GDPR & UU PDP Compliance
VillaTax, PT Asiah Legal Jaya Last updated: May 2026
Preamble
This page describes the compliance measures implemented by VillaTax (operated by PT Asiah Legal Jaya, No. 1446293) under two distinct and complementary legal frameworks:
- The General Data Protection Regulation (GDPR, EU Regulation 2016/679 of 27 April 2016), applicable by virtue of the presence of users residing in the European Union, regardless of the location of VillaTax's servers
- The Indonesian Personal Data Protection Law (Undang-Undang Perlindungan Data Pribadi, UU PDP No. 27/2022, which entered into force on 17 October 2024), applicable by virtue of PT Asiah Legal Jaya's activity on the territory of the Republic of Indonesia and the collection of data concerning Indonesian nationals and residents
These two frameworks complement and reinforce each other. Where the requirements of one are more stringent than the other, VillaTax systematically applies the higher level of protection. VillaTax's full Privacy Policy is available at villa-tax.operium.store/bali-villa-privacy and constitutes the reference document for personal data processing.
1. Data controller
PT Asiah Legal Jaya is the data controller (Data Controller within the meaning of the GDPR, Pengendali Data Pribadi within the meaning of the UU PDP) for all personal data collected and processed via the VillaTax platform.
| Detail | Information |
|---|---|
| Company name | PT Asiah Legal Jaya |
| Entity number | 1446293 |
| Registered office | Benoa Square lantai 3 suite 4.3, Jalan By Pass Ngurah Rai No 21 A, Badung, Bali, Indonesia |
| Contact email | commercial@operium.store |
| +6281387983316 |
PT Asiah Legal Jaya determines the purposes and means of personal data processing. Sub-processors engaged to provide the service act exclusively on the instructions of PT Asiah Legal Jaya and may not use the data for their own purposes.
In accordance with Article 53 of the UU PDP, PT Asiah Legal Jaya designates a Petugas Pelindungan Data Pribadi (equivalent to a Data Protection Officer, DPO) responsible for internal compliance oversight. This contact is reachable at commercial@operium.store.
2. Dual legal framework: GDPR & UU PDP
2.1 The GDPR, European Regulation
VillaTax's servers are located in Indonesia and PT Asiah Legal Jaya has no establishment in the European Union. The GDPR nonetheless applies to VillaTax on the following basis:
Targeting of persons in the EU: VillaTax is accessible to, and actively serves, users residing in EU Member States (French, German, Dutch, Swedish, etc. villa owners in Bali). The GDPR applies to the processing of these persons' data whenever the processing relates to the offering of services to them, regardless of the data controller's place of establishment or the location of its servers (Art. 3.2 GDPR).
2.2 The UU PDP, Indonesian Law
Law No. 27/2022 on Personal Data Protection (Undang-Undang Perlindungan Data Pribadi), enacted on 17 October 2022 and fully in force from 17 October 2024, is Indonesia's first law dedicated to personal data protection. It draws heavily on the GDPR but incorporates specificities reflecting the Indonesian legal and institutional context.
The UU PDP applies to VillaTax for the following reasons:
- PT Asiah Legal Jaya is an Indonesian legal entity
- VillaTax processes data concerning Indonesian nationals and residents (villa owners, employees, Indonesian guests)
- VillaTax's core activity (Indonesian tax compliance) involves the processing of tax and administrative data governed by Indonesian law
Key differences between the GDPR and UU PDP:
| Aspect | GDPR | UU PDP |
|---|---|---|
| Supervisory authority | CNIL, BfDI, AEPD, etc. (per Member State) | Kementerian Komunikasi dan Digital (Komdigi) |
| Breach notification deadline | 72 hours (Art. 33) | Immediately (segera), Art. 46 |
| Right to portability | Art. 20 (machine-readable format | Art. 11) appropriate format and method |
| Maximum sanctions | 4% global turnover or EUR 20M | 2% national turnover or Rp 25 billion |
| Data protection officer | DPO mandatory for large-scale processing | Petugas PDP recommended |
| Right to object | Art. 21 | Art. 10 |
3. Fundamental principles applied
VillaTax structures all its data processing around the fundamental principles of the GDPR (Art. 5) and the UU PDP (Art. 16), applied at the most demanding level of the two frameworks:
Lawfulness, fairness, and transparency: Every collection of data rests on an identified legal basis. No processing is carried out without the User's knowledge or in a manner contrary to their legitimate interests. This page and the Privacy Policy ensure full transparency of processing.
