Legal

Privacy Policy

How we collect, use, and protect your Personal Data under Indonesian Law No. 27/2022 (UU PDP).

Effective date: 30 July 2026
Last updated: 30 July 2026

1. Introduction

Katekima (“Katekima”, “we”, “us”) respects your privacy and is committed to protecting the Personal Data you entrust to us.

This policy explains how we collect, use, store, and protect Personal Data, in accordance with Indonesian Law No. 27 of 2022 on Personal Data Protection (“UU PDP”) and its implementing regulations.

This policy applies to the katekima.id website and all Katekima products and services.

2. Our Role in Data Processing

UU PDP distinguishes two roles. It is important that you understand when we act in which capacity:

a. As a Personal Data Controller
We determine the purposes and means of processing for data you provide to us directly, for example when you fill in the contact form, apply for a job, or contact our team.

b. As a Personal Data Processor
When a hospital or healthcare institution uses our products, that institution is the Controllerof its patients’ data. We only process that data on their instructions, under a written agreement. We do not use patient data for our own purposes.

If you are a patient and wish to exercise your rights over your health data, please contact the hospital where you were treated, as the Controller. We will support them in fulfilling your request.

3. Personal Data We Collect

a. Data you provide directly

Personal Data you provide directly
CategoryExamplesSource
Identity & contactFirst name, last name, work email, phone number"Partner with us" form
Organisation dataInstitution name, job title, area of interest"Partner with us" form
Communication contentMessages, emails, WhatsApp conversationsOur contact channels
Job applicant dataCV, education & employment history, portfolioApplications to katekima.hr@katekima.id

b. Data collected automatically

Data collected automatically
CategoryExamples
Technical dataIP address, device type, browser, operating system (server logs and form rate-limiting; we do not use third-party analytics)

c. Specific Personal Data

When our services begin to be used by healthcare institutions, our systems will process patient health data, which Article 4(2) of UU PDP classifies as Specific Personal Data. This data will be processed onlyin our capacity as a Processor, on the institution’s instructions, with the additional safeguards described in Section 7.

d. Children’s data
Our services are not directed at children under 18. Children’s data in the context of medical records is processed only in our capacity as a Processor, with parental/guardian consent managed by the healthcare institution as Controller.

4. Legal Bases and Purposes of Processing

Legal bases and purposes of processing
PurposeLegal Basis (UU PDP Article 20)
Responding to enquiries and demo requestsYour consent
Sending product information you have requestedYour consent
Processing job applicationsYour consent; pre-contractual steps
Providing and maintaining services to client institutionsPerformance of a contract
Keeping our systems secure and preventing abuseOur legitimate interests
Complying with legal obligations & healthcare regulationsLegal obligation

We do not sell your Personal Data to anyone.
We do not use your Personal Data for automated decision-making that produces legal effects concerning you.

5. Consent and Its Withdrawal

For processing based on consent, we ask for consent that is explicit, specific, and demonstrable, through checkboxes on our forms that are never pre-ticked.

You have the right to withdraw your consent at any time by contacting us as described in Section 11. Withdrawal does not affect the lawfulness of processing carried out before the withdrawal.

6. Sharing Data with Third Parties

We share Personal Data only with:

Third parties receiving Personal Data
RecipientPurposeLocation
Vercel Inc. (website hosting)Running the websiteUnited States (global edge network)
Zoho Corporation (Zoho Mail)Business communicationUnited States (Zoho account data-center region)
Resend Inc. (transactional email)Delivering contact-form messagesUnited States
Zoho Corporation (Zoho CRM)Managing prospectsUnited States (Zoho account data-center region)
Law enforcement authoritiesWhere required by regulationIndonesia

Each provider is bound by an agreement requiring them to protect data to a standard equivalent to this policy.

Some of the providers above process data outside Indonesia. For each such transfer, we ensure a level of protection equivalent to UU PDP through data-processing agreements with the relevant provider, in accordance with Articles 55–56 of UU PDP.

7. Data Security

We apply reasonable technical and organisational measures, including:

  • Encryption of data in transit (TLS/HTTPS) and at rest
  • Role-based access control, following the principle of least privilege
  • Audit logging of access to sensitive data
  • Separation of development and production environments
  • Periodic security reviews

Edge-first architecture.Our products are designed so that patient data remains within the healthcare institution’s on-premise infrastructure and is not sent to third-party clouds, supporting compliance with Indonesian data-residency requirements.

8. Data Retention and Deletion

Retention period per data type
Data TypeRetention Period
Contact form & prospect data24 months from last contact
Data of unsuccessful job applicants12 months, unless you allow us to keep it longer
Institutional client dataFor the duration of the agreement + 12 months
Patient medical recordsPer the retention policy of the healthcare institution as Controller, and the applicable Ministry of Health regulations
Technical & security logs12 months

Once the retention period ends, data is permanently deleted or anonymised.

9. Your Rights as a Personal Data Subject

Under Articles 5–15 of UU PDP, you have the right to:

  1. Be informed of our identity, the legal basis, and the purposes of processing
  2. Access and obtain a copy of your Personal Data
  3. Rectify inaccurate or incomplete data
  4. Delete your Personal Data
  5. Withdraw consent you have previously given
  6. Object to certain processing, including automated decision-making
  7. Suspend or restrict processing
  8. Obtain and port your data in a machine-readable format
  9. Claim compensation for violations in the processing of your Personal Data

How to exercise your rights: send your request to katekima.contact@katekima.id. We will respond within 3 x 24 hours at the latest, as required by UU PDP. We may ask you to verify your identity before processing the request.

10. Personal Data Breach Notification

In the event of a Personal Data breach, we will notify you and the supervisory authority in writing within 3 x 24 hours at the latest from the moment we become aware of it, as required by Article 46 of UU PDP, covering which data was exposed, when and how it happened, and our remediation efforts.

11. Contact

Questions, complaints, or requests concerning Personal Data:

Katekima
Jl. Sentra Dago Pakar Raya, Mekarsaluyu, Cimenyan District, Bandung Regency, West Java 40198
Email: katekima.contact@katekima.id
Phone / WhatsApp: +62 821-1634-3125

Data Protection Officer (DPO): Muhammad Shobir Abdussyakur, Backend Developer (katekima.contact@katekima.id)

If you are not satisfied with our response, you have the right to lodge a complaint with the personal data protection supervisory authority of the Republic of Indonesia.

12. Changes to This Policy

We may update this policy from time to time. We will notify you of material changes via the website or email no later than 14 days before they take effect. The “Last updated” date above always reflects the current version.