TABLE OF CONTENTS

 

INTRODUCTION

PART I: GENERAL PROVISIONS

  1. Definitions
  2. Scope
  3. Personal Data We Collect
  4. How We Collect Personal Data
  5. Purposes of Using Personal Data
  6. Legal Basis for Processing Personal Data
  7. Disclosure of Personal Data to Third Parties
  8. Cross-Border Transfer of Personal Data
  9. Storage and Retention of Personal Data
  10. Personal Data Security
  11. Rights of Personal Data Subjects
  12. Children's Privacy
  13. Data Protection Officer (DPO)

PART II: WEBSITE-SPECIFIC PROVISIONS

  1. Cookies and Website Tracking Technologies
  2. Web Analytics
  3. Special Website Features

PART III: MOBILE APPLICATION-SPECIFIC PROVISIONS

  1. Device Access Permissions (App Permissions)
  2. Push Notifications
  3. SDKs and Third-Party Services in the Application
  4. Local Data Storage on Devices
  5. Special Mobile Application Features
  6. App Store Platform Compliance
  7. Application Updates and Privacy Policy

PART IV: HOSPITALITY INDUSTRY-SPECIFIC PROVISIONS

  1. Guest Data During Stay
  2. CCTV and Physical Property Security
  3. Loyalty Program
  4. Bookings via Third Parties (OTA)
  5. Travel and Immigration Data

PART V: CLOSING PROVISIONS

  1. Amendments to the Privacy Policy
  2. Dispute Resolution
  3. Governing Law
  4. Contact Us

 

INTRODUCTION

PT Artotel Petualang Indonesia ("Artotel Wanderlust" or "we") is fully committed to protecting the privacy and security of the personal data of every user of our services. This Privacy Policy transparently explains how we collect, use, store, disclose, and protect your personal information when you use the Artotel Wanderlust website and mobile application.

This Privacy Policy is prepared and takes effect in accordance with the laws and regulations in force in Indonesia, including:

  • Law Number 27 of 2022 on Personal Data Protection ("PDP Law");
  • Law Number 11 of 2008 on Electronic Information and Transactions as amended by Law Number 19 of 2016 ("ITE Law");
  • Government Regulation Number 71 of 2019 on the Implementation of Electronic Systems and Transactions ("GR 71/2019");
  • Regulation of the Minister of Communication and Informatics Number 20 of 2016 on the Protection of Personal Data in Electronic Systems ("MOCI Regulation 20/2016");
  • Other applicable laws and regulations in force within the territory of the Republic of Indonesia.

By accessing the website and/or downloading and using the Artotel Wanderlust mobile application, you represent that you have read, understood, and agreed to all provisions of this Privacy Policy, including any amendments thereto.

If you do not agree to this Privacy Policy, please immediately discontinue use of the Artotel Wanderlust website and/or mobile application.

 

PART I: GENERAL PROVISIONS

Article 1
DEFINITIONS

In this Privacy Policy, the following terms shall have the meanings set out below:

TERM

DEFINITION

Personal Data

Any data about an individual, whether identified and/or identifiable, either on its own or in combination with other information, whether obtained directly or indirectly through electronic and/or non-electronic systems.

General Personal Data

Non-sensitive personal data, including full name, gender, nationality, religion, and/or personal data that, when combined, may identify an individual.

Specific Personal Data

Sensitive personal data, including health data and information, biometric data, genetic data, sexual life/orientation, political views, criminal records, children's data, personal financial data, and/or other data that may cause harm to the Personal Data Subject.

Personal Data Subject

An individual to whom Personal Data relates (in this Privacy Policy also referred to as "you" or "User").

Personal Data Controller

The party that determines the purposes of and controls the processing of Personal Data.

Personal Data Processor

The party that processes Personal Data on behalf of the Personal Data Controller.

Processing of Personal Data

Any activity involving Personal Data, whether automated or manual, including obtaining, collecting, processing, analyzing, storing, displaying, announcing, transmitting, disseminating, deleting, and/or destroying Personal Data.

User

Any person who accesses and/or uses the Artotel Wanderlust services through the website and/or mobile application.

Services

All products, features, content, and services provided by Artotel Wanderlust through the website (www.artotelwanderlust.com) and/or the Artotel Wanderlust mobile application.

Consent

A statement or action made in writing and/or recorded electronically, given freely, specifically, on an informed basis, and unambiguously by the Personal Data Subject.

