What we collect, which is very little.
This is a static marketing site. There are no forms, no accounts, and no tracking. Below is a plain description of what that means, and how we handle data during an actual engagement.
Last updated: 27 July 2026
What this website collects
Nothing that we ask you for. There is no contact form, no signup, no newsletter box, and no login. Every way of reaching us on this site is a link that opens your own email client.
Like any website, the server that delivers these pages writes standard request logs. Those typically include an IP address, the page requested, a timestamp, and the browser user agent. They exist so the host can serve pages, block abuse, and diagnose outages. We do not use them to build a profile of you, and we do not combine them with anything else.
No analytics, no advertising, no cookies
This site sets no cookies of its own. There is no analytics product measuring your visit, no advertising or retargeting pixel, no session recording, and no third-party script watching what you click. Nothing here follows you to another website.
If we ever add measurement, this page will say what it is and what it collects before it goes live.
Information you send by email
When you write to us, we receive whatever you chose to put in the message: your name, your email address, and the details of the problem you are describing. We use it to reply to you and to work out whether there is a fit. We do not add you to a mailing list, and we do not sell or share it for anyone else to market to you.
Your message is handled by our email provider in the ordinary way that email works. If your enquiry does not lead to an engagement, we keep the thread only as long as it is useful as a record of the conversation, and you can ask us to delete it.
Client data during an engagement
Building automation usually means touching systems that hold real information. How that access is handled is part of the work, not an afterthought. Our standing practice:
- Access is issued under least privilege. We ask for the narrowest scope that does the job, and nothing wider because it would be convenient.
- Credentials belong to you. Keys and connections are created in your accounts, so you can see them, rotate them, and revoke them without us.
- Secrets stay out of workflow bodies. Tokens live in a credential store, not pasted into a node, a URL, or a document.
- Access is listed at handoff and revoked when the work ends. If a managed care agreement continues, the remaining access is written down and kept to the minimum it needs.
- We work with real data only when the work requires it. Where a sample or a test record is enough, we use that instead.
Where a project needs a confidentiality or data processing agreement, that is signed separately and its terms govern the engagement.
How long things are kept
Server logs are kept for a short period by the host and then rotated out. Email threads are kept while the conversation or the project is live, and for a reasonable period afterwards as a record of what was agreed. Project material such as documentation, diagrams, and workflow definitions is handed to you at the end of the work. We keep our own copy only for as long as any ongoing agreement requires it.
Third parties involved
Two, in the running of this site: the provider that hosts and serves these pages, and the provider that carries our email. Both see the data described above in the course of doing that job. During a project, the third parties involved are the tools your system already uses, and those are named in the project documentation so there are no surprises.
Links from this site to other websites, including our own product at apiindonesia.id, lead to services with their own privacy notices. This one does not cover them.
Asking a question, or asking us to delete something
Write to hello@khaisa.studio and say what you want to know. If you have emailed us before and you want that correspondence deleted, ask and we will do it. You do not need to give a reason, and you will not get a form to fill in.
Changes to this page
If what we do changes, this page changes with it and the date at the top is updated. We will not quietly start collecting more than what is described here.