Indonesia Privacy Addendum

Effective Date: 14 July 2026

Last Updated: 14 July 2026

This Indonesia Privacy Addendum (the “Indonesia Addendum”) supplements the Fraw Privacy Policy and applies to individuals located in Indonesia who access or use the Fraw mobile application, website, software, official functions, extensions, creator tools, and related services collectively referred to as the “Service.”

The Service is operated by Untitled Labs Limited (“Fraw,” “we,” “us,” or “our”), a company incorporated in Hong Kong.

This Indonesia Addendum should be read together with the Privacy Policy, the Fraw Terms & Conditions, and any other notices presented through the Service.

Capitalized terms not defined in this Indonesia Addendum have the meanings given in the Privacy Policy.

If this Indonesia Addendum conflicts with the Privacy Policy, this Indonesia Addendum will apply to individuals in Indonesia to the extent required by applicable Indonesian law.

Nothing in this Indonesia Addendum limits any right or protection that cannot lawfully be limited or waived.

1. Scope and Applicable Indonesian Law

This Indonesia Addendum provides additional information concerning Fraw’s collection, use, disclosure, storage, transfer, retention, deletion, and other processing of personal data in connection with offering the Service to individuals in Indonesia.

Where applicable, our processing may be subject to Indonesian laws and regulations concerning:

  • personal-data protection;
  • electronic systems and electronic transactions;
  • private electronic-system operators;
  • user-generated content;
  • consumer protection;
  • child protection;
  • cybersecurity;
  • content governance;
  • app-based and digital services;
  • payment and creator-reward activity; and
  • other applicable legal or regulatory requirements.

These laws and regulations may include, as amended or replaced from time to time:

  • Law No. 27 of 2022 concerning Personal Data Protection;
  • Government Regulation No. 71 of 2019 concerning the Operation of Electronic Systems and Transactions;
  • Minister of Communication and Informatics Regulation No. 5 of 2020 concerning Private Electronic System Operators;
  • Government Regulation No. 17 of 2025 concerning Governance of Electronic System Operation in Child Protection; and
  • other implementing, sector-specific, or successor laws and regulations.

For purposes of applicable Indonesian personal-data protection law:

  • Fraw may act as a Personal Data Controller where it determines the purposes and means of processing personal data;
  • you may be referred to as a Personal Data Subject; and
  • service providers that process personal data on Fraw’s behalf may act as Personal Data Processors or in an equivalent service-provider capacity.

The exact application of a law, regulation, registration, approval, or requirement may depend on the nature of the Service, Fraw’s operations, regulatory interpretation, and the provisions in force at the relevant time.

2. Fraw as an Electronic Service Provider

Fraw operates an electronic service that may allow users to:

  • create and manage accounts;
  • submit prompts, images, and other content;
  • request AI-generated or transformed output;
  • save generated content;
  • create private extensions;
  • publish extensions;
  • view or use public extensions;
  • purchase subscriptions or credits;
  • participate in creator and reward programs;
  • communicate with Fraw; and
  • otherwise interact with electronic information and documents.

Where applicable law requires Fraw to register, file, notify, appoint a representative, maintain records, or complete another regulatory process as a private electronic-system operator or similar service provider, Fraw may take the steps it considers necessary to comply.

Fraw may restrict, delay, suspend, or discontinue the Service or particular features in Indonesia while:

  • assessing a legal or regulatory requirement;
  • applying for or maintaining a registration;
  • responding to a regulator;
  • implementing required technical or organizational controls;
  • updating legal notices;
  • responding to a lawful access or content-removal request; or
  • determining whether continued operation is legally or operationally feasible.

Availability of the Service in an Indonesian app store does not guarantee that every feature, creator function, reward, payment method, payout method, or item of content is available in Indonesia.

3. Personal Data We Process

We may process the categories of personal data described in the Privacy Policy, including the following.

3.1 Account and Profile Information

This may include:

  • name;
  • username;
  • display name;
  • creator name;
  • profile information;
  • email address;
  • account identifier;
  • authentication information;
  • Apple or Google login information;
  • subscription tier;
  • account status;
  • account preferences; and
  • other account information.

3.2 Device and Technical Information

This may include:

  • device type;
  • operating system;
  • application version;
  • browser type;
  • language settings;
  • IP address;
  • approximate location derived from IP address;
  • device or app identifiers;
  • network information;
  • session information;
  • timestamps;
  • crash logs;
  • diagnostic information;
  • performance information;
  • security logs; and
  • error reports.

3.3 Usage and Activity Information

This may include information about:

  • pages or screens viewed;
  • functions used;
  • button clicks;
  • generation requests;
  • session duration;
  • subscription activity;
  • credit activity;
  • top-up activity;
  • extension use;
  • creator activity;
  • referral activity;
  • Diamond activity;
  • moderation activity;
  • reporting activity; and
  • other interactions with the Service.

3.4 Transaction and Subscription Information

This may include:

  • subscription status;
  • plan type;
  • purchase date;
  • top-up purchase;
  • renewal status;
  • cancellation status;
  • transaction identifier;
  • payment-provider identifier;
  • refund status;
  • chargeback status;
  • currency;
  • entitlement information; and
  • limited billing information received from an app store or payment provider.

Fraw generally does not directly receive complete payment-card information where transactions are processed by Apple, Google, or another payment provider.

