This policy explains how PT Bali Mitra Bangun Bersama, through the Bali Project Partner brand, obtains, uses, stores, shares, protects, corrects and deletes personal data in connection with the website, consultation, CRM, project administration, quality control, due diligence, property search, tendering, workforce and related services.
This is an operational template prepared around relevant data-protection principles, including Indonesia's Law No. 27 of 2022 on Personal Data Protection. The processing grounds, retention periods, vendor relationships and rights procedures must still be reviewed by Indonesian legal counsel before adoption as the company's final policy.
1. Controller and contact
The controller is PT Bali Mitra Bangun Bersama. Privacy requests may be sent to contact@baliprojectpartner.com. Proportionate identity verification may be required.
2. Data we may process
- Identity and contact details.
- Partner registration data including expertise, service areas, experience, capacity, availability, professional biography, portfolio, certificates, identity and supporting evidence submitted for review.
- Project, proposal, contract, invoice, payment, communication and approval records.
- Site reports, schedules, drawings, photos, videos, inspections, defects and evidence.
- Lawfully obtained due-diligence documents, references, portfolio evidence, public-source notes and professional assessments.
- Technical and security data such as timestamps, hashed IP data, user-agent, authentication history, audit logs, session cookies and file metadata.
3. Sources
Data may come from you; your organisation or representatives; contractors, foremen, vendors, references, agents, property owners or project parties; lawfully accessed public material; and use of the system. We do not support hacking, interception, leaked datasets or unauthorised account access.
4. Purposes and processing grounds
- Responding to enquiries and taking pre-contract steps.
- Performing contracts and project, inspection, payment and handover services.
- Following consent or instructions you provide.
- Meeting legal, tax, accounting, safety, audit and dispute obligations.
- Protecting systems, preventing abuse and preserving proportionate business evidence.
5. Recipients and processors
Data may be shared on a need-to-know basis with authorised staff; hosting, email, backup, security, storage, accounting, payment or technology providers; professional advisers; relevant project parties; and lawful authorities. We do not sell personal data.
6. Cross-border processing
Technology providers may process data outside Bali or Indonesia. Before production use, the company should document provider locations, safeguards, contracts and applicable transfer mechanisms.
7. Retention
| Category | Initial retention guideline |
|---|---|
| Unconverted enquiries | Up to 24 months after the last interaction, subject to deletion requests and dispute needs. |
| Partner registrations and profiles | During review and the partner relationship. Rejected or abandoned registrations must be reviewed for deletion under the company retention schedule. |
| Client, transaction and finance records | For the contract period and applicable legal, tax, accounting, audit or claim periods. |
| Project, QC, evidence and handover records | According to contract, warranty/retention, proof and project-archive requirements. |
| Due diligence and reference checks | Until report expiry plus a limited audit/dispute period, followed by review or deletion. |
| Security logs and sessions | As needed for security and audit; sessions are revoked or removed when expired. |
8. Your rights
Subject to applicable law, you may request information and access; correction; restriction, cessation, deletion or destruction; withdrawal of consent where consent is relied upon; a copy or portability where applicable; and raise an objection or complaint. Lawful retention, security, evidence and third-party rights may limit a request.
9. Request procedure
- Send a request to the company contact and identify the data and action requested.
- We verify identity, authority and scope proportionately.
- We log and assess the request, applicable exceptions and required clarification.
- Approved changes are applied to active systems. Encrypted backups may remain until normal expiry and are not reintroduced except through a lawful recovery process.
10. Security
Controls may include HTTPS, role-based access, 2FA, audit logs, encrypted secrets and backups, file validation, checksums, rate limiting and portal separation. No system is risk-free, and hosting plus internal access must be reviewed regularly.
11. Cookies and analytics
Session cookies may be used for forms, login and portals. Analytics is used only when configured. Non-essential or marketing technologies require an appropriate notice or consent mechanism before activation.
12. Children and third-party data
The services are intended for owners, investors, companies and project professionals, not children. When providing another person's data, you must have authority and give any required notice.
13. Incidents and complaints
Suspected loss, unauthorised access or disclosure should be reported promptly. We will triage, secure systems, preserve evidence, assess impact, recover and meet applicable notification duties. Unresolved complaints may be escalated through the competent mechanism or authority.
14. Changes
Material changes receive a new effective date and, where appropriate, notice through the website or direct communication. Dates are not refreshed merely to create an appearance of freshness.