DPO

Data Protection Officer, namely the party appointed by the Personal Data Controller to ensure compliance with Personal Data protection provisions.

Data Breach

A security incident resulting in the unlawful disclosure, access, alteration, loss, or destruction of Personal Data.

OTA

Online Travel Agent, namely a third-party online travel booking platform such as Booking.com, Agoda, Expedia, Traveloka, Tiket.com, and similar platforms.

SDK

Software Development Kit, namely a third-party software package integrated into the Artotel Wanderlust mobile application to provide certain functions.

PMS

Property Management System, namely the property management system used by the hotel to manage operations, reservations, and guest data.

 

Article 2
SCOPE

2.1  This Privacy Policy applies to all Processing of Personal Data carried out by Artotel Wanderlust in connection with the use of:

  • The official Artotel Wanderlust website, accessible via www.artotelwanderlust.com and all related subdomains;
  • The Artotel Wanderlust mobile application, available on the Google Play Store (Android) and Apple App Store (iOS);
  • Hotel booking and reservation services made through the Artotel Wanderlust digital platform;
  • The Artotel Wanderlust loyalty program;
  • Customer service and related communications.

2.2  This Privacy Policy does not apply to third-party websites or applications that may be linked to or integrated with our services. We are not responsible for the privacy practices of such third parties.

2.3  This Privacy Policy applies to all Users without exception, including hotel guests, customers making reservations, website visitors, and mobile application users.

 

Article 3
PERSONAL DATA WE COLLECT

3.1  General Personal Data

  1. Identity Data: 

    Full name as stated in identification documents;

    National Identity Card (KTP), passport, or other official identification document number;

    Date of birth and age;

    Gender;

    Nationality;

    Profile photo (if uploaded by the User).

  2. Contact Data: 

    Email address;

    Telephone/mobile phone number;

    Residential address;

    City, province, and country of domicile;

    Postal code.

  3. Account Data:

    Username;

    Password in encrypted form;

    Notification and communication preferences;

    Login history and account activity.

  4. Booking and Transaction Data:

    Room and hotel service booking history;

    Planned check-in and check-out dates;

    Room type and room preferences;

    Special requests;

    Additional guest data;

    Transaction and payment history;

    Booking reference and confirmation numbers;

    Booking status and change history.

  5. Preference and Usage Data:

    Travel and tourism preferences;

    Food, beverage, and allergy preferences;

    Language and currency preferences;

    Search history and preferred content;

    Reviews, ratings, and comments provided;

    Participation in programs or promotions.

  6. Technical Data:

    IP (Internet Protocol) address;

    Browser type, version, and operating system;

    Device type and identification (Device ID);

    Location (GPS) data, where permission is granted;

    Usage log data and session duration;

    Pages visited and referral source.

     

3.2  Specific Personal Data

Under certain circumstances and with your explicit consent, we may collect the following Specific Personal Data:

  • Health Data: information on allergies, accessibility needs, or medical conditions relevant to the comfort of the service;
  • Financial Data: bank account and credit/debit card information in masked or tokenized form as provided by the payment service provider;
  • Biometric Data: fingerprint or facial recognition data for application security features, where activated by the User.

 

Article 4
HOW WE COLLECT PERSONAL DATA

4.1  Information You Provide Directly:

  • User registration and account creation;
  • Room and hotel service booking process;
  • Completion of contact and customer service forms;
  • Participation in surveys, questionnaires, and loyalty programs;
  • Submission of reviews, ratings, and comments;
  • Participation in competitions, promotions, or prize programs;
  • Linking social media accounts to your Artotel Wanderlust account;
  • Communication via email, telephone, or live chat.

4.2  Information Collected Automatically:

  • Cookies, pixel tags, web beacons, and similar tracking technologies;
  • Server logs and technical data of your device;
  • Analytics SDKs within the mobile application;
  • Geographic location data, where permission is granted on the device;
  • Interaction data with push notifications.

4.3  Information from Third Parties:

  • Data from partner travel agents and OTA platforms;
  • Transaction confirmations from payment service providers;
  • Identity verification data from authorized institutions;
  • Publicly available information in accordance with applicable law.

Article 5
PURPOSES OF USING PERSONAL DATA

5.1  Provision and Management of Services:

  • Processing and confirming room and hotel service reservations;
  • Managing User accounts and transaction history;
  • Facilitating the check-in and check-out process, including mobile check-in;
  • Providing customer service and technical support;
  • Processing payments and refunds;
  • Sending booking confirmations, invoices, and electronic receipts;
  • Managing the loyalty program and reward points.

