Privacy policy
PT Teknologi Otomatis Indonesia · Effective 17 September 2026
This policy explains what personal data PT Teknologi Otomatis Indonesia ("Tekomata", "we") processes when you use tekomata.com, why, who we share it with, how long we keep it, and how you can have it corrected or deleted. It is written to comply with Indonesia's Personal Data Protection Law (Law No. 27 of 2022).
1. Who is responsible
For your own account, PT Teknologi Otomatis Indonesia is the data controller. For the data a shop enters about its own buyers, suppliers and contacts, the shop is the controller and Tekomata processes that data on the shop's behalf and only to provide the service.
- PT Teknologi Otomatis Indonesia
- Email: halo@tekomata.com
2. What we collect
- Account data: your name, email address, business name, and a password stored only as a one-way hash.
- Sign-in data: session tokens (stored hashed), email verification codes and password-reset links, which expire.
- Business data you enter: products, prices, stock, invoices, payments, purchase records, settings, uploaded import files, and the knowledge you give your AI about your business.
- Contact data about other people that you enter: names, phone numbers, email addresses, addresses and tax numbers of your buyers and suppliers.
- Billing data: top-up requests, transfer references, credit balance and plan purchases.
- Email records: to whom we sent an email, its subject and whether it was delivered.
- Technical logs: IP address, request path, time and a request identifier, used to operate and secure the service. Some logs contain the email address involved in a sign-in or an email we sent.
- Cookies: a sign-in cookie, a language preference cookie, and for Tekomata staff a separate dashboard cookie. We use no advertising or analytics cookies.
3. Why we use it
- To provide the service you signed up for: your catalogue, invoices, stock and billing.
- To send the emails the service needs: verification codes, password resets, invoices you choose to send, payment reminders and top-up notices.
- To keep the service secure: preventing abuse, investigating problems and limiting repeated sign-in attempts.
- To meet legal obligations, including record-keeping required by Indonesian law.
We do not sell personal data, and we do not use it for advertising.
4. Who we share it with
Only the service providers needed to run Tekomata, bound to use the data only for that purpose:
- Hosting and network providers that store and deliver the service. Their servers may be located outside Indonesia; where that happens we rely on the safeguards Law No. 27 of 2022 requires for transfers abroad.
- An email delivery provider, to send the emails listed above.
- Artificial intelligence providers, only when a shop chooses to scan images or a web page into its AI knowledge: those images or that page text are sent to the provider to be read, and Tekomata does not keep the images. What the provider suggests is saved only if the shop reviews and saves it. No AI provider receives customers' messages.
- Meta Platforms, when a shop connects its Instagram account: replies the shop writes are sent to Instagram through Meta's API so they reach the customer.
We disclose data to authorities only when Indonesian law requires it.
5. WhatsApp and Instagram
A shop can connect its Instagram professional account to Tekomata. When it does, we receive from Meta: the direct messages customers send to that account and the account's replies (text, and the attachment links Meta provides), each customer's Instagram-scoped ID for that account, and the customer's name and username. The account's access token is stored encrypted.
We use this data only to show the shop its conversations and to send the replies the shop writes. It is not used for advertising, not sold, and not given to any artificial intelligence provider. Raw notifications from Meta are deleted 7 days after they are processed. Disconnecting the account deletes its token; the conversations stay as the shop's records until the shop or the customer asks for them to be deleted. WhatsApp is not available yet.
6. How long we keep it
Account and business data are kept while your account is active. When you ask us to delete your account, we delete it within 30 days, except records we are legally required to keep, which are retained only for that period and for no other use. Sign-in codes and links expire within hours. Technical logs are kept only as long as needed to operate and secure the service.
7. Your rights
Under Law No. 27 of 2022 you may ask us to tell you what data we hold about you, give you a copy, correct it, stop processing it, or delete it, and you may withdraw consent. Most account data can be corrected directly in the app. For anything else, email us from the address on your account and we will respond within the time the law requires.
If you are a buyer or supplier of a shop that uses Tekomata, please contact that shop first; it controls your data. You may also contact us and we will pass your request on.
8. Security
Passwords, session tokens and reset links are stored only as hashes. Connections use HTTPS. Access to the internal dashboard is limited to Tekomata staff, and staff actions are logged. No system is perfectly secure; if a breach affects your personal data we will notify you and the authorities as the law requires.
9. Deleting your data
Email halo@tekomata.com from the address on your account and ask for your account to be deleted. We will reply, and we delete your account, your sessions and your business data within 30 days, except records we are legally required to keep.
If you are a buyer or supplier recorded by a shop that uses Tekomata, tell us which shop. That shop controls your data and we will pass the request to them.
10. Changes
We will update this page when what we collect or how we use it changes, and change the effective date above. Significant changes will be announced by email to account holders before they take effect.