Privacy Policy
- Effective date: July 31, 2026
- Last updated: July 31, 2026
This Privacy Policy explains how PT. United Teknologi Integrasi ("Provider," "we," "us") collects, uses, stores, discloses, and protects personal data when you use Spensify.
This Policy has been prepared with reference to Indonesian Law No. 27 of 2022 on Personal Data Protection ("PDP Law") and other applicable requirements. It should be read together with the User Agreement and Terms and Conditions.
1. Who is responsible for your data
Spensify is used through a workspace owned by a company or other organization ("Organization"). Responsibility for personal data depends on the processing context:
- The Organization generally acts as the Personal Data Controller for employee, expense, Approval, Budget, payout, and other business data entered into its workspace. The Organization determines why that data is used.
- The Provider generally acts as a Personal Data Processor when it processes workspace data on the Organization's instructions.
- The Provider may act as a separate Personal Data Controller for account and service administration, platform security, abuse prevention, legal compliance, and direct communications with you.
If you use Spensify through an Organization, that Organization's privacy notice and internal policies may also apply. For requests concerning data within a workspace, you may first contact the Organization's administrator or privacy contact.
2. Personal data we process
The data processed depends on the features used and the Organization's configuration.
a. Account and profile data
- name, email address, username, profile image, and internal user identifiers;
- hashed password, email-verification status, and account recovery or change information;
- Google identifier and basic profile information if you choose to sign in or link an account through Google; and
- language, theme, color accent, and interface preferences.
b. Organization and employment data
- company, team, position or role, access rights, manager or approver, and membership status;
- company contact information, address, tax number, currency, and policy configuration; and
- relationships among users, teams, Approvals, Budgets, and organizational units.
c. Expense and document data
- transaction date, vendor, vendor address, description, category, payment method, currency, amount, tax, and line items;
- receipts, invoices, payment evidence, attachments, OCR extraction results, document hashes or fingerprints, and possible-duplicate indicators;
- notes, reasons, comments, statuses, change history, and Approval decisions; and
- data in reports, exports, or other documents generated through the service.
Receipts or documents may contain another person's personal data. You and the Organization must ensure that this data is relevant and can be processed lawfully.
d. Financial and Disbursement data
- account holder name, bank name and code, encrypted account number, last four digits of the account number, currency, and verification status;
- reimbursement or payment amounts, Disbursement instructions and batches, statuses, references, evidence, and payment-attempt history; and
- Budget information, allocations, adjustments, and reconciliation records.
Personal financial data may be classified as specific personal data under applicable law. Spensify does not store your online banking password, PIN, or credentials.
e. Technical, device, and security data
- IP address, user agent, browser type, operating system, device name or type, access time, session status, and session identifiers;
- authentication, security, language, theme, and interface-state cookies;
- device identifiers and push-notification tokens if device notifications are enabled;
- preferences, drafts, table filters, and display settings stored in the browser; and
- audit trails, account activity, application logs, error information, and security metadata.
f. Communications and preferences
- notification preferences, in-app messages, service emails, push notifications, delivery status, and read time; and
- the contents of questions, security reports, privacy requests, or support communications you submit.
Please do not enter unnecessary personal data—including health, biometric, criminal, children's, or other sensitive data—into free-text fields or attachments unless it is necessary and permitted by the Organization and applicable law.
3. Sources of data
We obtain data:
- directly from you when you create or update an account, upload a document, complete a form, or communicate with us;
- from the Organization when an administrator invites you, assigns a role, configures a team, or imports business data;
- automatically from your device and use of the service;
- from an authentication provider, such as Google, if you choose that feature; and
- from service providers that process documents, deliver notifications, or support a requested feature.
4. Purposes and legal bases
We process personal data only when there is a lawful basis. Depending on the role and context, that basis may be consent, performance of an agreement, compliance with a legal obligation, protection of vital interests, performance of a task in the public interest, or another legitimate interest that is balanced against your rights.
| Purpose | Example data | Legal basis generally used |
|---|---|---|
| Create accounts, authenticate users, and provide the service | Account, session, role, and workspace data | Performance of an agreement or steps taken at your request |
| Manage expenses, Approvals, Budgets, reports, and Disbursements | Transaction data, documents, decisions, and payout accounts | Performance of an agreement; lawful Organization instructions |
| Operate Smart Scan, OCR extraction, duplicate detection, and categorization | Receipts, transaction data, fingerprints, and categories | Performance of an agreement or legitimate interest in providing requested functions |
| Deliver notifications and service communications | Email, device token, preferences, and delivery status | Performance of an agreement, legitimate interest, or consent where required |
| Maintain security and prevent misuse | IP, device, session, audit trail, and log data | Legitimate interest; legal obligation |
| Support users and handle requests | Account data and communication content | Performance of an agreement or legitimate interest |
| Meet legal obligations and enforce rights | Transaction, audit, and communication records | Legal obligation or legitimate interest |
| Maintain and improve service reliability | Limited usage, performance, and error data | Legitimate interest, subject to data minimization |
Where processing is based on consent, you may withdraw that consent. Withdrawal does not affect processing already performed lawfully and may make an optional feature unavailable.
We do not sell personal data. We also do not use workspace data for behavioral advertising.
5. Smart Scan and automated processing
Spensify may use OCR, language models, or automated rules to:
- read information from receipts and documents;
- suggest a currency or category;
- create fingerprints and flag possible duplicate documents; and
- help organize or validate expense data.
