01Introduction
PT Sejuta Kawan Sehat ("Company", "we", "us", or "Sirka") is committed to protecting the privacy and security of the personal data of every user of the Sirka Application ("Application"). This Privacy and Data Protection Policy ("Policy") explains how we collect, use, store, share, and protect your personal data, as well as your rights with respect to that data.
This Policy has been prepared to comply with the licensing requirements of the Electronic Pharmaceutical System Provider (Penyelenggara Sistem Elektronik Farmasi / PSEF) as regulated by the Minister of Health of the Republic of Indonesia, the provisions of Law Number 27 of 2022 on Personal Data Protection (UU PDP), and the requirements of the Apple App Store and Google Play Store as distribution platforms for the Application.
By using the Sirka Application, you represent that you have read, understood, and agreed to this Policy. If you do not agree to this Policy, please do not use the Application.
02Definitions
In this Policy, the following terms shall have the meanings set out below:
| Term | Definition |
|---|---|
| Personal Data | Any information relating to an identified or identifiable natural person, directly or indirectly, through electronic or non-electronic systems. |
| Specific Personal Data | Personal data relating to health conditions, genetic data, biometric data, financial data, children's data, and other data as regulated under UU PDP. This includes all health data and medical profiles collected through the Application. |
| Processing of Personal Data | Any activity carried out on personal data, including collection, acquisition, processing, analysis, storage, correction, display, disclosure, transmission, dissemination, and deletion. |
| Personal Data Controller | PT Sejuta Kawan Sehat, as the party that determines the purposes and means of processing users' personal data. |
| Personal Data Processor | A third party that processes personal data on behalf of the Controller, pursuant to binding instructions and agreements. |
| User | An individual who uses the Sirka Application. |
| Application | The Sirka mobile application available on the Apple App Store and Google Play Store. |
| PSEF | Electronic Pharmaceutical System Provider (Penyelenggara Sistem Elektronik Farmasi) as defined under the applicable regulations of the Ministry of Health of the Republic of Indonesia. |
| Partner Pharmacy | A pharmacy that has registered and entered into a cooperation agreement with Sirka for the purpose of providing electronic pharmaceutical services. |
03Identity of the Data Controller
- Company Name
- PT Sejuta Kawan Sehat
- Application Name
- Sirka
- Registered Office
- Jl. Panglima Polim V No. 52, RT 1/RW 5, Melawai, Kebayoran Baru, South Jakarta 12160, Special Capital Region of Jakarta, Indonesia.
- Privacy Email
- tech@team.sirka.io
- Phone Number
- +62 851-7688-3358
- Data Protection Contact (DPO)
- +62 851-7688-3358
04Data We Collect
We collect the following data only to the extent necessary to deliver Sirka's services:
4.1 Account Identity Data
- Full name, phone number, and email address.
- User identification number and account status.
- Account metadata migrated from previous systems.
4.2 Authentication and Security Data
- PIN hash (never stored in plaintext).
- Failed PIN attempt records and account lockout status.
- Trusted device/session tokens and account recovery metadata.
4.3 Onboarding and Health Profile Data
The data below constitutes Specific Personal Data and is only processed on the basis of your explicit consent:
- Age or date of birth, and sex.
- Current height, weight, and weight goal.
- Program type, allergies, dietary preferences, and medical conditions where provided by the user.
4.4 Consultation and Prescription Data
- Consultation messages, timestamps, consultation type, and read status.
- Sender type and consultant attribution snapshots.
- Electronic prescriptions uploaded by the user and prescription documentation from Partner Pharmacies.
- Prescription verification logs and pharmacist–patient communications.
4.5 Consultation Attachments
- Files in JPEG, PNG, and PDF formats, along with file metadata.
- Attachment links and link access logs.
4.6 Pharmaceutical and Transaction Data
- Pharmaceutical products, health commodities (BHMP), and health supplements ordered or looked up.
- Barcode codes, product names, marketing authorization numbers, and composition information.
- Purchase quantities, transaction dates, and selected Partner Pharmacy.
- Medicine delivery data, including electronic proof of handover and receipt confirmation.
4.7 Meal Log and Food Analysis Data
- Food prompt text, food items, portions, calories, and macronutrients.
- Meal time slot, data source type, and optional meal photo.
- Nutrition analysis output generated by third-party services.
4.8 Weight Log Data
- Weight entries, BMI, and trend history.
4.9 Health Activity Data
The data below is collected solely on the basis of your explicit consent and is limited to whitelisted events:
- Metrics from Apple Health or Health Connect as authorized by the user.
- Event leaderboard snapshots and applicable event data.
4.10 Notification Data
- Push notification tokens, notification preferences, and delivery/open event logs.
4.11 Technical and Audit Logs
- Login events, sync logs, API errors, and attachment link access logs.
- Application diagnostics and crash data.
4.12 Cookies and Tracking Technologies
When you access Sirka's services through a browser or web view within the Application, we may use cookies and similar tracking technologies to:
- maintain your active login session;
- remember your preferences;
- analyze service usage for product improvement.
You may manage your cookie preferences through your browser or device settings. However, disabling certain cookies may affect the functionality of the Application.
