1. Introduction
PT. Cerebrum Edukanesia Nusantara (“Company”, “we”, “us”, or “our”) is committed to protecting your personal data. This Privacy Policy explains how we collect, use, store, protect, and share your personal information when you access and use JadiSekdin (“Platform”), accessible at https://jadisekdin.id, the platform for official academy entrance preparation.
This Privacy Policy should be read together with our Terms and Conditions. By registering for an account, accessing, or using the Platform, you acknowledge that you have read and understood this Privacy Policy and consent to the collection and processing of your personal data as described herein.
This Privacy Policy is drafted in compliance with Indonesian Law No. 27 of 2022 on Personal Data Protection (Undang-Undang Perlindungan Data Pribadi, “UU PDP”) and other applicable regulations.
2. Data Controller
The data controller responsible for your personal data processed through JadiSekdin is:
As the data controller, we determine the purposes and means of processing your personal data and are responsible for ensuring that such processing complies with applicable data protection laws.
3. Personal Data We Collect
We collect and process the following categories of personal data:
3.1 Identity Data
- Full name — obtained automatically from your Google account during registration via Google OAuth;
- Email address — obtained automatically from your Google account during registration; this field is read-only and cannot be modified after account creation;
- Google profile photo — obtained from your Google account if publicly available.
3.2 Contact Data
- Phone number — collected during the checkout/package purchase process; not required at registration;
- WhatsApp number — collected when you interact with our customer support or join community groups.
3.3 Location Data
- Province and city of residence — collected when you access the Tryout result analysis feature; this data is used for regional performance benchmarking and is not collected at registration.
3.4 Learning Activity Data
- Tryout attempt history, scores, and answer records;
- Course progress and completion status;
- Liveclass attendance and replay viewing history;
- Journey/Guided Learning progress through learning nodes;
- Practice Question (Latsol) activity and results;
- Bookmarks and saved content.
3.5 Transaction Data
- Membership package purchase history;
- Payment method selected (via third-party Payment Gateways);
- Transaction status (Success, Pending, Expired, Cancelled);
- Voucher codes applied and affiliate referral codes used;
- Invoice records and payment confirmation timestamps.
3.6 Technical and Device Data
- Browser type and version;
- Operating system and device type (web, Android, iOS);
- IP address;
- Device identifiers and push notification tokens (Firebase Cloud Messaging / FCM);
- Session data and access timestamps;
- App version (mobile application).
3.7 Helpdesk and Support Data
- Issue reports and inquiry messages submitted through the Helpdesk;
- Screenshots or attachments uploaded in support tickets;
- Communication history with our VOC (Voice of Customer) team.
4. How We Collect Your Data
We collect your personal data through the following methods:
| Method | Description | Data Collected |
|---|---|---|
| Google OAuth SSO | Single Sign-On authentication at registration. No additional registration form is required (lazy collection principle). | Full name, email address, profile photo |
| In-context collection | Data collected only when a specific feature requires it, at the point of use — not upfront. | Phone number (checkout), province/city (Tryout analysis) |
| Automatic collection | Data generated through your interaction with the Platform, collected by our systems automatically. | Learning activity, technical/device data, session data |
| Payment Gateway callbacks | Transaction confirmation data received from third-party payment providers after payment processing. | Transaction status, payment confirmation |
| User-submitted data | Information you voluntarily provide through Helpdesk reports, support tickets, or profile updates. | Support messages, attachments, profile updates |
5. Purpose of Data Processing
We process your personal data for the following purposes:
- Account creation and authentication — to create and manage your Account on the Platform using Google OAuth SSO, and to authenticate your identity each time you access the Platform;
- Service delivery — to provide, operate, and maintain the Services, including Tryout, Latsol, Course, Liveclass, and Journey features tailored to Sekolah Kedinasan (Official Academies) entrance examinations;
- Personalization — to display personalized analysis results, learning recommendations, performance benchmarks, and progress reports based on your learning activity data;
- Transaction processing — to process Membership purchases, verify payments through Payment Gateways, activate packages, apply vouchers, and manage billing;
- Customer support — to handle your complaints, inquiries, and issue reports submitted through the Helpdesk, and to communicate resolutions through our VOC team;
- Notifications — to send you push notifications (via Firebase Cloud Messaging), announcements, Liveclass reminders, and other Service-related communications;
- Analytics and improvement — to conduct internal analytics for understanding usage patterns, improving Service quality, and optimizing Platform performance;
- Security and fraud prevention — to detect, prevent, and investigate unauthorized access, cheating, or other prohibited activities on the Platform;
- Legal compliance — to fulfill our obligations under applicable laws and regulations, including UU PDP and related regulations.