5.2  Improvement and Personalization of Services:

  • Analyzing User behavior to improve service quality;
  • Personalizing the User experience on the website and application;
  • Providing recommendations for relevant products, services, and content;
  • Developing new features, products, and services;
  • Conducting research, market analysis, and business development.

5.3  Communication and Marketing:

  • Sending information about bookings, changes, or cancellations;
  • Sending newsletters, promotions, and special offers (with consent);
  • Informing you of the loyalty program and exclusive member offers;
  • Sending post-stay customer satisfaction surveys;
  • Conducting personalized marketing communications.

5.4  Security and Legal Compliance:

  • Preventing, detecting, and investigating fraud or illegal activity;
  • Verifying User identity in accordance with applicable provisions;
  • Complying with applicable legal, regulatory, and reporting obligations;
  • Responding to official requests from government authorities or law enforcement;
  • Protecting the rights, property, and safety of all parties involved;
  • Resolving disputes and enforcing applicable agreements.

5.5  Internal Business Operations:

  • Managing relationships with business partners, vendors, and suppliers;
  • Conducting internal audits, risk management, and financial reporting;
  • Strategic planning and property portfolio development;
  • Insurance management, claims, and incident management.

Article 6
LEGAL BASIS FOR PROCESSING PERSONAL DATA

 

In accordance with Article 20 of the PDP Law, we process your Personal Data based on one or more of the following legal bases:

LEGAL BASIS

EXPLANATION

EXAMPLE OF APPLICATION

Consent
(Consent)

Processing based on explicit consent given by you freely, specifically, and on an informed basis.

• Sending marketing emails
• Use of non-essential cookies
• Processing of biometric data
• Sharing data for marketing purposes

Performance
of a Contract
(Contract)

Processing necessary to perform the agreement between you and Artotel Wanderlust.

• Processing of hotel reservations
• Payment processing
• Management of User accounts
• Provision of requested services

Legal
Obligation
(Legal Obligation)

Processing required by applicable laws and regulations.

• Tax compliance
• Reporting data to authorities
• Financial reporting obligations
• Immigration regulatory compliance

Legitimate Interest
(Legitimate Interest)

Processing for our legitimate interests, provided this does not prejudice your rights and interests.

• Fraud prevention
• Information system security
• Internal analytics
• Business risk management

 

Article 7
DISCLOSURE OF PERSONAL DATA TO THIRD PARTIES

7.1  We may disclose your Personal Data to the following categories of third parties, solely for the purposes set out in this Privacy Policy:

  1. Service Providers and Vendors:

    Technology and IT infrastructure service providers;

    Payment service and payment gateway providers (Midtrans, Xendit, Doku, and similar providers);

    Cloud computing service providers (AWS, Google Cloud, Microsoft Azure, and similar providers);

    Analytics, CRM, and digital marketing service providers;

    Communication, email delivery, and SMS service providers;

    Cybersecurity and anti-fraud service providers.

  2. Artotel Group of Companies:

    Affiliates, subsidiaries, and entities within the ARTOTEL group for internal operational and administrative purposes;

    Group management for consolidated reporting and strategic planning purposes.

  3. Business Partners:

    Hotels and properties within the Artotel Wanderlust partner network;

    Loyalty program partners with an official cooperation arrangement;

    Partners providing tourism activities, tours, and travel experiences;

    Travel agents and OTA platforms with an official agreement with us.

  4. Authorities and Law Enforcement:

    Government agencies, courts, or law enforcement officials where required by applicable law;

    Tax and financial authorities in accordance with reporting obligations;

    Immigration authorities for the reporting of foreign guest data in accordance with Indonesian immigration regulations.

  5. Other Parties in Corporate Transactions:

    Prospective buyers, successors, or partners in the event of a merger, acquisition, or corporate restructuring, subject to data confidentiality obligations.

     

7.2  Principles of Data Disclosure. Any disclosure of Personal Data to third parties is carried out having regard to the following principles:

  • Disclosure is made solely for the purposes set out in and in accordance with this Privacy Policy;
  • Third parties are required to maintain the confidentiality and security of Personal Data through a binding agreement;
  • We do not sell your Personal Data to any third party for commercial purposes;
  • Disclosure is carried out in accordance with applicable laws and regulations in Indonesia.

