Balance — Indonesia Country Annex
Effective date: 19 July 2026 Last updated: 19 July 2026
Owner: , Director, BabaYaga Program, TOO — Privacy Officer and Designated Child Safety Officer for every Indonesian resident covered by this Annex; the officer or official designated to carry out the personal-data-protection function under Undang-Undang Nomor 27 Tahun 2022 tentang Pelindungan Data Pribadi (the "PDP Law" / "UU PDP") Arts 53-54 on the most-protective reading (systematic processing of children's personal data), with business contact ; the designated contact point for the Indonesian data-protection supervisory institution provided for by UU PDP Arts 58-60 (pending its full establishment, the Kementerian Komunikasi dan Digital — "Komdigi"), the Komisi Perlindungan Anak Indonesia ("KPAI"), the Badan Perlindungan Konsumen Nasional ("BPKN"), and the Kepolisian Negara Republik Indonesia ("Polri"), under their respective intake protocols.
Reviewed: at least once a year, by 9 June. Re-opened immediately on (a) any amendment to UU PDP 27/2022 (enacted 17 October 2022; the two-year transition ended 17 October 2024 — the law applies in full) or the issuance of its implementing Government Regulation(s); (b) the establishment, empowerment, or first enforcement practice of the PDP supervisory institution under UU PDP Arts 58-60 (pending at the Effective date); (c) any amendment to, or implementing regulation under, Peraturan Pemerintah 17/2025 (the child-protection-in-electronic-systems regulation, "PP Tunas" — enacted 27 March 2025, with electronic-system-operator obligations applying after the transition period, from March 2026); (d) any amendment to UU ITE (Law 11/2008 on Electronic Information and Transactions as amended by Law 19/2016 and Law 1/2024) or to GR 71/2019 (electronic-systems regulation, incl. PSE registration) or MR 5/2020; (e) any amendment to Law 8/1999 on Consumer Protection or Law 24/2009 (national language — bilingual-contract requirement, read with the Nine AM Ltd line of cases); (f) any amendment to Law 23/2002 on Child Protection as amended by Law 35/2014, or to Law 44/2008 on Pornography; (g) any decision of the Mahkamah Konstitusi or Mahkamah Agung materially bearing on UU PDP or the constitutional privacy right (UUD 1945 Art 28G); (h) any change in Indonesia's adequacy postures (no EU adequacy at the Effective date); (i) any change to a sub-processor's Indonesia data-handling posture under our sub-processor register; (j) the bringing into force of any post-Effective-date Indonesian regulation governing automated processing or related techniques (covered by the deliberate-silence carve-out in § 2); (k) any PSE-registration enforcement development affecting Balance's classification (tracked internally per the locked user decision).
Classification: Public legal annex. This document is published at Privacy Policy alongside the global Privacy Policy (H1) and at Children's Privacy Notice alongside the Children's Privacy Notice (H2), and is incorporated by reference into both. It is one of the country annexes that travel with the global documents under the "global policy + per-country annex" architecture documented in our internal compliance plan § 6.3.
This Annex discharges the country-annex obligations referenced in:
- Privacy Policy § 18 (Country annexes — Indonesia row).
- Children's Privacy Notice § 14 (Country annexes — Indonesia row).
- Child Safety Standards § 13 (Country annexes — Indonesia row).
- Terms of Service § 17 (Indonesia consumer-protection carve-out under Law 8/1999; bilingual provision under Law 24/2009).
- Subscription Terms § 18 (Indonesia consumer-rights overlay — Law 8/1999; Google Play refund policy as the operational floor).
- Data Retention & Deletion Policy § 13 (Indonesia complaint route).
- our breach-notification runbook § 9 (Indonesia breach-notification route under UU PDP Art 46 — 3×24 hours).
- our international-transfer pack § 6 (UU PDP Arts 55-56 cross-border-transfer mechanism).
This Annex is the canonical Indonesian-resident extension of the global Privacy Policy and Children's Privacy Notice. Where this Annex grants an Indonesian resident a right that the global Policy does not, this Annex governs; the converse also holds. The two are read together.