6. Legal Basis for Processing
In accordance with UU PDP, we process your personal data based on the following legal grounds:
- Consent — by registering and using the Platform, you provide explicit consent for the processing of your personal data as described in this Privacy Policy;
- Contractual necessity — processing necessary for the performance of the contract between you and the Company (i.e., providing the Services you have subscribed to);
- Legitimate interest — processing necessary for our legitimate interests, such as improving our Services, ensuring Platform security, and preventing fraud, provided these interests do not override your fundamental rights;
- Legal obligation — processing necessary to comply with our legal obligations under Indonesian law.
7. Data Storage and Security
7.1 Infrastructure
- Your personal data is stored on servers managed by the Company using Google Cloud Platform (GCP) infrastructure located in secure data center facilities.
- OAuth tokens are stored with per-user device tracking and support force-revocation capabilities for security purposes.
7.2 Security Measures
We implement reasonable technical and organizational measures to protect your personal data, including but not limited to:
- Encrypted data transmission using HTTPS/TLS protocols;
- Google Cloud Secret Manager for sensitive credential storage;
- Role-based access controls limiting internal access to personal data;
- Regular security assessments and vulnerability monitoring;
- Per-user OAuth token management with device-level tracking and force-revocation;
- Separate database credentials and configurations for data isolation.
While we take commercially reasonable measures to secure your data, no method of transmission over the internet or method of electronic storage is 100% secure. We cannot guarantee absolute security of your personal data.
8. Cookies and Tracking Technologies
The Platform uses cookies and similar technologies for the following purposes:
| Cookie / Technology | Purpose | Type |
|---|---|---|
| Authentication cookies | To maintain your login session and authenticate your identity across page loads | Essential / Functional |
| Google Analytics cookies | To collect anonymized usage statistics for internal analytics and Platform improvement | Analytics |
| Firebase Cloud Messaging (FCM) | To deliver push notifications for announcements, Liveclass reminders, and Service updates | Functional |
| Session and preference cookies | To remember your preferences, app version, and session state | Functional |
You may manage cookie preferences through your browser settings. Please note that disabling essential cookies may affect the functionality of the Platform.
9. Third-Party Service Providers
We engage the following categories of third-party service providers to operate the Platform. These providers may process your personal data on our behalf and under our instructions:
9.1 Payment Gateway Providers
| Provider | Purpose | Data Shared |
|---|---|---|
| Midtrans (by GoTo Financial) | Primary payment processing (Snap & Core API) | Transaction amount, payment method, order ID, email |
| iPaymu | Alternative payment processing (HMAC-SHA256 authenticated) | Transaction amount, payment method, order ID |
| DANA | E-wallet payment option (RSA-SHA256 authenticated) | Transaction amount, DANA account reference |
We do not store your full payment card details, bank account numbers, or e-wallet credentials on our servers. Payment processing is handled entirely by the respective Payment Gateway providers under their own privacy policies and security standards.
9.2 Cloud and Infrastructure Providers
| Provider | Purpose |
|---|---|
| Google Cloud Platform (GCP) | Server infrastructure, database hosting, cloud storage (GCS), Secret Manager |
| Firebase (Google) | Push notifications (FCM), authentication support, analytics |
9.3 Communication Providers
| Provider | Purpose |
|---|---|
| WooWa / WhatsApp Business API | Customer support communications, broadcast notifications, and community group management |
Each third-party provider operates under its own privacy policy and data protection standards. We require our providers to implement adequate safeguards for personal data and to process data only as instructed by us and for the purposes specified.
