Privacy Policy
Last updated: 4 October 2026
This policy explains what personal data PT CHINDO BALI EXPORT processes when you visit this website or write to us, why we do it and what rights you have. It follows the standard of the EU General Data Protection Regulation (GDPR) and Indonesian Law No. 27 of 2022 on Personal Data Protection (the PDP Law).
1. Who is responsible for your data
The controller of your personal data is PT CHINDO BALI EXPORT, a limited liability company (Perseroan Terbatas) established under the laws of the Republic of Indonesia.
Registered address: Jl. Raya Campuhan, Desa/Kelurahan Sayan, Kec. Ubud, Kab. Gianyar, Provinsi Bali, Kode Pos: 16966.
Contact for any question about personal data: info@chindobaliexport.com.
2. What data we process
- Request form: your name, email address, company name (if you give it) and the text of your message, together with the language version of the site, the page the form was sent from and the time of sending. The request is delivered to our mailbox by email.
- Anti-bot check: before the form can be sent, Cloudflare Turnstile checks that it is being used by a person and not by an automated program. For this Cloudflare processes your IP address and information about your browser and device (such as the browser type and the technical parameters of the connection). The check does not read what you type into the form. To confirm the result, our server passes the check token and your IP address to Cloudflare.
- Limit on repeated requests: to protect the form from abuse, our server keeps your IP address and the time of sending in its working memory for 10 minutes. It is not written to disk and is not included in the email.
- Email: if you write to us directly, your email address and whatever you include in the message.
- Technical data: when you open the site, your IP address, the date and time of the request, the page requested and the type of browser are processed by the server that hosts the site and by Cloudflare, through whose network the site is delivered. This is needed to deliver the pages and to keep the site secure.
- Your storage choice: a record of the choice you made in the storage notice is kept in your browser. It stays on your device and is not sent to us.
The site does not use analytics, advertising or tracking tools and does not build profiles of visitors. We do not ask for special categories of personal data; please do not include them in your message.
3. Why we process it and on what legal basis
| Purpose | Data | Legal basis |
|---|---|---|
| PurposeReplying to your request and preparing an agreement at your request | DataName, email address, company, message | Legal basisSteps taken at your request before entering into a contract (GDPR Art. 6(1)(b)); our legitimate interest in answering business enquiries (GDPR Art. 6(1)(f)). Under the PDP Law: performance of obligations at your request before an agreement, and our legitimate interest. |
| PurposeProtecting the form from spam and abuse: the anti-bot check and the limit on repeated requests | DataIP address, browser and device information, result of the check | Legal basisOur legitimate interest in protecting the form and our mailbox from automated abuse (GDPR Art. 6(1)(f)); legitimate interest under the PDP Law. |
| PurposeDelivering the website and keeping it secure | DataTechnical data | Legal basisOur legitimate interest in running a working and secure website (GDPR Art. 6(1)(f)); legitimate interest under the PDP Law. |
| PurposeRemembering your storage choice | DataThe choice record in your browser | Legal basisStrictly necessary to honour your choice; compliance with the rules on storage of information on a user's device. |
We do not use your data to send marketing material.
4. Who receives the data
Requests are meant for the company only. To receive them and to run the site, we use the following service providers:
- Cloudflare, Inc. (United States): the anti-bot check on the request form (Turnstile) and delivery of the website through its network, as a reverse proxy and content delivery network in front of our server; Cloudflare also encrypts the connection between your browser and its network (TLS), and the site is served over HTTPS only. It processes your IP address and information about your browser and device. For the anti-bot check, Cloudflare states in its Turnstile privacy terms that it processes this data on our behalf and also, as an independent controller, to improve its bot detection.
- Google LLC (United States): the Gmail service through which the form sends us your request by email. The email contains everything you entered in the form. We use a standard Gmail account, so Google provides this service under its own terms and privacy policy rather than under a data processing agreement with us.
- Proton AG (Switzerland): hosts the company's mailboxes at chindobaliexport.com, where requests and correspondence are received and kept.
- HOSTKEY B.V. (the Netherlands): provides the virtual server in Germany (European Union) on which the website runs. Technical data and the requests you send through the form pass through this server.
We do not sell personal data. Apart from the service providers named above, we do not pass it to third parties; Cloudflare also uses the anti-bot signals for its own purpose described above, and Google handles the email under its own terms. We disclose data to public authorities only where the law requires it.
