Privacy policy & data consents
How PT Tensor manages personal and business data when you create an account, use tensorERP apps, and interact with our marketing site.
Summary
This policy describes what data we collect, why we use it, where it is stored, who it may be shared with, and your rights. By creating an account or using tensorERP services, you agree to the practices on this page, together with the freemium billing policy and single-device login policy (where applicable).
Data controller: PT Tensor (“we”, “us”). Contact: wiratama@pttensor.com.
Data we collect
1. Account & signup data
When you register an admin account (including free signup forms), we may collect:
- Company name, office address, and type of business
- Contact name, phone number, and/or work email
- Account password (stored as a hash by the authentication service, not in plain text)
- Signup time and technical metadata needed to create the account
2. Authentication & session data
- User identity in Amazon Cognito (tensorAM) and group/role membership
- Device session identifiers and last-activity timestamps to enforce single-device login
- Session tokens required to keep you signed in
3. Business data in the apps
Operational content that you or your employees enter into tensorERP modules (finance, POS, CRM, inventory, HR, projects, and others) — such as transactions, products, customers, and documents — is stored on behalf of your company so the service can function.
4. Payment & billing data
For paid subscriptions, we process data needed for invoices, license quotas, and payment confirmation via payment partners (for example DOKU). Sensitive card or payment-method details are typically processed directly by the payment partner under their own policies.
5. Marketing site & analytics data
- Pages visited, locale, and aggregated visit counters (we do not persist raw client IPs in our analytics database)
- Contact details you voluntarily submit via quote forms for sales follow-up
How we use data
- Create and manage accounts, authentication, and module access
- Provide, maintain, secure, and improve the services
- Enforce freemium quotas, licenses, and device-session policy
- Process payments, invoices, and customer support
- Send operational account communications (not marketing spam without a lawful basis)
- Meet legal obligations and resolve disputes
Legal basis & consent
For account registration, we rely on your consent (the checkbox on signup forms) and on contractual necessity to provide the requested service. For company business data in the apps, we process data as a service provider on instructions from your organization (company admin).
Storage & security
Services run on Amazon Web Services (AWS). We apply access controls, encryption in transit (HTTPS), and reasonable operational practices to protect data. No method of transmission or electronic storage is 100% secure; we improve protections over time.
Sharing
We do not sell your personal data. Data may be shared only with:
- Infrastructure providers (AWS) for hosting and authentication
- Payment partners to complete paid transactions
- Support vendors bound by confidentiality, as needed
- Authorities when required by applicable law
Your company admins can view and manage workspace data, including user accounts in that organization.
Retention
- Accounts & business data: while the account/organization is active and as needed for service, legal, or dispute purposes
- Device sessions: removed on sign-out or session expiry (see single-device login policy)
- Aggregated site analytics: generally about 180–365 days for trends
- Quote records: as long as needed for sales/contracts/compliance, then deleted or anonymized
Cookies & local storage
The site and apps may use cookies, session storage, or similar local storage for login sessions, language preference, checkout cart, and technical functions. Disabling that storage may break login or certain features.
Your rights
Under applicable Indonesian law, you may request access to, correction of, or deletion of certain personal data by contacting us. For workspace data, also contact your organization’s tensorAM admin — some requests must be handled through the company admin.
Children
tensorERP is intended for business use. We do not knowingly collect children’s personal data for marketing purposes.
Policy changes
We may update this page from time to time. The “effective” date above will change. Continued use of the services after a change means you accept the updated policy to the extent permitted by law.
Contact
Privacy questions or data requests: wiratama@pttensor.com.
Related policies: Freemium billing policy · Single-device login policy.