Effective Date: 20 August 2026
Last Updated: 24 August 2026
This Privacy Policy explains how Layarva, operated by CV DNA Konsultan ("Layarva", "we", "us", or "our"), collects, receives, uses, processes, stores, shares, transfers, protects, retains, and deletes Personal Data when you use the Layarva website, dashboard, Studio, digital signage player, Queue Management, Public API, integrations, and other Layarva Services.
We seek to process Personal Data lawfully, transparently, proportionately, only as necessary, and consistently with the purposes for which it is processed.
1. Scope
This Privacy Policy applies to processing through:
- the Layarva website;
- web applications;
- Accounts and Workspaces;
- Studio;
- media management;
- content management;
- signage players;
- device management;
- Screen management;
- Queue Management;
- the Public API;
- customer support;
- Google Sign-In;
- Google APIs;
- third-party integrations;
- billing; and
- other Layarva features.
2. Layarva's Role in Data Processing
Depending on the context, Layarva may act as a Personal Data Controller or a Personal Data Processor.
2.1 As a Controller
Layarva generally acts as a Controller for data used for:
- Account creation;
- authentication;
- Subscriptions;
- billing;
- customer support;
- security;
- device management;
- administration; and
- platform operations.
2.2 As a Processor
Layarva may act as a Processor where a Customer uses the Services to store or process Personal Data for purposes determined by the Customer.
In that context, the Customer is responsible for determining the appropriate lawful basis and purpose of processing.
The Controller-Processor relationship may be further governed by a Data Processing Addendum.
3. Data We Process
3.1 Account Data
We may process:
- name;
- email address;
- user identifier;
- organization name;
- role;
- permissions;
- profile information;
- authentication information;
- account preferences; and
- other administrative information.
3.2 Organization and Workspace Data
We may process information relating to:
- organizations;
- Workspaces;
- team members;
- roles;
- permissions;
- Screens;
- channels;
- playlists;
- templates;
- projects;
- resources; and
- organization configuration.
3.3 Subscription and Billing Data
We may process:
- Subscription type;
- start date;
- expiration date;
- invoices;
- payment status;
- transaction references;
- billing information; and
- payment-administration records.
Certain payment-method details may be processed directly by a payment provider and may not be stored by Layarva.
3.4 Customer Content
We may process Content you upload or create, including:
- images;
- videos;
- audio;
- animations;
- text;
- fonts;
- documents;
- designs;
- templates;
- playlists;
- schedules;
- files;
- API payloads; and
- other materials.
Content may be processed for functions including:
- upload;
- storage;
- editing;
- rendering;
- transcoding;
- caching;
- synchronization;
- distribution;
- backup; and
- playback.
3.5 Screen and Device Data
We may process technical information about Screens and Devices, including:
- device identifiers;
- device UUIDs or similar identifiers;
- pairing information;
- platform;
- operating system;
- application version;
- IP address;
- heartbeat;
- connection status;
- Screen status;
- synchronization status;
- cache status;
- timestamps;
- error information;
- diagnostic information; and
- configuration data.
This information is used to provide and maintain device-management functionality.
3.6 Screen Location and Coordinates
Layarva allows authorized Users to provide information about a Screen's installation or operational location.
This information may include:
- latitude;
- longitude;
- location name;
- location label;
- address;
- associated Screen identifier; and
- other location information entered by the User.
Source of Coordinates
Screen location coordinates are provided and entered by the User.
Layarva does not automatically collect GPS location, background location, or geographic coordinates from a Screen merely because a Device is connected to Layarva.
Accordingly, these coordinates are user-provided Screen location information.
Purpose of Use
Screen location information may be used to:
- record a Screen's installation location;
- identify a Screen's operational location;
- display Screens on a dashboard or map;
- help manage Screens across multiple locations;
- search for or group Screens by location;
- support troubleshooting;
- provide support; and
- provide other operational functions directly related to Screen management.
Accuracy
Because Screen location information is provided by Users, the User or Customer organization is responsible for the accuracy of the coordinates or other location information entered.
