This Privacy Policy describes how SIMSDIG (“we,” “our,” or “us”) collects, uses, and shares your information when you use our mobile application and web platform (the “Service”). SIMSDIG is a school management platform developed by Akhmad Qasim and team, used by multiple educational institutions across Indonesia. We are committed to protecting your personal data and your privacy in accordance with the following Indonesian regulations:
- Undang-Undang No. 27 Tahun 2022 (Personal Data Protection Law - UU PDP)
- Peraturan Pemerintah No. 71 Tahun 2019 (Government Regulation on Electronic Systems and Transactions)
- Peraturan Menteri Komunikasi dan Informatika No. 20 Tahun 2016 (Ministerial Regulation on Personal Data Protection in Electronic Systems)
By using the Service, you agree to the terms of this Privacy Policy and our Privacy Rights.
1. Information We Collect
We collect several types of information to provide educational services, school administration, and a secure user experience.
Important: Most personal data listed below is originally collected offline by the school administration during the formal registration process. The Service serves as a digital interface to view and update this existing data. However, certain data - such as GPS coordinates, attendance photos, and session information - is collected directly by the Service during usage.
A. Data Shared Across All Roles
The following data is collected for all users (students, teachers, and staff):
Important: User accounts are created and managed by the school administration, not by users themselves from within the application. Users do not register or create accounts through the app. You sign in with the email or username and password from your school, with a Google or Apple account that is already linked to your school account, or with a passkey you add yourself from the account security menu. You can sign in on the mobile app or on the school’s web portal. See Sign in with Google and Apple.
- Account: Email, secondary email, username, phone number, profile picture (avatar), and role-based permissions. Accounts are provisioned by school administrators.
- Authentication: Hashed passwords, verification codes, the link to your Google or Apple account if you link one, and your passkeys if you add any (public key, credential ID, device name, and when each was created and last used). The private key of a passkey stays on your device and never reaches us.
- Session Data: IP address, user agent, login history (country, browser type, device model, CPU architecture, OS version), and timestamp.
- Attendance: Check-in/check-out timestamps, attendance status (present, late, permit, sick, absent, business trip), notes, and evidence attachments.
- Location (Attendance): GPS coordinates (latitude/longitude) collected during check-in and check-out when GPS-based attendance is used. An out-of-zone flag indicates if the user is outside the designated area.
- Attendance Photos: Photos captured during face-based attendance as visual proof of presence. These photos are not processed as biometric data - no facial recognition templates, models, or biometric identifiers are generated or stored. Photos are reviewed manually by authorized education staff (tenaga kependidikan) for verification purposes only. Attendance photos are retained for one year as part of the attendance recap, after which they are deleted. The Service supports GPS, QR code, face-based (photo), and manual attendance methods.
B. Student Data (Peserta Didik)
- Identity: NIK, Family Card (KK) number, Birth Certificate number, SKHUN, NISN, and NIPD.
- Demographics: Full name, gender, religion, blood type, place and date of birth, birth order, and nationality.
- Physical Info: Height, weight, head circumference, and special needs (disability conditions).
- Personal Interests: Hobby and aspiration (dream/cita-cita).
- Family: Father, mother, and guardian information (name, NIK, education, occupation, income, contact).
- Social Assistance: KPS/PKH, KIP, and PIP eligibility status including reasons for approval or rejection.
- Household: Home address (RT/RW, sub-district, city, postal code), residence type, number of siblings, landline number.
- Travel: Distance to school, travel time, and mode of transportation.
- Academic: Class, grade level, academic year, enrollment type (new student, transfer, promoted), enrollment status, and homeroom teacher.
C. Teacher & Staff Data (GTK)
- Identity: NIK, NIP (Employee ID), NPWP (Tax ID), tax name, and Family Card (KK) number.
- Demographics: Full name, gender, religion, place and date of birth, nationality, and special needs.
- Employment: Employment status and role within the school.
- Family: Father and mother information, marital status, spouse name/NIP/occupation.
- Contact: Phone number and home address.
- Teaching (Teachers only): Subject assignments, class schedules, time slots, homeroom class, and attendance session management.
D. Letters & Documents
- Letters: Subject, type of letter (dispensation, recommendation, duty assignment, exit permit, active student, custom), status, attachments, recipients, and processing history.
E. Regional Identifiers
- Country/Region: Country codes and regional identifiers used for administrative classification (e.g., province, city, district).
F. Device Permissions
The Service requests the following device permissions. Each permission is optional and can be revoked at any time through your device’s system settings.
- Camera: Used to capture attendance photos as visual proof of presence during face-based attendance check-in, and to take a new profile photo. The camera is not used for facial recognition processing, advertising, or any purpose other than attendance verification and profile photo capture.
