Legal · Privacy Policy

Privacy Policy

How Hodiva Technology and its products collect, use, share, and protect your personal data — including data received through Meta Platforms integrations.

Last updated: 9 August 2026

Who we are and what this covers

Hodiva Technology ("Hodiva", "we", "us") is a technology company headquartered in Jakarta, Indonesia. We build and operate a portfolio of software products and services (each a "Hodiva Product", together the "Hodiva Products").

This Privacy Policy applies to all Hodiva Products, websites, mobile applications, and integrations operated by Hodiva, regardless of the product name under which they are offered. When a Hodiva Product provides its own product-specific privacy notice, that notice supplements this policy with product-specific details; in the event of a conflict, the product-specific notice governs for that product only.

By using any Hodiva Product, you agree to the collection, use, and sharing of your information as described here. If you do not agree, you should not use the Hodiva Products.

Legal entity: PT Hodiva Teknologi · Jakarta, Indonesia · privacy@hodiva.tech

Information we collect

We collect information in the following categories:

Information you provide directly

  • Account & profile data — name, email address, phone number, and credentials you supply when you register for a Hodiva Product.
  • Business information — company name, role, and project details you share when you engage us for consulting or request a quote.
  • Communications — the content of messages you send to us via email, contact forms, or support channels, so we can respond and keep a record of the conversation.
  • Content you create — files, documents, and other materials you upload or generate while using a Hodiva Product.

Information collected automatically

  • Device & usage data — IP address, browser type and version, time zone, operating system, and information about how you interact with a Hodiva Product (pages viewed, features used, timestamps).
  • Cookies & similar technologies — used for authentication, remembering preferences, measuring traffic, and security. See Section 9.

Information from third-party integrations

  • When you connect a Hodiva Product to a third-party service (for example Meta Platforms, Google, or a payment provider), we receive the data that you authorise that service to share with us. The categories of data depend on the permissions you grant. See Section 5 for details specific to Meta Platforms.

How we use information

We use the information we collect to:

  • provide, operate, maintain, and improve the Hodiva Products;
  • create and manage your account and authenticate your identity;
  • process transactions and send related confirmations, receipts, and service notices;
  • respond to your requests, comments, and support inquiries, and provide consulting services you have engaged us for;
  • communicate with you about product updates, security alerts, and administrative messages, and, where you have opted in, marketing communications you may unsubscribe from at any time;
  • monitor and analyse usage to detect, prevent, and address technical issues, fraud, abuse, and security threats;
  • comply with our legal, regulatory, and contractual obligations; and
  • carry out any other purpose disclosed to you at the point of collection or that you otherwise consent to.

Where we rely on consent as the legal basis for processing, you may withdraw it at any time without affecting the lawfulness of processing carried out before withdrawal.

How we share information

We do not sell your personal data. We share information only as described in this policy:

  • Within Hodiva Products — between Hodiva Products and the Hodiva group entities that need the information to operate the relevant product, subject to this policy.
  • Service providers — with vendors and processors that perform services on our behalf (hosting, analytics, email delivery, payment processing, customer support). They are contractually bound to use the data only to provide those services and to protect it consistent with this policy.
  • Third-party integrations — when you connect a third-party service, we may share information necessary to operate the integration, as permitted by you and that service.
  • Legal & safety — where we believe disclosure is necessary to comply with applicable law, regulation, legal process, or government request; to protect the rights, property, or safety of Hodiva, our users, or others; or to investigate and respond to suspected fraud or security incidents.
  • Business transfers — in connection with a merger, acquisition, reorganisation, or sale of all or part of our business, subject to the protections of this policy.

Meta Platforms integrations

Certain Hodiva Products integrate with Meta Platforms, Inc. ("Meta") services, including the Meta Graph API, Messenger, Instagram, WhatsApp Business, and Meta Business Tools. This section explains how we handle data received from Meta.

Data received from Meta

  • Account & profile data — your Meta User ID, name, profile picture URL, and email address (where available and permitted).
  • Page & business data — for Meta Business integrations, Page information, business account details, and insights metrics you authorise.
  • Messaging data — for Messenger, Instagram, and WhatsApp integrations, message content and metadata as permitted by the applicable Meta API and your configuration.