3.5 User Content and Generated Content

This may include:

  • prompts;
  • text;
  • images;
  • photographs;
  • files;
  • instructions;
  • reference materials;
  • generated images;
  • transformed images;
  • extension assets;
  • extension descriptions;
  • thumbnails;
  • before-and-after images;
  • generated examples;
  • saved gallery content;
  • moderation information; and
  • other content submitted to or generated through the Service.

3.6 Creator and Reward Information

This may include:

  • creator eligibility;
  • publication status;
  • extension activity;
  • creator profile information;
  • Diamond records;
  • qualifying and non-qualifying activity;
  • withdrawal requests;
  • payout status;
  • payout amount;
  • payout-provider identifier;
  • transaction reference;
  • verification status;
  • fraud-prevention signals;
  • tax or compliance status received from a provider where applicable; and
  • communications relating to creator functions.

3.7 Support, Complaint, and Enforcement Information

This may include:

  • support requests;
  • privacy requests;
  • content complaints;
  • intellectual-property complaints;
  • user reports;
  • security reports;
  • grievance records;
  • investigation information;
  • enforcement actions;
  • correspondence;
  • evidence submitted by users; and
  • records relating to legal or regulatory requests.

3.8 Face-Containing Images

We may process Face-Containing Images and related non-identifying image-processing information as described in Section 3 of the Privacy Policy.

Fraw does not create or store biometric templates, faceprints, face-geometry scans, or biometric identifiers from Face-Containing Images.

Fraw does not use Face-Containing Images to:

  • identify you as a real-world person;
  • authenticate your account;
  • verify your identity;
  • perform facial recognition;
  • match your identity against another database; or
  • create a biometric identification profile.

An ordinary photograph containing a face is not necessarily processed by Fraw as biometric data.

Where an image, its contents, or the manner in which it is processed qualifies as specific, sensitive, or otherwise specially protected personal data under applicable law, Fraw will handle it in accordance with applicable legal requirements.

4. Sources of Personal Data

We may collect personal data:

  • directly from you;
  • automatically when you access or use the Service;
  • from Apple, Google, or another login provider;
  • from Apple App Store, Google Play, or another app store;
  • from payment processors;
  • from payout providers;
  • from cloud-hosting and storage providers;
  • from AI image-generation and image-processing providers;
  • from analytics, diagnostics, and performance providers;
  • from security, fraud-prevention, and moderation providers;
  • from customer-support and communication providers;
  • from another user who submits content, a report, or a complaint concerning you;
  • from public authorities or professional advisers; and
  • from other sources described in the Privacy Policy or disclosed to you.

If you provide personal data relating to another person, including an image containing another person’s face, you are responsible for ensuring that you have the permission, consent, authority, or other lawful basis required to:

  • provide the information to Fraw;
  • request the relevant processing;
  • store the information;
  • include the information in an extension;
  • publish the information where applicable; and
  • allow other users to use the relevant extension or content where applicable.

5. Purposes of Processing

We may process personal data for the purposes described in the Privacy Policy and this Indonesia Addendum.

5.1 Providing and Operating the Service

We may process personal data to:

  • create and manage accounts;
  • authenticate users;
  • maintain account security;
  • provide subscriptions;
  • manage credits and top-ups;
  • process generation requests;
  • provide requested Output;
  • save gallery content;
  • provide Rebuild, Blend, and official functions;
  • enable private and published extensions;
  • operate creator and Diamond functionality;
  • provide account history;
  • provide customer support; and
  • maintain the availability and functionality of the Service.

5.2 Processing Images and AI Requests

We may process personal data to:

  • receive prompts, images, files, and instructions;
  • transmit submitted content to relevant AI service providers;
  • generate or transform content;
  • return generated Output;
  • maintain technical reliability;
  • troubleshoot failed generation;
  • perform safety checks;
  • prevent abuse; and
  • comply with applicable legal requirements.

5.3 Transactions and Billing

We may process personal data to:

  • verify subscriptions and purchases;
  • provide purchased entitlements;
  • process renewals;
  • administer cancellations;
  • investigate transaction problems;
  • process or track refunds;
  • respond to chargebacks;
  • maintain accounting records; and
  • prevent payment fraud.

5.4 Creator and Reward Administration

We may process personal data to:

  • assess creator eligibility;
  • administer extension publication;
  • review creator content;
  • calculate Diamonds;
  • identify eligible or ineligible usage;
  • prevent self-dealing and manipulation;
  • process withdrawal requests;
  • track payout status;
  • maintain creator and accounting records; and
  • comply with tax, payment, regulatory, and legal requirements.

5.5 Safety, Security, and Fraud Prevention

We may process personal data to:

  • secure accounts and systems;
  • detect unauthorized access;
  • investigate suspicious activity;
  • detect fraud, spam, bots, abuse, or manipulation;
  • moderate prohibited content;
  • protect children;
  • enforce regional restrictions;
  • prevent misuse of credits or rewards;
  • investigate related accounts or devices;
  • maintain system logs;
  • respond to cybersecurity incidents; and
  • protect Fraw, users, service providers, and third parties.

5.6 Service Improvement

We may process personal data to:

  • monitor reliability;
  • diagnose errors;
  • measure performance;
  • understand feature use;
  • improve user experience;
  • develop and test features;
  • improve moderation and safety controls;
  • improve fraud-prevention systems; and
  • maintain service quality.

Where appropriate, we may use aggregated, de-identified, anonymized, or non-face operational information for these purposes.

