Subscriber Agreement
Effective Date: July 3rd, 2026
Please read this Subscriber Agreement ("Agreement") carefully along with the CPS, which is subject to change from time to time, before using the Certificate issued to the User. By obtaining or using the Certificate issued by Privy, the User agrees to be bound by the terms of this Agreement.
This Agreement constitutes a legally valid agreement between PT Privy Identitas Digital ("Privy") and User, an individual and/or legal entity/business entity who apply for a Certificate ("User"). This Agreement, provided that it is not amended, shall be effective as of July 3rd, 2026 and replaces the Subscriber Agreement number 010/Privy-LGL/KB/VIII/2025.
1.Definitions
“Privy Account” shall mean any account issued by Privy, under the name of PrivyID, where each account owner will be given a userID, can create a password, and can store their Personal Data.
"Privy App" shall mean an application that can be accessed through website and/or mobile phone (mobile apps) operated by PT Privy Identitas Digital.
"Certification Practice Statement" or "CPS" shall mean the provision of CA’s operational procedures including the procedure for issuing Privy Certificates, which is available at https://repository.privyca.id.
"Personal Data" shall mean any data that identifies or can be used to identify an individual, alone or in combination with other data/information, whether directly or indirectly in electronic and/or non-electronic systems, which is divided into Specific/Sensitive Personal Data and General Personal Data.
“Digital Identity” refers to Electronic Information containing the unique identity of a legal subject, the use of which is under the control of the legal subject associated with such identity.
"Electronic Information" means one or a set of electronic data, including but not limited to writing, sounds, images, maps, designs, photographs, Electronic Data Interchange (EDI), electronic mail (e-mail), telegram, telex, telecopy or similar forms, letters, signs, numbers, access codes, symbols, or perforations that have been processed and have meaning or can be understood by a person capable of understanding them.
"Warranty Policy" shall mean a document that describes the terms of the Warranty provided by Privy regarding the reliability of the Certificates it issues, as available at https://repository.privy.id/.
"Private Key" shall mean a key that is a pair of the User's Public Key and is confidential. The Private Key is used to create a Digital Signature and/or decrypt electronic information that has been encrypted with its paired Public Key or vice versa.
"Public Key" means the User's key that can be securely disclosed publicly, contained within the User’s Certificate and is the counterpart of the confidential Private Key used by the User. The Public Key is used by the Relying Party to verify Digital Signatures and/or to encrypt messages so that decryption can only be performed by the Certificate Holder using its paired Private Key or vice versa.
"Registration Authority" or "RA" shall mean a party that contractually cooperates with Privy, which is responsible for identifying and authenticating the Applicants. RA forwards the application process and/or Certificate revocation process to Privy.
"Key Pair" is two mathematically related cryptographic keys issued by Privy, where the key pair is referred to as the Private Key and the Public Key.
"Privacy Notice" shall mean a document that defines Privy's policy in collecting, using, sharing, processing, and securing the User’s Personal Data, as available at https://repository.privyca.id.
"Electronic Certificate Authority" or "CA" shall mean a legal entity that serves as a trustworthy party, which grants and audits Certificates.
“Privy Service" or "Service" shall mean the service of issuing Electronic Certificates, PrivySign, Privy Document Management System, PrivyPass, Electronic Seal, PrivyChat and/or other Privy services declared by Privy from time to time, both through the Website and the Privy Application.
"Warranty Period" shall mean the period of time during which the Certificate has not expired or has not been revoked.
"Subscriber" or "User" shall mean any individual or legal entity/business entity, whose identity is stated and uses the Certificate issued to it by Privy and is legally bound by the CPS and this Agreement.
"Applicant" shall mean an individual or legal entity/business entity submitting application for (including applying for renewal of) a Certificate.
"Relying Party" shall mean an individual or legal entity/business entity that trusts and relies on Certificate issued by Privy.
"Relying Party Agreement" shall mean an Agreement between Privy and Relying Party that determines the rights and responsibilities of the parties, as available at https://repository.privy.id/.
“Privy Personal Plan” shall mean a subscription package for User to access features on the Website or Privy App, including but not limited to using PrivySign on the Website or Privy App and/or third-party platforms.
"Privy" shall mean PT Privy Identitas Digital.
"Electronic Certificate" or "Certificate" shall mean an electronic certificate issued and/or provided by Privy, which contains an Electronic Signature, and identity that shows the legal subject or parties in an electronic transaction.
"Website" shall mean any URLs that use a domain with the address www.privy.id and/or www.privyca.id or other websites declared by Privy from time to time.
"Digital Signature" shall mean a type of Electronic Signature that uses asymmetric cryptographic methods and is proven by a Certificate.
