Privacy Notice

This Privacy Notice is effective as of 29 November 2024.

This Privacy Notice is an integral part of Obbidy Terms of Use.

INTRODUCTION
WHO WE ARE We are PT Transformasi Eksistensi Digital ("Us", "We", or "Obbidy" ) a limited liability company operating the website Obbidy.com and other related products and services.

We recognize the importance of protecting Your Personal Data in accordance with applicable data protection laws, including Law No. 27 of 2022 on Personal Data Protection, its amendment and implementing regulations applicable to Obbidy from time to time (" PDP Law"). Therefore, We are committed to complying with all provisions of the PDP Law, including its amendments and implementing regulations, to maintain the confidentiality of Your Personal Data and protect it in accordance with applicable law.
SCOPE OF THIS PRIVACY NOTICE In the context of this Privacy Notice, " Personal Data" means data about a natural person who is identified or can be identified, whether on its own or in combination with other information, directly or indirectly, through electronic or non-electronic systems as referred to in the PDP Law, its related regulations, and Section C of this Privacy Notice, including but not limited to personal data listed on identity cards that can identify a person (including Your photo), phone number, email address, personal financial data (including bank details, credit card details, and transaction data), email address, as well as Your date and place of birth.

This Privacy Notice, as amended from time to time (" Privacy Notice "), explains how We process Personal Data, including acquiring, collecting, processing, analyzing, storing, correcting, updating, displaying, publishing, transferring, disseminating, disclosing, deleting, and/or destroying Your Personal Data (" Personal Data Processing ") through website(s), application(s), and/or system(s) (if any), participation in certain programs or promotional activities offered by Obbidy and/or third parties that cooperate with or have a legal relationship with Obbidy (" Third-Party Partners "), whether online or offline, and through other activities, services, products, and features provided via our website(s), application(s), and/or system(s) (if any) (collectively, the ("Obbidy Services")

This Privacy Notice applies when You:
  1. become a user of the Obbidy Services or a customer of Obbidy, including Obbidy's employees who use Obbidy Services and/or are customers of Obbidy; and/or
  2. become (i) Obbidy's business partner, contractor, agent, and/or supplier, and/or (ii) have a legal relationship with Obbidy for a specific purpose, for example the implementation of social and environmental responsibility (corporate social responsibility).
HOW TO CONTACT US If You have any questions or complaints regarding this Privacy Notice and the Personal Data Processing activities We carry out, including if You intend to exercise Your rights as a Personal Data subject, You can contact Us at [email protected].
YOUR REPRESENTATIONS AND WARRANTIES
Please read and understand this Privacy Notice carefully so that You are aware of how We manage and protect Your Personal Data.

You hereby declare and warrant that:
  1. You have read and understood this Privacy Notice;
  2. The Personal Data You provide is accurate, complete, and authentic;
  3. You understand all the provisions of this Privacy Notice and how We process Your Personal Data in accordance with this Privacy Notice.

In specific situations, You may need to provide Us with another person's Personal Data (such as Your spouse, family member, employee, or another party You represent). If You provide another person's Personal Data for Us to process, You represent and warrant that You have obtained valid consent from that person or from their parent or legal guardian (if applicable). You also understand that We rely on Your representations and warranties to process that Personal Data. We are not responsible if the Personal Data You provide, especially Personal Data belonging to someone else, is obtained unlawfully or if Your representations and warranties are untrue. We reserve the right to request evidence of such consent from You at any time if necessary.
WHAT WE DO WITH YOUR PERSONAL DATA
TYPE OF PERSONAL DATA The types of Your Personal Data that are collected depend on the purpose of the intended Personal Data Processing. The Personal Data collected generally includes the following:

  1. Identity Data including name, photograph, place and date of birth, gender, and identity card(s) together with the Personal Data contained therein (including, among others, the Population Identification Number (Nomor Induk Kependudukan or NIK) and passport number).
  2. Contact Data including email address and phone number.
  3. Financial Data including information regarding bank accounts and/or payment instruments used in transactions for the provision of the Obbidy Services, and financial history.
  4. Device Data including the type/model of the device You use to access the Obbidy Services, Internet Protocol (IP) address and geolocation data (as required for the provision of the Obbidy Services), and cookies (used to personalize information, including Personal Data, used to access the Obbidy Services; You can manage Your cookies through Your browser settings, but doing so may limit the speed/quality of the Obbidy Services).
  5. Other Personal Data as permitted under applicable laws and regulations.

