Skip to main content
Epruvo
Home Features Pricing FAQ About
Bahasa Indonesia✓ English✓
Log in Start Free ↗

Epruvo Privacy Policy

An explanation of how Personal Data is processed when you visit the website, use the application, receive an access link, or interact with Epruvo services.

Updated July 31, 2026

PT Idemas Solusindo Sentosa, hereinafter referred to as “Idemas” or “we”, respects privacy and is committed to processing Personal Data responsibly.

This Privacy Policy explains how Personal Data is processed when you visit the Epruvo website, request a demo, create or use an account, use the Epruvo application, receive an invitation or access link, approve or sign a document, contact support, or otherwise interact with Epruvo services.

Epruvo is a software-as-a-service (SaaS) offering that helps organizations create forms, run approval workflows, manage documents, request signatures, record action history, and collaborate with internal and external parties.

This Policy is a notice concerning the processing of Personal Data. It is not blanket consent for all processing activities. Where an activity requires specific consent, that consent will be requested separately according to the context and applicable law.

Key summary

  • Idemas’s role depends on the context. Idemas generally acts as a Personal Data Controller for the website, accounts, commercial relationships, support, security, and service operations that we determine. For documents and workflows whose primary purposes are determined by the Customer organization, Idemas generally acts as a Personal Data Processor.
  • The Customer determines the documents, recipients, workflow participants, purposes of use, access rights, and data entered into Epruvo. The Customer is responsible for ensuring that the processing has a lawful basis.
  • We do not sell Personal Data. We also do not use Customer Content for targeted advertising or to train general-purpose generative AI models without specific written authorization and an appropriate legal basis.
  • Certain features may use unique links or QR codes that provide access without a full login. These links must be treated as access credentials and must not be forwarded to unauthorized parties.
  • Visual signature features on documents are not used for official identity verification or biometric matching by default.
  • Privacy requests may be sent to [email protected] with the subject “Epruvo Privacy Request”. For data controlled by a Customer, we may direct the request to the organization that manages the data.

1. Operator identity

Epruvo is developed and operated by:

PT Idemas Solusindo Sentosa
Level 23, Penthouse Plaza Marein
Jl. Jend. Sudirman Kav. 76–78
Jakarta 12910, Indonesia
Email: [email protected]
Telephone: (021) 3440-592 / (021) 2120-2041

2. Scope

This Policy applies to the processing of Personal Data through:

  1. the Epruvo website and landing pages;
  2. the Epruvo web application;
  3. the Epruvo mobile application, if available;
  4. emails, notifications, and links sent through Epruvo;
  5. external access pages and document verification pages;
  6. demo, onboarding, support, billing, complaint, and business communication processes relating to Epruvo.

This Policy does not govern third-party websites, applications, or services that have their own privacy policies, including identity providers, payment providers, or integrations selected by the Customer. Use of third-party services is subject to the relevant provider’s policies.

Customer organizations may also have privacy notices, internal policies, or other terms that apply to Users and their organizational data.

3. Key terms

In this Policy:

  • Customer means a company, organization, or party officially granted access to use Epruvo, including through a paid plan, trial, or free service.
  • User means a person who uses Epruvo through an account or Customer invitation.
  • Customer Administrator means a User authorized by the Customer to manage accounts, members, roles, permissions, workflows, or organizational configurations.
  • External Party means a person who receives a request for approval, signature, review, or document access without being required to hold a full Epruvo account.
  • Customer Content means data, documents, attachments, custom fields, comments, visual signatures, recipient lists, workflow configurations, and other information submitted, created, or managed by or for a Customer in Epruvo.
  • Personal Data, Specific Personal Data, Personal Data Controller, Personal Data Processor, and Personal Data Subject have the meanings assigned to them under applicable laws and regulations.

4. Roles of Idemas and the Customer

The parties’ roles are determined by the purpose of, and control over, each processing activity.

4.1 Idemas as a Personal Data Controller

Idemas generally acts as a Personal Data Controller for activities such as:

  • website visits, demo requests, and direct communications with Idemas;
  • account registration and administration;
  • management of commercial relationships, plans, invoices, and billing;
  • support, complaints, and service communications;
  • platform security, authentication, abuse prevention, logging, and incident investigation;
  • operation, maintenance, measurement, and improvement of Epruvo’s reliability;
  • product or marketing communications based on an appropriate processing basis;
  • compliance with legal obligations and protection of the rights of Idemas or other parties.

4.2 Idemas as a Personal Data Processor

For Customer Content and workflows whose primary purposes are determined by the Customer, the Customer generally acts as the Personal Data Controller and Idemas acts as the Personal Data Processor.