"Electronic Signature" shall mean a signature consisting of Electronic Information attached, associated or related to other Electronic Information used as a verification and authentication tool.
"Uniform Resource Locator" or "URL", shall mean a series of listed websites, containing folder names, language protocols and so on.
2.Role of Privy
Privy in this Agreement shall act as CA, and is responsible for carrying out its functions in accordance with the provisions stated in the CPS.
3.Certificate Holder Obligations
The User as Certificate Holders shall be obliged to:
- Provides accurate, complete and correct information to Privy (either directly or indirectly through RA) when requested, including but not limited to Personal Data which includes national identification number (NIK), full name, date of birth, and/or a copy of identity card issued by Indonesia Government (KTP). Privy can request additional information that may be needed to further verify the User's identity, including but not limited to Family Cards (KK), Driver's License (SIM), Passports and Temporary Stay Permit Cards (KITAS) for Foreigners, and/or certificates from the company as supporting documents for the identification and authentication process of Electronic Certificate applications (including the information contained therein) and/or the requirement to use other features on the Site and Privy Application such as cell phone number, electronic mail address, and biometric data (face record or selfie), IP Address, login information, geolocation, phonebook access and browser version.
- Specifically for the use of Digital Identity service, provide the Personal Data required for the creation of a Privy Account and the issuance of an Electronic Certificate as described in point a above, as well as additional relevant data required by Privy and/or third parties cooperating with Privy, including but not limited to the biological mother’s name.
- The User must immediately update the information and Personal Data that the User has provided to Privy to keep the information and Personal Data correct, accurate and complete from time to time. Any changes, additions, or updates to information and Personal Data must be made immediately by notifying Privy. Privy shall have the right to request additional documents and/or verify changes, additions, or updates to User information and Personal Data. Provisions regarding the use and processing of Personal Data shall be regulated in more detail in the Privacy Notice.
- Be responsible for the use of the Certificate and all required equipment, both hardware and software, to use the Certificate.
- Protect and keep confidential the User's control of the User's Private Key, including the authentication method used to use the Private Key, from unauthorized or unlawful use.
- Review the justification for authorizing the use of the Certificate to ensure it aligns with its intended purpose, whether for individual use or in affiliation with a legal entity/business entity.
4.Representations and Warranties of Certificate Holders
The User as the Certificate Holder represents that:
- The User is the actual party as recognized in the application for issuance of Certificate.
- All statements made during the application registration process are true and have conducted a review and verification of the information contained in the Certificate.
- The User has full power and authority to approve and perform all obligations of the Certificate Holder hereunder.
- The User is a Certificate Holder and not a CA, and does not use the Private Key whose Public Key is included in the Certificate for the purpose of signing other CA’s Certificates.
- All information that the User provides to Privy and the information contained within the Certificate is accurate.
The User as the Certificate Holder warrants:
- Not to use the Certificate before the User checks the validity of the information contained in the Certificate;
- To ensure that only the User has access to the User's Private Key and is responsible for losses and legal consequences arising from the User's negligence and/or error in maintaining control of the User's Private Key;
- Promptly initiate a request for revocation and termination of the use of the associated Certificate and Private Key in the event of suspicious activity, misuse, or leakage of the Private Key associated with the Public Key included in the Certificate.
- Promptly submit an application for the revocation of the Certificate and cease its use, if any information therein becomes inaccurate or ceases to be accurate;
- Immediately cease the use of the Private Key associated with the Public Key whose certificate has been revoked;
- To Carry out Privy's instructions regarding the compromised state or misuse of the Certificate within 48 (forty-eight) hours;
- Not to use a Certificate whose Warranty Period has expired, either due to the validity period has expired or the Certificate has been revoked; and
- To Use the Certificates in accordance with applicable laws and regulations, including all conditions of use as set out in the CPS.
The User agrees that:
- As long as the User has utilized the Electronic Certificate issued by Privy or has not submitted complaints within seven (7) business days, the User is deemed to have approved the issuance of the Electronic Certificate.
- The validity period of the Electronic Certificate shall be a maximum of 2 (two) years.
- Privy will act as a party that stores the User's Private Key after the Key Pair generation and Certificate issuance are carried out, where the use of the User's Private Key must be authenticated through 2 (two) authentication factors determined by Privy.
- Privy as a CA can revoke the Certificate in accordance with the provisions stated in the CPS, this includes violations of the provisions listed herein.
- The information contained in the Certificate is not confidential information and is therefore considered as public information to be used by the Relying Party to rely on the information contained in the Certificate. For this reason, the User agrees that the disclosure of information through the Certificate is not a violation of the rights to the User's Personal Data. Further provisions regarding privacy protection can be found in the CPS and Privacy Notice listed on the Website.
