Privacy Policy | KabarMeeting Apps

Privacy Policy

This policy explains how KabarMeeting processes, stores, protects, and manages information within the on-premise Evolusi Kilau Net deployment.

Effective Date: July 31, 2026 Last Updated: July 2026 Applies to: Admin and Member roles
Draft Notice

This is a working draft based on the current Product Requirements Document and Milestones. It is written to reflect the System’s actual technical behavior, including on-premise deployment, air-gap capability, and data retention settings. It should be reviewed and finalized by your organization’s Legal or Compliance team before publishing, particularly for alignment with Indonesia’s Personal Data Protection Law (UU No. 27/2022) or other applicable regulations in your jurisdiction.

1. Introduction

KabarMeeting (“the System,” “we,” “our”) is an internal enterprise application used by Evolusi Kilau Net (“the Company,” “the Organization”) to manage the full lifecycle of internal meetings scheduling, note-taking, audio transcription, AI-assisted summarization, action item tracking, and compliance export.

This Privacy Policy explains what information the System processes, how it is processed, where it is stored, and what rights you have as a user. This System is deployed on-premise, meaning it runs entirely on servers owned or controlled by the Company. KabarMeeting is not a public or multi-tenant SaaS product; this installation serves only Evolusi Kilau Net and its authorized personnel.

2. Who This Policy Covers

This policy applies to employees, contractors, and other authorized personnel of the Company who are granted a System account under one of two roles:

  • Admin — meeting organizers, secretaries, and system administrators who create meetings, manage users, and configure the System.
  • Member — team members and meeting participants who view meetings they are invited to and manage their own assigned action items.

3. Information We Process

Category Examples Source
Account information Name, email/username, password (hashed), role, department Provided during account creation by an Admin
Meeting content Meeting title, date, time, location/link, agenda, attendee and CC lists Entered by Admins
Meeting notes Manual notes, template-based notes, AI-generated summaries, edit history Entered or generated within the System
Audio recordings Uploaded or mobile-recorded audio of meetings, and their machine-generated transcripts Uploaded by Admins or captured via the mobile companion app
Attachments Documents, spreadsheets, images, and video files attached to meetings Uploaded by Admins
Action item data Task titles, descriptions, assignees (PIC), deadlines, status history Entered by Admins; status updated by assigned Members
Usage and security logs Login attempts, IP address, user-agent, activity/audit logs Automatically generated by the System
Mobile pairing data Temporary pairing tokens and scoped mobile session tokens Automatically generated when an Admin pairs the mobile app to a meeting

We do not collect information from individuals outside the Organization unless they are explicitly added as a meeting participant, attendee, or attachment content by an Admin.

4. How Information Is Processed

4.1 On-premise processing only

All core processing — including audio-to-text transcription and AI-generated meeting summaries — runs on the Company’s own infrastructure using locally hosted models. No meeting content is transmitted to any third-party or external cloud service. After initial software/model installation, the System is designed to operate with zero outbound internet traffic (air-gap capable).

4.2 Purpose of processing

Information is processed solely to:

  • Facilitate scheduling, documentation, and follow-up of internal meetings.
  • Generate searchable transcripts and AI-assisted summaries of meeting audio or notes.
  • Track and notify users about assigned action items and deadlines.
  • Produce compliance-ready exports (PDF/Word) for internal QA/ISO audit purposes.
  • Maintain security logs and an audit trail of system activity.
  • Enable a secure, single-use pairing between the mobile companion app and a specific meeting.

4.3 Automated processing

Certain features rely on automated processing:

  • Speech-to-text transcription of uploaded or recorded audio.
  • AI-generated meeting summaries and candidate action item suggestions, produced by a locally hosted language model. Admins review and confirm all AI-generated content before it becomes part of the official record — no AI output is finalized without human review.
  • Overdue detection for action items, based on assigned deadlines.

5. Data Storage, Security, and Retention

Aspect Detail
Storage location On the Company’s own server(s); no data is stored on external or third-party cloud infrastructure.
Encryption at rest Server storage volumes, including audio and the database, are encrypted at the operating-system level.
Encryption in transit All connections to the System are encrypted (TLS 1.2+).
Audio retention Audio recordings are retained for a configurable period, 30 days by default, after which they are automatically deleted. Transcripts and notes derived from audio are not affected by audio deletion.
Database backups Backed up daily and retained for 30 days on a separate, access-controlled volume.
Access control Role-based access control (RBAC) restricts visibility: Members can only see meetings where they are a participant or CC’d; Admins have organization-wide visibility for administrative purposes.
Authentication security Passwords are hashed (never stored in plain text); sessions use short-lived access tokens with automatic expiry and rotation.
Mobile pairing security QR pairing tokens are single-use and expire within 5 minutes; resulting mobile sessions are scoped strictly to one meeting’s capture functions and expire automatically after 2 hours.

6. Who Can Access Your Information

  • Admins of your organization’s instance can access all meetings, notes, audio, attachments, and action items for administrative, quality assurance, and compliance purposes.
  • Members can only access meetings they are invited to, as a participant or CC, and can only view or update the status of action items assigned to them.
  • System audit logs, including login history and activity logs, are accessible only to Admins and cannot be modified or deleted by any user, including Admins, once recorded.
  • No personnel outside the Company — including the software vendor/developer, unless under an explicit support agreement — have standing access to this instance’s data, as the System is self-hosted on the Company’s own infrastructure.

7. Your Rights

Subject to your organization’s internal policies and applicable law, you may generally:

  • Request access to the personal information the System holds about you, such as your account information, assigned action items, and activity history.
  • Request correction of inaccurate account information.
  • Request clarification on how your information is used, particularly regarding AI-generated summaries referencing you.

Requests should be directed to your organization’s designated System Administrator or Evolusi Kilau Net’s internal IT/Data Protection contact: [email protected] .

Important: Certain records — such as audit logs, login logs, and finalized meeting exports — are retained as immutable compliance records and cannot be deleted or altered by any user, including Admins, to preserve audit integrity.

8. Data Sharing

The System does not share, sell, or transmit meeting content or personal information to any external party, advertiser, or third-party service. The only outbound communication the System may perform is:

  • Internal email notifications, including meeting invitations, action item assignments, and deadline reminders, sent via the Company’s own internal SMTP relay, if configured. If no internal SMTP relay is configured, email notifications are simply not sent — no external email service is used as a substitute.

9. Children’s Privacy

KabarMeeting is an internal enterprise tool intended solely for use by employees, contractors, and authorized personnel of the Company. It is not directed at, and should not be used by, individuals under the age of 18.

10. Changes to This Policy

This Privacy Policy may be updated as the System’s features evolve, including new milestones such as export, notifications, and audit features. Material changes will be communicated to users through the in-app notification center or via internal announcement.

11. Contact

For questions about this Privacy Policy or how your information is handled within KabarMeeting, please contact:

Evolusi Kilau Net
[Data Protection Officer / IT Administrator]
Email: [email protected]

My Republic Plaza, Wing A, Zona 6
Green Office Park Jl. BSD Grand Boulevard
BSD City, Tangerang Selatan 15345
↑ Back to top