Home / Privacy Policy
Privacy & Data

Privacy Policy

Information about how SatuInbox collects, uses, stores, shares, and protects data when you use our website, platform, products, and services.

Effective Date: June 24, 2026 Updated: August 19, 2026 SatuInbox
Privacy SummarySatuInbox
Manage

Data You Provide

Account information, business contacts, support requests, and customer communication data managed through SatuInbox.

Protect

Security & Control

We apply administrative, technical, and organizational measures to help protect personal data.

Rights

User Privacy Rights

Users may have rights to access, correct, delete, restrict processing, and withdraw consent in accordance with applicable law.

Your Data Matters

Privacy Policy

Effective Date: June 24, 2026 · Updated: August 19, 2026

This Privacy Policy explains how SatuInbox (“SatuInbox,” “we,” “us,” or “our”) collects, uses, stores, shares, and protects personal data when you access or use the SatuInbox website, platform, products, and related services.

By using SatuInbox, you acknowledge that you have read and understood this Privacy Policy. If you do not agree with this Privacy Policy, please do not use SatuInbox services.

SatuInbox is committed to managing personal data transparently, responsibly, securely, and in accordance with applicable laws and regulations, including personal data protection principles in Indonesia.

1. Information We Collect

We may collect the following categories of personal information:

1.1 Information You Provide Directly

  • Name, email address, phone number, company name, and job title.
  • Account registration information, login credentials, and user profile information.
  • Billing, subscription, invoice, and payment information.
  • Messages, questions, support requests, and other communications you send to us.
  • Business data or customer communication data that you upload, connect, or manage through SatuInbox.

1.2 Information Collected Automatically

  • IP address, browser type, device information, operating system, and language settings.
  • Usage data, including pages visited, features used, clicks, session duration, and interaction logs.
  • Cookies, pixels, tags, and similar tracking technologies.
  • Approximate location derived from an IP address or device settings.

1.3 Information From Third Parties

  • Information from integrated platforms, communication channels, CRM systems, or business applications that you connect to SatuInbox.
  • Information from payment providers, analytics providers, advertising platforms, or service partners.
  • Publicly available business information, to the extent permitted by applicable law.

2. How We Use Information

We use personal data for the following purposes:

  • To provide, operate, maintain, and improve SatuInbox services.
  • To create, manage, and secure user accounts.
  • To process subscriptions, payments, invoices, and billing records.
  • To provide customer support and respond to questions.
  • To improve user experience and platform performance.
  • To monitor, analyze, and measure usage, performance, and service quality.
  • To send service updates, administrative messages, and important notices.
  • To send marketing communications where permitted by law or based on your consent.
  • To prevent fraud, abuse, unauthorized access, security incidents, and illegal activity.
  • To comply with legal obligations, regulatory requirements, audit processes, or lawful requests from authorities.

Where applicable, we process personal data based on one or more of the following legal bases:

  • Consent: when you provide consent to the processing of personal data for a specific purpose.
  • Performance of a contract: when processing is necessary to provide SatuInbox services to you or your organization.
  • Legal obligation: when we are required to comply with laws and regulations, authority requests, or lawful legal processes.
  • Legitimate interests: when processing is necessary for business operations, security, service improvement, abuse prevention, or protection of our rights, provided that such interests do not override your rights and interests as a personal data subject.

4. Cookies and Tracking Technologies

We may use cookies, pixels, tags, and similar technologies to operate the website, remember user preferences, analyze traffic, improve services, and support marketing activities.

You can manage or disable cookies through your browser settings. However, disabling certain cookies may affect the features or functionality of the SatuInbox website and services.

5. How We Share Information

We may share personal data with the following parties:

  • Service providers: including hosting, cloud infrastructure, analytics, payment, email, security, and customer support providers.
  • Integration partners: when you choose to connect SatuInbox with third-party platforms or services.
  • Professional advisers: including legal, accounting, audit, insurance, or compliance advisers.
  • Authorities or regulators: when required by law, legal process, or a lawful government request.
  • Business transactions: in connection with a merger, acquisition, financing, reorganization, asset transfer, or other corporate transaction.

We do not sell your personal data in the ordinary sense. If this practice changes, we will update this Privacy Policy and provide any applicable notices and rights as required by law.

6. Customer Data Processed Through SatuInbox

If you use SatuInbox to manage messages, contacts, customer conversations, agent activity, follow-ups, or business communications, you are responsible for ensuring that you have the necessary rights, permissions, and legal basis to collect and process that data.

In many circumstances, SatuInbox acts as a personal data processor or service provider that processes data on the instructions of business customers. Business customers remain responsible for the personal data they collect, upload, connect, or manage through the SatuInbox platform.

For account data, billing data, website usage data, communications with SatuInbox, and other data that we manage for our own operational purposes, SatuInbox may act as the personal data controller depending on the processing context.

7. Data Transfers

Your personal data may be transferred, stored, or processed in locations outside your place of residence, including by infrastructure providers or service partners that help operate SatuInbox.

If data is transferred outside the jurisdiction of Indonesia or the country where you are located, we will apply reasonable safeguards and lawful transfer mechanisms in accordance with applicable law, including contractual protections, security measures, and consent where required.

