Privacy Policy
This policy explains what PT. Metaseti Digital Indonesia ("Metaseti", "we") collects when you visit metaseti.com or get in touch, how we handle personal data in the systems and products we run for clients, and the rights you have over it.
Last updated 14 September 2026
Who we are
PT. Metaseti Digital Indonesia is a technology company registered in Jakarta, Indonesia. We are responsible for the personal data described in this policy, except where we process it on behalf of a client — see “Data we process for clients” below.
Where one of our products collects data directly, it has its own privacy notice as well. Meta-Koda's is at koda.metaseti.com/privacy.
What we collect on this website
This website has no forms that store what you type. When you book a call or send an enquiry, your email app or WhatsApp sends the message to us directly, so we receive only what you choose to include — usually your name, email address or phone number, company, and the details of your project.
When you browse, our hosting provider keeps standard server logs (IP address, browser and device type, pages requested, timestamps) for security and reliability, and we may look at them in aggregate to see how the site is used. The site runs no analytics, advertising or cross-site tracking, and sets no cookies — see our Cookie Policy.
Why we use it
To reply to your enquiry and prepare a proposal; to deliver and support the work you engage us for; to operate and secure this website; and to meet our legal, tax and accounting obligations. We do not sell personal data, and we do not use it for advertising.
Legal basis
Under Indonesia's Personal Data Protection Law (Law No. 27 of 2022), we rely on your consent when you contact us, on the performance of a contract when you are our client, on our legal obligations, and on our legitimate interest in answering enquiries and keeping our systems secure. You may withdraw consent at any time.
Data we process for clients
When we build or operate a system for a client — including our products Meta-Koda, Kinetik, Rackly and Amara — the client decides what data goes into it and why. The client is the controller of its customers' and employees' data; Metaseti is its processor. We process that data only on the client's instructions and under the engagement's agreement, keep each client's data separate from every other client's, and never use one client's data for another client or for our own purposes.
If you are a customer or employee of one of our clients, the quickest route for a question about your data is that business. You can also write to us, and we will work with them to answer it. Where we operate a WhatsApp Business account for a client, the relationship is listed on our Clients page.
AI in our products
Meta-Koda writes replies with an enterprise AI provider, currently Google's Gemini API. The conversation and the business's own settings — its menu, opening hours and booking rules — are sent to the provider only to produce that reply, and under the paid terms we use they are not used to train its models.
The AI does not make decisions with legal or similarly significant effects about anyone, and a business can switch it off at any time and have its staff reply in person.
Who we share it with
We never sell or rent personal data. We share it only with the service providers we need to run our business and our products, under contracts that limit what they may do with it:
- Hostinger — hosting for this website;
- our email provider — for the messages you send to info@metaseti.com;
- Meta Platforms — the WhatsApp Business Platform, for products that send and receive WhatsApp messages;
- Google — the Gemini API, for AI replies in Meta-Koda;
- DigitalOcean (Singapore) and Vercel — hosting for Meta-Koda's application, database and dashboard;
- Resend (Japan) — Meta-Koda's account emails, such as password resets and staff invitations.
Transfers outside Indonesia
Some of these providers store or process data outside Indonesia — in Singapore, in Japan, or on global infrastructure. Where that happens, we transfer only what the service needs, and only to providers bound by contract to protect it.
Requests from authorities
Every request for personal data from a public authority — the police, prosecutors, a ministry, or a foreign authority — goes to our Director. No one else at Metaseti answers it.
Before we respond, we check that the request is valid and binding under Indonesian law: in writing, from an authority with jurisdiction, citing its legal basis and specific about the data it wants. Informal or verbal requests are refused. We push back on requests that are unlawful or broader than they need to be, and where disclosure is legally required we disclose only the minimum the demand requires — never a whole database, and never data about people or businesses it does not name.
Where the law allows, we tell the affected client before or promptly after disclosing, and for data we hold on a client's behalf we involve the client in the response. Every request is recorded, with what was disclosed and who approved it, and those records are kept for at least five years.
How long we keep it
Enquiries are kept for twenty-four months after your last contact with us, then deleted. Records we must keep for tax or accounting purposes are kept for the period the law sets.
Data in a system we run for a client is kept for as long as the client's agreement says. When a business leaves Meta-Koda, its data — including its customers' data — is deleted or irreversibly anonymised within 90 days, unless the law requires us to keep something longer, such as invoices; backup copies expire within 30 days after that.
How we protect it
Data travels over encrypted connections (HTTPS). In Meta-Koda, each business's data is kept separate from every other business's at the database level, access is role-based and administrative actions are logged, passwords are stored only as one-way hashes, WhatsApp access credentials are stored encrypted, and databases are backed up automatically.
Your rights
Under the Personal Data Protection Law you may ask to see and receive a copy of the personal data we hold about you, to correct it, to delete it, to limit or pause how it is used, and to withdraw consent you gave earlier. You may also object to decisions made about you solely by automated processing.
Write to info@metaseti.com. We will confirm who you are before acting, and respond within the time the law allows.
How to delete your data
To ask us to delete your personal data:
- Email info@metaseti.com with the subject “Data deletion request”.
- Tell us how we know you. If you are a customer of a business that uses Meta-Koda, include the WhatsApp number you used and the name of the business; if you work at one of our clients, write from your registered email address.
- We will verify the request, delete your personal data within 30 days unless the law requires us to keep it, and confirm by reply.
Children
Our website and products are made for businesses and are not aimed at children. We do not knowingly collect children's personal data; if you believe a child's data has reached us, write to us and we will delete it.
Cookies
This website sets no cookies. What it and our product apps store in your browser is described in our Cookie Policy.
Changes
When this policy changes, we update the date at the top of this page. If a change matters to our clients, we tell them directly.
Questions about this document — info@metaseti.com