- Location (GPS): Used to record your coordinates (latitude/longitude) during GPS-based attendance check-in and check-out. This is used to verify that you are within the designated school attendance zone. Location data is not tracked continuously - it is only collected at the moment of check-in or check-out.
- Photo Library: Used to select an existing photo from your device’s gallery when updating your profile picture. The Service does not access or read any other photos in your library.
2. Sign in with Google and Apple
Besides the email and password from your school, you can sign in to the mobile app and the web portal with a Google or Apple account. This feature is optional. Signing in with a password keeps working even if you do not use it.
A Google or Apple account can only be linked to an account that the school has already created. You cannot create a new SIMSDIG account with Google or Apple.
Data we receive:
- Google (scopes
openid,email, andprofile): name, email address, profile picture, and Google account ID. - Apple (scopes
nameandemail): name, email address or Apple private relay email address, and Apple user ID.
How we use this data: only to sign you in to the account that the school has already created. We do not sell this data, do not share it with other parties, and do not use it for advertising.
Retention: the link to your Google or Apple account is kept until you unlink it or until your account is deleted.
Unlinking and revoking access: You can unlink your Google or Apple account in the account settings of the school’s web portal. You can also revoke SIMSDIG’s access at any time in your Google Account settings or in your Apple ID settings, under Sign in with Apple. After that you can still sign in with your password.
SIMSDIG’s use of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
3. How We Use Your Information
We use the collected data for the following purposes:
- Educational Administration: Managing student, teacher, and staff records across multiple schools.
- Attendance Management: Recording and verifying attendance through GPS, QR code, face-based photo, or manual entry to reduce fraud in presence tracking.
- Service Delivery: Processing official school letters, documents, academic tracking, and class scheduling.
- Security & Authentication: Protecting your account from unauthorized access through login history monitoring and secure sessions.
- School Logistics: Administrative classification for school zoning, transportation planning, and geofencing for attendance zones.
- Communications: Sending important notifications regarding school activities or administrative status.
Legal Basis for Processing
Under UU PDP Article 20, all processing of personal data needs a legal basis. The legal bases we use are:
- Identity data, academic data, and employment data (including Dapodik data): meeting the school’s legal obligations in education and carrying out the school’s tasks in the public interest.
- Attendance data, location at check-in, and attendance photos: carrying out the school’s tasks, and your consent through device permissions that you can revoke at any time.
- Session data and login history: legitimate interest in keeping accounts secure.
- Google or Apple account link: your consent when you link the account.
4. Data Sharing and Third-Party Services
We do not sell your personal data to third parties. Data is shared only under the following conditions:
- School Authorities: Authorized teachers and administrators have access to relevant data for educational purposes.
- Infrastructure Provider: The Service uses Cloudflare for security, performance, and content delivery. Cloudflare may process limited technical data (such as IP addresses and request headers) as part of its network and security services. As a global network provider, Cloudflare may route and process this technical data through servers located outside of Indonesia. Student records, academic records, attendance records, and other educational content stored by the school are not shared with Cloudflare for its own independent use.
- Google and Apple (sign-in providers): If you choose to sign in with Google or Apple, Google or Apple processes that sign-in under its own privacy policy (Google, Apple). We only receive the data listed in the Sign in with Google and Apple section.
- No Analytics or Advertising: The Service does not integrate any third-party analytics, advertising, or tracking SDKs.
- Legal Compliance: When required by law, government regulations, or legal processes.
We only work with third parties that protect personal data at the same or a higher level of protection than this Privacy Policy. At present these third parties are Cloudflare, Google, and Apple.
5. Data Security
Given the highly sensitive nature of the data (such as NIK and Family Card numbers), we implement rigorous security measures using industry-standard, high-security algorithms:
- Encryption at Rest: Sensitive identifiers and personal data are encrypted using industry-standard encryption algorithms.
- Password Hashing: Passwords are hashed using a cryptographically secure, one-way hashing algorithm resistant to brute-force and rainbow table attacks.
- Encryption in Transit: All data transmitted between the client and server is protected using HTTPS with modern TLS protocols.
- Access Control: Data access is strictly restricted based on user roles and permissions. Each role has granular access to only the data necessary for their function.
- Monitoring: Every login attempt is recorded to detect and prevent suspicious activities.
Data Controller and Liability
The school is the data controller and is solely responsible for the storage, management, and security of all personal and educational data on its own server infrastructure. The Service developer provides the software platform but does not host, store, or have direct access to the school’s data.
The Service developer shall not be held liable for any data breach, unauthorized access, or data loss caused by the school’s negligence, misconfiguration, or failure to maintain adequate security measures on its server infrastructure. In the event of a security incident, an independent audit may be conducted to determine the cause and responsible party.