Personal Data collected as described above is provided either directly by You or indirectly by Third-Party Partners, including through the completion of forms, submission of electronic or non-electronic documents, QR (quick response) code scanning, uploading data via websites, applications and/or systems, filling out online surveys, or through other media related to Obbidy Services. For example, when You register to access/receive and/or use Obbidy Services (including when You contact Us), when You attend events organized by Us or Third-Party Partners either online or offline (including Your participation in promotional programs), participate in fundraising (donations), and through other activities, services, products and/or features, or sourced from Third-Party Partners such as parties involved in the implementation of Customer Due Diligence (CDD) processes or in other contexts to achieve the purpose of Personal Data Processing (including from publicly available data sources or those provided by authorized government institutions).
WHY WE PROCESS YOUR PERSONAL DATA The processing of Your Personal Data is for purposes including:

  1. To provide and process Obbidy's Services for You, which include:
    1. Provide the Obbidy's Services and information about the Obbidy's Services (including changes thereto from time to time);
    2. To comply with laws and regulations, including implementing Customer Due Diligence (CDD) principles and Anti-Money Laundering, Counter-Terrorism Financing, and Prevention of Financing of the Proliferation of Weapons of Mass Destruction programs in connection with the provision of the Obbidy's Services to You;
    3. To respond to and resolve Your requests in relation with Obbidy's Services;
    4. To modify, enhance, and/or develop the Obbidy's Services, including updates to and/or adjustments of applications/systems related to the Obbidy's Services; and/or
    5. To fulfill other needs as necessary.

  2. Conducting and enhancing operational activities, and complying with applicable laws and regulations, which includes:
    1. Conducting research and studies related to the provision of the Obbidy's Services, including generating analytics derived from data analysis and/or usage patterns for research, analysis, testing, product development, and cooperation with Third-Party Partners;
    2. Billing for the provision of the Obbidy's Services;
    3. Conducting activities related to accounting, audit, taxation, and reconciliation connected to the provision of the Obbidy's Services, as well as internal administrative processes;
    4. Performing obligations under agreements to You and/or to relevant Third-Party Partners (including but not limited to Third-Party Partners);
    5. Preventing, detecting, and investigating any suspicious transactions, criminal acts, or prohibited activities, including as required under applicable laws and regulations;
    6. Communicating with You through various media, including to respond to questions, comments, or complaints;
    7. Processing Your participation in any production activities, contests, games, promotions, polls, or surveys;
    8. Conducting other internal activities necessary to provide the Obbidy's Services, such as software troubleshooting, bug fixes, operational issue resolution, data analysis, testing, and research, and monitoring and analyzing usage trends and activity;
    9. Complying with law enforcement requests and protecting our rights and/or Your rights; and/or
    10. Fulfilling other needs as necessary.

  3. Product offering and promotion, including offers of the Obbidy's Services, other products, competitions, loyalty programs, prize draws, events, and other forms of promotion tailored to Your needs and profile. We may deliver offers for products/services owned by or provided by Us and/or Third-Party Partners through various media and/or methods, whether oral or written, including via push notifications, social media, instant messaging applications (for example, WhatsApp), SMS, phone calls, email, QR code scanning, brochures, and other relevant electronic and non-electronic media in accordance with applicable requirements ( Other Offers).

  4. We may process Personal Data if We carry out corporate actions and/or other transactions, including but not limited to mergers, spin-offs, acquisitions, consolidations, restructurings, and/or other activities involving the transfer of intellectual property rights, insofar as they involve Personal Data Processing.

