Skip to main content
BisaPrompt

Legal

Privacy Policy

What BisaPrompt collects, why, and what control you have over it.

Version
2.0
Effective
6 September 2026
Last updated
6 September 2026

This policy explains how BisaPrompt handles your personal data: what we collect, why, who we share it with, how long we keep it, and what you can ask of us.

It is written from how the platform actually works: the data inventory, the provider list, the processing regions and the retention schedule below were read out of the running system, not copied from a template.

Language: this is a courtesy translation. The Indonesian version is the controlling version. Article 31 of Law No. 24 of 2009 requires agreements involving Indonesian parties to be made in Indonesian; where this translation and the Indonesian text differ, the Indonesian text governs.

1. About this policy

This policy covers bisaprompt.com, the application at app.bisaprompt.com, and the public certificate verification pages we publish.

It is not part of the Terms & Conditions; it is a separate notice. You do not "agree" to a privacy policy the way you agree to a contract — you are informed of its contents, and the processing that does require your consent is asked for separately and can be withdrawn.

In short: this document is a notice. Consent you can withdraw — analytics, marketing email — is always asked for separately and never bundled into creating an account.

2. Who we are

The BisaPrompt service is operated by PT BISA PROMPT ARTIFICIAL INTELLIGENCE, an Indonesian individual company (Perseroan Perorangan) domiciled in North Jakarta Administrative City, Republic of Indonesia.

The operator's full identity, incorporation and amendment approval numbers, business identification number, registered address, and complete list of registered business activities appear in the Operator identity block on this page. That block is maintained separately from this text so that a licensing update does not require amending the policy.

The company register writes the name without the "PT" prefix, which is how the Perseroan Perorangan register is styled; the Directorate General of Taxes registered the same entity as "PT BISA PROMPT ARTIFICIAL INTELLIGENCE". Both name one legal person.

Under Law No. 27 of 2022 on Personal Data Protection, BisaPrompt acts as the Personal Data Controller for the data described here; our providers act as Personal Data Processors and process data only on our instructions.

We have not appointed a Data Protection Officer. The law requires one in defined circumstances, including large-scale processing and systematic monitoring. We review that obligation periodically; if the criteria are met, an officer is appointed and this section is updated.

3. Scope

This policy covers data we process when you:

  • visit BisaPrompt's public site;
  • create an account and complete your profile;
  • take courses, sit assessments, and submit challenges;
  • earn, claim, or verify certificates;
  • accumulate XP, badges, and ranks, and redeem rewards;
  • take part in the community;
  • buy a membership or a digital product;
  • opt into the talent directory;
  • contact our support team.

It does not cover third-party services you use on your own, including AI providers we teach or demonstrate. Your use of those services is governed by their own policies.

4. Data we collect

We separate Account Data (private, never public unless you choose it) from Public Profile Data (the community and gamification layer).

Account and authentication

  • email address;
  • password, stored hashed — we never store the plaintext;
  • a link to your Google account, if you sign in with Google;
  • two-factor authentication status and settings;
  • email verification and sign-in codes, stored hashed and short-lived;
  • active sessions, including IP address, browser/device type, creation time, and expiry.

Profile

  • display name and avatar;
  • the name to print on certificates, if you provide one;
  • your chosen certificate language;
  • age as a range, not a date of birth — including a "prefer not to say" option;
  • current job role, a self-written role, industry, and company name where you provide them;
  • AI experience level and skill level;
  • profile visibility setting.

Learning

  • courses you are enrolled in, and progress through each lesson and PDF resource;
  • assessment attempts, the answers you selected, and scores;
  • challenge submissions with the evidence you upload, reviewer notes, and review outcomes;
  • certificate eligibility and issuance history.

Gamification

  • the XP ledger (credits and debits), rank, badges, achievements, quests, and reward redemptions with their processing status.

Community

  • messages you post in community rooms, reports you file, and the blocks and mutes you set.

Transactions

  • order reference, amount, currency, payment status, the payment provider's reference, any coupon or promotion applied, and timestamps;
  • membership history and digital product purchases.