05Legal Basis for Processing
In accordance with UU PDP, every processing of your personal data is based on one of the following legal grounds:
| Legal Basis | Data Categories | Explanation |
|---|---|---|
| Consent | Health profile data, Apple Health / Health Connect activity data, optional analytics | You provide consent during onboarding or when activating a feature. You may withdraw consent at any time. |
| Explicit Consent | Specific Personal Data: health conditions, medical data | Separate explicit consent is required under Article 26 of UU PDP for processing health and other sensitive data. |
| Performance of a Contract | Account identity data, consultation data, transaction data, prescription data | Processing is necessary to deliver the services you have requested under Sirka's Terms and Conditions. |
| Legal Obligation | Pharmaceutical transaction data, audit logs, prescription data | Processing is required by PSEF regulations of the Ministry of Health, UU PDP, and other applicable laws. |
| Legitimate Interests | Security logs, technical logs, fraud prevention data | Processing is necessary for system security and user protection, to the extent that it does not override your rights and freedoms. |
06Purposes of Collection and Use
We collect and use your personal data solely for the following purposes:
- account creation, authentication, and account recovery;
- onboarding and personalization of your Sirka health program;
- health consultations with Sirka's health support team;
- electronic prescription services, including prescription verification, submission to Partner Pharmacies, and medicine delivery;
- self-medication services in accordance with applicable drug classification regulations;
- meal logging, nutrition estimation, and meal history;
- pharmaceutical product and health supplement barcode lookup;
- weight tracking and progress visualization;
- Apple Health / Health Connect activity synchronization for whitelisted Event leaderboards;
- automated reporting of product transaction data to the Ministry of Health of the Republic of Indonesia as required under PSEF regulations;
- system security, fraud prevention, audit, debugging, and legal compliance;
- customer support and operational troubleshooting.
07Patient Data Confidentiality
As an Electronic Pharmaceutical System Provider (PSEF), we implement patient data confidentiality protections in accordance with the standards of the Ministry of Health and the Digital Health Transformation Directorate (DTO), including:
- encryption of sensitive patient data, including prescription data and consultation history, using applicable encryption standards;
- access to patient data is restricted on a role-based access control basis, limited to authorized healthcare personnel and staff;
- all access to patient data is recorded in traceable audit logs;
- prescription and consultation data is not shared with any third party other than the Partner Pharmacy directly involved in the relevant prescription service;
- our system ensures that prescriptions may only be used once or in accordance with the notes on the prescription, in order to prevent misuse of medication.
08Data Retention and Traceability
In accordance with PSEF requirements, we ensure the traceability of documents and transaction data for a minimum period of 5 (five) years. The full retention schedule is as follows:
| Data Category | Retention Period | Deletion / Anonymization Rule |
|---|---|---|
| Account identity data | While account is active + legally required period | Deleted or anonymized after account deletion, unless legally required |
| PIN hash and active sessions | While account is active | Deleted on logout, account deletion, or security reset |
| Failed PIN attempt logs | 90–180 days | Deleted unless required for investigation |
| Account recovery / support logs | 2–5 years | Retained longer only for disputes, fraud, or legal requirements |
| Onboarding health profile | While account is active | Deleted or anonymized after account deletion |
| Electronic prescription and prescription documentation | Minimum 5 years (PSEF mandatory) | Retained for PSEF audit traceability; anonymized after mandatory retention period expires |
| Pharmaceutical and medicine transaction data | Minimum 5 years (PSEF mandatory) | Reported to Ministry of Health every 24 hours; archived for audit purposes |
| Consultation messages and attachments | While account is active + operational retention period | Deleted or anonymized after account deletion |
| Attachment link access logs | 90–365 days | Retained longer only for security investigations |
| Meal logs and nutrition history | While account is active | Deleted or anonymized after account deletion |
| AI meal analysis request payloads | Not retained beyond processing | Only operational logs retained where required |
| Weight logs and BMI | While account is active | Deleted or anonymized after account deletion |
| Health activity metric snapshots | While account is active and/or event retention window | Deleted or anonymized upon request unless restricted by regulation |
| Push notification tokens | While app session / account is active | Deleted on logout, token invalidation, or account deletion |
| Cookies and analytics data | 12–24 months if user-linked | Anonymized and aggregated |
| Security and audit logs | 1–5 years | Personal data in logs is minimized |
| Backup data | Rolling 90–180 days | Deleted data may persist until backup rotation expires |
10Cross-Border Data Transfers
In the course of providing our services, your personal data may be transferred to, or processed at, servers or facilities located outside the territory of the Republic of Indonesia, including but not limited to countries where our third-party service providers operate.
We ensure that every cross-border data transfer is carried out with adequate safeguards, including:
- ensuring that the destination country provides a level of data protection that is equivalent or adequate;
- binding overseas third-party service providers with a Data Processing Agreement (DPA) incorporating protection clauses equivalent to those under UU PDP;
- applying appropriate technical and organizational security measures throughout the transfer process.
By using the Application, you consent to the transfer of data as described in this Policy. If you have questions regarding cross-border data transfers, please contact us at tech@team.sirka.io.
