Privacy Notice
This Privacy Notice (privacy policy / statement) explains how Floc Intelligence, LLC, in close collaboration with partners such as but not limited to PT Pionir Energi Hijau and Harrat Global Holdings, Inc, collects, uses, discloses, retains, and protects personal data through floc.systems and the Floc farm platform.
About this Privacy Notice
Floc Intelligence, LLC ("Floc," "we," "us"), in close collaboration with partners such as but not limited to PT Pionir Energi Hijau and Harrat Global Holdings, Inc, provides low-cost sensing and an AI agent for high-density fish and shrimp farms. This Privacy Notice is a notice (pemberitahuan) and statement to data subjects (subjek data) about the personal data processed through this marketing website (floc.systems) and the separate farm platform it links to (app.floc.systems). Where the two services differ, this Notice says so.
Under fair information practices, a privacy notice must identify the purposes of processing, be clear and easy to find, accurate and complete, and written so that a lay reader can understand it. Our primary legal obligation is Indonesia's Personal Data Protection Law (UU PDP, Law No. 27 of 2022), fully enforceable since October 2024, because that is where most of our farm operators are located. Sections 1 through 10 below are written primarily around UU PDP — including its legal bases, deadlines, and data-subject rights — and are not a GDPR or CCPA policy adapted for Indonesia.
We also operate a pilot farm in Escondido, California, and this is a public website that may be visited from the EU, the EEA, or the UK. What we collect, how long we retain it, and to whom we disclose it is the same regardless of where you are. Two short sections near the end describe what is specifically different for California residents (CCPA) and for EU/EEA/UK visitors (GDPR) — principally legal-basis language, certain additional rights, and, for the EU/EEA/UK specifically, a consent banner for the activity beacon.
Personal Data Controller
Floc Intelligence, LLC is the Personal Data Controller (Pengendali Data Pribadi) for the processing described in this Notice. For questions or requests concerning personal data, contact admin@floc.systems — the same address listed for pilot enquiries on our farm login page.
Collection of Personal Data
Under the principle of collection limitation (pembatasan pengumpulan), personal data is collected only where relevant to a stated purpose. The following is the personal data this site and the farm platform collect today.
Account credentials
When you sign in on our farm login page, you provide an email address or phone number and a password. That information is sent to our backend at app.floc.systems, where the password is hashed with bcrypt before storage. Passwords are not stored or logged in plain text.
Session cookie (identifier)
After you sign in, a cookie named floc.sid maintains your authenticated session. It is scoped to .floc.systems so it works across this site and the platform, is httpOnly (page JavaScript cannot read it), and lasts 30 days if you select "Keep me signed in," or clears when you close your browser if you do not. Browser identifiers of this kind are personal data where they enable recognition of an individual user.
Activity beacon (usage data)
A first-party script (js/track.js) runs on pages of this site. It records: a random session ID kept in your browser's sessionStorage and not tied to your name or account; a random visitor ID in a first-party cookie named floc.vid so a returning browser can be distinguished from a new one, also not tied to your name or account; the page path visited; the referring site; labelled clicks on a short list of buttons and links (Farm login, the WhatsApp button, the demo video link, a language switch); how long certain sections remain in view; and a country derived server-side from your IP address. The IP address itself is not stored — only the country it resolves to.
WhatsApp buttons on this site open a chat to Floc's WhatsApp number through a wa.me link. This site does not collect your phone number for that handoff — WhatsApp handles it. Information you share inside that chat afterwards is governed by WhatsApp's own privacy policy, not this Notice.
Google sign-in
"Continue with Google" on our farm login page is a placeholder. Selecting it shows a message only — no personal data is sent to or received from Google through that button today. If that changes, this Notice will be updated before the feature is enabled.
Farm production data
Once you are signed in as a farm owner, the platform (app.floc.systems, a separate application from this website) records production data for your farm — water quality readings, feed records, pond cycles. That processing is performed by the platform, not by this marketing site, and is included here because it forms part of the same product offered by the same controller.
Legal Bases for Processing
Under Article 20 of UU PDP, every processing of personal data must rest on one of six legal bases (landasan hukum). Consent (persetujuan) is one of those six — not a blanket requirement for all processing. The bases and how they apply to Floc are as follows:
- Consent (persetujuan) — freely given, specific, informed, and unambiguous, and withdrawable at any time. We do not currently rely on consent for the processing listed above: there is no marketing opt-in and no non-essential cookie for which we request acceptance outside the EU/EEA/UK banner described later. If that changes, consent will be requested separately for the specific purpose.
- Performance of a contract (pemenuhan kewajiban perjanjian), or steps taken at your request before entering a contract — the basis for account credentials, the session cookie, and farm production data. These are required to provide the account and dashboard you requested.
- Compliance with a legal obligation (pemenuhan kewajiban hukum) — for example, retaining certain records where Indonesian law requires it.
- Protection of vital interests (kepentingan vital) — an emergency basis for protecting life. Not one we expect to need for a farm-management product; listed because it is one of the six bases under Article 20.
- Public interest or official authority (kepentingan umum) — generally applicable to public bodies, not a private company such as ours. Listed for completeness under Article 20.