  5. We may process Personal Data when instructed or required by competent government authorities, for purposes as described or as stipulated under applicable laws and regulations.
HOW WE COLLECT YOUR PERSONAL DATA
  1. Directly: We obtain Your Personal Data directly from Your interactions with our services, including but not limited to account registration, use of the services, and communications with our team.

  2. Third Parties: We may also obtain Your Personal Data through other parties, including Third-Party Partners that work with Us to support the provision of the services, in accordance with applicable law.
LEGAL BASIS OF PERSONAL DATA PROCESSING
  1. Your explicit valid consent to this Privacy Notice;
  2. Fulfillment of contractual obligations to provide the Obbidy Services to You or for other needs in accordance with this Privacy Notice;
  3. Fulfillment of legal obligations under laws and regulations;
  4. Performance of tasks in the public interest, public services, or the exercise of Obbidy authority under laws and regulations;
  5. Fulfilling obligations and considering business needs based on other legitimate interests, while considering the purposes, needs, and balance of interests of Us as the Personal Data controller and Your rights as the Personal Data subject; and/or
  6. Other legal bases for Personal Data Processing in accordance with applicable laws and regulations.
WHY YOU CANNOT RESTRICT SOME PERSONAL DATA PROCESSING ACTIVITIES Some Personal Data Processing is necessary for Us to provide services to You. Without Personal Data Processing, including by Third Parties that support our services, We cannot provide those services.

This also applies to Personal Data Processing that must be carried out to comply with applicable legal requirements.
THIRD PARTIES
OUR REASONS FOR TRANSFERRING YOUR PERSONAL DATA THIRD PARTY INVOLVED CAN YOU RESTRICT THIS PERSONAL DATA TRANSFER
Obbidy's Service Provision & Operations Third-Party Partners that support the provision of Obbidy Services and our operations No
Marketing & Promotions Other service and/or product providers that collaborate with Us Yes
Legal Compliance Government authorities No
Your Payment Processing Payment service providers No
STORAGE AND MANAGEMENT OF PERSONAL DATA BY US
WHILE USING OBBIDY SERVICES AFTER NO LONGER USE OF OBBIDY'S SERVICES HOW WE STORE PERSONAL DATA DELETION & DESTRUCTION
We will process Your Personal Data for as long as You use our services and/or have a legal relationship with Us, where Personal Data Processing is required to fulfill the rights and obligations arising from that legal relationship. We will retain Your Personal Data after You are no longer our user or customer, or no longer have a legal relationship with Us, for a certain period, based on applicable laws and regulations, Your consent, and/or our operational needs. We are committed to maintain appropriate physical, technical, and procedural safeguards to protect Your Personal Data from loss, misuse, copying, damage or alteration, and unauthorized or unlawful access or disclosure, and from loss or damage.

Further, although We have taken what We believe are the best and optimal measures to protect Your Personal Data, We cannot fully guarantee that the Personal Data You transmit will be completely secure, and You assume that risk. We will not be liable for any security breach or any acts of third parties, or for any events beyond our reasonable control, including but not limited to acts of government, computer hacking, unauthorized access to computer data and storage devices, computer crashes, breaches of security and encryption, and poor quality of Your internet or telephone service, and other similar occurrences.
We will delete and destroy Your Personal Data in accordance with the provisions set out in applicable laws and regulations.
CROSS-BORDER DATA TRANSFER
TRANSFER OF PERSONAL DATA OUTSIDE THE JURISDICTION OF THE REPUBLIC OF INDONESIA OUR COMMITMENT TO COMPLIANCE
If You use or access the website, application, and/or system related to the Obbidy Services in another country (outside the Republic of Indonesia) where our website, application, and/or system can be accessed (" Destination Country"), We may transfer Your Personal Data from the country of origin (" Country of Origin") to the Destination Country so that You can access our website, application, and/or system outside the Republic of Indonesia. You hereby understand and consent to the transfer of Your Personal Data out of Your country of origin and/or the Country of Origin as described in this Privacy Notice, the details of which We can provide to You if necessary. We will comply with applicable laws and regulations and use our best efforts to ensure a level of protection equivalent to that in the Republic of Indonesia and as set out in this Privacy Notice, including by using standard contractual clauses for Personal Data protection in connection with transfers of Personal Data outside the jurisdiction of the Republic of Indonesia (cross-border), where relevant and required.

