← Back

Privacy Policy

Last updated: 3 July 2026

1. Who we are

This policy explains how we handle personal data when you use the platform. For data you upload about your own contacts, you are the data controller and we act as a data processor on your behalf.

2. Data we process

3. How we use data

We use personal data to provide, secure, and improve the Service, to process payments, to send transactional messages (e.g. password resets, receipts), and to comply with legal obligations. We do not sell personal data.

4. Sub-processors

We rely on vetted third parties to run the Service — for example a payment gateway (Xendit), email delivery providers, cloud hosting, and error-monitoring tooling (e.g. Sentry) used to detect and fix problems. See our current Sub-processors list, each bound by our Data Processing Agreement.

5. Retention

We retain personal data for as long as your account is active and as needed to provide the Service, then delete or anonymize it within a reasonable period, unless a longer retention is required by law. The DPA sets out our retention schedule by data category.

6. Your rights

Subject to applicable law (including Indonesia’s UU PDP and GDPR where relevant), you may request access, correction, export, or deletion of your personal data. Account owners can export or erase their organization’s data from within the app or by contacting support.

7. Security

We use encryption in transit, per-tenant isolation, access controls, and audit logging to protect data. No system is perfectly secure; we will notify affected parties of a breach as required by law.

8. Changes & contact

We may update this policy; material changes will be notified. See also our Terms of Service. For privacy requests, contact your workspace administrator or our support contact.