Who we are
This Privacy Policy explains how PT PENTAHELIX SISTEM TERPERCAYA, trading as Olio / OlioPay ("Olio," "we," "us," or "our"), processes personal data when you use oliopay.xyz and our related account, payment, verification, and Business Passport services (the "Services").
The entity responsible for determining the purposes and means of the processing described in this Policy is:
- Legal entity: PT PENTAHELIX SISTEM TERPERCAYA
- Registered address: Jl. Pondok Kopi Raya No. 180, Pondok Kopi Village, Duren Sawit District, East Jakarta Administrative City, DKI Jakarta Province, Postal Code: 13460
- Privacy contact: ptpentahelixsistemterpercaya@gmail.com / olio@oliopay.xyz
- Compliance contact: ptpentahelixsistemterpercaya@gmail.com / olio@oliopay.xyz
This Policy describes information processing; it does not itself constitute consent to every activity described below. Where consent is required, we request it through the relevant flow.
Scope and privacy limits
The information we process depends on the features you use, your account type, and the services available in your location. A description of a payment route or provider does not mean that route is available to every user.
Olio uses privacy technologies to reduce unnecessary public exposure of payment information. These technologies do not guarantee anonymity or prevent all links between accounts, identities, and transactions. Information visible to Olio or a service provider can differ from information visible on a public blockchain.
The current Business Passport provides identity-verification status. This Policy does not describe an available revenue score, credit rating, business-quality grade, or portable cryptographically signed financial credential. Before introducing additional uses of personal data for such products, we will provide the relevant information and obtain consent where required.
Personal data we process
Account and authentication information
We process account identifiers, usernames, authentication and session information, and contact details supplied through your selected sign-in method or directly to us. We also process business membership and permission information, such as whether an account is a business owner or administrator.
Identity and business verification information
When you undertake KYC or KYB verification, the configured process may require names, dates of birth, nationality, addresses, government identification details, identity-document images, proof of address, business registration details, business activities, and information about representatives, directors, controllers, or beneficial owners.
Sumsub collects and processes verification submissions through the configured verification flow. Olio receives and stores verification metadata, including applicant and case identifiers, status, check timestamps, rejection labels, associated-person references and roles, and moderation comments. Free-text comments may contain personal information. Our integration may also receive applicant information while retrieving and interpreting verification results, even when only a smaller set of fields is retained in our operational records.
Documents and selfies submitted through Sumsub are handled in its verification environment. This does not mean that Olio receives only a yes/no result or can never process information contained in a verification case.
Facial verification and biometric information
Where the selected verification process requires facial matching or liveness checks, Sumsub may process selfies, facial images, video, and derived facial or biometric information as described in the notices presented during verification. The information collected depends on the configured checks.
Olio does not use verification documents or biometric information for advertising. Where separate consent is required for biometric processing, it must be obtained before that processing begins. Required notices explain the relevant purposes and parties involved.
Verification, fraud, and compliance records
We process verification outcomes, review history, credential eligibility, suspensions, screening indicators returned by enabled checks, and audit records of relevant actions. We may request additional information when necessary to resolve a verification issue, investigate suspected misuse, or meet an applicable obligation.
An automated flag or screening match does not by itself establish wrongdoing. Not every screening or transaction-monitoring product offered by a provider is necessarily enabled for Olio.
Wallet, payment, and blockchain information
Depending on the payment route, we process public addresses and keys, account or username references, transaction hashes, assets, amounts, timestamps, commitments, payment references, recipient information, fee quotes, payment status, settlement information, and related cryptographic data.
Fiat payment or bridge services may require additional customer information, such as contact details, and may generate records linking a user or username with a payment amount and transaction reference. Some session information is encrypted in storage but can be decrypted by Olio's service to operate the transaction.
Wallet recovery and device storage
For the supported recovery flow, Olio stores an encrypted wallet recovery master together with the salt and key-derivation parameters needed for recovery. The application uses your recovery credentials to perform the relevant cryptographic operations. Encrypted recovery material is still sensitive information.
The application also stores wallet owner and viewing secrets in browser local storage for wallet functionality. Those stored values are usable secret material and are not all protected by an additional application-level encryption layer. Browser storage may also contain preferences and cached wallet information.
