary), language preference
- Analytics: page views, session duration (anonymous)
1.3 Data from visitors of your site
Contact forms you place on your public site will store: name, email, phone, message from visitors of your site. This data lives in your tenant database — it belongs to you, not us.
2. Processing Purposes
- Provide website builder service and *.profilemu.com subdomain hosting
- Process trial / subscription payments
- Send important notifications: trial expiry, invoices, service changes
- Detect & prevent abuse (spam, fraud)
- Meet legal obligations (tax audit, legitimate authority requests)
We DO NOT sell data to third parties, DO NOT use your data to train AI, and DO NOT display third-party ads on your site.
3. Sharing Data with Third Parties
We only share data with processors necessary for operating the service: Cloudflare R2 (file storage), Xendit/Midtrans (payment), Postmark/Mailgun (email), Fonnte (WhatsApp), Sentry (error monitoring). All processors are bound by DPAs prohibiting use of your data for other purposes.
4. Data Retention
- Active accounts: for the duration of the account
- Expired trial accounts: 7-day grace + 30-day retention before hard delete
- Deleted accounts: tenant data is dropped, except invoices which MUST be retained for 10 years (Indonesian Tax Law)
- Access logs: 90 days
- Database backups: 30-day rolling
5. Your Rights as a Data Subject (UU PDP Articles 5-15)
- Access: request a copy of your data (Settings > Export Data)
- Correction: modify inaccurate data anytime via the dashboard
- Deletion: close your account via Settings > Close Account
- Consent withdrawal: cancel subscription via dashboard
- Portability: export all your data as a ZIP file
For manual requests, contact dpo@profilemu.com (response within 14 business days).
6. Security
Passwords are hashed with bcrypt, HTTPS on all endpoints (TLS 1.3), encrypted sessions, multi-tenant database isolation, daily encrypted backups, audit logs for sensitive access. In case of a data breach, we WILL notify you + Kominfo within 3×24 hours (UU PDP Article 46).
7. Cookies
We use session cookies (auth), CSRF tokens, and language preferences. NO third-party tracking cookies (Google Analytics, Facebook Pixel, etc). You may block cookies via your browser, but authentication will be affected.
8. Contact
- DPO: dpo@profilemu.com
- Customer Support: support@profilemu.com
Complaints may also be addressed to the Personal Data Protection Authority (once established) or Kominfo via aduankonten.id.