This website uses cookies and other tracking technologies, which improve your web experience, analyze site usage, and deliver personalized content to you. Some are essential to the functionality of our site, while others are optional and used only with your consent. Cookies and other tracking technologies may be stored on your device and placed by us and trusted partners. Please visit our Cookie Consent Manager for information on how this website uses cookies and other tracking technologies and to change your settings at any time. For more information please also visit our Cookie Policy. By continuing to use this website, you agree to the use of cookies and other tracking technologies as described in this notice.
Accept

Privacy policy

1. Our Commitment
PT Digital Karyaloka Nusantara (“DIKA”, “we”, “us”) is a Payment Service Provider (PJP) licensed by Bank Indonesia. As a Data Controller, we process your Personal Data to deliver payment and payment gateway services in accordance with Law No. 27 of 2022 on Personal Data Protection (the “PDP Law”) and its implementing regulations, Bank Indonesia’s Payment System rules, and Anti-Money Laundering and Counter-Terrorism Financing (“AML-CTF”) requirements. This Policy evolves with the PDP Law and its implementing regulations, guidance from Bank Indonesia and the Personal Data Protection Authority, judicial or administrative rulings,
2. Definitions
  1. Personal Data means data about an identified or identifiable natural person, alone or combined with other information.
  2. Specific Personal Data includes health, biometric, genetic, criminal-record, children’s, and financial data.
  3. Processing means any operation on Personal Data, from collection, analysis, and storage to transfer, disclosure, deletion, or destruction.
  4. Data Subject means the individual to whom Personal Data relates.
  5. Controller / Processor means, respectively, the party determining the purposes of Processing (DIKA), and a party Processing on the Controller’s behalf under a valid agreement.
  6. Merchant means a party using our services to accept payment for goods and/or services
3. Scope and Sources
This Policy covers Personal Data collected via our websites, apps, APIs, plugins, merchant portals, service points, and communication channels. We obtain data: (a) directly from you—on registration, KYC/KYB, transactions, support contact, or when you consent to specific uses; (b) automatically—IP address, device and browser type, activity logs, and Cookies; and (c) from third parties—group companies, Merchants, partner banks, payment operators, and verification or screening providers. Where data is obtained indirectly, we notify you within the period required by law unless an exemption applies.
4. Categories of Personal Data
  1. Identity & profile: name, title, place/date of birth, gender, nationality; ID numbers (KTP, passport, NPWP); signature, photo, voice/video records; account credentials and history.
  2. Contact: residential, work, or mailing address; phone; email.
  3. Financial & transaction: bank account and e-wallet IDs; tokenized card data; transaction history, amounts, timestamps, settlement status; Merchant, invoice, refund, and chargeback details.
  4. KYC/KYB & AML-CTF: customer and beneficial-owner documents; source of funds/wealth; risk profiles and sanctions/DTTOT screening; transaction-monitoring and suspicious-transaction records.
5. Lawful Bases for Processing
Under Article 20 of the PDP Law, we rely on one or more of: your consent; performance of a contract; compliance with legal obligations (Payment System rules, AML-CTF, taxation, regulatory reporting); protection of vital interests; performance of a public-interest task; and other legitimate interests such as fraud prevention, security, and audit—balanced against your rights. You may withdraw consent at any time without affecting prior processing.
6. Purposes of Use
We process Personal Data only as necessary to: verify accounts and conduct KYC/KYB; process, clear, and settle transactions; secure the service through fraud detection, monitoring, and dispute resolution; meet legal and regulatory obligations including reporting to Bank Indonesia and the PPATK; provide customer support; maintain system integrity, audit, and risk management; improve and personalize the service; and—subject to consent where required—conduct relevant marketing.
7. Cookies
We use Cookies to enable, secure, optimize, and analyze the service. Essential Cookies (e.g., login, session, security) are required for core functionality; disabling them may break features. Non-essential Cookies are set only with your consent. You can manage Cookies via your browser. See our separate Cookie Policy for details.
