Version: 1.1.0-2026-05-16 · Effective: 2026-05-16
Bukujanji Privacy Policy
Version: 1.1.0
Effective Date: 16 May 2026
1. Introduction
Bukujanji ("we") respects your privacy and is subject to Law No. 27 of 2022 on Personal Data Protection (UU PDP), PP 71/2019, Permenkominfo 5/2020, and sound international privacy practice. This policy explains what data we collect, how we process it, with whom we share it, and the rights you have as a data subject.
Data Controller: PT Bukujanji Indonesia, Jakarta.
Data Protection Officer (DPO): dpo@bukujanji.com.
2. Data We Collect
2.1 Identity and contact data
- Name, email address, WhatsApp number, country code, city, profile photo.
- For Organizer Owners: KTP (national ID number, name, address), selfie photo, NPWP (if applicable), bank account details.
- For Participants booking on behalf of a child: child's name, date of birth, gender, relation to the booker.
2.2 Transaction and booking data
- Booking history for events/packages, payment status, refund history, promo codes used.
- Check-in records (QR scan timestamp), reviews you submit.
- Payment instrument data (card number, VA) is not stored on our servers — it is processed and stored by Midtrans in line with PCI-DSS standards.
2.3 Device and usage data
- IP address, device type, OS, browser, locale, push token (OneSignal).
- Pages visited, actions taken, timestamps.
- Cookies and similar technologies (see Cookie Policy).
2.4 Communication data
- The content of messages you send to customer service, history of broadcast emails we send to you, and your notification preferences.
2.5 Health declaration data
- For classes that require it (e.g. yoga, sports), you may be asked to fill out a short health declaration. This is not a medical record; it is stored on the booking record as basic information for the Organizer Owner.
3. Lawful Basis for Processing
Per Article 20 UU PDP, we process your data on the following bases:
- Explicit consent — when you check a consent box at signup/booking.
- Performance of contract — to deliver the booking service you requested.
- Legal compliance — for tax, audit, and lawful orders.
- Legitimate interest — for platform security, fraud prevention, and product improvement.
You may withdraw consent at any time; see Section 7.
4. How We Use Data
- Process bookings, payments, refunds, and settlements.
- Send booking confirmations, event reminders (email + push), and receipts.
- Allow Organizer Owners to manage their event rosters (they see the name, email, and phone of participants who booked their event).
- Display public reviews with masked names (e.g. "Sari W.").
- Detect fraud and maintain platform integrity.
- Aggregate analytics for product improvement (not individual targeting).
- Opt-in only marketing communications (new-organizer broadcasts, promos) — you can unsubscribe at any time.
5. Data Sharing With Third Parties
We share data on a limited, contractually-bound (DPA) basis with:
- The Organizer Owner of an event you booked: name, email, phone, health declaration, participant identity (for roster + check-in). They do not receive your booking history with other organizers.
- Midtrans for payment processing.
- Iris by Midtrans for disbursement to Organizer Owners / Outlets.
- AWS (S3, RDS, SES) as infrastructure provider — data is kept in Asia-Pacific regions (Singapore/Jakarta) wherever practical.
- OneSignal for push notifications.
- Meta (WhatsApp Business API) for transactional messaging when enabled.
- Lawful authorities when there is a valid court order, police summons, or other lawful request.
We do not sell your personal data to third parties for their own commercial purposes.
6. Data Retention
- Active account data: kept while the account is active.
- Transaction records: 10 years per tax law.
- Audit and security logs: 2 years.
- Data you request deletion of: deleted within 30 working days, except for legally mandated retention (flagged as "anonymized" and no longer used for personal profiling).
- Encrypted backups: may contain your data for up to 90 days post-deletion, then overwritten by the backup rotation cycle.
7. Data Subject Rights (Articles 5–14 UU PDP)
You have the right to:
- Access — see the data we hold about you.
- Correction — request correction of inaccurate/outdated data.
- Erasure — request deletion of your account and associated data (subject to the Section 6 exceptions).
- Portability — request a copy of your data in a common format (JSON/CSV).
- Restriction — ask us to pause processing of certain data while a request is investigated.
- Withdrawal of consent — withdraw consent for optional processing (marketing notifications, etc.).
- Complaint to authority — file a complaint with Komdigi (Personal Data Protection Supervisor) if our response is unsatisfactory.
How to exercise: email dpo@bukujanji.com with identity proof. We respond within 3×24 working hours per UU PDP standards.
8. Data Security
- TLS 1.2+ for all connections.
- Encryption-at-rest for databases (AWS RDS encryption).
- Bcrypt hashing for passwords (Organizer Owner / Customer login).
- Limited internal access with role-based permissions + audit logs.
- Periodic security testing and an informal bug-bounty.
- Material security incidents will be notified to affected data subjects and to Komdigi within 3×24 hours per Article 46 UU PDP.
9. Minors
The Platform is not intended for users under 18 as standalone account holders. If an event participant is a child, the booking must be made by a parent/guardian aged 18+ on the child's behalf (the "book for a child" feature). Child data stored is limited to name, date of birth, and gender — used only for the relevant event roster.
10. Cross-Border Transfer
If we need to transfer data outside Indonesia (e.g. backup servers, analytics vendors), we ensure the destination country has an equivalent level of protection or rely on Standard Contractual Clauses (SCC) as the legitimacy mechanism under Article 56 UU PDP.
11. Changes to This Policy
Material updates will be communicated via email + in-app banner 14 days before they take effect. The latest version is always available at /legal/privacy-policy.
12. Contact
DPO: dpo@bukujanji.com
Customer service: cs@bukujanji.com
Mail: PT Bukujanji Indonesia, Jakarta.