Privacy Policy
Last updated: July 7, 2026
This Privacy Policy explains how PT Kelola Kamar Dengan Teknologi (“BIND Room”, “we”, “us”) collects, uses, shares, and protects personal data when you visit our website, create an account, or use the BIND Room platform. We handle personal data in line with Indonesia’s Personal Data Protection Law (Law No. 27 of 2022, the “PDP Law”) and, where it applies, the EU General Data Protection Regulation (“GDPR”).
This document is provided for transparency and is not legal advice. It may be updated as our services and applicable regulations evolve.
1.Who we are
BIND Room is a property management system operated by PT Kelola Kamar Dengan Teknologi, a company incorporated in Indonesia.
- Legal entity: PT Kelola Kamar Dengan Teknologi
- Business Identification Number (NIB): 3005260001633
- Registered office: Jl. Pulau Saelus I, Kel. Sesetan, Kec. Denpasar Selatan, Kota Denpasar, Bali 80223, Indonesia
- Contact: privacy@bindroom.com
2.Our role: controller and processor
Depending on the data, BIND Room acts either as a data controller (deciding why and how data is processed) or as a data processor (processing data on behalf of a property that uses BIND Room).
- Account data (the property owner and users who sign up): we are the controller.
- Guest data that a property enters into BIND Room (e.g. guest name, ID/passport, contact, reservations): the property is the controller and we are the processor, acting on its instructions.
- Usage and technical data (logs, analytics, device data): we are the controller.
3.Personal data we collect
- Account & identity data: name, email, phone, password, property and role.
- Guest data (entered by properties): guest name, contact, nationality, and identity documents such as ID card or passport — which may be sensitive personal data.
- Reservation & operational data: bookings, stays, tasks, staff attendance, messages, and reviews.
- Payment data: billing details and transaction records. Card payments are processed by certified gateways (Midtrans, Xendit); we do not store raw card numbers.
- Technical & device data: IP address, browser, device identifiers, cookies, and usage logs.
- Communications: messages you send to support and your preferences.
4.How we collect it
- Directly from you when you sign up, use the platform, or contact us.
- Automatically through cookies and similar technologies as you use the site and app.
- From third parties such as connected OTAs (Booking.com, Airbnb, Agoda, Expedia and others), payment gateways, and your property’s team.
5.Purposes and legal basis
We process personal data on one or more lawful bases: performance of a contract, consent, compliance with a legal obligation, and our legitimate interests.
- Provide, operate, and maintain the platform (contract).
- Process subscriptions, billing, and taxes (contract and legal obligation).
- Provide support and communicate about your account.
- Secure the service and prevent fraud and abuse (legitimate interest).
- Improve the product and understand usage through analytics (legitimate interest).
- Comply with legal, tax, and regulatory obligations.
- Send marketing where you have consented (you can opt out at any time).
7.International data transfers
Some of our providers may process data outside Indonesia. Where we transfer personal data across borders, we apply safeguards required by the PDP Law and, for data protected by the GDPR, appropriate mechanisms such as Standard Contractual Clauses.
8.Data retention
We keep account and usage data for as long as your account is active and afterwards only as required for legitimate business, accounting, and legal purposes, then delete or anonymize it. Guest data is retained according to the instructions of the property that controls it.
9.How we protect data
- Encryption of data in transit.
- Role-based access controls so users only see what they should.
- Card payments handled by PCI-DSS compliant gateways; we do not store raw card data.
- Ongoing monitoring and access logging.
No method of transmission or storage is completely secure, but we work to protect personal data using appropriate technical and organizational measures.
10.Your rights
Subject to applicable law, you have the right to access, correct, update, delete, restrict, or object to the processing of your personal data, to withdraw consent, to data portability, and to lodge a complaint with the relevant authority.
If your request concerns guest data held on behalf of a property, please contact that property (the controller); we will assist it as processor. To exercise your rights with us, email privacy@bindroom.com.
11.Data breach notification
If a personal data breach occurs that is likely to affect your rights, we will notify affected data subjects and the relevant authority as required by law (generally within 3×24 hours under the PDP Law).
12.Children’s data
The platform is not directed to children. Where a property records data of a guest who is a minor, that processing is under the property’s responsibility and lawful basis, including any required parental or guardian consent.
13.Changes to this policy
We may update this Privacy Policy from time to time. We will post the updated version here and revise the “last updated” date. Material changes will be communicated where appropriate.
14.Contact us
For any privacy question or to reach our data protection contact, email privacy@bindroom.com or write to PT Kelola Kamar Dengan Teknologi, Jl. Pulau Saelus I, Kel. Sesetan, Kec. Denpasar Selatan, Kota Denpasar, Bali 80223, Indonesia.