We do not store card numbers, CVV, PINs, bank credentials, or other sensitive payment data. That data never passes through our systems — see section 14.

Talent directory — only if you switch it on

  • profile headline, skills, preferred roles, availability, and portfolio;
  • one contact channel you choose to share, and only after you approve a specific recruiter's contact request.

Support and security

  • your correspondence with support and internal notes relating to your account;
  • audit records of significant actions (who did what, to what, with what outcome) for security and traceability.

Analytics

  • aggregate usage events via Google Analytics, only on the consent basis described in section 15.

5. How we obtain data

From three sources:

  1. Directly from you — registration, profile, learning activity, community posts, challenge evidence, support conversations.
  2. Automatically from your use of the service — sessions, IP address and device type, learning progress, security records, and analytics events on the applicable consent basis.
  3. From third parties you connect — Google, if you choose Google sign-in (we receive your email address, name, and profile photo); and the payment provider, which sends us transaction status.

We do not buy personal data from data brokers and do not build profiles of you from outside sources.

6. Purposes of processing

We process your data only for the following purposes:

PurposeConcrete example
Account creation and managementregistering, verifying email, recovering a password
Authentication and account securitymaintaining sessions, two-factor, detecting suspicious sign-ins
Delivering learning contentopening courses, saving progress, resuming on another device
Assessmentscoring assessments, recording attempts, reviewing challenges
Certificatesdetermining eligibility, issuing, and rendering certificates
Certificate verificationanswering a third party's question about a certificate's authenticity
Gamificationcalculating XP, ranks, badges, quests, and rewards
Communitydisplaying messages, enforcing the guidelines, handling reports
User supportanswering questions and tracing problems on your account
Payment processingcreating orders, receiving confirmations, activating access
Fraud and abuse preventionstopping XP manipulation, assessment cheating, and system abuse
Reliability and maintenancemonitoring errors and fixing them
Analytics and product improvementunderstanding what confuses people, improving the learning path
Operational communicationverification email, important notifications, policy changes
Marketing communicationonly if you consent to it separately
Legal compliance and financial recordsmeeting legal, tax, and bookkeeping obligations

We do not use phrasing such as "for other business purposes". If a new purpose arises, this policy is updated first.

  • Performance of a contract — account, learning, assessment, certificate, and transaction data. Without it, the service cannot be provided.
  • Legal obligation — financial and bookkeeping records, and anything else the law requires.
  • Legitimate and balanced interest — security, fraud prevention, system reliability, and certificate integrity, to the extent this does not override your rights and interests.
  • Consent — analytics, marketing email, appearing in the talent directory, and sharing your contact channel with a recruiter. Consent can be withdrawn at any time without affecting access to what you already have.

These four correspond to the lawful bases in Article 20(2) of Law No. 27 of 2022: performance of a contractual obligation; compliance with a legal obligation; pursuit of other legitimate interests with regard for the data subject's rights; and valid explicit consent.

8. Account and public profile

By default, your profile is private.

Visible to other users when you take part in the community, leaderboards, or other public features:

  • display name and avatar;
  • rank, badges, and XP level;
  • achievements displayed by that feature.

Never shown to other users unless you deliberately share it:

  • email address and contact details;
  • transaction and payment history;
  • assessment answers and attempt details;
  • your correspondence with support;
  • account security data, including sessions and two-factor settings;
  • profile details you have not marked for display.

You are not required to use your legal name as your display name. The certificate name is a separate field, because a certificate is meant to name you.

9. Learning data

Progress, completed lessons, and materials you open are stored so you can stop and resume on another device. We use this to show your progress, determine certificate eligibility, and improve material that many people get stuck on.

Your progress is not shown to other users.

10. Assessment data

Attempts, the answers you selected, timing, and scores are kept for three reasons: showing you your result, enforcing attempt limits, and keeping certificates meaningful.

Assessment answers are private. Authorised staff may access them for scoring, support, dispute resolution, and cheating investigations — not for anything else.

Challenge submissions are reviewed by people. Reviewers see your submission and the evidence attached to it.

