Privacy Policy

1) Introduction

PT Autokon Digital Indonesia (“Autokon,” “we,” “us,” or “our”) respects your privacy and is committed to protecting your personal data in accordance with Indonesia’s Personal Data Protection Law (UU No. 27/2022) and applicable regulations. This Policy explains how we collect, use, store, protect, and disclose personal data when you use Autokon’s products — including the WhatsApp assistant “TARA,” the Autokon web application/portal, and our BAST/BASTP reporting and defect-inspection services.

By using Autokon, you agree to the practices described in this Policy.


2) Scope of Services

This Policy covers:

  • Interactions through WhatsApp (TARA) and other official Autokon channels.

  • The Autokon web app/dashboard (including BAST/BASTP report generation and defect management).

  • Relevant integrations (e.g., notifications, document storage, and—if enabled—digital payments).


3) Personal Data We Collect

We only collect data that is relevant and proportionate to the purposes in Section 4. Examples include:

  • Identity & Contact Data: name, mobile phone number, WhatsApp ID/account, email (if provided).

  • Project/Operational Data: defect photos/videos, unit descriptions, unit identifiers, project location, work stages, and related attachments/files for reports.

  • Interaction & Usage Data: message content processed by the system (only as needed to generate responses and reports), timestamps, features used.

  • Technical Data: device model, operating system, IP address, error/crash logs.

  • Payment Data (optional): if you purchase credits/packages, we process transaction data via our payment service provider(s).

  • Account/Organization Data: company/project name, user role(s), and team settings.


4) Purposes of Processing

We process your personal data to:

  • Provide core service features (message processing, defect classification, report creation and delivery).

  • Improve service quality, troubleshoot issues, and develop new features.

  • Provide customer support and technical assistance.

  • Comply with applicable laws and respond to lawful requests by authorities.

We will not use your data for other purposes without additional consent or unless permitted/required by law.

Legal bases: your consent, performance of a contract with you/your organization, and/or compliance with legal obligations.


5) Consent & Withdrawal

Where required, we obtain your consent prior to collecting, using, or disclosing personal data. You may withdraw consent at any time by contacting our DPO (see Section 13). Please note that withdrawal may affect our ability to provide certain services.


6) Disclosure of Personal Data

We may disclose data to third parties that support our services, such as: cloud and storage providers, analytics, communications platforms, AI inference/model processors, and—if enabled—payment processors. We may also disclose data to government authorities if required by law. We do not sell or rent your personal data.


7) Cross-Border Data Transfers

Where necessary to deliver the services, your data may be processed or stored outside Indonesia by our third-party service providers (including WhatsApp/Meta infrastructure). In such cases, we take steps to ensure a level of protection comparable to Indonesian requirements.


8) Relationship with WhatsApp & Meta

TARA operates on WhatsApp infrastructure. Messages you send/receive may pass through WhatsApp systems and are subject to WhatsApp and Meta privacy terms. Autokon does not control how WhatsApp/Meta independently process your data.


9) Data Retention

We retain data only as long as needed for the purposes in Section 4 or as required by law. Indicative periods:

  • Conversation logs/usage records: up to 90 days for troubleshooting and service improvement.

  • Account & billing data: while the account is active and up to 12 months after closure, unless earlier deletion is requested and not in conflict with legal obligations.

  • Project/report files (defect photos, BAST/BASTP documents): for the duration of the engagement/contract and up to 24 months thereafter, unless deletion is requested or a different period is agreed in writing.


10) Data Security

We implement reasonable technical and organizational measures (e.g., encryption, role-based access controls, secure storage) to protect data against unauthorized access, use, disclosure, alteration, or loss. However, no method of transmission or storage is completely risk-free.


11) Your Rights

Subject to the PDP Law, you have the right to:

  • Access the personal data we hold about you and obtain a copy.

  • Rectify inaccurate or incomplete data.

  • Withdraw consent, restrict or object to certain processing, request deletion (erasure), and lodge a complaint with the competent authority.

Please submit requests in writing to our DPO (see Section 13).


12) Cookies & Tracking Technologies

When you visit Autokon’s website, we may use cookies and similar technologies for functionality, analytics, and user experience. You can manage cookie preferences via your browser or site settings.


13) Contact — Data Protection Contact (DPO/PPDP)

  • Data Protection Contact (DPO/PPDP): info@autokon.id

  • Address: Villa Sentra Raya A-6/18, Surabaya, 60217

  • Phone: +62 812-1303-0910


14) Children’s Privacy

Autokon is intended for professional/adult users. We do not knowingly collect data from individuals under 17 years of age.


15) Changes to This Policy

We may update this Policy from time to time. The latest version will be available via our official app/site. By continuing to use the services after an update, you acknowledge the revised Policy.


16) Additional Terms (If Applicable)

  • Payments & Credits: If you purchase packages/credits, transaction data is processed by our payment provider(s); proof of payment is retained as needed for reconciliation and tax compliance.

  • Automated Processing & AI: Defect analysis and report compilation leverage automated processing. Any legal/contractual decisions remain with the relevant parties (developers/contractors/unit owners).

  • Third-Party Links: Third-party sites/apps have their own privacy practices; we are not responsible for their policies.