We do not use Face-Containing Images to train general-purpose artificial-intelligence or machine-learning models, including general-purpose image-generation, facial-recognition, biometric-identification, or identity-matching models, unless we obtain separate consent where required by applicable law.

5.7 Communications

We may process personal data to:

  • send account notices;
  • send transaction confirmations;
  • send subscription or billing information;
  • provide support;
  • send security alerts;
  • provide policy notices;
  • communicate regulatory or regional restrictions;
  • respond to complaints; and
  • send marketing communications where permitted.

5.8 Legal and Regulatory Compliance

We may process personal data to:

  • comply with Indonesian or other applicable laws;
  • maintain regulatory registrations;
  • respond to a court order;
  • respond to a lawful governmental request;
  • respond to a regulator or law-enforcement agency;
  • comply with cybersecurity obligations;
  • process content-removal requests;
  • preserve information;
  • establish, exercise, or defend legal claims;
  • maintain accounting, tax, and audit records; and
  • protect legal rights and public safety.

6. Legal Bases for Processing

Where applicable law requires a legal basis, we may process personal data based on one or more of the following:

  • your explicit or other valid consent;
  • performance of an agreement with you;
  • steps taken at your request before entering into an agreement;
  • compliance with a legal obligation;
  • protection of your vital interests or those of another person;
  • performance of a task in the public interest or exercise of lawful authority, where applicable;
  • Fraw’s legitimate interests or those of another party, where permitted and appropriately balanced against your rights;
  • processing of information you voluntarily provide for a specified purpose;
  • prevention, detection, investigation, or enforcement relating to fraud, abuse, security incidents, or unlawful conduct; and
  • another lawful ground permitted under applicable law.

Fraw does not necessarily rely on every listed ground for every processing activity.

Where processing is necessary to:

  • create or operate your account;
  • perform a transaction;
  • provide a generation you request;
  • maintain security;
  • prevent fraud;
  • comply with law;
  • maintain regulatory compliance; or
  • enforce the Service,

Fraw may rely on a lawful ground other than consent where permitted by applicable law.

7. Consent

Where Fraw relies on consent, we may request consent through:

  • an account notice;
  • an in-app screen;
  • a website notice;
  • a setting;
  • a checkbox;
  • a button;
  • an affirmative upload or submission action;
  • a cookie or analytics preference tool; or
  • another appropriate affirmative action.

A consent request may identify:

  • the personal data or categories of personal data involved;
  • the purposes of processing;
  • the consequences of giving or refusing consent;
  • how consent may be withdrawn;
  • how to contact Fraw; and
  • other information required by applicable law.

Consent to one purpose does not automatically constitute consent to a materially different purpose.

Silence, inactivity, or continued use will not replace an express consent where express consent is required by applicable law.

7.1 User-Initiated AI Processing

By voluntarily submitting a prompt, image, file, instruction, or other content and initiating an AI-generation, transformation, Rebuild, Blend, or extension-based request, you instruct Fraw to:

  • receive and process that content;
  • transmit the content to Fraw’s systems;
  • transmit the content to relevant service providers;
  • perform the requested generation or transformation;
  • perform related safety, security, moderation, debugging, or reliability checks; and
  • return the requested Output.

This instruction does not authorize Fraw or its providers to use your Face-Containing Images for:

  • unrelated advertising;
  • resale;
  • independent profiling;
  • facial recognition;
  • biometric identification;
  • identity matching; or
  • unrelated model training.

8. Withdrawal of Consent

Where processing is based on your consent, you may withdraw that consent using an available:

  • account control;
  • privacy setting;
  • cookie preference control;
  • device setting;
  • unsubscribe link;
  • website control;
  • in-app control; or
  • support channel.

You may also email hi@fraw.ai with the subject line “Indonesia Privacy Request.”

Withdrawal of consent:

  • does not affect processing lawfully carried out before withdrawal;
  • does not require deletion where retention is required or permitted by law;
  • does not affect processing based on another lawful ground;
  • may prevent Fraw from continuing to provide a feature; and
  • may result in restriction or termination of the relevant Service function where the personal data is necessary to provide it.

Where required by applicable law, Fraw will take reasonable steps to make withdrawal of consent reasonably accessible.

9. Face-Containing Images and AI Processing

The Service may allow you to upload, capture, edit, transform, rebuild, blend, save, publish, or otherwise process images containing human faces.

The collection, purpose, sharing, storage, security, retention, and deletion of Face-Containing Images are described in detail in Section 3 of the Privacy Policy.

When you initiate an image-generation or transformation request:

  • Fraw may transmit the submitted image and related prompt or instruction to one or more AI image-generation or image-processing providers;
  • processing may occur outside Indonesia;
  • providers may process information to provide the requested output;
  • providers may also process limited information for technical, safety, security, debugging, abuse-prevention, reliability, or legal purposes permitted under their applicable terms and service configuration;
  • provider retention may vary according to provider terms and technical settings;
  • Fraw does not authorize providers to use the information for unrelated advertising, resale, facial recognition, biometric identification, independent profiling, or unrelated model training; and
  • Fraw may use more than one provider or route requests between providers for reliability, availability, quality, or operational reasons.

You must not submit an image or personal data relating to another person unless you have the rights, permissions, consent, authority, or other lawful basis necessary to do so.

10. Personal Data Relating to Other People

If you submit or publish personal data relating to another person, you represent that you are authorized to provide the data and request the relevant processing.

This may include:

  • a photograph;
  • a group photograph;
  • a reference image;
  • a likeness;
  • a name;
  • a creator asset;
  • an extension example;
  • a before-and-after image; or
  • other information relating to another person.