8. Disclosure and Sharing
We disclose Personal Data only as necessary and lawful, to: group companies; partners and service providers (banks, switching operators, principals, acquirers, verification, fraud, IT, and cloud providers, payment aggregators); Merchants and commercial partners; banks involved in settlement or verification; and authorities as required by law, including Bank Indonesia, the PPATK, OJK, the Directorate General of Taxes, the Personal Data Protection Authority, law enforcement, and courts, plus auditors and professional advisors. We do not sell your Personal Data.
9. Cross-Border Transfer
We may transfer Personal Data to affiliates or providers outside Indonesia (e.g., cloud or processing providers). Before doing so, we ensure the destination country offers protection at least equivalent to the PDP Law; failing that, we put in place adequate and binding safeguards and/or obtain your consent, consistent with the PDP Law and Payment System data provisions.
10. Retention
We retain Personal Data while your account is active and as required by law—Payment System rules, AML-CTF, corporate and tax obligations. Absent a specific requirement, we retain data only as long as reasonably necessary, then delete, destroy, or anonymize it, unless further retention is legally required or needed for dispute resolution.
11. Security
We apply appropriate safeguards against loss, unauthorized access, misuse, alteration, and disclosure:
  1. Administrative policies, procedures, and internal controls.
  2. Technical encryption, firewalls, tokenization, and intrusion detection.
  3. Physical access controls over systems and devices, restricted to authorized personnel, with audit logging of access, changes, deletion, and transfers.
Processors acting on our behalf must maintain confidentiality and adequate controls and may not use data beyond their engagement. In the event of a data breach, we notify affected Data Subjects and the Personal Data Protection Authority within the period and manner required by law.
12. Your Rights as a Data Subject
Under the PDP Law you may: obtain information about the processing; access and obtain a copy of your data; correct or update it; end processing, delete, or destroy it; withdraw consent; object to solely automated decisions, including profiling; restrict or postpone processing; obtain your data in a portable, machine-readable format; and sue and receive compensation for violations. We may decline requests unrelated to your own data or prohibited by law, law-enforcement interests, or financial-sector supervision. Rights are exercised after identity verification.
13. Age Restriction
Our services are intended for individuals aged 18 or older, or otherwise legally competent. We do not knowingly collect data from ineligible individuals; where children’s data is processed, we do so with parental/guardian consent as required. We promptly delete data collected inadvertently from ineligible individuals.
14. Third-Party Data
If you provide another person’s Personal Data, you warrant you are authorized and have obtained the necessary consent, and you are responsible for its accuracy. This Policy does not cover third-party services; please review their privacy policies.
15. Limitation of Liability
To the extent permitted by law, DIKA is not liable for loss arising from: data intercepted, accessed, or altered by unauthorized third parties beyond our reasonable control or through your fault; your failure to safeguard your data, credentials, or OTPs; your own negligence; or your use of media, networks, or cloud storage to handle data. This does not reduce DIKA’s obligations under the PDP Law and other applicable laws.
16. Governing Law and Disputes
This Policy is governed by the laws of the Republic of Indonesia. Disputes are first resolved amicably; failing that, through mechanisms available under applicable law.
17. Language
This Policy may be issued in several languages. In case of discrepancy, the Indonesian text prevails.
18. Contact
All notices may be delivered via our website, email, or SMS. For questions, complaints, or to exercise your rights, contact our Data Protection Officer:
PT Digital Karyaloka Nusantara
Address: The Plaza Office Tower, Jl. MH Thamrin, Gondangdia, Menteng, Jakarta Pusat
Email: info@dika.co.id
Business Hours: Monday–Friday, 09.00–17.00 WIB
19. Changes
We may amend this Policy from time to time, with changes communicated via our website and/or other channels. You are responsible for reviewing it periodically
©dika.co.id 2026. All rights reserved.
WhatsApp: +6285199110998
The Plaza Office Tower, Lantai 38 
Jl. M.H. Thamrin Kav. 28 – 30,
JAKARTA PUSAT, Indonesia.