Privacy Center

Privacy Policy

How Bursa collects, uses, and protects your personal data under the PDP Law.

Privacy Center

If the Indonesian and English versions conflict, the Indonesian version governs.

Effective: 4 August 2026 · Version 2.1

If the Indonesian and English versions differ, the Indonesian version governs.

Bursa Trading Academy (“Bursa”, “Platform”, “we”) — operated through bursanalar.com — is committed to protecting your personal data (“User”, “you”) under Law No. 27 of 2022 on Personal Data Protection (UU PDP) and its implementing rules. This policy explains what data we collect, why, how we protect it, and your rights as a data subject.

Under UU PDP, Bursa acts as personal-data controller and uses third-party personal-data processors (hosting, payment gateway, email) as described in Article 4. This policy is an integral part of the Terms of Service.

Article 1 — Data we collect

CategoryExample dataSource
Basic identityName, email, phone (optional), usernameRegistration
Waitlist & email preferencesEmail, time/version of consent, campaign source, chosen topics, delivery/click eventsWaitlist form and preference centre
Professional credentials (mentors)ID card, tax ID, OJK/Bappebti licences, track-record documentsMentor application
Transactions & financialPurchase history, payment method (not card numbers), mentor bank accountsTransactions
Learning behaviourCourse progress, private Notes, watchlistPlatform use
CommunicationsComments, discussion messages, support ticketsUser input
TechnicalIP, device, browser, cookies, activity logsAutomatic

Google login (optional): email, display name, public profile photo URL — we do not access Gmail, contacts, or calendar.

We do not intentionally collect specific personal data (for example health, biometric, or personal financial data beyond what a transaction requires, or political views). Please do not upload such data to community spaces or Notes.

Article 2 — Purposes of collection

CategoryPurpose
Basic identityAccount, authentication, transactional communication
Waitlist & email preferencesRegistration confirmation, education onboarding, product updates, and launch information according to your choices
Mentor KYCMentor eligibility verification — not for marketing without separate consent
TransactionsPayment, commission/payout, tax reporting
Learning behaviourRecommendation personalisation, curriculum improvement
CommunicationsModeration, customer support
TechnicalSecurity (anomaly detection), aggregate analytics

We process data only for the purposes above and do not use it outside those purposes without separate consent.

Note: Your Notes/private notes are private by default and are not shared with mentors or others without explicit permission.

Article 3 — Legal bases for processing

Under UU PDP, we process data on one of the following bases:

  1. Explicit consent — account registration and waitlist lifecycle email (separate checkbox, not pre-checked, withdrawable at any time).
  2. Performance of a contract — processing course-purchase transactions.
  3. Legal obligation — retaining transaction data for tax reporting.
  4. Legitimate interests — fraud detection and system security, balanced against your rights.

Article 4 — Sharing data with third parties

We do not sell your personal data. Data is shared only as needed with:

Third partyDataPurpose
Payment gateway (Midtrans/Xendit)Transaction dataPayment processing
Hosting (Vercel) & cloud databaseEncrypted account dataApplication infrastructure
Google OAuthEmail, public profileOptional login
Email provider (Resend)Email, name (if available), topic preferences, and delivery eventsTransactional notices and waitlist lifecycle based on consent
Analytics (PostHog — planned)Aggregate/pseudonymous dataProduct improvement
Competent authoritiesAs required by lawful requestRegulatory compliance

Each third-party processor is bound by contractual duties of confidentiality and security equivalent to ours. Full subprocessor detail: Subprocessors.

Article 5 — Data-subject rights

Under UU PDP, you have the right to:

  1. Information — clarity of identity, legal basis, and purpose of processing.
  2. Access — a copy of personal data (JSON/PDF).
  3. Correction — fix inaccurate data via your profile.
  4. Erasure — delete the account (with exceptions for legally required retention).
  5. Portability — receive your data in a readable format and move it.
  6. Withdraw consent — for non-essential processing.
  7. Object — to certain processing, including automated decisions (for example algorithmic personalisation) that significantly affect you.
  8. Complain — to the Platform and to the body that administers personal-data protection under UU PDP.

Submit requests via the Data request form or email privacy@bursanalar.com. Response within 14 working days.

For waitlist email, every message includes a preference-centre and unsubscribe link. Withdrawal of consent applies immediately to waitlist marketing email and does not stop security, authentication, or necessary account-transaction email.

Article 6 — Retention

CategoryRetentionAfter account deletion
Basic identityWhile the account is activeDeleted/anonymised in 30–90 days
Waitlist & email preferencesWhile consent is active; reviewed after 24 months without interactionDeleted/anonymised 30–90 days after withdrawal, except a minimal email on the suppression list to honour opt-out
Mentor KYCPartnership term + legal dutiesArchived as required by law
TransactionsTax obligation (~10 years)Anonymised after the period
Notes & progressWhile the account is activePermanently deleted
Technical logs90–180 daysDeleted automatically

Article 7 — Data security

  • Encryption in transit (TLS) and at rest for sensitive data
  • RBAC — role-based access
  • Audit logs for access to sensitive data
  • Passwords hashed with bcrypt (cost ≥ 12)
  • No card data stored — delegated to a PCI-DSS payment gateway

Security detail: Trust Center.

Data-breach notification: If personal-data protection fails, we will notify affected data subjects and the competent authority no later than 3×24 hours after we become aware of the incident, under UU PDP, including what data was exposed, when and how, and the containment and recovery steps.

Article 8 — Cookies & tracking

Summary — full detail in the Cookie Policy:

TypeFunctionCan be turned off?
EssentialLogin session, checkoutNo
AnalyticsFeature usageYes
MarketingAdvertising campaignsYes

Article 9 — Cross-border transfers

Some infrastructure (Vercel, cloud database) may be located outside Indonesia (for example the US or Singapore). Under Article 56 UU PDP, we transfer personal data outside Indonesia only if: (a) the destination country has an equivalent or higher level of protection; (b) adequate and binding protection exists through agreements with subprocessors (for example standard contractual clauses); or (c) the data subject has consented.

Article 10 — Children’s data

The Platform is intended for ages 18+. Collection and processing of a child’s personal data (if any) requires consent of a lawful parent/guardian under UU PDP. If we learn that a child’s data was collected without guardian consent, it will be deleted promptly.

Article 11 — Policy changes

Material changes are notified by email/notification before they take effect. Continued use is acceptance.

Article 12 — Contact & data-protection officer

We will respond to questions or data-subject requests within 14 working days.

Article 13 — Community & AI data (if features are active)

If community/chat or an AI assistant is enabled:

DataPurposeRetention
Public discussion messagesModeration, community supportWhile the account is active + moderation period
AI interaction logsImproving support-bot quality90 days, without raw PII in logs
Room/class metadataOrganising discussion per courseWhile enrolment is active

We do not use the contents of private Notes or learning data to train external AI models without separate explicit consent.

Article 14 — Updates & notices

Material changes to this policy will be notified through:

  1. Email to the registered address
  2. In-app banner/notification
  3. Updating the “Effective” date on this page

We recommend reviewing this policy periodically. The latest version is always at the Privacy Center.