6. Cookies and Authentication
The Service uses a limited set of cookies for authentication and user preferences. These cookies:
- Are not used for advertising, tracking, or analytics.
- Are stored locally on your device.
- Do not collect or transmit data to third parties.
The following cookies are used:
- __Secure-core.session_token - Stores your authenticated session token. Expires when you sign out.
- __Secure-core.session_data - Stores session-related metadata. Expires when you sign out.
- __Secure-core.dont_remember - Controls whether the session persists after closing the browser.
- colorPref - Stores your preferred color theme (light/dark mode). Persists across sessions.
The cookies above are used by the SIMSDIG app and the school’s web portal. The public website simsdig.com sets no cookies at all and loads no analytics.
7. Data Retention and Deletion
Retention Period
Your personal data is stored on the school’s own server located in Indonesia. The Service developer does not independently store or control this data. The school is the data controller.
- Identity data, academic data, and employment data: for the duration of your enrollment or employment at the school, then for the archive period required by education regulations.
- Attendance records and letters: for the duration of your enrollment, as part of the academic archive.
- Attendance photos: one year for attendance recap purposes, after which they are automatically deleted from the server.
- Session data: until you sign out or the session expires.
- Login history: at most 90 days by default (the school can set it between 7 and 365 days), then deleted automatically.
- Google or Apple account link: until you unlink it or your account is deleted.
Account Deactivation
Account deactivation is managed by the school administration based on the student’s academic status. Accounts are deactivated under the following circumstances:
- Graduation: Upon graduation, the account role is changed to alumni. Alumni accounts have limited access to the Service, restricted to the tracer study program (program Kemendikti).
- Transfer: If a student transfers to another school, their account is deactivated.
- Dismissal: If a student is dismissed from the school, their account is deactivated.
- Voluntary request: A student may request account deactivation through the school’s administrative office (Tata Usaha). This will be treated as withdrawal from the school.
Upon deactivation:
- Your login credentials are disabled and you can no longer access the Service.
- Your profile is no longer visible to other users within the Service.
Limitations on Data Deletion
Student, teacher, and staff records are part of the national education data system (Dapodik) maintained by the Indonesian Ministry of Education. Due to regulatory requirements, certain data (such as NISN, NIP, and enrollment records) cannot be permanently deleted from the school’s system, as doing so would affect the integrity of national education records.
What You Can Do
- Update your data: Correct or modify personal information through the Service or by contacting your school administration.
- Request deactivation: Submit an explicit request to the school’s administrative office (Tata Usaha).
- Revoke optional permissions: Disable device-level permissions (such as camera for profile photo) at any time through your device’s system settings.
Response Timeline
When you submit a request to update, correct, or deactivate your data, the school administration will process your request within 5 business days from the date the request is received. You will be notified once the action has been completed.
8. Account and Data Deletion
SIMSDIG accounts are created and deleted by the school. You cannot create an account yourself through the app.
How to request deletion: submit a request to the school’s administrative office (Tata Usaha), or send an email to admin@simsdig.com from the email address registered on your account. We will forward your request to the school and help the school process it.
What is deleted: your account and its records in the database, namely account data, Google or Apple account links, sessions, login history, and attendance records. After that your account can no longer be used. Stored files, such as profile pictures and attendance photos, are removed by the school at your request.
What is kept: data the school must keep under education regulations, such as NISN, NIP, enrollment records, and academic history in Dapodik. This data is kept for the period those regulations require. See Data Retention and Deletion.
Processing time: the school processes the request within 5 business days from the date the request is received. You will be notified once it is done.
Deactivating an account alone is not deletion. If you want your data deleted, say so in your request.
9. Children's Privacy
SIMSDIG is a school app for students, teachers, and education staff. Students are typically aged 12 and above. Under UU No. 35 Tahun 2014 on Child Protection, students under 18 years of age are children.
Children’s data is specific personal data under UU PDP Article 4. This data is processed only for school administration. Under UU PDP Article 25, processing children’s data requires the consent of a parent or guardian. The school asks the parent or guardian for written consent when the student registers.
Other specific data, such as blood type, disability conditions, height, and weight, is also used only for school administration.
Signing in with Google or Apple is optional. Students can use every SIMSDIG feature with the email and password from their school.
The Service developer does not collect or process children’s data beyond the data provided by the school.
10. Data Storage Location and Transfer
All personal and educational records are primarily stored on servers located in Indonesia, typically hosted on-premise at each respective school. The school’s core educational records - including student data, academic records, and attendance records - are not intentionally hosted outside of Indonesia. However, limited technical data (such as IP addresses and request headers) may be processed internationally by Cloudflare as part of its security and content delivery services (see Section 4).
