This policy explains how PT Bali Mitra Bangun Bersama, through the Bali Project Partner brand, obtains, uses, stores, shares, protects, corrects and deletes personal data in connection with the website, consultation, CRM, project administration, quality control, due diligence, property search, tendering, workforce and related services.

Document status

This is an operational template prepared around relevant data-protection principles, including Indonesia's Law No. 27 of 2022 on Personal Data Protection. The processing grounds, retention periods, vendor relationships and rights procedures must still be reviewed by Indonesian legal counsel before adoption as the company's final policy.

1. Controller and contact

The controller is PT Bali Mitra Bangun Bersama. Privacy requests may be sent to contact@baliprojectpartner.com. Proportionate identity verification may be required.

2. Data we may process

  • Identity and contact details.
  • Partner registration data including expertise, service areas, experience, capacity, availability, professional biography, portfolio, certificates, identity and supporting evidence submitted for review.
  • Project, proposal, contract, invoice, payment, communication and approval records.
  • Site reports, schedules, drawings, photos, videos, inspections, defects and evidence.
  • Lawfully obtained due-diligence documents, references, portfolio evidence, public-source notes and professional assessments.
  • Technical and security data such as timestamps, hashed IP data, user-agent, authentication history, audit logs, session cookies and file metadata.

3. Sources

Data may come from you; your organisation or representatives; contractors, foremen, vendors, references, agents, property owners or project parties; lawfully accessed public material; and use of the system. We do not support hacking, interception, leaked datasets or unauthorised account access.

4. Purposes and processing grounds

  • Responding to enquiries and taking pre-contract steps.
  • Performing contracts and project, inspection, payment and handover services.
  • Following consent or instructions you provide.
  • Meeting legal, tax, accounting, safety, audit and dispute obligations.
  • Protecting systems, preventing abuse and preserving proportionate business evidence.

5. Recipients and processors

Data may be shared on a need-to-know basis with authorised staff; hosting, email, backup, security, storage, accounting, payment or technology providers; professional advisers; relevant project parties; and lawful authorities. We do not sell personal data.

6. Cross-border processing

Technology providers may process data outside Bali or Indonesia. Before production use, the company should document provider locations, safeguards, contracts and applicable transfer mechanisms.

7. Retention

CategoryInitial retention guideline
Unconverted enquiriesUp to 24 months after the last interaction, subject to deletion requests and dispute needs.
Partner registrations and profilesDuring review and the partner relationship. Rejected or abandoned registrations must be reviewed for deletion under the company retention schedule.
Client, transaction and finance recordsFor the contract period and applicable legal, tax, accounting, audit or claim periods.
Project, QC, evidence and handover recordsAccording to contract, warranty/retention, proof and project-archive requirements.
Due diligence and reference checksUntil report expiry plus a limited audit/dispute period, followed by review or deletion.
Security logs and sessionsAs needed for security and audit; sessions are revoked or removed when expired.

8. Your rights

Subject to applicable law, you may request information and access; correction; restriction, cessation, deletion or destruction; withdrawal of consent where consent is relied upon; a copy or portability where applicable; and raise an objection or complaint. Lawful retention, security, evidence and third-party rights may limit a request.

9. Request procedure

  1. Send a request to the company contact and identify the data and action requested.
  2. We verify identity, authority and scope proportionately.
  3. We log and assess the request, applicable exceptions and required clarification.
  4. Approved changes are applied to active systems. Encrypted backups may remain until normal expiry and are not reintroduced except through a lawful recovery process.

10. Security

Controls may include HTTPS, role-based access, 2FA, audit logs, encrypted secrets and backups, file validation, checksums, rate limiting and portal separation. No system is risk-free, and hosting plus internal access must be reviewed regularly.

11. Cookies and analytics

Session cookies may be used for forms, login and portals. Analytics is used only when configured. Non-essential or marketing technologies require an appropriate notice or consent mechanism before activation.

12. Children and third-party data

The services are intended for owners, investors, companies and project professionals, not children. When providing another person's data, you must have authority and give any required notice.

13. Incidents and complaints

Suspected loss, unauthorised access or disclosure should be reported promptly. We will triage, secure systems, preserve evidence, assess impact, recover and meet applicable notification duties. Unresolved complaints may be escalated through the competent mechanism or authority.

14. Changes

Material changes receive a new effective date and, where appropriate, notice through the website or direct communication. Dates are not refreshed merely to create an appearance of freshness.