This Annex is drafted in English. The national language is Bahasa Indonesia (UUD 1945 Art 36; Law 24/2009 Art 31 requires agreements involving Indonesian parties to be in Bahasa Indonesia — bilingual versions permitted). A Bahasa Indonesia translation of this Annex and of the common documents is provided via the language switcher at balance.babayagaprogram.com as part of the batch-1 locale rollout; contracts with Indonesian consumers are thereby provided bilingually (Bahasa Indonesia + English) per Law 24/2009.
1. Scope and applicability
This Annex applies to every Balance user (parent or kid) whose country of residence is Indonesia — the unitary Republic comprising 38 provinces. UU PDP is a national statute; there is no provincial data-protection sub-layer.
We determine country of residence at install/sign-up time by (a) the country the parent self-declares in onboarding, (b) the IP-geolocation read at sign-up (discarded immediately after the residence decision — our internal data-flow map § 2.1), and (c) the Play Store account locale. Reviewable at Settings → Account → Region. Where any signal identifies Indonesia, this Annex applies; the most-protective reading controls.
UU PDP has explicit extraterritorial reach at Art 2(1)(b): it applies to acts outside Indonesia that have legal consequences in Indonesia or for Indonesian personal-data subjects outside Indonesia. Balance offers its service to Indonesian residents through Google Play Indonesia; UU PDP applies in full. Balance is the Pengendali Data Pribadi (controller); the parent and kid are data subjects.
2. Statutory framework — what applies
| Instrument | What it does | Balance's posture |
|---|---|---|
| UUD 1945 — Art 28G(1) | Constitutional right to protection of self, family, honour, dignity — the privacy anchor. | Constitutional layer. §§ 3, 6 below. |
| UU PDP 27/2022 | The principal statute (transition ended 17 October 2024). Art 2 extraterritorial reach; Art 4 general vs specific personal data — specific data includes health, biometric, genetic, criminal record, children's data, personal financial data; Arts 20-23 lawful bases (consent; contract; legal obligation; vital interest; public task; legitimate interest) + valid-consent requirements (Arts 22-23); Arts 24-25 children's data must be processed in a specifically protected manner with parental/guardian consent; Arts 26-32 data-subject rights; Arts 34 processing-risk assessment (PDPIA) mandatory for, inter alia, processing of specific personal data including children's data; Arts 35-39 security + processing records; Art 46 breach notification — written notification no later than 3×24 hours to the data subject and the supervisory institution; Arts 53-54 data-protection-officer designation for, inter alia, large-scale processing of specific personal data; Arts 55-56 cross-border transfers (equivalent-or-higher protection in the recipient country; failing that, adequate binding safeguards; failing that, the data subject's consent); Arts 57-61 supervisory institution + sanctions (administrative fines up to 2% of annual revenue; criminal provisions Arts 67-73). | The principal statute. Applies in full via Art 2. Treatment throughout. |
| PP Tunas — Peraturan Pemerintah 17/2025 (child protection in electronic systems; operator obligations from March 2026) | The child-online-protection regulation under Law 23/2002 (as amended) + UU ITE: age tiers (under-13 accounts only with parental consent and supervision; 13-17 with parental supervision), age-assurance duties proportionate to risk, privacy-by-default for children, a ban on commercial profiling of children and on advertising exploitation, a child-specific PDPIA duty, and a mandate that operators provide parental-control tools — Balance is such a tool: the kid account exists only under the parent's supervision, at every age tier. | Applies. Treatment in §§ 5, 7 below. |
| UU ITE (11/2008 as amended by 19/2016, 1/2024) + GR 71/2019 + MR 5/2020 | Electronic-transactions and content framework; electronic-system-operator (PSE) duties; content-governance and lawful-access procedures. Registration/licensing postures are operational matters tracked internally per the locked user decision. | Applies. Treatment in §§ 12, 13 below. |
| Law 23/2002 on Child Protection (as amended by Law 35/2014) + Law 44/2008 on Pornography | Child-protection duties; CSAM offences (Law 44/2008 Arts 4, 29-38; Law 35/2014 Art 76E et seq.). | Applies. Treatment in § 14 below. |
| Law 8/1999 on Consumer Protection | Consumer rights (Art 4), prohibited clauses (Art 18 — exculpatory standard clauses null), dispute resolution via BPSK (consumer-dispute settlement bodies) or courts. | Applies. Treatment in § 16 below. |
| Law 24/2009 (national language) | Art 31 — agreements involving Indonesian parties in Bahasa Indonesia (bilingual permitted). | Discharged by the Bahasa Indonesia documentation set. |
| EU adequacy / Convention 108 / Budapest | No EU adequacy; Indonesia is not a party to Convention 108/108+ or the Budapest Convention. Cross-border lawful access via MLATs (incl. the ASEAN MLAT) and reciprocity. | Context-setting facts. § 13 below. |
(Any prospective Indonesian regulation governing automated processing, algorithmic decisions, or related techniques — including Komdigi AI circulars and any successor instrument — is intentionally omitted from this Annex on the principle that this Annex makes no affirmative or negative statement about whether Balance does or does not process personal data using techniques within the scope of any such regulation. Balance's substantive product posture is described elsewhere in the policy bundle and is the controlling reference; this Annex's silence is deliberate.)
