1. Introduction
This Privacy Policy describes Our policies and procedures on the collection, use and disclosure of Your information when You use the SISKANA application (the "Service") and tells You about Your privacy rights and how the law protects You.
We use Your Personal Data to provide and improve the Service. By using the Service, You agree to the collection and use of information in accordance with this Privacy Policy.
2. Interpretation and Definitions
2.1 Interpretation
The words whose initial letters are capitalized have meanings defined under the following conditions. The following definitions shall have the same meaning regardless of whether they appear in singular or in plural.
2.2 Definitions
- Account
- means a unique account created for You to access our Service or parts of our Service.
- Application
- refers to SISKANA, the software program provided by the Company.
- Company
- (referred to as either "the Company", "We", "Us" or "Our") refers to SMK Negeri 6 Semarang, Jl. Sidodadi Barat No.8, Karangturi, Kec. Semarang Tim., Kota Semarang, Jawa Tengah 50124.
- Country
- refers to: Indonesia.
- Device
- means any device that can access the Service, such as a computer, a cell phone or a digital tablet.
- Personal Data (or "Personal Information")
- is any information that relates to an identified or identifiable individual.
- Biometric Data (Face Data)
- means the live facial image captured by the Device's camera, and any data mathematically derived from that image (such as facial geometry), used to verify Your identity within the Application.
- Service
- refers to the Application.
- Service Provider
- means any natural or legal person who processes data on behalf of the Company to facilitate or provide the Service, or to assist the Company in analyzing how the Service is used.
- Usage Data
- refers to data collected automatically, either generated by the use of the Service or from the Service infrastructure itself.
- You
- means the individual accessing or using the Service.
3. Collecting and Using Your Personal Data
3.1.1 Personal Data
While using Our Service, We may ask You to provide Us with certain personally identifiable information that can be used to contact or identify You, including but not limited to:
- First name and last name
- Phone number
- Address, State, Province, ZIP/Postal code, City
3.1.2 Usage Data
Usage Data is collected automatically when using the Service, and may include Your Device's Internet Protocol address, browser type and version, the pages of our Service that You visit, the time and date of Your visit, time spent on those pages, unique device identifiers, and other diagnostic data.
3.1.3 Information Collected while Using the Application
While using Our Application, in order to provide features of Our Application, We may collect, with Your prior permission:
- Information regarding your location
- Pictures and other information from your Device's camera, used, among other things, for the facial verification feature described in Section 3.1.4 below
You can enable or disable access to this information at any time through Your Device settings.
3.1.4 Face Data (Biometric Information) for Attendance Verification
When You use the attendance ("presensi") feature of the Application, the Application accesses Your Device's camera to capture a live facial image for the sole purpose of verifying Your identity as a registered student before recording Your attendance.
This facial verification is performed entirely on Your Device, using the Device's built-in, on-device processing capabilities. The facial image and any data derived from it (such as facial geometry used for matching) are never transmitted to, or stored on, the Company's servers or any third-party server.
We do not share Your facial data with the Company, with any Service Provider, or with any other third party, because this data never leaves Your Device.
Once the identity verification process is complete — whether the verification succeeds or fails — the captured facial image and any related biometric data are immediately and permanently deleted from the Device's memory. No facial image or biometric template is cached, backed up, or retained in any form, on the Device or elsewhere.
Because this data is never collected by or transmitted to Us, it is not subject to the retention periods described in Section 3.4 ("Retention of Your Personal Data"), which apply only to Personal Data that We actually collect and store.
- Data collected: A live facial image captured via the Device camera, and temporary facial geometry data derived from it for matching purposes.
- Purpose: To verify a student's identity for the school attendance ("presensi") system.
- Processing location: Entirely on-device (local processing only).
- Shared with third parties: No — the data never leaves the Device.
- Stored on Company or third-party servers: No.
- Retention period: None. Automatically deleted immediately after each verification attempt, whether successful or not.
3.2 Use of Your Personal Data
The Company may use Personal Data for the following purposes:
- To provide and maintain our Service, including to monitor the usage of our Service.
- To manage Your Account: to manage Your registration as a user of the Service.
- To verify Your identity for attendance: to use the Device's on-device facial recognition capability to confirm You are the registered student recording attendance. This processing occurs entirely on Your Device and no facial data is retained or transmitted to Us, as described in Section 3.1.4.
- To contact You: by email, telephone, SMS, or other electronic communication regarding updates or informative communications related to the Service.
