Privacy Policy
Epektibo mula 9 Oktubre 2026
Ibinibigay ang salin na ito para sa kaginhawahan. Kung may pagkakaiba, ang bersyon sa Bahasa Indonesia ang masusunod. Bahasa Indonesia
This Privacy Policy explains which personal data PT. Inolab Teknologi Indonesia ("Inolab", "we") collects when you use Inolab at inolab.id and app.inolab.id, what it is used for, who it is shared with, and your rights over it, in line with Law No. 27 of 2022 on Personal Data Protection.
1. Our role
For your account data, we are the data controller. For data you enter about your customers, such as names, contacts, tax IDs, addresses and invoices, your business is the data controller and we process that data on your business's behalf, only to provide the service. Customers who want to access or change their data should contact the business that invoices them.
2. Data we collect
- Account data: name, email, password (stored as a hash, never as plain text), language preference, and two-factor authentication settings (the secret key is stored encrypted).
- Business data: business and legal name, address, phone, email, tax ID (NPWP), payment instructions, and team members with their roles.
- Data you enter: customers, invoices, payment records and internal notes.
- Subscription payment data: plan, amount, status and the transaction reference from the payment provider. We do not receive or store card numbers, PINs or bank account passwords.
- Technical data: IP address, browser and device type, and activity times, for sign-in sessions, sign-in rate limiting and the activity log.
- Mobile app: device name and notification token, if you use the mobile app and turn on notifications.
3. How we use data
- To provide the service: accounts, invoices, reports and teamwork.
- To send service email: email verification, password resets, team invitations, invoices you send to customers, and subscription reminders and confirmations.
- To process subscription payments.
- To keep the service secure: two-factor authentication, abuse prevention and the activity log.
- To meet legal obligations, such as keeping transaction records.
The legal bases are performing our agreement with you (the Terms of Service), complying with legal obligations, our legitimate interest in keeping the service secure, and your consent where required. We do not sell personal data or use it for advertising.
4. Who receives data
- Payment providers (Midtrans, Xendit): the account owner's name and email, the plan name and the amount paid, when you pay for a subscription.
- Hosting and email providers: where our application, database and email delivery run.
- Firebase Cloud Messaging (Google): device tokens and notification content, only when mobile app notifications are on.
- AI provider for the AI assistant: OpenAI (United States), or Anthropic (United States) if we switch to it: only when the business owner turns it on in Settings › AI. That page names the provider in use, and consent is asked again when the provider changes. Sent: team members’ questions and the business data needed to answer them within the asker’s access (for example customer names, invoice amounts, report summaries and activity notes), and invoice details for payment reminder drafts. Email addresses, phone numbers, tax numbers and street addresses are not sent. The AI provider processes the data on our behalf and, under its API terms, does not use API data to train models. OpenAI keeps abuse-monitoring logs for up to 30 days; we ask OpenAI not to store conversations. The owner can turn the feature off at any time.
- Authorities: when required by law.
5. Cookies
The inolab.id site does not use cookies. The app at app.inolab.id uses cookies that are needed for sign-in sessions and form protection. We do not use advertising, analytics or third-party tracking cookies.
6. Retention and deletion
Data is kept while your account or business is active. If you ask us to delete your account or business, the data is deleted within a reasonable time, except data we must keep longer by law, such as payment transaction records.
7. Security
Data is sent over encrypted connections (HTTPS). Passwords are stored as hashes, two-factor secrets and sessions are stored encrypted, each business's data is kept separate from other businesses, and access within a team is limited by role. No system is free of risk; if a personal data protection failure occurs, we will notify you as required by law.
8. Your rights
You have the right to information about how your data is processed, to access and obtain a copy of your data, to correct inaccurate data, to request deletion, and to withdraw consent you have given. You can change most data yourself in Settings. For other requests, email support@inolab.id from your account's email address.
9. Children
Inolab is intended for businesses and is not directed at children.
10. Changes to this policy
We may update this Privacy Policy. We will announce important changes by email or in the app before they apply. The effective date is shown at the top of this page.
11. Contact
Privacy questions can be sent to support@inolab.id.