Legal

Privacy Policy

How E-Pondok and PT Joyo Digitama Solusi collect, use, and protect your personal data — including facial biometric data. Effective as of 12 July 2026.

Introduction

This policy explains the privacy practices of E-Pondok (the “Service”), the facial attendance system, digital guest book, and institutional relationship management for pondok (Islamic boarding schools). The controller of personal data under this policy is PT Joyo Digitama Solusi, a software company incorporated in Indonesia.

By registering, managing a pondok, enrolling a face, or using the Service, you agree to the practices described here. This policy is drafted with reference to the Personal Data Protection Law (Law No. 27 of 2022) and is aligned with GDPR principles.

For pondok administrators

If you are a pondok admin or pengurus, you act as the controller of the data of santri, ustadz, and visitors that you record in the system. PT Joyo Digitama Solusi acts as a processor of that data on your instructions.

Data we collect

Facial biometric data

During enrollment and attendance capture, the kiosk camera processes facial frames locally on the device — including anti-spoofing checks to reject photos, videos, or fake masks. What is transmitted and stored on the server is a numeric vector (512-dimensional embedding), not a photo file or facial recording.

  • Facial embeddings are stored in Cloudflare Vectorize for fast matching.
  • Enrollment metadata: capture quality, device, and time.
  • Raw frames are not stored permanently on the server.

Attendance & visitor data

  • Attendance events: entry/exit time, direction, confidence score, recording device.
  • Guest book: name, phone, category, purpose, check-in/out time, visit contribution.

Relationship contact data

  • Name, institution, position, expertise, status, notes, as well as collaboration and follow-up tags.

Account & authentication data

  • Email and/or phone number for passwordless magic-link login.
  • Password (if used) is stored as a PBKDF2 hash, not as plain text.
  • User roles and session tokens.

Payment data

Subscription payments are processed by Polar. We do not store card numbers — we only receive subscription status and billing history.

Technical data

  • Access logs, performance metrics, and kiosk device IDs for synchronization and security.

Purposes & legal bases

  • Recording attendance via facial matching — administering pondok operations.
  • Guest book & relationships — managing visits and institutional networks.
  • Account security — authentication, device verification, abuse prevention.
  • Billing — managing subscriptions and seats.
  • Legal compliance — applicable record-keeping and retention obligations.
Biometric consent

Processing of facial biometric data falls into a special category of data. We process it on the basis of your consent (for your own account) and the consent you collect from each person whose face is enrolled.

Storage & retention

Data is retained while the subscription is active and for as long as needed for the purposes above. Embeddings and enrollment records can be disabled at any time from the dashboard; deleting a person is a soft delete that can be made permanent on request.

  • Facial embeddings are disabled when the enrollment is deleted or the person is archived.
  • Attendance and visitor data is retained for the duration of the subscription for reporting.
  • Account data can be fully deleted on request via the contact below.

Data sharing

We do not sell personal data. Processing involves:

  • Polar — payment processor.
  • Cloudflare — infrastructure (Workers, D1, Vectorize, R2, Email).
  • Your pondok administrators — admins/ustadz you grant access to in the relevant pondok.

Data between pondok is never mixed: each pondok has its own subdomain and an isolated data space. We only share data when required by law or by a legitimate authority request.

Security

  • All traffic is encrypted in transit (TLS).
  • Each kiosk signs requests with an Ed25519 key; revoked kiosks are rejected.
  • Layered tenant isolation: subdomain, pondok_id on every row, and the pondok claim in the session token.
  • Passwords are hashed with PBKDF2; passwordless login via email magic link.

Your rights (PDP Law)

As a data subject, you have the right to:

  • Access and obtain a copy of your personal data.
  • Correct inaccurate data or complete incomplete data.
  • Request deletion of data, including facial embeddings.
  • Withdraw consent for biometric processing — withdrawal stops facial matching.
  • Raise objections and lodge complaints with the data protection authority.

To exercise these rights, contact your pondok administrator (for pondok data) or privasi@epondok.id for requests related to accounts and infrastructure.

Children's & student data

Some santri may be minors. Face enrollment and attendance recording for santri is carried out by authorized pengurus or guardians of the pondok. Pondok administrators are responsible for collecting guardian consent in accordance with applicable requirements.

Cross-border data transfer

Cloudflare’s infrastructure runs on a global edge network; data may be processed outside Indonesia for performance and resilience purposes. We select providers with equivalent protections and restrict access to what is technically necessary.

Changes to this policy

This policy may be updated as the Service evolves. Material changes will be announced via the app or by email. The effective date at the top indicates the currently applicable version.

Contact

Questions regarding privacy or data-rights requests may be sent to privasi@epondok.id or addressed to PT Joyo Digitama Solusi.