- To manage Your requests: to attend and manage Your requests to Us.
- For other purposes: such as data analysis, identifying usage trends, and evaluating and improving our Service.
3.4 Retention of Your Personal Data
The Company will retain Your Personal Data only for as long as is necessary for the purposes set out in this Privacy Policy, or to comply with legal obligations, resolve disputes, and enforce our agreements.
- Account Information: retained for the duration of your account relationship, plus up to 24 months after account closure.
- Application usage statistics: up to 24 months.
- Server logs (IP addresses, access times): up to 24 months for security and troubleshooting.
- Face Data (Biometric Information): not retained at all. As described in Section 3.1.4, facial images and derived data are deleted automatically and immediately after each verification attempt and are never stored on the Device or on any server.
3.5 Transfer of Your Personal Data
Your information, including Personal Data, is processed at the Company's operating offices and in any other places where the parties involved in the processing are located, which may be outside Your jurisdiction. Where required by applicable law, We will ensure appropriate safeguards are applied to such transfers. Face Data is not subject to this section, as it is never transmitted off Your Device.
3.6 Delete Your Personal Data
You have the right to delete or request that We assist in deleting the Personal Data that We have collected about You. You may update, amend, or delete Your information by signing in to Your Account and visiting account settings, or by contacting Us. Please note We may need to retain certain information where we have a legal obligation to do so. Face Data requires no deletion request, as it is never stored.
4. Disclosure of Your Personal Data
Business Transactions
If the Company is involved in a merger, acquisition or asset sale, Your Personal Data may be transferred. We will provide notice before Your Personal Data becomes subject to a different Privacy Policy.
Law Enforcement
Under certain circumstances, the Company may be required to disclose Your Personal Data if required to do so by law or in response to valid requests by public authorities.
Other Legal Requirements
The Company may disclose Your Personal Data in the good faith belief that such action is necessary to comply with a legal obligation, protect the rights or property of the Company, prevent or investigate wrongdoing, protect personal safety, or protect against legal liability.
5. Security of Your Personal Data
The security of Your Personal Data is important to Us, but remember that no method of transmission over the Internet, or method of electronic storage, is 100% secure. While We strive to use commercially reasonable means to protect Your Personal Data, We cannot guarantee its absolute security.
6. Detailed Information on the Processing of Your Personal Data
6.1 Google Places
Google Places is a service that returns information about places using HTTP requests, operated by Google. It may collect information from You and Your Device for security purposes. Information gathered by Google Places is held in accordance with Google's Privacy Policy: https://www.google.com/intl/en/policies/privacy/.
6.2 On-Device Face Recognition Processing
The Application's attendance verification feature uses Your Device's own local, on-device machine learning capabilities to compare a live facial image with a reference previously registered by You for the sole purpose of confirming Your identity. No third-party face-recognition service, SDK, or cloud API is used for this purpose, and the Company does not operate or have access to any server-side facial recognition system. See Section 3.1.4 for full details.
7. Children's Privacy
The Application is intended for use by students, teachers, and staff of SMK Negeri 6 Semarang, some of whom may be under the age of 18. Where the Application processes Personal Data of a student who is a minor — including facial data used solely for on-device attendance verification, as described in Section 3.1.4 — such processing is carried out in the context of, and under the supervision of, the school as an educational institution, and no facial data is retained.
We do not knowingly collect personally identifiable information from anyone under the age of 16 outside of this educational context. If You are a parent or guardian and are aware that Your child has provided Us with Personal Data outside this context, please contact Us so that We can take appropriate action.
Biometric data such as facial images is treated as a specific category of personal data under Indonesia's Personal Data Protection Law (UU No. 27/2022), which is why the Application is designed so that this data is processed only on-device and is never stored or transmitted.
8. Links to Other Websites
Our Service may contain links to other websites that are not operated by Us. We strongly advise You to review the Privacy Policy of every site You visit. We have no control over and assume no responsibility for the content, privacy policies, or practices of any third-party sites or services.
9. Changes to this Privacy Policy
We may update Our Privacy Policy from time to time. We will notify You of any changes by posting the new Privacy Policy on this page, and, where the change is material, via email and/or a prominent notice on Our Service prior to the change becoming effective. The "Last updated" date at the top of this page will be revised accordingly.
10. Contact Us
If you have any questions about this Privacy Policy, You can contact Us:
By email: smkn6smg@yahoo.co.id, app.smg@nexa.net.id