8. Data Retention

We retain personal data and customer communication data only for as long as necessary to provide SatuInbox services, operate our business, maintain platform security, resolve disputes, comply with legal obligations, and fulfill the processing purposes described in this Privacy Policy.

Retention periods may vary depending on the type of data, account status, service configuration, operational needs, security requirements, audit obligations, agreements with business customers, and applicable laws and regulations.

8.1 SatuInbox Data Retention Periods

For data processed through SatuInbox, the following retention periods apply unless legal obligations, security requirements, audit needs, dispute resolution processes, or contractual terms require longer retention:

  • Notifications: retained for 90 days from the date the notification is created or received. After that period, notification data may be deleted, destroyed, anonymized, or aggregated.
  • Conversation History: displayed on the platform for 2 months for users’ operational needs. Conversation history data may be retained in SatuInbox systems for up to 12 months for service continuity, limited audits, troubleshooting, security, dispute resolution, and compliance with applicable legal obligations.
  • Agent Activity: displayed and retained for 3 months, including assignment activity, ticket or conversation status changes, response times, resolution times, and other activity records needed to monitor team performance and maintain operational accountability.

8.2 Deletion, Destruction, or Anonymization of Data

After the retention period ends, data may be deleted, destroyed, anonymized, or aggregated so that it can no longer be directly associated with a specific individual or customer account, unless the data must still be retained for legal obligations, security, audit, bookkeeping, fraud prevention, contract enforcement, or dispute resolution.

If a personal data subject requests deletion, withdrawal of consent, restriction of processing, or termination of processing, SatuInbox will respond to the request in accordance with applicable law, agreements with business customers, and reasonable technical limitations.

8.3 Backup Data and Security Logs

Deleting data from active systems may not immediately remove all copies stored in backup systems. Data in backups will remain protected, access-restricted, and deleted or overwritten according to the applicable backup cycle, unless required for system recovery, security, incident investigation, audit, or legal obligations.

Security logs, system logs, and certain metadata may be retained in limited form to maintain service security, prevent abuse, detect unauthorized access, perform troubleshooting, or comply with legal and audit obligations.

In short: data is not retained indefinitely. SatuInbox limits how long data remains visible and stored based on service needs, security, compliance, and reasonable data-retention principles.

9. Data Security

We apply reasonable administrative, technical, and organizational measures to protect personal data against unauthorized access, loss, misuse, disclosure, alteration, destruction, or unlawful processing.

These security measures may include access controls, user-permission restrictions, system safeguards, activity monitoring, credential management, and internal procedures designed to maintain data confidentiality.

However, no method of transmission over the internet or electronic storage is completely risk-free. Therefore, we cannot guarantee absolute security of personal data, but we strive to protect data proportionately based on the nature and risks of the data being processed.

10. Your Privacy Rights

Depending on your location, the type of data, your relationship with SatuInbox, and applicable law, you may have the following rights:

  • The right to obtain information about the processing of personal data.
  • The right to access personal data we hold about you.
  • The right to correct or update inaccurate or incomplete personal data.
  • The right to request deletion of personal data in accordance with applicable law.
  • The right to withdraw consent where processing is based on consent.
  • The right to restrict or object to certain processing in accordance with applicable law.
  • The right to data portability, where applicable.
  • The right to stop receiving certain marketing communications.
  • The right to lodge a complaint with a competent authority, where applicable.

To exercise your rights, please contact us using the contact details in this Privacy Policy. We may request identity verification before processing your request.

11. Marketing Communications

We may send marketing emails, product updates, event information, or promotional content when you have provided consent or where permitted by applicable law.

You can stop receiving marketing emails at any time by using the unsubscribe link in the email or by contacting us directly. However, we may still send non-marketing messages related to your account, transactions, security, service updates, or administrative notices.

12. Third-Party Links and Services

The SatuInbox website or services may contain links to third-party websites, applications, or services. We are not responsible for the privacy practices, content, or security of those third-party services.

We recommend reviewing the privacy policy of each third-party service you access or connect with SatuInbox.

13. Children’s Privacy

SatuInbox is intended for business use and is not directed to children. We do not knowingly collect children’s personal data without the legal basis or consent required under applicable laws and regulations.

If you believe that a child has provided personal data to us without appropriate authorization, please contact us so we can take the necessary action.

14. Notice for Users in Indonesia

If you are located in Indonesia, we will process personal data in accordance with applicable personal data protection requirements in Indonesia, including principles of limited, specific, lawful, transparent, secure, accurate, and accountable processing, while respecting the rights of personal data subjects.

For data processed on behalf of business customers, the business customer may act as the party determining the purposes and means of processing. In such cases, requests concerning customer data managed through a SatuInbox business account may need to be submitted first to the relevant business customer.

15. Changes to This Privacy Policy

We may update this Privacy Policy from time to time to reflect changes in our services, business operations, security needs, legal obligations, or privacy practices.

If there are material changes, we may provide notice through the website, email, account dashboard, or another appropriate communication channel. The latest version will take effect from the date stated at the top of this page.

16. Contact Us

If you have questions, complaints, or requests regarding this Privacy Policy or how we manage personal data, please contact us at:

SatuInbox
Email: [email protected]
Website: https://satuinbox.com/en/
Address: [Company address to be completed]

Need Help With Personal Data?

Contact us at [email protected] with questions, complaints, or requests related to personal data.