We conduct assessments of the transfer of Your Personal Data outside the jurisdiction of the Republic of Indonesia to meet the requirements of applicable laws and regulations, including determining the appropriate transfer mechanisms and assessing risks.
G. YOUR RIGHTS AS A PERSONAL DATA SUBJECT
HOW CAN YOU EXERCISE YOUR RIGHTS If You wish to submit a request to exercise Your rights as a Personal Data subject, You may contact Us through the channel(s)/contact(s) listed in Section A of this Privacy Notice.

We will verify and review each of Your requests. To ensure that Your request is valid, We may ask for supporting information or documents. Once Your request is verified, We will inform You of the consequences of exercising Your rights. After You agree to those consequences, We will process Your request within the time limits specified by applicable regulations.
YOUR RIGHTS AS A SUBJECT OF PERSONAL DATA
  1. Right to obtain information;
  2. Right to obtain access and/or copies of Personal Data;
  3. Right to complete, update, and/or correct errors and/or inaccuracies in Personal Data;
  4. Right to terminate the Processing of Personal Data;
  5. Right to erase Personal Data;
  6. Right to portability;
  7. Right to interoperability;
  8. Right to withdraw consent to the Processing of Personal Data;
  9. Right to delay or restrict the Processing of Personal Data in a proportionate manner; and/or
  10. Right to lodge a claim and receive compensation in the event of a violation of the Processing of Personal Data based on our errors or negligence that directly harms you.
EXCEPTIONS Please understand that, under applicable regulations, in certain circumstances We are entitled to refuse Your request to exercise Your rights, including requests to delete or destroy some or all of Your Personal Data in our possession. Such refusal may occur if required or permitted by law, particularly where the request could affect the following:
  1. National defense and security interests;
  2. Law enforcement interests;
  3. Public interest in the administration of the state;
  4. Supervisory interests of the financial services sector, monetary and payment systems, and financial system stability, carried out in the context of state administration;
  5. Statistical and scientific research interests;
  6. The need to implement provisions of applicable laws and regulations, for example related to implementing Customer Due Diligence (CDD) processes and/or preventing criminal acts;
  7. The reason for the request is not relevant to the Personal Data Processing We carry out or to You as the Personal Data subject;
  8. Would endanger the security, physical health, or mental health of the Personal Data subject and/or others; and/or
  9. Would result in the disclosure of another person's Personal Data.
H. SECURITY
The confidentiality of Your Personal Data is very important to Us. We will use our best efforts to protect and secure Your Personal Data from access, collection, use, or disclosure by unauthorized parties, as well as from unlawful processing, accidental loss, destruction, and damage or similar risks. However, because the transmission of Personal Data over the internet is not completely secure, We cannot guarantee that Your Personal Data will not be intercepted, accessed, disclosed, altered, or destroyed by unauthorized third parties, due to factors beyond our control.

We will also take reasonable steps to keep Your Personal Data accurate and updated as needed.

You are also responsible for maintaining the confidentiality of Your account details. Do not share Your account details, including Your password and One Time Password (OTP), with anyone. Make sure You always keep the devices You use secure.
I. OTHER IMPORTANT INFORMATION
LANGUAGE This Privacy Notice may be translated into languages other than Indonesian. If there is any inconsistency between the Indonesian version of this Privacy Notice and any other language version, the Indonesian version shall prevail.
GOVERNING LAW This Privacy Notice is governed by the laws of the Republic of Indonesia.
CHANGE OF THE PRIVACY NOTICE We may change, supplement, and/or replace this Privacy Notice from time to time (with notice to you) to ensure that this Privacy Notice is in line with the procedures and practices carried out by Us in carrying out the Processing of Personal Data, including to comply with the provisions of applicable laws and regulations.