← Back to Home
GTA

PRIVACY POLICY

Indonesian PDP Law (No. 27/2022) & GDPR Benchmark

1. Scope & Data Controller Identification

PT GO TRAVELIST ASIA acts as the Data Controller governing all personal data collected through gotravelist.asia under Indonesian Law No. 27/2022 and regional privacy benchmarks.

2. Categories of Personal Data Collected

We collect essential traveler identities (name, email), ITU-T E.164 phone numbers, bank transfer receipts, and meta profile credentials upon authentication.

3. Lawful Bases for Processing

Data processing is conducted strictly to execute direct travel vouchers, satisfy statutory audit ledgers, and attribute creator referral commissions.

4. Zero-Data Selling & Direct Vendor Sharing

GTA never sells or monetizes personal data. Traveler contacts are transmitted strictly on a need-to-know basis to the specific verified operator fulfilling the service.

5. Data Retention & Automatic Purging

Completed transaction records are retained for five (5) fiscal years for tax compliance. Unsettled guest cart drafts are purged automatically after seven (7) days.

6. Client-Side Compression & Encryption

Uploaded bank mutation receipts and identity documents are scaled and compressed in-browser via HTML5 Canvas before TLS 256-bit transmission.

7. Web Storage Persistence

We utilize standard browser localStorage strictly for functional persistence: GTA_PREF_LANG, GTA_PREF_CURR, and GTA_LOCAL_WISHLIST.

8. Data Subject Rights (Right to be Forgotten)

Users hold enforceable rights to access, rectify, or request permanent profile erasure provided no active unsettled transactions remain.

9. Cross-Border Asian Data Transfers

Minimal logistical data may be processed across Asian boundaries to coordinate island pickups under binding contractual safety clauses.

10. Data Protection Officer (DPO) Inquiries

Statutory inquiries or erasure notices must be directed to our appointed DPO: dpo@gotravelist.asia.