- In cases where the User represents a legal or business entity, the User must review the justification for authorizing the use of the Certificate to ensure it aligns with its intended purpose, whether for individual use or in affiliation with a legal entity/business entity.
- Users are only permitted to use Electronic Certificates for their personal capacity and not to represent any position within a government institution.
- Each Digital Signature created using the Private Key associated with the Public Key in the Certificate is considered the Digital Signature of the Certificate Holder and the Certificate has been received and is still valid (not expired or revoked) at the time of signing.
- Before the Certificate’s validity period ends, the User may request for a renewal of the Certificate.
- If the User requests for the Certificate renewal, Privy will require the User to authenticate using a valid Certificate.
- When the Certificate's validity period ends, the User must apply for a new Certificate in accordance with the Electronic Certificate registration process.
- When the User requests the closure of its Privy Account, the User's Electronic Certificate will be automatically be revoked.
- Upon the successful closure of the User's Privy Account, the User will no longer have access to any features within the Privy Account, including, but not limited to, all documents stored in the User's Privy Account.
- Privy will destroy the User's Private Key upon the expiry of the expiration of the Certificate’s validity period, the User closing its Privy Account, the User requests the revocation of their Electronic Certificate, and/or the User renewing the Certificate's validity period.
- The Privy Personal Plan is non-refundable under any circumstances, including but not limited to the closure of the Privy Account and/or when the User requests the revocation of their Electronic Certificate.
5.Fees
The User will pay all applicable fees for the User’s Certificate in accordance with the terms stated on the Website or through other contractual agreements between the User and Privy, RA, or the Relying Party. In the event that Privy charges a fee for the User’s Certificate, Privy will regulate the refund terms that prioritize the reasonable protection of the User.
6.Intellectual Property Rights
Neither the User nor the User's representatives, including all employees of the User, shall obtain property rights or intellectual property rights, including but not limited to patents, copyrights, brands, and trade secrets, for the content available on the Privy Service (including but not limited to all information, software, information, texts, letters, numbers, color arrangements, images, logos, names, videos and audios, features, and design selection and settings). The User agrees not to use Privy's intellectual property rights without prior written approval from Privy. The User acknowledges that any attempt or actual violation of the provisions relating to intellectual property rights will result in the termination of all User rights related to the Privy Service.
7.Term and Termination
- Term
This Agreement takes effect when the User applies for the issuance of a Certificate either directly to Privy or through RA and shall continue until the end of the Certificate Warranty Period.
- Termination
Privy at its sole discretion may immediately terminate this Agreement with a User if:
- the User violates the provisions contained herein;
- Privy cannot assure and verify the information provided by the User;
- The user carries out activities that may harm Privy; or
- There are changes in industry standards and/or laws and regulations that affect the provisions stipulated herein.
In the event that termination of the Agreement occurs for the aforementioned reasons, Privy may revoke any Certificate issued hereunder.
8.Indemnification and Limitation of Liability
- Privy provides the Service in "as is" or "as available" conditions. As an effort to support the service, Privy has provided control procedures with reasonable control in carrying out its services. The User understands that Privy does not make any representations and warranties in any form that:
- The use of the Privy Service to use the Certificate will always be timely, always work without interruption, or always be free from changes, additions, subtractions, transmissions, damage, loss, removal, concealment caused by intentional and unlawful actions by any party;
- Privy Service can continue to operate and be used simultaneously with other party devices or systems that are not provided or owned by Privy; and/or
- Privy Services will always meet User expectations.
- The User agrees to release Privy from all lawsuits, claims, consequences, or losses arising in connection with:
- failure or delay of electronic transactions; and/or
- interruptions, delays, changes, or unavailability of the Website or Privy App to use the Certificate (including in the event that Privy is unable to carry out or continue some or all of the User's instructions or communications to Privy through the Website or Privy App), caused by events or matters beyond Privy's control, including but not limited to earthquakes, storms, hurricanes, landslides, floods or prolonged droughts, tsunamis, volcanic eruptions, plagues, pandemics, epidemics, radiation or nuclear explosions, fires, accidents, radioactive radiation, shock waves due to airplanes other floating objects at or above the speed of sound, strikes, blockades, boycotts, riots, coups, revolutions, armed conflicts, wars (whether declared or undeclared), acts or threats of terrorism, piracy, sabotages, criminal acts, blackouts, and government actions or policies.
- The only remedy for a damage to a Certificate is to request Privy to use reasonable efforts to repair the damage. Privy is not obliged to repair the damage if:
- the damage occurs because the User's Certificate is misused, damaged, or modified;
- in the event of damage but the User does not immediately report the damage to Privy; or
- the User violates the provisions of this Agreement.
