Privacy Policy

Privacy Policy

Last updated: August, 24 2026

PT Supranusa Sindata (“Sindata”, “we”, “us”, or “our”) respects your privacy and is committed to protecting Personal Data in accordance with applicable laws, regulations, and contractual requirements, including Law No. 27 of 2022 concerning Personal Data Protection (“UU PDP”).

 

This Privacy Policy explains how we collect, use, disclose, retain, and protect Personal Data when you visit or interact with our corporate website at www.sindata.net (the “Website”), contact us, submit an inquiry, apply for employment, or otherwise interact with us through the Website.

 

1. Scope and Our Role

This Privacy Policy primarily applies to Personal Data that Sindata processes in its capacity as a Data Controller in connection with the Website and our direct interactions with individuals.

This may include Personal Data relating to:

  • visitors to our Website;
  • individuals who submit inquiries or contact requests;
  • prospective and existing customers and their representatives;
  • business partners and their representatives;
  • individuals who subscribe to communications from us; and
  • job applicants and other individuals who communicate with us.

 

Our Role in Relation to VHP PMS

Sindata also provides web-based property management and hospitality technology services, including the VHP Property Management System (“VHP PMS”).

 

When a hotel or hospitality customer uses the VHP PMS to collect and process Personal Data relating to its guests, employees, or other individuals, the relevant hotel customer generally acts as the Data Controller and Sindata acts as a Data Processor, processing such Personal Data on behalf of and in accordance with the instructions of the relevant hotel customer and the applicable agreement between the parties.

 

Such Personal Data may include guest names, contact details, identification or passport information, reservation information, stay history, and other information entered into or processed through the VHP PMS.

 

If you are a guest, employee, or other data subject of one of our hotel customers and your Personal Data has been processed through the VHP PMS, please contact the relevant hotel directly regarding requests concerning that Personal Data. Sindata will provide reasonable assistance to the relevant hotel customer in accordance with applicable law and our contractual obligations.

 

This Privacy Policy does not replace or supersede any data processing agreement or other contractual arrangement between Sindata and its customers.

 

 

2. Definitions

For purposes of this Privacy Policy:

“Personal Data” means information relating to an identified or identifiable individual.

“Data Controller” means a party that determines the purposes and means of the processing of Personal Data.

“Data Processor” means a party that processes Personal Data on behalf of and according to the instructions of a Data Controller.

“Usage Data” means information collected automatically when you access or use the Website, such as technical information regarding your device, browser, IP address, pages visited, and similar information.

“Website” means the Sindata corporate website accessible at www.sindata.net.

 

3. Personal Data We Collect

Depending on how you interact with us, we may collect the following categories of Personal Data:

 

A. Information You Provide Directly

This may include:

  • name;
  • company or organization name;
  • job title or position;
  • email address;
  • telephone or mobile number;
  • country or location;
  • information contained in your inquiry or correspondence with us;
  • information provided when requesting a product demonstration or quotation;
  • information provided when applying for employment; and
  • other information you voluntarily provide to us.

We will only request information that is reasonably necessary for the relevant purpose.

 

B. Information Collected Automatically

When you access the Website, certain technical information may be collected automatically, which may include:

  • IP address;
  • browser type and version;
  • operating system;
  • device type;
  • pages visited;
  • date and time of access;
  • referring website or source; and
  • other technical or diagnostic information necessary for Website security, operation, and improvement.

4. Cookies and Similar Technologies

We may use cookies and similar technologies on the Website to:

  • ensure the Website functions properly;
  • remember certain preferences;
  • understand how visitors use the Website;
  • improve Website performance and user experience; and
  • support Website security.

Where required by applicable law, we will obtain the appropriate consent before using non-essential cookies or similar technologies.

You may also manage or disable cookies through your browser settings. Disabling certain cookies may affect the functionality of some parts of the Website.

Where applicable, information regarding the specific cookies used on the Website may be provided through a separate Cookie Notice or cookie-management mechanism.

 

5. How We Use Personal Data

Depending on the circumstances, we may process Personal Data for the following purposes:

  • to respond to inquiries, requests, or communications;
  • to provide information about our products and services;
  • to arrange product demonstrations, meetings, or other business communications;
  • to establish and manage business relationships;
  • to perform or take steps necessary to enter into contracts;
  • to provide customer and technical support;
  • to communicate important information regarding our products, services, or contractual relationship;
  • to send marketing or promotional communications where permitted by applicable law and, where required, with your consent;
  • to recruit and evaluate job applicants;
  • to operate, maintain, secure, and improve our Website and information systems;
  • to detect, prevent, and investigate fraud, misuse, security incidents, or other unlawful activities;
  • to comply with applicable legal and regulatory obligations;
  • to establish, exercise, or defend legal claims; and
  • for other purposes permitted by applicable law.

 

6. Legal Basis for Processing

Where applicable under UU PDP and other relevant data protection laws, we process Personal Data based on one or more lawful grounds, including:

  • your consent;
  • the performance of a contract or steps taken at your request prior to entering into a contract;
  • compliance with legal obligations;
  • protection of vital interests;
  • performance of tasks in the public interest or exercise of lawful authority, where applicable; and
  • other lawful grounds permitted under applicable law.

Where we rely on your consent, you may withdraw your consent at any time, subject to applicable legal and contractual limitations.

Withdrawal of consent does not affect the lawfulness of processing carried out before the withdrawal.

 

7. Disclosure and Sharing of Personal Data

We may disclose or provide access to Personal Data where reasonably necessary for the purposes described in this Privacy Policy, including to:

 

Service Providers

We may engage third-party service providers to support our business and Website operations, such as hosting providers, IT and security providers, communication providers, analytics providers, and other professional service providers.