11. Gamification

XP, rank, badges, achievements, quests, and redemptions are recorded on your account. The XP ledger is append-only: every credit and debit is stored as its own row and is never deleted, so your balance is always traceable.

Some gamification elements are public, as described in section 8.

In short: XP, ranks, and badges are part of BisaPrompt's gamification. Unless a specific programme says otherwise, none of them has cash value.

12. Certificates

When a certificate is issued we store: the name you set for printing, the related course, completion and issuance dates, the credential ID, the certificate language, the collaborating partner if any, validity status, and the history of events on that certificate (issued, exported, revoked).

The credential ID is not a sequence. Its format is BP-YYYY-MMDD-XXXXXX with six random symbols at the end, so one certificate's ID cannot be used to guess another's.

13. Certificate verification

The public verification page is designed to expose as little as possible.

Shown: credential ID, recipient name as printed, course title, completion date, issuer, partner if any, and validity status.

Never shown: email, phone number, internal account ID, transaction reference, assessment answers, address, date of birth, or any government identifier.

Verification pages are not indexed by search engines and are not included in the sitemap. They are open to anyone who already holds the credential ID — usually from the certificate itself or its QR code.

We may retain certificate verification records after an account is deleted, because a certificate that cannot be verified loses all its value to the person holding it. See sections 19 and 20.

How long verification records are kept. Indefinitely, limited to the minimal fields listed above. The reason is the holder's own legitimate interest: a certificate that cannot be verified stops proving anything, and the person harmed is the one who earned it.

If you want your verification record removed, ask through the contact channels on this page. We meet that request by revoking the certificate — after which it is no longer valid and cannot be used as proof.

14. Payments and Xendit

Payments are processed by Xendit, our payment service provider. Xendit processes payments; the learning service is provided by BisaPrompt.

When you start a payment, our system sends Xendit only: our order reference, the amount, the currency, the country, and the return URL. We do not send your name, email, or profile data to Xendit.

What we receive back: payment status, the payment session reference, event timestamps, and reconciliation information. We store every webhook event together with the result of its signature verification, as an audit record.

Available payment methods are those enabled on BisaPrompt's Xendit account and shown on Xendit's payment page at the time you transact.

Anything you enter directly on Xendit's payment page is processed by Xendit under Xendit's privacy policy, not this one.

We do not list the methods here, because that list can change without changing this policy. What applies is what appears on the payment page when you transact.

15. Cookies and similar technologies

We use browser storage for two things:

Essential. Session cookies, security markers, and basic interface preferences such as light/dark theme. Without these you cannot stay signed in and the service does not work. Essential cookies do not require consent.

Analytics, on consent. Google Analytics loads only after you agree. On the public site a banner asks. In the application, analytics run on the basis of the agreement you gave when completing onboarding; if you have previously declined on that device, your refusal stands and the script does not load.

We do not run third-party advertising pixels and we do not run cross-site tracking advertising.

Full detail is in the Cookie Policy.

16. Service providers

FunctionProviderData processed
DatabaseNeon (PostgreSQL)all application data
Application hostingHostingerrequest traffic and server logs
File storageCloudflare R2PDFs, e-books, lesson images, certificate assets, uploaded evidence
Transactional emailResendemail address and the contents of verification/notification email
PaymentsXenditorder reference, amount, status — see section 14
Google sign-inGoogleemail address, name, profile photo (optional, only if you choose it)
AnalyticsGoogle Analyticsaggregate usage events, on consent only

These providers act as processors on our instructions. We do not sell your personal data and do not trade it for commercial benefit.

17. Sharing

Beyond the providers above, we share data only in these circumstances:

  • Publicly, by your choice — display name, avatar, and gamification elements per section 8; and the minimal certificate data on the verification page per section 13.
  • With recruiters, on your consent — only if you switch on the talent directory. Your contact channel is shared only after you approve a specific contact request.
  • With programme partners — where you take part in a partner programme and its certificate carries the partner's identity. The scope is set by that programme's terms.
  • Under legal obligation — to authorities acting on a lawful request under Indonesian law.
  • To enforce rights — in disputes, fraud investigations, or chargeback handling, to the extent necessary.
  • In a corporate change — on a merger or transfer of the business, with notice to you and without widening the existing purposes of processing.