- The User agrees that Privy is not responsible for any consequences or losses arising from the things mentioned above, including but not limited to:
- loss of data:
- loss of revenue, profit, or other income; and/or
- loss, damage or injury arising from the use of the User's Privy Certificate.
- The User agrees to release Privy from all claims, prosecutions, lawsuits and damages whatsoever and from any party arising in connection with:
- The use of Certificates intended for experimentation and/or demonstration;
- The use of information or Personal Data by Privy based on this Agreement, or based on the approval, acknowledgment, authority, power, and/or rights granted by the User to Privy;
- The provision of information or Personal Data by the User to Privy which is conducted in violation of the law or applicable laws and regulations;
- The infringement of rights (including privacy rights and intellectual property rights) of any other party;
- The breach of any agreement, contract, agreement, statement, decision, or document to which the User is a party or bound; and
- The unauthorized use of Privy Certificates, violating the law and the provisions of applicable laws and regulations.
- Privy as a CA will only cover compensation to the Relying Party as stipulated in the Relying Party Agreement and Warranty Policy documents.
9.Continuous Applicability
All provisions of this Agreement relating to intellectual property rights, representations and warranties of the Certificate Holder, and limitations of liability shall survive termination of this Agreement.
10.Notification
Every notification from Privy to the User will be announced through the Website, or sent via electronic mail (e-mail), short message service (SMS), and/or push notification through the Privy Application installed on the User's device registered with Privy. Every notification from the User addressed to Privy shall become effective when the notification is received by Privy via email address helpdesk@privy.id and/or through physical documents sent to PT Privy Identitas Digital at CIBIS NINE, 8th Floor, Jl. T.B. Simatupang No. 2, RT 001, RW 005, East Cilandak Sub-District, Pasar Minggu District, South Jakarta, 12560, Indonesia.
11.Governing Laws
This Agreement shall be subject to and construed under the laws of the Republic of Indonesia.
12.Dispute Resolutions
The User and Privy agree that all disputes or disagreements arising from or relating to matters governed by this Agreement (including all disputes or disagreements caused by unlawful acts or violations of one or more terms and conditions in this Agreement) ("Disputes") will be resolved in the following manner:
- One of the parties, either the User or Privy, must submit written notification to the other party of the occurrence of a Dispute ("Dispute Notification"). Disputes must be resolved by deliberation to reach consensus within a maximum of 30 (thirty) calendar days from the date of the Dispute Notification ("Deliberation Period").
- If the Dispute cannot be resolved by deliberation until the end of the Deliberation Period, the User and Privy agree that the Dispute will be referred and resolved through the Indonesian National Arbitration Board ("BANI") in accordance with the BANI’s Rules and Procedures for arbitration located at Wahana Graha 1st and 2nd floors, Jalan Mampang Prapatan Number 2, Jakarta 12760, with the following provisions:
- The language used in the arbitration shall be Bahasa Indonesia;
- The place of arbitration shall be in Jakarta, Indonesia;
- The user and Privy will collectively appoint 1 (one) arbitrator who will be the sole arbitrator to resolve the Dispute;
- Arbitration costs and legal fees shall be paid by the losing party; and
- The arbitration award shall be final and binding on the User and Privy.
13.Language
In the event that this Agreement is presented in multiple language options and in the event of any inconsistency between one language and another, then the Bahasa Indonesia text shall prevail.
14.Miscellaneous
- User's Responsibility for Violations
The User is responsible for indemnifying Privy or its RA, and contractors, agents, employees, officers, directors, shareholders, and their affiliates and indemnify them against all liabilities, claims, damages, costs, and expenses, including attorneys' fees, caused by the User's intentional or negligent violation of this Agreement, including claims related to unauthorized use of the User's Private Key, unless prior to such unauthorized use, the User has promptly notified Privy to request revocation of the Certificate.
- Changes
Privy may change the Website and any documents contained therein, including but not limited to the CPS, Privacy Notice and Warranty Policy. The User's use of the Certificate after the effective date of the changes announced through the Website is a form of acceptance and approval of the User to such changes. The User is expected to always check the documents available on the Website.
- Waiver
No amendment or waiver of this Agreement shall be effective unless it is made in writing and approved by Privy.
- Assignment
The certificate issued to the User is specifically intended for the User and the User cannot transfer or in any other way assign the Certificate. The User is not allowed to assign any of his rights or obligations hereunder without prior written consent from Privy. Any assignment without consent shall be void and a material breach of this Agreement. Privy may assign its rights and obligations without the User's consent.
- Severability
In the event that part of this Agreement is unenforceable, the remaining provisions shall not be null and void and will continue to apply in full force. Privy has the right to replace and/or change the null provisions with other provisions provided that it is permitted by the applicable laws and regulations.
