Skip to content
Rahat
Rahat FieldRahat EngageRahat InsightPricing
Sign inRequest a demo

DRAFT — not legal advice. Every bracketed value is an unfilled blank, and this page must be reviewed by counsel before it is published. Delete this banner when it has been.

Privacy Policy

How Rahat handles personal data, under Undang-Undang No. 27 of 2022 on Personal Data Protection.

Last updated
[DATE]

Contents

  1. 1. Who this covers, and in what role
  2. 2. What we collect from console users
  3. 3. What the field app records
  4. 4. The attendance selfie, and the liveness check
  5. 5. What we do not collect
  6. 6. Location, and when it is recorded
  7. 7. Photographs as evidence
  8. 8. Consent, where consent is the basis
  9. 9. How long we keep it
  10. 10. Records that are kept as a history
  11. 11. Your rights under UU PDP
  12. 12. Who else can see it
  13. 13. Where it is stored
  14. 14. Security
  15. 15. Children
  16. 16. Changes
  17. 17. Contact and complaints

1. Who this covers, and in what role

Two different relationships sit behind one product. For the agency or brand that subscribes, we are the processor and never the owner: the staff records, outlet data and captured work are proprietary to the subscriber or to the principal whose work they document, and the subscriber decides what is collected and why. For the people who hold accounts with us directly, and for visitors to this website, we are the controller.

If you are a field worker asking what is held about you, your employer is the right first point of contact — they decide what the app collects. We will help them answer.

2. What we collect from console users

Name, work email, the role granted to you, and a record of your sign-ins — when, from where, and from which device. Sign-in history exists so an access dispute can be settled with facts rather than recollection.

3. What the field app records

Attendance events with the time and place they were made; visits and the answers submitted on them; photographs taken as evidence; the device’s identifier, model, app version and battery level; and, while a shift is running, periodic location points.

The device identifier is minted on the handset. It lets a lost phone be revoked without knowing anything more about the person carrying it.

4. The attendance selfie, and the liveness check

Clocking in takes a photograph of the worker. Before it is accepted the camera analyses movement on the device to confirm a live person is present rather than a photograph of one.

That analysis runs entirely on the handset. What leaves it is the outcome, the timing of each challenge, and non-biometric signal values — booleans and ratios used to tell a live capture from a spoofed one. The selfie itself is sent as attendance evidence, which the worker is told about at enrolment.

Individual frames from that check are not stored. Frame storage is a project setting that is off by default; where a client turns it on, those frames carry their own retention window and their own line in the enrolment notice.

5. What we do not collect

We do not create, transmit or store a face template, embedding, descriptor or landmark set. No crop of the face region is kept. This is not a preference we could quietly change: it is the condition the liveness feature was approved on, and it is asserted by a test so that a future change cannot begin storing them unnoticed.

The camera is used to confirm a live capture. It is not used to identify anyone against a database of faces.

6. Location, and when it is recorded

Location is recorded when a worker clocks in or out, when a visit is opened or closed, and at intervals while a shift is running — every two minutes by default — so that a route can be reconstructed and coverage measured.

It is not recorded outside a running shift, and that boundary is enforced by the server as well as by the app: readings that fall outside a shift are discarded on arrival, because a device left to decide when to stop tracking is a device that can be made to lie about it. A gap in a trail can mean lost signal, a flat battery or a phone left in a drawer, which is why battery level is recorded alongside it — those need different responses and should not be guessed at.

7. Photographs as evidence

Photographs taken in the field carry a watermark burned into the image: the worker’s name, the coordinates and the time, and their identity number where the employee record holds one. It is burned in rather than drawn over, because a photograph used to settle a dispute has to carry its own claim.

Where an identity number is held, it is therefore present inside the image file itself. Subscribers should take that into account before sharing photographs outside their organisation.

8. Consent, where consent is the basis

Where the platform captures details of a member of the public — a visitor at an activation, or a consumer lead — consent is required and is enforced by the database itself: such a record cannot exist without recorded consent. Stored with it are the wording that was agreed to, the version of that wording, the moment of agreement and the signature, so it can be shown not merely that consent was given but which words were consented to.