In that context, Idemas processes data to provide, secure, maintain, and support Epruvo based on Customer instructions reflected in feature use, configurations, an Order Form, a Data Processing Agreement (DPA), or other agreed written instructions.

The Customer is responsible for:

  • having the required processing basis, permissions, and authority;
  • providing notices to Personal Data Subjects where required;
  • determining who receives or may access the data;
  • ensuring that data entered is relevant, accurate, and not excessive;
  • assessing whether Epruvo is appropriate for the Customer’s data categories, document types, and sector-specific obligations;
  • handling requests concerning Personal Data Subject rights as Controller, with assistance from Idemas in accordance with the agreement and applicable law.

If your request concerns Customer Content, we may ask you to contact the organization that invited you or manages the relevant data.

5. Data that may be processed

The data processed depends on the features used, the Customer’s configuration, and the information provided by the Customer, User, or External Party.

5.1 Identity, account, and organization data

This data may include:

  • name, email address, telephone number, and contact information;
  • company or organization name, department, title, function, role, and permissions;
  • account information, activation status, memberships, invitations, and preferences;
  • profile photo, avatar, company logo, language, country, and time zone;
  • authentication credentials in secured form, session information, and Single Sign-On information where used.

5.2 Workflow and document content

This data may include:

  • document titles, numbers, categories, descriptions, custom fields, and metadata;
  • documents, PDFs, attachments, images, or other files;
  • the identities of requesters, approvers, signers, delegates, reviewers, and external recipients;
  • comments, notes, and reasons for approval, rejection, cancellation, or revision;
  • the status, sequence, and time of actions in a workflow;
  • activity history and audit trails;
  • visual signatures, signature positions in documents, and final documents;
  • other data entered by the Customer through forms or attachments.

Epruvo does not use visual signatures for biometric matching or official identity verification by default.

5.3 External Party data

To send and manage external invitations, we may process:

  • the recipient’s name and email address;
  • organization or title, if provided;
  • documents and actions intended for the recipient;
  • invitation status and actions performed;
  • time, IP address, user agent, and relevant security records;
  • acceptance of terms displayed before an action, where implemented.

5.4 Technical, security, and usage data

We may process:

  • IP address, user agent, device type, operating system, browser, and language;
  • login times, session activity, errors, and diagnostic logs;
  • security activity, login attempts, account changes, and administrative actions;
  • feature usage, performance, and service capacity information;
  • device identifiers and push notification information where those features are used.

5.5 Communications and commercial data

This data may include:

  • demo requests, inquiries, complaints, support tickets, and correspondence;
  • company name, business requirements, and the contact information of the person in charge;
  • plan, subscription period, invoice, payment status, and tax information;
  • limited payment information received from a payment provider if online payment is available. Idemas need not store complete payment card data where it is processed directly by the payment provider.

5.6 Cookies and similar technologies

The website or application may use cookies, local storage, and similar technologies to:

  • maintain sessions and preferences;
  • provide security functions;
  • measure performance and usage;
  • support analytics or marketing communications where enabled and supported by an appropriate basis.

6. Data sources

We may obtain Personal Data from:

  • you directly;
  • the Customer or Customer Administrator;
  • another User who adds you as a workflow participant or recipient;
  • an identity provider or SSO service you use;
  • a payment provider or implementation partner;
  • your device, browser, and interactions with Epruvo;
  • public sources or legitimate business partners for business communications, to the extent permitted by law.

If a Customer enters another person’s Personal Data, the Customer is responsible for ensuring that the collection and disclosure are lawful.

7. Purposes and bases of processing

We may process Personal Data to:

  • provide accounts, workflows, approvals, signatures, final documents, notifications, and other service functions;
  • authenticate users, manage sessions, and protect accounts and the platform;
  • send invitations, reminders, status notices, and service communications;
  • provide demos, onboarding, support, maintenance, and troubleshooting;
  • manage plans, billing, payments, taxes, and contract administration;
  • detect, prevent, and investigate fraud, abuse, or security incidents;
  • measure performance, usage, and capacity, and improve Epruvo;
  • comply with legal obligations and lawful authority requests, and protect or defend legal rights;
  • send product or marketing communications where a lawful basis and an option to opt out are available.

The basis for processing may be:

  • consent;
  • performance of, or steps preparatory to, an agreement;
  • compliance with a legal obligation;
  • protection of vital interests;
  • performance of a task in the public interest or exercise of authority under regulations, where relevant;
  • the legitimate interests of Idemas or another party that have been proportionately assessed and do not override the rights of the Personal Data Subject;
  • Customer instructions where Idemas acts as a Personal Data Processor.