You must not submit or publish personal data in violation of:

  • privacy rights;
  • publicity rights;
  • confidentiality obligations;
  • intellectual-property rights;
  • child-protection laws;
  • data-protection law;
  • contractual restrictions; or
  • other applicable rights.

Fraw may remove, restrict, preserve, or disclose content where reasonably necessary to investigate a complaint, enforce its policies, protect another person, or comply with law.

11. Service Providers and Other Recipients

We may disclose or make personal data available to the following categories of recipients.

11.1 Cloud Hosting and Storage Providers

These providers may store or process:

  • account information;
  • uploaded content;
  • generated content;
  • gallery content;
  • extension assets;
  • logs;
  • backups;
  • transaction information; and
  • other Service data.

11.2 AI Providers

AI image-generation and image-processing providers may process:

  • prompts;
  • uploaded images;
  • reference images;
  • instructions;
  • related technical information; and
  • generated Output.

11.3 Authentication Providers

Apple, Google, or another login provider may process information necessary to authenticate your account.

11.4 App Stores and Payment Providers

Apple App Store, Google Play, payment processors, and other billing providers may process information relating to:

  • subscriptions;
  • purchases;
  • renewals;
  • refunds;
  • chargebacks;
  • entitlements; and
  • payment compliance.

11.5 Payout Providers

Where creator payout functionality is available, a payout provider may process:

  • identity information;
  • tax information;
  • payment-account information;
  • compliance information;
  • sanctions information;
  • withdrawal requests; and
  • payout transactions.

The payout provider may collect this information directly under its own terms and privacy policy.

11.6 Analytics and Performance Providers

These providers may process:

  • device information;
  • app activity;
  • usage information;
  • event information;
  • performance information;
  • crash reports; and
  • diagnostic data.

11.7 Safety, Security, and Moderation Providers

These providers may process limited information to:

  • detect prohibited content;
  • investigate fraud;
  • prevent abuse;
  • secure accounts;
  • respond to security incidents;
  • identify spam or bots; and
  • support policy enforcement.

11.8 Support and Communication Providers

These providers may process:

  • contact information;
  • support communications;
  • complaint records;
  • notification information; and
  • account-related messages.

11.9 Professional Advisers

We may disclose information to:

  • lawyers;
  • accountants;
  • auditors;
  • insurers;
  • consultants;
  • compliance advisers; and
  • other professional advisers.

11.10 Corporate Transactions

We may disclose information in connection with:

  • a merger;
  • acquisition;
  • financing;
  • restructuring;
  • asset sale;
  • insolvency;
  • investment transaction; or
  • similar corporate event.

11.11 Public Authorities

We may disclose information to:

  • courts;
  • regulators;
  • law-enforcement authorities;
  • cybersecurity authorities;
  • consumer-protection bodies;
  • data-protection authorities;
  • electronic-system regulators;
  • tax authorities;
  • ministries; and
  • other competent authorities,

where required or permitted by law.

Fraw does not sell your personal data.

Fraw does not authorize personal data to be used for unrelated cross-context behavioural advertising unless Fraw provides any notice, consent mechanism, or other choice required by applicable law.

12. Personal Data Processors

Where a service provider processes personal data on Fraw’s behalf, Fraw may require the provider to be subject to appropriate:

  • contractual obligations;
  • confidentiality duties;
  • security requirements;
  • processing instructions;
  • data-protection terms;
  • retention restrictions;
  • access controls;
  • platform terms;
  • technical safeguards; or
  • legal obligations.

The precise safeguards may vary depending on:

  • the service;
  • provider;
  • information involved;
  • processing location;
  • available provider terms;
  • technical configuration; and
  • applicable law.

Fraw may replace, add, or remove service providers from time to time.

13. International Transfers and Processing Outside Indonesia

Fraw is established in Hong Kong and uses service providers, infrastructure, and technical systems that may operate outside Indonesia.

Personal data relating to users in Indonesia may be transferred to, stored in, accessed from, or otherwise processed in:

  • Hong Kong;
  • Singapore;
  • the United States;
  • Japan;
  • Korea;
  • countries in which Fraw’s service providers operate; and
  • other countries or regions reasonably necessary to provide or support the Service.

The information transferred may include:

  • account and authentication information;
  • device and technical information;
  • usage and diagnostic data;
  • transaction and subscription information;
  • support and complaint records;
  • prompts;
  • uploaded images;
  • Face-Containing Images;
  • generated content;
  • extension assets;
  • creator and Diamond records;
  • payout-status information;
  • fraud and security records; and
  • other information described in the Privacy Policy.

We may transfer personal data outside Indonesia where reasonably necessary to:

  • provide the Service;
  • process generation requests;
  • maintain accounts;
  • store content;
  • process transactions;
  • provide customer support;
  • secure the Service;
  • moderate content;
  • prevent fraud;
  • operate creator features;
  • maintain regulatory compliance;
  • comply with law; and
  • protect legal rights.

Where required by applicable Indonesian law, Fraw may take measures such as:

  • assessing the level of data protection in the destination;
  • applying contractual safeguards;
  • entering into data-processing terms;
  • obtaining consent where required;
  • performing provider due diligence;
  • implementing access controls;
  • encrypting information in transit;
  • encrypting information at rest where supported;
  • limiting processing instructions;
  • maintaining transfer records;
  • notifying or consulting an authority where required; or
  • using another legally recognized transfer mechanism.

