Privacy Notice
How PT IJI HOME GROUP collects, uses and protects personal data submitted through ijihomegroup.com.
Last updated: 13 August 2026. This notice applies to this website. Bookings completed on a booking engine or a payment page operated by a third party are governed by that provider’s own notice as well as this one.
Who we are
The controller of your data
This website is operated by PT IJI HOME GROUP, a limited liability company incorporated in the Republic of Indonesia, operating from Kutuh, Kecamatan Kuta Selatan, Badung Regency, Bali 80361, Indonesia. Our full registration particulars, including the company registration number and registered address, are available on request to the contact address below.
Under Indonesian Law No. 27 of 2022 on Personal Data Protection (Undang-Undang Pelindungan Data Pribadi, “UU PDP”) we act as the data controller for the personal data described here. Where the EU General Data Protection Regulation applies to a visitor by virtue of Article 3(2) GDPR, we act as controller within the meaning of that Regulation as well.
Data protection contact: [email protected]. We have assessed our processing against Article 53 UU PDP and concluded that a mandatory Data Protection Officer is not triggered: our core activity is hotel and villa operation rather than large-scale regular and systematic monitoring, and we do not process special-category or criminal data on a large scale. We have nonetheless designated a named person responsible for data protection matters, reachable at that address, and we will appoint a formal officer if the scale or nature of our processing changes.
What we collect
Only what a request requires
We collect personal data in three ways: you give it to us in a form, your browser transmits it automatically, and — only with your permission — analytics tools record how you use the site.
Data you give us
| Form | Data collected | Why |
|---|---|---|
| Contact | Name, email, topic, message | To answer your enquiry |
| Reservation & waitlist | Name, email, phone, dates, unit type, number of guests | To respond about a stay or to notify you when bookings open |
| Management enquiry | Name, company, email, phone, project stage, number of keys, property location, comment | To assess whether we can operate your property and reply with a scope |
| Travel trade | Name, agency, partner type, market, email, phone, expected model, comment | To set up a partnership and quote |
Data your browser sends
- IP address — recorded in server and security logs, and used to rate-limit form submissions so the forms cannot be abused.
- User agent, referring page and requested URL — recorded in server logs.
- A strictly necessary session and security identifier — set when you submit a form, to protect against cross-site request forgery.
Data collected only with consent
If you accept analytics cookies, Google Analytics 4 and Microsoft Clarity record which pages you visit, how long you stay, how you scroll and where you click, and — in the case of Clarity — a reconstructed recording of the session. Analytics is off until you accept, and declining changes nothing about how the site works for you.
We do not collect payment card data on this website. Payments are handled on the systems of our booking engine and payment provider, under their own security certification. We never see or store a full card number. We do not knowingly collect special-category data — health, religion, biometrics, political opinion — and ask that you do not submit any in a free-text field.
Legal basis
Why each use is lawful
| What we do | Basis under UU PDP | Basis under GDPR (where applicable) |
|---|---|---|
| Answer an enquiry or a booking request | Art. 20(2)(b) — performance of, or steps prior to, a contract at your request | Art. 6(1)(b) |
| Waitlist notifications | Art. 20(2)(a) — your consent | Art. 6(1)(a) |
| Analytics and heatmaps | Art. 20(2)(a) — your consent | Art. 6(1)(a) |
| Server logs, rate limiting, abuse prevention | Art. 20(2)(f) — our legitimate interest in keeping the service secure | Art. 6(1)(f) |
| Accounting and tax records of a concluded contract | Art. 20(2)(c) — compliance with a legal obligation | Art. 6(1)(c) |
Where we rely on consent you may withdraw it at any time, and withdrawal does not affect processing carried out before it. Where we rely on legitimate interest you may object, and we will stop unless we can demonstrate compelling grounds that override your rights.
Retention
How long we keep it, and then what
| Category | Retention period | Then |
|---|---|---|
| Enquiry and correspondence | 24 months from our last contact with you about it | Deleted |
| Waitlist entry | Until you withdraw, or 36 months without a response from you | Deleted |
| Records of a concluded booking or contract | 10 years, as required of company records under Indonesian Law No. 8 of 1997 | Deleted |
| Server and security logs | 30 days | Overwritten |
| Database backups | 30 days on a rolling cycle | Overwritten |
| Consent records | For the life of the consent plus 3 years, as evidence that it was validly given | Deleted |
| Analytics data | 14 months in Google Analytics; up to 30 days for Clarity recordings | Deleted by the provider |
Where a retention period is set by law, that period prevails over the shorter ones above. Where a dispute or a legal claim is live, the relevant records are retained until it is finally resolved.