18. Cross-border transfers

Some of our providers process data outside Indonesia.

We do not claim that all data is stored in Indonesia, because we have not verified that for every provider.

Here is the actual position, verified on 6 September 2026:

FunctionProviderProcessing region
Application hostingHostingerIndonesia
DatabaseNeonSingapore (ap-southeast-1)
File storageCloudflare R2Cloudflare's global network
Transactional emailResendUnited States
Google sign-in, analyticsGoogleglobal

Transfers outside Indonesia are made under Article 56 of Law No. 27 of 2022. We use providers that apply an adequate level of protection and are bound by their own data processing agreements. We do not transfer personal data to a party in a country without adequate protection absent a lawful basis.

We do not claim that all data is stored in Indonesia, because the table above says otherwise.

19. Retention

We keep data for as long as it is needed for the purpose it was collected for, or for as long as the law requires.

CategoryWhy keptPeriod
Account profilerunning the servicewhile the account is active, then per section 20
Sign-in and session logsaccount securitysessions end at expiry or sign-out
Verification codesemail and two-factor verificationshort-lived, then invalid
Learning progressresuming study, certificate eligibilitywhile the account is active
Assessmentsscoring and certificate integrity5 years from the last attempt, or as long as the related certificate stands — whichever is longer
Certificates and verification recordsvalidity for the holder and for third partiesindefinitely, limited to the minimal fields in section 13
Transactions and financial recordslegal, bookkeeping, and tax obligations10 years, per Article 28(11) of the General Tax Provisions Law and Article 11 of Law No. 8 of 1997 on Company Documents
Support conversationstracing an issue's history24 months after the ticket closes
Audit and security recordsabuse investigation12 months
Community contentkeeping conversations coherentper that room's retention rule
Backupsdisaster recovery30-day rotation

Once a period above has passed, the data is deleted or anonymised so it can no longer be linked to you.

20. Account deletion

You can request deletion from Settings → Security. The process:

  1. The request is accepted only from an authenticated session.
  2. The account is disabled and can no longer sign in.
  3. Related records are classified: erasable, to be anonymised, and legally required.
  4. Personal data that need not be retained is erased, or anonymised in records that must survive.
  5. Records that must be kept remain — including transaction and bookkeeping records, fraud investigation records, and certificate verification records.
  6. The deletion event is logged for audit.

What we will say honestly:

  • Your account row is not simply deleted from the database. Some records are append-only and cannot be removed without breaking the integrity of other data; those are anonymised in place.
  • Issued certificates remain verifiable unless revoked. This protects you: a certificate that cannot be verified proves nothing.
  • Data in backups does not disappear instantly. Backups rotate on their own cycle, and we will not claim otherwise.

21. Your rights

To the extent provided by applicable Indonesian law, you have the right to:

  • be informed about the processing of your personal data;
  • access and obtain a copy of it;
  • correct and update inaccurate data;
  • withdraw consent you previously gave;
  • request erasure or destruction, subject to the limits in section 20;
  • request restriction of processing;
  • object to certain processing;
  • receive your data in a portable form, where technically feasible;
  • lodge a complaint.

Some of these may be limited where meeting them would conflict with a legal obligation or harm another person's rights — for example, a request to delete transaction records we are required to keep.

Requests go through the contact channels on this page. We will verify that a request genuinely comes from the account holder before acting on it.

Timing. We meet access, correction, and update requests within 3 x 24 hours of receiving the request and verifying the requester's identity, as required by Law No. 27 of 2022. Requests needing further examination — an erasure that touches records we must keep, for instance — are answered within the same period, with an explanation of which parts can and cannot be met, and why.

22. Children

The minimum age to hold a BisaPrompt account is 17.

Under Law No. 23 of 2002 on Child Protection, a person under 18 is still a child, and Article 25 of Law No. 27 of 2022 requires parental or guardian consent to process a child's personal data.

