1. Introduction
Welcome to Datlyne.
PT DATLYNE ONE GLOBAL (“us”, “we”, or “our”) is a limited liability company incorporated in Indonesia, trading as Datlyne. It owns and operates the Service and is the data controller for the personal data described in this policy.
Our Privacy Policy governs your visit to datlyne.com, and explains how we collect, safeguard and disclose information that results from your use of our Service.
We use your data to provide and improve Service. By using Service, you agree to the collection and use of information in accordance with this policy. Unless otherwise defined in this Privacy Policy, the terms used in this Privacy Policy have the same meanings as in our Terms and Conditions.
Our Terms and Conditions (“Terms”) govern all use of our Service and together with the Privacy Policy constitutes your agreement with us (“agreement”).
2. Definitions
SERVICE means the datlyne.com website operated by PT DATLYNE ONE GLOBAL.
PERSONAL DATA means data about a living individual who can be identified from those data (or from those and other information either in our possession or likely to come into our possession).
USAGE DATA is data collected automatically either generated by the use of Service or from Service infrastructure itself (for example, the duration of a page visit).
COOKIES are small files stored on your device (computer or mobile device).
DATA CONTROLLER means a natural or legal person who (either alone or jointly or in common with other persons) determines the purposes for which and the manner in which any personal data are, or are to be, processed. For the purpose of this Privacy Policy, we are a Data Controller of your data.
DATA PROCESSORS (OR SERVICE PROVIDERS) means any natural or legal person who processes the data on behalf of the Data Controller. We may use the services of various Service Providers in order to process your data more effectively.
DATA SUBJECT is any living individual who is the subject of Personal Data.
THE USER is the individual using our Service. The User corresponds to the Data Subject, who is the subject of Personal Data.
3. Information Collection and Use
We collect several different types of information for various purposes to provide and improve our Service to you.
4. Types of Data Collected
Personal Data
While using our Service, we may ask you to provide us with certain personally identifiable information that can be used to contact or identify you (“Personal Data”). Personally identifiable information may include, but is not limited to:
- Email address
- First name and last name
- Phone number
- Company, job title and industry, when you enter them on your profile or on our contact form
- The subject and text of messages you send us through our contact form, including any invoice number you quote
- Your IP address and the user agent string your browser sends
- Essential session cookie and Usage Data
We use your Personal Data to operate your account, to deliver what you have bought, and to answer you. Our email is transactional only: address verification, password reset, order and download information, API key issuance, and replies to messages you send us. We do not send newsletters, marketing or promotional email, and we do not sell or rent your data.
Usage Data
We may also collect information that your browser sends whenever you visit our Service or when you access Service by or through any device (“Usage Data”).
This Usage Data may include your IP address, the user agent string your browser sends (which identifies the browser and its version), and the address and time of the request. Our web server writes these to its own request log, in the ordinary way a web server does. We do not measure how long you spend on a page, and we do not assign or read any device identifier.
Beyond that server log, the Usage Data we store in our database is limited to the following: your IP address and user agent string recorded with sign-in sessions, contact messages, dataset downloads and administrative actions, as described below, and a per-day count of the API requests made with each API key.
IP Address and User Agent
We record your IP address and the user agent string your browser sends, each with a time, in four places: on every sign-in session, so that a sign-in you do not recognise can be investigated; on every message sent through our contact form, so that we can detect and limit abuse of the form; on every dataset download, so that downloads can be accounted for against the purchase that authorises them; and on administrative actions taken in our own admin tools, which is an internal audit record and keeps the IP address only.
An IP address is personal data under the GDPR. We use it for account security, abuse prevention, download accounting and audit, and for nothing else. We do not use it to profile you, to target advertising, or to identify you beyond the account or the message the record belongs to.
Cookies We Use
Datlyne sets exactly one cookie: a first-party, essential session cookie that keeps you signed in while you use the Service. We do not use web beacons, tracking pixels, tags, or scripts to track your activity on the Service or elsewhere.
This session cookie carries no advertising or analytics identifier, is never read by any third party, and is deleted when you sign out or after a period of inactivity.
Because this cookie is strictly necessary for the Service to function, we do not run a cookie consent/preference tool for it. The notice on our site is a factual notice, not a request for consent. You can still block it in your browser settings, but you will not be able to stay signed in if you do.
