PRIVACY POLICY
This Policy underscores our unwavering commitment to respecting and protecting all personal data or information collected from you, in relation to the services offered through the website www.kolegahr.id and its associated services, accessible via the website and/or mobile applications (hereinafter referred to as the "Services").
By submitting data through the forms provided within the Services, you affirm your consent to be contacted by us and confirm the accuracy and legitimacy of all Personal Data shared. You acknowledge that you have been informed of and fully understand the terms of this Policy, and you grant your consent for us to obtain, collect, process, analyze, display, transmit, disclose, store, modify, delete, manage, and/or utilize your Personal Data and Personal Opinions for the purposes outlined in this Privacy Policy.
This Privacy Policy outlines the processing of your Personal Data and Personal Opinions as conducted by us. It sets forth the following provisions:
- Definition;
- The Acquisition and Collection of Personal Data;
- The Objectives of Personal Data Processing;
- Disclosure of Personal Information;
- Acquisition of Personal Data from Third Parties;
- Protection of Personal Data Security
- Access, Correction, and Updating of Personal Data;
- Approval;
- Deletion/Destruction of Personal Data and Revocation of Consent;
- Third-Party Platform;
- Marketing and Promotional Assets; and
- Other Provisions.
This Privacy Policy is applicable to individuals who complete the forms provided within our Services. We encourage you to read this Privacy Policy thoroughly to ensure your understanding of the provisions pertaining to our Privacy Policy.
1. DEFINITION
- "Affiliation" refers to any company or other entity that, whether directly or indirectly, controls, is controlled by, or shares common control with us.
- "You" may refer to you as the individual completing the form and accessing our Services.
- "Personal Data" refers to any data that can identify or be used to identify, contact, or track you, whether individually or in combination with other information, both directly and indirectly, within our electronic and/or non-electronic systems. This includes, but is not limited to, your name, nickname, residential address or citizenship status, gender, occupation, phone number, International Mobile Equipment Identity (IMEI), home address, Global Positioning System (GPS) location, email address, your image, government-issued identification numbers, date of birth, marital status, religion, bank details, facial features, photographs of your face, and any other images or information you have provided to us through application forms or similar formats, as well as any information about you that has been or may be collected, stored, used, and processed by us over time as you utilize the Services.
- "Personal Opinion" is any opinion or feedback you provide that is directly or indirectly associated with our services offered within the Services.
- "We" are PT Bima Sakti Alterra, the administrator of a private electronic system, the service provider for the Services, and the entity responsible for the ownership and management of the Services.
- "Our Contact Information" serves as a channel through which you may reach us regarding any matters pertaining to the implementation of this Policy.
- "The Competent Authority" pertains to any agency or institution vested with authority under applicable laws and regulations, including but not limited to ministries, non-departmental agencies, judicial bodies, and law enforcement agencies.
- "Processing" or "To Process" , depending on the context and the arrangement of words within a sentence, encompasses the activities of acquiring and collecting, processing and analyzing, storing, disclosing, deleting, and/or destroying Personal Data and/or other information.
- "Destruction" refers to the process of permanently eliminating your Personal Data, either entirely or partially, from our electronic and non-electronic systems in a manner that renders it irretrievable in the future.
- "Deletion" is the process of restricting the use of your Personal Data, either wholly or partially, within our electronic and non-electronic systems, which may be retrievable in the future for the purposes specified in this Policy.
- "Disclosure" or "To Disclose" , depending on the context and phrasing within a sentence, encompasses the presentation, announcement, transmission, dissemination, and/or granting of access to your Personal Data and/or other information.
- "Third-Party" denotes parties, including but not limited to Competent Authorities, our partners, contractors, vendors, agents, and Affiliates.
2. ACQUISITION AND COLLECTION OF PERSONAL DATA/PERSONAL OPINIONS
- We acquire your Personal Data and Personal Opinions through the following methods:
- Direct submission by you, including, but not limited to:
- Registration for the Services;
- Participating in surveys distributed by us or by third parties officially authorized to act on our behalf;
- When we initiate contact with you or vice versa;
- When you provide updates to your previously stored Personal Data with us;
- Utilizing functionalities within the Services that necessitate access permissions to pertinent data stored on your device.