 

Article 8
CROSS-BORDER TRANSFER OF PERSONAL DATA

8.1  In conducting our business operations, your Personal Data may be transferred to, stored in, or processed in a country other than Indonesia. We ensure that any cross-border data transfer is carried out in accordance with Article 56 of the PDP Law, subject to the following requirements:

  • The destination country has a level of Personal Data protection equivalent to or higher than Indonesia;
  • Adequate protection mechanisms are applied, such as standard contractual clauses or data protection agreements;
  • Your consent is obtained where required by applicable legal provisions;
  • Cross-border data transfers are reported to the competent authority in accordance with the provisions of the PDP Law.

8.2  Your Personal Data may be transferred to countries where our service providers operate, including Singapore, the United States, and other countries. A complete list of destination countries for such transfers is available upon request to our DPO.

 

Article 9
STORAGE AND RETENTION OF PERSONAL DATA

9.1  Storage Location. Your Personal Data is stored on servers located in Indonesia and/or outside Indonesia as set out in Article 8 of this Privacy Policy, using secure and encrypted cloud infrastructure.

9.2  Retention Period. We retain your Personal Data for as long as necessary to fulfill the purposes set out in this Privacy Policy:

TYPE OF DATA

RETENTION PERIOD

BASIS

Active User Account Data

For as long as the account remains active + 5 years
after account closure

Legitimate Interest

Transaction & Booking Data

10 years

Tax Obligations

Guest Stay Data

5 years from check-out

Legal Obligation

Passport & Immigration Data

In accordance with applicable
immigration provisions

Legal Obligation

CCTV Recordings

30 - 90 days

Property Security

Marketing Communication Data

Until consent is withdrawn

Consent

Technical & System Log Data

1 year

System Security

Data for Dispute Resolution

Until the dispute is resolved
+ 5 years

Legitimate Interest

Data Retained under Legal Obligation

In accordance with applicable
laws and regulations

Legal Obligation

9.3  After the retention period expires or upon your valid request, we will securely delete or anonymize your Personal Data using methods that ensure the data cannot be recovered or re-associated with you.

 

Article 10
SECURITY OF PERSONAL DATA

 

10.1  Technical Security Measures. We implement the following technical security measures:

 

  • SSL/TLS encryption for data transmission and encryption of data at rest;
  • Tokenization of sensitive data such as payment card information;
  • Firewalls and intrusion detection/prevention systems (IDS/IPS);
  • Multi-factor authentication (MFA) for system and account access;
  • Regular penetration testing and vulnerability assessments;
  • 24/7 security system monitoring;
  • Local data encryption on mobile devices using Secure Enclave (iOS) and Android Keystore.

 

10.2  Organizational Security Measures:

  • Restriction of access to Personal Data based on the need-to-know and least-privilege principles;
  • Regular information security and data protection training programs for all employees;
  • Execution of non-disclosure agreements (NDAs) by all employees, contractors, and partners with access to data;
  • Implementation of comprehensive, documented information security policies and procedures;
  • Documented security incident response procedures that are tested on a regular basis.

 

10.3  Data Breach Procedure. In the event of a Personal Data breach that could give rise to a risk to your rights and freedoms, we will:

  • Conduct an investigation and immediate mitigation as soon as the incident is detected;
  • Notify you no later than 14 (fourteen) days from the date we become aware of the breach;
  • Report to the Minister administering government affairs in the field of personal data protection in accordance with the provisions of the PDP Law;
  • Take remedial and preventive steps to avoid the recurrence of similar incidents.

 

Article 11
RIGHTS OF PERSONAL DATA SUBJECTS

In accordance with Chapter VI of the PDP Law, you have the following rights in relation to your Personal Data:

11.1  Right to Information:

  • To obtain clear and transparent information regarding the identity of the Personal Data Controller, the legal basis, purposes, and manner of processing your Personal Data.

11.2  Right to Access Personal Data:

  • To request access to and obtain a copy of your Personal Data that we are processing, including information on how such data is used.

11.3  Right to Rectify Personal Data:

  • To request the correction or updating of Personal Data that is inaccurate, incomplete, or outdated.

11.4  Right to Erasure of Personal Data:

  • To request the deletion of Personal Data where the data is no longer needed, consent has been withdrawn, or the processing is unlawful, provided that this right may be limited by applicable legal obligations.