A 17-year-old user is therefore still a child in law and must obtain parental or guardian consent before creating an account. On completing registration you declare that you are at least 17 and, if under 18, that you have obtained that consent. The declaration is recorded with its timestamp.

We state the limit of what we can do: we verify a declaration, not an identity document. If you are a parent or guardian and believe a child created an account without your consent, contact us through the channels on this page. We will disable the account and delete its data as described in section 20.

23. Security

We apply reasonable technical and organisational measures, including:

  • passwords and verification codes stored hashed;
  • row-level access control in the database, so one user cannot read another's rows;
  • separation of staff roles and permissions;
  • two-factor authentication, mandatory for staff accounts;
  • signature verification on every incoming payment notification;
  • secret credentials never sent to the browser;
  • audit logging of significant actions.

We do not claim the system is "100% secure", "unhackable", or anything equivalent. Such claims cannot be substantiated and we will not make them.

24. Security incidents

If a personal data protection failure occurs, we will investigate, contain it, and notify affected people and the competent authority in accordance with applicable requirements.

Notification deadline. Under Article 46 of Law No. 27 of 2022, in the event of a personal data protection failure we give written notice within 3 x 24 hours to the affected data subjects and to the competent authority.

The notice states which personal data was exposed, when and how it happened, and what we are doing to contain and remediate it. Where an incident disrupts public services or seriously affects data subjects' interests, notice is also given publicly.

Our learning material names, demonstrates, and links to third-party AI services. Linking does not mean we own, sponsor, or partner with them.

Once you leave BisaPrompt, that provider's privacy policy governs. Read it before entering data — especially other people's personal data.

26. Changes to this policy

This policy carries a version number and an effective date. Version history is kept; a published version is never edited in place — changes are published as a new version with a summary of what changed.

For changes that materially affect your rights, we will notify you in the application before the new version takes effect.

27. Contact

Questions, data subject requests, and privacy complaints go through the channels listed in the Contact block on this page.

We publish a contact address only once that mailbox actually exists. Addresses that are not yet live are marked as unavailable rather than written as though they were.

Operator identity

Legal entity
PT BISA PROMPT ARTIFICIAL INTELLIGENCE
Entity type
Perseroan Perorangan
Domicile
Kota Administrasi Jakarta Utara, Republik Indonesia
Registered address
Jl. Boulevard Raya No. 1, RT 012/RW 018, Kelapa Gading Timur, Kec. Kelapa Gading, Kota Administrasi Jakarta Utara, DKI Jakarta 14240
Incorporation approval
AHU-A119002.AH.01.30.Tahun 2026
Established
3 September 2026
Latest amendment approval
AHU-A012826.AH.01.31.Tahun 2026 · 6 September 2026
Business identification number (NIB)
0209260097679

Registered business activities (KBLI 2025)

  • 85592Pendidikan Komputer (Teknologi Informasi dan Komunikasi) Swasta
  • 85572Pelatihan Kerja Teknologi Informasi dan Komunikasi Swasta
  • 85610Jasa Perantara Kursus dan Tutor
  • 58290Penerbitan Perangkat Lunak (Software) Lainnya
  • 58110Penerbitan Buku
  • 60390Aktivitas Situs Jejaring Sosial dan Distribusi Konten Lainnya
  • 62199Aktivitas Pemrograman Komputer Lainnya YTDL
  • 62900Aktivitas Jasa Teknologi Informasi dan Komputer Lainnya
  • 47901Platform Digital Intermediasi Perdagangan Eceran

The full list from the latest amendment approval. Code 47901 is among them, but BisaPrompt is not a retail marketplace — its principal activities are education, training, publishing, and software development.

Licensing values are taken from the operator's official documents. A number we do not hold is simply not listed, and never filled in provisionally.

Contact

What changed in this version: Final version, tracking Indonesian v2.0: operator identity and licensing published; legal bases mapped to Law No. 27 of 2022; 3x24-hour response and breach-notification deadlines set by statute; the retention schedule completed, with financial records at ten years; processing regions verified; minimum age set at 17 with guardian consent below 18.

Related policies