- Data collected during your use of the Service, including but not limited to:
- Actual or estimated location data, including IP addresses, Wi-Fi positioning, and geo-location information.
- Data pertaining to the timing of each activity associated with your utilization of the Services.
- Data concerning your usage and preferences, encompassing your interactions with the Services, saved selections, and configured settings. This information is collected through the use of cookies, pixel tags, and analogous technologies that generate and sustain unique identifiers;
- Device data, which encompasses the type of device utilized to access the Services, including hardware model, operating system and its version, software, IMEI number, file name and version, language preferences, unique device identifiers, advertising identifiers, serial number, device motion information, and/or cellular network information; and/or;
- Log data, which includes records on servers that capture data such as the device's IP address, date and time of access, application features or pages viewed, application workflow processes, and other system activities, as well as browser type and/or third-party sites or services utilized prior to interacting with the Services.
- Data acquired from additional sources, including, but not limited to, information received via emails from marketing service providers.
- Acquisition and collection from Third Parties that maintain your Personal Data; and
- Acquisition and collection through alternative means and from any available sources, insofar as such actions comply with applicable laws and regulations.
- Direct submission by you, including, but not limited to:
- You hereby acknowledge and consent to the provision of your Personal Data/Personal Opinions, and authorize us to acquire and collect such data or related information as outlined in point (a) above, for the purposes specified in this Policy.
- You are responsible for ensuring that the Personal Data you provide to us is accurate, complete, and not misleading. You must notify us of any changes to your Personal Data prior to such changes taking effect or as stipulated in the agreement you have entered into with us concerning modifications to your Personal Data. Any incompleteness, inaccuracy, or misleading information in the Personal Data submitted may constitute a breach of legal obligations. Additionally, you hereby indemnify us against any consequences arising from your negligence or errors in maintaining the accuracy, completeness, and truthfulness of your Personal Data, as well as your failure to ensure the validity and accuracy of the Personal Data provided to us.
- In submitting your Personal Data/Personal Opinions, you hereby affirm and warrant that you possess the legal capacity to do so, and that if:
- If you are an individual under the age of 21 (twenty-one) and have never been married, we will presume that the submission of your Personal Data/Personal Opinions has received the consent of your parents, guardian, or legal representative acting on your behalf;
- If you are an organization or entity, we will presume that the submission of your Personal Data is conducted by an authorized representative duly empowered to provide such data on your behalf, including, but not limited to, an attorney-in-fact or a director; and.
- If you are a legally competent individual and the submission of your Personal Data is made by an attorney-in-fact, we will presume that such submission has been executed by the duly appointed attorney-in-fact authorized to represent you.
3. OBJECTIVES OF PROCESSING PERSONAL DATA AND PERSONAL OPINIONS
- We may utilize the Personal Data and Personal Opinions obtained and collected from you, as outlined in the preceding section, for the following purposes:
- Facilitating features to deliver, implement, maintain, and enhance our products and services.
- Provision of information that we consider beneficial to you, encompassing details about our services and those of Third Parties collaborating with us, as well as updates, developments, and enhancements to our services or facilities.
- Customization of Services to optimize your benefit, provided by us and/or Third Parties with whom we have collaborated.
- Our compliance with obligations mandated by Relevant Authorities or applicable laws, as advised by our legal counsel, includes disclosures in response to subpoenas, court orders, law enforcement requests during investigations, or any requirements applicable to us or our Affiliates.
- Facilitating your requests for access, correction, updates, and/or deletion/destruction of your Personal Data within our system, as well as communicating with you regarding these requests.
- Additional purposes, provided they are not prohibited by applicable laws. To clarify, we will notify you of these purposes when obtaining your consent, unless otherwise mandated by relevant legislation.
