Bronyx Privacy Notice

Version 1.0Effective Date: To be Continued

1. Introduction

PT ITSEC Asia Tbk ("ITSEC Asia," "we," "us," or "our") operates the Bronyx autonomous AI penetration testing platform and website at bronyx.ai ("Bronyx," this "Website"). This Privacy Notice explains what personal data we collect through this Website and our Demo Request process, why we collect it, how we use and share it, and the rights available to you under Law No. 27 of 2022 on Personal Data Protection ("UU PDP").

This Notice applies to visitors to the Bronyx website and to individuals who submit a Demo Request. It does not govern personal data or client environment data processed once you become a Bronyx client and undergo an actual security testing engagement (e.g., scan targets, vulnerability findings, or systems data), that processing is governed separately by the signed Rules of Engagement and service agreement with ITSEC Asia, consistent with ITSEC Asia's internal Global Privacy Policy.

2. Data We Collect

When you submit a Demo Request on this Website, we collect the following:

  • First Name and Last Name
  • Work Email Address
  • Company Name
  • Role
  • Service Plan of interest
  • What You Are Looking to Achieve — optional free-text field

We also automatically collect limited technical data as you browse this Website, such as IP address, browser and device type, pages visited, and referring URL through cookies and similar technologies (see Section 8, Cookies). If you opt in to marketing communications, we additionally record your consent status and communication preferences.

3. Purpose of Processing

We use this data to:

  • Schedule and deliver the product demonstration you requested;
  • Evaluate which Bronyx service plan may suit your needs;
  • Respond to your inquiry and follow up as part of the sales process;
  • Where you have separately consented, send you marketing communications about Bronyx and related ITSEC Asia products (see Section 5);
  • Maintain and improve the security and functionality of this Website; and
  • Comply with applicable legal and regulatory obligations.

4. Legal Basis

We rely on the following legal bases under Article 20(2) of the UU PDP:

  • Pre-contractual steps at your request (Article 20(2)(b)): processing your Demo Request details to schedule and conduct the demo is necessary to take steps you requested before any potential service arrangement.
  • Consent (Article 20(2)(a)): sending marketing communications is based on your separate, freely given, opt-in consent, which you may withdraw at any time (see Section 5).
  • Legitimate interest (Article 20(2)(f)): maintaining basic website security, fraud prevention, and aggregate, non-identifying analytics.

5. Marketing Communications Consent

If you tick the marketing communications checkbox on the Demo Request form, you agree to receive emails from ITSEC Asia about Bronyx product updates, related IntelliBroń / ITSEC Asia offerings, security research, and event invitations.

This consent is optional and separate from your Demo Request, leaving it unchecked will not affect your ability to receive your requested demo or any related follow-up needed to deliver it. You may withdraw this consent at any time by replying to any marketing email indicating you wish to opt out, or by contacting our Data Protection Officer (Section 12). Withdrawal does not affect the lawfulness of communications sent before withdrawal.

6. Data Sharing and Processors

We do not use a dedicated external CRM or marketing-automation platform. Demo Request submissions are currently recorded in a Google Sheet maintained under ITSEC Asia's company Google Workspace account, accessible only to ITSEC Asia and Bronyx personnel involved in the sales and product evaluation process, on a need-to-know basis.

We share Demo Request data only with:

  • ITSEC Asia personnel involved in the Bronyx sales and product evaluation process, on a need-to-know basis;
  • Google, as the provider of the Google Workspace account used to store Demo Request submissions, acting as our data processor under Google's Workspace terms; and
  • A third-party email delivery/relay service provider used to send demo-confirmation emails and, where you have separately consented, marketing communications. This provider processes limited data (your name and email address) strictly to deliver these communications, acting as our data processor under contractual confidentiality and data protection obligations.

We do not sell your personal data, and we do not share it with any other third party for their own marketing purposes.

7. Cross-Border Data Transfer

Demo Request data is stored using ITSEC Asia's company Google Workspace account, provided by Google. Google's Workspace infrastructure is global: unless a specific data region has been configured for our account, your data is likely processed in the Asia region, and may also involve the European Union, depending on Google's infrastructure and any region settings applied to our account.

Submitting the Demo Request form necessarily involves this processing by Google, since Google Workspace is the system through which we receive and handle your request. By submitting the form, you acknowledge and accept that your data will be processed by Google, including potentially outside Indonesia, as a necessary part of our receiving and responding to your request.

Should our data processing arrangements change in the future — for example, if we adopt a different hosting provider or software system — we will update this Notice accordingly and, where the change affects your rights or how your data is processed, provide direct notice before the change takes effect (see Section 13, Notice Updates).

8. Cookies

This Website uses cookies and similar technologies to operate correctly, remember your preferences, and understand how visitors use our site. You can manage your cookie preferences through your browser settings. Declining non-essential cookies will not affect your ability to submit a Demo Request.

9. Data Retention and Disposal

If your Demo Request does not lead to you becoming a Bronyx client, we retain your data for up to 24 months from your last interaction with us, after which it is securely deleted or anonymised. If you become a Bronyx client, retention of your data then follows the data retention terms set out in the applicable service agreement between you and ITSEC Asia.

If you withdraw your marketing consent or request deletion of your data, we will delete your profile information, but we retain a minimal suppression record (your email address and the date of your request) for as long as necessary to ensure we do not contact you again. This limited record is kept solely to honour your request and is not used for any other purpose.

This retention schedule applies to Demo Request and lead data only. It is separate from Scan Data generated during an actual security testing engagement, which this Website already states is retained 90 days by default and is configurable per client policy.

10. Your Rights

Under the UU PDP, you have the right to:

  • Access the personal data we hold about you;
  • Correct inaccurate or incomplete personal data;
  • Request deletion of your personal data, subject to legal exceptions;
  • Restrict or object to certain processing;
  • Withdraw consent at any time, without affecting processing carried out before withdrawal;
  • Request a copy of your data in a structured, commonly used format (data portability), where applicable; and
  • Lodge a complaint with the Ministry of Communication and Digital Affairs (KEMKOMDIGI) or pursue remedies available under the UU PDP.

To exercise any of these rights, contact our Data Protection Officer using the details in Section 12.

11. Data Security and Incident Notification

We implement appropriate technical and organisational measures to protect personal data collected through this Website against unauthorised access, loss, misuse, or disclosure. In the event of a personal data breach affecting Demo Request data, we will notify KEMKOMDIGI and affected individuals within 3×24 hours, as required under Article 46 of the UU PDP.

12. Contact Us

For any questions, concerns, or requests regarding this Notice or your personal data, please contact our Data Protection Officer:

Email: privacy@itsecasia.com
Noble House, Level 11, Jakarta 12950, Indonesia

13. Notice Updates

This Notice may be updated periodically to reflect changes in our practices or applicable laws. The latest effective date is shown at the top of this document. Where a material change directly affects your rights or how we process your personal data, and we have your contact information on file, we will provide you direct notice (for example, by email) before the change takes effect, in addition to updating this page. For more information about our data protection approach, contact our Data Protection Officer at the address above.