Knowing what happens to your data when it sits in the cloud is vitally important. We have extracted some data related statements from our General Terms and Conditions so you know our position.

5.1 Data Ownership

5.1.1 At all times, the “Customer Data” remains the exclusive property of The Customer.

5.2 Data Import and Export

5.2.1 The Customer Data (subject to any licence transfer limitations as per section 5.8) may be imported or exported from or to Zettagrid at any time by the Customer.

5.2.2 If the Customer is unable to retrieve this data using Zettagrid supplied self-provisioned means (i.e. File Download) and the Customer requests manual intervention by Zettagrid, then we will charge the Customer an hourly rate for the copy and shipping of this data.

5.3 Data Retention

5.3.1 Once the Customer cancels a Service, the Customer Data pertaining to that Service shall not be retrievable at this point by the Customer in any shape or form.

5.3.2 Zettagrid may retain Metadata pertaining to the Customer account and usage for an indefinite period.

5.3.3 Zettagrid will erase the Customer Data from our systems no later than 90 (ninety) days from the date of Service cancellation.

5.4 Data Access

5.4.1 We will not attempt to gain access to the Customer Data without express written consent of the Customer.

5.4.2 The use of the Customer Data shall strictly be limited to the provisions and delivery of the Service, and shall not be exploited for any other revenue-generating purpose.

5.4.3 If we are approached by law enforcement agencies. it is our policy to provide the request information upon receipt of request from such agencies.

5.4.4 We do not provide access to the Customer Data to third parties other than law enforcement agencies as set out above.

5.5 Data Sovereignty

5.5.1 We store all the Customer Data and backups of this data within Indonesia.

5.5.2 We may offer Products that store data outside of the Indonesian lawful jurisdiction. Where this is the case, we will identify that the Customer Data may be stored in a non-Indonesian location.

5.5.3 We cannot guarantee the Service usage information and related Meta Data is not stored by our upstream communication providers in non-Indonesian locations.

5.6 Data Backup

5.6.1 Zettagrid will be responsible for backup of Zettagrid Data.

5.6.2 Zettagrid does not backup the Customer Data unless the Customer purchases a Zettagrid Backup Service.

5.6.3 The Customer is solely responsible for backup of the Customer Data and for implementation of an appropriate retention strategy.

5.6.4 Where the Customer subscribes to a Zettagrid Backup Service, the Customer is responsible for setting up, maintaining, monitoring and testing backups.

5.7 Intellectual or Copyright Infringement

5.7.1 Where Zettagrid is provided with reasonable evidence from copyright owners or their authorized agents that alleges that the Customer may be using the Service unlawfully we will:

  • Send the Customer default notice by email. This email will contain the reference to specific alleged copyrighted content or unlawful activity.
  • Request that the Customer remove the alleged copyrighted content and or cease the alleged unlawful activity within 72 (seventy-two) hours.

5.7.2 Where the provision of alleged copyrighted content or unlawful activity has not ceased after 72 (seventy-two) hours from the receipt of the notice, Zettagrid will limit the Customers Services in order to enforce the restriction of the dissemination of alleged copyrighted content or the activity.

5.7.3 If the Customer provides reasonable evidence to suggest the unauthorized use of the Service or a breach and subsequent resolution of the Customers own policies resulted in the issue of the notice from the copyright holder we may waive the default notice.

5.7.4 Where we issue the Customer with more than 3 (three) ACIN’s within a 30-day period the Customer will be classified as a repeat offender and the Customers Service will be terminated under Clause 4.9.1

5.7.5 Intellectual property rights or copyright infrigement complaints can be lodged via Support.

5.8 Cyber Security Incidents

5.8.1 If we discover that the Customer Data has been lost or compromised, we shall, to the extent applicable to the provision of Services to the Customer, be subject to and comply with:

  • The Notifiable Data Breach provisions under Law No. 27 of 2022 concerning Personal Data Protection, Law No. 11 of 2008 on Electronic Information and Transactions, and Article 14 paragraph (3) of Government Regulation No. 71 of 2019 concerning the Operation of Electronic Information and Transactions; and
  • The Cyber incident reporting obligations under regulation of National Cyber and Crypto Agency of the Republic of Indonesia (BSSN) No. 4 of 2024,

As well as all other applicable legal and regulatory requirements.

We shall notify the Customer of such breach within a maximum of 8 (eight) business hours from the time of discovery, either by email to the Customer’s designated email address or by telephone to the Customer’s nominated representative, unless such notification would reasonably be expected to compromise a criminal investigation relating to the incident.

5.8.2 When we are in possession of evidence of criminal activity associated with the breach (such as evidence of hacker activity) we will notify appropriate law enforcement agencies.

5.8.3 We receive a request for information under Clause 5.4.3 we will notify the Customer of this request unless otherwise requested by the law enforcement agency.

5.8.4 Upon the occurrence of a Cyber Security Incident pertaining to Zettagrid Data:

  • Zettagrid shall propose and provide the Customer with all remedial actions Zettagrid intends to take in order to mitigate the consequences and/or impacts associated with the Security Incident;
  • Zettagrid shall provide updates to the Customer on the status of the Security Incident and remediation efforts; The cadence of status updates will be determined by the severity of the Security Incident but will be not less than 30 (thirty) minutes; and
  • assist the Customer in complying with its notification and information disclosure obligations about the Security Incident under the applicable laws (including to the relevant Regulatory Authority and affected organisations and/or Individuals).

5.8.5 All Customer specific information concerning the Security Incident shall be deemed to be the Customer’s confidential information. Zettagrid shall not disclose any information regarding the Security Incident without the Customer’s prior written consent.

5.8.6 Zettagrid acknowledges and agrees that the Customer and Zettagrid may be subject to investigations by a Regulatory Authority arising out of or in connection with any Security Incident. In such event, Zettagrid shall provide the Customer and/or the Regulatory Authority with full access to and copies of all relevant evidence, including logs and audit trails.

5.8.7 The Customer may report a Security Incident or request further Security Handling information by contacting Support.

5.8.8 Security Incidents may be tracked on https://support.zettagrid.id