Concorde

(CCS® — DOC) PRIVACY & SECURITY

Privacy & Security Statement

Last updated — 13 July 2026 · Draft pending legal review

Concorde is built for plants that care where their data lives. This statement covers the personal data we handle as a company under Indonesian law — and the boundaries we keep around Customer Data processed inside DECODER, ASSIST, STATION, HORIZON, and FOG.

001.

Who we are & scope

This statement explains how PT. Maestro Imperium Teknologi, operating as Concorde Systems (“Concorde”, “we”), collects, uses, discloses, protects, and retains personal data when you visit our website, contact us, or use the Concorde platform (DECODER, ASSIST, STATION, HORIZON, FOG).

For personal data contained inside Customer Data that our customers upload (for example a technician name inside a work order), the customer acts as the data controller and Concorde acts as a data processor operating on documented instructions.

002.

Legal framework

We process personal data in accordance with the laws of the Republic of Indonesia, in particular Law No. 27 of 2022 on Personal Data Protection (UU PDP), Law No. 11 of 2008 on Electronic Information and Transactions as amended (UU ITE), Government Regulation No. 71 of 2019 on Electronic Systems and Transactions (PP 71/2019), and Minister of Communication and Informatics Regulation No. 20 of 2016 on Personal Data Protection in Electronic Systems.

003.

Data we collect

  • 01.Identity & contact data — name, role, company, email, phone number (from forms, WhatsApp, or demos).
  • 02.Account data — workspace credentials, roles, permissions, and activity within the Platform.
  • 03.Operational data (Customer Data) — documents, sensor/IoT streams, logs, drawings, and photos our customers connect; processed on the customer's instructions.
  • 04.Technical data — device, browser, IP address, pages visited, and diagnostics needed to run and secure the service.
  • 05.Communications — messages you send us and support history.
004.

How we collect it

  • 01.Directly from you — forms, email, WhatsApp, demos, and pilots.
  • 02.From your organization — when an administrator creates your workspace account.
  • 03.Automatically — cookies and service logs when you use the website or Platform.
  • 04.From integrations you enable — ERP, SCADA, historian, and messaging systems connected via FOG.
005.

Purposes & legal bases

We process personal data to: provide and secure the Platform (contract performance); respond to inquiries and run demos and pilots (contract / legitimate interest); improve reliability and develop features using aggregated, de-identified telemetry (legitimate interest); send service notices and, with consent, marketing (consent — withdrawable at any time); and meet legal obligations (legal obligation). We do not sell or rent personal data.

006.

AI processing & Customer Data boundaries

ASSIST answers are produced by traversing the customer's own knowledge graph; answers cite retrieved sources and are scoped to the customer's workspace. We do not use one customer's data to serve another customer, and we do not use Customer Data to train models offered to other customers without written agreement.

FOG deployments can run fully inside the customer's environment (private cloud, on-premises, or air-gapped edge), in which case Customer Data does not leave the customer's infrastructure.

007.

Disclosure to third parties

We share personal data only with: processors that help us run the service (hosting, communications, analytics) under contracts imposing confidentiality and security; professional advisers; and authorities where required by Indonesian law. Any processor list relevant to your deployment is available on request.

008.

Cross-border transfers

Where personal data is transferred outside Indonesia (for example to a cloud region you select), we ensure the receiving jurisdiction or recipient provides a level of protection consistent with UU PDP, or we obtain your consent, in line with Articles 55–56 of UU PDP.

009.

Retention

We keep personal data only as long as needed for the purposes above: account data for the life of the workspace plus a wind-down period; contact and contract records per statutory retention (generally up to 5 years for transaction documents); service logs for security windows. Customer Data is retained per the customer agreement and deleted or returned on termination.

010.

Security measures

  • 01.Encryption in transit (TLS) and at rest for managed deployments.
  • 02.Role-based access control, least-privilege administration, and audit logging.
  • 03.Environment isolation per workspace; on-prem and air-gapped options via FOG.
  • 04.Vendor and infrastructure review aligned with ISO 27001 practices.
  • 05.Regular backups and tested recovery procedures for managed services.
011.

Breach notification

In the event of a personal-data breach, we will notify affected data subjects and the competent authority in writing no later than 3×24 hours after becoming aware, as required by Article 46 of UU PDP, including the data affected, when and how it occurred, and the handling and recovery steps taken.

012.

Your rights

Under UU PDP you may request: information about processing; access and a copy; correction; deletion or destruction; restriction; withdrawal of consent; objection to solely automated decisions with significant effects; and data portability where technically feasible. Submit requests to business@concordesystems.com — we respond within the timelines set by UU PDP and may verify your identity first. Certain requests can be refused where law allows (for example, records we must retain).

013.

Cookies

The website uses strictly-necessary cookies and, only with consent where required, analytics cookies to understand aggregate usage. You can disable cookies in your browser; core pages remain usable.

014.

Children

Our services are business tools and are not directed at children. We do not knowingly process children's personal data; parents or guardians who believe a child's data reached us can contact us for deletion.

015.

Changes & language

We may update this statement; material changes are announced on this page or by email. This statement is issued in English and Indonesian; in case of inconsistency, the Indonesian version prevails.

016.

Contact

Data protection contact: PT. Maestro Imperium Teknologi (Concorde Systems), Innovation Factory, Jl. Ir. H. Juanda No. 108, Lebakgede, Coblong, Bandung, Jawa Barat 40132, Indonesia · business@concordesystems.com · +62 851-1120-8072.

(CCS® — 10)CONTACT US

Let's Talk & Try For Free — let us prove ourselves with your data

OPENS YOUR EMAIL CLIENT — NO DATA IS STORED ON THIS DRAFT