Privacy Policy
Last updated: September 23, 2026
Welcome to Certive. We deeply value your privacy and are committed to protecting your Personal Data. This Privacy Policy explains how Baliola (hereinafter referred to as “Certive,” “We,” or “Platform”) collects, uses, discloses, and secures your information when using the Certive ecosystem, including certive.id and app.certive.id.
By using Certive services, you are deemed to have read, understood, and agreed to all terms in this Privacy Policy. This Privacy Policy applies to all Certive Users, whether as Publishers, Document Holders, Organization members, or Verifiers using services with or without an account.
1. Definitions
1.1. Personal Data is data about an identified or identifiable individual, directly or indirectly, through electronic or non-electronic systems, pursuant to Article 1 point 1 of Law Number 27 of 2022 on Personal Data Protection (“PDP Law”).
1.2. User is any person who creates an account and uses Certive services, whether as a Document Holder, Publisher, or Organization member.
1.3. Publisher is a User who issues a Document via Certive, either as an individual or on behalf of an Organization.
1.4. Document Holder is a User who receives and stores a Document issued for them.
1.5. Verifier is anyone who checks the authenticity of a Document via a Certive verification link, with or without an active account.
1.6. Organization is an entity formed within Certive to issue Documents collectively on behalf of an institution.
1.7. Document is any digital file issued by a Publisher via Certive to record its integrity and provenance.
1.8. Digital Fingerprint (Hash) is a unique representation of a Document's contents, generated on the Publisher's own device, which Certive records to prove Document integrity without ever storing the Document itself.
1.9. Hash Registry is Certive's internal database storing Digital Fingerprints of every Document ever issued, for duplicate checking purposes.
1.10. Crypto Wallet is a blockchain-based digital wallet that can optionally be linked to a Certive account.
1.11. Personal Data Controller is the party determining the purpose and exercising control over Personal Data processing, in this case, Baliola.
1.12. Personal Data Processor is a third party processing Personal Data on behalf of and based on instructions from the Personal Data Controller, as outlined in Section 4.
2. Information We Collect
2.1. Information you provide directly. When creating and using an account, We collect name, email address, and password (stored in encrypted form, never in plain text). When establishing or managing an Organization, We collect institution name and invited member information. When undergoing Publisher eligibility reviews for notary and law firm segments, We may request professional registration numbers or business entity documents as regulated in Article 4.3 of the Terms and Conditions.
2.2. Document-related information. We collect issuance metadata comprising Document type, short description, recipient email address, and issuance timestamp, along with the Digital Fingerprint of the Document. We never collect or store the actual content or original file of the Document itself. Each file is processed directly on the Publisher's device to generate a Digital Fingerprint, and only its derived value is transmitted to Certive. Document type and short description fields are filled directly by the Publisher; Certive does not review or moderate the content of these fields, so Publishers are responsible for not including specific Personal Data, such as health data or children's data, unless strictly necessary, in line with the Publisher responsibility declaration in Article 7.5 of the Terms and Conditions.
2.3. Payment information. For paid Service Plans, transactions are processed through third-party payment service providers. Certive does not store your credit card, debit card numbers, or payment instrument details directly on Our servers.
2.4. Crypto Wallet information. If you optionally link a Crypto Wallet, We only collect your public wallet address. Certive never requests, receives, or stores your Crypto Wallet private key.
2.5. Technical and log information. We collect IP address, device and browser type, authentication and login attempt logs, as well as Hash Registry access logs as regulated in Article 13.6 of the Terms and Conditions, for security and audit trail purposes.
2.6. Information from Verifiers. For Verifiers logged in with an account, We collect performed verification history. For Verifiers not logged in with an account, We only collect standard technical logs (such as IP address) necessary for system security, without additional personal identity data.
2.7. Google Drive Integration Data (OAuth Tokens). If an Organization enables cloud storage integration features (Google Drive), We collect and store authorization tokens (OAuth access token and refresh token) with limited scope access. These tokens are used exclusively to upload and store stamped document files into designated folders specified by the Organization. Certive never reads, accesses, modifies, or stores other files or personal data stored in your Google Drive account outside the dedicated integrated folder.
2.8. PDF Certificate Metadata & Public Verify Data. For the purpose of generating Certificates of Document Integrity and rendering public verification pages (Public Verify), We collect and process technical metadata as well as official publisher profile data. This data includes:
- Document Metadata: File name, document number, document version (v1, v2, etc.), stamping mode (Stamping Mode), file size, description, and official attestation timestamp (Stamped At).
