PT SPACE DRAGON BALI PRIVACY NOTICE

Last updated: January 2024

This privacy notice of PT Space DragonBali (“we,” “us”, “our” or the “Company”),describes how and why we might collect, store, use, disclose, transfer, and/or protect(“process”) your Personal Data when you use our services (“Services”),such as when you:

  • visit our website at https://www.taryandragon.com,or any website of ours that links to this privacy notice;
  • accept cookies when accessing our website at https://www.taryandragon.com, or any website ofours that links to this privacy notice;
  • contact us by phone or text, or when you visit our offices; and
  • interact with us in other related ways, including any sales, marketing, or events,

(“PrivacyNotice”).

In this context, personaldata means any individual’s or person’s data that can be identified on its own or in combination with other information either directly or indirectly throughan electronic or non-electronic system as defined in Law Number 27 of 2022 onPersonal Data Protection (“Personal Data”).

Please take a moment to familiarizeyourself with our Privacy Notice to help you understand your privacy rights andchoices. If you do not agree with our policies and practices, please do not useour Services. If you still have any questions or concerns, please contact us at info@taryandragon.com.

This Privacy Notice explains on:

1. WHAT PERSONAL DATADO WE COLLECT?

2. HOW DO WE PROCESS YOUR PERSONAL DATA?

3. WHATLEGAL BASES DO WE RELY ON TO PROCESS YOUR PERSONAL DATA?

4. WHEN AND WITH WHOM DO WE SHARE YOUR PERSONAL DATA?

5. HOW LONG DO WE KEEP YOUR PERSONAL DATA?

6. HOW DO WE KEEP YOUR PERSONAL DATA SAFE?

7. DOWE COLLECT INFORMATION FROM MINORS?

8. WHAT ARE YOUR PRIVACY RIGHTS?

9. DO WE DO CROSS-BORDER DATA TRANSFER?

10. CONTROLS FOR DO-NOT-TRACK FEATURES

11. DO WE MAKE UPDATES TO THIS PRIVACY NOTICE?

12. HOW CAN YOU CONTACT US ABOUT THIS PRIVACY NOTICE?

13. HOW CAN YOU REVIEW, UPDATE, OR DELETE THE DATA WE COLLECT FROM YOU?

 

1. WHAT PERSONAL DATA DO WE COLLECT?

Personal information you disclose to us

In Short: We collect Personal Data that you provide to us.

We collect Personal Data that youvoluntarily provide to us when you express an interest in obtaining informationabout us or our products and Services, when you participate in activities onthe Services, or otherwise when you contact us.

Personal Data Provided by You. The PersonalData that we collect depends on the context of your interactions with us andthe Services, the choices you make, and the products and features you use. The PersonalData we collect may include the following:

  • full name;
  • phone numbers;
  • email addresses;
  • address;
  • country of residence;
  • date of birth;
  • personal identification documentation, such as your passport, ID card or other documentation required by Indonesian law;
  • payment details;
  • survey information (your comments and responses, etc. to market surveys, contests and promotional offers conducted by us or on our behalf); and/or
  • website and communication usage (details of your visits to our websites or social media platforms collected through cookies or other tracking technologies, including behaviour alinformation, browser details, Internet Protocol (“IP”) addresses, purchasing history, location information, etc.)

Specific (Sensitive) Personal Data. We donot process specific Personal Data, e.g., biometric data, medical records,etc., as determined in Law Number 27 of 2022 on Personal Data Protection (“PDPLaw”).

All Personal Data that you provide to usmust be true, complete, and accurate, and you must notify us of any changes tosuch Personal Data by referring to Section 13 of this Privacy Notice 

Data automatically collected from yourdevice by using our Services

In Short: Some information — such as your IP address and/or browserand device characteristics — is collected automatically when you visit ourServices.

We automatically collect certain information when you visit, use, or navigate the Services. This information does not reveal your specific identity (like your name or contact information) but may include device and usage information, such as your IP address, browser and device characteristics, operating system, language preferences, referring UniformResource Locator (“URL”), device name, country, location, information about how and when you use our Services, and other technical information. This information is primarily needed to maintain the security and operation of our Services, and for our internal analytics and reporting purposes. We may use external web analytics services to collect the above information.