Who else sees it
Processors and recipients
We do not sell personal data, we do not trade it, and we do not disclose it for anyone else’s marketing. We share it only with the providers that operate this website and our own communications, each bound by a written processing agreement that restricts them to our instructions:
| Provider | Role | Processing location |
|---|---|---|
| DigitalOcean, LLC | Website and database hosting | Singapore |
| Cloudflare, Inc. | Content delivery, TLS termination, protection against attack | Global edge network, including Singapore |
| Telegram FZ-LLC | Internal notification of a new enquiry to our team | United Arab Emirates / global |
| Google LLC | Google Analytics 4 — only if you accept analytics cookies | United States |
| Microsoft Corporation | Clarity heatmaps and session recordings — only if you accept analytics cookies | United States |
We also disclose personal data where we are legally required to: to a court, a regulator or a law enforcement body acting within its powers. We assess every such demand before responding, we require it in writing, and we disclose only the minimum the demand covers.
International transfer
Data that leaves Indonesia
Our servers are in Singapore, and some of the providers listed above process data in the United States and elsewhere. That makes those transfers cross-border transfers under Article 56 UU PDP and, where the GDPR applies, transfers under Chapter V.
We rely on the following, cumulatively rather than in the alternative, so that a transfer remains lawful even if one mechanism is later found wanting:
- Contractual safeguards. Every provider is engaged under terms incorporating the European Commission’s Standard Contractual Clauses, or its own equivalent data protection addendum offering a comparable standard of protection.
- Your consent. Analytics providers in the United States receive nothing at all unless you have accepted analytics cookies, which constitutes explicit consent to that transfer.
- Necessity for the contract. Hosting and delivery of the site you requested cannot be performed without transfer to the infrastructure that serves it.
- Data minimisation. IP anonymisation is enabled in Google Analytics and Google advertising signals are disabled, so the data transferred is reduced before it leaves.
You may ask us for a copy of the safeguards applying to any specific transfer, and we will provide it.
Your rights
What you can require of us
Under UU PDP and, where it applies, the GDPR, you may:
- Obtain confirmation and a copy of the personal data we hold about you, and information about how it is processed.
- Correct data that is inaccurate, and complete data that is incomplete.
- Delete your data, where we have no overriding legal obligation to keep it.
- Restrict or object to processing, including any processing based on our legitimate interest.
- Withdraw consent at any time, without giving a reason.
- Receive your data in a portable form, and have it transmitted to another controller where technically feasible.
- Not be subject to a decision based solely on automated processing. We take no such decisions.
- Claim compensation for damage caused by processing that breached the law.
Write to [email protected]. We answer a request for access within 3 × 24 hours where Article 30 UU PDP requires it, and every request in any event within 30 days, extendable once by a further 30 days for a genuinely complex request — in which case we tell you inside the first 30 days why.
We may need to confirm who you are before we act, and we will ask only for what is necessary to do that. Exercising any of these rights is free of charge; we reserve the right to charge a reasonable fee only for a manifestly unfounded or repetitive request, and we will say so before doing anything.
If you are not satisfied with our response you may complain to the competent supervisory authority: in Indonesia, the authority established under UU PDP, whose functions are currently administered through the Ministry of Communication and Digital Affairs (Kementerian Komunikasi dan Digital); in the European Economic Area, the supervisory authority of your country of residence, place of work or the place of the alleged infringement.
Security
How we protect it, and what happens if that fails
- All traffic is encrypted in transit with TLS, and the site is served only over HTTPS.
- Administrative access is served only over HTTPS and limited to named accounts held by our own team. The XML-RPC interface is disabled and user enumeration is blocked.
- The origin server accepts traffic only from our content delivery network, and administrative ports are closed to the public internet.
- Access to personal data is limited to staff who need it for the task in front of them.
- The database and our application code are backed up nightly to storage separate from the web root, and backups are retained on a rolling 30-day cycle.
- Form submissions are rate-limited and screened for automated abuse.
No system is perfectly secure. If a breach of personal data occurs, we will notify you and the supervisory authority within 3 × 24 hours of becoming aware of it, as Article 46 UU PDP requires, and within 72 hours where the GDPR applies — telling you what happened, what data was involved, what we are doing about it, and what you can do to protect yourself.
Children
Who this site is for
This website is directed at adults. We do not knowingly collect personal data from anyone under 18 through it, and we ask that children do not submit forms here.
Under Article 25 UU PDP, processing the data of a child requires the consent of a parent or guardian. Where a booking involves children — a cot, an extra bed, the ages of a family travelling — that information is given to us by the adult making the booking, on the basis of their parental responsibility. If you believe a child has given us personal data directly, write to [email protected] and we will delete it.
Changes
How you will know
We may update this notice as our processing changes or as the law develops. The date at the top always reflects the current version. Where a change materially affects your rights or the purposes for which we use your data, we will say so prominently on the site before it takes effect, and — where the law requires consent for the change — we will ask for it rather than assume it.
Questions about anything in this notice: [email protected].