Users with the appropriate permissions may update that information.
No Continuous User Tracking
Layarva does not use user-provided Screen coordinates to perform background or continuous tracking of an individual's movements.
Screen coordinates are intended to identify a Screen's location, not a User's real-time location.
Advertising
Layarva does not sell Screen coordinates to advertising networks or data brokers for location-based advertising.
3.7 Queue Management Data
If Queue Management is used, we may process operational information such as:
- service name;
- queue number;
- ticket time;
- call time;
- counter;
- operator;
- queue status;
- service status; and
- activity logs.
Customers may choose to enter additional Personal Data into Queue Management.
Where they do so, the Customer is responsible for ensuring an appropriate lawful basis for that processing.
3.8 Public API Data
We may process:
- API key identifiers;
- endpoints;
- timestamps;
- IP addresses;
- HTTP status;
- usage;
- quotas;
- errors;
- rate-limit information; and
- security events.
This information may be used for:
- authentication;
- security;
- monitoring;
- troubleshooting;
- rate limiting;
- auditing; and
- reliability.
3.9 Customer Support Data
When you contact us, we may receive:
- name;
- email address;
- message content;
- screenshots;
- diagnostic information;
- files; and
- other information you choose to provide.
3.10 Integration Data
If you enable a third-party integration, we may receive data in accordance with the permissions you grant through that provider.
3.11 Cookies and Similar Technologies
Layarva may use:
- cookies;
- session storage;
- local storage; and
- similar technologies
for authentication, security, preferences, application functionality, and appropriate analytics.
4. Sources of Data
We may obtain data:
- directly from you;
- from your organization administrator;
- through your use of the Services;
- from Screens or Devices for technical operational data;
- through the Public API;
- from service providers;
- through integrations you enable; or
- from another source where there is a lawful basis.
Screen location coordinates are not automatically collected by Layarva and are obtained from information entered by Users.
5. Purposes of Processing
We may process data to:
- provide the Services;
- create and manage Accounts;
- authenticate Users;
- authorize access;
- manage Workspaces;
- pair Devices;
- manage Devices;
- manage Screens;
- manage Screen location information;
- provide storage;
- distribute Content;
- synchronize Content;
- support offline caching;
- provide Queue Management;
- provide the Public API;
- administer billing;
- manage Subscriptions;
- provide customer support;
- troubleshoot;
- log system activity;
- monitor system health;
- protect security;
- prevent fraud;
- respond to incidents;
- improve stability and reliability;
- comply with legal obligations; and
- protect the rights of Layarva, Customers, Users, or others.
6. Lawful Bases for Processing
Depending on the context, processing may be based on:
- performance of a contract;
- consent;
- compliance with legal obligations;
- legitimate interests where permitted by law; or
- another lawful basis recognized by applicable law.
Where processing relies on consent, you may withdraw that consent in accordance with applicable law and available mechanisms.
7. Google Sign-In and Google APIs
This section explains how Layarva accesses, uses, stores, shares, and allows Users to control data received from Google API Services.
Google authorization is optional unless a particular Layarva feature expressly requires a Google connection. Layarva requests Google permissions only when a User chooses a feature that requires those permissions.
7.1 Google Sign-In Data
When a User chooses Sign in with Google, Layarva may receive the basic Google account information made available through the approved authentication scopes, such as:
- name;
- email address;
- profile image or profile information; and
- Google account/user identifier.
Layarva uses this information to:
- authenticate the User;
- create or link the User's Layarva account;
- prefill identity information during registration;
- identify the signed-in account; and
- protect account and authentication security.
Google Sign-In does not replace the additional Layarva registration information that the User is required to provide, such as Organization Name, Workspace Name, Primary Use Case, Country, and required legal acceptances.
Layarva does not use Google Sign-In data to access Google Drive, Google Sheets, Google Slides, Google Calendar, Gmail, or other Google service content unless the User separately enables and authorizes a feature that requires such access.
7.2 Connected Google Services
Layarva may offer integrations with Google services. An integration is accessed only when the User explicitly enables it and grants the permissions shown by Google.