- Facilitating your communication with our customer service, including for:
- Examining and resolving your concerns;
- Directing your inquiries to the relevant customer service representatives for issue resolution
- Engaging with you through email, postal mail, telephone, fax, and other communication channels to assist with and resolve issues, as well as to provide updates or notifications regarding the protection of your Personal Data by us, including any potential breaches of such protection.
- Leveraging the information collected from you for research, analysis, product development, and testing purposes to enhance the security of our services and to innovate new features and products; and
- Providing you with information about our products, services, promotions, studies, surveys, news, updates, events, and other relevant details through our Services and various media. We may also use this information to promote contests and sweepstakes, award prizes, and deliver relevant advertisements and content related to our services and business partners.
- in certain circumstances, we may be required to utilize or disclose your Personal Data for law enforcement purposes or to comply with legal and regulatory obligations. This includes instances involving disputes or legal proceedings between you and us, as well as suspected criminal activities such as fraud or data theft
4. DISCLOSURE OF PERSONAL DATA
- We may occasionally need to disclose your Personal Data for the following purposes, as well as for other purposes permitted by applicable laws and regulations:
- Fulfilling obligations, responsibilities, or directives arising from applicable laws and regulations, including but not limited to: requirements for investigations or inquiries, compliance with court orders in legal proceedings, adherence to filing or reporting obligations, and other purposes mandated by relevant legislation.
- Promoting public interests. We may disclose your Personal Data to Relevant Authorities and/or other parties designated by them for purposes including, but not limited to, contact tracing, supporting initiatives, policies, or programs of the Relevant Authorities, and any other purposes considered necessary.
- Mergers, consolidations, acquisitions, and restructurings in which we participate as a party to the transaction, or in which we are the entity being merged or consolidated with another organization, or acquired by another company.
- The use of Personal Data by Third Parties for provision, testing, research, analysis, sales, marketing, or enhancement of our products or services. Third Parties working with us may require the transfer and/or disclosure of your Personal Data as part of their collaboration, which may include marketing and complaint resolution services.
- The collaboration with Third Parties aims to (i) assist us in delivering our services; (ii) operate our business; (iii) process data on our behalf; (iv) conduct marketing; and (v) pursue any other lawful purposes. All collaborating Third Parties are dedicated to processing the Personal Data they receive from us in full compliance with applicable laws and regulations.
- In disclosing your Personal Data to Third Parties, including any further parties they may involve, we require them to uphold the security and confidentiality of your data in accordance with applicable laws. If a Third Party does not need certain Personal Data linked to you, we will ensure that such data is reasonably deleted to prevent identification before its disclosure or transfer. However, these parties will only manage and utilize your Personal Data for the purposes specified in this Privacy Policy and in compliance with relevant laws.
5. COLLECTION OF PERSONAL DATA FROM THIRD PARTIES
- We may also collect your Personal Data from Third Parties with whom we collaborate. In such cases, the collection will be limited to purposes directly related to the Third Party or the execution of our collaboration with them.
- In instances where we receive your Personal Data from Third Parties, we will presume that such submission has been authorized by you. Consequently, we shall not be held liable for any circumstances arising from the Third Party disclosing your Personal Data without your prior consent.
- Our Services may include links to Third Party websites. We disclaim any responsibility for the acquisition, collection, processing, analysis, use, storage, display, disclosure, transmission, dissemination, deletion, or destruction of your Personal Data by these Third Parties. If you choose to provide information directly to such sites, their privacy policies and terms of service will govern, and we shall not be liable for any information processing activities or privacy policies associated with those sites.
6. PROTECTION OF PERSONAL DATA
- We are committed to protect your Personal Data stored in our systems by implementing measures that include restricting access to your data to employees on a need-to-know basis. The processing of your Personal Data will be conducted solely in accordance with permitted practices to uphold its confidentiality. We will protect your data from unauthorized processing by third parties, as well as from activities that contravene applicable laws. Additionally, we will take reasonable legal, organizational, and technical measures to mitigate the risks of accidental loss, destruction, damage, or other similar incidents.