No statement in this Indonesia Addendum guarantees that personal data will be stored exclusively in Indonesia.

14. Data Localization and Regulatory Records

Fraw does not generally promise that all personal data relating to Indonesian users will be stored in Indonesia.

However, Fraw may:

  • maintain selected records in Indonesia;
  • replicate selected technical or regulatory records;
  • use an Indonesian hosting or service provider;
  • maintain local compliance documentation;
  • store regulatory registration information;
  • maintain complaint or content-removal records;
  • maintain local contact information; or
  • apply another localization measure,

where required by applicable law, a regulator, or Fraw’s compliance arrangements.

Information maintained for regulatory or electronic-system purposes may include:

  • corporate and registration information;
  • service descriptions;
  • domain and application information;
  • system categories;
  • contact information;
  • complaint records;
  • content-removal records;
  • security information;
  • access-request records;
  • audit records; and
  • other required information.

15. Data Retention

We retain personal data only for as long as reasonably necessary for the purposes described in the Privacy Policy and this Indonesia Addendum, unless a longer period is required or permitted by law.

Retention periods may depend on:

  • whether your account remains active;
  • whether content is saved;
  • whether an extension remains active, archived, published, unpublished, or previously used;
  • whether a subscription remains active;
  • whether a transaction, refund, or chargeback remains unresolved;
  • whether creator or payout activity remains under review;
  • whether a complaint, dispute, or investigation remains open;
  • fraud-prevention requirements;
  • security requirements;
  • moderation requirements;
  • tax, accounting, or audit obligations;
  • regulatory registration obligations;
  • legal claims;
  • government requests;
  • preservation obligations; and
  • backup-retention schedules.

General retention periods and practices are described in Sections 3.6 and 9 of the Privacy Policy.

These include retention relating to:

  • temporary processing images;
  • gallery images;
  • original input images;
  • draft extensions;
  • private extensions;
  • public extensions;
  • archived extensions;
  • unpublished extensions;
  • account deletion;
  • transaction records;
  • creator and payout records;
  • fraud records;
  • support records;
  • security logs; and
  • backups.

16. Deletion, Destruction, and De-Identification

When personal data is no longer reasonably necessary and retention is not required or permitted, Fraw may:

  • delete it;
  • remove it;
  • destroy it;
  • de-identify it;
  • anonymize it;
  • aggregate it; or
  • otherwise securely dispose of it.

Deletion from active systems may not result in immediate deletion from:

  • encrypted backups;
  • disaster-recovery systems;
  • legal-preservation systems;
  • security records;
  • audit records;
  • transaction records;
  • fraud records; or
  • regulatory records.

Backup copies are not ordinarily used for active processing and may remain until overwritten or deleted according to applicable backup-retention practices.

17. Your Rights in Indonesia

Subject to applicable law, verification requirements, exceptions, and the relevant provisions being in force, you may have the rights described below.

17.1 Right to Information

You may request information concerning:

  • Fraw’s identity;
  • the basis of processing;
  • the purposes of processing;
  • the type and relevance of personal data;
  • the period of retention;
  • the intended use;
  • accountability concerning processing; and
  • other information required by law.

17.2 Right of Access

You may request access to personal data concerning you that Fraw processes, subject to applicable exceptions.

17.3 Right to Obtain a Copy

Where required by law, you may request a copy of personal data concerning you in an available or legally required format.

17.4 Right to Correction

You may request that Fraw:

  • correct inaccurate personal data;
  • complete incomplete personal data;
  • update outdated personal data; or
  • otherwise rectify information concerning you.

17.5 Right to Deletion or Destruction

You may request deletion or destruction of personal data where available under applicable law, subject to lawful retention grounds.

17.6 Right to Withdraw Consent

You may withdraw consent where processing is based on consent.

17.7 Right to End Processing

Where provided by applicable law, you may request that Fraw end, limit, or suspend particular processing.

17.8 Right to Object to Automated Decisions

Where applicable law provides such a right, you may object to a decision based solely on automated processing that produces legal consequences or a significant impact on you.

17.9 Right to Data Portability

Where required by applicable law and technically feasible, you may request that personal data you provided be made available in a structured, commonly used, machine-readable, or interoperable format.

17.10 Right to Complain

You may submit a privacy complaint or grievance to Fraw.

You may also contact a competent Indonesian authority where you have a legal right to do so.

17.11 Right to Compensation or Legal Remedies

You may have a right to seek compensation or another remedy where provided by applicable law.

17.12 Other Rights

You may exercise additional rights available under applicable Indonesian law.

18. Limits and Exceptions to Rights

Privacy rights are not absolute.

Fraw may decline, limit, defer, or request clarification of a request where permitted by law, including where:

  • Fraw cannot reasonably verify your identity;
  • Fraw cannot verify your authority to act for another person;
  • the request relates to another person’s information;
  • fulfilling the request would adversely affect another person’s rights;
  • retention is required by law;
  • information is required for a transaction;
  • information is required for tax, accounting, or audit purposes;
  • information is required for fraud prevention;
  • information is required for security;
  • information is required for moderation;
  • information is required for creator-program administration;
  • information is required for payout or payment processing;
  • information is subject to a legal hold;
  • information is needed to establish or defend a legal claim;
  • the request is fraudulent, abusive, excessive, or manifestly unfounded;
  • disclosure would compromise security or fraud-detection systems;
  • compliance would violate another legal obligation; or
  • another lawful exception applies.

