{"id":3,"date":"2025-06-17T09:53:22","date_gmt":"2025-06-17T09:53:22","guid":{"rendered":"https:\/\/bodystudiobali.com\/?page_id=3"},"modified":"2026-04-28T07:36:00","modified_gmt":"2026-04-28T07:36:00","slug":"privacy-policy","status":"publish","type":"page","link":"https:\/\/bodystudiobali.com\/nl\/privacy-policy\/","title":{"rendered":"Privacy Policy"},"content":{"rendered":"<h1>Privacy Policy<\/h1>\n<p><strong>Body Studio Bali<\/strong> \u2014 operated by <strong>PT New Beginnings Retreat<\/strong><\/p>\n<p>Effective date: 28 April 2026 Version: 1.0 (English)<\/p>\n<blockquote><p>This English text is provided for the convenience of international clients. The Bahasa Indonesia version of this Privacy Policy is the legally controlling version in accordance with Law of the Republic of Indonesia No. 24 of 2009 (UU 24\/2009). In case of any inconsistency between the two versions, the Bahasa Indonesia version prevails.<\/p><\/blockquote>\n<hr>\n<h2>1. Who we are (Data Controller)<\/h2>\n<p>The Data Controller for personal data processed in connection with <strong>bodystudiobali.com<\/strong> and the services offered at the premises of Body Studio Bali is:<\/p>\n<blockquote><p><strong>PT New Beginnings Retreat<\/strong>, trading as Body Studio Bali Uluwatu St No.184, Ungasan, South Kuta, Badung Regency, Kuta Selatan, 80361, Bali, Indonesia Email: info@bodystudiobali.com WhatsApp: +62 822-2160-0336 Indonesian business classification: SPA \/ Salon Kecantikan (KBLI). Registration details available on request.<\/p><\/blockquote>\n<p>Questions about this Privacy Policy or about your data can be sent to <strong>info@bodystudiobali.com<\/strong>.<\/p>\n<h2>2. Scope and applicable law<\/h2>\n<p>This Privacy Policy applies to:<\/p>\n<ul>\n<li>your use of the website <strong>bodystudiobali.com<\/strong>;<\/li>\n<li>bookings made online, by WhatsApp, by telephone, or in person;<\/li>\n<li>services delivered at our premises;<\/li>\n<li>the Health Intake &amp; Informed Consent Form you complete and sign on first visit and before each new service type;<\/li>\n<li>our hiring and recruitment processes (including any application form on our website).<\/li>\n<\/ul>\n<p>We process personal data in accordance with:<\/p>\n<ul>\n<li><strong>Law of the Republic of Indonesia No. 27 of 2022 on Personal Data Protection<\/strong> (&#8220;UU PDP&#8221; \/ Indonesian PDP Law);<\/li>\n<li><strong>Law of the Republic of Indonesia No. 8 of 1999 on Consumer Protection<\/strong> (UU 8\/1999), to the extent applicable;<\/li>\n<li>the <strong>EU General Data Protection Regulation 2016\/679 (GDPR)<\/strong>, where it applies to clients located in the European Economic Area or the United Kingdom; and<\/li>\n<li>all other applicable Indonesian laws and regulations.<\/li>\n<\/ul>\n<h2>3. Categories of personal data we collect<\/h2>\n<p>We collect and process the following categories of personal data, depending on how you interact with us.<\/p>\n<h3>3.1 Identification and contact data<\/h3>\n<ul>\n<li>full name, date of birth, sex, nationality;<\/li>\n<li>passport \/ national ID number (for our records and for compliance with Indonesian regulation that may apply to certain bookings);<\/li>\n<li>address (your address while in Bali, or your home address);<\/li>\n<li>email address;<\/li>\n<li>mobile \/ WhatsApp number;<\/li>\n<li>emergency contact name and phone number.<\/li>\n<\/ul>\n<h3>3.2 Booking, transaction, and service-history data<\/h3>\n<ul>\n<li>the services, combos, and packages you book and receive;<\/li>\n<li>session dates, times, and the practitioner who served you;<\/li>\n<li>prices paid, payment method, payment-processor reference (we do <strong>not<\/strong> store full card numbers);<\/li>\n<li>vouchers and packages you hold and have used;<\/li>\n<li>any notes our practitioners record about your service preferences.<\/li>\n<\/ul>\n<h3>3.3 Health data (sensitive \/ specific category)<\/h3>\n<p>When you complete the <strong>Health Intake &amp; Informed Consent Form<\/strong>, you disclose health-related information including: medical conditions, current medications, pregnancy status, surgical history, implants and medical devices, allergies, and any other health information relevant to the service you are about to receive.<\/p>\n<p>Under Indonesian PDP Law, health data is <strong>specific personal data<\/strong> (&#8220;data pribadi yang bersifat spesifik&#8221;) and under GDPR it is a <strong>special category of personal data<\/strong>. We process it on a strict need-to-know basis (Section 5).