For the purpose of the Information and Electronic Transaction Law (No. 11 of 2008) (the “Law”) and Personal Data Protection in Electronic System Regulation 2016 (No. 20 of 2016) (the “Regulation”), we have designated the following individual as our representative to ensure compliance with the Regulation:
Name of representative:
Data Privacy Protection Officer
The Plaza Office Tower, 21st
Jalan M.H. Thamrin Kav. 28-30
1. DATA CONTROLLERS IN RESPECT OF BMW INDONESIA
a. Dealers, unless stated otherwise, are independent businesses and not part of the BMW Group, but operate using the BMW brand under license to sell and service BMW vehicles.
2. PERSONAL DATA WE MAY COLLECT ABOUT YOU.
a. We may obtain personal data about you (such as your name, postal address, email address, telephone number, national registration identity card number, credit card number and expiry date, financial details (e.g. income, expenses and/or credit history), employment details (e.g. occupation, directorships and other positions held, employment history, salary and/or benefits)) whenever you visit or use our website or complete any of our forms (both online and off line).
b. For example, we will obtain your personal data when you register to use the website, send us feedback, post material, contact us for any reason, sign up for a service, enter a competition, purchase goods or services.
d. Occasionally we may receive information about you from other sources (such as credit reference agencies) which we will add to the information which we already hold about you in order for us provide the goods and services, improve and personalize our service to you.
e. If you are under 18, please do not provide us with any of your information unless you have the permission of your parent or guardian to do so.
3. HOW WE USE YOUR PERSONAL DATA.
We will use your personal data for the purposes described in the privacy notice that was given to you at the time your data were obtained. These purposes may include:
- To help us identify you and any accounts you hold with us.
- To fulfil your request of rendering goods or services which you sign up for by providing us with your information.
- Research, statistical analysis and behavioral preferences.
- Customer profiling and analyzing your purchasing preferences.
- Marketing – please see “Marketing and Opting Out” section below.
- Fraud and criminal activities prevention and detection.
- Billing and order fulfillment.
- Credit scoring and credit checking – please see “Credit Checking” section below.
- Customizing this website and its contents to your particular preferences.
- To notify you of any changes to this website or to our goods or services which may affect you.
- Security vetting.
- Improving our services.
- Where the use is necessary to enter into or perform our contract with you.
- Where the use is necessary to comply with our legal obligations.
- Where the use is necessary in the national interest.
- Where the use is necessary for any investigation or legal proceedings.
We may monitor and record communication with you (such as telephone conversations and emails) for the purposes of quality assurance, training, fraud prevention and compliance of applicable laws and regulations.
5. MARKETING AND OPTING OUT
We may share your personal data with organizations which are our business partners and we or they may contact you (unless you have asked us or them not to do so) by mail, telephone, SMS, text/picture/video message, fax, email, etc. about our products, services, promotions, special offers, charitable causes which may be of interest to you. If you prefer not to receive any further direct marketing communications from us or our business partners, you can opt out at any time. Please see further at “Your Rights” section below.
6. DISCLOSURE OF YOUR PERSONAL DATA
We may disclose your personal data to:
a. Other companies within our group.
b. Our agents and service providers (e.g. providers of web hosting or maintenance services).
c. Credit reference agents – please see “Credit Checking” section below.
d. Law enforcement agencies in connection with any investigation to help prevent unlawful activity.
e. Our business partners in accordance with the “Marketing and Opting Out” section above.
7. CREDIT CHECKING
To enable us and other companies in our group to make credit decisions about you and other members of your household and for fraud prevention and money laundering purposes, we may search files of credit reference and fraud prevention agencies (who will record the search). We may disclose information about how you conduct your account to such agencies and your information may be linked to records relating to other people living in the same address with whom you are financially linked. Other credit grantors may use this information to make credit decisions about you and the people with whom you are financially associated, as well as for fraud prevention, debtor tracing and money laundering purposes.
