Privacy Policy
How CV DNA Konsultan processes account, Blueprint, AI, payment, email, support, and operational-log data.
Data, purposes, bases, and retention
| Activity | Main data | Purpose and basis | Retention | Recipients |
|---|---|---|---|---|
| Registration and sign-in | Name, email, password hash, locale, verification status, session, IP, and security events | Contract performance, authentication, security, and fraud prevention | While the account is active; tokens until used or expired; security events follow the log schedule | Operator infrastructure; Google only when OAuth is selected |
| Projects and Blueprints | Ideas, decisions, documents, versions, attachments, and Assistant chats | Provide the requested service and preserve work history | While the project/account is active; deletion requests are handled subject to law, disputes, fraud, and accounting exceptions | Operator infrastructure; AI providers receive only minimum necessary data |
| AI operations | Bounded inputs/outputs, model/provider, tokens, cost, retry/fallback, IP, and sanitised request metadata | Generation, billing, security, diagnosis, and recovery | Raw diagnostics 7 days; attempts 180 days; logical calls 365 days | OpenRouter, OpenAI, and upstream providers selected by the active route |
| Payments and credits | Plan/top-up, invoice, amount, status, Midtrans reference, and credit ledger | Payment, reconciliation, tax, disputes, and fraud prevention | As required for accounting/disputes; cost aggregates after project deletion up to 2,555 days | Midtrans and operator infrastructure |
| Transactional email | Address, name, locale, message type, delivery status and metadata | Verification, password reset, payment, Blueprint status, and service communications | For the operational job/mailbox lifecycle and lawful delivery evidence | Hostinger and operator infrastructure |
| Support | Ticket content, attachments, status, assigned staff, and transition audit | Respond to requests and resolve incidents | 730 days after closure; audit minimum 2,555 days | Authorised staff and operator infrastructure |
| Security and abuse | IP, bounded user-agent, request correlation, error, warning, and audit events | Protect accounts/service, investigate, and meet legal duties | Debug/info 30 days; warning 90 days; error/critical 365 days; audit minimum 2,555 days | Authorised staff and operator infrastructure |
| Optional analytics or marketing | None in this version | Inactive; no third-party analytics script or advertising pixel is loaded | No optional data collected | None |
AI and automated decisions
The minimum project data needed is sent to the provider/model active in AI Routing. Production routes may currently use OpenRouter and OpenAI, including the selected upstream model provider. We bound, sanitise, and record calls for operations; we do not make unqualified promises about third-party training or retention outside their contracts. See the Subprocessor registry for current detail and policy links.
Generated Output requires human review. We do not use it for decisions producing legal or similarly significant effects on individuals without an appropriate basis and safeguards.
Recipients and international transfers
Minimum necessary data may reach operator-managed infrastructure, Hostinger email, Google OAuth, Midtrans payments, OpenRouter/OpenAI processing, and vendors in the Subprocessor registry. Some processing may occur outside Indonesia. We assess available contract, purpose, location, and transfer safeguards; third-party use remains subject to their policies.
Operational retention schedule
- Encrypted raw AI diagnostics: 7 days.
- AI attempt detail: 180 days; logical calls: 365 days.
- System debug/info: 30 days; warnings: 90 days; error/critical: 365 days.
- Aggregated cost after project deletion: up to 2,555 days.
- Closed Support tickets: 730 days; audit minimum: 2,555 days.
- Verification/reset tokens: until expiry or use. Active account/project data is kept while the account is active; valid deletion requests are actioned unless law, disputes, fraud, or accounting require longer retention.
Security and internal access
Controls include password hashing, hashed single-use tokens, TLS, role-based access, audit events, log sanitisation, restricted diagnostic detail, backups, and a private database. Internal access is limited to operations, support, security, and legal duties. No system is risk-free.
Data-subject rights
Subject to applicable law, you may request information, access, a copy, correction, updates, deletion, consent withdrawal, restriction or objection, portability, and damages. We may verify identity and authority. Requests can be submitted without signing in through hello@aiblueprint.web.id or the Contact page. Do not send passwords, API keys, OTPs, or full payment details.
Children and high-risk data
The service is intended for people aged 18 or over. Do not submit children’s, health, biometric, personal financial, or other specific data unless you have required authority, legal basis, and safeguards. Contact us if such data was submitted without permission.
Incidents, changes, and contact
We investigate incidents, contain impact, and notify data subjects and/or authorities within legally required time and content. Material changes are notified and may require reacceptance. Requests can be submitted without signing in through hello@aiblueprint.web.id or the Contact page. Do not send passwords, API keys, OTPs, or full payment details.