Privacy
Update date: January 2, 2025
This privacy notice provides you with information about how we process your Personal Data as a form of our commitment and compliance with applicable personal data protection provisions.
We are committed to:
- Not collecting personal information without your knowledge,
- Processing all data and/or personal information obtained from any party and in any form, in accordance with applicable laws in the Republic of Indonesia,
- Implementing procedures to limit who has access to personal information.
We will update this privacy notice from time to time. You can find the date of the current version listed at the beginning of this privacy notice. If you have any questions or concerns regarding your personal data, please contact us.
The information we collect about you and how we process it may vary depending on the products and services you use, how you have used those products and services, and how you interact with us.
Such Personal Data may include:
- Personal Data of individuals including, but not limited to:
- General data, including name, place and date of birth, Population Identification Number, registered address, residential address, telephone number, email address, gender, nationality, religion, marital status, Taxpayer Identification Number, educational history, employment, photo or video, signature, voice recording; and
- Specific data, including biometric data such as fingerprint recordings, records, information in any form relating to the individual's finances.
- Personal Data of entities including, but not limited to:
- General data, including names, addresses, telephone numbers, composition of the Board of Directors and Board of Commissioners, information related to shareholders, data on agency employees, all information on the identity cards (and/or residence permits) of the Board of Directors, Board of Commissioners and shareholders; and
- Specific data, for example financial data of the entity.
For the purpose of providing the Services and customer satisfaction, we may need your Personal Data. When we need to collect Personal Data and you choose not to provide such Personal Data or provide incomplete Personal Data, we may not be able to provide the services and perform the existing or pending agreement with you.
We may obtain your Personal Data in printed form or in electronic form through:
- You
When you submit your Personal Data directly, either through officers at branch offices, marketing staff, applications, pages, systems, networks, media, events that we organize and other channels that we provide. - Other parties
Based on an agreement that you have previously given to another party to be able to provide your Personal Data to us. We may use the Personal Data according to the purposes explained when you provide the relevant agreement.
We have determined the scope or list of Personal Data required to enable us to provide services or make certain commitments/agreements with you, including to fulfill matters required by applicable laws and regulations.
We will only process your Personal Data in accordance with the legal basis for the Processing of Personal Data by taking into account the applicable provisions, including:
- fulfillment of obligations based on an agreement between you and us;
- fulfillment of legal obligations in accordance with statutory provisions;
- fulfillment of the protection of your vital interests;
- implementation of tasks in the context of public interest or public services based on statutory regulations;
- fulfillment of other legitimate interests, including our internal interests by taking into account the objectives, needs; and
- consent that you explicitly provide for a specific purpose.
We may Process Personal Data for the purposes of:
- provision of services (including request processing) or use of our infrastructure;
- processing of employment relationships;
- processing of certain agreements or contracts; and/or
- other commercial or non-commercial purposes.
We will Process Personal Data for the purposes of, among others:
- If you use our services or infrastructure (including Customers and Prospective Customers):
- provision of our services;
- ensuring the fulfillment of your and our rights and obligations in accordance with the agreement you have with us, including but not limited to providing access to your Personal Data to our work units or employees for coordination and implementation purposes;
- conducting analysis of the provision of products and/or services to you;
- commercial purposes, with reference to the separate consent you provide:
- We may contact you via your personal communication media during operating hours to offer products and/or services that we provide;
- We and/or other parties who cooperate with us may contact you to offer products that are the result of cooperation between us and such other parties; and/or
- non-commercial purposes, including for security purposes (in accordance with applicable standards in practice) or to carry out data analytic activities on Personal Data (which do not have a commercial purpose to offer certain products and/or services to you), and other purposes.
- If you are in an employment relationship with us (including Employees and Prospective Employees):
- the selection process to determine whether your job application will be accepted;
- recording of Employee data for personnel purposes;
- prevention and/or handling of fraud;
- Employee development programs through certification or training activities;
- tax reporting; and/or
- health insurance.
- If you engage with us (including Vendors):
- a selection process to determine whether your offer will be accepted;
- an internal analysis and monitoring process to assess your performance;
- supporting the payment process for products and/or services you provide to us;
- efforts to prevent bribery and/or corruption; and/or
- audio and visual recording as required in connection with your products and/or services.
- Other purposes:
- comply with the provisions related to the implementation of anti-money laundering programs, prevention of terrorism financing, and prevention of financing for the proliferation of weapons of mass destruction in the financial services sector;
- compliance and fulfillment of requests for reports or information from authorized bodies, regulators or institutions in accordance with applicable laws;
- upholding our rights in the dispute resolution process, both inside and outside the court;
- implementing court decisions, arbitration or other dispute resolution institutions that have permanent legal force;
- detecting and preventing actions or deeds that violate applicable laws;
- internal and external audits by considering the scope of Personal Data in accordance with the purpose of the audit;
- preparation and/or planning of business strategies or other corporate actions that we will carry out; and/or
- exploring the potential for collaboration in business activities with other entities in the financial institution business group that houses us.
We, in accordance with applicable laws and regulations, may also:
- Process Personal Data of children under the age of 18 and persons with disabilities by referring to separate consent from the parent or guardian of the owner of such Personal Data;
- Send your Personal Data to other parties outside the territory of Indonesia for the purposes of processing as described in letters a to d above and/or in the context of disclosing your Personal Data as described in this privacy notice; and/or
- Process Personal Data of the beneficial owner/actual fund owner (Beneficial Owner) of your account if you admit that you do not have any income/revenue and/or are the authorized holder of your account.