3. Supervisory authorities
3.1 The PDP supervisory institution / Komdigi
UU PDP Arts 58-60 provide for a data-protection supervisory institution established by and responsible to the President. Pending its full establishment at the Effective date, supervision and complaint intake operate through the Kementerian Komunikasi dan Digital (Komdigi).
| Field | Value |
|---|---|
| Name | Kementerian Komunikasi dan Digital (Komdigi) — pending the UU PDP Arts 58-60 institution |
| Address | Jl. Medan Merdeka Barat No. 9, Jakarta Pusat 10110, Indonesia |
| Website / complaint channel | https://www.komdigi.go.id/ — content/complaint portal https://aduankonten.id/ |
An Indonesian resident may complain to the supervisory institution and may always first raise the matter with us at (named individual: ); we respond within the UU PDP Art 32 timeline (§ 6 below).
3.2 Other regulatory bodies
| Body | Subject matter | Channel |
|---|---|---|
| KPAI — Komisi Perlindungan Anak Indonesia | Child-protection oversight + complaints | https://www.kpai.go.id/ |
| BPKN / BPSK | Consumer protection (Law 8/1999) | https://bpkn.go.id/; BPSK per city/regency |
| Polri — Direktorat Tindak Pidana Siber | Cybercrime + online CSAE | https://patrolisiber.id/ — emergency 110 |
| Komdigi content channel | Illegal-content reports incl. CSAM | https://aduankonten.id/ |
| SAPA 129 (Ministry of Women's Empowerment and Child Protection) | Child-abuse hotline | dial 129; WhatsApp +62 8111-129-129 |
3.3 The DPO-function designation
UU PDP Arts 53-54 require a DPO designation where core activities include large-scale processing of specific personal data (children's data is specific personal data). On the most-protective reading Balance designates , Director, BabaYaga Program, TOO — , published here, in the global Privacy Policy § 1, and at balance.babayagaprogram.com. No local representative is engaged (locked user decision; exposure tracked internally).
4. Lawful bases — UU PDP Arts 20-25
- Parent account data: Art 20(2)(b) contract performance + Art 20(2)(a) explicit valid consent obtained at sign-up (Arts 22-23: written/recorded, specific, informed, withdrawable).
- Kid profile + device data: Arts 24-25 children's-data regime — processed in a specifically protected manner on the parent's/guardian's consent, obtained by design through the parent-first onboarding (§ 7 below), and reviewed against a child-specific PDPIA (UU PDP Art 34 + PP Tunas) recorded in our Data Protection Impact Assessment.
- Security, fraud-prevention, legal compliance: Art 20(2)(c) legal obligation + Art 20(2)(f) legitimate interest with balancing, never overriding the child's interests.
- No advertising, profiling, or sale. Monitoring/limits/tasks are performed at the parent's direction, strictly for the safety, well-being and parental supervision of the child, never for any commercial purpose — this also discharges the PP Tunas ban on commercial profiling of children.
5. Children's rights overlay — UU PDP Arts 24-25 + PP Tunas
- The parent always consents; the kid never self-registers. At every PP Tunas age tier (<13; 13-17) the kid account exists only inside the authenticated parent account and under the parent's live supervision — the under-13 parental-consent requirement and the 13-17 parental-supervision requirement are satisfied by construction.