We do not set any other cookies. In particular, Datlyne does not use preference cookies, advertising cookies, analytics cookies, or any third-party tracking cookie.
5. Use of Data
Datlyne uses the collected data for various purposes:
- to provide and maintain our Service;
- to notify you about changes to our Service;
- to answer the messages you send us through our contact form;
- to provide customer support;
- to count API requests against the limits of your plan;
- to monitor the use of our Service for security and abuse prevention;
- to detect, prevent and address technical issues;
- to fulfil any other purpose for which you provide it;
- to carry out our obligations and enforce our rights arising from any contract between you and us;
- to send you transactional email about your account, your orders, your downloads and your API keys, including address verification and password reset messages;
- in any other way we may describe when you provide the information;
- for any other purpose with your consent.
6. Retention of Data
We will retain your Personal Data only for as long as is necessary for the purposes set out in this Privacy Policy. We will retain and use your Personal Data to the extent necessary to comply with our legal obligations (for example, if we are required to retain your data to comply with applicable laws), resolve disputes, and enforce our legal agreements and policies.
Expired sign-in sessions are deleted seven days after they expire, and a session ends sooner when you sign out or reset your password. Records of email verification requests are deleted 30 days after they expire, and records of password reset requests 90 days after they are created. Records of dataset downloads, of messages sent through the contact form, and of administrative actions in our admin tools are kept for accounting, support and audit purposes.
7. Transfer of Data
Your information, including Personal Data, may be transferred to – and maintained on – computers located outside of your state, province, country or other governmental jurisdiction where the data protection laws may differ from those of your jurisdiction.
Datlyne is operated from Indonesia by PT DATLYNE ONE GLOBAL. The Service and its database run on virtual server infrastructure provided by Hostinger, located outside Indonesia, so your Personal Data is stored and processed outside your country of residence, and outside the European Economic Area.
Your consent to this Privacy Policy followed by your submission of such information represents your agreement to that transfer.
Datlyne will take all the steps reasonably necessary to ensure that your data is treated securely and in accordance with this Privacy Policy and no transfer of your Personal Data will take place to an organisation or a country unless there are adequate controls in place including the security of your data and other personal information.
8. Disclosure of Data
We may disclose personal information that we collect, or you provide:
- Disclosure for Law Enforcement. Under certain circumstances, we may be required to disclose your Personal Data if required to do so by law or in response to valid requests by public authorities.
- Business Transaction. If the business is sold or transferred, your Personal Data may be transferred as part of that transaction.
Other cases. We may disclose your information also:
- to our authorised reseller and merchant of record, which processes your order and the payment for it;
- to the hosting, file storage and email providers that run the Service on our behalf, which process data on our instructions only;
- to fulfill the purpose for which you provide it;
- for any other purpose disclosed by us when you provide the information;
- with your consent in any other cases;
- if we believe disclosure is necessary or appropriate to protect the rights, property, or safety of the Company, our customers, or others.
9. Security of Data
The security of your data is important to us but remember that no method of transmission over the Internet or method of electronic storage is 100% secure. While we strive to use commercially acceptable means to protect your Personal Data, we cannot guarantee its absolute security.
The measures we do take include these: account passwords are stored as Argon2 hashes and never in a form we can read; session tokens are stored as hashes; where an administrator uses two-factor authentication, the secret is stored encrypted; and traffic between your browser and the Service is encrypted in transit.
10. Your Data Protection Rights Under General Data Protection Regulation (GDPR)
If you are a resident of the European Union (EU) and European Economic Area (EEA), you have certain data protection rights, covered by GDPR.
We aim to take reasonable steps to allow you to correct, amend, delete, or limit the use of your Personal Data.
If you wish to be informed what Personal Data we hold about you and if you want it to be removed from our systems, please email us at info@datlyne.com.
In certain circumstances, you have the following data protection rights:
- the right to access, update or to delete the information we have on you;
- the right of rectification. You have the right to have your information rectified if that information is inaccurate or incomplete;
- the right to object. You have the right to object to our processing of your Personal Data;
- the right of restriction. You have the right to request that we restrict the processing of your personal information;
- the right to data portability. You have the right to be provided with a copy of your Personal Data in a structured, machine-readable and commonly used format;
- the right to withdraw consent. You also have the right to withdraw your consent at any time where we rely on your consent to process your personal information;
Please note that we may ask you to verify your identity before responding to such requests. Please note, we may not able to provide Service without some necessary data.