- Publisher & Organization Identity: Publisher name, responsible contact email address, organization name, website, as well as digital wallet addresses (wallet address) of publisher and organization.
- Organization Physical Location Data: Official domicile information of the organization including country (Country), state/province (State), city (City), postal code (Postal Code), and full address (Address).
All above metadata is processed and displayed publicly on PDF certificate sheets and public verification browsers to provide proof of document integrity and provenance transparency.
3. Use of Information
3.1. We use collected information to provide and operate core Certive services, including Document issuance, verification, and revocation.
3.2. We use email addresses to verify account identity, send issuance notifications and Verification Links, and secure your account.
3.3. We use supporting documents submitted by you to perform Publisher eligibility reviews and determine Publisher Trust Levels as regulated in Article 9 of the Terms and Conditions.
3.4. We use Digital Fingerprints and issuance metadata to prevent duplication, detect indications of abuse, and follow up on reports as regulated in Article 11 of the Terms and Conditions.
3.5. We use payment information to process billing for Service Plans and Web3 Staking programs.
3.6. We use collected information to fulfill legal obligations, including compliance with the PDP Law and official requests from competent authorities.
3.7. We use aggregated usage data to enhance the quality, reliability, and security of Certive services.
3.8. We may send marketing communications related to Baliola products and services. These communications are optional, and you may unsubscribe at any time via the link in every email.
4. Data Sharing and Disclosure
4.1. Certive does not sell your Personal Data to any party.
4.2. Mandala Chain. Digital Fingerprints, in derived secret-key value form as regulated in Article 13.3 of the Terms and Conditions, are permanently recorded onto partner blockchain networks. This record contains no Personal Data or Document content, but is public and permanent on the blockchain network so that it cannot be erased by anyone, including Baliola, once successfully recorded. Erasure right implications are further explained in Section 6.5.
4.3. Third-party service providers. We share relevant information with payment service providers, email delivery services, Key Management Service providers, and cloud infrastructure providers as Personal Data Processors acting on Our instructions and bound by confidentiality obligations.
4.4. Document Recipients. When a Publisher issues a Document, recipient email addresses specified are used to send notifications and Verification Links as an inherent part of issuance services.
4.5. Competent authorities. We may disclose information if required by law, court order, or other lawful legal process.
4.6. Business transactions. In the event of a corporate reorganization, merger, acquisition, or business transfer of Baliola, your information may be transferred to successor parties as regulated in Article 23.4 of the Terms and Conditions, with notice to affected Users.
4.7. Third-Party Cloud Storage Providers. If an Organization enables Google Drive integration features, stamped original document files will be automatically transmitted to the connected Organization storage account. In this case, cloud storage service providers (Google Drive / Google Workspace) act as Third-Party Data Processors managing those files based on instructions, terms, and full control of the User Organization, not under Certive's independent control.
4.8. Technical Separation of Google SSO and Organization Google Drive Data Processing. We technically and operationally separate data processing for individual authentication and organization storage integration:
- Google SSO authorization data (under Personal Account menu) is strictly used to verify sign-in (login) identity for individual User accounts.
- Google Drive authorization data (under Organization Settings menu) is strictly used for organization document file delivery processes. Authorization permissions from either feature are never used to grant access or trigger actions in the other feature.
5. Information Security
5.1. All data communications between User devices and Certive systems are encrypted, and passwords as well as sensitive data are stored using industry-standard encryption.
5.2. Digital Fingerprints are generated directly on the Publisher's own device. Original Document files are never sent to or stored on Certive servers—a privacy commitment engineered from the product design stage (privacy by design).
5.3. Secret keys used to derive final hash values are stored in managed Key Management Services, never embedded directly in code, supporting periodic rotation with version tracking.
5.4. Access to the Hash Registry is restricted internally, and every access is logged as part of Baliola's security audit trail.
5.5. Certive temporarily limits repeated failed login attempts, and login sessions automatically expire after a specified duration to prevent unauthorized access.
5.6. We continuously evaluate and update information security practices in line with evolving threats and applicable industry standards.
5.7. Data protection failure notification. In the event of a Personal Data Protection failure affecting the confidentiality, integrity, or availability of your Personal Data, Baliola will issue written notification to you no later than 3 (three) calendar days (3x24 hours) from the moment the failure becomes known, pursuant to Article 46 of the PDP Law, along with handling and recovery steps taken or to be taken. Under certain circumstances impacting public service seriously or widespread community interest, notification will also be delivered publicly.
6. User Rights (Under PDP Law)
Pursuant to Law Number 27 of 2022 on Personal Data Protection, you possess the following rights over your Personal Data.
