1. Introduction
Tatan is a construction project management platform developed and operated by PT Rancang Nusantara Teknologi for and on behalf of Acme Corp (the “Service”).
For personal data processed within the Service:
- Acme Corp acts as the Data Controller
- PT Rancang Nusantara Teknologi acts as the Data Processor, processing data solely on documented instructions from Acme Corp
We are committed to protecting personal data in accordance with applicable laws, including Indonesia’s Personal Data Protection Law (UU No. 27 Tahun 2022) where applicable.
2. Information We Collect
2.1 Personal Information
- Account details (name, email, phone number, WhatsApp number)
- Profile information (job role, profile photo, organization)
- Project and site information
- Worker and subcontractor details
- Material and inventory records
2.2 Automatically Collected Information
- GPS location data for site verification
- Device and browser information
- Usage and interaction data
- Log data (IP address, access timestamps)
2.3 Photos and Media
- Site and project photos
- Selfie verification images
- Quotation and documentation files
Such data is collected solely for attendance verification, fraud prevention, operational accountability, and project documentation, and not for unrelated surveillance.
3. How We Use Information
Information is processed to:
- Provide and operate the Service
- Authenticate users and manage access
- Enable project, labor, and material management
- Verify on-site presence and submissions
- Deliver notifications and system messages
- Generate AI-assisted summaries and insights (optional)
- Improve system performance and security
- Comply with legal and contractual obligations
4. Data Sharing and Disclosure
We may share data:
- Within your organization based on role permissions
- With trusted service providers (hosting, analytics, AI processing)
- To comply with legal obligations
- In business transfers (mergers, acquisitions)
- With user or organizational consent
We do not sell personal data.
5. Data Storage and Security
- Encrypted data at rest and in transit
- Role-based access controls
- Two-factor authentication support
- Regular backups and monitoring
Upon account termination, data is retained for a commercially reasonable period or as required by law, unless otherwise instructed by Acme Corp.
6. Your Rights
Depending on applicable law, users may request:
- Access to personal data
- Correction of inaccuracies
- Deletion (subject to retention requirements)
- Data export
- Feature opt-outs (AI, WhatsApp notifications)
- Withdrawal of consent where applicable
Requests should be directed to your organization’s administrator.
7. Third-Party Services
The Service integrates with:
- Supabase (database and authentication)
- Google Gemini (AI features, optional)
- WhatsApp / Meta (notifications, optional)
Use of third-party services is subject to their respective privacy policies.
8. Cookies
We use essential cookies for authentication and session management. No advertising cookies are used.
9. Children’s Privacy
The Service is intended for professional and employment-related use only and is not designed for individuals under 18 years of age.
10. International Data Transfers
Data may be processed in jurisdictions outside your own. Appropriate safeguards are applied to protect personal data.
11. Data Deletion Requests
11.1 WhatsApp / Meta Data
If you have received WhatsApp notifications from the Service and wish to request deletion of your data, you may do so by contacting us at [email protected].
Please include:
- The phone number associated with your WhatsApp account
- A description of your request
Upon receiving a valid deletion request, we will:
- Delete all WhatsApp message logs associated with your phone number
- Confirm completion of the deletion within 30 days
11.2 General Data Deletion
For deletion of other personal data held within the Service, please contact your organization's administrator, who may submit a request on your behalf.
12. Changes to This Policy
We may update this Privacy Policy periodically. Continued use of the Service constitutes acceptance of the updated policy.
13. Contact
For privacy-related questions, please contact your organization's administrator or reach out to the system operator at [email protected].