Privacy Policy
SIPESAN Privacy Policy
Effective date: August 13, 2026 Last updated: August 13, 2026
SIPESAN ("we", "us", the "Service") is an omnichannel livechat Software-as-a-Service (SaaS) platform operated by PT Tri Sahridaya Teknologi, located at Menara Tendean, 11th Floor, Unit 28, Jl. Kapten Tendean No. 20C, Mampang Prapatan, South Jakarta, Special Capital Region of Jakarta 12710, Indonesia. This Privacy Policy explains how we collect, use, store, and protect personal data in connection with your use of the Service, in accordance with Indonesia's Personal Data Protection Law No. 27 of 2022 ("UU PDP").
1. Our role in data processing
SIPESAN has two distinct roles depending on the data category:
- As Data Controller, for business account data of organizations that sign up for SIPESAN (name, email, phone number of admins/agents, billing data).
- As Data Processor, for end-customer data belonging to the businesses that use our Service (WhatsApp/Telegram/Instagram conversations, names, phone numbers of that business's own customers). In this case, the business using SIPESAN (the "tenant") is the Data Controller for their own customers' data and is responsible for ensuring a valid legal basis for processing (e.g. their customer's consent) under UU PDP.
2. Data we collect
| Category | Examples | Source | |---|---|---| | Business account data | Name, email, phone number, role (admin/supervisor/agent) | Directly from the user at signup | | End-customer conversation data | Name, phone number, message text, media (images/documents/audio), message metadata | Sent by the tenant's own customers via WhatsApp/Telegram/Instagram | | Document verification data (optional feature) | Document images (e.g. payment proof, ID cards if a tenant enables this feature), extracted data | Uploaded/sent by the tenant's customers, processed by AI | | Usage & analytics data | Chat session counts, response times, channel statistics, feature usage events | Automatically from Service usage | | Technical data | IP address, device/browser type (for security & error monitoring) | Automatic | | Payment data | Transaction history, subscription status (card/payment details are processed by a third-party payment gateway, not stored by us) | From the payment process |
We currently have no fixed retention period for end-customer conversation data, customer profiles, or analytics data — data is retained for as long as the tenant's account remains active. A formal retention policy is under development.
3. How we use data
- Providing and operating the livechat Service (message routing, agent assignment, chatbot).
- AI Agent features (optional, tenant-enabled): generating automated replies, intent detection, sentiment detection, and (if enabled by the tenant) image-based document verification.
- Usage analytics for tenants (performance dashboards, channel statistics).
- Billing and subscription management.
- Security, abuse prevention, and legal compliance.
We do not sell personal data to third parties for marketing purposes.
4. Third-party data sharing
| Third party | Data shared | Purpose | |---|---|---| | Meta (WhatsApp Business Platform, Instagram) | Messages, phone numbers, media | Sending/receiving messages on the WhatsApp & Instagram channels | | Telegram | Messages, chat ID | Sending/receiving messages on the Telegram channel | | AI providers (Anthropic, OpenAI, Google Gemini — depending on tenant configuration; or the self-hosted local model "Ollama", which does not send data outside our own servers) | Conversation content, and for the document verification feature: uploaded document images | Generating AI replies, extracting structured data from documents | | Payment gateway provider | Payment transaction data | Processing subscription/credit payments | | Sentry (error monitoring) | Technical error metadata (personal data is scrubbed before transmission) | System stability monitoring |
Cross-border data transfer. If a tenant selects a cloud AI provider (Anthropic, OpenAI, or Google Gemini), conversation data and/or document images processed by the verification feature are sent to that provider's servers outside Indonesia (typically the United States). Businesses that do not want their customers' data processed abroad can select the local AI mode (Ollama, processed entirely on our servers in Indonesia) in their AI Agent settings.
5. Data security
- Cross-business (multi-tenant) data isolation is enforced at both the application and database layers.
- Channel credentials (WhatsApp/Telegram/Instagram tokens) and API keys are stored encrypted.
- Connections to the Service use transport encryption (HTTPS/TLS).
- Access to customer data is restricted by role (admin/supervisor/agent) within the relevant tenant.
6. Your rights as a data subject
Under UU PDP, you have the right to:
- Access the personal data we/the tenant process about you.
- Request correction of inaccurate data.
- Request deletion of your personal data (subject to data we are legally required to retain for bookkeeping/tax obligations).
- Withdraw consent for processing (where processing is based on consent).
The above requests are currently handled manually via the contact below. We aim to respond to valid requests within a reasonable time as required by UU PDP.
If you are a customer of a business that uses SIPESAN (e.g. a WhatsApp user chatting with a store/clinic), requests about your data should first be directed to that business (they are your Data Controller). You may also contact us below and we will help coordinate with the relevant business.
7. Data retention
Business account data is retained for the duration of an active subscription plus any additional period required by legal (bookkeeping/tax) obligations after account closure. A specific retention period for end-customer conversation data has not yet been formally defined (see §2).
8. Children's privacy
The Service is intended for business (B2B) use and does not knowingly collect personal data from minors as account holders. End-customer conversation data from our tenant businesses may include individuals of any age, subject to each tenant business's own privacy practices.
9. Changes to this policy
We may update this Privacy Policy from time to time. Material changes will be communicated via email or an in-app notification.
10. Contact
For privacy questions, data access/correction/deletion requests, or incident reports, contact us at support@sipesan.com.
PT Tri Sahridaya Teknologi Menara Tendean, 11th Floor, Unit 28, Jl. Kapten Tendean No. 20C Mampang Prapatan, South Jakarta Special Capital Region of Jakarta 12710, Indonesia