11Opt-Out and Tracking Controls
11.1 Analytics and Cookies
You may opt out of analytics data collection by:
- adjusting tracking preferences through Settings > Privacy in the Application (where available);
- enabling "Limit Ad Tracking" or "Opt Out of Ads Personalization" in your device settings;
- disabling cookies through your browser settings when accessing services via the web.
11.2 Apple Health and Health Connect
You may revoke the Application's access to Apple Health or Health Connect at any time through your device settings. Following revocation, previously stored activity data may still be deleted upon your request by contacting tech@team.sirka.io.
11.3 Push Notifications
You may disable push notifications at any time through your device settings or through the notification preference menu in the Application.
12Pharmaceutical Product Safety and Quality Controls
As a PSEF, Sirka implements risk control measures to ensure the safety, efficacy, and quality of pharmaceutical products, health commodities (BHMP), and health supplements available on the platform, including:
- all products available on the platform must hold a marketing authorization number issued by the competent authority;
- narcotics, psychotropics, injectable preparations, and contraceptive implants are not available for sale on the Sirka platform;
- insulin preparations for personal use may be sold in accordance with applicable regulations;
- the purchase of over-the-counter restricted medicines and prescription-only medicines may only be made through the electronic prescription mechanism verified by a Partner Pharmacy pharmacist;
- our delivery system is designed to maintain product quality and safety, with electronic proof-of-handover documentation and recipient confirmation by the patient.
13Transaction Data Reporting to the Ministry of Health
In compliance with PSEF obligations, Sirka's system provides pharmaceutical product and health supplement transaction data transmitted automatically every 24 hours to the Ministry of Health of the Republic of Indonesia. The reported data covers transaction information required by regulation and does not include patients' personal data beyond what is necessary for national pharmaceutical oversight purposes.
14Your Rights
In accordance with UU PDP and applicable law, you have the following rights with respect to your personal data:
| Right | Description |
|---|---|
| Right of Access | Request a copy of the personal data held by Sirka. |
| Right to Rectification | Correct inaccurate profile or account information. |
| Right to Erasure | Request deletion of eligible personal data. |
| Right to Account Closure | Request deletion of your account and associated data. |
| Right to Health Data Deletion | Request deletion of previously synced Health Activity data. |
| Right to Disconnect Health Source | Disconnect Apple Health or Health Connect. |
| Right to Withdraw Consent | Withdraw consent for features that rely on consent, without affecting the lawfulness of processing prior to withdrawal. |
| Right to Restriction of Processing | Request restriction of processing under certain conditions as provided under UU PDP. |
| Right to Data Portability | Request export of your data in a machine-readable format where the feature is available. |
| Right to Object | Object to processing based on legitimate interests. |
| Right to Lodge a Complaint | Contact Sirka regarding privacy concerns at tech@team.sirka.io. |
We will respond to privacy requests within the period required by applicable law. If additional time is needed due to technical, legal, or security reasons, we will notify you in advance.
15Data Security
We implement reasonable technical and organizational measures to protect your personal data against unauthorized access, disclosure, alteration, or destruction, including:
- encryption of data at rest and in transit;
- role-based access control;
- multi-factor authentication for access to internal systems;
- regular access log monitoring and auditing;
- periodic security risk assessments and penetration testing.
In the event of a personal data breach affecting your personal data, we will notify you and the competent authority in accordance with the timelines set out under UU PDP. Notwithstanding the above, no security system is completely impenetrable. We strongly encourage you to keep your PIN and account credentials confidential.
16Children's Data
The Sirka Application is not intended for users under the age of 18 (eighteen) years. We do not knowingly collect personal data from children. If you become aware that a minor has provided us with personal data without the consent of a parent or lawful guardian, please contact us at tech@team.sirka.io so that we may promptly take the necessary action, including deletion of such data.
17Changes to This Policy
We may update this Policy from time to time to reflect changes in our privacy practices, regulatory updates, or the addition of new features. Material changes will be communicated to you via a notification in the Application or by email at least 14 (fourteen) days before the change takes effect. Your continued use of the Application after the effective date of the changes constitutes your acceptance of the updated Policy.
18Governing Law and Dispute Resolution
This Policy is governed by the laws of the Republic of Indonesia, including but not limited to Law Number 27 of 2022 on Personal Data Protection, the Ministerial Regulations governing PSEF, and other applicable laws and regulations.
In the event of a dispute arising from or in connection with this Policy, the parties shall seek to resolve it amicably. If no resolution is reached, the dispute shall be settled in accordance with the dispute resolution mechanisms provided under applicable Indonesian law.
19Contact Us
If you have any questions, requests, or concerns regarding this Policy or the processing of your personal data, please contact:
- Team
- Legal & Compliance Team, PT Sejuta Kawan Sehat
- Privacy Email
- contact@sirka.co.id · tech@team.sirka.io
- Address
- Jl. Panglima Polim V No. 52, RT 1/RW 5, Melawai, Kebayoran Baru, South Jakarta 12160, Special Capital Region of Jakarta, Indonesia.
- Phone
- +62 851-7688-3358
- Operating Hours
- Monday – Friday, 09:00 – 17:00 WIB