Purpose limitation: Data collected is used only for the purposes for which it was gathered and declared. No incompatible secondary use is made. In particular, the User's tax data is never used for advertising, commercial third-party, or profiling purposes.
Data minimisation: VillaTax collects only data strictly necessary to provide the Services. The Free plan requires only an email address and a name. Additional data (NPWP, regency, legal structure) is collected as and when functionally required, at the User's initiative.
Accuracy: VillaTax makes available to the User the tools necessary to keep their data accurate and up to date (Settings page, API access). The User is responsible for the accuracy of the data they enter; VillaTax undertakes to process that data in accordance with its state at the time of processing.
Storage limitation: Data is retained only for as long as strictly necessary. Specific retention periods by category are detailed in Article 7 of the Privacy Policy and section 9 of this page.
Integrity and confidentiality: Appropriate technical and organisational measures are implemented to protect data against any unauthorised access, loss, destruction, or alteration (see section 5).
Accountability: PT Asiah Legal Jaya documents its processing activities, legal bases, security measures, and incidents. This documentation is available on request from the competent supervisory authorities (Komdigi, CNIL, and equivalents).
4. Legal bases for processing
In accordance with Article 6 of the GDPR and Articles 20 et seq. of the UU PDP, each processing activity of personal data carried out by VillaTax rests on a specific and identified legal basis.
4.1 Contract performance (Art. 6.1.b GDPR, Art. 20.1.b UU PDP)
Constitutes the primary legal basis for VillaTax for processing necessary to provide the service:
- Account creation and management (email, name, hashed password)
- Processing of OTA booking data for automated tax calculation (PBJT, PPh, PPN)
- Generation of DJP / Coretax compliance reports and SPT declarations
- BPJS social contribution and PPh 21 payroll calculation (HR module)
- Subscription payment processing via Xendit
- Sending transactional emails (confirmations, payment reminders, tax alerts)
4.2 Legal obligation (Art. 6.1.c GDPR, Art. 20.1.c UU PDP)
Applicable where processing is imposed by a binding rule of law:
- Retention of tax data for 10 years pursuant to Article 29 of the KUP Law (Law No. 6/1983 as amended)
- Processing of NPWP data and DJP declarations pursuant to Indonesian tax obligations
- Maintenance of PSAK accounting records pursuant to Law No. 8/1997 on Company Documents
- BPJS Kesehatan and Ketenagakerjaan declarations pursuant to Law No. 24/2011
4.3 Legitimate interest (Art. 6.1.f GDPR, Art. 20.1.f UU PDP)
Used restrictively and proportionately for processing not falling within the preceding categories:
- Security logs (access logs, intrusion detection, rate limiting), legitimate interest in securing the platform
- Error and performance monitoring via Sentry (with PII scrubbing enabled), legitimate interest in continuous service improvement
- Aggregated and anonymised usage statistics, legitimate interest in optimising the user experience
For each processing activity based on legitimate interest, PT Asiah Legal Jaya has carried out a balancing test confirming that this interest does not override the fundamental rights and freedoms of the data subjects. This test is available on request.
4.4 Consent (Art. 6.1.a GDPR, Art. 20.1.a UU PDP)
Consent is sought only for processing not covered by the preceding legal bases and not necessary to provide the Services: optional marketing communications, satisfaction surveys. Consent may be withdrawn at any time without prejudice to access to the Services.
5. Technical and organisational security measures
VillaTax implements a comprehensive set of technical and organisational security measures in accordance with Article 32 of the GDPR and Article 35 of the UU PDP, proportionate to the level of risk presented by the processing activities.