- Balance is a parental-control tool of the kind PP Tunas mandates operators to provide. Screen-time limits, app limits, tasks and usage visibility exist solely so the parent can supervise the child.
- Privacy-by-default is the only mode Balance ships: no public profile, no content feed, no social graph, no contact-by-strangers surface, no advertising surface.
- Children's data = specific personal data (Art 4(2)): heightened security, PDPIA, DPO function, and the E2EE proof-media posture (§ 13).
- Age assurance: the parent declares and manages the kid's age; the kid cannot alter it — proportionate to risk in a closed family system where the consenting adult is identity-verified (§ 7).
6. UU PDP rights catalogue — Arts 26-32
Honoured at and in-app (the parent exercises the kid's rights as guardian):
- Art 26 — information about the identity of the controller, the legal basis and the purposes (this bundle + the Section-5-equivalent notice at sign-up).
- Art 27 — completion, updating, correction: Settings → Account → Edit.
- Art 28 — access and copy: in-app JSON export at Settings → Family → [kid name] → "Export this kid's data".
- Art 29 — ending processing, erasure, destruction: Settings → "Delete my account" / "Delete this kid"; Delete-account page; cascade per Data Retention & Deletion Policy § 7.
- Art 30 — withdrawal of consent (processing stops within 3×24 hours of withdrawal per Art 41).
- Art 31 — objection to solely-automated decision-making with significant effects — Balance performs none; the earned-time ledger is deterministic and parent-reviewable.
- Art 32 — restriction of processing.
- Art 33 + Art 38 — portability (the JSON export) — delivered in a commonly-used, structured format.
Timeline: UU PDP Art 32(2)-context practice: we acknowledge within one business day and fulfil within 3×24 hours for withdrawal/erasure-driven stops (Art 41) and within 14 days for access/portability at the outside. Requests may be in Bahasa Indonesia or English, free of charge.
7. Children's data — consent mechanics and minimisation
- Parent creates the account with verified email (+ Google Play payment instrument where subscribed), then affirmatively creates the kid profile and pairs the kid's device — the Arts 24-25 parental consent, evidenced and logged.
- The consent screen (Bahasa Indonesia for Indonesian parents) itemises categories, purposes (safety and parental supervision only), sub-processors, retention, and rights.
- Data minimisation: only what the supervision service needs; proof media is E2EE to the parent's devices — Balance holds ciphertext only.
- The child-specific PDPIA (UU PDP Art 34 + PP Tunas) is recorded in our Data Protection Impact Assessment and re-run on any feature change touching kid data.
8. International data transfers from Indonesia — UU PDP Arts 55-56
Art 56 sets a three-step cascade: (1) recipient country with equivalent or higher protection; (2) failing that, adequate binding safeguards; (3) failing that, the data subject's consent. No equivalence determination covering the US or Kazakhstan exists at the Effective date. Balance relies on:
- binding safeguards — written DPAs with every sub-processor incorporating security and confidentiality controls (our international-transfer pack § 6), reinforced by the E2EE supplementary measure for proof media; and
- the parent's explicit transfer consent at sign-up (the transfer-disclosure consent names the US hosting and the controller's Kazakhstan seat) as the Art 56(4) fallback.
§ 18 covers any implementing-regulation development on transfer mechanics.
9. Data residency for Indonesian residents
| Question | Answer |
|---|---|
| Where is the backend hosted? | United States. Emergent Labs Inc. (Delaware) on US infrastructure. |
| Where is the MongoDB database located? | United States. |
| Where is the proof-media storage located? | United States — Google Cloud Storage us multi-region (E2EE ciphertext only). |
| Where are push notifications dispatched from? | United States — Firebase Cloud Messaging. |
| Is any Indonesian resident's data held in Indonesia? | No. The Arts 55-56 mechanisms in § 8 ground the transfer. |
| Where is the controller? | Kazakhstan (BabaYaga Program, TOO), with administrative access under written processor DPAs. |
| Is there an Indonesian establishment? | No. |
GR 71/2019 localisation duties attach to public-scope electronic-system operators; private-scope operators may process abroad subject to supervision-access duties. Balance is a private-scope operator and imposes no Indonesian-residency requirement on its own data at the Effective date.
