Legal
Privacy Policy
This site is a portfolio, not a product. We do not ask you to register, and there is no form to fill in. What we do collect is analytics, so we can see which work people actually read. This page explains exactly what that means.
Effective 8 September 2026 Last updated 8 September 2026
Who we are
Terza Agency (“Terza”, “we”, “us”) is a boutique brand and marketing agency based in Jakarta, Indonesia. This policy covers the website at terza.agency and its subdomains.
For the purposes of Indonesia’s Personal Data Protection Law (Law No. 27 of 2022) we act as the data controller for the data described here. Where a visitor is in the European Economic Area or the United Kingdom, we treat the equivalent GDPR concepts as applying to that visitor.
What we collect
There are no sign-up, contact, comment or newsletter forms on this website. We never ask you to type personal information into a page here. Two categories of data reach us anyway:
Data collected automatically
When you load a page, our analytics providers and our web server record technical information about the visit. This includes your IP address (truncated or masked before it reaches our reports), your approximate location at city level, your device type, browser and operating system, the page you viewed, the page or search that referred you, and how long you stayed.
Data you send us directly
Every contact route on this site is an outbound link, to WhatsApp or to email. If you follow one and get in touch, we receive whatever you choose to send: your name, your phone number or email address, your company, and the content of your message. That conversation happens on WhatsApp’s or your email provider’s infrastructure, under their privacy policies, not ours. We keep the correspondence so we can reply and, if it turns into a project, so we have a record of what was agreed.
We do not buy contact lists, we do not run advertising retargeting pixels on this site, and we do not sell personal data to anyone. Ever.
Why we collect it
- To keep the site working. Server logs let us find broken pages, slow pages and abuse.
- To understand what is read. Aggregate analytics tell us which case studies and articles are worth writing more of.
- To reply to you. If you message us, we use your contact details to answer and to quote for work.
Our lawful bases are consent for analytics and behavioural cookies, and legitimate interest for security logging and for responding to an enquiry you initiated. Where consent is the basis, you can withdraw it at any time; see how to opt out.
Cookies and analytics
We use two third-party analytics tools. Neither is used to build an advertising profile of you.
| Service | What it does | Provider policy |
|---|---|---|
| Google Analytics 4 | Counts visits and page views, and reports them in aggregate. IP addresses are anonymised by Google before we see any report. | policies.google.com |
| Microsoft Clarity | Records anonymised interaction data — scroll depth, clicks and heatmaps — so we can see where a layout confuses people. Text you type is masked by default. | privacy.microsoft.com |
| Google Fonts | Serves the typefaces used across the site. Loading a font makes a request to Google’s servers, which exposes your IP address to them. | policies.google.com |
These services set cookies and similar identifiers in your browser to tell a returning visit from a new one. They are not required for the site to render — every page works with them blocked.
How to opt out
You have several options, none of which will break the site:
- Turn on Do Not Track or Global Privacy Control in your browser settings.
- Install Google’s official Analytics opt-out add-on.
- Block cookies for this domain, or use a content blocker. The site is built to work without any third-party script.
- Browse in a private or incognito window, which discards identifiers when you close it.
If you would rather we deleted analytics data already associated with you, email us and we will pass the request to the relevant provider.
Who we share it with
We share personal data only with the processors listed in the table above, with our hosting provider, which necessarily processes server logs on our behalf, and with professional advisers or authorities where the law requires it.
Those providers are based outside Indonesia, mainly in the United States, so using this site involves an international transfer of the technical data described in section 2. We rely on the providers’ own standard contractual clauses and equivalent safeguards for that transfer.
How long we keep it
- Analytics data: retained by the provider on their default schedule, currently up to 14 months for Google Analytics and 13 months for Clarity.
- Server logs: typically 30 days, then rotated out.
- Correspondence: kept for as long as the client relationship is live, and for up to five years afterwards to meet Indonesian tax and accounting record-keeping requirements. Enquiries that do not become projects are deleted within 24 months.
Your rights
Under the Indonesian PDP Law, and under the GDPR where it applies to you, you may ask us to:
- confirm what personal data of yours we hold, and give you a copy;
- correct anything inaccurate or incomplete;
- delete your data, where we have no overriding legal reason to keep it;
- restrict or object to a particular use, including any use based on legitimate interest;
- withdraw consent you previously gave, without affecting what was lawful before you withdrew it;
- receive your data in a portable, machine-readable format.
Email us to exercise any of these. We will respond within 30 days. There is no charge, and we may ask a question or two to confirm it is really you before we act. If you are not satisfied with our response, you may complain to your local data protection authority.
Security
The whole site is served over HTTPS, so traffic between your browser and our server is encrypted in transit. We apply a strict Content Security Policy that limits which third-party code may run on a page, and we keep access to our hosting and analytics accounts restricted to the people who need it.
No method of transmission over the internet is perfectly secure, and we cannot guarantee absolute security. If a breach ever affects your personal data, we will notify you and the relevant authority as required by law.
Children
This site is aimed at businesses and is not directed at children under 18. We do not knowingly collect data from children. If you believe a child has sent us personal data, contact us and we will delete it.
Changes to this policy
We may update this policy as the site or the law changes. The “last updated” date at the top of the page always reflects the current version. If a change materially affects how we handle your data, we will make that clear on this page rather than quietly editing it.
Contact us
Questions about this policy, or about the data we hold on you, go to:
- hello@terza.agency
- +62 8512 8008 792
- Based in
- Jakarta, Indonesia
See also our Terms & Conditions.