KuboBahasa Indonesia
CV CERDAS BERSAMA TEKNOLOGI

Privacy Policy

How Kubo collects, uses, protects, and deletes personal and business data.

Last updated
May 26, 2026
Privacy and support contact
support@hikubo.id

If the Indonesian and English versions differ, the Indonesian version controls.

1. Controller and contact2. Data we process3. Purposes and legal bases4. WhatsApp and channel privacy boundary5. AI, models, and business decisions6. Processors, vendors, and cross-border processing7. Retention8. Your rights9. Account deletion10. Security and incidents11. Children12. Changes

1. Controller and contact

Kubo is operated by CV CERDAS BERSAMA TEKNOLOGI, located in Pontianak, West Kalimantan, Indonesia. Send privacy questions, support requests, data subject requests, and deletion requests to support@hikubo.id.

This policy covers the Kubo service for business setup, rules, audit, billing, Kubo Chat, approved WhatsApp sources, and operational modules.

2. Data we process

We process data needed to run the service. The exact data depends on the features your business uses.

  • Account and authentication data: name, email, Firebase UID, session status, and login security information.
  • Business data: business profile, memberships, branches, warehouses, settings, business rules, audit, business facts, documents, inventory, POS, finance, purchasing, employees, payroll, cash advances, and tasks.
  • Channel data: WhatsApp/channel account metadata, approved groups and senders, accepted business messages, and minimal metadata for rejected messages.
  • AI and memory data: owner instructions, action drafts, classifications, Kubo conversations, business facts, and semantic memory when enabled.
  • Billing and support data: subscription status, invoices, Midtrans payment references, and support messages.
  • Device, security, and performance logs needed to keep the service safe and reliable.

3. Purposes and legal bases

We use data to provide the service, open secure sessions, run business workflows, process approved WhatsApp sources, create AI drafts, keep audit trails, process billing, secure the platform, and comply with law.

Legal bases may include service contract necessity, explicit consent where required, legal obligations, or legitimate interests balanced with user rights.

4. WhatsApp and channel privacy boundary

Connecting WhatsApp does not give Kubo permission to read every chat. Read permission starts only after the owner chooses the account, groups, and senders Kubo may process.

Messages from unapproved sources should fail closed. Rejected message bodies must not become accepted business history, AI memory, recaps, documents, or business module data.

5. AI, models, and business decisions

Kubo may use AI to read reports, classify messages, create drafts, summarize, answer questions, and support audit. AI output is operational assistance.

Owners and admins remain responsible for reviewing important decisions such as saving records, stock changes, payroll, pricing, payments, and business documents.

6. Processors, vendors, and cross-border processing

We may use infrastructure, authentication, payment, WhatsApp/transport, AI, memory/vector, monitoring, and support providers. Examples include Firebase/Google, Midtrans, WhatsApp/Meta, hosting providers, AI gateways/models, and observability systems.

We do not sell personal data. Some vendors may process or store data outside Indonesia. Kubo applies Indonesian personal data protection principles, contracts, access controls, and reasonable technical safeguards.

7. Retention

Account and business data is kept as long as needed to provide the service, maintain security, resolve disputes, meet legal, tax, or audit obligations, and while the account or business remains active.

Rejected source data is kept minimal. Backups and logs may remain until normal rotation where immediate deletion is not technically possible.

8. Your rights

You may request access, correction, update, deletion/destruction, restriction, consent withdrawal, portability, objection, or complaints through support@hikubo.id.

We will verify requests and respond under applicable Indonesian law, including 3x24-hour obligations where the Personal Data Protection Law applies.

9. Account deletion

Users can delete their account from Settings. Kubo requires email confirmation before running this destructive action.

Account deletion removes the Kubo account, Firebase Auth user, businesses owned by the user, other memberships, scoped Kubo memory, and known authorization tuples from active systems. Data required for law, tax, security, disputes, or normal backup rotation may remain only as needed.

10. Security and incidents

We use reasonable safeguards such as authentication, access limits, audit, business-scope separation, and monitoring. No system is risk-free.

If a notifiable personal data protection failure occurs, Kubo will notify affected users and the competent authority as required by law, including the 3x24-hour PDP timeline where applicable. Contact support@hikubo.id if you suspect unauthorized access.

11. Children

Kubo is for business owners, admins, and workers. It is not intended for children.

12. Changes

We may update this policy when features, laws, or service operations change. Material changes will be announced in-product, by email, or through support channels where required.