1. Who we are
cmpny.id is operated by cmpny.id, acting as the data controller for the data described on this page.
This policy follows Indonesia's Law No. 27 of 2022 on Personal Data Protection. It covers the cmpny.id site, the client dashboard, and the subscription process — not the contents of sites our clients build on the service.
2. What we collect
We collect only what running the service requires:
- Account data — your name, email address, and password. Passwords are stored hashed, never as plain text, and we cannot read them.
- Organization & subscription data — business name, subdomain, custom domain if you have one, chosen plan, subscription status, and end date.
- Billing data — invoice numbers and amounts, payment status, and the transfer proof you upload. Worth knowing: a transfer proof image usually shows your bank account name and number.
- Site content — the text, logos, and images you upload to be displayed on your site.
- Communications — messages you send us by email or WhatsApp, including the phone number you contact us from.
- Technical data — IP address, browser type, and server logs created automatically when you use the service.
3. Legal basis & purpose
Everything above is processed on a clear basis, for a clear purpose:
- Performing our contract — creating your account, building and serving your site, issuing invoices, and supporting you.
- Legal obligation — keeping financial records and meeting tax rules and lawful requests from authorities.
- Legitimate interest — keeping the system secure, preventing abuse, and diagnosing faults.
- Your consent — for anything beyond those three, such as featuring your site as an example of our work. You can withdraw consent at any time.
4. Cookies
We use two cookies, both strictly necessary for the service to work:
- A session cookie — keeps you signed in after you log in.
- A language cookie — remembers whether you chose Indonesian or English.
5. No third-party tracking
This site carries no Google Analytics, no advertising pixels, and no other third-party trackers. We do not build behavioural profiles and we do not serve ads.
That is also why you will not find a cookie consent banner here — there are no non-essential cookies for you to consent to.
6. We do not sell your data
We never sell, rent, or trade your personal data. It is shared only as far as necessary with:
- The server provider the service runs on, as part of storing data.
- A licensed payment provider, if you pay through that channel — they process your payment data under their own privacy policy.
- Email and WhatsApp providers, limited to the messages you send through those channels.
- Authorities, where the law or a valid official order requires it.
7. How long we keep it
- Site content — while your subscription is active, plus 90 days after the site goes offline, as set out in the Terms.
- Account data — for as long as your account exists. You can ask us to delete it at any time.
- Invoices and payment records, including transfer proofs — up to 10 years, following Indonesian financial record-keeping obligations. These are kept even if your account is deleted.
- Contact-form messages from your site — for as long as you keep them. They are deleted when you delete them from your dashboard, and all of them go with your account. There is no automatic expiry: this is your customers' data, so delete what you no longer need. See section 13.
- Server logs — no more than 12 months, then deleted automatically.
8. Security
The protections we apply:
- Passwords are stored hashed, not in plain text.
- All traffic runs over an encrypted connection (HTTPS).
- Access to data is limited by role, and uploaded files are separated per client.
- Administrative access to the server is restricted to those who need it.
9. If there is a data breach
No system is perfectly secure. If personal data is breached, we will notify you and the relevant authority within 3x24 hours of becoming aware of it, as Indonesia's Personal Data Protection Law requires.
That notice will explain what data was affected, what happened, and what we are doing about it.
10. Your rights
Under the Personal Data Protection Law, you have the right to:
- Know what data we hold about you and request a copy of it.
- Correct data that is wrong or out of date.
- Ask us to delete your data, where no legal obligation requires us to keep it.
- Withdraw consent you gave earlier, without affecting processing already carried out.
- Object to or restrict certain processing of your data.
- Receive your data in a machine-readable format, or ask us to send it to another provider.
- Complain to us, and pursue legal remedies if your complaint is not resolved.
11. How to exercise your rights
Send your request to hello.cmpny.id@gmail.com from the email address registered on your account, so we can confirm it is you.
We respond within 3x24 hours. Most account and content changes you can also make yourself from the dashboard, without waiting for us.
12. Children's data
This service is for businesses, not children. We do not knowingly collect personal data from anyone under 18. If that happens without our knowledge, tell us and we will delete it.
13. Visitors to our clients' sites
Sites our clients build on this service are their sites. For data they collect from visitors — through a contact form, for instance — the client is the data controller and their own privacy policy applies. Our role is limited to being the processor that stores it on their behalf, on the terms set out in section 7 of the Terms of Service.
To be concrete about what is stored: when a visitor submits a contact form on a client's site, the message is handed to the client's WhatsApp as it always has been, and one copy is kept for that client. The copy holds the answers the visitor typed together with the labels of the fields they filled in, and the time it was sent.
- We store no IP address, browser details, or tracking data alongside the message.
- The contents are readable only by the client who owns the site, from their own dashboard. Our administration panel shows how many messages there are and when they arrived — never what they say.
- A client can delete a message at any time, and all of them are deleted with the client's account. Otherwise a message is kept for as long as the client keeps it.
- If you are a visitor who wants a message removed, contact the business whose site you sent it to — they are its controller. You can also reach us at hello.cmpny.id@gmail.com and we will pass the request on to them.
14. Changes to this policy
We may update this policy. The effective date at the top of the page always shows the current version, and we will notify you of material changes by email or in your dashboard before they take effect.
15. Contact us
Questions, requests about your data, or objections to how we process it can go to hello.cmpny.id@gmail.com, or WhatsApp at https://wa.me/6281375604104.
See also: Terms of Service