Tiêu chuẩn Bảo vệ Dữ liệu Toàn cầu cho Du khách VVIP
Tại PT. Komodo Explorer Indonesia (KEXI), quyền riêng tư của bạn là nền tảng của cơ sở hạ tầng dịch vụ của chúng tôi. Giao thức này mô tả cách chúng tôi bảo vệ danh kỹ số của bạn trong tất cả các khu vực pháp lý.
Chúng tôi tuân thủ các tiêu chuẩn toàn cầu cao nhất. Dù bạn là cư dân Liên minh Châu Âu (GDPR), California (CCPA), hay Indonesia (OJK/PDP), dữ liệu của bạn được xử lý với cùng sự bảo vệ quân đội.
Chúng tôi sử dụng Microsoft Clarity để hiểu rõ hơn cách bạn sử dụng trang web của chúng tôi. Clarity nắm bắt cách bạn tương tác với trang web của chúng tôi bằng cách sử dụng phát lại phiên và bản đồ nhiệt. Thông tin này giúp chúng tôi cải thiện trải nghiệm người dùng và xác định các điểm ma sát kỹ thuật. Dữ liệu được xử lý theo Tuyên bố Quyền riêng tư của Microsoft.
Chúng tôi chỉ thu thập những gì cần thiết cho một cuộc thám hiểm không gián đoạn: xác minh danh tính cho danh sách biển, yêu cầu chế độ ăn uống/y tế cho an toàn trên tàu, và điều phối thanh toán cho các chuyến thuê an toàn.
Dữ liệu của bạn được mã hóa khi nghỉ ngơi và khi truyền đi bằng các giao thức hàng đầu trong ngành. Cơ sở hạ tầng của chúng tôi được kiểm toán cho các tiêu chuẩn an toàn 'Thống trị Toàn cầu', đảm bảo không có truy cập trái phép.
Bạn duy trì chủ quyền tuyệt đối trên dữ liệu của mình. Bạn có quyền yêu cầu truy cập, sửa chữa, hoặc xóa hoàn toàn ('Quyền bị lãng quên') khỏi sổ đăng ký toàn cầu của chúng tôi bất cứ lúc nào.
To request deletion of the personal data we hold about you — including data collected through WhatsApp — please follow the instructions at https://www.komodoexplorer.com/data-deletion.html. You may also contact us directly using the details in the Privacy Contact section below.
Với sự đồng ý của bạn, chúng tôi chia sẻ một số định danh nhất định — email và/hoặc số điện thoại của bạn, đã được băm không thể đảo ngược (SHA-256) — với Google và Meta chỉ nhằm mục đích đo lường hiệu quả quảng cáo của chúng tôi (đo lường chuyển đổi), cùng với các định danh quảng cáo kỹ thuật như GCLID và fbclid. Việc này chỉ được thực hiện trên cơ sở sự đồng ý của bạn theo Luật Bảo vệ Dữ liệu Cá nhân của Indonesia (UU No. 27 of 2022) và các quy định GDPR hiện hành. Bạn có thể rút lại sự đồng ý bất cứ lúc nào thông qua biểu ngữ quyền riêng tư; việc rút lại chỉ có hiệu lực về sau và không ảnh hưởng đến dịch vụ, khả năng đặt chỗ hay giá cả của chúng tôi. Nếu bạn từ chối, chúng tôi sẽ không chia sẻ email hoặc số điện thoại của bạn với Google hay Meta.
Các hệ thống nghiệp vụ nội bộ của chúng tôi kết nối với Dịch vụ Google API — Google Ads, Google Analytics, Google Search Console và Google Drive/Google Sheets — thông qua ủy quyền OAuth an toàn do chính các tài khoản Google của công ty chúng tôi cấp. Dữ liệu được truy cập: số liệu thống kê chiến dịch quảng cáo, báo cáo phân tích trang web dạng tổng hợp, dữ liệu hiệu suất tìm kiếm và các bảng tính vận hành (chẳng hạn như lịch trình tàu) thuộc về tài khoản công ty của chúng tôi. Chúng tôi không truy cập, thu thập hoặc lưu trữ dữ liệu tài khoản Google của khách truy cập trang web hay khách hàng. Mục đích sử dụng dữ liệu: thông tin này chỉ được sử dụng để vận hành, đo lường và cải thiện các dịch vụ cũng như chiến dịch quảng cáo của chính chúng tôi, và không nhằm bất kỳ mục đích nào khác. Lưu trữ và bảo vệ: thông tin xác thực OAuth được lưu trữ phía máy chủ trong cấu hình hạn chế truy cập, chỉ được truyền qua các kết nối mã hóa (TLS) và không bao giờ bị để lộ trong mã phía máy khách; quyền truy cập được giới hạn cho các quản trị viên được ủy quyền. Chia sẻ: chúng tôi không bán, cho thuê hoặc chuyển giao dữ liệu người dùng Google cho bên thứ ba. Việc chúng tôi sử dụng thông tin nhận được từ Google API tuân thủ Google API Services User Data Policy (Chính sách Dữ liệu Người dùng của Dịch vụ Google API), bao gồm các yêu cầu Limited Use (Sử dụng Hạn chế) của chính sách này (developers.google.com/terms/api-services-user-data-policy). Bạn có thể thu hồi quyền truy cập này bất cứ lúc nào trong phần quyền của Tài khoản Google của mình (myaccount.google.com/permissions) hoặc bằng cách liên hệ info@komodoexplorer.com.