Where processing is based on consent, consent may be withdrawn for future processing. Withdrawal does not affect processing already carried out lawfully or processing that remains necessary under another legal basis.

8. Access through unique links and verification pages

Certain features may use unique links or QR codes to provide recipient access, display document information, or enable specific actions without a full login.

These links must be treated as access credentials. While a link remains active, anyone holding it may gain access to the associated information or action. Customers and Users are responsible for:

  • ensuring that the recipient address is correct;
  • not forwarding, publishing, or sharing the link with unauthorized parties;
  • securing the email account, device, and account that receive the link;
  • assessing whether this access method is appropriate for the document’s sensitivity;
  • promptly contacting the Customer Administrator or Idemas if a link is misdirected or suspected of misuse.

Epruvo may apply validity periods, access restrictions, additional verification, or other controls according to the feature, configuration, and development of the service. Unless additional verification is expressly stated, possession of a link does not itself constitute official identity verification.

A QR code or verification page may display information recorded in Epruvo. The feature does not automatically constitute a certificate of authenticity, notarial validation, or cryptographic proof that a file has never changed, unless that capability is expressly stated in the service or a separate agreement.

9. Disclosure of Personal Data

We may disclose Personal Data to the following recipients, and only to the extent necessary:

9.1 Customers and authorized Users

Administrators and workflow participants may access data according to their relationship with the document, role, permissions, and Customer configuration.

9.2 External Parties

Relevant data may be sent or displayed to recipients selected by the Customer for approval, signing, review, verification, or another action.

9.3 Service providers

We may use providers for functions such as:

  • hosting, servers, databases, storage, backups, and monitoring;
  • email, notifications, and push notifications;
  • authentication and Single Sign-On;
  • support, error tracking, analytics, and security;
  • payment and billing, where available;
  • professional consulting subject to confidentiality obligations.

These providers are permitted to process data only for the assigned functions and are subject to appropriate data protection obligations. Where Idemas acts as a Processor, the use of subprocessors is governed by a DPA, Order Form, or another applicable written mechanism.

9.4 Authorities and legal process

We may disclose data where required by law, court order, or a lawful request from an authority, or to the extent necessary to protect the rights, safety, and integrity of Idemas, Customers, Users, or other parties.

9.5 Corporate transactions

In a merger, acquisition, restructuring, financing, or business transfer, data may be transferred as part of the transaction with the safeguards and notices required by law.

We do not sell Personal Data to third parties. We also do not allow service providers to use Customer Content for their own advertising.

10. Transfers of data outside Indonesia

Certain technology providers or integrations may process data outside Indonesia.

Where a cross-border transfer occurs, Idemas will apply the basis, assessment, and safeguards required by applicable law. These safeguards may include an equivalent or higher level of protection, binding contractual protections, technical and organizational measures, consent where required, or another lawful mechanism.

Where Idemas acts as a Processor, transfers are made based on Customer instructions or authorization and the terms of the applicable DPA, Order Form, or agreement.

Further information about material subprocessors and processing locations may be provided to Customers through a DPA, Order Form, or an information channel made available by Epruvo.

11. Retention, deletion, and destruction

Idemas retains Personal Data for as long as necessary to:

  • provide Epruvo and maintain active accounts;
  • manage the relationship with the Customer;
  • carry out Customer instructions;
  • maintain security, workflow integrity, and audit trails;
  • comply with legal, tax, accounting, and dispute-resolution obligations;
  • protect or defend legal rights.

Customer Content is retained for the duration of the service relationship and is deleted or returned according to configuration, Customer instructions, the Order Form, the DPA if any, and applicable law.

After the purpose of processing ends, data will be deleted, destroyed, anonymized, or restricted in accordance with retention policies, lawful instructions, and applicable law. Certain copies may remain in backups until deleted through the normal backup cycle. Backup data is not used for ordinary operational activities unless needed for recovery, security, incident investigation, or legal compliance.

Data may be retained for a longer period where:

  • required by law;
  • needed for a legal hold, dispute, investigation, or enforcement of rights;
  • deletion is postponed under lawful Customer instructions;
  • the data has been anonymized so that it no longer reasonably identifies an individual.

More specific schedules may be set out in a DPA, Order Form, service configuration, or Customer retention policy.

12. Security and incidents

Idemas applies reasonable and proportionate technical and organizational measures based on the nature of the data, the context of processing, and the associated risks. These measures may include access management, authentication, activity logging, infrastructure safeguards, monitoring, operational backups, vendor management, and incident response procedures.

