Legal
Privacy Policy
Last updated: 1 September 2026
Draft for legal review. Must be checked against Indonesia's Personal Data Protection Law, UU 27/2022, before publication.
Kepiai is operated by [legal entity name], Jakarta, Indonesia. This policy explains what we collect, why, and what you can ask us to do with it.
What we collect
- Account data — name, work email, company, role, billing details of people using Kepiai on your behalf.
- Platform data — metrics, content, public interaction data from social accounts you authorise, via official Instagram/TikTok/Facebook APIs.
- Public data — publicly available metrics from competitor accounts you nominate.
- Usage data — platform usage, for support and improvement.
How we access it
We access your platform data only through official APIs, and only after you authorise the connection. We do not scrape, and we do not ask for your platform passwords. You can withdraw authorisation at any time from the platform itself or by writing to us.
Why we process it
To deliver the analytics and reporting you have contracted us for, to support your account, and to meet legal and accounting obligations. We do not sell your data and we do not use it to train third-party models.
Where it is stored and who can access it
Data is stored on [provider, region]. Access is limited to Kepiai personnel who need it to deliver your service, under confidentiality obligations. Sub-processors are listed at [link].
How long we keep it
For the term of your agreement plus [x] months, unless you ask us to delete it sooner or law requires us to keep it longer.
Your rights
You may request access, correction, deletion or export of your data, and you may object to certain processing. Write to halo@kepiai.co and we will respond within [x] working days.
Changes
We will post changes on this page and notify account holders of anything material.
