← Back to sign in

Privacy Policy / Kebijakan Privasi

Version 2026-04-29 · Effective 29 April 2026

What this is / Apa ini

erudioflow is the learning-tracking platform used by Erudio Indonesia. This page explains what data we collect, why, who can see it, and the rights you have over it.

erudioflow adalah platform pelacakan pembelajaran yang digunakan Erudio Indonesia. Halaman ini menjelaskan data apa yang kami kumpulkan, mengapa, siapa yang dapat melihatnya, dan hak apa yang Anda miliki atas data tersebut.

What we collect

  • Identity: name, email (@erudioindonesia.sch.id), role (student / coach / admin), avatar initials.
  • Academic profile (students only): level (SMP / SMA), batch year, current cycle stage, focus area.
  • Learning content (students only): your goals, challenges, reflections, portfolio items, skill self-assessments, competency progress, resources you map out.
  • Coaching data (coaches only): notes you write about students, session logs, your skill assessments of students.
  • Technical data: IP address and browser type, captured only in the audit log when administrative actions occur.

We do not collect: home address, phone numbers, family/parent contact info, payment info, biometric data, or any tracking from third-party analytics.

Why we collect it (purpose limitation)

  • To run the school's self-directed learning programme.
  • To let coaches give meaningful feedback and track student progress.
  • To document evidence for Paket B/C, BTEC, IELTS, TOEFL, BNSP and other certifications students choose to pursue.
  • To produce school-level statistics (counts, distributions only — never individual student names) for educational planning.

We do not use your data for advertising, sell it to third parties, or share it with anyone outside Erudio Indonesia.

AI features (enabled by default — you can opt out)

The platform offers AI-assisted periodic progress reports for parents, powered by OpenAI's ChatGPT API. By Erudio Indonesia's policy, this is enabled by default for all students. You can disable it for your own account at any time from your profile (/me → AI features). When enabled:

  • Your coach can click “Draft report” for a chosen period. Your reflections, completed challenges, portfolio additions, skill changes, and coach session notes for that period are bundled and sent to OpenAI.
  • Before sending, names, email addresses, and phone-like patterns are redacted to [NAME], [EMAIL], [PHONE].
  • Your coach reviews and edits the AI draft before it is sent to anyone. Drafts are not sent automatically.
  • OpenAI's paid commercial API does not retain content for training (per their data-usage policy at platform.openai.com/docs).
  • Every AI generation and every parent email is recorded in the audit log so you can ask for a list of which periods have touched the model.
  • If you disable AI features, your coach's “Draft report” action will refuse to run for you — they will need to write any reports manually.

Who sees your data

  • Students: see only their own data.
  • Coaches: see data of students assigned to them (and their coaching family). They cannot see other coaches' students.
  • Admins: see school-wide statistics and can manage users, families, and curriculum. When admins use “View as” to inspect a student or coach's view, every page shows a banner naming who they're viewing as, and the action is recorded in the audit log.

How long we keep it (retention)

  • Active students: data is kept while you are enrolled.
  • Alumni / graduated students: data is kept for 3 years after graduation, then automatically deleted unless you explicitly request to keep your portfolio longer for university applications.
  • Audit logs: kept for 7 years for compliance and child-protection traceability.

Your rights (GDPR Articles 15–22 / UU PDP 27/2022)

You have the right to:

  • Accessall your data — use the “Download my data” button on your profile.
  • Rectifydata you can edit yourself; for fields you can't edit (name, email, level), use “Request a correction”.
  • Eraseyour account and all associated data — use the “Delete my account” button. For students under 18, this requires confirmation from your school admin and parent.
  • Port your data to another platform — the export is a stable JSON format.
  • Object to specific processing (e.g. AI features) — toggle the relevant settings in your profile.
  • Withdraw consent at any time — sign out and request account deletion.

Security

  • All connections are encrypted in transit (HTTPS / TLS 1.2+).
  • Sessions are HMAC-signed cookies; we never see or store your Google password.
  • Database access is restricted to the school's servers and is encrypted at rest.
  • Every administrative action (creating accounts, graduating, impersonation, exports, deletions) is logged with actor + IP + timestamp.

Contact / Kontak

Questions, corrections, or data requests: imron.zuhri@erudioindonesia.sch.id

Erudio Indonesia's designated Data Protection contact is the school admin (Imron Zuhri). For complaints you cannot resolve with the school, you may contact the Indonesian data-protection authority (Kementerian Komunikasi dan Informatika).

Changes to this policy

When we update this policy materially, we'll bump the version number and ask all users to review and accept the new version on next sign-in. Your continued use of the platform after re-consenting means you accept the changes.

← Back to sign in