5.1 Infrastructure security
- Hosting: servers located in Indonesia
- Encryption in transit: TLS 1.3 on all communications between the browser and VillaTax servers; minimum TLS 1.2 for inter-service communications
- Encryption at rest: Encrypted backups; encryption keys managed separately from data
- Server access: Exclusive authentication via SSH key (password authentication disabled at OS level); access limited to authorised IP addresses by firewall
- Database: PostgreSQL accessible only from authenticated local connections (127.0.0.1); strict separation of production and development environments
5.2 Application security
- Passwords: bcrypt hashing with cost factor 12 rounds (irreversible by design, PT Asiah Legal Jaya cannot retrieve your password in plain text)
- JWT tokens: Signed via jose (HMAC-SHA256), configured expiry, regular rotation
- API keys: Randomly generated (256 bits of entropy), hashed before storage, not retrievable in plain text
- CSRF: Protection against Cross-Site Request Forgery attacks on all forms and state-mutation operations
- Rate limiting: Rate limiting on all API routes and authentication endpoints to prevent brute-force attacks
- Cookies:
httpOnly,secure, andsameSite: laxattributes on all session cookies - HTTP headers: Content Security Policy (CSP), X-Frame-Options, X-Content-Type-Options, and HSTS configured
- Secrets: No secret keys or sensitive data transmitted as URL parameters or stored in plain text in the source code
5.3 Monitoring and detection
- Sentry: Error and performance monitoring with PII scrubbing configuration enabled, no personally identifiable data in error reports transmitted to Sentry
- Application logs: Logging of access, critical actions (audit log), and system errors, retained for 90 rolling days
- Alerts: Automated alert system in the event of behavioural anomalies (unusual request volume, repeated authentication errors)
5.4 Backups and continuity
- Frequency: Full database backup daily at 03:00 UTC
- Retention: 14 rolling days (automatic rotation)
- Encryption: All backups are encrypted at rest
- Restoration testing: Periodic restoration tests to ensure the integrity and usability of backups
5.5 Organisational measures
- Access to production data restricted to team members who strictly need it (principle of least privilege)
- Confidentiality agreement signed by all staff and service providers with access to data
- Documented security incident management procedure
- Regular reviews of access rights
6. Processing of sensitive data
6.1 Passport photographs
Passport photographs of guests, collected pursuant to the Indonesian obligation to report foreign travellers (Siskoharlat), constitute sensitive data requiring enhanced protection. VillaTax applies the following protocol:
- Temporary secure storage on servers located in Indonesia, with encryption at rest
- Automatic and irreversible deletion within 24 hours of the guest's checkout, executed by an automated cron process running daily
- No analysis, text extraction (OCR), facial recognition, or analytical processing on these images
- Simultaneous deletion of the physical file and any database reference
- No copy retained on any medium after deletion
This 24-hour period complies with the Siskoharlat regulation and goes beyond the minimum requirements, by application of the storage minimisation principle.
6.2 Tax data and NPWP numbers
NPWP numbers (Nomor Pokok Wajib Pajak) and associated tax data are processed with the highest level of confidentiality. They are never transmitted to commercial third parties and access is restricted to VillaTax's automated systems required for tax calculation. NPWP numbers are encrypted at rest in the database.
6.3 Personnel data
Salary and social contribution data of villa employees (names, salaries, BPJS) are processed within the strict framework of VillaTax's HR module. They are accessible only to the account owner concerned and to team members with explicit authorisation. This data is subject to a statutory retention obligation of 5 years in accordance with BPJS regulations.
7. International data transfers
7.1 Data flows and location
| Service | Location | Data transferred | Guarantees |
|---|---|---|---|
| Hosting provider | Indonesia | All user data | See sub-processor list, section 11 |
| Xendit | Indonesia | Payment data (anonymised) | PCI DSS Level 1, Indonesian law |
| Resend Inc. | USA | User email, transactional content | Standard Contractual Clauses (SCC) |
| Sentry | USA | Anonymised error logs (PII scrubbing) | Standard Contractual Clauses (SCC) |
7.2 Transfers of EU/EEA personal data to Indonesia
VillaTax's servers being located in Indonesia, processing personal data transferred from the EU/EEA involves a transfer outside the European Economic Area. Indonesia does not currently benefit from an adequacy decision from the European Commission. VillaTax does not use Article 49 derogations as a general mechanism for regular or repetitive transfers. An appropriate transfer mechanism under Chapter V of the GDPR must be in force before such transfers take place. Any exceptional reliance on an Article 49 derogation must be assessed, documented and limited to the specific transfer concerned.
7.3 Protection mechanisms for transfers to other sub-processors outside the EU and Indonesia
For transfers to sub-processors located in the United States (Resend, Sentry), VillaTax relies on the Standard Contractual Clauses (SCC) approved by the European Commission pursuant to Implementing Decision (EU) 2021/914 of 4 June 2021. These SCC are incorporated in the data processing agreements signed with each sub-processor.
