Pantograf Portal & Platform
Privacy Policy
Last updated: 26 July 2026
This page is provided in English for the Portal. It is intended to meet Google Sign-In / OAuth disclosure requirements and UU PDP transparency expectations. Have counsel review before relying on it for regulated processing.
This Privacy Policy describes how PT Pemeta Antariksa Grafika collects and uses personal data in connection with Pantograf services.
1. Who we are
This Privacy Policy explains how PT Pemeta Antariksa Grafika (“Pantograf”, “Provider”, “we”) collects, uses, stores, and shares personal data when you use the Pantograf marketing site (https://pantograf.id), Portal (https://portal.pantograf.app), related Centre / Instance services, and associated websites.
Provider details: PT Pemeta Antariksa Grafika, Jl. BDN 1, Kelurahan Cilandak Barat, Kecamatan Cilandak, Kota Administrasi Jakarta Selatan, DKI Jakarta 12430, Indonesia. NIB 1405260002939. Contact: contact@pantograf.app.
We process personal data in accordance with the laws of the Republic of Indonesia, including Law Number 27 of 2022 on Personal Data Protection (UU PDP), and — where applicable — other regimes that bind you as a customer.
2. Scope
This Policy covers:
- Portal account holders (members, admins, and staff) who register or sign in at the Portal;
- Users of Pantograf Instances (Centre / trial / paid deployments) insofar as Pantograf processes account or operational data as a service provider;
- Visitors who interact with Portal pages (including authentication and billing flows).
For spatial / GIS content you upload into an Instance (“Client Data”), Pantograf typically acts as a personal data processor on behalf of the Client (the controller), as described in our Terms of Service (Personal Data Protection article). This Policy also describes how we process your Portal account data as a controller.
3. Personal data we collect
Depending on how you use Pantograf, we may process:
- Account data: email address, username, display name, optional account image, password hash (we do not store plaintext passwords), role, email verification status, and account status;
- Google Sign-In data: if you choose “Continue with Google”, we receive an ID token from Google and process identifiers Google provides for authentication (typically email and Google subject ID / profile basics needed to create or link your Portal account). We use this only to authenticate you and manage your account;
- Security data: multi-factor authentication secrets / verification status for staff accounts; session cookies;
- Usage and visit data: approximate country/region derived from IP, last visit time, and similar operational metadata used for security, market/currency display, and service integrity;
- Billing and commercial data: selected plan / seat SKU, billing period, voucher redemptions, payment references, and related emails (receipts, renewal reminders);
- Support and communications: messages you send to us (e.g. contact@pantograf.app) and transactional emails we send you;
- Client Data on Instances: spatial files, project content, and any personal data contained therein that Users upload — processed to provide the Instance services under the Client’s instructions;
- Technical telemetry: Aggregated and Anonymized Data (performance, feature usage, error logs) that cannot reasonably identify you or your projects, as described in our Terms.
4. How we use personal data
We use personal data to:
- create and authenticate Portal and Instance accounts (including Google Sign-In and staff 2FA);
- provide, maintain, secure, and improve the Portal, Centre, and Instance services;
- provision seats, enforce plan limits, process vouchers/payments, and send service notices;
- provide customer support and respond to requests;
- comply with legal obligations and enforce our Terms;
- generate Aggregated and Anonymized Data for monitoring and product improvement (not to re-identify individuals or Client projects).
We do not sell your personal data.
5. Google user data
If you sign in with Google, Pantograf’s use of information received from Google APIs complies with the Google API Services User Data Policy, including Limited Use requirements. We use Google authentication data to sign you in, create or link your Portal account, and secure access. We do not use Google user data for advertising, and we do not sell it.
6. Legal bases
Where UU PDP or similar rules require a lawful basis, we rely on: performance of a contract (providing the services you request); your consent (e.g. optional Google Sign-In, marketing if ever offered separately); legitimate interests in securing and improving the service that do not override your rights; and legal obligations.
Clients who upload personal data into an Instance must ensure they have a lawful basis. Foreign regimes (including GDPR) may require a separate Data Processing Agreement before such uploads.
7. Sharing and sub-processors
We may share personal data with:
- Infrastructure and storage providers used to host the Portal/Centre and durable backups (for example object storage such as Cloudflare R2);
- Email delivery providers used to send transactional mail (for example SMTP via our mail provider);
- Payment providers when you complete paid checkout (as configured for your market);
- Google, solely as part of Google Sign-In when you choose that method;
- authorities when required by law; and
- professional advisors under confidentiality, when needed.
When Pantograf engages sub-processors for Client personal data on an Instance, we bind them to equivalent protection obligations and follow the notice/consent approach described in our Terms.
8. International transfers
Personal data may be processed on servers or by sub-processors located outside Indonesia. Transfers are carried out in accordance with Article 56 of UU PDP (adequate protection and/or other permitted mechanisms, including consent where required).
9. Retention
We retain Portal account data for as long as your account remains active and as needed for billing, security, and legal compliance. After Instance service ends, Client Data is returned and/or deleted within 14 calendar days (or a shorter period agreed in writing), unless renewal or a permanent digital copy option applies, as described in our Terms.
Backup archives associated with cancelled seats may remain available for download while your Portal login remains active, subject to retention practices we communicate in-product.
10. Security
We implement reasonable technical and organizational measures to protect personal data (access controls, encryption in transit where applicable, least-privilege staff access, and operational monitoring). No method of transmission or storage is completely secure; please protect your credentials and enable staff 2FA where required.
If we become aware of a personal data breach affecting data we process, we will notify the Client / affected parties as required by UU PDP and our Terms (including cooperation so Controllers can meet their 3×24 hour notification duties where applicable).
11. Your rights
Subject to UU PDP and other applicable law, you may request access, correction, deletion, restriction, or objection regarding your personal data, and withdraw consent where processing is consent-based. Contact contact@pantograf.app. We may need to verify your identity before fulfilling a request.
If you use an Instance under a Client organization, some requests about Client Data should be directed to that Client (the controller); we will assist them as processor.
12. Cookies and similar technologies
The Portal uses essential cookies / local session mechanisms (for example an HTTP-only session cookie) to keep you signed in and protect authentication flows. We do not use these essential cookies for third-party advertising.
The marketing site (pantograf.id) and Portal guest pages may send first-party Aggregated and Anonymized conversion telemetry (for example page views and button clicks) to the Portal API. Country is derived server-side from the request network. This telemetry does not use advertising cookies, does not create a persistent visitor profile for ads, and is not sold to third parties.
13. Children
Pantograf services are directed to organizations and adult professionals. We do not knowingly collect personal data from children as defined under applicable law.
14. Changes
We may update this Privacy Policy from time to time. We will post the updated version on this page and adjust the “Last updated” date. Material changes will be notified through the Portal or by email when appropriate.
15. Related documents
Use of Pantograf Instances is also governed by our Terms of Service (Paid) and, for trial deployments, our Trial Terms. Those documents include additional rules on Client Data, confidentiality, and processor obligations.
16. Contact
Privacy questions and requests: contact@pantograf.app
PT Pemeta Antariksa Grafika, Jl. BDN 1, Cilandak Barat, Cilandak, South Jakarta 12430, Indonesia.