- Management of Personal Data Storage by Us
We will retain your Personal Data in our storage system for the duration of:- The storage of your Personal Data is essential for achieving the objectives specified in this Privacy Policy:
- Storage of your Personal Data is authorized or mandated by applicable laws and regulations;
- Provided that the established retention period complies with applicable laws and regulation;
- You have neither requested the deletion or destruction of your Personal Data in our possession nor revoked your consent for us to retain such data; and/or
- Your request for the deletion or destruction of your Personal Data in our possession has been declined based on the criteria specified in this Privacy Policy.
- Personal Data stored by Relevant Authorities:
- We may be obligated by applicable laws and/or Relevant Authorities to disclose or share your Personal Data with those Authorities and/or other parties designated by them.
- I=n relation to point (i) above, you hereby consent to and acknowledge that the storage of your Personal Data by Relevant Authorities and/or other parties designated by those Authorities will comply with the data storage policies and standards set forth by the Relevant Authorities and/or the designated parties.
- You acknowledge and agree that we are not liable for the security or confidentiality of your Personal Data held by Relevant Authorities or other parties designated by them, and you release us from any liability arising from security or confidentiality breaches of your Personal Data in their possession.
- Principal of Prudence
- We highly advise you to take careful measures in protecting the security and confidentiality of your Personal Data, including but not limited to the following methods:
- Carefully evaluate the media you use to store, upload, transmit, send, or share your Personal Data; and
- Implement due diligence by signing a confidentiality agreement with any party you authorize to receive and store your Personal Data, or by requiring them to maintain and enforce a privacy policy that complies with applicable laws. Ensure that your Personal Data is entrusted solely to parties with established credibility and integrity in safeguarding such information.
- Use of the Internet: Please be advised that utilizing the Internet for the transmission, sharing, uploading, or conveyance of your Personal Data is not entirely secure, as the Internet is accessible to anyone and presents risks associated with the provision and use of online services that are beyond our control and oversight. The provision of Personal Data by you is undertaken at your own risk. We strongly recommend exercising caution at all times when engaging with the Internet in connection with your Personal Data.
- We highly advise you to take careful measures in protecting the security and confidentiality of your Personal Data, including but not limited to the following methods:
- Disclaimer of Liability: We cannot be held liable in any form for:
- The security and confidentiality of your Personal Data that you either store independently or share with Third Parties or other entities;
- The security and confidentiality of Personal Data that has been disclosed to the public or Third Parties, whether such disclosure was initiated by you or by any entity other than us, and provided that this disclosure was not the result of any negligence or fault on our part in safeguarding your Personal Data;
- All consequences resulting from your failure to adequately maintain the security and confidentiality of your Personal Data; and
- All consequences resulting from your utilization of any media to store, upload, transmit, send, and/or share your Personal Data, including, but not limited to, the Internet and cloud storage services.
- We ensure the protection of all your Personal Data stored in our systems and safeguard it against unauthorized access, use, modification, retrieval, and/or disclosure through a comprehensive set of security measures and protocols.
- Your Personal Data may also be stored or processed outside of your country by entities operating on our behalf in other jurisdictions, as well as by third-party service providers, vendors, suppliers, partners, contractors, or affiliates. In these instances, we will ensure that your Personal Data remains protected in accordance with the commitments outlined in this Privacy Policy.
- While we strive to secure your Personal Data, please note that Internet data transmission is never entirely secure. Therefore, we cannot guarantee 100% security of the information you provide, and sharing it is at your own risk.
- We will remove your Personal Data within our control under the following circumstances: (i) when it is no longer necessary to fulfill the purposes for which it was collected; (ii) upon the expiration of the retention period established by us; and/or (iii) when its storage is no longer required for compliance with applicable laws and regulations.
- Please be aware that certain aspects of your Personal Data may be retained by third parties, including authorized government agencies. If we share your Personal Data with these entities, you acknowledge that their storage policies will govern how your data is handled.