- Legitimate interests (kepentingan yang sah), balanced against your interests and fundamental rights — the basis for the activity beacon. What that beacon collects is kept deliberately narrow (see Collection of Personal Data above) so that this balance is not tipped against the data subject. Where legitimate interests are relied upon, a purpose, necessity, and balancing assessment is applied.
Retention of Personal Data
Personal data is not retained longer than necessary for the purposes of processing (pembatasan penyimpanan / storage limitation). Retention periods for the categories above are as follows:
- Passwords are stored only as bcrypt hashes, for as long as the account exists.
- The session cookie clears itself: after 30 days if you selected "Keep me signed in," otherwise when you close your browser.
- The activity beacon's session ID is held in sessionStorage, which the browser clears when the tab or browser session ends. The visitor ID cookie (floc.vid) lasts up to 400 days, or until you clear this site's cookies.
- Beacon events, the country they resolve to, and the anonymous visitor ID are retained on the backend for as long as they remain necessary to understand how the site is used. The source IP address is never retained. The visitor ID is a random value, not a name.
- Your saved language choice (floc.lang) remains in this browser until you clear its storage.
- The floc.region cookie expires after 30 days and carries no visitor identifier — only a coarse region label used for the consent banner.
- Your activity-beacon consent choice (floc.consent), when set, remains in this browser until you clear its storage.
Account and farm data are retained while the account is active. If you close your account or request deletion, we act on that request in accordance with your rights as a data subject (see Rights of the Data Subject below), subject to any retention required by law.
Cookies and Local Storage
Six items of browser storage support the processing described in this Notice: the floc.sid session cookie (an identifier); the floc.vid first-party cookie the activity beacon uses to recognise a returning browser; the sessionStorage entry used by the activity beacon for its session ID; a localStorage entry (floc.lang) that remembers your language preference for subsequent visits; a first-party floc.region cookie that records whether your visit resolved to the EU, EEA, or UK so the consent banner can be shown where required; and, for visitors from those regions who have made a choice, a localStorage entry (floc.consent) that stores that choice so the banner is not shown again.
Outside the EU, EEA, and UK, this site does not display a cookie-consent banner. None of the storage above is used for advertising or cross-site tracking; UU PDP does not require the EU-style opt-in banner pattern associated with Europe's ePrivacy rules; and the storage used here is either necessary to provide the account you requested or a narrowly scoped first-party measurement tool. If that changes, a banner will be shown before any additional tracking is introduced. For visitors in the EU, EEA, or UK, see the section below.
Cross-Border Transfer of Personal Data
Some of the processors listed above operate infrastructure outside Indonesia — in particular Vercel and Google, which run global networks. UU PDP (including Article 56) places conditions on the transfer of personal data across borders, including consideration of whether the destination provides an equivalent level of protection (kesetaraan / adequacy). We are working with counsel to confirm and document the safeguards that apply to each vendor above; until that review is complete, this section should be read as identifying the issue rather than as a final statement of compliance measures.
Security of Personal Data
The Controller is obliged to implement reasonable technical and organisational measures to protect personal data against unauthorised access, disclosure, alteration, destruction, or loss. Measures currently in place include:
- Passwords are hashed with bcrypt on the backend and are not stored or logged in plain text.
- The session cookie is httpOnly, so page JavaScript — ours or a third party's — cannot read it.
- IP addresses behind activity-beacon events are not stored; only the resolved country is retained.
- No system is free of risk. If a personal data protection failure occurs, we will notify affected data subjects and the relevant authority as required by law — see the next section.
Rights of the Data Subject
Recognition of the rights of the data subject (hak-hak subjek data) is central to personal data protection. Under Articles 6–13 of UU PDP, data subjects have, among others, the following rights:
- Right to information (hak atas informasi) — to know when personal data about you is, will be, or has been processed, and for what purposes.
- Right of access (hak akses) — to obtain a description of the personal data we hold about you, the purposes of processing, retention periods, and recipients, in an accessible format and plain language (Pasal 7).
- Right to rectification (hak memperbaiki) — to complete, update, or correct inaccurate or incomplete personal data (Pasal 6).
- Right to erasure and restriction (hak menghapus dan membatasi) — to end processing, erase, or destroy personal data about you, subject to legal retention requirements (Pasal 8 and Pasal 11).
- Right to data portability (hak portabilitas) — to obtain your personal data in a structured, commonly used, machine-readable format, or to have it transferred to another controller where systems can communicate securely (Pasal 13).
- Right to object (hak untuk menolak) — to object to processing that rests on legitimate interests (including the activity beacon), or to suspend or limit processing in the circumstances provided by law (Pasal 11).
- Withdrawal of consent (penarikan persetujuan) — where processing rests on your consent, to withdraw that consent at any time, without affecting the lawfulness of processing carried out before withdrawal.
- Rights related to automated decision-making and profiling — to object to decisions based solely on automated processing, including profiling, that produce legal or similarly significant effects (Pasal 10). Floc does not currently take such automated decisions about individuals through this site.
