Effective 11 October 2026 · Version 2026-10-11
Operator and scope
Rekanta is operated by PT AIRA TEKNOLOGI INDONESIA, at Perum De Green Cempaka, Anturium 5, Kec. Sukun, Kota Malang, Jawa Timur, Indonesia. Contact hello@airagroup.co with the subject “Rekanta privacy” for questions or requests.
This policy applies to the Rekanta website and application. Customer companies determine the purposes for employee data and instruct Rekanta in its processing. AIRA manages account, security and service relationship data needed to operate Rekanta.
Data and purposes
Account data includes names, email addresses, profiles, authentication and company membership. Depending on company features, data may include employee identity, organization, documents, schedules, attendance, leave, overtime, claims, assets, bank details, salary components and payroll results.
Session, IP address, device and activity information supports service operation and security. Data supports selected HR functions, accounts, subscriptions, service notifications, assistance and applicable obligations. Companies must inform employees, establish a lawful basis and ensure authorized data use. Where consent is required, it is obtained for its purpose and can be withdrawn through a data request.
Access and service providers
Application access follows the active company, membership and permissions. Privileged roles require MFA. Assistance access is limited to authorized parties and relevant needs.
Hosting and storage providers support the service; Amazon SES delivers application email, and Cloudflare provides domain services. Provider processing information can be requested through the official contact. Data is not sold.
Providers outside Indonesia do not imply that all data is held in one region. Cross-border processing and transfers must follow applicable data protection requirements.
Retention and deletion
Data is retained as needed for the service and lawful purposes. Certain transaction, security or company records may remain for legal, tax or dispute obligations with restricted access.
Ending a subscription does not automatically delete all HR records. Companies can request assistance with handing over available data and deleting data no longer needed. Requests are reviewed against authority and retention duties; backup data is handled in relevant maintenance and recovery processes.
Your rights and requests
You can request information, access, copies, correction, deletion or restrictions, and withdraw consent where it is the processing basis. Contact your company administrator for employment data, or hello@airagroup.co.
Provide your account name, company and request type. We may seek necessary authority verification to protect other people’s data. Do not send passwords, OTPs, full identity numbers, bank details or salary information in an initial email.
Requests follow applicable legal deadlines and conditions. General administrative timelines do not extend mandatory rights deadlines. We coordinate with the company where needed and explain relevant limitations.
Cookies, security and incidents
Session cookies support login and preferences preserve display choices. Technical information supports operation and security.
Access controls and appropriate security measures reduce risks without guaranteeing that risks can be eliminated. Data protection failures are handled and notified as required by applicable law.
Policy changes
The version and effective date appear on this page. Material changes are communicated through available service channels. Contact us for questions about this policy or your data.