19. How to Exercise Your Rights

You may exercise available rights by:

  • using relevant account controls;
  • using gallery deletion controls;
  • using account-deletion controls;
  • using privacy or cookie preference controls;
  • contacting Fraw support; or
  • emailing hi@fraw.ai with the subject line “Indonesia Privacy Request.”

Your request should include sufficient information for us to:

  • identify the relevant account;
  • understand the right you wish to exercise;
  • identify the information concerned;
  • verify your identity or authority; and
  • communicate with you.

We may request additional information where reasonably necessary to:

  • verify your identity;
  • prevent unauthorized disclosure;
  • prevent unauthorized deletion;
  • locate the relevant data;
  • determine whether an exception applies; or
  • complete the request.

Do not send:

  • passwords;
  • full payment-card information;
  • government identity documents;
  • tax records;
  • biometric information; or
  • other highly sensitive information,

unless Fraw specifically requests it through an approved secure method.

Where required by applicable law, Fraw will respond within the applicable period.

The response or completion period may depend on:

  • verification;
  • complexity;
  • scope;
  • the number of systems involved;
  • legal exceptions;
  • third-party processing;
  • archived information;
  • backup systems; and
  • technical circumstances.

20. Indonesia Privacy Contact and Complaints

Users in Indonesia may submit privacy-related questions, complaints, requests, or grievances to:

  • Indonesia Privacy Contact
  • Untitled Labs Limited
  • 20/F, Harbourside HQ
  • 8 Lam Chak Street
  • Kowloon Bay, Kowloon
  • Hong Kong

Email: hi@fraw.ai

Suggested subject line: Indonesia Privacy Request

Please provide:

  • the email address or account identifier connected with your account;
  • a description of the request or complaint;
  • the relevant date or approximate period;
  • any previous support reference;
  • the content or extension concerned where applicable; and
  • the resolution you are seeking.

Fraw may:

  • acknowledge the complaint;
  • verify your identity;
  • investigate the issue;
  • request additional information;
  • provide an explanation;
  • correct information;
  • remove or restrict content;
  • take corrective action;
  • preserve relevant records;
  • decline the request where permitted; or
  • refer the matter to another responsible team or service provider.

Nothing in this section prevents you from contacting a competent Indonesian authority where you are legally entitled to do so.

21. Data Protection Officer or Responsible Contact

Where applicable Indonesian law requires Fraw to appoint a data-protection officer, responsible person, representative, or other designated contact, Fraw may appoint that role and publish the relevant details through:

  • this Indonesia Addendum;
  • the Privacy Policy;
  • the Service;
  • Fraw’s website;
  • a regulatory registration;
  • an app-store listing; or
  • another reasonable method.

Until a separate contact is published, privacy questions may be sent to hi@fraw.ai.

22. Security Safeguards

We use reasonable technical, administrative, and organizational measures designed to protect personal data against:

  • unauthorized access;
  • unauthorized disclosure;
  • unlawful use;
  • alteration;
  • misuse;
  • loss;
  • destruction;
  • interference; and
  • other security risks.

These measures may include, where appropriate:

  • encryption in transit;
  • encryption at rest where supported;
  • authentication;
  • authorization controls;
  • role-based access;
  • system logging;
  • monitoring;
  • vulnerability management;
  • security testing;
  • incident response;
  • backup and recovery;
  • access restrictions;
  • service-provider safeguards;
  • fraud-detection systems;
  • abuse-prevention controls;
  • content-safety controls; and
  • employee or contractor confidentiality obligations.

No security method, system, transmission, or storage process is completely secure.

Fraw cannot guarantee absolute security.

You are responsible for:

  • maintaining the confidentiality of your login credentials;
  • securing devices used to access Fraw;
  • avoiding unauthorized account sharing;
  • reviewing suspicious account activity; and
  • notifying Fraw promptly if you suspect unauthorized access.

23. Personal Data Breaches

If Fraw becomes aware of a personal-data breach affecting personal data within its control, Fraw may:

  • investigate the incident;
  • contain the incident;
  • take remediation measures;
  • preserve relevant records;
  • assess the affected data and risks;
  • notify affected individuals;
  • notify a competent Indonesian authority;
  • notify law enforcement or a cybersecurity authority;
  • coordinate with service providers; and
  • provide protective recommendations.

Where required by applicable law, notification may include information concerning:

  • the personal data affected;
  • when and how the incident occurred;
  • the potential impact;
  • remediation steps;
  • protective steps users may take; and
  • contact information.

The timing, form, content, and recipients of a notification may depend on:

  • applicable law;
  • the nature of the incident;
  • the information involved;
  • the number of people affected;
  • risk of harm;
  • technical investigation;
  • law-enforcement requests;
  • security considerations; and
  • other legal restrictions.

Nothing in this Indonesia Addendum means that every security event constitutes a legally reportable personal-data breach.

24. Cybersecurity Incidents and Electronic-System Security

Fraw may process and preserve information in connection with:

  • unauthorized system access;
  • malware;
  • account compromise;
  • service disruption;
  • fraud;
  • scraping;
  • automated attacks;
  • content abuse;
  • manipulation;
  • suspicious traffic;
  • security vulnerabilities;
  • regulatory investigations; and
  • other cybersecurity events.

Fraw may disclose information to:

  • cybersecurity authorities;
  • law-enforcement agencies;
  • infrastructure providers;
  • app stores;
  • payment providers;
  • affected users;
  • professional advisers; and
  • other relevant parties,

where required or permitted by law.