The information we collect includes:

    ■  Log and Usage Data. Log and usage data is service-related, diagnostic, usage, and performanceinformation our servers automatically collect when you access or use ourServices and which we record in log files. Depending on how you interact withus, this log data may include your IP address, device information, browsertype, and settings and information about your activity in the Services (such asthe date/time stamps associated with your usage, pages and files viewed, searches, and other actions you take such as which features you use), device event information (such as system activity, error reports (sometimes called “crashdumps”), and hardware settings).

    ■  Device Data. We collect device data such as information about your computer, phone, tablet,or other device you use to access the Services. Depending on the device used,this device data may include information such as your IP address (or proxyserver), device and application identification numbers, location, browser type,hardware model, Internet service provider and/or mobile carrier, operating system, and system configuration information.

    ■  Location Data. We collect location data such as information about your device's location,which can be either precise or imprecise. How much information we collectdepends on the type and settings of the device you use to access the Services.For example, we may use Global Positioning System (“GPS”) and othertechnologies to collect geolocation data that tells us your current location(based on your IP address). You can opt out of allowing us to collect thisinformation either by refusing access to the information or by disabling yourLocation setting on your device. However, if you choose to opt out, you may notbe able to use certain aspects of the Services.

2. HOW DO WE PROCESS YOUR PERSONAL DATA?

In Short: We process your information to provide, improve, andadminister our Services, communicate with you, for security and fraudprevention, and to comply with applicable laws and regulations. We may alsoprocess your information for other purposes with your consent.

We process your Personal Data for avariety of reasons, depending on how you interact with our Services, including:

    ■  to provide the Services to you, including identification and verification ofyour identity, negotiating, execution and performance of agreements, contractswith you, processing of payment for any of the Services provided to you (unlessotherwise governed under a specific privacy notice); 

    ■  to provide customer support (such as responding to your enquiries, and communicatingwith you by email, letter, telephone, or other means);

    ■  for marketing purposes (such as providing you with news, latest offers andpromotions or marketing communications, where you have chosen to receivethese);

    ■  for analytics and profiling (for analysis of consumption needs, preferences,interests); 

    ■  to improve our Services;

    ■  for safety and security purpose; and

    ■  for legal and administrative purposes (to comply with applicable laws andregulations, court order or any requirements of relevant governmentauthorities; to establish legal claims or defenses; to obtain legal advice; toexercise and/or protect our rights). 

3. WHAT LEGAL BASES DO WE RELY ON TOPROCESS YOUR PERSONAL DATA?

In Short: We only process your Personal Data when we believe it isnecessary and we have a valid legal reason (i.e., legal basis) to do so under thePDP Law and its implementing and related regulations, like with your consent,to comply with the applicable laws and regulations, to provide you withservices to enter into or fulfill our contractual obligations, to protect yourrights, to fulfill our legitimate business interests, or to accommodate vitaland public interests.

The PDP Law requires us to explain thevalid legal bases we rely on in order to process your personal information. Assuch, we may rely on the following legal bases to process your personalinformation:

    ■  Consent. We may process your Personal Data if you have given us permission (i.e.,consent) to use your personal information for a specific purpose. You canwithdraw your consent at any time. Learn more about withdrawing your consent.

    ■  Contractual Obligations. We may process your Personal Data in order to negotiate, enterinto or fulfill a contract with you as well as to keep records foraccounting purposes after the termination of the contract with you.

    ■  Legal Obligations. We may process your Personal Data where we believe it is necessaryfor compliance with our regulatory and legal obligations, including our ‘knowyour customer’ (KYC) and due diligence requirements, cooperation with a lawenforcement body or regulatory agencies, exercising or defending our legalrights, disclosure your information as evidence in litigation in which we areinvolved and/or for tax purposes when we act as a tax withholder.

    ■  LegitimateInterests. We may process your information to prevent fraud or to ensure thenetwork and information security of our IT systems.

