This Data Processing Addendum ("Addendum") supplements the BounceZero Data Processing Agreement ("Master DPA") and applies where the customer ("Controller", "you") submits for verification email addresses relating to data subjects in Indonesia. It sets out how BounceZero Ltd ("Processor", "we", "us") complies with Law No. 27 of 2022 on Personal Data Protection ("PDP Law") when acting as a personal data processor on your behalf. In the event of any conflict, the more protective obligation prevails.
1. Introduction
This Addendum forms part of the Master DPA. The terms defined in the Master DPA apply to this Addendum unless stated otherwise. Under the PDP Law, "controller" (pengendali) means you, and "processor" (prosesor) means BounceZero (PDP Law Art. 1(3), 1(4)).
We process personal data on EU infrastructure (OVH, France). BounceZero does not maintain an establishment in Indonesia; this Addendum governs our processing of personal data of Indonesian data subjects on your behalf.
2. Governing Law and Regulator
The processing described in this Addendum is governed, so far as the data subjects are in Indonesia, by the PDP Law, enacted on 17 October 2022 and in force since 17 October 2024, together with implementing regulations of the minister responsible for personal data protection. Sanctions for non-compliance include administrative sanctions and, for corporate controllers or processors, fines of up to 2% of annual revenue (PDP Law Art. 57).
3. Role and Scope
For the email verification services described in the Master DPA, you act as the controller and we act as the processor (prosesor) under PDP Law Art. 1(4). The subject matter, nature, and purpose of the processing are the same as set out in Section 2 of the Master DPA: syntactic validation, DNS/MX lookup, SMTP probing, catch-all detection, deliverability scoring, and fraud/abuse checks of the email addresses you submit.
We process personal data only on your documented instructions and never for our own benefit, except where applicable law requires otherwise (PDP Law Art. 17).
4. Data Subject Rights
We will assist you in responding to requests from data subjects exercising their rights under the PDP Law (Arts. 5-13), including:
- To be informed of the identity of the controller and the purpose of processing.
- To access a copy of their personal data and information about the processing.
- To request the correction or completion of inaccurate personal data.
- To request deletion or destruction of personal data.
- To request that processing be suspended or restricted.
- To withdraw consent, object to profiling, and, on your instruction, to data portability.
If a data subject contacts us directly, we will forward the request to you without undue delay and comply with your reasonable instructions. You are responsible for the legal basis of the processing, including consent or another basis available under PDP Law Arts. 15-16.
5. Breach Notification
We will notify you of any personal data breach affecting the personal data you submitted, without undue delay and in any event within 72 hours (3 × 24 hours) of becoming aware of it, consistent with the Master DPA and the PDP Law notification window (Art. 46). You, as the controller, are responsible for notifying the data subjects and the relevant authority in the form and manner required by the PDP Law and its implementing regulations. We will provide the information needed to support your notification.
6. Cross-Border Transfers
Personal data of Indonesian data subjects is processed on EU infrastructure. The PDP Law (Arts. 55-56) permits cross-border transfers where the destination country or international organisation provides an adequate level of protection equivalent to Indonesian law, or pursuant to an international agreement, in accordance with conditions set by the minister. To the extent any transfer relies on contractual safeguards, we rely on the Standard Contractual Clauses set out in the Master DPA. A copy is available on request at [email protected].
7. Additional Obligations
- Data protection impact assessment: where the PDP Law requires an impact assessment for high-risk processing (Art. 37), we will provide the information about our processing reasonably needed for you to complete it.
- Data protection officer: we maintain a point of contact able to support the appointment and functioning of a data protection officer where the PDP Law requires one (Art. 54).
- Consent records: we retain the evidence of lawful processing instructions that you rely on as your legal basis, for accountability purposes.
- Data minimisation: only the email addresses and derived metadata necessary for validation are processed (PDP Law Art. 16).
- Audit: we will co-operate with reasonable audits conducted by you or your authorised auditor, on reasonable prior written notice.
8. Contact
For enquiries about this Addendum or to exercise rights in respect of the processing described here, contact our Data Protection contact:
BounceZero Ltd66 Paul Street, London, EC2A 4NA, United Kingdom
Email: [email protected]
You may also refer to the Master DPA and its terms on sub-processors, security measures, retention, and liability at bouncezero.io/dpa.