6.1. Right to obtain information regarding clear identity, legal interest basis, purpose of request and usage, as well as accountability of the party requesting your Personal Data.
6.2. Right to access and receive copies of your Personal Data stored by Us.
6.3. Right to complete, update, and/or rectify errors and/or inaccuracies in your Personal Data. We will process this request no later than 3 (three) calendar days upon receiving a complete application, pursuant to Article 30 of the PDP Law.
6.4. Right to delay and restrict processing of your Personal Data partially or entirely. We will process this request no later than 3 (three) calendar days upon receiving an application, pursuant to Article 41 of the PDP Law.
6.5. Right to terminate processing, erase, and/or destroy your Personal Data, with one important exception to understand: Digital Fingerprints permanently recorded on the blockchain cannot be erased by anyone, including Baliola, due to the tamper-resistant nature of blockchain networks. This record contains no Personal Data or Document content. Account data, issuance metadata, and other personal information stored in internal Certive systems can be erased or anonymized upon your request, except portions required to be retained for legal compliance.
6.6. Right to withdraw consent previously granted for Personal Data processing, provided such withdrawal does not conflict with other statutory provisions.
6.7. Right to object to decision-making actions based solely on automated processing, including profiling, producing legal consequences or significantly impacting you.
6.8. Right to data portability, specifically to obtain and use your Personal Data in a commonly used, machine-readable electronic format, and transfer it to another Personal Data Controller, to the extent technically feasible.
6.9. Right to sue and receive compensation for violations of Personal Data processing concerning you pursuant to applicable laws and regulations.
6.10. Right to lodge complaints with the Personal Data Protection supervisory authority mandated under Article 58 of the PDP Law. As of the update date of this Privacy Policy, such authority has not been officially established by the Government of the Republic of Indonesia. Pending operation of said authority, PDP Law sector compliance complaints may be submitted to the Ministry of Communication and Digital, without prejudice to your right to lodge complaints with the supervisory authority once officially operational.
6.11. You may exercise the rights above by contacting Us through the channel in Section 10. For requests without statutory deadlines under the PDP Law, We will respond within a reasonable period.
8. Data Retention
8.1. Your account data is retained while your account is active, and for a specified period after account closure to satisfy legal, audit, or dispute resolution requirements.
8.2. Issuance metadata and Digital Fingerprints in the Hash Registry are retained for as long as the relevant Document remains actively recorded on the blockchain, as required for duplicate checking reference and continuous verification as regulated in Article 7.4 of the Terms and Conditions.
8.3. Digital Fingerprints recorded on blockchain networks are permanent and carry no retention period, as they cannot be erased by anyone once recorded, including Baliola itself.
8.4. Payment data is retained in accordance with statutory retention periods required by applicable tax and accounting laws in Indonesia.
8.5. Retention and Visibility of PDF Certificates of Document Integrity. PDF Certificate of Document Integrity files along with their verification metadata are stored in Our system for as long as the relevant Document maintains active status. Public access to certificate files and verification sheets is subject to the following document visibility mechanisms:
- Unpublish: If a Document access status is changed to Unpublish, PDF certificate files and public verification pages will be hidden from general public access, but underlying blockchain records (hashes) remain stored permanently.
- Revoke: If a Document is revoked (Revoked), certificates and verification pages will permanently display revocation status labels along with revocation reasons.
- Account Closure: If an Organization account is closed, access to download new PDF certificates will cease, whereas hash records published on the blockchain network remain stored permanently and cannot be erased.
8.6. Upon account closure, Personal Data no longer required will be erased or anonymized, except portions required to be retained for legal compliance as regulated in Section 6.5.
9. Changes to Privacy Policy
9.1. Baliola reserves the right to update this Privacy Policy from time to time to reflect changes in services, technology, or applicable legal provisions, including development of PDP Law implementing regulations and establishment of its supervisory authority.
9.2. Material changes will be notified to Users via registered email or in-platform notifications at least seven calendar days prior to taking effect, aligned with Article 21.2 of the Terms and Conditions.
9.3. Continued use of Certive services after the effective date of changes shall constitute your agreement to the updated Privacy Policy.
10. Contact Us
10.1. Any questions, requests to exercise Personal Data rights, or privacy-related complaints may be submitted via email to: support@baliola.io.
10.2. Baliola will respond to received requests within statutory timeframes set forth in Section 6, or within a reasonable timeframe for requests without fixed statutory deadlines under the PDP Law.
Still have questions about your privacy? Our Team is ready to help you understand how Certive protects your data. Contact Us at support@baliola.io.
Certive · certive.id · app.certive.id — by Baliola · Trustless by Design