Fraw may retain security logs and related records for the period reasonably necessary to:

  • investigate incidents;
  • protect the Service;
  • comply with law;
  • support regulatory registration;
  • respond to authorities;
  • prevent repeat incidents; and
  • establish or defend legal claims.

25. Lawful Requests and Regulatory Access

Fraw may receive requests, orders, notices, or inquiries from:

  • Indonesian courts;
  • law-enforcement agencies;
  • ministries;
  • regulators;
  • cybersecurity authorities;
  • consumer-protection bodies;
  • data-protection authorities;
  • tax authorities;
  • electronic-system authorities; and
  • other competent bodies.

Subject to applicable law, Fraw may:

  • verify the request;
  • seek clarification;
  • preserve relevant information;
  • disclose personal data;
  • provide electronic records;
  • provide technical or registration information;
  • restrict or remove content;
  • restrict an account;
  • restrict a feature;
  • cooperate with an investigation;
  • challenge an invalid or excessive request; or
  • take another legally permitted action.

Fraw will seek to limit disclosures to information reasonably relevant to the valid request, taking into account:

  • the authority relied upon;
  • the scope of the request;
  • privacy and confidentiality obligations;
  • technical feasibility;
  • user rights;
  • public safety; and
  • lawful grounds for objection or challenge.

Fraw may be legally prohibited from notifying you about a request, investigation, preservation instruction, disclosure, or enforcement action.

26. Content Reports and User-Generated Content

The Service may contain Published Extensions and other user-generated content.

Fraw may process personal data in order to:

  • receive user reports;
  • investigate unlawful content;
  • investigate intellectual-property complaints;
  • investigate unauthorized use of images;
  • investigate privacy complaints;
  • address child-safety issues;
  • address impersonation;
  • address fraud or deceptive content;
  • enforce platform rules; and
  • respond to lawful content-removal or access-blocking requests.

Information processed may include:

  • reporter contact information;
  • reported-user information;
  • content identifiers;
  • extension information;
  • account records;
  • evidence;
  • device information;
  • IP addresses;
  • transaction information;
  • moderation decisions; and
  • communications.

Fraw may preserve relevant records after content is removed where reasonably necessary for:

  • legal compliance;
  • fraud prevention;
  • repeat-offender enforcement;
  • dispute resolution;
  • audit;
  • security;
  • regulatory reporting; and
  • protection of legal rights.

27. Children’s Personal Data

Indonesian law may impose additional requirements concerning children’s use of electronic systems and processing of children’s personal data.

The Service is not intended to be used by a child in Indonesia where applicable law requires:

  • parental or guardian consent;
  • verification of parental or guardian authority;
  • age assurance;
  • age verification;
  • child-specific notices;
  • age-appropriate design;
  • restricted profiling;
  • restricted advertising;
  • restricted publication;
  • restricted creator participation;
  • child-specific safety controls; or
  • another safeguard

that Fraw has not made available.

A parent or legal guardian must not permit a child to use the Service where doing so would violate applicable law or Fraw’s eligibility requirements.

Where Fraw becomes aware that it has unlawfully processed a child’s personal data, Fraw may:

  • suspend or restrict the account;
  • request information concerning age;
  • request information concerning parental authority;
  • disable publication;
  • disable creator or reward functions;
  • disable transactions;
  • remove content;
  • delete or de-identify personal data;
  • preserve information required by law; and
  • take other legally permitted action.

Fraw does not knowingly use children’s personal data for:

  • targeted advertising;
  • unlawful profiling;
  • behavioural monitoring prohibited by law; or
  • other prohibited processing.

If you believe that a child has provided personal data to Fraw unlawfully, contact hi@fraw.ai with the subject line “Indonesia Child Privacy.”

28. Age and Child-Safety Assessment

Fraw may assess whether particular features, content, or creator functions present risks to children.

Fraw may:

  • apply an age classification;
  • restrict a feature by age;
  • restrict public extensions;
  • restrict publication;
  • restrict creator rewards;
  • restrict direct interaction;
  • add safety notices;
  • apply content filters;
  • restrict personalized recommendations;
  • prevent access to certain material;
  • request age information; or
  • discontinue a function in Indonesia.

These actions may differ from controls used in another country or region.

29. Automated Systems and Moderation

Fraw may use automated, manual, or hybrid systems to:

  • process generation requests;
  • detect unsafe content;
  • identify prohibited content;
  • detect fraud or manipulation;
  • identify spam or automated activity;
  • assess creator eligibility;
  • calculate Diamonds;
  • prioritize moderation;
  • protect accounts;
  • enforce regional restrictions; and
  • support cybersecurity.

These systems may:

  • flag content;
  • reject a generation;
  • restrict an extension;
  • delay a transaction;
  • refer activity for review;
  • restrict a creator reward;
  • suspend an account; or
  • take another automated action.

Where applicable law grants a right relating to a decision based solely on automated processing that produces legal consequences or a significant effect, you may contact Fraw to request available information or review.

Any such right remains subject to:

  • identity verification;
  • security needs;
  • fraud-prevention requirements;
  • intellectual-property rights;
  • confidential business information;
  • applicable exceptions; and
  • technical feasibility.

30. Marketing Communications

Fraw may send marketing or promotional communications where permitted by law.

You may opt out of marketing email by:

  • using the unsubscribe link; or
  • contacting hi@fraw.ai.