To exercise any of these rights, email admin@floc.systems, state which right you wish to exercise, and identify the relevant account. We will first take steps reasonably necessary to confirm that you are the account holder, so that another person cannot delete or export your data.
There is a working process for these requests today: an administrator runs an internal export or deletion procedure against the account you name. Contact us, and we will act on your request promptly, consistent with our obligations under UU PDP.
You also have the right to an effective remedy, including raising a concern with the relevant Indonesian authority. UU PDP's dedicated Personal Data Protection Authority had not yet been formally established at the time this Notice was written; until it is, personal-data-protection matters are overseen by the Ministry of Communication and Digital Affairs (Kementerian Komunikasi dan Digital / Komdigi), through its Directorate General of Digital Space Supervision. Data subjects who suffer loss from unlawful processing may also have rights to compensation under Pasal 12, subject to applicable law.
Notification of Personal Data Protection Failure
Where a failure of personal data protection (kegagalan pelindungan data pribadi) occurs, UU PDP requires the Controller to notify both affected data subjects and the relevant supervisory authority in writing within 3×24 hours (72 hours) of becoming aware of the failure. That notification will identify the personal data involved, when and how the failure occurred, and the measures being taken. If such an event occurs, we will meet that deadline and communicate those facts clearly.
If you are in the EU, EEA, or UK
We do not currently have EU, EEA, or UK farm customers, but this is a public website, and the GDPR (and the UK's UK GDPR) may apply to a visit from those regions regardless of where our company or customers are established. Everything above about what we collect, how long we retain it, and to whom we disclose it applies to you as described. This section covers what is specifically different.
GDPR's six legal bases (Article 6) correspond closely to UU PDP's — consent, contract, legal obligation, vital interests, a public-interest task, and legitimate interests — and the same practices map onto them in the same way: account credentials and the session cookie rest on contract; the activity beacon rests on legitimate interests outside these regions; and for visitors from the EU, EEA, or UK specifically, the activity beacon runs only after consent, for the reason explained below.
In addition to the rights described above, GDPR also provides:
- The right to restrict processing — to ask us to pause processing of your personal data in certain circumstances, without requiring immediate erasure.
- The right to withdraw consent at any time for processing that runs on consent for you specifically: the activity beacon, gated by the banner described below.
To exercise these rights, contact admin@floc.systems.
You may also lodge a complaint with the data protection authority in your EU/EEA country of residence, or with the UK's Information Commissioner's Office (ICO) if you are in the UK, whether or not you contact us first.
Under ePrivacy rules applicable in the EU, EEA, and UK, opt-in consent is required before non-essential cookies or similar browser storage are used. UU PDP does not impose the same banner pattern. If Vercel's edge network resolves your visit to one of those regions, a banner asks for consent before the activity beacon runs; visitors elsewhere on this site do not see that banner. If you do not see a banner and expected to, you may already have made a choice on an earlier visit — clearing this site's data in your browser settings will present the choice again.
Floc Intelligence, LLC has no establishment in the EU or UK. Transfers of EU/UK personal data to a US company, or to the processors listed above, are subject to GDPR transfer requirements (for example, standard contractual clauses, and whether an EU representative must be appointed under Article 27). That analysis forms part of the legal review noted elsewhere in this Notice and is not yet complete.
If you are a California resident
We operate a pilot farm in Escondido, California, so California's privacy law (the CCPA, as amended by the CPRA) applies to individuals using this product in California as well as to visitors. What we collect, how long we retain it, and to whom we disclose it, above, describes that processing — it is the same for California residents as for other users.
California residents have the following rights under the CCPA:
- Know and access — what personal information we have collected about you, and the sources of that information.
- Delete — to request erasure, subject to legal retention requirements.
- Correct — to request correction of inaccurate personal information.
- Opt out of sale or sharing — see below; we do not sell or share personal information for cross-context behavioural advertising.
- Limit use of sensitive personal information — we do not collect the categories CCPA defines as "sensitive" (such as precise geolocation, government ID numbers, or health data) through this site, so there is nothing to limit under that heading.
- Non-discrimination — we will not deny service, charge a different price, or provide a lesser experience because you exercised any of these rights.
We do not sell personal information, and we do not "share" it for cross-context behavioural advertising within the meaning of the CCPA. Accordingly, a "Do Not Sell or Share My Personal Information" link is not applicable to processing on this site today.
To exercise these rights, email admin@floc.systems. An authorised agent may submit a request on your behalf — please state that when you write.
Children
Floc is intended for farm owners and operators running a business. We do not knowingly collect personal data from children through this site or the platform. If you believe a child's personal data has been provided to us, email admin@floc.systems and we will delete it.
Changes to this Notice
This Privacy Notice may be updated as the product, the legal review noted above, or applicable law changes. When we update it, we will revise the date at the top of this page. For changes that materially affect signed-in farm accounts, we will endeavour to notify account holders directly in addition to posting the updated Notice here.
Contact
Questions about this Privacy Notice, or requests concerning your personal data: admin@floc.systems. The Personal Data Controller is Floc Intelligence, LLC, in close collaboration with partners such as but not limited to PT Pionir Energi Hijau and Harrat Global Holdings, Inc.