Business Passport information
We process the business profile, authorized members, verification case references, credential status, publication choices, and related audit records. The public fields are described in Section 7.
Technical and support information
We process technical information necessary for authentication, request handling, security, and troubleshooting, which can include IP addresses, browser or device information, session information, timestamps, and error records. We also process messages, attachments, and contact details you provide when requesting support or reporting an issue.
[CONFIRM THE PRODUCTION LOGGING AND ANALYTICS INVENTORY; IDENTIFY ANY OPTIONAL ANALYTICS DATA AND PROVIDERS BEFORE PUBLICATION.]
Where information comes from
We receive information from you, authorized business members, payment counterparties, authentication and verification providers, payment providers, and blockchain networks. Verification providers may consult public registers and screening sources as part of enabled checks.
If you submit personal information about a representative, director, beneficial owner, or another person, you must have appropriate authority or another lawful basis to provide it and give them the relevant privacy information. This does not remove Olio's own responsibility to provide notices where required.
Purposes and legal bases
We use personal data for defined purposes and rely on the basis applicable to the activity and jurisdiction. We do not treat consent as the basis for all processing or describe fraud prevention itself as a separate legal basis.
| Purpose | Data involved | Applicable basis to be confirmed for publication |
|---|---|---|
| Provide accounts, authentication, wallet recovery, and requested payments | Account, wallet, recovery, and payment information | Performance of a contract or requested precontractual steps, where applicable |
| Carry out identity/business verification and determine passport eligibility | Verification submissions, results, business relationships, and case records | [IDENTIFY THE BASIS FOR EACH CHECK; CITE ANY APPLICABLE LEGAL OBLIGATION. DO NOT ASSUME ALL KYC IS LEGALLY MANDATED FOR OLIO.] |
| Publish a Business Passport at an authorized user's request | The public fields listed in Section 7 and publication evidence | [CONFIRM THE BASIS AND AUTHORITY TO PUBLISH PERSONAL DATA, INCLUDING REPRESENTATIVE OR SOLE-TRADER NAMES] |
| Protect accounts, investigate misuse, and maintain security | Relevant account, technical, payment, and verification records | Legitimate interests where recognized and appropriately balanced; legal obligation where specifically applicable |
| Respond to support requests and resolve disputes | Communications and relevant service records | Contractual necessity or legitimate interests, as applicable |
| Meet accounting, reporting, or other mandatory obligations | Records required by the particular obligation | The applicable legal obligation, identified in our processing and retention records |
| Establish, exercise, or defend legal claims | Relevant communications and transaction or account records | An applicable lawful basis and any additional conditions required for protected data |
| Run optional analytics, if enabled | The categories stated in the applicable notice | Consent before activating optional analytics where required by applicable law; the relevant notice identifies the technologies and purposes. |
Sensitive or specially protected information may require additional conditions or explicit consent. We identify those conditions before the relevant processing. We do not use a general acceptance of this Policy as a substitute.
Verification through Sumsub
Olio integrates with Sumsub for the identity and business verification checks configured for the relevant product. The verification flow identifies the information required and presents the relevant notices and consents before submission.
For processing undertaken on Olio's instructions, the respective responsibilities are governed by our agreement with the provider. Sumsub may also act as an independent controller for particular processing described in its applicable notice. Its role is not necessarily the same for every purpose.
Read the Sumsub Service Delivery Privacy Notice and any additional notices presented during verification. [CONFIRM THIS NOTICE MATCHES THE CONTRACTED SUMSUB ENTITY AND SERVICES.]
Sumsub's SDK handles provider consent collection within its supported flow. Olio remains responsible for its own applicable transparency and consent requirements. Where required, additional notices or consent are presented separately. Acceptance records must be available to demonstrate the relevant choices.
If you decline information or consent necessary for a particular check, that check may not be completed and the associated feature or passport may be unavailable. This does not automatically mean that every Olio service is unavailable.
Business Passport and public profiles
The current Business Passport is an Olio-issued identity-verification status displayed through a hosted public page. Sumsub performs configured checks; Olio applies its credential policy to determine eligibility.