<\/p>\n<h3>3.4 Photographs and audio-visual data<\/h3>\n<ul>\n<li>&#8220;before \/ after&#8221; photographs of treatment areas, <strong>only with your prior written, opt-in consent<\/strong> as recorded on the Intake &amp; Consent Form or on a separate consent form;<\/li>\n<li>security CCTV footage at the entrance of our premises, if applicable, retained for short periods.<\/li>\n<\/ul>\n<h3>3.5 Recruitment \/ job-application data<\/h3>\n<p>If you apply for a job with us through our website or by other means, we collect: name, age, marital status, email, phone, education, previous workplaces, area of residence, and any photo \/ CV you submit. This data is processed by our <strong>bsb-applications<\/strong> plugin and stored in our Supabase database (Section 7).<\/p>\n<h3>3.6 Website usage data<\/h3>\n<p>When you visit bodystudiobali.com we may collect:<\/p>\n<ul>\n<li>IP address, approximate geo-location, device and browser type, language preference;<\/li>\n<li>pages viewed, time spent, referring URL, search terms used to reach us;<\/li>\n<li>cookies and similar technologies (see Section 9).<\/li>\n<\/ul>\n<h3>3.7 Communication data<\/h3>\n<ul>\n<li>messages you send us via WhatsApp, email, our contact form, or social media;<\/li>\n<li>our written replies to you.<\/li>\n<\/ul>\n<h2>4. How we collect personal data<\/h2>\n<p>We collect personal data:<\/p>\n<ul>\n<li><strong>directly from you<\/strong> \u2014 when you fill in our website forms (booking, contact, hiring), make a booking by WhatsApp or telephone, attend the premises and complete the Intake &amp; Consent Form, or otherwise communicate with us;<\/li>\n<li><strong>automatically<\/strong> \u2014 when you visit bodystudiobali.com (cookies, server logs, analytics);<\/li>\n<li><strong>from third parties<\/strong> \u2014 for example, payment processors confirming a transaction, or referrals if you tell us a friend recommended us.<\/li>\n<\/ul>\n<h2>5. Why we process your data (purposes and legal basis)<\/h2>\n<div class=\"bsb-table-wrap\">\n<table>\n<thead>\n<tr>\n<th>Purpose<\/th>\n<th>Categories used<\/th>\n<th>Legal basis (UU PDP \/ GDPR)<\/th>\n<\/tr>\n<\/thead>\n<tbody>\n<tr>\n<td>Confirming and delivering a booking<\/td>\n<td>identification, contact, booking, health<\/td>\n<td>performance of a contract (Art. 20(2)(b) UU PDP \/ Art. 6(1)(b) GDPR)<\/td>\n<\/tr>\n<tr>\n<td>Pre-service health screening (Intake form)<\/td>\n<td>identification, health<\/td>\n<td>client&#8217;s explicit consent on the Intake &amp; Consent Form (Art. 20(2)(a) UU PDP \/ Art. 9(2)(a) GDPR)<\/td>\n<\/tr>\n<tr>\n<td>Issuing receipts, processing payments, and complying with tax \/ accounting law<\/td>\n<td>identification, transaction<\/td>\n<td>legal obligation (Art. 20(2)(c) UU PDP \/ Art. 6(1)(c) GDPR)<\/td>\n<\/tr>\n<tr>\n<td>Communicating with you about appointments, vouchers, and packages<\/td>\n<td>identification, contact, booking<\/td>\n<td>performance of a contract \/ our legitimate interest in operational communication<\/td>\n<\/tr>\n<tr>\n<td>Marketing communications (only if you have opted in)<\/td>\n<td>identification, contact<\/td>\n<td>your consent (Art. 20(2)(a) UU PDP \/ Art. 6(1)(a) GDPR), withdrawable at any time<\/td>\n<\/tr>\n<tr>\n<td>Publishing &#8220;before \/ after&#8221; photographs<\/td>\n<td>photographs<\/td>\n<td>your written, opt-in consent on the Intake &amp; Consent Form, withdrawable at any time<\/td>\n<\/tr>\n<tr>\n<td>Processing job applications<\/td>\n<td>recruitment data<\/td>\n<td>steps to enter into an employment contract \/ your consent<\/td>\n<\/tr>\n<tr>\n<td>Operating, securing, and improving our website<\/td>\n<td>usage data, cookies<\/td>\n<td>our legitimate interest in operating a functional website (subject to consent for non-essential cookies \u2014 Section 9)<\/td>\n<\/tr>\n<tr>\n<td>Defending or pursuing legal claims<\/td>\n<td>as relevant<\/td>\n<td>legitimate interest \/ establishment, exercise, or defence of legal claims<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<\/div>\n<p>We do <strong>not<\/strong> sell your personal data, and we do <strong>not<\/strong> use it for automated decision-making with legal or similarly significant effects on you.<\/p>\n<h2>6. Data sharing (recipients)<\/h2>\n<p>We share personal data only with the recipients listed below, on a need-to-know basis and under appropriate confidentiality and data-processing arrangements.<\/p>\n<ul>\n<li><strong>Our staff and beauty therapists<\/strong> \u2014 only the data necessary for them to deliver your service safely (name, booking, health intake).