Opting out of marketing does not prevent Fraw from sending:

  • account notices;
  • billing information;
  • purchase confirmations;
  • security alerts;
  • support communications;
  • policy updates;
  • legal notices;
  • service notices;
  • regulatory notices; or
  • creator and payout communications.

31. Cookies, SDKs, and Similar Technologies

Fraw may use:

  • cookies;
  • local storage;
  • mobile SDKs;
  • app-instance identifiers;
  • device identifiers;
  • authentication technologies;
  • analytics technologies;
  • crash-reporting technologies;
  • fraud-prevention technologies;
  • security technologies; and
  • similar tools.

These technologies may be used for:

  • authentication;
  • account security;
  • user preferences;
  • service operation;
  • analytics;
  • diagnostics;
  • performance;
  • fraud prevention;
  • abuse prevention; and
  • service improvement.

Additional information is available in the Fraw Cookie Policy.

Where consent is required for optional analytics, advertising, or similar technologies, Fraw will seek consent through an appropriate notice or preference control.

32. Creator, Diamond, and Payout Data

If you participate in creator, extension-publication, Diamond, withdrawal, or payout functionality, Fraw may process personal data to:

  • assess eligibility;
  • administer creator activity;
  • review extensions;
  • calculate Diamonds;
  • determine qualifying activity;
  • investigate fraud or self-dealing;
  • process withdrawal requests;
  • track payout status;
  • resolve payout disputes;
  • comply with tax requirements;
  • comply with accounting and audit obligations;
  • maintain regulatory records; and
  • enforce the Terms and Creator Policy.

Creator payout and withdrawal functionality may not be available in Indonesia.

The display or accumulation of Diamonds does not guarantee that:

  • withdrawal is available in Indonesia;
  • a payout provider supports Indonesia;
  • a provider will approve your account;
  • you satisfy legal or tax requirements;
  • you satisfy identity or payment verification;
  • a registration or regulatory approval has been completed; or
  • Diamonds create an immediate or unconditional entitlement to cash.

Where a third-party payout provider is used, that provider may independently collect:

  • identity information;
  • tax information;
  • payout-account information;
  • banking information;
  • sanctions information; and
  • other compliance information.

That information is governed by the payout provider’s own terms, privacy policy, and legal obligations.

33. Consumer Transactions

Personal data relating to subscriptions, credits, top-ups, refunds, renewals, cancellations, and app-store transactions may be processed to:

  • perform the transaction;
  • provide purchased entitlements;
  • verify payment status;
  • prevent fraud;
  • address complaints;
  • respond to chargebacks;
  • comply with consumer-protection obligations;
  • maintain records; and
  • establish or defend legal claims.

Where a transaction is processed by Apple, Google, or another provider, that provider acts under its own terms and privacy policy.

34. Regulatory Registration Information

Where Fraw completes or maintains an Indonesian regulatory registration, Fraw may publish or provide information such as:

  • Fraw’s legal name;
  • country of incorporation;
  • registered address;
  • regulatory registration number;
  • service name;
  • website domain;
  • application name;
  • service category;
  • contact information;
  • local representative or contact information, where applicable;
  • complaint channel; and
  • other information required by law.

Publication of regulatory information does not mean that Fraw:

  • is incorporated in Indonesia;
  • has a permanent establishment in Indonesia;
  • has an Indonesian office;
  • has appointed a local representative for every legal purpose; or
  • provides every feature in Indonesia.

35. Language

This Indonesia Addendum may be made available in English and Bahasa Indonesia.

Where a Bahasa Indonesia translation is provided, it is intended to improve accessibility and understanding.

If there is an inconsistency between language versions:

  • the English version will control to the extent permitted by applicable law; and
  • the Bahasa Indonesia version or mandatory local interpretation will apply to the extent required by applicable Indonesian law.

The absence of a translation does not waive any mandatory language requirement.

36. Changes to This Indonesia Addendum

Fraw may update this Indonesia Addendum to reflect:

  • changes to the Service;
  • changes to personal-data practices;
  • changes to service providers;
  • changes to technical systems;
  • changes to Indonesian law;
  • regulatory guidance;
  • PSE or other registration requirements;
  • child-protection requirements;
  • security or operational requirements; or
  • improvements to clarity.

If Fraw makes a material change, Fraw may provide notice:

  • through the Service;
  • by email;
  • on Fraw’s website;
  • through an app-store update; or
  • by another reasonable method.

The revised Indonesia Addendum will become effective on the date stated at the top.

Your continued use after the effective date means that you acknowledge the revised Indonesia Addendum.

Where additional consent is required by law, continued use alone will not replace the required consent.

37. Contact Us

For questions, concerns, requests, complaints, or grievances concerning this Indonesia Addendum or Fraw’s privacy practices, contact:

  • Untitled Labs Limited
  • 20/F, Harbourside HQ
  • 8 Lam Chak Street
  • Kowloon Bay, Kowloon
  • Hong Kong
  • Privacy and Support Email: hi@fraw.ai
  • Suggested subject line: Indonesia Privacy Request
  • Company Registration: 71095371

Where Fraw appoints an Indonesia-specific representative, data-protection contact, electronic-system contact, or other local responsible person, the relevant contact information may be published through:

  • this Indonesia Addendum;
  • the Privacy Policy;
  • Fraw’s website;
  • the Service;
  • an app-store listing;
  • an Indonesian regulatory register; or
  • another reasonable method.

This Indonesia Addendum forms part of the Fraw Privacy Policy.