11.5  Right to Restrict Processing:

  • To request the restriction of Personal Data processing in certain situations, for example when you dispute the accuracy of the data or the lawfulness of the processing.

11.6  Right to Data Portability:

  • To receive your Personal Data in a structured, machine-readable format, and to transfer it to another data controller where technically feasible.

11.7  Right to Object to Processing:

  • To object to the processing of Personal Data for certain purposes, including direct marketing, profiling, and automated decision-making.

11.8  Right to Withdraw Consent:

  • To withdraw consent previously given at any time, without affecting the lawfulness of processing carried out prior to such withdrawal.

11.9  Right to Lodge a Complaint:

  • To lodge an objection regarding the processing of Personal Data with us and/or with the competent data protection authority.

11.10  Right to Account Deletion:

  • To request the deletion of your account together with all related Personal Data, subject to data retention requirements under applicable legal obligations.

11.11  How to Exercise Your Rights. To exercise the rights set out above, you may contact us through:

  • Account Settings in the Artotel Wanderlust application or website (for rights of access, rectification, and account deletion);
  • Email to the DPO: legal@artotelgroup.com;
  • Written letter to:

PT Artotel Rasa Indonesia

Jl. Bunga Mawar No. 42, Cipete Selatan, Cilandak,

Jakarta Selatan, DKI Jakarta 12410

We will respond to your request within a maximum of 30 (thirty) days from the date the request is received in full. We reserve the right to verify your identity before processing the request in order to protect the security of your Personal Data.

 

Article 12
CHILDREN'S PRIVACY

12.1  The Artotel Wanderlust services are not directed at children under the age of 18 (eighteen). We do not knowingly collect Personal Data from children without the consent of a parent or legal guardian.

12.2  If you are a parent or guardian accompanying a child staying at our hotel, the child's Personal Data is collected solely for hotel operational purposes (such as guest count and special needs) and is protected with the highest security standards.

12.3  If we become aware that we have collected Personal Data from a minor without valid consent, we will promptly delete such data. Parents or guardians may contact our DPO to report this matter.

 

Article 13
DATA PROTECTION OFFICER (DPO)

13.1  In accordance with Article 53 of the PDP Law, Artotel Wanderlust has appointed a Data Protection Officer (DPO) responsible for ensuring compliance with all Personal Data protection provisions.

13.2  The DPO is responsible for:

  • Monitoring compliance with the PDP Law and this Privacy Policy;
  • Providing advice and recommendations relating to data protection;
  • Serving as the point of contact between Artotel Wanderlust and Personal Data Subjects and the competent authorities;
  • Handling complaints and requests relating to Personal Data;
  • Conducting a data protection impact assessment (DPIA) where necessary;
  • Coordinating the response to data breach incidents.

13.3  DPO Contact Information:

INFORMATION

DETAILS

Name

Legal

Position

Data Protection Officer

Email

legal@artotelgroup.com

Phone

021 2781 2980

Address

Jl. Bunga Mawar No. 42, Cipete Selatan, Cilandak, Jakarta Selatan, DKI Jakarta 12410

Working Hours

Monday - Friday, 09:00 - 17:00 WIB

 

PART II: WEBSITE-SPECIFIC PROVISIONS

Article 14
COOKIES AND WEBSITE TRACKING TECHNOLOGIES

14.1  What is a Cookie? A cookie is a small text file stored on your device when you visit our website. Cookies help us recognize your device, remember your preferences, and provide a better, more personalized experience.

14.2  Types of Cookies We Use:

COOKIE TYPE

DESCRIPTION

EXAMPLE

CAN BE DISABLED?

Essential Cookies
(Strictly Necessary)

Required for the basic functioning of the website. Without these cookies, the website cannot function properly.

Session ID, login authentication, form security

NO

Functional Cookies
(Functional)

Remember your choices and preferences for a better experience.

Language, currency, location, and display theme preferences

YES

Analytics Cookies
(Analytics)

Collect anonymous usage data to understand how the website is used and to improve our services.

Google Analytics, Hotjar, click and scroll data

YES

Marketing Cookies
(Marketing)

Display relevant advertising and measure the effectiveness of our marketing campaigns.

Meta Pixel, Google Ads, retargeting ads

YES

Third-Party Cookies
(Third-Party)

Placed by our partners for various purposes in accordance with their own privacy policies.