No electronic system is entirely free from risk. Users are also responsible for protecting their accounts, passwords, devices, email addresses, one-time passwords, sessions, and access links.

If an incident meets the notification criteria under applicable law, Idemas will respond and notify the parties required by law within the period and with the contents prescribed by applicable law.

If you discover a suspected vulnerability or security incident, do not exploit it. Report it to [email protected] with the subject “Epruvo Security Report”, and do not send passwords, one-time passwords, or active links through ordinary email.

13. Rights of Personal Data Subjects

Subject to applicable law and permitted exceptions, you may have the right to:

  • obtain information about the processing of Personal Data;
  • access and obtain a copy of Personal Data;
  • complete, update, or correct Personal Data;
  • terminate processing or request the deletion or destruction of Personal Data;
  • withdraw consent;
  • object to or request restriction of processing;
  • obtain or transfer Personal Data in an available, machine-readable format, where applicable;
  • submit a complaint or claim in accordance with law.

To exercise these rights, send a request to [email protected] with the subject “Epruvo Privacy Request”. We may request reasonable information to verify your identity, authority, and the scope of the request.

If the data is controlled by a Customer, we may forward or direct the request to that Customer. Idemas will provide assistance in accordance with its role, the agreement, and applicable law.

A request may be refused or restricted where permitted by law, for example if identity cannot be verified, the request infringes another party’s rights, the data must be retained to meet a legal obligation, or the request is unlawful or excessive. Reasons will be provided where required.

14. Communications, cookies, and user choices

Transactional communications such as activation messages, one-time passwords, invitations, workflow reminders, security notices, billing communications, and important service changes may continue to be sent for as long as necessary to provide Epruvo.

Marketing communications are sent only on an appropriate basis. You may opt out of marketing communications through an unsubscribe link or by contacting us. Opting out of marketing does not stop necessary service communications.

Cookie settings may be available through your browser, device, or the consent mechanism used on the website. Disabling certain cookies may affect Epruvo’s functionality.

15. Automated processing and AI

Epruvo may apply automated workflow rules, such as determining an approval sequence, sending reminders, or changing status based on User actions. These functions follow the Customer’s configuration and are not intended to independently make legal or similarly significant decisions about an individual.

Idemas does not use Customer Content to train general-purpose generative AI models owned by Idemas or third parties. If AI features are added, the use of data, providers, user choices, and additional terms will be communicated as appropriate.

16. Children

Epruvo is intended for organizational use and not for children to create accounts directly.

A Customer must not knowingly create an account for a person under 18 without the basis, authority, and safeguards required by law. If Customer documents contain children’s data, the Customer is responsible for ensuring that the processing is lawful and for applying appropriate additional safeguards.

If we become aware that children’s data is being processed improperly, we may restrict access, request clarification, or take another action in accordance with law and the agreement.

17. Changes to this Policy

We may update this Policy due to changes in the service, processing practices, security, or law.

The version and effective date will be updated. Material changes will be notified by email, through the application or website, or through another reasonable channel. New consent will be requested where required by law.

Previous versions may be retained for audit purposes and as evidence of acceptance.

18. Relationship with Customer agreements

This Policy applies together with the Epruvo Terms and Conditions, an Order Form, DPA, Enterprise Agreement, or another applicable written agreement.

If there is a discrepancy concerning the processing of Customer Content, the more specific terms in a DPA or written agreement signed by the parties will prevail to the extent they govern the same matter.

19. Complaints and contact

Privacy inquiries, requests, or complaints may be sent to:

PT Idemas Solusindo Sentosa
Level 23, Penthouse Plaza Marein
Jl. Jend. Sudirman Kav. 76–78
Jakarta 12910, Indonesia
Email: [email protected]
Telephone: (021) 3440-592 / (021) 2120-2041

Use the email subject “Epruvo Privacy Request” and include enough information for us to understand and handle the request. Do not send passwords, one-time passwords, or active access links through ordinary email.

Epruvo

Approval workflows and document signing for more structured business processes.

PT Idemas Solusindo SentosaLevel 23, Plaza MareinJl. Jend. Sudirman Kav. 76–78Jakarta 12910, Indonesia

Product

FeaturesPricingFAQLog in

Company

AboutIdemas ↗Contact

Legal

Privacy PolicyTerms & Conditions

Contact

[email protected]idemas.id ↗
© 2026 PT Idemas Solusindo Sentosa. All rights reserved.Back to top ↑

WhatsApp us