An authorized owner or administrator can choose to publish an eligible passport. The public response contains:
- The profile's public identifier and display name, if supplied.
- Whether the profile represents an individual or a company.
- Its verified status, issuer, and identity-verification scope.
- The credential policy version, verification date, and expiry date.
The public response does not include identity documents, selfies, provider rejection reasons, private transaction history, or wallet recovery secrets.
A published page is accessible to anyone with its link. Search-engine exclusion does not make it access-controlled. Recipients may copy, screenshot, retain, or redistribute information they receive.
Eligibility is reassessed over time. A passport may become unavailable when unpublished, suspended, stale, or expired. Unpublishing removes public availability through Olio's passport response; it does not delete internal verification records or remove copies already held by others.
The passport does not certify revenue, transaction volume, independent customers, creditworthiness, business quality, or general legal compliance. Publishing it does not authorize publication of the business's entire financial history.
Public blockchains and payment privacy
Public blockchain records are replicated by independent network participants. Olio cannot generally erase, amend, or control their copies.
Depending on the route and contract operation, public information can include addresses, registered public keys or identifiers, deposits, withdrawals, amounts, transaction hashes, timestamps, commitments, fees, and contract events. Certain payment-fee events contain payer and amount information. Other information may become linkable through timing, payment references, or data held by counterparties.
Privacy mechanisms can reduce particular links between transactions but do not conceal every amount or all activity. Olio and enabled payment providers may hold off-chain records that connect accounts or business information with transactions.
Do not add identification numbers, private keys, recovery credentials, or unnecessary personal information to public transaction fields. Ordinary identity verification does not require you to give Olio or Sumsub your wallet seed phrase or private key.
Payment disclosure exports
When you choose to export a payment disclosure, the current bundle includes the exact payment amount, commitment, owner public key, salt, Merkle proof information, pool and network identifiers, disclosure timestamp, and a username if included.
These fields allow a recipient to inspect the disclosed payment information and can link the disclosure with other records. This export is not an amount-hiding proof that merely confirms a threshold, and it is not a guarantee that the recipient cannot infer additional information.
Share disclosures only with recipients you intend to receive them. A recipient can retain or redistribute a downloaded export. Olio cannot revoke copies already received. The bundle does not contain the wallet owner secret or recovery master.
Recipients and service providers
We share information necessary for the relevant service or lawful purpose with:
- Authentication and wallet providers, including Privy for the configured authentication services.
- Sumsub for configured verification services.
- Payment, bridge, settlement, or anchor providers involved in the route you select.
- Hosting, database, infrastructure, security, and support providers used to operate the Services.
- Professional advisers where necessary for legal, accounting, audit, or compliance work.
- Authorities where disclosure is required or otherwise lawfully justified.
- Parties involved in a proposed business transfer, subject to appropriate confidentiality, legal basis, and required notices.
Public passport viewers and people to whom you send disclosure exports also receive information as described above.
