Privacy Policy
1. Who we are
Familya is a family management service operated by PT PENDAR CITA PARAMARTA, an individual company established in Indonesia and based in Kabupaten Bogor, West Java.
In this policy, "we" means PT PENDAR CITA PARAMARTA as the data controller, and "you" means a Familya user.
2. Data we collect
- Account data — your name, email address, and profile photo (optional) used to register and sign in.
- Family data you enter — family name, family vision and mission, member names, dates of birth, phone numbers, invitation emails, home address, postal code, and important numbers.
- Financial data — assets, liabilities, and receivables: amounts, currency, institution name, account reference, related parties, witnesses, and free-text notes.
- Documents — files you upload together with their metadata (filename, type, size).
- Subscription data — active plan, validity period, and payment history. We do not store your card number; payments are processed by our payment provider.
- Technical data — IP address and device information at the time a session is created, for account security.
3. How we use it
- To provide the service: storing and displaying your family data to authorized members.
- To enforce role-based access control (family head, mother, children).
- To keep accounts secure and prevent abuse.
- To send the notifications you enable and important account information.
- To handle support requests and meet legal obligations.
We never sell your personal data or family data, and we do not use it for advertising.
4. Legal basis
We process personal data under Law No. 27 of 2022 on Personal Data Protection (Indonesia), on the basis of: performance of our agreement with you, legal obligations, our legitimate interest in keeping the service secure, and your consent where required.
5. Encryption and security
- Field-level encryption — sensitive data is encrypted in the application layer before it is stored, using AES-256-GCM with a fresh IV for every value. This covers money amounts, member names and dates of birth, phone numbers, invitation emails, home address, postal code, important numbers, institution names, account references, related parties, witnesses, all free-text notes, and the family name, vision, and mission.
- Key management — the data encryption key (DEK) is stored wrapped and unwrapped only when the service starts, through a KMS. Keys are never stored in the database or in our source code.
- Data in transit — all communication between your device and our service uses HTTPS/TLS.
- Documents — files are kept in object storage and can only be accessed through time-limited signed links.
- Operations — production access is restricted, the database is not exposed to the internet, and backups are taken regularly.
We are straightforward about the limits: account email addresses, some dates and statuses, and internal IDs are stored without field-level encryption so that authentication and service operations keep working. Document contents are not field-encrypted; they are protected by storage access controls. The encryption keys are held by our servers, so this is not end-to-end encryption — we describe it as it is.
6. Storage and retention
We keep your family data for as long as your account is active. If you delete your account or request deletion, we delete or anonymize that data, except where we must retain it to meet legal obligations such as tax and accounting requirements. Data remaining in backups is removed as our backup rotation cycle completes.
7. Third parties
We use trusted service providers that process data on our behalf and only on our instructions. Categories of recipients:
- Cloud infrastructure provider — runs the service and stores data.
- File storage provider — stores the document files you upload.
- Key management provider — manages the encryption keys (KMS) that protect sensitive data.
- Payment provider — processes subscription payments.
- Email delivery provider — sends notification and transactional email.
We may disclose data where required by applicable law, and will inform you to the extent we are legally permitted to.
8. Your rights
Under Indonesia's Personal Data Protection Law you have the right to access and obtain a copy of your data, correct inaccurate data, request deletion, withdraw consent, restrict or object to certain processing, receive your data in a machine-readable format, and lodge a complaint.
Many of these you can exercise directly in account settings. For anything else, email tanya@familya.id. We respond to every request within 14 calendar days at the latest.
9. Cookies
We use essential cookies to keep you signed in. This site does not use advertising cookies or third-party tracking.
10. Children and family members
Familya is intended for use by adults. Data about family members who are minors may only be added by a parent or guardian, who by doing so confirms they are authorized to consent on their behalf.
11. Changes to this policy
If we change this policy materially, we will tell you by email or in the app before the change takes effect. The date at the top of this page shows the latest version.
12. Contact us
Questions about your data or this policy: tanya@familya.id. Physical mail can be sent to PT PENDAR CITA PARAMARTA, Kabupaten Bogor, West Java, Indonesia.