Privacy Policy

How we handle
your data.

This Privacy Policy explains what data our workforce applications collect, why we collect it, how our WhatsApp number-verification integration works, and what rights you have. It applies to the internal business applications built and operated by PT Rekayasa Data Digital (Evercode Software).

Effective date16 September 2026
ControllerPT Rekayasa Data Digital (Evercode Software)
Contact[email protected]

In short: our applications are internal business tools. Accounts are created by your company's admin — there is no public self-signup. We use the WhatsApp Business Cloud API for one purpose only: verifying that a phone number belongs to you when you change it. We never sell data, never share it for advertising or marketing, and verification codes are automatically deleted after use or after 15 minutes.

01Data we collect

We collect only the data needed to operate internal workforce applications for our business clients. There is no public registration: employee and user accounts are created and managed by the client's company admin, not by users signing themselves up.

  • Employee / user account data — employee ID number (NIP), name, email address, mobile phone number, department, job title, level, and role / access rights, entered by the company admin of the client organisation.
  • Audit log data — a record of each data change (who changed what, and when), generated automatically by the application for internal compliance.
  • WhatsApp verification data — during phone-number verification only: the sender's phone number and the message content containing the 6-digit verification code, received via the WhatsApp Business Cloud API webhook after you send it from your own WhatsApp account to our business number.

How WhatsApp verification works

When you change your own mobile number in the application, we must confirm that the new number genuinely belongs to you. The flow is:

  • The application generates a one-time 6-digit verification code tied to your account and shows it to you.
  • You send that code from your own WhatsApp account to our business WhatsApp number.
  • We receive — via Meta's WhatsApp Business Cloud API — only the sender's phone number and the message content, and we use them solely to match the code against the pending verification request.

We do not store your WhatsApp messages, we do not read any messages outside of this verification flow, and we do not use this integration for notifications, marketing, or any other messaging purpose.

What we do not collect

We do not collect data through public self-signup, we do not track you for advertising, and we do not pull contact lists, message histories, or any other content from your WhatsApp account beyond the single verification message you choose to send us.

02How we use data

We use the data above strictly for the following purposes:

  • Operating the application — creating and managing employee accounts, enforcing role-based access rights, and running day-to-day workforce processes (such as attendance, leave, overtime, and shift planning) for the client company.
  • Verifying phone-number ownership — matching the 6-digit code you send via WhatsApp against your pending change request, so that notifications and account recovery reach the right person.
  • Internal compliance and security — maintaining insert-only audit logs of who changed what and when, investigating misuse, and protecting the integrity of company records.
  • Support and maintenance — diagnosing technical issues and keeping the systems we built running for our clients.

We do not use your data for advertising, profiling for marketing, or any purpose unrelated to operating these business applications.

03Data sharing and third parties

We do not sell your data, and we do not share it with third parties for advertising or marketing. Data is disclosed only as follows:

  • Your employer (our client) — employee data in the application belongs to the client organisation's HR and operational processes and is visible to its authorised admins according to role-based access rights.
  • Meta Platforms / WhatsApp — solely for the technical sending and receiving of the verification message described in Section 1. When you send the verification code to our business number, that message necessarily passes through Meta's WhatsApp infrastructure under Meta's own terms. Our use of the WhatsApp Business Cloud API is subject to the Meta Platform Terms, and data processed through WhatsApp's business products is additionally subject to the WhatsApp Business Data Processing Terms and the WhatsApp Privacy Policy. We encourage you to review those policies.
  • Legal obligations — where required by applicable law or a lawful order of an Indonesian authority, and only to the extent strictly necessary.

Apart from the technical transmission and receipt of the WhatsApp verification message itself, data is stored on servers owned and controlled by the company — it is not hosted on, or routinely disclosed to, any other third-party service.

04Retention and deletion

How long we keep data

  • Verification codes and verification messages are deleted automatically once used, or when they expire — no later than 15 minutes after issuance.
  • Employee / user account data is kept for as long as the account is active and as required by the client company's legitimate HR and operational needs and applicable law. When employment ends or an account is deactivated by the company admin, the data is removed or anonymised within a reasonable period, unless a law requires longer retention.
  • Audit logs are insert-only and cannot be deleted through the application. They are retained for internal compliance for as long as necessary to demonstrate the integrity of company records and to meet legal obligations.

How to request deletion

To request access, correction, or deletion of your data, contact your company's admin in the first instance, or email us at [email protected] with your name, company, and the data concerned. We will verify your identity, coordinate with the client company that controls the HR record, and respond within a reasonable time and no later than required by applicable law.

Please note that where an audit-log entry is required for compliance or legal purposes, that entry may be retained even after the underlying account data is deleted; in that case we will explain the legal basis in our response.

05Security

We apply appropriate technical and organisational measures to protect personal data, including:

  • Encryption in transit — all traffic between your device, our servers, and Meta's WhatsApp API is protected with industry-standard encrypted connections (TLS/HTTPS).
  • Access control — data is accessible only to authenticated users, limited by role-based access rights so each person sees only what their role requires.
  • Self-managed infrastructure — data is stored on servers owned and controlled by the company, with restricted administrative access.
  • Integrity safeguards — audit logs are insert-only, so any change to company records leaves a tamper-evident trail.

No method of transmission or storage is completely secure, and we do not publish internal security details that could weaken these protections — but we continuously review and improve our safeguards as our systems evolve.

06Your rights

Under Indonesia's Personal Data Protection Law (UU No. 27 Tahun 2022 tentang Pelindungan Data Pribadi, "UU PDP"), you have the following rights over your personal data:

  • Right to information — to know what data is held about you and for what purpose (as described in this policy).
  • Right of access — to obtain a copy of your personal data.
  • Right to correction — to have inaccurate or outdated data (for example your phone number, department, or job title) corrected, including through your company admin.
  • Right to deletion — to request erasure of your data as described in Section 4, subject to legal retention duties such as compliance audit logs.
  • Right to withdraw consent — where processing is based on consent, to withdraw it; withdrawal does not affect processing already carried out.
  • Right to object and to lodge a complaint — to object to processing you consider unlawful and to file a complaint with the competent Indonesian data-protection authority.

To exercise any of these rights, email [email protected]. We will verify your identity and handle your request in accordance with the UU PDP.

07Contact us

For any question about this policy, your personal data, or a rights request, contact:

PT Rekayasa Data Digital (Evercode Software)
Plaza Mutiara 8th Floor, Kuningan, South Jakarta, Indonesia
Email: [email protected]

08Effective date and changes

This policy is effective from 16 September 2026.

We may update this policy from time to time — for example when our data flows change, when we adopt a new integration, or when the law requires it. When we make material changes, we will update the effective date above and, where appropriate, notify users through the application or through the client company's admin before the changes take effect. Continued use of the application after an updated policy takes effect signifies acceptance of the update.

Questions about your data?

Reach out to our privacy contact and we'll get back to you. For account changes such as updating your department or role, your company admin is the fastest route.

Email
Address
PT Rekayasa Data Digital
Plaza Mutiara 8th Floor, Kuningan, South Jakarta