Social media plugins, embedded content

YES

14.3  Cookie Management. You can manage your cookie preferences through:

  • The Cookie Banner displayed the first time you visit our website;
  • The Cookie Preference Center available at: [Cookie Settings Link];
  • Your browser settings to block or delete cookies manually.

14.4  Other Tracking Technologies. In addition to cookies, we also use:

  • Web Beacons/Pixel Tags: small transparent images used to track email and website page interactions;
  • Local Storage and Session Storage: to store user preferences locally in the browser;
  • Fingerprinting: technical device data used for security purposes and fraud prevention.

 

Article 15
WEB ANALYTICS

15.1  We use website analytics services to understand how Users interact with our website and to improve the quality of our services. The analytics services we use include:

SERVICE

PROVIDER

PURPOSE

OPT-OUT

Google Analytics

Google LLC

Analytics on website usage, User behavior, traffic sources

tools.google.com/dlpage/gaoptout

Google Tag Manager

Google LLC

Management of website analytics tags and scripts

Via cookie settings

15.2  Data collected by analytics services is generally aggregated and anonymous. However, certain analytics services may use cookies or similar technologies that collect data that can be linked to your device. We encourage you to read the privacy policy of each analytics service provider.

 

Article 16
SPECIAL WEBSITE FEATURES

16.1  Live Chat and Chatbot. Our website provides live chat and/or chatbot features for customer service. Conversations through these features may be recorded and stored for the purposes of service improvement and training.

16.2  Search Engine and Filters. Search and filter data you use on our website is collected anonymously to improve the relevance of search results and recommendations.

16.3  Social Media Integration. Our website may contain social media sharing buttons and plugins (such as Facebook, Instagram, Twitter/X). Such plugins may collect data about your visit in accordance with the privacy policy of the relevant social media platform.

 

PART III: MOBILE APPLICATION-SPECIFIC PROVISIONS

Article 17
DEVICE ACCESS PERMISSIONS (APP PERMISSIONS)

17.1  To carry out certain functions, the Artotel Wanderlust mobile application will request access permissions to features of your device. Full details of the permissions requested and their purposes are set out below:

PERMISSION

PURPOSE OF USE

ANDROID

iOS

MANDATORY?

Camera
(Camera)

Scanning QR codes for check-in, uploading profile photos, scanning identification documents

READ_MEDIA_IMAGES
CAMERA

NSCameraUsage
Description

Optional

Location
(Location)

Displaying nearby hotels, navigation to the hotel, location-based services

ACCESS_FINE_LOCATION
ACCESS_COARSE_LOCATION

NSLocationWhen
InUseUsage
Description

Optional

Notifications
(Notifications)

Booking confirmations, check-in/out reminders, special offers, booking updates

POST_NOTIFICATIONS

NSUserNotification
UsageDescription

Optional

Storage
(Storage)

Storing e-tickets, vouchers, photos, and offline content

READ_EXTERNAL_STORAGE
WRITE_EXTERNAL_STORAGE

NSPhotoLibrary
UsageDescription

Optional

Biometric
(Biometric)

Login using fingerprint or Face ID for account security

USE_BIOMETRIC
USE_FINGERPRINT

NSFaceID
UsageDescription

Optional

Bluetooth & NFC

Digital room key feature and contactless check-in

BLUETOOTH
NFC

NSBluetoothAlways
UsageDescription

Optional

Microphone
(Microphone)

Voice search feature and in-app customer service calls

RECORD_AUDIO

NSMicrophoneUsage
Description

Optional

Contacts
(Contacts)

Sharing booking details with friends or family members

READ_CONTACTS

NSContactsUsage
Description

Optional

Calendar
(Calendar)

Adding check-in and check-out schedules to the device calendar

READ_CALENDAR
WRITE_CALENDAR

NSCalendarsUsage
Description

Optional

17.2  All permissions are optional unless stated otherwise. Declining a permission will not prevent you from using the application's basic features, although certain specific features may not be available.

17.3  You may change permissions previously granted at any time through the Settings menu on your device, under Applications > Artotel Wanderlust > Permissions.

 

Article 18
PUSH NOTIFICATIONS

18.1  Types of Notifications. The Artotel Wanderlust application sends two categories of push notifications:

CATEGORY

TYPE OF NOTIFICATION

BASIS FOR SENDING

CAN BE DISABLED?