8. OVERSEAS TRANSFER
9. KEEPING YOUR DATA SECURE
a. We will use technical and organizational measures to safeguard your personal data, for example:
• Access to your account is controlled by password and username which are unique to you.
• We store your personal data on secured servers.
b. Whilst we will use all reasonable efforts to safeguard your personal data, you acknowledge that the use of the Internet is not entirely secure and for this reason we cannot guarantee the security or integrity of any personal data which is transferred from you or to you via the Internet.
10. HOW LONG WE KEEP YOUR PERSONAL DATA FOR
We shall cease to retain your personal data if the purpose for which that personal data was collected is no longer being served by retention of the personal data, or retention of such personal data is no longer necessary for our business or legal purposes.
11. INFORMATION ABOUT OTHER INDIVIDUALS
If you give us information on behalf of someone else, you confirm that the other person has appointed you to act on his/her behalf and has agreed that you can:
• Give consent on his/her behalf to the processing of his or her personal data.
• Receive on his/her behalf any privacy notices.
• Give consent to the transfer of his/her personal data abroad.
• Give consent to the processing of his or her sensitive data, e.g. health information.
• Keep track of the items stored in your shopping basket and take you through the checkout process.
• Recognize you whenever you visit this website (this speeds up your access to the site as you do not have to log on each time).
• Obtain information about your preferences, online movements and use of the internet.
• Carry out research and statistical analysis to help improve our content, products and services and to help us better understand our visitor/customer requirements and interests.
• Target our marketing and advertising campaigns and those of our partners more effectively by providing interest-based advertisements that are personalized to your interest.
• Make your online experience more efficient and enjoyable.
e. We will work with third party suppliers who may also set cookies on our website, for example (Facebook, Twitter, You Tube and Adobe Flashplayer which we use to display video content). These third party suppliers are responsible for the cookies they set on our site. If you want further information please go to the website of the relevant third party.
f. If you do not want to accept cookies, you can change your browser settings so that cookies are not accepted. If you do this, please be aware that you may lose some of the functionality of this website.
13. YOUR RIGHTS
a. You have the right to request access to personal data which we may process about you. If you wish to exercise this right you should:
• Put your request in writing by downloading and filling up the following Access Request Form.
• Include proof of your identity and address (e.g. a copy of your driving license, passport, or national registration identity card, with the irrelevant personal information redacted).
• Specify the personal data you want access to including any account or reference numbers where applicable.
b. You have the right to require us to correct any inaccuracies in your data. If you wish to exercise this right you should:
• Put your request in writing by downloading and filling up the following Correction of Personal Data Request Form.
• Provide us with enough information to identify you (e.g. registration details, with the irrelevant personal information redacted).
• Specify the information which is incorrect or outdated and what it should be replaced with.
c. You also have the right to ask us to stop processing your personal data for certain purposes. If you wish to exercise this right you should:
• Put your request in writing by downloading and filling up the following Withdrawal of Consent Request Form.
• Provide us with enough information to identify you (e.g. registration details).
d. If your objection is not to direct marketing in general, but to direct marketing by a particular channel (e.g. email or telephone), please specify the channel to which you are objecting.
e. Your exercise of these rights is subject to certain exemptions pursuant to the Regulation. Upon receiving and verifying your request, we shall endeavor to respond to your request within thirty (30) days. In the event we need more time to verify and fulfill your request, we shall inform you of the additional time needed via the contact information you provided in the respective e-mail.
14. SALE OF BUSINESS
If the business of BMW Indonesia is sold or integrated with another business, your details may be disclosed to our advisers and any prospective purchasers and their advisers and will be passed on to the new owners of the business.
15. YOUR CONSENT
17. OUR CONTACT DETAILS
We welcome your feedback and questions. You may contact us via any of the following manner:
Data Privacy Protection Officer – BMW Indonesia
Address: The Plaza Office Tower, 21st Floor
Jalan M.H. Thamrin Kav. 28-30