Privacy Policy
How we collect, use, and protect your Personal Data under Indonesian Law No. 27/2022 (UU PDP).
Effective date: 30 July 2026
Last updated: 30 July 2026
1. Introduction
Katekima (“Katekima”, “we”, “us”) respects your privacy and is committed to protecting the Personal Data you entrust to us.
This policy explains how we collect, use, store, and protect Personal Data, in accordance with Indonesian Law No. 27 of 2022 on Personal Data Protection (“UU PDP”) and its implementing regulations.
This policy applies to the katekima.id website and all Katekima products and services.
2. Our Role in Data Processing
UU PDP distinguishes two roles. It is important that you understand when we act in which capacity:
a. As a Personal Data Controller
We determine the purposes and means of processing for data you provide to us directly, for example when you fill in the contact form, apply for a job, or contact our team.
b. As a Personal Data Processor
When a hospital or healthcare institution uses our products, that institution is the Controllerof its patients’ data. We only process that data on their instructions, under a written agreement. We do not use patient data for our own purposes.
If you are a patient and wish to exercise your rights over your health data, please contact the hospital where you were treated, as the Controller. We will support them in fulfilling your request.
3. Personal Data We Collect
a. Data you provide directly
| Category | Examples | Source |
|---|---|---|
| Identity & contact | First name, last name, work email, phone number | "Partner with us" form |
| Organisation data | Institution name, job title, area of interest | "Partner with us" form |
| Communication content | Messages, emails, WhatsApp conversations | Our contact channels |
| Job applicant data | CV, education & employment history, portfolio | Applications to katekima.hr@katekima.id |
b. Data collected automatically
| Category | Examples |
|---|---|
| Technical data | IP address, device type, browser, operating system (server logs and form rate-limiting; we do not use third-party analytics) |
c. Specific Personal Data
When our services begin to be used by healthcare institutions, our systems will process patient health data, which Article 4(2) of UU PDP classifies as Specific Personal Data. This data will be processed onlyin our capacity as a Processor, on the institution’s instructions, with the additional safeguards described in Section 7.
d. Children’s data
Our services are not directed at children under 18. Children’s data in the context of medical records is processed only in our capacity as a Processor, with parental/guardian consent managed by the healthcare institution as Controller.
4. Legal Bases and Purposes of Processing
| Purpose | Legal Basis (UU PDP Article 20) |
|---|---|
| Responding to enquiries and demo requests | Your consent |
| Sending product information you have requested | Your consent |
| Processing job applications | Your consent; pre-contractual steps |
| Providing and maintaining services to client institutions | Performance of a contract |
| Keeping our systems secure and preventing abuse | Our legitimate interests |
| Complying with legal obligations & healthcare regulations | Legal obligation |
We do not sell your Personal Data to anyone.
We do not use your Personal Data for automated decision-making that produces legal effects concerning you.
5. Consent and Its Withdrawal
For processing based on consent, we ask for consent that is explicit, specific, and demonstrable, through checkboxes on our forms that are never pre-ticked.
You have the right to withdraw your consent at any time by contacting us as described in Section 11. Withdrawal does not affect the lawfulness of processing carried out before the withdrawal.
6. Sharing Data with Third Parties
We share Personal Data only with:
| Recipient | Purpose | Location |
|---|---|---|
| Vercel Inc. (website hosting) | Running the website | United States (global edge network) |
| Zoho Corporation (Zoho Mail) | Business communication | United States (Zoho account data-center region) |
| Resend Inc. (transactional email) | Delivering contact-form messages | United States |
| Zoho Corporation (Zoho CRM) | Managing prospects | United States (Zoho account data-center region) |
| Law enforcement authorities | Where required by regulation | Indonesia |
Each provider is bound by an agreement requiring them to protect data to a standard equivalent to this policy.
Some of the providers above process data outside Indonesia. For each such transfer, we ensure a level of protection equivalent to UU PDP through data-processing agreements with the relevant provider, in accordance with Articles 55–56 of UU PDP.
7. Data Security
We apply reasonable technical and organisational measures, including:
- Encryption of data in transit (TLS/HTTPS) and at rest
- Role-based access control, following the principle of least privilege
- Audit logging of access to sensitive data
- Separation of development and production environments
- Periodic security reviews
Edge-first architecture.Our products are designed so that patient data remains within the healthcare institution’s on-premise infrastructure and is not sent to third-party clouds, supporting compliance with Indonesian data-residency requirements.
8. Data Retention and Deletion
| Data Type | Retention Period |
|---|---|
| Contact form & prospect data | 24 months from last contact |
| Data of unsuccessful job applicants | 12 months, unless you allow us to keep it longer |
| Institutional client data | For the duration of the agreement + 12 months |
| Patient medical records | Per the retention policy of the healthcare institution as Controller, and the applicable Ministry of Health regulations |
| Technical & security logs | 12 months |
Once the retention period ends, data is permanently deleted or anonymised.
9. Your Rights as a Personal Data Subject
Under Articles 5–15 of UU PDP, you have the right to:
- Be informed of our identity, the legal basis, and the purposes of processing
- Access and obtain a copy of your Personal Data
- Rectify inaccurate or incomplete data
- Delete your Personal Data
- Withdraw consent you have previously given
- Object to certain processing, including automated decision-making
- Suspend or restrict processing
- Obtain and port your data in a machine-readable format
- Claim compensation for violations in the processing of your Personal Data
How to exercise your rights: send your request to katekima.contact@katekima.id. We will respond within 3 x 24 hours at the latest, as required by UU PDP. We may ask you to verify your identity before processing the request.
10. Personal Data Breach Notification
In the event of a Personal Data breach, we will notify you and the supervisory authority in writing within 3 x 24 hours at the latest from the moment we become aware of it, as required by Article 46 of UU PDP, covering which data was exposed, when and how it happened, and our remediation efforts.
11. Contact
Questions, complaints, or requests concerning Personal Data:
Katekima
Jl. Sentra Dago Pakar Raya, Mekarsaluyu, Cimenyan District, Bandung Regency, West Java 40198
Email: katekima.contact@katekima.id
Phone / WhatsApp: +62 821-1634-3125
Data Protection Officer (DPO): Muhammad Shobir Abdussyakur, Backend Developer (katekima.contact@katekima.id)
If you are not satisfied with our response, you have the right to lodge a complaint with the personal data protection supervisory authority of the Republic of Indonesia.
12. Changes to This Policy
We may update this policy from time to time. We will notify you of material changes via the website or email no later than 14 days before they take effect. The “Last updated” date above always reflects the current version.