<\/li>\n<li><strong>Payment processors<\/strong> \u2014 to process payments. Card details are handled directly by the processor; we do not store card numbers.<\/li>\n<li><strong>WordPress \/ WooCommerce hosting provider<\/strong> \u2014 to host bodystudiobali.com.<\/li>\n<li><strong>Supabase, Inc.<\/strong> \u2014 provides the database that stores submissions from our hiring form (and may process other operational data). Supabase acts as our <strong>processor<\/strong>.<\/li>\n<li><strong>Email and messaging providers<\/strong> \u2014 to deliver booking confirmations and communications.<\/li>\n<li><strong>Tax, accounting, and legal advisers<\/strong> \u2014 to comply with Indonesian law and to defend legal claims, under professional confidentiality.<\/li>\n<li><strong>Public authorities<\/strong> \u2014 when required by Indonesian law or by a lawful request from a competent authority.<\/li>\n<\/ul>\n<p>We do <strong>not<\/strong> disclose your data to advertisers, brokers, or other third parties for their own marketing purposes.<\/p>\n<h2>7. International transfers<\/h2>\n<p>Some of our processors are based outside Indonesia. In particular, <strong>Supabase, Inc.<\/strong> (and the cloud infrastructure on which it relies) processes data outside Indonesia. Where personal data is transferred outside Indonesia, we apply the safeguards required by <strong>Article 56 of UU PDP<\/strong> and, for clients to whom GDPR applies, the safeguards required by <strong>Chapter V of GDPR<\/strong> (such as adequacy decisions, standard contractual clauses, or your explicit informed consent for the specific transfer).<\/p>\n<p>You may request more information about the transfer mechanism applicable to your data by writing to info@bodystudiobali.com.<\/p>\n<h2>8. Retention<\/h2>\n<p>We retain personal data only for as long as necessary for the purposes for which it was collected, and as required by applicable law:<\/p>\n<ul>\n<li><strong>Booking and transaction records<\/strong> \u2014 for the duration of our service relationship with you and thereafter for the period required by Indonesian tax, accounting, and consumer-protection law (typically up to 10 years for accounting records).<\/li>\n<li><strong>Health Intake &amp; Informed Consent Form data<\/strong> \u2014 for as long as you remain an active client and, after your last service, for the period required to defend possible legal claims, after which it is securely destroyed or anonymised.<\/li>\n<li><strong>Marketing-consent records and &#8220;before \/ after&#8221; photographs<\/strong> \u2014 until you withdraw your consent; once withdrawn, removed from active use within a reasonable period and from public-facing channels where reasonably practicable.<\/li>\n<li><strong>Job-application data<\/strong> \u2014 if you are not hired, for up to 12 months after the application, unless you ask us to delete it sooner; if you are hired, kept under our HR retention rules.<\/li>\n<li><strong>Website server logs and analytics<\/strong> \u2014 for short periods, typically not exceeding 14 months.<\/li>\n<\/ul>\n<p>After the applicable retention period, we securely delete or anonymise your data.<\/p>\n<h2>9. Cookies and similar technologies<\/h2>\n<p>bodystudiobali.com uses cookies and similar technologies to:<\/p>\n<ul>\n<li>make the site work (essential cookies \u2014 for example, session and security cookies);<\/li>\n<li>remember your preferences (functional cookies);<\/li>\n<li>understand how visitors use the site so we can improve it (analytics cookies, e.g. Google Analytics);<\/li>\n<li>enable embedded content from social media or video platforms when you choose to view it.<\/li>\n<\/ul>\n<p>Essential cookies are set automatically. <strong>Non-essential cookies (analytics, social-media embeds) are only set with your consent<\/strong> through our cookie banner. You can change or withdraw your consent at any time via the cookie banner or your browser settings. Blocking essential cookies may affect the functionality of the website.<\/p>\n<p>A more detailed Cookie Notice may be published in due course; until then, this Section sets out our cookie practice.