You have the right to complain to a Data Protection Authority about our collection and use of your Personal Data. For more information, please contact your local data protection authority in the European Economic Area (EEA).
11. Your Data Protection Rights under Indonesian Law
PT DATLYNE ONE GLOBAL is incorporated in Indonesia and operates the Service from Indonesia, so Law No. 27 of 2022 on Personal Data Protection applies to our processing of your Personal Data.
Under that law you may ask us to confirm what Personal Data we hold about you, to correct it if it is wrong or incomplete, to delete it, to stop processing it, and to give you a copy of it. You may also withdraw a consent you have given us.
To exercise any of these rights, email us at info@datlyne.com. We may ask you to verify your identity first, and we may be unable to provide parts of the Service without the data those parts depend on.
These rights are the same ones we extend to everyone who uses the Service, wherever they are. We do not operate a shorter list for people outside Indonesia or the European Economic Area.
12. Tracking, Advertising and Selling Data
We do not track you across other websites, we do not serve advertising, and we do not sell, rent or share your Personal Data with any third party for monetary or other consideration. There is no advertising network, data broker or analytics profile behind this Service.
Because we do not track you in the first place, a “Do Not Track” signal from your browser changes nothing about how we behave. We treat every visitor as though the signal were set.
In practical terms:
- you can read our public pages without creating an account;
- the link to this policy contains the word “Privacy” and is reachable from every page;
- we will post any change to this policy on this page;
- you can correct or delete the information we hold about you by emailing info@datlyne.com.
13. Service Providers
We use third-party providers to run the Service (“Service Providers”): our merchant of record for payment, order and subscription processing, and the providers that host our servers, store our dataset files and deliver our email.
These third parties have access to your Personal Data only to perform these tasks on our behalf and are obligated not to disclose or use it for any other purpose.
14. Analytics
Datlyne does not use analytics services. No third-party analytics, session-recording, or heat-mapping tool runs on the Service, and no analytics cookie or script is set.
15. CI/CD tools
We use third-party tools to build and deploy the Service. Those tools handle our source code and our infrastructure, not your personal data.
16. Behavioral Remarketing
Datlyne does not use behavioral remarketing or advertising services. We do not advertise to you on third-party websites based on your visits to our Service, and no advertising cookie or pixel is set on the Service.
17. Payments
Paid products and subscriptions on the Service are sold through our authorised online reseller, which acts as the merchant of record for every order. You buy from that reseller; the dataset or API access itself is licensed to you by us.
We do not collect or store your payment card details. You give them directly to our merchant of record, whose use of your personal information is governed by its own privacy policy, and which handles card data to the PCI-DSS standard managed by the PCI Security Standards Council. From it we receive an order record: what was bought, the amount and currency, the invoice number, and the email address on the order.
18. Links to Other Sites
Our Service may contain links to other sites that are not operated by us. If you click a third party link, you will be directed to that third party’s site. We strongly advise you to review the Privacy Policy of every site you visit.
We have no control over and assume no responsibility for the content, privacy policies or practices of any third party sites or services.
19. Children’s Privacy
Our Services are not intended for use by children under the age of 18 (“Child” or “Children”).
We do not knowingly collect personally identifiable information from Children under 18. If you become aware that a Child has provided us with Personal Data, please contact us. If we become aware that we have collected Personal Data from Children without verification of parental consent, we take steps to remove that information from our servers.
20. Changes to This Privacy Policy
We may update our Privacy Policy from time to time. We will notify you of any changes by posting the new Privacy Policy on this page.
We will let you know via email and/or a prominent notice on our Service, prior to the change becoming effective and update “effective date” at the top of this Privacy Policy.
You are advised to review this Privacy Policy periodically for any changes. Changes to this Privacy Policy are effective when they are posted on this page.
21. Contact Us
If you have any questions about this Privacy Policy, please contact us by email: info@datlyne.com.
This Privacy Policy is published by PT DATLYNE ONE GLOBAL, the operator of datlyne.com.