Transactional
Notifications

• Booking confirmations
• Check-in/check-out reminders
• Reservation changes/cancellations
• Payment confirmations
• Booking status updates

Performance of Agreement

Limited
(can be configured
by type)

Marketing
Notifications

• Special offers and promotions
• Loyalty program & rewards
• Hotel recommendations
• Flash sales and early bird offers
• Newsletter updates

User
Consent

YES
(fully)

18.2  Data Used for Push Notifications:

  • Unique device token for delivering notifications to your device;
  • Interaction data with notifications (opened, dismissed, or deleted);
  • Optimal time and frequency of delivery based on your preferences.

18.3  How to Manage Notifications. You can set your notification preferences through:

  • The Notification Settings menu within the Artotel Wanderlust application;
  • Notification settings on your device (Settings > Notifications > Artotel Wanderlust);
  • Contact our customer service to request manual notification settings.

 

Article 19
SDKs AND THIRD-PARTY SERVICES WITHIN THE APPLICATION

19.1  The Artotel Wanderlust mobile application integrates third-party Software Development Kits (SDKs) to provide certain functions. The list of SDKs used, along with their purposes and the data collected, is set out below:

SDK/SERVICE

PROVIDER

FUNCTION

DATA COLLECTED

Firebase Analytics

Google LLC

Application user analytics

User events, behavior,
device properties

Firebase Crashlytics

Google LLC

Crash and bug reporting

Stack traces, device info,
error logs

Firebase Cloud
Messaging (FCM)

Google LLC

Push notification delivery
(Android)

Device token, notification data

Apple Push
Notification Service

Apple Inc.

Push notification delivery
(iOS)

Device token, notification data

Google Maps SDK

Google LLC

Maps, navigation, and
hotel location search

Location data (where permitted)

Payment Gateway
(Midtrans/Xendit)

Midtrans/Xendit

Secure payment
processing

Transaction data (tokenized),
not raw card data

Facebook SDK

Meta Platforms Inc.

Analytics and retargeting

User ID, user behavior,
advertising data

Google Sign-In SDK

Google LLC

Login with Google account

Email, name, Google profile photo

Sign in with Apple

Apple Inc.

Login with Apple ID

Email (optional), Apple User ID

Adjust/AppsFlyer

Adjust GmbH /
AppsFlyer Ltd.

Marketing attribution and
installation analytics

Install source, event tracking,
IDFA/GAID

OneSignal

OneSignal Inc.

Push notification management
and in-app messaging

Device token, notification
behavior

Intercom/Zendesk

Intercom/Zendesk

Customer support and
in-app live chat

Conversation history,
User data

19.2  Each third-party SDK used is bound by a data processing agreement with us and is required to comply with equivalent security and privacy standards. We encourage you to read the privacy policy of each SDK provider for further information.

19.3  For iOS users specifically, if you choose not to grant tracking permission via the App Tracking Transparency (ATT) framework, we will respect that choice and will not use the IDFA for personalized advertising purposes.

 

Article 20
LOCAL DATA STORAGE ON DEVICES

20.1  Types of Data Stored Locally. The Artotel Wanderlust application stores the following data locally on your device:

  • Application cache data to improve performance and the offline experience;
  • Authentication tokens in encrypted form to maintain your login session;
  • User preferences and settings;
  • Downloaded e-tickets, vouchers, and booking documents;
  • Encrypted digital room key data;
  • Search history and content saved for offline features.

20.2  Security of Local Data. All sensitive data stored locally on your device is protected using:

  • AES-256 encryption for sensitive data stored in local storage;
  • iOS Secure Enclave and Android Keystore for storing biometric data and cryptographic keys;
  • Automatic deletion of authentication tokens when you log out.

20.3  Deletion of Local Data. You can delete the application's local data through:

  • The Application Settings menu > Clear Cache;
  • Device Settings > Applications > Artotel Wanderlust > Clear Data;
  • Uninstalling the application from your device will automatically delete all local data.

 

Article 21
SPECIAL MOBILE APPLICATION FEATURES

21.1  Mobile Check-In and Check-Out:

  • Data collected: photo of identification document, verification selfie (where required), time and location of the digital check-in process;
  • Uploaded identity data is stored in encrypted form and used solely for verification purposes;
  • Digital check-in process data is stored in accordance with the applicable retention period.

21.2  Digital Room Key:

  • The application uses Bluetooth Low Energy (BLE) and/or NFC technology to function as a digital room key;
  • Room access data (door open/close times) is recorded in the hotel's security system;
  • Digital key data is encrypted and valid only for the duration of your stay;
  • Room door access data is retained for security and investigative purposes where necessary.

