Privacy Policy
How Kubo collects, uses, protects, and deletes personal and business data.
- Last updated
- May 26, 2026
- Privacy and support contact
- support@hikubo.id
If the Indonesian and English versions differ, the Indonesian version controls.
1. Controller and contact
Kubo is operated by CV CERDAS BERSAMA TEKNOLOGI, located in Pontianak, West Kalimantan, Indonesia. Send privacy questions, support requests, data subject requests, and deletion requests to support@hikubo.id.
This policy covers the Kubo service for business setup, rules, audit, billing, Kubo Chat, approved WhatsApp sources, and operational modules.
2. Data we process
We process data needed to run the service. The exact data depends on the features your business uses.
- Account and authentication data: name, email, Firebase UID, session status, and login security information.
- Business data: business profile, memberships, branches, warehouses, settings, business rules, audit, business facts, documents, inventory, POS, finance, purchasing, employees, payroll, cash advances, and tasks.
- Channel data: WhatsApp/channel account metadata, approved groups and senders, accepted business messages, and minimal metadata for rejected messages.
- AI and memory data: owner instructions, action drafts, classifications, Kubo conversations, business facts, and semantic memory when enabled.
- Billing and support data: subscription status, invoices, Midtrans payment references, and support messages.
- Device, security, and performance logs needed to keep the service safe and reliable.
3. Purposes and legal bases
We use data to provide the service, open secure sessions, run business workflows, process approved WhatsApp sources, create AI drafts, keep audit trails, process billing, secure the platform, and comply with law.
Legal bases may include service contract necessity, explicit consent where required, legal obligations, or legitimate interests balanced with user rights.
4. WhatsApp and channel privacy boundary
Connecting WhatsApp does not give Kubo permission to read every chat. Read permission starts only after the owner chooses the account, groups, and senders Kubo may process.
Messages from unapproved sources should fail closed. Rejected message bodies must not become accepted business history, AI memory, recaps, documents, or business module data.
5. AI, models, and business decisions
Kubo may use AI to read reports, classify messages, create drafts, summarize, answer questions, and support audit. AI output is operational assistance.
Owners and admins remain responsible for reviewing important decisions such as saving records, stock changes, payroll, pricing, payments, and business documents.
7. Retention
Account and business data is kept as long as needed to provide the service, maintain security, resolve disputes, meet legal, tax, or audit obligations, and while the account or business remains active.
Rejected source data is kept minimal. Backups and logs may remain until normal rotation where immediate deletion is not technically possible.
8. Your rights
You may request access, correction, update, deletion/destruction, restriction, consent withdrawal, portability, objection, or complaints through support@hikubo.id.
We will verify requests and respond under applicable Indonesian law, including 3x24-hour obligations where the Personal Data Protection Law applies.
9. Account deletion
Users can delete their account from Settings. Kubo requires email confirmation before running this destructive action.
Account deletion removes the Kubo account, Firebase Auth user, businesses owned by the user, other memberships, scoped Kubo memory, and known authorization tuples from active systems. Data required for law, tax, security, disputes, or normal backup rotation may remain only as needed.
10. Security and incidents
We use reasonable safeguards such as authentication, access limits, audit, business-scope separation, and monitoring. No system is risk-free.
If a notifiable personal data protection failure occurs, Kubo will notify affected users and the competent authority as required by law, including the 3x24-hour PDP timeline where applicable. Contact support@hikubo.id if you suspect unauthorized access.
11. Children
Kubo is for business owners, admins, and workers. It is not intended for children.
12. Changes
We may update this policy when features, laws, or service operations change. Material changes will be announced in-product, by email, or through support channels where required.