    ■  Vital Interests. We may process your Personal Dataif circumstances risk your life in the Company’s properties, e.g., naturaldisaster, personal injury, etc.

    ■  Public Interests. We may process your informationif circumstances necessitate your Personal Data being processed by theauthorized governmental authority, e.g., for immigration purposes, etc.

 

4. WHEN AND WITH WHOM DO WE SHARE YOURPERSONAL DATA?

In Short: We may share information in specific situations describedin this section and/or with the following third parties.  

We will only transfer Personal Data to third parties where we have the legal right todo so. In order to preserve the Personal Data and ensure that our Personal Dataprotection, confidentiality, and security requirements are met when we sharedata with others, we put in place contractual agreements and security methodsas necessary. 

We may need to share your Personal Datain the following situations in which as examples of Personal Data processingactivities in which case we will need to transfer your data to a third party orsuch processing activities are performed by a third party as data processors:

    ■  Business Transfers. We may share or transfer your information in connection with, orduring negotiations of, any merger, sale of company assets, financing, oracquisition of all or a portion of our business to another company subject tothe procedures as governed under the applicable laws and regulations (includingthe PDP Law);

    ■  Service providers. We may share your information with our agents, banks, contractors or third party service providers whichprovide administrative, marketing, distribution, data processing,telemarketing, telecommunications, computer, payment or other services tosupport the provision of the Services (including operations of our business andperform activities on our behalf); and/or

    ■  Advisors. We may share your information with our advisors (e.g., legal, financial,business or other advisors) who are under a duty of confidentiality tous.  

 

5. HOW LONG DO WE KEEP YOUR PERSONAL DATA?

In Short: We keep your information for as long as necessary tofulfill the purposes outlined in this Privacy Notice unless otherwise requiredby law.

We will only keep your Personal Data foras long as it is necessary for the purposes set out in this Privacy Notice, in aminimum of five years, unless a longer retention period is required orpermitted by law (such as tax, accounting, or other legal requirements).

When we have no ongoing legitimate business need to process your Personal Data, we will either delete or anonymizesuch information, or, if this is not possible (for example, because your PersonalData has been stored in backup archives), then we will securely store your PersonalData and isolate it from any further processing until deletion is possible.

 

6. HOW DO WE KEEP YOUR PERSONAL DATASAFE?

In Short: We aim to protect your Personal Data through a system oforganizational and technical security measures.

We have implemented appropriate andreasonable technical and organizational security measures designed to protectthe security of any Personal Data we process: your personal data is securelystored on a cloud basis storage namely Microsoft Azur.

When we share your Personal Data with anythird parties, we will strive to ensure that such third parties comply withthis Privacy Notice and other appropriate confidentiality and security measuresthat we require them to comply with when using your Personal Data, except forthe Personal Data you provide directly to the third parties through the use oftheir services 

However, despite our safeguards and efforts to secure your information, no electronic transmission over theInternet or information storage technology can be guaranteed to be 100% secure,so we cannot promise or guarantee that hackers, cybercriminals, or otherunauthorized third parties will not be able to defeat our security andimproperly collect, access, steal, or modify your information. Although we willdo our best to protect your Personal Data, transmission of Personal Data to andfrom our Services is at your own risk. You should only access the Serviceswithin a secure environment.

 

7. DO WE COLLECT INFORMATION FROM MINORS?

In Short: We do not knowingly collect data from or market tochildren under 18 years of age. 

We do not knowingly solicit data from or market to children under 18 years of age. By using the Services, you representthat you are at least 18 or that you are the parent or guardian of such a minorand consent to such minor dependent’s use of the Services. If we learn that PersonalData from users less than 18 years of age has been collected, we willdeactivate the account and take reasonable measures to promptly delete suchdata from our records. If you become aware of any data we may have collectedfrom children under age 18, please contact us at info@taryandragon.com.