Depending on the integration that is actually available and enabled, authorized Google data may include:
- file or folder metadata;
- files or content selected or authorized by the User;
- presentation metadata or content;
- spreadsheet metadata or values;
- calendar and event information; and
- other data specifically covered by the OAuth scopes requested for the enabled feature.
Layarva does not request access to Google user data merely for possible future functionality. If a Google integration is not implemented or enabled, Layarva should not request OAuth scopes for that integration.
7.3 Purpose of Accessing Google User Data
Google user data is used only to provide or improve the User-facing Layarva feature for which the User granted access.
Examples may include:
- authenticating a User with Google Sign-In;
- allowing a User to select authorized Google Drive files for import into Layarva;
- importing or synchronizing authorized media or documents into the Layarva Content Library;
- importing an authorized Google Slides presentation into supported Layarva content functionality;
- reading authorized Google Sheets data for a User-configured widget or display;
- reading authorized Google Calendar events for a User-configured schedule or display; or
- operating another Google integration that is clearly presented to the User before authorization.
Layarva will not use Google user data for a materially different purpose without updating the applicable disclosures and obtaining any additional authorization or consent required by Google policy or applicable law.
7.4 Data Storage
Basic account information received through Google Sign-In may be stored as part of the User's Layarva account while that account is maintained.
When a User explicitly imports Google content into Layarva, the imported copy may be stored as Customer Content in Layarva infrastructure so that Layarva can provide the requested signage, content-management, synchronization, or related functionality.
Where a connected feature only needs temporary access and does not require a persistent copy, Layarva seeks to avoid retaining unnecessary Google user data.
OAuth tokens or related credentials may be stored while the relevant integration remains connected and requires the credential to operate, or until the credential is revoked, expires, is replaced, is disconnected by the User, or is deleted in accordance with the integration lifecycle and applicable legal obligations.
Google-derived data retained by Layarva remains subject to the applicable Layarva retention and deletion rules described in this Privacy Policy, subject to any stricter Google API requirements that apply.
7.5 Sharing and Transfers
Layarva does not sell Google user data.
Google user data is not transferred or shared with third parties except where permitted and necessary to:
- provide or improve the User-facing feature that the User requested and authorized;
- use service providers or Subprocessors that are necessary to operate Layarva infrastructure and that process data on Layarva's behalf;
- protect security, investigate abuse, or respond to a security incident;
- comply with applicable law or a valid and binding legal request; or
- complete a lawful corporate transaction where the required notice or consent is obtained.
Layarva does not transfer Google user data to advertising platforms, data brokers, or information resellers.
7.6 Prohibited Uses
Layarva does not use Google user data for:
- personalized, interest-based, or retargeted advertising;
- sale to data brokers or information resellers;
- determining creditworthiness or lending decisions;
- unrelated surveillance purposes; or
- training or improving a general-purpose artificial intelligence or machine-learning model using Google Workspace API user data.
Google user data may only be used for the User-facing functionality that justified the access, together with limited security, legal, or operational uses permitted by applicable Google policies.
7.7 Human Access
Human access to Google user data is restricted.
Authorized personnel may access specific Google user data only where:
- the User has expressly requested assistance and provided the authorization necessary for personnel to view the relevant data;
- access is necessary for security, abuse, fraud, or incident investigation;
- access is necessary to comply with applicable law or a valid legal requirement; or
- data has been appropriately aggregated or anonymized for permitted internal operations.
Personnel with access are subject to applicable confidentiality and access-control requirements.
7.8 Minimum Permissions and Contextual Authorization
Layarva seeks to request only the minimum Google OAuth scopes necessary for the feature the User chooses to use.
Where technically appropriate, Layarva uses contextual or incremental authorization so that a User is asked for access when enabling the relevant feature rather than granting unrelated permissions during initial registration.
Permissions for Google services that are not implemented or not currently required must not be requested solely for future use.
7.9 Google API Services User Data Policy and Limited Use
Layarva's use and transfer of information received from Google API Services will comply with the Google API Services User Data Policy, including the applicable Limited Use requirements.