To operate our booking, communication, and payment services, we share limited personal data with the following third-party service providers, each for a specific purpose. Meta Platforms, Inc. operates the WhatsApp Business Cloud API channel you use when you message us on WhatsApp, and processes advertising identifiers (hashed email/phone, click identifiers) for ad conversion measurement described in Section 6. Cerebras Systems, Inc. (United States), an AI inference provider, may process WhatsApp message text to help our team draft or route a reply — see the Automated Processing and AI Assistance section below. Xendit (PT Xendit, Indonesia) and PayPal process your email address as part of creating and completing a payment for your booking. Brevo (formerly Sendinblue) sends transactional emails on our behalf, such as booking confirmations and account-related notices, using your name and email address. Google LLC, in addition to the Google API access described in Section 7, also maintains an off-site backup of our operational database — which may include your booking and message records — for disaster-recovery purposes; see the Backups section below. Cloudflare, Inc. provides content delivery, DNS, and security infrastructure in front of our website and WhatsApp integration, handling encrypted network traffic without independently storing your personal data for its own purposes. We do not sell your personal data to any third party. We enter into these relationships on the basis of performing our contract with you, our legitimate interest in operating and securing our services, or your consent for advertising measurement as described in Section 6 — consistent with Indonesia's Personal Data Protection Law (UU No. 27 of 2022) and, for EEA visitors, the GDPR. Some of these providers are located outside Indonesia, including in the United States. Where we transfer personal data internationally, we rely on each service provider's own data-protection commitments and contractual safeguards.
When you contact us through WhatsApp, we receive and store your phone number, profile name, and the content of your messages through the WhatsApp Business Cloud API, operated by Meta Platforms, Inc. We use this data to respond to your inquiry, manage your booking, and provide customer service; your conversation may be mirrored into our internal customer-relationship system so our team can see conversation history when assisting you. We do not currently apply a fixed maximum retention period to WhatsApp conversation history — it is retained as part of our customer-service and booking records unless you ask us to delete it. You can ask us to delete the data we hold about your WhatsApp conversations at any time (see Data Deletion Requests above); doing so does not delete your own copy of the conversation on your device, or Meta's own copy, which is governed by Meta's policies and managed separately through WhatsApp.
Some of your messages to us may be processed by an AI inference provider, Cerebras Systems, Inc. (United States), to help our team understand your request and draft or route a reply more quickly — for example, when a message does not match our standard automated responses, or to prepare a first-touch welcome message. This automated processing helps prepare a response; it does not make any decision that produces legal effects or similarly significantly affects you, such as accepting or rejecting a booking or setting a price, without a human being involved. Automated drafts are intended to support — not replace — our customer-service team, and a human is involved in your booking and in any decision that affects your reservation or its price.
We maintain regular backups of our operational database — which can include booking details and WhatsApp conversation records — for disaster-recovery purposes. These backups are stored in an access-restricted Google Drive folder used by our company, and we keep a limited number of recent backups, automatically removing older ones.
If you have questions about this policy or how we handle your personal data, or wish to exercise any of the rights described above, please contact PT Komodo Explorer Indonesia at info@komodoexplorer.com, or by mail at Jl. Kerta Dalem Sari IV No.2, Desa/Kelurahan Sidakarya, Kec. Denpasar Selatan, Kota Denpasar, Provinsi Bali, Kode Pos: 80224 (PT Komodo Explorer Indonesia, NIB 1805260128363).
PT. Komodo Explorer Indonesia © 2026. Maritime Excellence & Digital Sovereignty.