10. Sub-processors touching Indonesian-resident data
| Sub-processor | Role | Location | Indonesia transfer basis |
|---|---|---|---|
| Emergent Labs Inc. (Delaware, USA) — using MongoDB Atlas (US); relationship per our internal vendor-handling plan | Hosts the FastAPI backend + MongoDB cluster | United States | UU PDP Art 56 binding safeguards (DPA) + explicit transfer consent; E2EE supplementary measure for proof media. |
| Google LLC — Google Cloud Storage (USA) | E2EE proof-media ciphertext + daily 30-day-rolling backups | United States (us multi-region) |
Art 56 safeguards via Google Cloud DPA; ciphertext-only. |
| Google LLC — Firebase Cloud Messaging | Push notifications | United States | Art 56 safeguards; push body free of sensitive content (M3). |
| Google LLC — Google Sign-In | Parent Google authentication (when used) | United States | Art 56 safeguards via Google DPA. |
| Google LLC — Google Play Billing | Subscription purchases | United States / Indonesia (Google Play) | Google Play Developer Distribution Agreement + Art 56 safeguards. |
| Resend, Inc. (San Francisco, CA, USA) | Transactional email | United States | Art 56 safeguards (DPA on file). |
Full list: our sub-processor register.
11. Breach notification — UU PDP Art 46
| Audience | Trigger | Deadline | Channel |
|---|---|---|---|
| Affected data subjects | Any failure of personal-data protection (breach of confidentiality/integrity/availability). | Written notification no later than 3×24 hours from awareness — stating the data compromised, when and how, and the handling and recovery measures. | Direct email to the affected parent; in-app banner; public incident page fallback. Bahasa Indonesia. |
| Supervisory institution (Komdigi pending the Arts 58-60 body) | The same breach. | 3×24 hours. | The institution's incident channel, filed by the Privacy Officer or Indonesian counsel on instruction. |
| Public disclosure | Where the breach disrupts public services or materially affects the public interest (Art 46(3)). | As required. | Public incident page. |
| CSAE-specific | An incident with a CSAE component. | Per § 14 + runbook M1. | Polri / patrolisiber.id + KPAI + aduankonten.id + (where applicable) NCMEC. |
Internal SLA: our breach-notification runbook § 5.4 + § 9.
12. Cookies, spam, and electronic direct marketing
Indonesia has no standalone cookies statute; cookie-equivalent identifiers are personal data under UU PDP. The Balance app deploys strictly-necessary storage only (authentication tokens; device-pairing key wrap; earned-time cache), covered by the sign-up consent. The public site uses no analytics, advertising cookies, trackers, or fingerprinting. Balance sends no electronic direct marketing to Indonesian residents — transactional email only. PP Tunas's ban on advertising exploitation of children is honoured absolutely (Balance has no advertising surface at all).
13. Lawful-access requests and the encryption posture
Indonesian authorities may seek data via UU ITE/GR 71 lawful-access procedures (court-sanctioned criminal-procedure instruments, KUHAP production orders), Komdigi administrative requests to electronic-system operators, and international channels (MLAT / reciprocity; Indonesia is not a Budapest Convention party). Posture:
- Proof media is end-to-end encrypted (fresh per-file key, XChaCha20-Poly1305, wrapped to parent-device X25519 keys; ciphertext-only upload). No master key, no backdoor.
- Response protocol: (1) acknowledge within one business day; (2) engage Indonesian counsel to assess validity; (3) preserve relevant ciphertext; (4) inform the authority plaintext is unavailable from us; (5) cooperate in identifying the lawful route to the key-holding parent.
- No bulk plaintext interception assistance; no server-side content scanning. CSAE cooperation runs via § 14 regardless.
Full encryption posture: our encryption-posture record.
