Data Processing Agreement
Last updated: September 30, 2026
How Firma processes the personal data of your customers and team on your behalf: roles, instructions, security, subprocessors and incident notice.
1. Parties and roles
This agreement applies between you as the data controller and Firma as the data processor, for personal data you put into or connect to Firma. It supplements the Terms of Service.
2. Scope of processing
Firma processes data such as names, contact details, message content and order history of your customers and team members, only for as long and as far as needed to run the service.
3. Instructions and confidentiality
- Firma processes data only on your documented instructions, including the settings, approvals and tasks you give in the app.
- Everyone authorised to process the data is bound by confidentiality.
4. Security measures
- Encryption in transit (TLS) and encryption of provider keys at rest.
- Data separated per company; access across companies is refused.
- Role-based access control, two-step verification and re-verification for sensitive actions.
- An audit log that cannot be edited, for activity and outside actions.
5. Subprocessors
You approve the subprocessors listed in the Privacy Policy. Firma gives at least 30 days' notice before adding or replacing one, and you may object on reasonable grounds.
6. Assistance and incidents
Firma helps you respond to requests from data subjects and assess data protection impact. If a personal data breach happens, Firma tells you without undue delay and no later than 72 hours after becoming aware of it.
7. End of service and audits
When the service ends you can export your data, after which Firma deletes it as the Privacy Policy describes. On written request, Firma provides reasonable information to show compliance with this agreement.
Data may be processed outside Indonesia by the listed subprocessors, with equivalent protection as the applicable law requires.