10. Data Sharing and Disclosure
We do not sell, rent, or trade your personal data to third parties for their marketing purposes. We may share your personal data only in the following circumstances:
- Service providers — with third-party service providers described in Section 9, strictly for the purpose of providing and operating the Services;
- Legal requirements — when required to comply with applicable laws, regulations, legal processes, or enforceable governmental requests;
- Protection of rights — when necessary to protect the rights, property, or safety of the Company, our users, or the public;
- Business transfers — in connection with a merger, acquisition, or sale of assets, your personal data may be transferred as part of the transaction, subject to the same level of protection described in this Privacy Policy;
- With your consent — in any other circumstances where we have obtained your explicit prior consent.
11. Data Retention
- We retain your personal data for as long as your Account is active or as needed to provide you with the Services.
- Our systems operate on a soft-delete architecture, meaning that when data is deleted through user-facing features, it is marked as inactive rather than permanently erased from our databases. This approach ensures data integrity for audit trails and regulatory compliance.
- After account closure or deletion request, we may retain certain data for a reasonable period as required by applicable laws and regulations, including but not limited to tax, accounting, and legal compliance obligations.
- Learning activity data (Tryout scores, Course progress) may be retained in anonymized or aggregated form for analytical purposes even after account deletion.
- Transaction records are retained in accordance with Indonesian tax and commercial record-keeping requirements.
12. Your Rights as a Data Subject
In accordance with UU PDP (Law No. 27 of 2022), you have the following rights regarding your personal data:
- Right to access — you have the right to request access to the personal data we hold about you and to obtain a copy of such data;
- Right to rectification — you have the right to request the correction or update of inaccurate or incomplete personal data;
- Right to erasure — you have the right to request the deletion of your personal data, subject to applicable legal retention requirements;
- Right to restrict processing — you have the right to request the restriction of processing of your personal data under certain circumstances;
- Right to data portability — you have the right to request the transfer of your personal data in a structured, commonly used, and machine-readable format;
- Right to withdraw consent — you have the right to withdraw your consent for processing at any time, without affecting the lawfulness of processing based on consent before its withdrawal;
- Right to object — you have the right to object to the processing of your personal data based on legitimate interests.
To exercise any of these rights, please contact us using the information provided in Section 16 (Contact Us). We will respond to your request within 3 × 24 (three times twenty-four) hours as required by UU PDP.
13. Account Deletion
- You may request the deletion of your Account through the “Delete Account” feature available in the Account & Profile menu on the Platform.
- Upon submission of a deletion request, your Account will be marked for deletion and access to the Platform will be restricted.
- The deletion process will be carried out in accordance with our internal procedures and applicable regulations, including any mandatory data retention periods.
- Certain data may be retained after account deletion to comply with legal obligations, resolve disputes, or enforce our Terms and Conditions. Such retained data will be stored securely and processed only for the specific retention purpose.
- Account deletion is irreversible. All Membership packages, learning progress, Tryout history, and other associated data will become permanently inaccessible.
14. Children’s Privacy
- JadiSekdin is designed for high school students preparing for entrance to official academies such as STIN, STIS, IPDN, PKN STAN, and others. The Platform is not directed at children under the age of 13.
- We do not knowingly collect personal data from children under 13 years of age. If we become aware that we have inadvertently collected personal data from a child under 13, we will take steps to delete such data as promptly as possible.
- For users between the ages of 13 and 18, we recommend that registration and use of the Platform be conducted with the knowledge and consent of a parent or legal guardian.
15. Changes to This Privacy Policy
- We may update this Privacy Policy from time to time to reflect changes in our data practices, legal requirements, or operational needs.
- Any material changes to this Privacy Policy will be communicated to you through notifications on the Platform, email, or other official communication channels prior to the changes taking effect.
- Your continued use of the Platform after any modification constitutes your acceptance of the revised Privacy Policy.
- The latest version of this Privacy Policy will always be available on the designated page of the Platform, with the effective date clearly indicated at the top.
- We encourage you to review this Privacy Policy periodically to stay informed about how we protect your personal data.
16. Contact Us
If you have any questions, concerns, or requests regarding this Privacy Policy or our data practices, you may contact us through the following channels:
Email: office@cerebrum.id
Helpdesk: Available within the JadiSekdin Platform (Account → Helpdesk)
Website: https://jadisekdin.id
We will acknowledge receipt of your inquiry and respond within 3 × 24 hours in accordance with UU PDP requirements.