Data Processing Agreement
Last updated: July 7, 2026
This Data Processing Agreement (“DPA”) supplements the Terms of Service between PT Kelola Kamar Dengan Teknologi (“BIND Room”, “we”, “Processor”) and the property or organization using the service (“Customer”, “you”, “Controller”). It governs how we process personal data — in particular your guests’ data — on your behalf, in line with Indonesia’s Personal Data Protection Law (Law No. 27 of 2022, “PDP Law”) and, where applicable, the EU General Data Protection Regulation (“GDPR”).
This document is provided for transparency and is not legal advice. It may be updated as our services and applicable regulations evolve.
1.Background and application
When you use BIND Room to run your property, you enter personal data about your guests, team, and business into the platform. For that data, you decide the purposes and means of processing, so you act as the Controller and we act as your Processor. This DPA sets out our obligations in that role. It forms part of, and is subject to, the Terms of Service.
2.Roles of the parties
- You are the Controller of guest data and other personal data you enter into the platform; we process it as your Processor, only on your instructions.
- We are the Controller of your account data (the people who sign up and manage the account) and of usage and technical data, as described in our Privacy Policy.
- Each party complies with the data protection laws that apply to it.
3.Scope, term, and precedence
This DPA applies for as long as we process personal data on your behalf, and ends when processing ends. If there is a conflict, this DPA prevails over the rest of the Terms on data-protection matters. Details of the processing are in Schedule A.
4.Our processing obligations
- We process personal data only on your documented instructions, including as given through your use of the platform’s features, unless required by law (in which case we will inform you where permitted).
- We do not sell personal data and do not use guest data for our own purposes.
- We ensure personnel authorized to process the data are bound by confidentiality.
- We will tell you if, in our reasonable opinion, an instruction breaches applicable data-protection law.
5.Security measures
We maintain appropriate technical and organizational measures to protect personal data, and rely on the certified security of our infrastructure providers. Current measures include:
- Encryption of data in transit (HTTPS/TLS).
- Role-based access control and per-property permissions, so users only see what they are authorized to.
- Authentication via secure tokens and HTTP-only, secure session cookies.
- Rate limiting, security HTTP headers, and input validation against abuse.
- Activity and audit logging of key actions.
- Card payment data for subscriptions is handled by PCI-DSS compliant gateways (Midtrans, Xendit); we do not store raw card numbers.
- File storage (including identity documents) on a reputable cloud storage provider with access controls; hosting, database, and backups on established cloud providers.
These measures may evolve with technology, provided the overall level of security is not materially reduced.
6.Personal data breach notification
We will notify you without undue delay after becoming aware of a personal data breach affecting data we process for you, and will provide the information you reasonably need to meet your own notification duties. Under the PDP Law, notification to affected data subjects and the authority is generally required within 3×24 hours; the GDPR expects notification within 72 hours where it applies.
7.Sub-processing
You authorize us to engage the sub-processors listed on our Sub-processors page to help deliver the service (for example, cloud hosting, file storage, the channel manager, payment gateways, and notification services). We impose data-protection obligations on each sub-processor that are no less protective than this DPA, and we remain responsible for their performance.
We will give reasonable prior notice of any new sub-processor. If you have a reasonable data-protection objection, you may raise it, and if it cannot be resolved you may terminate the affected service.
8.Assistance and cooperation
- We will help you respond to data-subject requests (access, rectification, erasure, restriction, objection, portability), taking into account the nature of the processing and the tools available in the platform.
- If a data subject contacts us directly about data we process for you, we will forward the request and await your instructions.
- We will provide reasonable assistance with data protection impact assessments and consultations with authorities where you cannot reasonably do so yourself.
- We will notify you of binding requests from authorities relating to your data, unless legally prohibited.
9.International data transfers
Some of our sub-processors process data outside Indonesia. Where personal data is transferred across borders, we apply the safeguards required by the PDP Law and, for personal data protected by the GDPR, appropriate transfer mechanisms such as the EU Standard Contractual Clauses.
10.Return and deletion of data
During the term, you can access, export, and delete data through the platform. After termination, you may export your data for a limited period, after which we will delete or anonymize it, except where retention is required by law or held in routine backups (which are protected and expire on a rolling basis).
11.Audit and inspection
On reasonable written request, and no more than once a year unless required by law or after a breach, we will provide information reasonably necessary to demonstrate our compliance with this DPA, subject to confidentiality.
12.Liability
Each party’s liability under this DPA is subject to the limitations and exclusions of liability set out in the Terms of Service.
13.Governing law
This DPA is governed by the laws of the Republic of Indonesia, without prejudice to mandatory data-protection rights that data subjects may have under the GDPR or other applicable laws.
14.Schedule A — Description of processing
- Subject matter and duration: processing of personal data to provide the BIND Room platform, for the duration of your subscription.
- Nature and purpose: hosting, storing, organizing, transmitting, and displaying data to operate reservations, channel management, guest records and documents, finance, staff, notifications, and reporting.
- Categories of data subjects: your guests; your owners, staff, and users; and your business contacts.
- Categories of personal data: identity and contact details; reservation and stay data; financial and transaction records; communications; technical and device data; and staff attendance data (including clock-in location).
- Special / sensitive categories: identity documents such as national ID (KTP) and passport, and precise location data captured for staff attendance. You are responsible for having a lawful basis for these.
15.Schedule B — Sub-processors
The categories of sub-processors, their purpose, and processing locations are listed on our Sub-processors page and form part of this DPA. The names of the specific providers behind each category are available to you on request, subject to a confidentiality agreement.
16.Contact
For DPA requests or to sign a countersigned copy, contact privacy@bindroom.com — PT Kelola Kamar Dengan Teknologi, Jl. Pulau Saelus I, Kel. Sesetan, Kec. Denpasar Selatan, Kota Denpasar, Bali 80223, Indonesia.