However, it is important for you to remember that we are committed not to sell your data to other parties, without your permission.
We will store the Personal Data that has been collected as long as you are still using our services/infrastructure or in the process of being or being registered as our Customer/Employee/Vendor.
Your Personal Data will be stored in any form and media, either on our premises or on the premises of another party that we appoint (to carry out storage) according to the document storage period by referring to our internal policies or in accordance with applicable laws and regulations.
For the purpose of such storage, we determine the document storage period by considering:
- the type, level of complexity and duration of the service or engagement that you create or carry out with us;
- the obligation to store certain types of documents as stipulated by applicable laws and regulations; and
- the interests of evidence in the trial or litigation process.
We will delete and destroy documents containing Personal Data in accordance with the document retention period provisions as explained above.
In the event that we share your Personal Data with authorized government institutions and/or other institutions that may be appointed by the authorized government or have cooperation with us, the storage of your Personal Data by the relevant institutions will follow the data retention policies of each institution.
In carrying out Personal Data Processing for the purposes above, we may share Personal Data by appointing other parties to:
- contact you to obtain information or documents that we need;
- respond to certain questions or requests from you;
- create documentation that must meet certain formalities based on statutory provisions;
- prepare a Personal Data security mechanism;
- obtain independent opinions from consultants, advisors or auditors in certain fields.
- conduct feasibility analysis and historical analysis required for the provision of products and/or services or to carry out certain engagements with you;
- storage of Personal Data, both storage of printed documents and storage of electronic documents;
- validate authorized signatories;
- delivery of documents or information via delivery services;
- printing of attributes and/or publications that need to be used to carry out the engagement between you and us, which inherently contain certain Personal Data;
- giving gifts for programs we organize in the form of products belonging to other parties whose delivery requires Personal Data;
- holding an event;
- providing certain benefits or facilities that we have agreed with you; and/or
- other purposes that involve disclosing your Personal Data to other parties.
We will disclose your Personal Data to the party appointed to do the above. The party acts on our behalf as the Personal Data Processor.
In appointing the Personal Data Processor, we determine the purpose and exercise control over the processing and establish the confidentiality obligations of the Personal Data for the activities carried out by the Personal Data Processor. The arrangements regarding the processing of Personal Data (including recording activities, confidentiality, security measures, and reporting in the event of a breach) are set out in a written agreement made between us and the Personal Data Processor.
The identity of the Personal Data Processor can be found, among others, in the letter/publication/page/form/document/agreement explaining the services you use and the specific engagement/agreement you make with us, or will be conveyed to you directly (if you are contacted).
With reference to the provisions of applicable laws and internal policies that we have set, your rights (as a Personal Data Subject) are as follows:
- Right to Obtain Information
You have the right to obtain Information about the clarity of your identity, the basis of legal interests, the purpose of the request and the use of your Personal Data by us, in a form that is in accordance with the structure and/or format commonly used or can be read by an electronic system. - Right to Update Personal Data
You have the right to ask us to complete, update, and/or correct errors and/or inaccuracies in your Personal Data. This can be done by including detailed information and supporting documents related to the Personal Data in question. - Right to Access Personal Data
You have the right to access and obtain a copy of your Personal Data that we have obtained. This will be done upon your written request and subject to our terms of service (including but not limited to the imposition of fees). - Right to Delete Personal Data
You have the right to terminate the processing, delete, and/or destroy your Personal Data. This is done by taking into account the deletion criteria that we have set and applicable laws and regulations. - Right to Withdraw Consent
You have the right to withdraw your consent to the processing of your Personal Data that has been given to us. The withdrawal of consent is binding on you and us from the time the consent withdrawal process has been completed and is effective. - Right to Object
You have the right to object to decisions based solely on automated processing, including profiling, that have legal consequences or significant impacts on you. This can be done by submitting a written objection to us. Due to such objection, there are consequences where our services cannot be run optimally. - Right to Limit or Object to Personal Data Processing
You have the right to delay or limit the processing of your Personal Data proportionally according to the purpose of processing the Personal Data. This can be done by providing information on the desired limitations clearly and in writing to us. Due to such objection, there are consequences where our services cannot be run optimally.
In this privacy notice:
- "You" means the parties who will, are or have: (a) used our services or infrastructure (including prospective Customers or Customers); (b) in the process of employment (including prospective Employees or Employees); (c) entered into certain agreements with us (including vendors); who have provided Personal Data.
- "Personal Data" means data about individuals who are identified or can be identified individually or in combination with other information either directly or indirectly through electronic or non-electronic systems (as referred to in the provisions on personal data protection) or data and/or information about consumers (as referred to in the provisions on consumer protection).
- "Employees" are individuals who have an employment relationship with us.
- "Customers" are parties, whether individuals or corporations who use the products and/or services provided by us.
- "Personal Data Processing" is a series of processes that include obtaining and collecting, processing and analyzing, storing, correcting and updating, displaying, announcing, transferring, disseminating, or disclosing, and/or deleting or destroying Personal Data.
- "Personal Data Processor" is any person, public body and international organization acting individually or jointly in processing Personal Data on our behalf.
If you have any further questions regarding this privacy notice, you may contact us through:
Zurich Care 1500-456
or by referring to the Contact Us page.