Berlaku efektif: 19 September 2026
InOne Estatika ("Aplikasi") adalah dashboard operasional manajemen properti/fasilitas ("Every property, in one.") yang digunakan oleh staf internal dari organisasi klien (mis. tim engineering, security, housekeeping, HR/GA, finance) untuk mengelola aset, work order, absensi, keamanan, dan operasional gedung. Aplikasi ini bukan aplikasi konsumen untuk umum — akses dibatasi hanya untuk pengguna yang diberi akun oleh organisasi klien terkait.
| Kategori | Data | Tujuan |
|---|---|---|
| Akun & identitas | Username, password (di-hash, tidak pernah disimpan dalam bentuk asli), nama, peran/jabatan, klien/tenant. Opsional (diisi oleh administrator organisasi): email & nomor telepon (untuk reset password & notifikasi), NIK/nomor pegawai (untuk pencocokan data kepegawaian) | Login, kontrol akses berbasis peran, reset password, administrasi kepegawaian oleh organisasi klien |
| Foto wajah | Foto yang diambil saat absensi (check-in/check-out) | Verifikasi kehadiran, opsional verifikasi otomatis via AI |
| Lokasi (GPS) | Koordinat lokasi saat absensi atau checkpoint patroli | Memastikan absensi/checkpoint dilakukan di lokasi kerja yang benar |
| Kamera (QR/foto) | Pemindaian QR code aset/checkpoint; foto sebelum-sesudah pada Work Order & Berita Acara | Identifikasi aset, dokumentasi pekerjaan/insiden |
| Data operasional | Data aset, work order, procurement, jadwal kerja, shift, anggaran (OPEX/CAPEX), data kontrak vendor | Fungsi inti aplikasi (manajemen fasilitas) |
| Data kepegawaian | Riwayat absensi, jadwal shift, data outsource/vendor terkait pekerja | Administrasi HR/GA oleh organisasi klien |
| Percakapan Chat AI | Pertanyaan yang dikirim ke fitur "Tanya AI" (jika digunakan) | Menjawab pertanyaan terkait data operasional pengguna |
| Log aktivitas | Catatan aksi penting di dalam aplikasi (audit trail) | Keamanan, audit, penelusuran masalah |
Kami memproses data pribadi berdasarkan salah satu atau lebih dasar berikut, sesuai UU No. 27 Tahun 2022 tentang Pelindungan Data Pribadi ("UU PDP"):
Karena Aplikasi digunakan dalam konteks kerja (B2B), sebagian besar dasar pemrosesan berasal dari hubungan kerja/kontrak antara pengguna dan organisasi klien — organisasi klien bertindak sebagai Pengendali Data Pribadi untuk data karyawan/staf-nya, dan InOne Estatika bertindak sebagai Prosesor Data Pribadi yang memproses data tersebut atas instruksi organisasi klien.
Data digunakan semata-mata untuk menjalankan fungsi Aplikasi bagi organisasi klien yang mempekerjakan/menugaskan pengguna: absensi, manajemen aset & work order, keamanan, laporan keuangan operasional gedung, dan pelaporan manajemen. Kami tidak menjual data pengguna, dan tidak menggunakan data untuk iklan atau profil pemasaran pihak ketiga.
| Penyedia | Peran |
|---|---|
| Supabase | Database & penyimpanan file utama (foto, dokumen) — data disimpan terenkripsi saat transit (HTTPS/TLS) |
| Hostinger | Hosting aplikasi & server Node.js (proses login, admin user, log aktivitas) |
| OpenAI | Memproses pertanyaan pada fitur "Tanya AI" — hanya dikirim saat fitur ini aktif digunakan |
| Google Sheets API | Sumber data forecast/estimasi (read-only), tidak menerima data pribadi pengguna |
Kami tidak membagikan data pengguna kepada pihak ketiga untuk tujuan iklan.
Sebagian penyedia layanan pihak ketiga kami memproses/menyimpan data di luar wilayah Indonesia:
Transfer data lintas negara ini kami lakukan dengan memastikan penyedia terkait menerapkan standar keamanan data yang setara (enkripsi saat transit dan saat disimpan, kontrol akses, sertifikasi keamanan penyedia layanan cloud), sebagaimana disyaratkan Pasal 56 UU PDP. Data lokasi (GPS) dan foto wajah tidak dikirim ke penyedia AI pihak ketiga mana pun — hanya teks pertanyaan pengguna pada fitur "Tanya AI" yang diproses OpenAI, dan hanya jika fitur tersebut aktif digunakan.
Password disimpan dalam bentuk hash (bcrypt), akses ke data dibatasi per klien/tenant dan per peran pengguna (Row Level Security di database), dan komunikasi antara aplikasi dan server dilakukan melalui HTTPS.
Data disimpan selama akun pengguna aktif dan sesuai kebutuhan operasional/administratif organisasi klien. Permintaan penghapusan atau akses data dapat diajukan melalui administrator organisasi klien terkait, atau lewat formulir Permintaan Hapus Data di halaman ini.
Sesuai UU PDP, Anda sebagai subjek data memiliki hak untuk:
Karena Aplikasi ini digunakan dalam konteks kerja, sebagian besar permintaan di atas (khususnya penghapusan data kepegawaian) tunduk pada kebijakan organisasi klien Anda selaku Pengendali Data. Untuk mengajukan hak-hak di atas, hubungi administrator organisasi Anda atau kontak kami di bagian 13.
