Privacy Policy
Datella ("Datella", "we", "us", or "our") operates the Datella platform at datella.app and its associated subdomains (e.g. couplename.datella.app), progressive web app, and related services (collectively, the "Service").
This Privacy Policy explains what personal data we collect, why we collect it, how we use and share it, and the rights you have over it. It is written to comply with the Indonesian Personal Data Protection Law (UU No. 27 of 2022, "UU PDP").
- Last updated: 2026-05-21
- Effective date: 2026-05-21
- Operator: PT Logika Startup Sempurna
- Data Controller: PT Logika Startup Sempurna, Perum Legok Permai Blok D.1 no B4, Desa/Kelurahan Legok, Kec. Legok, Kab. Tangerang, Provinsi Banten
- Privacy contact / DPO: support@datella.app
- Data Protection Officer (UU PDP Art. 53): Wibowo, privacy@datella.app
Plain-language summary. Datella is an all-in-one event-planning platform with an AI assistant ("Aira"). We collect the information you give us to plan your event (checklists, budgets, guest lists, moodboards, vendor notes), basic account and device data so the app works offline and can send reminders, and payment confirmations for one-time purchases. We use trusted processors (AI, storage, payments, push delivery) to run the Service. We do not sell your personal data. You can export or delete your data at any time.
1. Who this policy covers
This policy applies to:
- Planners / hosts ("Users") — individuals who create and manage events (e.g. couples planning a wedding) and their invited collaborators.
- Guests — people invited to an event who interact with an Open Invitation page, RSVP form, or a published event subdomain.
- Vendors — businesses listed in or claiming a listing in the Datella vendor directory.
- Visitors — anyone browsing public pages, listed events, or vendor profiles.
If you are under the age of majority in your jurisdiction (18 in Indonesia), you may use the Service only with the involvement of a parent or guardian. We do not knowingly create accounts for children under 13. See Section 11.
2. What we collect
2.1 Information you provide
| Category | Examples |
|---|---|
| Account data | Name or display name, email address, password (stored only as a salted hash), authentication / multi-factor (MFA) settings. |
| Event-planning content | Event type and date, checklists and tasks, budget figures and expense items, guest lists and RSVP responses, moodboard images and notes, vendor notes and saved deals. |
| Uploaded media | Images you attach to moodboards, checklist items, tasks, and other features (stored in object storage). |
| AI assistant ("Aira") input | Messages, prompts, and instructions you send to Aira, including any content Aira reads from your event to answer you. |
| Reminders & notifications | Reminder text, schedules, recurrence rules, and notification preferences you configure. |
| Vendor data (vendors only) | Business name, category, city, contact (e.g. WhatsApp number), profile bio, gallery, packages, and verification details. |
| Payment data | Records of one-time purchases (e.g. Lifetime AI Bundle, add-ons, vendor Verified/Pro). Card and bank details are handled by our payment processor — we do not store full card numbers. |
| Support & communications | Messages you send us and our responses. |
2.2 Information collected automatically
| Category | Examples |
|---|---|
| Device & technical data | Browser type, operating system, IP address, language, time zone, and PWA install state. |
| Push subscription data | Web Push endpoint and keys used to deliver notifications and reminders to your device. |
| Usage data | Features used, actions taken, AI points consumed, and error/diagnostic logs. |
| Local / offline data | Datella is offline-first. Some of your event data and pending changes are stored on your device (e.g. IndexedDB) so the app works without a connection. This data syncs to our servers when you reconnect. |
| Cookies & similar | Strictly necessary cookies/local storage for sessions and security; see Section 9. |
2.3 Information from third parties
- Payment processor — confirmation of completed payments and transaction IDs.
- Vendor verification — WhatsApp OTP confirmation when a vendor claims a listing.
- Guests — information guests submit themselves via RSVP / Open Invitation pages.
We do not purchase personal data or build advertising profiles.
3. How we use your data and our legal basis
Under UU PDP we must have a lawful basis for each use:
| Purpose | UU PDP basis |
|---|---|
| Create and operate your account, deliver core planning features | Performance of a contract |
| Run the AI assistant (Aira) on your request | Performance of a contract; consent for optional features |
| Send reminders and push notifications you set up | Performance of a contract; consent for push |
| Process one-time payments and prevent fraud | Performance of a contract; legal obligation |
| Security, abuse prevention, rate-limiting, MFA | Legitimate interest; legal obligation |
| Improve and debug the Service (aggregated/diagnostic) | Legitimate interest |
| Publish content you choose to make public (Listed Event, subdomain, Open Invitation) | Consent / your instruction |
| Vendor directory listing and lead delivery | Performance of a contract (vendors) |
| Legal compliance, responding to lawful requests | Legal obligation |
We rely on consent for non-essential processing (e.g. enabling push notifications, publishing your event publicly). You can withdraw consent at any time without affecting prior lawful processing.
We do not use your event content or Aira conversations to train third-party foundation models. See Section 4.
4. The AI assistant (Aira)
Aira is the AI feature that helps you plan, drafts vendor negotiation messages, and answers questions about your event.
- What Aira reads. To answer you, Aira may read the event data relevant to your request (e.g. your checklist, budget, or event summary). It does this on your instruction.
- AI processor. Your prompts and the necessary context are sent to our AI model provider (a third-party large-language-model API) to generate responses. This provider processes the data on our behalf under a data-processing agreement and does not use it to train its models.
- No training on your data. We do not sell or license your event content or Aira conversations for model training.
- Merit-based recommendations. When Aira recommends a vendor in chat, the recommendation is merit-based and is never a paid placement. Sponsored content, where it appears, is shown only in browse/search and is clearly labeled "Disponsori" (Sponsored).