Data transfer outside Indonesia: Cloudflare (network technical data), Google, and Apple (sign-in data, if you use sign-in with Google or Apple) may process data outside Indonesia. In line with UU PDP Article 56, we only use providers that give personal data protection equal to or higher than UU PDP, through data processing agreements and each provider’s privacy policy.
11. Data Breach Notification
If a failure of personal data protection occurs, we and the school will give written notice no later than 3 x 24 hours to:
- affected users, by email; and
- the personal data protection authority,
in accordance with UU PDP No. 27/2022 Article 46. The notice states the personal data that was disclosed, when and how it was disclosed, and the steps taken to handle and recover from it.
12. Automated Decision-Making
The Service does not use automated decision-making, artificial intelligence (AI), or profiling algorithms that produce legal effects or significantly affect users. All decisions regarding academic records, attendance verification, and account management are made by authorized school personnel.
If this changes in the future, we will update this Privacy Policy and notify affected users accordingly.
13. Anonymous and Aggregate Data
We may create and use anonymized or aggregate data derived from personal data, where all identifying information has been removed so that the data cannot be linked to any individual. Examples include:
- Total number of students enrolled (displayed on the school’s public website)
- Aggregate attendance statistics
- Aggregate counts produced on the school’s server for Service improvement, without analytics or tracking SDKs. The simsdig.com website itself collects no usage metrics at all.
Anonymized data is not considered personal data under UU PDP No. 27/2022 (Personal Data Protection Law) and may be used without restriction for statistical, analytical, or reporting purposes.
14. Your Rights as a Data Subject
Under UU PDP Articles 5 to 13, you have the right to:
- get information about the identity of the party requesting the data, the legal basis, the purpose, and the accountability of the processing (Article 5);
- complete, update, and correct personal data that is wrong or inaccurate (Article 6);
- access and get a copy of your personal data (Article 7);
- end the processing of, delete, or destroy your personal data (Article 8);
- withdraw your consent to the processing of personal data (Article 9);
- object to decisions based only on automated processing (Article 10);
- delay or restrict the processing of personal data (Article 11);
- sue and receive compensation for violations in the processing of personal data (Article 12);
- get and use your personal data in a common format that electronic systems can read, and send it to another data controller (Article 13).
Submit your request in writing to the school’s administrative office (Tata Usaha) or to the data protection contact in the Contact Information section. How to use these rights is explained on the Privacy Rights page.
15. Complaints and Disputes
If you believe your personal data has been misused, processed without proper authorization, or handled in violation of this Privacy Policy, you have the right to file a complaint.
How to File a Complaint
- To the school: Contact the school’s administrative office (Tata Usaha) directly. The school is the data controller and is responsible for handling complaints and requests related to personal data processed within the Service.
- To the developer: You may also contact the developer for technical issues related to the Service or if you need help identifying the appropriate school contact. If a privacy-related complaint is sent to the developer, the developer may acknowledge receipt and forward the complaint to the relevant school, but the school remains responsible for reviewing and resolving the matter.
Response Timeline
The school will review and respond to privacy-related complaints and requests within a reasonable timeframe in accordance with applicable laws and internal school procedures. If a complaint is first submitted to the developer, the developer may acknowledge receipt and forward it to the relevant school, but this does not transfer responsibility for handling the complaint from the school to the developer.
16. Contact Information
If you have any questions or concerns regarding this Privacy Policy, please contact us:
For Google Play Developers:
- Contact: Muhammad Fauzan Gifari Dzul Fahmi
- Email: fauzan@simsdig.com
For Apple App Store Developers:
- Contact: Akhmad Qasim
- Email: aqas@simsdig.com
Data protection contact and deletion requests: admin@simsdig.com
Address: Jl. Kemakmuran, Sungai Pinang, Sungai Pinang, Kota Samarinda, Kalimantan Timur
For data-related requests (updates, corrections, deactivation, or portability):
Please contact your school’s administrative office (Tata Usaha) directly. For a list of schools currently using SIMSDIG and their contact information, see the Privacy Rights page.
17. Changes to This Privacy Policy
We may update this Privacy Policy from time to time to reflect changes in our practices or legal requirements. When we make changes:
- We will notify affected users by email before the changes take effect, in accordance with UU PDP Article 21 paragraph (2).
- The “Last Updated” date at the top of this page will be revised.
We encourage you to review this page periodically to stay informed about how we protect your data.
Revision History
- October 7, 2026 - Added the sections on signing in with Google and Apple, legal basis, account and data deletion, data transfer outside Indonesia, data subject rights, and the data protection contact. Attendance photos are now kept for one year. Updated the developer contacts and address. Listed sign-in with a username and with a passkey.
- March 24, 2026 - Initial version published.