Privacy Policy
This policy explains how ONEXTO handles account, security, administration, and operational information.
Provider, dates, and scope
This Privacy Policy explains how Indo Human Resources handles personal information in connection with ONEXTO. It is effective on 19 August 2026, was last updated on 19 August 2026, and is governed by the Republic of Indonesia.
This policy applies to public login, registration, and legal pages, and to authenticated ONEXTO workflows used by approved operations, engineering, administration, and support users.
Privacy roles
Indo Human Resources provides this public privacy notice for ONEXTO. Depending on the deployment, workflow, and the organization that authorizes your account, Indo Human Resources may act as the party responsible for handling personal information, as an operator acting on instructions, or as a contact point for privacy requests.
If another organization controls your access, role, source data, or operational instructions, that organization may also have privacy responsibilities. This policy does not replace notices, employment rules, customer rules, or contractual instructions that apply outside ONEXTO.
Product-domain data and personal information
ONEXTO can process product-domain operational data and personal information. Product-domain data includes network, KPI, measurement, reporting, server-status, configuration, and tool workflow data that relates to operations rather than to an individual person.
Personal information includes account, contact, authentication, approval, session, profile, activity, support, or security information that identifies or can reasonably be linked to a user. Some records may contain both categories, such as activity logs tied to a user action on operational data.
Sources of information
Information may come from you, administrators, approval owners, authenticated product use, configured identity or communication providers, security controls, support interactions, application-generated logs, and connected operational sources shown inside ONEXTO.
Information may also be created by ONEXTO when it records account state, session state, configuration activity, workflow activity, export activity, support references, errors, or service readiness states.
Information we collect
ONEXTO collects information needed to provide account access, operational workflows, administration, security controls, and support. The exact information depends on your role, configuration, and the features you use.
- Account and registration details, such as email address, phone number, approval owner, role or level, approval state, and registration state.
- Authentication and security details, such as login identifiers, one-time password challenge state, session identifiers, Google sign-in results when configured, reCAPTCHA verification results, and request context needed for abuse prevention.
- Profile and contact updates submitted through account settings.
- Operational activity, such as page access, configuration activity, user administration actions, measurement or tool usage context, export or report actions, support codes, and error reference identifiers.
- Technical information, such as request context, browser interaction with the application, service availability states, build identifiers, and telemetry needed to recover from loading or service errors.
How we use information
We use personal information for product, operational, security, administration, legal, and support purposes connected to ONEXTO.
- Approve, create, authenticate, and manage user accounts.
- Send or verify one-time passwords and account-related messages through configured communication channels.
- Provide dashboards, measurement pages, reporting, tools, server-status views, administration pages, and configuration workflows.
- Record activity needed for auditability, troubleshooting, abuse prevention, incident investigation, and service reliability.
- Maintain theme, configuration, profile, session, and workspace preferences where supported by the product.
Lawful bases and operational necessity
Where a lawful basis is required, processing may rely on one or more bases depending on the context: performing an authorized service or work arrangement, complying with applicable law, protecting systems and users, supporting legitimate operational interests, handling requests, or acting with consent where consent is required and valid.
The applicable basis can vary by user role, deployment, organization, feature, and jurisdiction. This policy should be read conservatively and does not claim that every basis applies to every processing activity.
Automated insights and human oversight
ONEXTO may calculate, organize, filter, display, export, or summarize operational data, including KPI views, readiness states, reporting views, tool outputs, warnings, and support references. These outputs can help users notice operational patterns or exceptions.
ONEXTO does not replace human review for important operational decisions. Users remain responsible for validating outputs, applying professional judgment, following approval procedures, and escalating issues through the proper operational path.
Third-party features
Configured features may involve third-party identity, abuse prevention, or communication services. Examples include Google sign-in, Google reCAPTCHA, email delivery, or WhatsApp messaging when those features are configured for the deployment.
Those providers may process information under their own terms and privacy policies. ONEXTO public legal pages do not intentionally load third-party scripts for page display.
Retention
We keep information for as long as needed to provide ONEXTO, maintain security and auditability, comply with applicable requirements, resolve disputes, and support operational continuity. Retention periods may differ by account data, activity logs, configuration records, operational records, support evidence, and security records.
When information is no longer needed, it should be deleted, anonymized, or retained only where a lawful, contractual, security, audit, or operational reason requires it.
Security safeguards
ONEXTO uses access controls, role-aware surfaces, session handling, one-time password flows, approval states, abuse checks, maintenance gates, and operational logging to protect the workspace. No system can guarantee absolute security.
Users must protect their accounts, devices, verification codes, and any operational data they access. Do not send secrets, credentials, or unnecessary personal information through support messages.
Security incidents
If we identify a security incident affecting personal information, we will evaluate the incident and take steps that are appropriate for the risk, legal requirements, operational context, and available contact information.
Report suspected unauthorized access, exposed credentials, suspicious verification messages, or privacy incidents to Anungmahargono@gmail.com.
Storage and access location
ONEXTO may be accessed by authorized users and supported by configured infrastructure or providers. Information may be processed where the application, communication, identity, hosting, support, or operational services are operated, subject to applicable law and organizational requirements.
Your rights and choices
Subject to applicable law and account authorization, you may request access, correction, deletion, restriction, objection, portability where applicable, or review of personal information connected to your ONEXTO account. Some records may need to be retained for security, audit, legal, contractual, or operational reasons.
Send privacy requests to Anungmahargono@gmail.com. We may need to verify your identity, role, and authorization before acting on a request.
Children
ONEXTO is an internal operational workspace for authorized professional users. It is not directed to children and should not be used by anyone who is not authorized for operational access.
Changes and contact
We may update this Privacy Policy as ONEXTO, legal requirements, provider configuration, or operational practices change. The effective date and last updated date show when this version applies.
For privacy questions, contact Anungmahargono@gmail.com or write to Indo Human Resources at Ruko Bidex Blok G17, Jalan Pahlawan Seribu No.8, Kelurahan Lengkong Gudang, Kecamatan Serpong, Kota Tangerang Selatan, Banten, 15310, Indonesia.