In addition, supplementary technical measures are applied:
- PII scrubbing configuration in Sentry, no personally identifiable data in error logs transmitted outside the EU
- Minimisation of data transmitted to Resend (email address and transactional content only, no tax data)
- No booking, tax, or personnel data is transmitted to non-European sub-processors
7.4 UU PDP compliance for transfers outside Indonesia
In accordance with Article 56 of the UU PDP, transfers of personal data to foreign countries or territories are conditional on a level of protection equivalent to that guaranteed by the UU PDP. VillaTax ensures that:
- Transfers to the United States are governed by SCC and appropriate contractual guarantees
- No transfer to countries without adequate guarantees is made without the User's explicit consent
8. Your rights, GDPR & UU PDP
The rights described below apply to all VillaTax Users, regardless of their nationality or place of residence, on the basis of the GDPR (for EU residents) or the UU PDP (for Indonesian nationals), whichever framework affords the most protection in your situation.
8.1 Right of access (Art. 15 GDPR, Art. 6 UU PDP)
You may at any time request a complete copy of the personal data VillaTax holds about you, together with information on the purposes of processing, recipients, retention periods, and your rights. Most of your data is directly accessible and exportable from your dashboard without support intervention.
8.2 Right to rectification (Art. 16 GDPR, Art. 7 UU PDP)
You may correct any inaccurate or incomplete data directly from your Settings page. For data not accessible as self-service, contact commercial@operium.store. Rectification is processed within 30 days.
8.3 Right to data portability (Art. 20 GDPR, Art. 11 UU PDP)
VillaTax makes self-service export tools available in your dashboard:
- CSV export: Bookings, tax breakdowns, BPJS/PPh 21 payroll data, Banjar payments, property data
- ZIP export: Complete archive of all documents and generated reports (SPT declarations, PBJT reports, payslips)
These exports are available immediately, with no processing time and no support intervention required. You may also submit a formal portability request to commercial@operium.store if you require a specific format not available as self-service.
8.4 Right to erasure (Art. 17 GDPR, Art. 8 UU PDP)
You may request complete deletion of your account and all associated data. Upon receipt of a verified request at commercial@operium.store, VillaTax will proceed within 30 calendar days to permanently and irreversibly delete:
- All personal account information (email, name, hashed password)
- All associated property and booking data
- All personnel files and payroll calculations
- All uploaded documents and generated reports
- All Banjar payment records
- All identifiable activity logs
Mandatory legal exception: Tax data subject to a statutory retention obligation (DJP, BPJS data, 5 years pursuant to the UU KUP) cannot be deleted before the expiry of that period. This data will be irreversibly anonymised within 30 days of your request, so that it no longer enables your identification. A deletion/anonymisation confirmation will be sent to you by email.
8.5 Right to restriction of processing (Art. 18 GDPR, Art. 9 UU PDP)
You may request restriction of the processing of your data in the cases provided for by law: contestation of data accuracy, unlawful processing without a deletion request, retention required for litigation. During the restriction period, your data will no longer be actively processed (account placed on hold).
8.6 Right to object (Art. 21 GDPR, Art. 10 UU PDP)
You may object to any processing based on VillaTax's legitimate interest. In the event of an objection, VillaTax will cease that processing unless it can demonstrate compelling legitimate grounds overriding your rights, or if the processing is necessary for the establishment, exercise, or defence of legal claims. The right to object to processing for direct marketing purposes is absolute and without exception.
8.7 Right not to be subject to automated decision-making (Art. 22 GDPR, Art. 12 UU PDP)
VillaTax does not carry out any fully automated decision-making producing significant legal effects on the User. The Tax Engine's automated tax calculations are decision support tools, the final decision on filing always remains with the User or their konsultan pajak.
8.8 Procedure for exercising rights
To exercise any of these rights, send your request to commercial@operium.store from the email address associated with your VillaTax account. Include in your email: your full name, your account email address, the right you wish to exercise, and, where applicable, the data concerned.
Processing timescales:
| Step | Timescale |
|---|---|
| Acknowledgement of receipt | 72 hours |
| Identity verification | 5 business days |
| Full processing | 30 calendar days (extendable to 90 days in complex cases, with prior notification) |
| Execution confirmation | Within 5 days of execution |
The exercise of these rights is entirely free of charge.
