Privacy Policy - EKN
Last updated: April 23, 2026
The EKN application is an internal application
owned by Firdaus Adinegoro used by employees to submit and validate reimbursement claims.
This Privacy Policy explains how We collect, use, store, and protect
your personal data when you use the App.
By using the App, you agree to the practices described in this Privacy
Policy.
1. Data We Collect
1.1 Account Data
-
Username and password - passwords are stored as
bcrypt hashes on Our servers and are never stored in plain text.
-
Full name, email, phone number, employee code, and
role within the system.
-
2FA credentials (TOTP secret) - only if you enable
two-factor authentication.
1.2 Reimbursement Data
-
Reimbursement category (Fuel, Hotel, Meals, Out-of-Town Visits, etc.)
- Transaction details, amount, receipt date, and notes
-
Receipt photos you upload from your device's camera
or gallery
- Approval or rejection notes from validators
1.3 Technical Data
-
Session token (JWT) - stored encrypted on your device
(Android Keystore / iOS Keychain)
-
Basic device information necessary for the App to function (OS
version, device model)
The App does NOT collect: GPS location, contact list,
browsing history, third-party data, or data for advertising purposes.
2. How We Use Your Data
The collected data is used solely to:
- Authenticate your access to the App
- Process, validate, and approve reimbursement submissions
- Generate internal reports for company financial purposes
-
Send email notifications related to the status of your reimbursement
(when a claim is rejected)
- Ensure system security and integrity
We do not use your data for advertising, third-party
analytics, or sale to any party.
3. How We Share Your Data
This App is an internal company application. Your data
can only be accessed by:
- Yourself
-
Validators within the company authorized to process your reimbursement
- System administrators for maintenance purposes
We never sell, rent, or share your data with third
parties outside the company, except when required by law or with your
written consent.
4. Data Security
We implement the following security measures:
-
Encrypted communication: all data sent between the
App and the server uses HTTPS/TLS
-
Hashed passwords: passwords are stored as bcrypt
hashes and cannot be reversed to their original text
-
Encrypted tokens: session tokens are stored in
Android Keystore (Android) or Keychain (iOS), backed by
hardware-backed encryption
-
Role-based access control: data is only accessible
based on user roles
-
Optional 2FA: you can enable two-factor
authentication for additional protection
5. Data Retention
Your data is stored on Our company servers for as long as your account
is active. If your account is deactivated, related data may be retained
for audit purposes, tax compliance, and legal requirements in accordance
with applicable Indonesian regulations.
6. Your Rights
You have the right to:
- Access the personal data We hold about you
7. Device Access
The App requests the following permissions on your device:
-
Camera - to take photos of reimbursement receipts
-
Gallery / Storage - to select existing receipt photos
- Internet - to communicate with the server
The App does not request access to location, contacts,
microphone, SMS, or call history.
8. Changes to This Privacy Policy
We may update this Privacy Policy from time to time. Material changes
will be communicated via the App or email. The "Last updated" date at
the top of this page indicates the latest version.
9. Contact Us
If you have questions about this Privacy Policy or wish to exercise your
rights, please contact:
Firdaus Adinegoro
Email:
[email protected]