<\/p>\n<h2>10. Your rights<\/h2>\n<p>Subject to the conditions and limitations in UU PDP and, where it applies, GDPR, you have the right to:<\/p>\n<ul>\n<li><strong>be informed<\/strong> about our processing of your personal data (this Privacy Policy);<\/li>\n<li><strong>access<\/strong> the personal data we hold about you;<\/li>\n<li><strong>correct<\/strong> inaccurate or incomplete data;<\/li>\n<li><strong>delete<\/strong> your data (&#8220;right to erasure&#8221;), subject to our legal retention obligations;<\/li>\n<li><strong>restrict<\/strong> or object to certain processing;<\/li>\n<li><strong>withdraw consent<\/strong> for any processing based on consent (such as marketing or photo publication) at any time, without affecting the lawfulness of processing carried out before withdrawal;<\/li>\n<li><strong>data portability<\/strong> \u2014 receive your data in a structured, commonly used, machine-readable format, where applicable;<\/li>\n<li><strong>lodge a complaint<\/strong> with the competent Indonesian supervisory authority for personal-data protection (and, for clients in the EU\/EEA, with your local data-protection authority).<\/li>\n<\/ul>\n<p>To exercise any of these rights, write to <strong>info@bodystudiobali.com<\/strong>. We will respond within 30 (thirty) days and may ask you to verify your identity before we act on your request.<\/p>\n<h2>11. How we keep your data secure<\/h2>\n<p>We apply reasonable organisational and technical safeguards to protect personal data against unauthorised access, loss, alteration, or disclosure. These include access controls (only authorised staff can access intake forms and booking data), secure storage of paper forms, encryption in transit for online communication, application passwords for our WordPress administration, and role-based access to our Supabase database.<\/p>\n<p>No system is perfectly secure. If we become aware of a personal-data breach that is likely to result in a high risk to your rights and freedoms, we will notify you and the competent authority as required by UU PDP and (where applicable) GDPR.<\/p>\n<h2>12. Children<\/h2>\n<p>Our services are not directed at children under 13. Clients between 13 and 18 are minors under our Terms of Use; their data is processed only with parental \/ guardian consent (Section 9 of the Terms of Use).<\/p>\n<h2>13. Changes to this Privacy Policy<\/h2>\n<p>We may update this Privacy Policy from time to time. The current version is the version published at bodystudiobali.com\/privacy-policy\/. For material changes, we will notify you at your next booking confirmation or by email.<\/p>\n<h2>14. Governing law and language precedence<\/h2>\n<p>This Privacy Policy is governed by the laws of the Republic of Indonesia. It is issued in English and in Bahasa Indonesia; the <strong>Bahasa Indonesia version is the legally controlling version<\/strong> in accordance with UU 24\/2009. The English version is provided for the convenience of international clients only.<\/p>\n<h2>15. Contact<\/h2>\n<blockquote><p><strong>PT New Beginnings Retreat \u2014 Body Studio Bali<\/strong> Uluwatu St No.184, Ungasan, South Kuta, Badung Regency, 80361, Bali, Indonesia Email: info@bodystudiobali.com WhatsApp: +62 822-2160-0336<\/p><\/blockquote>\n<hr>\n<p><em>End of Privacy Policy.<\/em><\/p>","protected":false},"excerpt":{"rendered":"<p>Privacy Policy Body Studio Bali \u2014 operated by PT New Beginnings Retreat Effective date: 28 April 2026 Version: 1.0 (English) This English text is provided for the convenience of international clients. The Bahasa Indonesia version of this Privacy Policy is the legally controlling version in accordance with Law of the Republic of Indonesia No. 24 [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":0,"parent":0,"menu_order":0,"comment_status":"closed","ping_status":"open","template":"","meta":{"_et_pb_use_builder":"","_et_pb_old_content":"","_et_gb_content_width":"","footnotes":""},"class_list":["post-3","page","type-page","status-publish","hentry"],"aioseo_notices":[],"_links":{"self":[{"href":"https:\/\/bodystudiobali.com\/nl\/wp-json\/wp\/v2\/pages\/3","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/bodystudiobali.com\/nl\/wp-json\/wp\/v2\/pages"}],"about":[{"href":"https:\/\/bodystudiobali.com\/nl\/wp-json\/wp\/v2\/types\/page"}],"author":[{"embeddable":true,"href":"https:\/\/bodystudiobali.com\/nl\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/bodystudiobali.com\/nl\/wp-json\/wp\/v2\/comments?post=3"}],"version-history":[{"count":2,"href":"https:\/\/bodystudiobali.com\/nl\/wp-json\/wp\/v2\/pages\/3\/revisions"}],"predecessor-version":[{"id":2575,"href":"https:\/\/bodystudiobali.com\/nl\/wp-json\/wp\/v2\/pages\/3\/revisions\/2575"}],"wp:attachment":[{"href":"https:\/\/bodystudiobali.com\/nl\/wp-json\/wp\/v2\/media?parent=3"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}