Where Google Workspace API data is involved, Layarva will also follow applicable Google Workspace API user-data requirements.
7.10 Disconnecting Google and Revoking Access
Users may revoke or disconnect Google access:
- through Layarva functionality where available; or
- through their Google Account security and third-party access settings.
After access is revoked or the integration is disconnected, Layarva will stop using the affected Google credential to obtain new Google user data.
Previously imported Customer Content or other data already stored in Layarva may remain subject to Layarva's normal retention and deletion lifecycle unless the User validly requests deletion or another applicable obligation requires different handling.
7.11 Changes to Google Data Use
If Layarva materially changes the categories of Google user data it accesses or the purposes for which that data is used, Layarva will update this Privacy Policy and any required in-product disclosure before using Google user data for the new purpose, and will obtain additional authorization or consent where required.
8. Sharing and Service Providers
We may use service providers to help operate the Services, including providers of:
- cloud infrastructure;
- hosting;
- databases;
- storage;
- Content Delivery Networks;
- authentication;
- email;
- payment processing;
- analytics;
- logging;
- monitoring;
- mapping;
- customer support;
- security; and
- backups.
Service providers should receive access only to the extent necessary to perform their functions.
We may share data in certain circumstances with:
- administrators of a Customer organization;
- service providers;
- competent authorities where required by law; or
- parties to a lawful corporate transaction subject to appropriate protections.
We do not sell Personal Data to data brokers.
9. Cloud Infrastructure and Processing Locations
Layarva uses a cloud architecture.
Data may be stored or processed:
- in Indonesia;
- outside Indonesia; or
- across multiple locations.
Data may be processed, replicated, cached, backed up, or transmitted across multiple regions to support:
- availability;
- reliability;
- performance;
- scalability;
- security;
- disaster recovery; and
- continuity.
Technical locations may change from time to time.
Unless expressly agreed in a written contract, Layarva does not guarantee storage in a specific country or region.
Changes to technical locations that do not materially change the purpose or nature of processing may not result in individual notice.
If a change materially affects Personal Data processing practices, or if notice is required by applicable law, we will provide appropriate notice.
10. Cross-Border Data Transfers
Where Personal Data is transferred to a party or infrastructure outside Indonesia, Layarva will apply transfer mechanisms required by applicable law.
Such mechanisms may include:
- ensuring an appropriate level of protection;
- implementing adequate contractual or binding safeguards; or
- relying on another transfer basis permitted by applicable law.
11. Data Retention
We seek not to retain Personal Data longer than necessary for the purposes for which it is processed.
11.1 Active Paid Subscriptions
Data required to operate the Account, Workspace, features, Content, and Services may be retained while the paid Subscription remains active, subject to the lifecycle applicable to each data type and feature in use.
A paid Account is not treated as dormant merely because a User has not logged in.
11.2 Expired Paid Subscriptions
If a paid Subscription expires and is not renewed, Layarva may retain Customer Operational Data and Customer Content for up to:
180 days from the Subscription expiration date.
The deletion deadline is based on the expiration date, not the User's most recent login.
Logging in during the retention period does not reset the 180-day period.
If the Subscription is reactivated before the deletion date, the deletion process may be cancelled.
11.3 Free Accounts
A Free Account may be classified as dormant after:
180 days without qualifying activity.
Qualifying activity may include login, Screen use, Device activity, content management, API activity, publishing, or other activity demonstrating actual use of the Services.
For Free Accounts, qualifying activity may update the last-activity date.
11.4 Customer Content
Media, projects, playlists, templates, configuration, and Workspace data generally follow the lifecycle of the relevant Account and Subscription.
11.5 Screen Location Information
Latitude, longitude, location names, and other location data entered by a User generally follow the lifecycle of the relevant Screen, Workspace, and Account.
If a Screen or Workspace is deleted, associated location information may also be deleted in accordance with the retention policy.
11.6 Device Data
Pairing information, Device configuration, and Screen operational data may be deleted when no longer required or after the Account lifecycle ends, unless a longer period is necessary for security or legal obligations.
