docs.resmi.id Privacy
Additional detail on data processed specifically by the document and electronic signature service. The data controller is Badan Perizinan Indonesia. This applies alongside the Resmi.ID Privacy Policy.
Last updated:
1. Scope
This page describes only the processing that happens specifically at docs.resmi.id. General matters — definitions, the legal basis for processing, data transfers, cookies, your rights as a data subject, and how to contact us — are covered by the Resmi.ID Privacy Policy.
2. Additional data processed here
In addition to the account data already described in the main policy, this service processes:
- Document content — the files you upload or build, including any personal data they contain.
- Signer data — the name, email and/or phone number you enter when inviting them.
- Signing evidence — when it was opened and signed, IP address, browser/device type, and approximate location from the IP.
- One-time codes — stored as a hash rather than the code itself, along with where it was sent.
- Public verification records — the time and IP address when someone checks a document's authenticity.
3. Why signing evidence is recorded
IP address, device and timestamps are recorded on the basis of our and your legitimate interest: without them an electronic signature loses its evidential value. This is the data that lets your document stand up if its authenticity is ever questioned.
4. Your position regarding signer data
Signer data is processed on your instructions. In that respect you are the controller and we process it on your behalf. You are responsible for having a lawful basis to process their data and for informing them that it is processed through this service.
5. Retention of documents and audit trails
Signed documents and their audit trails are retained permanently, including after your account is closed. This is deliberate and differs from the general retention terms in the main policy: those documents are evidence, and their recipients are entitled to verify them at any time. Deleting them would break public verification and harm the party holding the document. Documents never sent for signature can be deleted by you at any time.
6. Limits on the right to erasure
Your rights as a data subject are set out in Law No. 27 of 2022 on Personal Data Protection and described in the Resmi.ID Privacy Policy. One exception applies here: the right to erasure does not extend to signed documents and their audit trails, because that data is needed to meet evidential obligations and to protect the rights of others holding the document.
7. What we do not do
Two points worth stating specifically for this service:
- We do not use your document content for advertising or to train AI models.
- When you match a file on the verification page, the hash is computed in your browser — the file is never uploaded to our servers.
8. Providers involved
For this service specifically, data is shared as needed with the official e-Meterai provider (when you affix a stamp) and with email and WhatsApp delivery providers (to send signing invitations and one-time codes). Other infrastructure providers are listed in the Resmi.ID Privacy Policy.
9. Document-specific security
Access to documents is restricted by authentication and ownership checks. Signing links use tokens stored as hashes with a limited lifetime. One-time codes are valid for 5 minutes with a limited number of attempts. The audit trail uses a hash chain: each record contains the hash of the one before it, so inserting or altering a single line breaks the chain and is detected.
10. Contact
Questions specific to data in the document service may be sent to [email protected]. General personal-data requests follow the channels listed in the Resmi.ID Privacy Policy.
docs.resmi.id Service Terms docs.resmi.id Privacy Back to home