Automated results may be inaccurate or incomplete. They are assistive outputs and must be reviewed by a user or other authorized person. Spensify is not intended to make a solely automated decision that independently produces legal or similarly significant effects for you. The Organization remains responsible for Approval, reimbursement, Budget, and payment decisions.
6. Cookies and browser storage
We use necessary or functional cookies and browser-storage technologies to:
- maintain login sessions and secure authentication flows;
- save language, theme, color, and sidebar choices;
- remember an email address only if you select that option;
- preserve drafts, filters, dashboard layouts, and table preferences; and
- manage device identifiers and push-notification prompts.
Authentication cookies are necessary for the service to operate. You can clear preference cookies and data in localStorage or sessionStorage through your browser settings, but doing so may remove preferences or locally saved drafts.
7. Disclosure of data
We may disclose limited personal data to:
- the Organization, workspace administrators, approvers, team members, auditors, or others according to their roles and access rights;
- cloud hosting, database, file-storage, and backup providers;
- OCR and document-processing providers;
- language-model providers if AI-assisted categorization or data-resolution features are enabled;
- authentication, email, push-notification, and communications providers;
- exchange-rate data providers or other technical services, to the extent personal data is required;
- professional advisers, auditors, insurers, or parties to a corporate transaction subject to confidentiality obligations; and
- regulators, courts, or authorities where required by law or necessary to protect rights and safety.
Service providers may process data only under applicable instructions and contractual obligations. Providers may differ by deployment configuration and region. You may request the applicable provider list through the contact in Section 15.
8. Cross-border data transfers
Some service providers may process data outside Indonesia. If a cross-border transfer occurs, we or the Organization, as applicable, will implement PDP Law requirements, including ensuring an equivalent or higher level of protection, adequate and binding safeguards, obtaining consent where required, or using another lawful mechanism.
You may request information about the applicable destination countries and transfer mechanisms through the contact in Section 15.
9. Retention and deletion
We retain data only for as long as necessary for the described purposes, the Organization's instructions, contract administration, dispute resolution, security, and legal compliance.
Before this Policy is published, the following periods must be completed according to an approved retention schedule:
| Data type | Retention period |
|---|---|
| Account, profile, and membership data | While the account or service relationship is active and for [ACCOUNT RETENTION PERIOD] afterward |
| Expense, Approval, Budget, Disbursement, and business documents | As instructed by the Organization and required by law, for at least or no longer than [BUSINESS RECORD RETENTION PERIOD], as applicable |
| Sessions, audit trails, security logs, and technical logs | [SECURITY LOG RETENTION PERIOD] from creation unless needed longer for an investigation |
| Extractions, temporary uploads, and failed or canceled jobs | [TEMPORARY FILE RETENTION PERIOD] after processing ends |
| Support and privacy requests and consent records | [COMMUNICATION RETENTION PERIOD] after the request closes or consent ends |
| Backups | Deleted or overwritten within [BACKUP DELETION CYCLE] after removal from active systems |
Data may be retained longer where required by law, involved in a dispute or investigation, or needed to establish, exercise, or defend legal claims. When the applicable period ends, data will be deleted, destroyed, anonymized, or returned according to our role and lawful instructions.
10. Security
We use technical and organizational measures that are reasonable and proportionate to risk, including role-based access controls, workspace separation, password hashing, encryption of certain bank-account information, session controls, audit trails, backups, and security monitoring.
No system is completely secure. You must protect your credentials, use secure devices, review active sessions, and promptly report suspected unauthorized access.
If a personal-data protection failure occurs, we will assess, contain, document, and notify the parties required by law within the applicable time and with the required information.
11. Your rights
Subject to applicable law and lawful exceptions, you may request:
- information about the identity and accountability of the party processing data and the basis, purpose, and use of the data;
- access to and a copy of personal data and available processing records;
- updating or correction of inaccurate data;
- cessation of processing, deletion, or destruction;
- withdrawal of consent;
- objection to a decision based solely on automated processing that produces legal or similarly significant effects;
- proportionate restriction of processing;
- data portability in a commonly used and structured format where applicable; and
- submission of a complaint or claim for damages under applicable law.
We may request reasonable information to verify your identity and authority. If the Provider processes data only on the Organization's instructions, we may refer the request to the Organization or ask you to contact it. A request may be refused or limited where permitted or required by law, with an appropriate explanation.
To exercise a right, contact sales@spensify.ai.
12. Organization accounts and administrator access
Administrators and authorized personnel within the Organization may access, correct, export, restrict, or delete workspace data; change roles; and terminate your access. The Organization is responsible for ensuring that these actions have a lawful basis and are consistent with notices provided to you.
If you leave the Organization, business data created within its workspace may remain under the Organization's control and be retained according to its retention policies and legal obligations.
13. Children
Spensify is intended for users in a business context and is not directed to children. Users must have legal capacity or the required authority to use the service. Do not enter children's data unless it is strictly necessary, has a lawful processing basis, and meets applicable consent requirements.
14. Changes to this Policy
We may update this Privacy Policy to reflect changes to the service, practices, providers, or law. The updated date will appear at the top. We will communicate material changes through the application, email, or another reasonable method. If new consent is legally required, we will request it before continuing the relevant processing.
15. Contact
Questions, complaints, security reports, or privacy-rights requests may be sent to:
PT. United Teknologi IntegrasiJl. Siantar No.18, Cideng, Gambir Jakarta Pusat, Jakarta
sales@spensify.ai
If your request concerns data in an Organization's workspace, include the Organization's name so the request can be routed correctly.