 

Where such service providers process Personal Data on our behalf, we will take reasonable steps to ensure that appropriate contractual, organizational, and technical safeguards are in place and that Personal Data is processed only for authorized purposes.

 

Business Partners

Where appropriate and permitted by applicable law, we may share limited Personal Data with business partners in connection with legitimate business activities, products, or services.

 

Corporate Transactions

Personal Data may be disclosed or transferred in connection with a merger, acquisition, restructuring, financing, sale of assets, or other corporate transaction involving Sindata, subject to applicable law.

 

Legal and Regulatory Requirements

We may disclose Personal Data where required or permitted by applicable law, regulation, court order, or lawful request from a competent government authority.

 

Protection of Rights and Security

We may disclose Personal Data where reasonably necessary to protect the rights, property, safety, or security of Sindata, our customers, users, or other persons, or to prevent or investigate suspected unlawful activity.

We do not sell Personal Data to third parties.

 

8. International Transfers

Some of our service providers or business partners may process or store Personal Data outside Indonesia.

Where Personal Data is transferred across jurisdictions, Sindata will take appropriate measures as required by applicable law to ensure that the transfer and subsequent processing are subject to appropriate privacy, security, and contractual safeguards.

 

9. Retention of Personal Data

We retain Personal Data only for as long as reasonably necessary to fulfil the purposes for which it was collected, to maintain our business and contractual relationships, to comply with applicable legal or regulatory obligations, to resolve disputes, and to establish, exercise, or defend legal claims.

 

Retention periods may vary depending on the type of Personal Data, the purpose for which it is processed, applicable legal requirements, and contractual obligations.

 

Sindata maintains appropriate retention and disposal practices for Personal Data and other information records within the scope of our information security and information management processes.

 

When Personal Data is no longer required, we will take reasonable steps to delete, securely destroy, or anonymize it in accordance with applicable law, contractual requirements, and our internal policies and procedures.

 

10. Security and Protection of Personal Data

We take appropriate technical and organizational measures to protect Personal Data against unauthorized access, alteration, disclosure, loss, destruction, or other unlawful processing.

 

These measures are implemented through our Information Security Management System (ISMS) and relevant information security policies, procedures, and controls.

 

Our ISMS is designed to protect the confidentiality, integrity, and availability of information and to support compliance with applicable legal, regulatory, and contractual requirements.

 

Sindata is committed to maintaining and continually improving its information security practices based on identified risks, applicable requirements, and evolving information security threats.

 

However, no method of transmission or electronic storage can be guaranteed to be completely secure.

 

11. Privacy, Legal, Regulatory, and Contractual Compliance

Sindata identifies and maintains requirements relating to information security, privacy, and protection of Personal Data that arise from applicable laws, regulations, regulatory requirements, and contractual obligations.

 

These requirements are considered within our Information Security Management System and relevant policies, procedures, risk assessments, contractual arrangements, and technical and organizational controls.

 

Where Sindata processes Personal Data as a Data Processor on behalf of a customer, applicable privacy and information-security obligations may also be governed by the relevant customer agreement and/or data processing agreement.

 

12. Your Privacy Rights

Subject to applicable laws and regulations, you may have rights in relation to your Personal Data, including the right to:

  • obtain information regarding the processing of your Personal Data;
  • access your Personal Data;
  • correct or update inaccurate or incomplete Personal Data;
  • request deletion or destruction of Personal Data, where permitted by law;
  • request restriction of certain processing;
  • object to certain processing, where applicable;
  • withdraw consent where processing is based on consent;
  • obtain or request portability of Personal Data where applicable; and
  • submit a complaint concerning the processing of your Personal Data.

These rights are subject to applicable legal exceptions and limitations.

 

If your request relates to Personal Data that Sindata processes as a Data Processor on behalf of one of our hotel customers, please contact the relevant hotel or customer first. Sindata will reasonably assist the relevant Data Controller in handling such requests in accordance with applicable law and our contractual arrangements.

 

13. Third-Party Websites

The Website may contain links to websites or services operated by third parties.

 

Those websites and services are not controlled by Sindata, and their privacy practices may differ from ours.

 

We recommend that you review the applicable privacy policy of any third-party website before providing Personal Data to it.

 

14. Children’s Privacy

Our corporate Website is intended primarily for business and professional users.

 

We do not knowingly seek to collect Personal Data from children through the Website where such collection is not appropriate or permitted by applicable law.

 

If you believe that a child has provided Personal Data to us in circumstances where such collection was not appropriate, please contact us using the details below.

 

15. Changes to This Privacy Policy

We may update this Privacy Policy from time to time to reflect changes in our business, Website, technology, applicable laws, regulatory reuirements, or privacy practices.

 

When we make material changes, we may provide an appropriate notice through the Website or other reasonable means.

 

The “Last Updated” date at the top of this Privacy Policy indicates when the Privacy Policy was most recently updated.

 

16. Contact Us

If you have questions, concerns, or requests relating to this Privacy Policy or the processing of your Personal Data by Sindata, please contact:

 

PT Supranusa Sindata
Jl. Bukit Gading Raya
Perkantoran Gading Bukit Indah Blok O No. 3–5
Jakarta 14240 – Indonesia

Email: info@sindata.net

 

When submitting a privacy request, please provide sufficient information for us to identify the request and respond appropriately.

 

PT Supranusa Sindata
Privacy Policy – Last Updated: August 24, 2026