The following provider schedule must accurately identify the production arrangements:
| Provider / legal entity | Purpose and relevant data | Role | Processing locations and transfer safeguards |
|---|---|---|---|
| Privy | Authentication and configured wallet services; account identifiers and sign-in information. | Responsibilities depend on the service and applicable agreement; independent processing is described in Privy’s privacy notice. | [CONFIRM CONTRACTED ENTITY, PROCESSING LOCATIONS, AND APPLICABLE TRANSFER SAFEGUARDS] |
| Sumsub | Configured identity and business verification; verification submissions, technical information, and results. | Processor for checks performed on Olio’s instructions; independent controller for specified own-purpose processing described in its notice. | [CONFIRM CONTRACTED ENTITY, ENABLED CHECKS, DATA REGION, AND TRANSFER SAFEGUARDS] |
| Circle CCTP / Iris | Cross-chain USDC transfer and attestation, where the selected route uses CCTP; public blockchain messages, transaction references, addresses, and amounts. | External protocol and attestation services; Olio separately processes its own payment-session records. | Public blockchain information is distributed across network participants. [CONFIRM APPLICABLE SERVICE TERMS AND OFF-CHAIN PROCESSING LOCATIONS] |
| Application hosting | Olio-operated application services deployed to a virtual private server; service requests, account data, and operational information. | Olio controls application processing; the infrastructure provider’s role is governed by the hosting arrangement. | [CONFIRM VPS PROVIDER, SERVER COUNTRY/REGION, AND TRANSFER SAFEGUARDS] |
| Database hosting | MongoDB storage for account, payment, verification, and operational records. | Olio controls database processing. MongoDB identifies the database technology, not necessarily the hosting provider. | [CONFIRM SELF-HOSTED OR MANAGED DATABASE, HOSTING PROVIDER, REGION, AND SAFEGUARDS] |
| Operational logs and backups | Application/container logs and database recovery copies. Deployment configuration uses size-based log rotation; backup arrangements require confirmation. | Olio manages operational processing; any external storage provider’s role depends on the actual arrangement. | [CONFIRM LOG ACCESS, BACKUP PROVIDER/LOCATION, RETENTION, AND SAFEGUARDS] |
| Google Gmail — company contact mailbox | Support and privacy correspondence sent to ptpentahelixsistemterpercaya@gmail.com, including sender details, messages, and attachments. | Email service supporting the company contact mailbox; applicable account terms determine the provider’s responsibilities. | [CONFIRM ACCOUNT TERMS AND TRANSFER ARRANGEMENTS; CONFIRM THE SEPARATE OLIO-DOMAIN EMAIL HOST] |
Third parties acting independently may process information under their own notices. Their independent role does not remove Olio's responsibility for disclosures or processing under Olio's control.
Advertising and sale of information
Olio does not sell personal data for monetary consideration or use KYC documents, biometric information, private payment records, or non-public financial history for third-party behavioral advertising.
[VALIDATE THIS STATEMENT AGAINST THE PRODUCTION SDK, ANALYTICS, AND COMMERCIAL INVENTORY BEFORE PUBLICATION.]
International transfers
Providers and infrastructure may process information outside your country. The schedule in Section 10 identifies the relevant locations and safeguards.
For transfers subject to Indonesian personal-data law, we assess the recipient country's level of protection and, where that requirement is not met, the availability of adequate and binding safeguards. Where the preceding requirements cannot be met, the applicable consent requirements must be addressed before transfer. These are not interchangeable options chosen without assessment.
Where another transfer regime applies, we use its required mechanism and provide additional information as required. You can request information about applicable safeguards through the privacy contact.
Retention and deletion
We retain personal data for the period necessary for its stated purpose and any applicable, identified legal obligations. Retention is determined by category and trigger, rather than by an indefinite general need for compliance.
| Record category | Retention period or specific criterion |
|---|---|
| Account and business membership records | [ACTIVE ACCOUNT PERIOD AND DEFINED POST-CLOSURE PERIOD] |
| Verification cases, applicant references, and review metadata | [PERIOD, STARTING EVENT, AND APPLICABLE REQUIREMENT] |
| Passport credentials and publication/action audit records | [PERIOD AND STARTING EVENT; DISTINGUISH PUBLIC AVAILABILITY FROM INTERNAL RETENTION] |
| Provider-held verification documents and biometric information | [AGREED PROVIDER RETENTION AND DELETION ARRANGEMENT, INCLUDING INDEPENDENT PROCESSING WHERE APPLICABLE] |
| Payments, settlement records, and accounting information | [PERIOD AND APPLICABLE REQUIREMENT] |
| Encrypted recovery material | [RETENTION AND ACCOUNT-CLOSURE/DELETION RULE] |
| Security logs, support records, and processed webhook events | [SEPARATE PERIODS BY CATEGORY] |
| Backups | [BACKUP EXPIRY CYCLE AND RESTRICTIONS ON RESTORED DATA] |
If a specific legal hold requires longer retention, we limit it to the affected records and retain them for the applicable purpose and duration. Once retention is no longer justified, we delete or effectively anonymize the relevant information according to the applicable process.
Unpublishing or suspending a passport does not itself delete verification data. Deletion requests are assessed across Olio's records and information processed on our behalf by providers. Provider-independent processing may require a separate request or explanation of the provider's obligations.
