DPRD Legal Chat

AI Legal Intelligence

Privacy Policy

Last Updated: November 10, 2025

1. Introduction

This Privacy Policy describes how DPRD Legal Chat (the "Service") collects, uses, and protects your personal information. This Service is operated within the Republic of Indonesia and complies with Indonesian data protection laws, including UU No. 27 Tahun 2022 tentang Pelindungan Data Pribadi (Personal Data Protection Law). By using the Service, you consent to the collection and use of information in accordance with this policy. This Service is intended exclusively for users within Indonesia.

2. Information We Collect

We collect the following types of information: Personal Information: • Username and display name • Email address • Organization affiliation • User role and permissions • Account credentials (passwords are encrypted) Meeting Data: • Meeting transcripts and recordings • Meeting metadata (title, date, duration, participants) • AI-generated content (summaries, recommendations, regulation extractions) • Chat conversations with the AI assistant Technical Information: • IP addresses • Browser type and version • Device information • Access logs and timestamps • System usage patterns

3. How We Use Your Information

We use the collected information for the following purposes: Service Provision: • Authenticate and authorize users • Provide meeting transcription and analysis • Generate AI-powered summaries and recommendations • Enable chat functionality with AI assistant • Extract and identify relevant regulations Security and Compliance: • Monitor system access and usage • Detect and prevent unauthorized access • Maintain audit logs as required by law • Ensure compliance with organizational policies Service Improvement: • Analyze usage patterns to improve functionality • Troubleshoot technical issues • Enhance AI model accuracy

4. Data Storage and Security

We implement appropriate technical and organizational measures to protect your personal data: • All data is stored within Indonesia • Passwords are encrypted using industry-standard algorithms • Access to personal data is restricted to authorized personnel only • All system access is logged for audit purposes • Regular security assessments and updates are performed • Data transmission is encrypted using secure protocols Meeting data is treated as confidential and is protected according to your organization's security requirements.

5. Data Sharing and Disclosure

We do NOT share your personal data with third parties except in the following circumstances: • With your organization's administrators as necessary for service management • When required by Indonesian law or legal proceedings • To protect the rights, property, or safety of the Service, its users, or the public • With service providers who assist in operating the Service, under strict confidentiality agreements We do NOT: • Sell your personal data to third parties • Share your data with international entities outside Indonesia • Use your data for marketing purposes without consent

6. Data Retention

We retain your personal data for as long as necessary to provide the Service and comply with legal obligations: • Account information: Retained while your account is active • Meeting data: Retained according to your organization's policies • Access logs: Retained for security and audit purposes (typically 1-2 years) • AI-generated content: Retained as long as the associated meeting data When data is no longer needed, it is securely deleted or anonymized.

7. Your Rights

Under Indonesian data protection law (UU No. 27 Tahun 2022), you have the following rights: • Right to access your personal data • Right to correct inaccurate or incomplete data • Right to request deletion of your data (subject to legal obligations) • Right to withdraw consent for data processing • Right to data portability • Right to object to certain data processing • Right to file complaints with supervisory authorities To exercise these rights, please contact your organization's administrator or designated data protection officer.

8. AI and Automated Processing

The Service uses artificial intelligence for: • Transcribing meetings • Generating summaries and recommendations • Extracting regulatory references • Providing chat responses While we strive for accuracy, AI-generated content may contain errors. You are responsible for verifying important information. AI processing is performed to assist your work, not to make automated decisions with legal or similar significant effects.

9. Children's Privacy

The Service is not intended for individuals under 18 years of age. We do not knowingly collect personal information from children. If we become aware that we have collected personal data from a child without proper authorization, we will take steps to delete such information.

10. Cookies and Tracking

We use cookies and similar technologies to: • Maintain user sessions • Remember language preferences • Analyze system usage • Enhance user experience You can control cookie settings through your browser, but disabling cookies may limit some functionality of the Service.

11. Data Breach Notification

In the event of a data breach that may affect your personal data, we will: • Notify your organization's administrators promptly • Report to relevant Indonesian authorities as required by law • Take immediate steps to secure the system and prevent further unauthorized access • Provide information about the breach and mitigation steps

12. International Data Transfer

This Service operates exclusively within Indonesia. Personal data is stored and processed within Indonesian territory. We do not transfer personal data outside Indonesia except where: • Explicitly required by law • Authorized by your organization • Necessary for technical maintenance with adequate safeguards Any international transfers comply with Indonesian data protection requirements.

13. Changes to This Policy

We may update this Privacy Policy from time to time to reflect changes in our practices or legal requirements. We will notify you of significant changes through: • In-app notifications • Email to your registered address • Notice on the login page Continued use of the Service after changes constitutes acceptance of the updated policy.

14. Contact Information

For questions or concerns about this Privacy Policy or your personal data, please contact: • Your organization's system administrator • Your organization's designated data protection officer • The Service provider through official channels For formal complaints about data protection, you may contact the Indonesian data protection authority as established under UU No. 27 Tahun 2022.

DPRD Legal Chat