9. Retention periods
| Data category | Duration | Legal basis for retention |
|---|---|---|
| Account data | Duration of subscription + 90 days | Contract performance |
| Booking and tax revenue data | 5 years | UU KUP (Art. 29), statutory DJP obligation |
| Exported SPT declarations | 5 years from declaration | UU KUP (Art. 29) |
| BPJS and payroll data | 5 years | UU BPJS (Law 24/2011) |
| Passport photographs | 24h post-checkout | Minimisation (Siskoharlat) |
| Xendit transaction logs (ID) | 3 years | Accounting (Law No. 8/1997) |
| Technical logs and Sentry errors | 90 rolling days | Legitimate security interest |
| Database backups | 14 days | Service continuity |
| JWT session tokens | Max 30 days (auto expiry) | Security |
| Email magic links | 7 days | Security |
10. Incident management, Breach notification
10.1 Internal procedure
In the event of a detected personal data breach, VillaTax immediately activates its Incident Response Plan (IRP), which provides for:
- Isolation and containment of the breach within one hour of detection
- Assessment of the nature, scope, and risks of the breach within 24 hours
- Full documentation of the incident (nature of data, number of persons affected, probable consequences, measures taken)
- Notification to authorities and persons concerned within statutory timescales
10.2 Notification to supervisory authorities
Under the GDPR (Art. 33): In the event of a breach likely to give rise to a risk to the rights and freedoms of the persons concerned, VillaTax will notify the competent supervisory authority within 72 hours of becoming aware of the incident. The notification will include: the nature of the breach, the categories and approximate number of persons concerned, and the measures taken or envisaged.
Under the UU PDP (Art. 46): Indonesian law requires immediate (segera) notification to Komdigi (Kementerian Komunikasi dan Digital) in the event of a failure of personal data protection (kegagalan pelindungan data pribadi). VillaTax will fulfil this obligation by notifying Komdigi within a maximum of 14 calendar days, in accordance with the regulatory clarifications of the UU PDP.
10.3 Notification to persons concerned
Under the GDPR (Art. 34): If the breach is likely to give rise to a high risk to the rights and freedoms of the persons concerned, VillaTax will inform affected Users without undue delay, in clear and plain terms: the nature of the breach, contact details, likely consequences, and measures taken.
Under the UU PDP (Art. 46): VillaTax will inform the persons concerned within 14 days of becoming aware of the breach, in accordance with UU PDP requirements.
11. Sub-processors
| Sub-processor | Role | Location | Guarantees | DPA |
|---|---|---|---|---|
| Hosting provider | Hosting and storage | Indonesia | Contractual security and confidentiality obligations | Data Processing Agreement |
| PT Xendit Pembayaran Indonesia | Payment processing | Indonesia | PCI DSS Level 1 | Xendit partner agreement |
| Resend Inc. | Transactional emails | USA | Standard Contractual Clauses | DPA available on request |
| Sentry | Error / performance monitoring | USA | SCC + PII scrubbing configured | DPA available on request |
Each sub-processor is bound to PT Asiah Legal Jaya by a Data Processing Agreement (DPA or Perjanjian Pemrosesan Data) imposing contractual obligations of security, confidentiality, and regulatory compliance. PT Asiah Legal Jaya carries out an annual review of its sub-processors' compliance.
12. Updates to this page
This GDPR & UU PDP Compliance page is reviewed quarterly or whenever a significant legislative or regulatory change requires it. Any material change affecting your rights or the terms of processing is communicated by email to all registered users at least 14 calendar days before taking effect.
The "Last updated" date at the top of this page indicates the date of the most recent revision. Previous versions are available on request at commercial@operium.store.
13. Competent supervisory authorities
You have the right to lodge a complaint with the data protection authority competent in your jurisdiction of residence:
| Jurisdiction | Authority | Contact |
|---|---|---|
| France | CNIL, Commission Nationale de l'Informatique et des Libertés | cnil.fr |
| Germany | BfDI, Bundesbeauftragter für den Datenschutz | bfdi.bund.de |
| Netherlands | AP, Autoriteit Persoonsgegevens | autoriteitpersoonsgegevens.nl |
| Australia | OAIC, Office of the Australian Information Commissioner | oaic.gov.au |
| Indonesia | Komdigi, Kementerian Komunikasi dan Digital | komdigi.go.id |
| European Union (ODR) | ODR Platform, Online Dispute Resolution | ec.europa.eu/consumers/odr |
VillaTax (PT Asiah Legal Jaya) villa-tax.operium.store, May 2026
This document is governed by the law of the Republic of Indonesia and by Regulation (EU) 2016/679 for aspects falling within the GDPR. In the event of any discrepancy between a translation and the French version, the French version shall prevail.