- Accuracy. AI output can be wrong. Aira's negotiation drafts, suggestions, and reminders are aids, not professional advice — you are responsible for what you send and decide.
5. How we share data
We share personal data only as described here. We do not sell your personal data.
- Service providers (processors) acting on our instructions:
- AI model provider — to generate Aira responses.
- Cloud hosting & object storage — to host the Service and store uploaded media.
- Payment processor — to take one-time payments.
- Push delivery / messaging — to send web-push notifications; WhatsApp for vendor OTP and reminders.
- Error monitoring & analytics — to keep the Service reliable.
- Other Users you collaborate with — collaborators you invite to an event can see that event's content within the scope you grant (per-event or global).
- Guests and the public — content you deliberately publish (Open Invitation, Listed Event in the public directory, or a vanity subdomain) becomes visible to anyone with the link or who browses the directory.
- Vendors — if you contact a vendor through the Service, your inquiry and relevant details are shared with that vendor as a lead.
- Legal & safety — to comply with law, lawful requests, or to protect rights, safety, and the integrity of the Service. This includes mandatory reporting of child sexual abuse material (CSAM) to the relevant authorities (e.g. NCMEC) where required.
- Business transfers — if Datella is involved in a merger, acquisition, or asset sale, data may transfer subject to this policy.
A current list of sub-processors is available on request at support@datella.app.
6. Public content and subdomains
Some features make your content publicly accessible by your choice:
- Open Invitation — a shareable page where guests RSVP themselves.
- Listed Event — a public listing in the Datella event directory.
- Subdomain (e.g.
couplename.datella.app) — a vanity URL for your event.
Important — subdomains are permanent. Once claimed, a subdomain is a permanent, non-editable, non-transferable identifier. This is a security property: it prevents a freed subdomain from being re-registered by someone else to impersonate you or harvest data from old links. We can unpublish the content served at a subdomain if you delete the event or your account, but the subdomain string itself remains reserved and will not be reassigned. Consider this before claiming a subdomain that contains personal information.
Anything you publish may be cached or indexed by search engines and third parties outside our control even after you unpublish it.
7. International data transfers
Our processors may store or process data outside Indonesia (for example, AI, hosting, and payment infrastructure). When we transfer personal data internationally we use safeguards required by law, including:
- UU PDP — transfer to jurisdictions with adequate protection, or contractual safeguards and your consent where required (UU PDP Arts. 56).
8. Data retention
We keep personal data only as long as needed for the purposes above:
| Data | Retention |
|---|---|
| Account & event data | While your account is active; deleted on account deletion (see Section 10), subject to backup cycles. |
| On-device / offline data | Until you clear it, log out where applicable, or uninstall; logout preserves pending unsynced changes. |
| Payment records | As required by tax/accounting law (typically up to 10 years in Indonesia). |
| Security & access logs | Up to 12 months, for security and abuse prevention. |
| Backups | Rolling backups are purged within 90 days after deletion. |
When you request erasure, we run an erasure process that hard-purges your personal data; residual copies in backups age out on the backup cycle.
9. Cookies and local storage
We use only what the Service needs to function:
- Strictly necessary — session/authentication tokens, security (CSRF, MFA), and rate-limiting.
- Functional / offline — local storage and IndexedDB for the offline-first experience and your preferences.
We do not use third-party advertising or cross-site tracking cookies. Because we rely on strictly necessary and functional storage only, no cookie-consent banner is required for advertising; you can still control storage via your browser settings (clearing it may sign you out and remove unsynced offline data).
10. Your rights
Subject to UU PDP (Arts. 5–15), you have the right to:
- Access a copy of your personal data.
- Rectify inaccurate or incomplete data (editable in-app).
- Erase your data ("right to be forgotten") — available in-app via account deletion / erasure, or by contacting us.
- Export / portability — export your data (e.g. CSV export of supported content) in a machine-readable format.
- Restrict or object to certain processing, including profiling.
- Withdraw consent for optional processing (e.g. push notifications, public publishing) at any time.
- Lodge a complaint with the data-protection authority in Indonesia under UU PDP (currently overseen by the Kementerian Komunikasi dan Digital / Komdigi, pending establishment of the dedicated authority).
To exercise any right, use the in-app controls or contact support@datella.app.
We respond within the timeframes required by UU PDP (without undue delay).
11. Children
The Service is intended for adults planning events. We do not knowingly collect personal data from children under 13, and accounts require users to meet the age of majority in their jurisdiction (18 in Indonesia) or have parental/guardian involvement. Guests' data submitted via RSVP is the responsibility of the hosting User. If you believe a child has provided us data, contact support@datella.app and we will delete it.
12. Security
We protect your data with measures including: encryption in transit, hashed passwords, optional multi-factor authentication, rate-limited authentication, access controls, and security logging. No system is perfectly secure; please use a strong password and keep your devices safe. We will notify affected users and
authorities of a personal-data breach as required by UU PDP.
13. Vendors
If you list or claim a vendor profile, your business information (name, category, city, contact, profile content) is shown publicly in the directory to help Users find you. Lead and analytics data we provide to you about Users must be used only to respond to those leads and in accordance with this policy and applicable law.
14. Changes to this policy
We may update this policy. Material changes will be announced in-app or by email, and the "Last updated" date will change. Continued use after the effective date means you accept the updated policy.
15. Contact
- Privacy / data requests: support@datella.app
- Operator: PT Logika Startup Sempurna
- Data Controller: PT Logika Startup Sempurna, Perum Legok Permai Blok D.1 no B4, Desa/Kelurahan Legok, Kec. Legok, Kab. Tangerang, Provinsi Banten
- Data Protection Officer: Wibowo, privacy@datella.app