How we use Meta data

We use data received from Meta solely to operate the feature you connected — for example to display your Meta content within a Hodiva Product, send messages on your behalf, or surface analytics. We do not use data received from Meta for advertising, and we do not share it with third parties for advertising purposes.

Your controls

  • You can review and remove a Hodiva Product's access to your Meta data at any time in your Meta App Settings (Facebook → Settings & Privacy → Settings → Apps and Websites, or the equivalent for Instagram / WhatsApp Business).
  • When you disconnect, we will delete the Meta data we have stored on your behalf within 30 days, except where retention is required by law. See Section 6.

This policy, and our use of data received from Meta, comply with the Meta Platform Terms and the applicable Meta Developer Policies. Hodiva is responsible for the data we receive from Meta under this integration.

Data retention and deletion

We retain personal data only as long as necessary to fulfil the purposes described in this policy, comply with legal obligations, resolve disputes, and enforce our agreements.

  • Account data is retained while your account is active and for a limited period after deletion to allow recovery and meet legal requirements.
  • Project & consulting records are retained for the duration of the engagement and the contractual record-keeping period that follows.
  • Data from third-party integrations (including Meta) is deleted within 30 days of you disconnecting the integration or requesting deletion, unless a longer retention is required by law. You can submit a deletion request at any time via our Data Deletion Request page.
  • Server logs and security data are retained on a rolling basis up to 12 months for security and abuse investigation.

When retention is no longer required, we delete the data or render it irreversibly anonymised so it can no longer identify you.

Your rights and choices

Depending on where you live, you may have the following rights regarding your personal data. To exercise any of these rights, contact us at privacy@hodiva.tech.

  • Access — request a copy of the personal data we hold about you.
  • Rectification — ask us to correct inaccurate or incomplete data.
  • Erasure — request deletion of your personal data, subject to legal retention obligations. Submit via our Data Deletion Request page.
  • Restriction & objection — ask us to limit or stop certain processing of your data.
  • Portability — receive your data in a structured, machine-readable format, where applicable.
  • Withdraw consent — withdraw consent to processing that relies on it at any time.
  • Opt out of marketing — unsubscribe using the link in any marketing email or by contacting us.

We respond to verified requests within the timeframe required by applicable law (generally 30 days). You also have the right to lodge a complaint with your local data protection authority — in Indonesia, the relevant authority under Law No. 27 of 2022 on Personal Data Protection ("UU PDP").

Data security

We use administrative, technical, and physical safeguards designed to protect personal data against unauthorised access, alteration, disclosure, or destruction. These include encryption in transit (TLS) and at rest, access controls limited to personnel who need the data to do their job, regular security reviews, and monitoring for suspicious activity.

No method of transmission or storage is fully secure. In the event of a data breach affecting your personal data, we will notify you and the relevant authorities as required by applicable law.

Cookies and similar technologies

We use cookies and similar technologies to keep you signed in, remember your preferences, measure traffic, and protect against abuse. You can control cookies through your browser settings; disabling them may affect some features of the Hodiva Products.

  • Essential — required for core functionality and security. Cannot be disabled.
  • Functional — remember preferences such as language and theme.
  • Analytics — help us understand how the Hodiva Products are used so we can improve them.

Children's privacy

The Hodiva Products are not directed at individuals under the age of 18, and we do not knowingly collect personal data from children. If you believe we have collected data from a child, please contact us at privacy@hodiva.tech and we will take steps to delete it.

International data transfers

Hodiva is based in Indonesia, and we may process and store your personal data in countries other than your own, including through our service providers. Where we transfer personal data across borders, we do so in accordance with applicable data transfer laws and put appropriate safeguards in place, such as standard contractual clauses or other lawful transfer mechanisms.

Changes to this policy

We may update this Privacy Policy from time to time. When we do, we will revise the "last updated" date at the top of this page. For material changes, we will provide a more prominent notice — such as an in-product notification or email — before the change takes effect. We encourage you to review this page periodically.

Contact us

If you have questions about this Privacy Policy or how we handle your personal data, contact our privacy team:

For data protection requests, please include enough information for us to verify your identity and locate your data.