5. Transfers to other countries
The company is located in Indonesia, so a request you send from another country is received and handled in Indonesia. The European Commission has not adopted an adequacy decision for Indonesia; when you write to us from the European Economic Area, the transfer takes place because it is necessary to answer your request and to take steps at your request before a contract.
The service providers named in section 4 are located in the United States (Cloudflare, Google), Switzerland (Proton), and the Netherlands and Germany (HOSTKEY), so your data is transferred to these countries. The European Commission recognises Switzerland as ensuring an adequate level of data protection. For the anti-bot check by Cloudflare in the United States we rely on the safeguards set out in Cloudflare's data protection terms (such as the European Commission's standard contractual clauses or Cloudflare's certification under the EU–US Data Privacy Framework, as applicable). Google LLC states that it is certified under the EU–US Data Privacy Framework; in addition, your request passes through Gmail in the United States because this is necessary to deliver and answer the request that you send us.
Under the PDP Law, data is transferred abroad only where the country of the recipient or the recipient's safeguards provide adequate protection, or otherwise on a basis allowed by that law.
The website runs on a server in Germany, in the European Union, provided by HOSTKEY B.V. (the Netherlands). Technical data and the requests you send through the form are therefore processed in the EU on their way to us; within the EU this data is protected by the GDPR. Hosting the site involves no transfer outside the EU.
6. How long we keep it
- Requests and correspondence, including the copies in our mailboxes (the receiving mailbox at Proton and the sending Gmail account): for as long as it takes to deal with the request and the correspondence that follows from it. After that they are deleted, unless an agreement is concluded or the law requires them to be kept longer.
- IP address for the limit on repeated requests: up to 10 minutes, in the server's working memory only.
- Anti-bot check: we receive only the result of the check and do not keep it. Cloudflare keeps the data it collects for the check under its own terms.
- Technical data on the hosting server: the web server keeps no access logs. Application and system logs, which may contain an IP address, are kept for 14 days and then deleted automatically. Cloudflare keeps its own logs under its own policy.
- The storage choice record: in your browser until you delete it; we ask again after 12 months or when the Cookie Policy changes.
When the period ends, the data is deleted or destroyed.
7. Your rights
You have the right to:
- be informed about who processes your data, for what purpose and on what basis;
- access your data and receive a copy of it;
- have inaccurate or incomplete data corrected or updated;
- have your data erased or destroyed and have its processing ended;
- have processing restricted or suspended;
- object to processing based on legitimate interest;
- receive your data in a commonly used, machine-readable format and have it transferred to another controller;
- withdraw consent at any time, without affecting processing carried out before the withdrawal;
- object to decisions based solely on automated processing;
- claim compensation for a breach of the rules on personal data processing, as provided by law.
To exercise a right, write to info@chindobaliexport.com. We may ask you to confirm your identity. We answer within the time limits set by the applicable law.
8. Complaints
If you believe your data is handled unlawfully, please write to us first so that we can put it right. You may also lodge a complaint with a supervisory authority.
- In Indonesia: the personal data protection authority provided for by the PDP Law; until that authority begins to operate, the ministry responsible for communication and digital affairs.
- In the European Economic Area: the data protection authority of the country where you live or work, or where the alleged infringement took place.
9. Whether you have to provide data. Automated decisions
Providing data is voluntary. Without a name, an email address and a message we cannot answer a request.
The anti-bot check decides automatically whether the form can be sent. It does not decide anything else about you, and if it fails you can always write to us by email instead. Apart from this check, we do not make decisions based solely on automated processing, and we do not profile visitors.
10. Security
The site is available only over an encrypted connection (HTTPS): Cloudflare, through whose network the site is delivered, provides the encryption, and plain HTTP requests are redirected to HTTPS.
The site sends security headers that tell the browser to use an encrypted connection and restrict what it may load, and serves its fonts together with its own pages. The only third-party script is Cloudflare's anti-bot check, which is loaded only on the page with the request form.
Requests are passed from our server to the mail service over an encrypted connection. The keys and passwords needed for this are kept on the server and are never sent to your browser.
If a personal data breach occurs, we notify the persons affected and the competent authority within the time limits required by law.
11. Changes to this policy
We update this policy when the way we handle data changes. The date of the current version is shown at the top of the page.
This document is available in English and Indonesian.