11.7 Billing and Legal Records
Invoices, payment evidence, accounting records, tax records, and certain other documents may be retained for longer periods where required by law or reasonably necessary for a lawful legal purpose.
11.8 Technical Log Retention
Layarva applies standard retention periods based on technical log categories that can be identified by the system:
| Log Category | Standard Retention Period |
|---|---|
| Application / request log | 45 days |
| API access log | 45 days |
| Device heartbeat / operational log | 45 days |
| Error / diagnostic log | 90 days |
| Security log | 180 days |
If administrator or User activity is recorded in one of the categories above, the record follows the retention period of the technical category in which it is stored.
After the applicable retention period expires, logs may be automatically deleted as part of normal system lifecycle, housekeeping, and storage management.
Layarva does not guarantee the availability of historical logs after the applicable retention period has expired.
Investigation and Evidence Export
If Layarva receives or becomes aware of a security incident, investigation, audit, dispute, claim, or valid legal request while relevant logs are still available, authorized personnel may search for and export records reasonably necessary for that purpose into a separate file.
The exported file may be retained for a maximum of 365 days from the date the export is created, and may be deleted earlier when it is no longer required for the related purpose.
If applicable law or a valid and binding order specifically requires a longer retention period, the exported file may be retained to the extent and for the period required by that obligation.
Creating or retaining an export file does not suspend, extend, or otherwise change the retention lifecycle of the source logs. Source logs continue to follow their normal retention periods.
If a log or other data has already been deleted, anonymized, overwritten, or otherwise become unavailable through the normal system lifecycle before a request is received, Layarva is not required to recover, reconstruct, recreate, or provide that record, to the extent permitted by applicable law.
Layarva can only provide records that remain available when a request is processed or records that were previously exported and retained separately.
Layarva is not required to preserve logs specifically for a possible future investigation, dispute, claim, or legal proceeding before receiving a valid and sufficiently specific request, notice, or binding order concerning the relevant data.
The unavailability of data that has aged out of the system in accordance with the applicable retention lifecycle does not by itself constitute a Service failure, unlawful data loss, or breach by Layarva.
Nothing above limits obligations that mandatorily apply under applicable law or under a valid and binding order received by Layarva.
11.9 Backups
Data may temporarily remain in backups after deletion from the production environment.
Such data will age out in accordance with the applicable backup lifecycle.
Backups are not intended to function as operational storage for a deleted Account and are not intended to function as an archive of historical logs that have aged out of the applicable production retention period.
Retention in backups does not guarantee that a particular log or item of data can be recovered or provided again after it is no longer available in production systems.
If recovery is required because of a technical disruption, Layarva will use reasonable recovery efforts based on backups or other recovery mechanisms that remain available, but successful recovery is not guaranteed in every circumstance.
12. Account and Data Deletion
After the applicable retention period ends, Layarva may delete or anonymize data such as:
- operational Account data;
- Workspaces;
- profile data;
- media;
- projects;
- playlists;
- templates;
- Device configuration;
- pairing information;
- Screen coordinates;
- API configuration;
- Queue configuration; and
- other operational data.
Before deletion due to expiration or dormancy, Layarva will use reasonable efforts to provide notice by email or another available mechanism.
After deletion is completed, data may become unrecoverable.
Where required by applicable law, Layarva will provide notice regarding deletion or destruction of Personal Data.
13. User-Initiated Deletion Requests
Users may request deletion of Personal Data or closure of an Account through an available mechanism or by contacting Layarva.
We may verify identity before processing a request.
Certain data may continue to be retained where retention is specifically required by applicable law, including accounting records, tax records, or other records subject to an independent retention obligation.
In addition, an evidence file or export created before the deletion request may remain stored in accordance with the applicable Evidence Export retention period, which is a maximum of 365 days from the date the export is created, unless it is deleted earlier or a longer period is specifically required by applicable law or a valid and binding order.
A deletion request does not require Layarva to recover or recreate data that was already unavailable through the normal system lifecycle when the request was received.