For the agency’s own staff, the basis is normally the employment relationship and the subscriber’s legitimate interest in verifying work done, not consent. Your employer should be able to tell you which applies.

9. How long we keep it

Unless a subscriber’s contract sets a different period, records are kept for two years from the date they were created. Two years is the window a year-on-year comparison needs: with less than that there is no equivalent period to compare against, and a subscriber can read this year against last from their own data rather than reconstructing it.

The two years covers everything held for a subscriber, including what a record produced. An alert raised from a submission, a supervisor’s finding, a photo-audit sample and a planogram analysis are all kept for the same period as the record they came from, and are deleted with it. Nothing is kept indefinitely because something else came to point at it.

The photograph taken when a worker clocks in is kept for six months from the day it was submitted — an attendance question usually surfaces at the end of a payroll cycle rather than during it. Photographs captured on a visit are kept for three months. Both are deleted at the end of their period.

The record a photograph belongs to is not deleted with it. An attendance event, a visit or a submission is the history that settles a payroll question or a client dispute later, so what goes is the image and what stays is the fact it evidenced, marked to show the image is no longer held.

When a subscription ends, the subscriber keeps access for one month so it can export its data. After that month we delete it.

10. Records that are kept as a history

Records of work done — attendance, visits, submissions, photographs and location points — are kept as an unalterable history, because they are what settles a payroll question or a client dispute months later. Unalterable is about what may be changed, not about how long: they are held for the period in section 9 and then deleted.

A correction does not overwrite the original. The earlier record is marked void, the change is recorded, and both remain visible. This is deliberate, and it shapes how an erasure request is handled: see below.

11. Your rights under UU PDP

You may ask for access to your personal data, for it to be corrected, for its processing to be restricted or objected to, for it to be erased, and for a copy in a portable form.

Where we hold data as a processor for a subscriber, we will pass your request to them and support them in answering it. Where a record forms part of the history described above, we will explain what can be erased, what must be retained and on what basis, rather than deleting silently or refusing without a reason. Requests are answered within [RESPONSE PERIOD].

12. Who else can see it

A subscriber’s data is separated from every other subscriber’s, and that separation is enforced by the database rather than remembered by the application. A client of an agency can be granted a read-only view of their own project and nothing else.

We use third parties to host and operate the service, and where required for crash diagnostics. Current sub-processors: [SUB-PROCESSOR LIST].

13. Where it is stored

Personal data is stored in [HOSTING REGION]. Where data is transferred outside Indonesia we will do so only on a basis UU PDP permits, and will name that basis here: [TRANSFER BASIS].

14. Security

Access to the console is granted by role and can be withdrawn. Credentials and the device identifier are held behind the operating system’s own protection on the handset, and a device can be revoked. The field app computes a checksum for every file it uploads and the server verifies it, refusing a file that does not match rather than storing a corrupt record.

No system is beyond compromise. If a breach affects your personal data we will notify as UU PDP requires.

15. Children

The service is not intended for anyone under 18, and we do not knowingly collect their personal data.

16. Changes

We will update this policy as the service changes. Where a change materially affects how personal data is handled we will give notice, and the date at the top is always the date of the current version.

17. Contact and complaints

Write to [PRIVACY CONTACT EMAIL], or [COMPANY LEGAL NAME], [REGISTERED ADDRESS]. If you are not satisfied with our answer you may complain to the supervisory authority.

Rahat

One connected platform for field execution, customer engagement and business intelligence.

Rahat Field

  • Attendance
  • Journey plans
  • Forms and capture
  • Store audit
  • Planogram and POSM
  • Exports

Rahat Engage

  • Retailer loyalty
  • Consumer CRM
  • Campaigns and rewards
  • Surveys and feedback

Rahat Insight

  • Dashboards
  • Reporting schema
  • Custom reports
  • Data integration

Company

  • About
  • Contact
  • Privacy (UU PDP)
  • Terms
© 2026 Rahat · rahat-tech.comPersonal data handled under UU PDP