 

8. WHAT ARE YOUR PRIVACY RIGHTS?

We would like to make sure you are fully aware of all of your data protectionrights. You are entitled to the following rights:

    ■  The right to be informed – request to know. Depending on the circumstances, youhave a right to know:

        - whether we collect and use your personal data;
        - the categories of personal data that we collect;
        - the purposes for which the collected personal data is used;
        - whether we share personal data to third parties;
        - the categories of personal data that we shared, or disclosed for a businesspurpose;
        - the categories of third parties to whom the personal information was shared, ordisclosed for a business purpose;
        - the business or commercial purpose for collecting or sharing personal information;and
        - the specific pieces of personal information we collected about you.

    ■  The right to access – You have the right to request the Company for access/copies ofyour personal data.  

    ■  The right to rectification – You have the right to request that the Company correct any information youbelieve is inaccurate. You also have the right to request the Company tocomplete the information you believe is incomplete.

    ■  The right to erasure – You have the right to request that the Company terminate the data processing orerase/destroy your personal data to the extent permissible under prevailinglaws and regulations.  If you ask us todelete your personal data, we will respect your request and delete yourpersonal information, subject to certain exceptions provided by the laws andregulations, such as (but not limited to) our compliance requirements resultingfrom a legal obligation, or any processing that may be required to protectagainst illegal activities.

    ■  The right to restrict processing – You have the right to request that the Company restrict/delay/suspend theprocessing of your personal data to the extent permissible under prevailinglaws and regulations.

    ■  The right to object to the processing – You have the right to object to the Company’s processing of your personal datato the extent permissible under prevailing laws and regulations.

    ■  The right to data portability – You have the right to request that the Company transfer the data that we havecollected to another organization, or directly to you to the extent permissibleunder prevailing laws and regulations.

    ■  Theright to withdraw consent – You have the right to withdraw your personal data processing to the extent permissibleunder the applicable laws and regulations.

    ■  The right to obtain compensation – You have the right to submit a claim and obtain compensation for the violationof personal data processing under the applicable laws and regulations.

By sending an email to info@taryandragon.com, you can exercise the above rights, and we will respond to you subject to theapplicable laws and regulations as well as in a timely manner.

 

9. DO WE DO CROSS-BORDER DATA TRANSFER?

The Company complies with laws on the transfer of Personal Data between countries to helpensure your data is protected, wherever it may be. In any case, we will takeappropriate steps to ensure that your Personal Data remains subject to astandard of protection comparable to the requirements under the applicable lawsand regulations.

 

10. CONTROLS FOR DO-NOT-TRACK FEATURES

Most web browsers and some mobile operating systems and mobile applications include a Do-Not-Track (“DNT”) feature or setting you can activate to signal your privacy preference not tohave data about your online browsing activities monitored and collected. Atthis stage no uniform technology standard for recognizing and implementing DNTsignals has been finalized. As such, we do not currently respond to DNT browsersignals or any other mechanism that automatically communicates your choice notto be tracked online. If a standard for online tracking is adopted that we mustfollow in the future, we will inform you about that practice in a revisedversion of this Privacy Notice.

 

11. DO WE MAKE UPDATES TO THIS PRIVACY NOTICE?

In Short: Yes, we will update this notice as necessary to staycompliant with relevant laws and regulations in Indonesia.

We may update this Privacy Notice fromtime to time. The updated version will be indicated by an updated “Revised”date and the updated version will be effective as soon as it is accessible. Ifwe make material changes to this Privacy Notice, we may notify you either byprominently posting a notice of such changes or by directly sending you anotification. We encourage you to review this Privacy Notice frequently to beinformed of how we are protecting your information.

 

12. HOW CAN YOU CONTACT US ABOUT THIS PRIVACYNOTICE?

If you have questions or comments about this notice, you may email us at info@taryandragon.com or contact us by post at. 

[The Promenade Jl. Shortcut Teratai - Batu Bolong No.P14, Canggu, Kuta Utara, Badung, Bali , Indonesia]

 

13. HOW CAN YOU REVIEW, UPDATE, OR DELETE THE DATA WE COLLECT FROM YOU?

Based on the PDP Law, you may have theright to request access to the Personal Data we collect from you, change that information, or delete it. To request to review, update, or delete your Personal Data, please write to us at info@taryandragon.com.