7. ACCESS, CORRECTION, AND UPDATE OF PERSONAL DATA
- You may request us to:
- provide your Personal Data and/or grant you access to your Personal Data stored in our storage system;
- amend your Personal Data stored in our systems; and/or
- amend your Personal Data stored in our systems; and/or
- Should we provide your personal data to you, such provision will be conducted electronically, and your personal data will be made available in electronic format or through other methods and formats as we determine periodically.
- We retain the right to reject your request, as outlined in paragraph a above, either in part or in full, under the following circumstances:
- Your request is deemed irrelevant to the personal data we hold about you, including, but not limited to, instances where you seek personal data concerning another party for which you lack authorization; and/or
- We are prohibited from fulfilling your request by the relevant authorities and/or applicable regulations.
- You are obligated to update your personal data should any changes occur to the information you have provided to us. It is essential for you to do so to ensure the security and relevance of your personal data.
- We reserve the right to charge an administrative fee to process your request for access to or correction of your personal data.
- You may withdraw your consent for the processing of your personal data under our control by submitting a written request to our customer service, as detailed in this Privacy Policy. We will process your request within a reasonable timeframe from the receipt of your withdrawal request and will discontinue processing your personal data in accordance with your initial request, unless otherwise mandated by applicable laws and regulations.
8. CONSENT
- By consenting to this Privacy Policy, you affirm that you have read and understood the terms set forth herein. Specifically, you authorize us to process your personal data in accordance with the provisions outlined in this Privacy Policy.
- You are deemed to have provided your consent to the applicability of this Privacy Policy if one or more of the following conditions are met:
- You access and/or utilize our Services and/or the facilities we offer;
- You provide your personal data to us for the purpose of processing it as specified in this Privacy Policy;
- Your personal data is securely stored within our storage system and/or
- communicate with us.
- This Privacy Policy takes effect upon your consent, whether explicitly given or through the methods outlined in section b above, and will remain in force as long as any of the conditions mentioned in section b continue or until you withdraw your consent.
- You may choose not to share your personal data with us. Should you withdraw your consent for processing, we will adhere to our legal obligations. However, this may hinder our ability to fulfill the purposes outlined in this Privacy Policy or restrict your access to our services.
9. DISPOSAL/DESTRUCTION OF PERSONAL DATA AND WITHDRAWAL OF CONSENT
- Your data collected by us will be securely stored in compliance with the relevant laws and regulations in Indonesia. We will retain your data for as long as necessary to achieve the purposes outlined in this Privacy Policy.
- You have the right to withdraw your consent for us to retain your Personal Data. Upon withdrawal, we will remove your Personal Data from our storage system and discontinue its processing.
- Alongside the provisions stated in point a above, your Personal Data may also be removed from our storage system, if:
- Your Personal Data is no longer required, and its deletion/destruction is authorized by applicable laws and regulations;
- You may request the deletion or destruction of your Personal Data stored in our system, in whole or in part, by submitting a written request to our designated contact; and/or
- We are prohibited from retaining your Personal Data in accordance with applicable laws and regulations and/or directives issued by the relevant authorities.
- We retain the right to refuse your request for the deletion or destruction of your Personal Data, as specified in point a above, either in whole or in part, if:
- Your Personal Data has been deleted/destroyed from our storage system based on your prior request and/or at the directive of the relevant Authorities;
- Your request is deemed irrelevant to the Personal Data we hold, including, but not limited to, instances where you seek Personal Data related to another party for which you lack the requisite authority; and/or
- We are not authorized by the relevant Authorities and/or applicable laws and regulations to comply with your request.
- In relation to the deletion/destruction and withdrawal of this consent, you hereby agree to indemnify us against any liability of any kind for all consequences arising from such deletion/destruction and withdrawal.
10. THIRD-PARTY PLATFORM
- Please note that our Services may include links to Third-Party platforms, such as advertisements or widgets, which may redirect you to those platforms when clicked.
- You acknowledge and agree that Third-Party platforms are independently managed by their respective operators, and we are released from any liability regarding the Processing of your Personal Data by these Third Parties, as outlined in point a above.
