This policy explains how Bali Mitra Bangun Bersama, as the service operator trading under the Bali Project Partner brand, obtains, uses, stores, shares, protects, corrects and deletes personal data in connection with the website, consultation, CRM, project administration, quality control, due diligence, property search, tendering, workforce and related services.
This policy applies to the production features currently available. A new feature that changes processing purposes, recipients, storage locations or user risk must be assessed and described before activation. This policy does not claim a particular legal certification or endorsement.
1. Operator, controller and contact
The operator and controller is Bali Mitra Bangun Bersama, trading under the Bali Project Partner brand, with an operational base in Bali, Indonesia. Privacy requests may be sent to halo@baliprojectpartner.com. Proportionate identity verification may be required.
2. Data we may process
- Identity and contact details.
- Partner registration data including expertise, service areas, experience, capacity, availability, professional biography, portfolio, certificates, identity and supporting evidence submitted for review.
- Work-request data including private contact details, category, area, scope, target timing, initial budget range and internal shortlist records.
- Project, proposal, contract, invoice, payment, communication and approval records.
- Site reports, schedules, drawings, photos, videos, inspections, defects and evidence.
- Lawfully obtained due-diligence documents, references, portfolio evidence, public-source notes and professional assessments.
- Technical and security data such as timestamps, hashed IP data, user-agent, authentication history, audit logs, session cookies and file metadata.
3. Sources
Data may come from you; your organisation or representatives; contractors, foremen, vendors, references, agents, property owners or project parties; lawfully accessed public material; and use of the system. We do not support hacking, interception, leaked datasets or unauthorised account access.
4. Purposes and processing grounds
- Responding to enquiries and taking pre-contract steps.
- Performing contracts and project, inspection, payment and handover services.
- Following consent or instructions you provide.
- Meeting legal, tax, accounting, safety, audit and dispute obligations.
- Protecting systems, preventing abuse and preserving proportionate business evidence.
5. Recipients and processors
Data may be shared on a need-to-know basis with authorised staff; hosting, email, backup, security, storage, accounting, payment or technology providers; professional advisers; relevant project parties; and lawful authorities. We do not sell personal data.
6. Cross-border processing
Technology providers may process data outside Bali or Indonesia. Before production use, the company should document provider locations, safeguards, contracts and applicable transfer mechanisms.
7. Retention
| Category | Initial retention guideline |
|---|---|
| Unconverted enquiries | Up to 24 months after the last interaction, subject to deletion requests and dispute needs. |
| Partner registrations and profiles | During review and the partner relationship. Rejected or abandoned registrations must be reviewed for deletion under the company retention schedule. |
| Work requests and shortlists | During review and any related offer or assignment, followed by applicable contract, dispute, audit and company-retention needs. |
| Website interaction analytics | Up to 30 days. Records are limited to the interaction type, page, time and a hashed daily visitor identifier. |
| Client, transaction and finance records | For the contract period and applicable legal, tax, accounting, audit or claim periods. |
| Project, QC, evidence and handover records | According to contract, warranty/retention, proof and project-archive requirements. |
| Due diligence and reference checks | Until report expiry plus a limited audit/dispute period, followed by review or deletion. |
| Security logs and sessions | As needed for security and audit; sessions are revoked or removed when expired. |
8. Your rights
Subject to applicable law, you may request information and access; correction; restriction, cessation, deletion or destruction; withdrawal of consent where consent is relied upon; a copy or portability where applicable; and raise an objection or complaint. Lawful retention, security, evidence and third-party rights may limit a request.
9. Request procedure
- Send a request to the company contact and identify the data and action requested, or use the account/data deletion form.
- We verify identity, authority and scope proportionately.
- We log and assess the request, applicable exceptions and required clarification.
- Approved changes are applied to active systems. Encrypted backups may remain until normal expiry and are not reintroduced except through a lawful recovery process.
10. Security
Controls may include HTTPS, role-based access, 2FA, audit logs, encrypted secrets and backups, file validation, checksums, rate limiting and portal separation. No system is risk-free, and hosting plus internal access must be reviewed regularly.
11. Cookies, analytics and operational notifications
Session cookies may be used for forms, login and portals. To measure service functionality, the system may record bounded interactions such as page visits, navigation or contact clicks, downloads, directory searches, and form starts or submissions. These records do not include form-field values, message content, passwords, authentication tokens, email addresses, telephone numbers or full addresses. IP addresses and user-agent strings are not retained in these analytics records; a hashed daily visitor identifier is used and records are deleted after no more than 30 days.
Operational summaries and unique-visit alerts, including crawler categories inferred from user-agent data, may be forwarded to an administrator-controlled Telegram bot. Alerts are time-windowed, contain neither raw IP addresses nor raw user-agent strings, and do not prove bot identity. Other notification payloads for leads, orders, payments, security and system health are filtered to the metadata required for follow-up; sensitive records remain available only through the protected Admin portal. Non-essential or marketing technologies require an appropriate notice or consent mechanism before activation.
12. Children and third-party data
The services are intended for owners, investors, companies and project professionals, not children. When providing another person's data, you must have authority and give any required notice.
13. Incidents and complaints
Suspected loss, unauthorised access or disclosure should be reported promptly. We will triage, secure systems, preserve evidence, assess impact, recover and meet applicable notification duties. Unresolved complaints may be escalated through the competent mechanism or authority.
14. Changes
Material changes receive a new effective date and, where appropriate, notice through the website or direct communication. Dates are not refreshed merely to create an appearance of freshness.