14. CSAE reporting routes — Indonesia
- Balance Designated Child Safety Officer:
(named individual: ). Acknowledgement within one business day. - Polri cybercrime channel:
https://patrolisiber.id/— emergency 110. - Komdigi illegal-content portal:
https://aduankonten.id/(CSAM category). - KPAI:
https://www.kpai.go.id/— child-protection complaints. - SAPA 129: dial 129 / WhatsApp +62 8111-129-129 (Ministry of Women's Empowerment and Child Protection hotline).
- NCMEC CyberTipline (
https://report.cybertip.org/) — provider-side discoveries route to NCMEC, which relays to Indonesian law enforcement.
Full routing table: Child Safety Standards § 8.5.
15. Complaint routes (summary)
| Authority | Subject matter | Channel |
|---|---|---|
| PDP supervisory institution / Komdigi | UU PDP | https://www.komdigi.go.id/ |
| BPSK / BPKN | Law 8/1999 consumer disputes | Per city/regency; https://bpkn.go.id/ |
| KPAI | Child-rights complaints | https://www.kpai.go.id/ |
| Polri | Criminal (UU ITE, CSAM, Law 44/2008) | https://patrolisiber.id/ |
| Courts | Civil claims (UU PDP Art 12 compensation right) | Per jurisdiction |
An Indonesian resident may always first raise the matter at ; prior contact is not a precondition to any authority route.
16. Consumer rights — the Law 8/1999 overlay
- Art 4 basic rights: correct, clear, honest information — implemented in Subscription Terms § 5 and the Bahasa Indonesia documentation set.
- Art 18 prohibited standard clauses: exculpatory clauses, unilateral-variation clauses and burden-shifting clauses are null — the Terms of Service are drafted to avoid each.
- Withdrawal/refunds: Law 8/1999 has no statutory digital cooling-off; the Google Play refund policy is honoured as the operational floor, plus Balance's voluntary refund posture (Subscription Terms § 8).
- Dispute resolution: BPSK conciliation/mediation/arbitration or the courts, at the consumer's election; nothing in the Terms displaces this.
- Language: Law 24/2009 bilingual provision discharged by the Bahasa Indonesia set.
- Contracting capacity: the age of majority for contract purposes is governed by the Civil Code (KUHPerdata Art 330 — 21, with marriage emancipation) read with Law 1/1974; Balance applies the most-protective reading and requires the subscribing parent to be an adult under Indonesian law; the kid never contracts with Balance.
17. Cross-references
- Global Privacy Policy: Privacy Policy (H1).
- Children's Privacy Notice: Children's Privacy Notice (H2).
- Terms of Service: Terms of Service (H3).
- Subscription Terms: Subscription Terms (H4).
- Child Safety Standards: Child Safety Standards (H5).
- Retention Policy: Data Retention & Deletion Policy (H6).
- Records of Processing: our Records of Processing Activities (Article 30) (H7).
- DPIA + LIA: our Data Protection Impact Assessment (H8).
- Breach Runbook: our breach-notification runbook (M1).
- Transfer Pack: our international-transfer pack (M2) — UU PDP Arts 55-56 safeguards on file.
- JIT Permission Disclosures: the just-in-time permission disclosures (M3).
- App Classification: our country classification table.
- Sub-processor list: our sub-processor register.
- Encryption Posture: our encryption-posture record.
- Data Flow / Inventory Map: our internal data-flow map.
- Compliance Plan: our internal compliance plan.
18. Versioning and review
- Every change to a substantive row in §§ 2-16 bumps the frontmatter and triggers re-publication.
- The establishment of the UU PDP Arts 58-60 supervisory institution, any UU PDP implementing Government Regulation, or any transfer-mechanics regulation triggers an off-cycle rewrite of §§ 3, 8, 11.
- Any PP Tunas implementing regulation (age assurance, parental-control standards, PDPIA form) triggers an off-cycle update to §§ 5, 7.
- Any PSE-registration enforcement development affecting Balance triggers the internal-checklist workstream (public-doc posture unchanged per the locked user decision).
- A material Law 8/1999 / Law 24/2009 change triggers an off-cycle update to § 16.
- A material change to a sub-processor's posture triggers an off-cycle update to §§ 8, 10.
- The annual review is by 9 June. The Privacy Officer signs off; the Designated Child Safety Officer co-signs any change to §§ 5, 7, 11, 13, 14.
End of Indonesia Country Annex.