Public blockchain records and copies independently retained by disclosure recipients are not generally deletable by Olio. We explain these limits when responding to relevant requests.
Security and recovery
We use safeguards appropriate to the systems and information involved. The architecture includes encrypted recovery records and encrypted fields for some payment-session information, but this does not mean that every record is encrypted in every location or inaccessible to Olio.
No online service, device, or cryptographic system guarantees absolute security. Protect your device, browser profile, authentication access, and recovery credentials. Clearing browser storage or deleting recovery information can affect access to wallet functionality; confirm that you have an appropriate recovery method before doing so.
[CONFIRM IMPLEMENTED ACCESS CONTROLS, SECURITY PROCEDURES, AND RECOVERY INSTRUCTIONS BEFORE PUBLICATION.]
Automated checks and review
Configured verification processes use automated checks, which may include document checks, facial matching, liveness, and screening. Olio also applies credential eligibility rules based on verification results and their freshness. These can prevent publication, require further information, or make an existing passport unavailable.
If you believe a result or restriction is incorrect, contact ptpentahelixsistemterpercaya@gmail.com / olio@oliopay.xyz. We will assess the request and provide the review and challenge mechanisms required by applicable law. A flag or failed check is not a public finding that you committed wrongdoing.
Your rights and choices
Depending on applicable law, you may request information about processing, access, correction, deletion, restriction, portability, withdrawal of consent, or objection to certain processing. You may also have rights concerning decisions based solely on automated processing and the right to complain to a competent authority.
Send requests to ptpentahelixsistemterpercaya@gmail.com / olio@oliopay.xyz. We may ask for proportionate information to verify your identity or authority to act for a business. We respond within the applicable legal period and explain any lawful limitations or retained categories.
Where processing relies on consent, you can withdraw that consent through the relevant control or by contacting us. Withdrawal does not invalidate prior lawful processing. It may affect the feature requiring that consent. Continued processing requires an independently applicable lawful basis; withdrawing consent is not a blanket authorization for indefinite retention.
You can request that a passport be unpublished separately from requesting deletion of personal data.
Age eligibility
The Services are intended for users aged 18 or older. If you believe a child has provided personal data through the Services, contact us so we can assess the information and take appropriate action.
[CONFIRM THIS AGE RULE MATCHES THE TERMS, SUPPORTED MARKETS, AND ONBOARDING CONTROLS.]
Incidents and lawful requests
We investigate personal-data incidents and provide notifications required by applicable law within the applicable deadlines. For incidents subject to Article 46 of Indonesia's Personal Data Protection Law, this includes the applicable written notification requirement within 3 × 24 hours. Our incident procedures must account for the relevant recipients, content, and any applicable exceptions.
We assess official requests for their legal basis, authority, and scope, and limit disclosures as required by law. Where legally permitted and appropriate, we provide notice. Some investigations or legal obligations may restrict what we can disclose about a request.
Indonesian law and other jurisdictions
Where Indonesia's Law No. 27 of 2022 concerning Personal Data Protection applies, our processing is subject to its requirements, including those concerning specific personal data, rights, security, accountability, and international transfers. Biometric and personal financial information require particular attention under that law.
We conduct a data-protection impact assessment where required for high-risk processing. We also assess whether appointment of a data protection officer or another designated contact is required.
If additional jurisdiction-specific notices or rights apply, we provide the necessary information for those services and users. This Policy does not itself establish that Olio offers services in the EEA, United Kingdom, United States, or every other jurisdiction.
Changes and contact
We update this Policy when our processing changes and revise the date above. Where required, we provide advance or additional notice and obtain new consent before the relevant change takes effect.
For questions, requests, or complaints, contact:
Olio Privacy TeamPT PENTAHELIX SISTEM TERPERCAYA
Jl. Pondok Kopi Raya No. 180, Pondok Kopi Village, Duren Sawit District, East Jakarta Administrative City, DKI Jakarta Province, Postal Code: 13460
ptpentahelixsistemterpercaya@gmail.com / olio@oliopay.xyz
You may also contact the competent data-protection authority where applicable law provides that right.