Aplikasi ini ditujukan untuk penggunaan internal oleh staf dewasa yang bekerja/ditugaskan oleh organisasi klien, dan tidak ditujukan untuk digunakan oleh anak-anak.
Kebijakan ini tunduk pada dan ditafsirkan sesuai hukum Republik Indonesia, termasuk UU No. 27 Tahun 2022 tentang Pelindungan Data Pribadi. Setiap sengketa terkait pemrosesan data pribadi dalam Aplikasi ini akan diupayakan penyelesaiannya secara musyawarah; apabila tidak tercapai kesepakatan, sengketa akan diselesaikan melalui mekanisme yang berlaku sesuai peraturan perundang-undangan Indonesia.
Kebijakan ini dapat diperbarui dari waktu ke waktu. Tanggal "Berlaku efektif" di atas menunjukkan revisi terakhir.
Pertanyaan seputar privasi, permintaan akses, atau penghapusan data:
Untuk saat ini, permintaan terkait pelindungan data pribadi ditangani langsung melalui kontak di atas, sampai Petugas Pelindungan Data Pribadi (DPO) resmi ditunjuk.
InOne Estatika (the "Application") is an operational property/facility management dashboard ("Every property, in one.") used by internal staff of client organizations (e.g. engineering, security, housekeeping, HR/GA, and finance teams) to manage assets, work orders, attendance, security, and building operations. This Application is not a consumer app for the general public — access is limited to users who have been provisioned an account by their client organization.
| Category | Data | Purpose |
|---|---|---|
| Account & identity | Username, password (hashed, never stored in its original form), name, role/position, client/tenant. Optional (entered by the client organization's administrator): email & phone number (for password reset & notifications), national ID/employee number (for matching HR records) | Login, role-based access control, password reset, HR administration by the client organization |
| Face photo | Photo captured during attendance check-in/check-out | Attendance verification, optional automatic AI verification |
| Location (GPS) | Location coordinates at the time of check-in or patrol checkpoint | Confirming attendance/checkpoints are performed at the correct work location |
| Camera (QR/photo) | Asset/checkpoint QR code scanning; before-and-after photos on Work Orders & Handover Reports (Berita Acara) | Asset identification, work/incident documentation |
| Operational data | Asset data, work orders, procurement, work schedules, shifts, budgets (OPEX/CAPEX), vendor contract data | Core application functions (facility management) |
| Employment data | Attendance history, shift schedules, outsourced/vendor worker data | HR/GA administration by the client organization |
| AI Chat conversations | Questions sent to the "Ask AI" feature (if used) | Answering questions related to the user's operational data |
| Activity logs | Records of key actions within the app (audit trail) | Security, auditing, and troubleshooting |
We process personal data based on one or more of the following legal bases, in accordance with Indonesia's Law No. 27 of 2022 on Personal Data Protection ("UU PDP"):
Because the Application is used in a work context (B2B), most processing bases arise from the employment/contractual relationship between the user and the client organization — the client organization acts as the Data Controller for its employees'/staff's data, and InOne Estatika acts as the Data Processor handling that data on the client organization's instructions.
Data is used solely to run the Application's functions for the client organization that employs or assigns the user: attendance, asset & work order management, security, building operational financial reporting, and management reporting. We do not sell user data, and we do not use it for advertising or third-party marketing profiling.
| Provider | Role |
|---|---|
| Supabase | Primary database & file storage (photos, documents) — data is encrypted in transit (HTTPS/TLS) |
| Hostinger | Application & Node.js server hosting (login process, user administration, activity logs) |
| OpenAI | Processes queries for the "Ask AI" feature — only sent while this feature is actively in use |
| Google Sheets API | Source of forecast/estimate data (read-only); does not receive users' personal data |
We do not share user data with third parties for advertising purposes.
Some of our third-party service providers process/store data outside Indonesia:
We carry out these cross-border transfers by ensuring the relevant providers apply an equivalent data security standard (encryption in transit and at rest, access controls, cloud provider security certifications), as required under Article 56 of the UU PDP. GPS location data and face photos are not sent to any third-party AI provider — only the text of a user's question in the "Ask AI" feature is processed by OpenAI, and only while that feature is actively used.
Passwords are stored hashed (bcrypt), data access is restricted per client/tenant and per user role (database Row Level Security), and all communication between the application and server uses HTTPS.
Data is retained for as long as the user account is active and as needed for the client organization's operational/administrative purposes. Requests for data deletion or access may be submitted through the relevant client organization's administrator, or via the Data Deletion Request form.
In accordance with the UU PDP, you as a data subject have the right to:
Because this Application is used in a work context, most of the above requests (particularly deletion of employment data) are subject to the policies of your client organization as the Data Controller. To exercise the rights above, contact your organization's administrator or reach us via the contact in section 13.
This Application is intended for internal use by adult staff employed or assigned by client organizations, and is not directed at children.
This policy is governed by and construed in accordance with the laws of the Republic of Indonesia, including Law No. 27 of 2022 on Personal Data Protection. Any disputes relating to the processing of personal data within this Application will first be resolved through deliberation/consultation; if no agreement is reached, disputes will be resolved through the mechanisms available under applicable Indonesian law.
This policy may be updated from time to time. The "Effective date" above reflects the latest revision.
Questions about privacy, data access requests, or data deletion:
For now, personal data protection requests are handled directly via the contact above, pending the formal appointment of a Data Protection Officer (DPO).