This policy explains how Bali Mitra Bangun Bersama, as the service operator trading under the Bali Project Partner brand, obtains, uses, stores, shares, protects, corrects and deletes personal data in connection with the website, consultation, CRM, project administration, quality control, due diligence, property search, tendering, workforce and related services.

Status and scope

This policy applies to the production features currently available. A new feature that changes processing purposes, recipients, storage locations or user risk must be assessed and described before activation. This policy does not claim a particular legal certification or endorsement.

1. Operator, controller and contact

The operator and controller is Bali Mitra Bangun Bersama, trading under the Bali Project Partner brand, with an operational base in Bali, Indonesia. Privacy requests may be sent to halo@baliprojectpartner.com. Proportionate identity verification may be required.

2. Data we may process

  • Identity and contact details.
  • Partner registration data including expertise, service areas, experience, capacity, availability, professional biography, portfolio, certificates, identity and supporting evidence submitted for review.
  • Work-request data including private contact details, category, area, scope, target timing, initial budget range and internal shortlist records.
  • Project, proposal, contract, invoice, payment, communication and approval records.
  • Site reports, schedules, drawings, photos, videos, inspections, defects and evidence.
  • Lawfully obtained due-diligence documents, references, portfolio evidence, public-source notes and professional assessments.
  • Technical and security data such as timestamps, hashed IP data, user-agent, authentication history, audit logs, session cookies and file metadata.

3. Sources

Data may come from you; your organisation or representatives; contractors, foremen, vendors, references, agents, property owners or project parties; lawfully accessed public material; and use of the system. We do not support hacking, interception, leaked datasets or unauthorised account access.

4. Purposes and processing grounds

  • Responding to enquiries and taking pre-contract steps.
  • Performing contracts and project, inspection, payment and handover services.
  • Following consent or instructions you provide.
  • Meeting legal, tax, accounting, safety, audit and dispute obligations.
  • Protecting systems, preventing abuse and preserving proportionate business evidence.

5. Recipients and processors

Data may be shared on a need-to-know basis with authorised staff; hosting, email, backup, security, storage, accounting, payment or technology providers; professional advisers; relevant project parties; and lawful authorities. We do not sell personal data.

6. Cross-border processing

Technology providers may process data outside Bali or Indonesia. Before production use, the company should document provider locations, safeguards, contracts and applicable transfer mechanisms.

7. Retention

CategoryInitial retention guideline
Unconverted enquiriesUp to 24 months after the last interaction, subject to deletion requests and dispute needs.
Partner registrations and profilesDuring review and the partner relationship. Rejected or abandoned registrations must be reviewed for deletion under the company retention schedule.
Work requests and shortlistsDuring review and any related offer or assignment, followed by applicable contract, dispute, audit and company-retention needs.
Website interaction analyticsUp to 30 days. Records are limited to the interaction type, page, time and a hashed daily visitor identifier.
Client, transaction and finance recordsFor the contract period and applicable legal, tax, accounting, audit or claim periods.
Project, QC, evidence and handover recordsAccording to contract, warranty/retention, proof and project-archive requirements.
Due diligence and reference checksUntil report expiry plus a limited audit/dispute period, followed by review or deletion.
Security logs and sessionsAs needed for security and audit; sessions are revoked or removed when expired.

8. Your rights

Subject to applicable law, you may request information and access; correction; restriction, cessation, deletion or destruction; withdrawal of consent where consent is relied upon; a copy or portability where applicable; and raise an objection or complaint. Lawful retention, security, evidence and third-party rights may limit a request.

9. Request procedure

  1. Send a request to the company contact and identify the data and action requested, or use the account/data deletion form.
  2. We verify identity, authority and scope proportionately.
  3. We log and assess the request, applicable exceptions and required clarification.
  4. Approved changes are applied to active systems. Encrypted backups may remain until normal expiry and are not reintroduced except through a lawful recovery process.

10. Security

Controls may include HTTPS, role-based access, 2FA, audit logs, encrypted secrets and backups, file validation, checksums, rate limiting and portal separation. No system is risk-free, and hosting plus internal access must be reviewed regularly.

11. Cookies, analytics and operational notifications

Session cookies may be used for forms, login and portals. To measure service functionality, the system may record bounded interactions such as page visits, navigation or contact clicks, downloads, directory searches, and form starts or submissions. These records do not include form-field values, message content, passwords, authentication tokens, email addresses, telephone numbers or full addresses. IP addresses and user-agent strings are not retained in these analytics records; a hashed daily visitor identifier is used and records are deleted after no more than 30 days.

Operational summaries and unique-visit alerts, including crawler categories inferred from user-agent data, may be forwarded to an administrator-controlled Telegram bot. Alerts are time-windowed, contain neither raw IP addresses nor raw user-agent strings, and do not prove bot identity. Other notification payloads for leads, orders, payments, security and system health are filtered to the metadata required for follow-up; sensitive records remain available only through the protected Admin portal. Non-essential or marketing technologies require an appropriate notice or consent mechanism before activation.

12. Children and third-party data

The services are intended for owners, investors, companies and project professionals, not children. When providing another person's data, you must have authority and give any required notice.

13. Incidents and complaints

Suspected loss, unauthorised access or disclosure should be reported promptly. We will triage, secure systems, preserve evidence, assess impact, recover and meet applicable notification duties. Unresolved complaints may be escalated through the competent mechanism or authority.

14. Changes

Material changes receive a new effective date and, where appropriate, notice through the website or direct communication. Dates are not refreshed merely to create an appearance of freshness.