14. Data Subject Rights
Subject to applicable law, you may have the right to:
- receive information about processing;
- access Personal Data;
- obtain a copy of Personal Data;
- correct Personal Data;
- update Personal Data;
- withdraw consent;
- request restriction or termination of processing;
- request deletion or destruction;
- object to certain processing;
- receive data portability where applicable;
- object to certain fully automated decisions where applicable; and
- exercise other rights provided by applicable law.
We may request additional information to verify the identity or authority of the person making the request.
15. Data Security
We use technical and organizational measures appropriate to the type and risk of the data processed.
Measures may include:
- authentication;
- authorization;
- role-based access;
- encryption for appropriate data in transit or storage contexts;
- credential protection;
- security logging;
- monitoring;
- backups;
- network protection;
- access restrictions; and
- incident response.
No electronic system can be guaranteed to be completely free of risk.
16. Data Breaches and Security Incidents
If a Personal Data protection failure occurs, Layarva will take appropriate actions that may include:
- investigation;
- containment;
- mitigation;
- recovery;
- documentation; and
- notification where required by applicable law.
Notifications will be provided within the time period and to the parties required by applicable law.
17. Customer Data Processed on Behalf of an Organization
If a Customer uses Layarva to process Personal Data relating to employees, customers, visitors, patients, members, or other individuals, the Customer is responsible for ensuring that:
- an appropriate lawful basis exists;
- required notices have been provided;
- consent has been obtained where necessary;
- access is appropriately restricted; and
- the data is used in compliance with applicable law.
In that context, Layarva may act as a Processor in accordance with the Customer's instructions.
18. Cookies
Layarva may use cookies necessary for:
- login;
- session management;
- authentication;
- security;
- preferences; and
- core application functionality.
If non-essential cookies or technologies are used and applicable law requires consent, they will be managed through an appropriate consent mechanism.
19. Analytics
We may process technical usage information to understand:
- performance;
- errors;
- reliability;
- feature usage; and
- system health.
Analytics data is not used to sell Personal Data to data brokers.
20. Marketing Communications
We may send communications about products or services where an appropriate legal basis exists.
Users may opt out of marketing communications through the available unsubscribe mechanism.
Important communications relating to security, Accounts, billing, expiration, deletion, or Service administration are not treated as ordinary marketing communications.
21. Children's Privacy
Layarva is primarily a platform for businesses and organizations and is not a consumer service specifically directed to children.
If an organization uses Layarva in a context involving children, the organization is responsible for ensuring that processing complies with applicable requirements relating to children's data.
22. Automated Decision-Making
Layarva does not intend to use Personal Data for solely automated decisions that produce legal effects or similarly significant effects on individuals unless the relevant feature is specifically introduced with an appropriate lawful basis and safeguards.
If this practice changes, relevant information will be provided as required by law.
23. Change of Ownership or Restructuring
If Layarva undergoes a merger, acquisition, restructuring, sale, or change of legal entity, data may be transferred as part of a lawful transaction.
Processing and notification will be handled in accordance with applicable legal obligations.
24. Changes to This Privacy Policy
We may update this Privacy Policy to reflect changes in:
- products;
- integrations;
- infrastructure;
- technology;
- security;
- operations; or
- law.
If a change materially affects how we process Personal Data, we will provide notice as appropriate.
The "Last Updated" date identifies the current version.
25. Language Versions
This Privacy Policy may be made available in Indonesian and English.
Both versions are intended to communicate the same substance. If there is an inconsistency or difference in interpretation between the Indonesian and English versions, the Indonesian version will be used as the reference to the extent permitted by applicable law.
26. Privacy Contact
For questions, requests, or complaints regarding Personal Data:
Layarva
Operated by: CV DNA Konsultan
Address: Jl. Arabika 8 Blok AA 1 No. 9, RT.001/RW.005, Pondok Kopi, Duren Sawit, Jakarta Timur, DKI Jakarta 13460
Email: halo@layarva.com
Suggested email subject:
Privacy Request – Layarva