- If you provide your Personal Data to Third Parties through these platforms, you acknowledge that their privacy policies and terms of service apply, releasing us from any liability for the Processing of your Personal Data by those Third Parties."
11. COOKIES, MARKETING AND PROMOTIONAL MATERIALS
- Cookies are small files automatically placed on your device to store your preferences and settings while browsing a website.
- By using our Services, you consent to our use and that of our Third-Party partners of cookies and similar technologies to collect your Personal Data for legally permissible purposes.
- You consent to receive direct marketing and promotional materials from us and/or our Third-Party partners through email or other available communication channels
- You have the right to restrict cookie collection on our Services, as outlined in point a above, by:
- modifying your browser's cookie settings;
- clearing your browsing history; and/or
- clearing your browser cache.
- You have the right to opt out of receiving marketing and promotional materials to your email or contact, as outlined in point b above, by:
- clicking the unsubscribe link in the marketing and promotional materials received;
- disabling notification and location services on your device; and/or
- contacting our designated representative to express your objection to receiving marketing and promotional materials at your email or contact.
- We employ Google Analytics Demographics and Interests features to collect data, including your age, gender, interests, and other identifiable information. This data will be used to enhance the features, facilities, and content of our Services. If you prefer not to have your data tracked by Google Analytics, you may use the Google Analytics Opt-Out Browser Add-On.
- We may utilize third-party features to enhance our services and content, including the assessment and presentation of advertisements tailored to your interests or browsing history. If you prefer not to receive customized ads, you can modify your settings through your browser.
12. MARKETING POLICY
- By accepting this Policy, you acknowledge and consent that we may occasionally invite you to participate and/or share personal opinions in surveys, videos, or marketing recordings that we will feature across our media, including our products, social media, and websites.
- You have the right to request not be featured or to provide personal opinions, as well as to request the removal of any marketing videos or recordings from our media within 7 (seven) days of publication. To do so, please contact our designated representative and express your objection regarding the display of the marketing content.
13. OTHER PROVISIONS
- Additional Policy:
- Regarding the collection of your facial structure and photo ('Facial Data') for Service use, we act as a processor to validate attendance recording features.
- Your Facial Data will be retained only while you or the controlling entity use our Service, in line with agreed retention terms in the contract or standard operating procedures. We may disclose Facial Data as outlined in section 4(a), points i, ii, and iii of this Privacy Policy.
- Unless otherwise specified in this Supplementary Policy, the provisions for Facial Data as Personal Data follow the Privacy Policy.
- Modification:
- We may review and amend this Privacy Policy at our discretion to ensure alignment with future developments and changes in laws, regulations, or orders from Relevant Authorities.
- We will inform you of the changes mentioned in point i above through a public notice on our Service or a direct notification to your registered email or contact details in our system.
- You acknowledge that you are responsible for periodically reviewing this Privacy Policy to stay informed of updates through our Service or your registered email and contact information. Please visit our Service regularly to remain updated on our Privacy Policy.
- By your continued engagement:
- You access and/or utilize our Services and/or the facilities we offer;
- You provide your personal data to us for the purpose of processing it as specified in this Privacy Policy;
- Your personal data is securely stored within our storage system and/or
- communicate with us.
- this indicates your agreement to the changes we implement.
- You must ensure that your registered contact information is accurate and active to avoid any notification delivery failures.
- Invalidity: The invalidation of any provision in this Policy due to legislation or other reasons does not affect the validity of the remaining provisions.
- Contact Us: For questions or concerns regarding this Privacy Policy, please reach us using the contact information below:
- Phone number: +62361 4785050 / +6281 138008800;
- Email: info@bsa.id
- Language: This Privacy Policy is provided in Indonesian.
- Governing Law: This Privacy Policy is governed by and interpreted in accordance with the laws of the Republic of Indonesia.
- Version: This Privacy Policy was last updated on [November 7, 2023]. Please periodically review it for updates.