Privacy Policy
Last updated May 2026
Privacy Policy
Last updated: May 2026
Overview
UU PDPPDPAGDPRAnoman AI (PT Anoman Artifisial Informasi) operates a managed LLM gateway that routes AI requests through a unified, guarded API. This policy explains how we collect, use, store, and protect personal data. All data from Indonesian customers is stored exclusively in our Indonesia data center (Jakarta). Singapore region is planned for Q3 2026.
Data We Collect
UU PDPWe collect the following categories of personal data:
- Account information: name, email address, company name
- API metadata: request timestamps, model used, token counts, latency
- Usage telemetry: aggregated request patterns for anomaly detection
- Security events: guardrail trigger logs, injection detection scores
Prompts and completions are processed in-region and are not stored beyond the configured retention window (90 days for Pro, 365 days for Enterprise).
How We Use Data
PDPAWe use your data to:
- Provide and operate the Anoman gateway service
- Enforce guardrails and policy rules per your configuration
- Detect anomalous agent behaviour using statistical models
- Calculate usage costs and generate billing records (weighted token model)
- Send transactional emails (account alerts, usage summaries)
- Improve service reliability and performance
We do not sell personal data. We do not use your data to train AI models.
Data Residency
UU PDPAll customer data is stored in our Indonesia data center (Jakarta) to comply with UU PDP (Law No. 27/2022). Our infrastructure stack:
- Compute: container platform, Jakarta
- Database: primary database with hot standby + point-in-time recovery
- Cache: in-memory cache with append-only persistence
- Backups: hourly snapshots to encrypted object storage, 14-day retention
Singapore region (PDPA compliance) is planned for Q3 2026. No customer data is ever processed outside our Indonesia data center unless the customer's chosen model explicitly declares cross-border processing (surfaced on the model detail page).
Retention Periods
GDPR| Data Type | Retention |
|---|---|
| Account data | Duration of account + 90 days after deletion |
| API request logs (Pro) | 90 days |
| API request logs (Enterprise) | 365 days |
| Security/guardrail events | 180 days |
| Billing records | 7 years (tax compliance) |
| Anomaly detection data | 30 days rolling window |
Your Rights
UU PDPPDPAGDPRDepending on your jurisdiction, you have the following rights regarding your personal data:
- Right to access your personal data
- Right to rectify inaccurate data
- Right to erasure ("right to be forgotten")
- Right to data portability
- Right to object to processing
- Right to withdraw consent at any time
To exercise these rights, contact our DPO at [email protected]. We respond within 14 business days.
Third Parties & Processors
GDPRWe share data with the following sub-processors:
- Upstream LLM services — receive prompts for completion. Each model in our catalog declares its data processing region (visible on the model detail page) and is subject to that service's own data processing agreement.
- Infrastructure — compute, database, and cache in our Indonesia data center (Jakarta).
- Resend — transactional email delivery
- Vercel — marketing site hosting and anonymous analytics
We do not share personal data with advertising networks or data brokers.
Contact & DPO
For privacy inquiries, contact our Data Protection Officer: [email protected]. PT Anoman Artifisial Informasi, Jakarta, Indonesia.