21.3  In-App Chat and Virtual Concierge:

  • Conversation history with hotel staff and/or the chatbot is stored to improve service quality;
  • Messages sent may be processed by the AI/chatbot system to provide automated responses;
  • Conversation history is available in your account and may be deleted at your request;
  • Conversation content is not shared with third parties unless required by law.

21.4  In-App Room Service and F&B:

  • Room service and food/beverage orders placed through the application are stored in your transaction history;
  • Food, beverage, and allergy preferences you save are used to personalize services;
  • Order data is forwarded to the relevant hotel's PMS.

21.5  Map and Navigation Features:

  • Your GPS location data is used only while the map feature is active and where permission has been granted;
  • We do not permanently store your location history;
  • Location data is not shared with third parties for marketing purposes.

21.6  QR Code and Barcode Scanner:

  • The camera is used to scan QR codes during check-in, facility access, and voucher verification;
  • Data read from QR codes is processed solely for the purposes of the ongoing transaction and is not permanently stored.

 

Article 22
APP STORE PLATFORM COMPLIANCE

22.1  Google Play Store - Data Safety Section. In accordance with Google Play Store policy, the following is a summary of the data collected and shared by the Artotel Wanderlust application:

DATA CATEGORY

COLLECTED?

SHARED?

DELETABLE?

Personal Information
(Name, Email, Phone)

YES

YES
(Service Providers)

YES

Financial Info
(Purchase History)

YES

YES
(Payment Gateway)

YES

Location
(Approximate Location)

YES
(Optional)

NO

YES

In-App Messages

YES

NO

YES

App Info
(Crash Logs)

YES

YES
(Firebase)

NO

Device
Identifiers

YES

YES
(Analytics)

NO

App Activity
(Search History)

YES

NO

YES

22.2  Apple App Store - Privacy Nutrition Label. In accordance with Apple App Store policy, the following is the data categorization for the Artotel Wanderlust application:

APPLE CATEGORY

DATA TYPE

DESCRIPTION

Data Used to
Track You

Device Identifiers,
Usage Data

Used for personalized
advertising
(can be disabled
via ATT)

Data Linked
to You

Name, Email, Phone,
Purchase History,
Location, Messages,
Financial Info

Linked to your
identity within your
ARTOTEL account

Data Not
Linked to You

Crash Logs, Diagnostic
Data, Anonymous
Usage Data

Collected to
improve application
performance

22.3  App Tracking Transparency (ATT). For users of iOS 14.5 and above, our application will request tracking permission via the ATT framework before using the IDFA (Identifier for Advertisers) for personalized advertising purposes. You are free to decline this request without affecting the application's core functionality.

 

Article 23
APPLICATION UPDATES AND PRIVACY POLICY

23.1  When an application update contains significant changes to this Privacy Policy, we will notify you through:

  • An in-app notification displayed the first time you open the application after the update;
  • A push notification to users who have enabled notifications;
  • A notification email to your registered email address;
  • Release notes on the application's page on the Google Play Store and Apple App Store.

23.2  For policy changes that require re-consent, the application will display a consent screen that you must accept before you can continue using the application.

23.3  We strongly recommend that you always use the latest version of the Artotel Wanderlust application to receive the latest security and privacy features.

 

PART IV: HOSPITALITY INDUSTRY-SPECIFIC PROVISIONS

Article 24
GUEST DATA DURING STAY

24.1  During your stay at an Artotel Wanderlust property, we collect and process the following data to ensure your comfort and safety:

  1. Property Access and Movement Data:

    Room key card and digital room key usage data (access times);

    Access data for hotel areas and facilities (gym, spa, swimming pool, lounge);

    Elevator usage data and access to certain areas requiring verification;

    Hotel property entry and exit times.

  2. Consumption and Service Data:

    Minibar and in-room dining consumption data;

    Room service orders;

    Use of laundry and dry cleaning facilities;

    Use of business facilities (meeting rooms, printers, etc.);

    Billing and consumption data during the stay.

  3. Special Request Data:

    Pillow, bed, and room temperature preferences;

    Special room decoration requests (birthdays, anniversaries, honeymoons);

    Special accessibility needs;

    Room preferences (floor, view, etc.);

    Special housekeeping requests.

  4. Spa and Wellness Data:

    Type of spa treatment selected;

    Health data relevant to treatment safety (blood pressure, skin condition, etc.);

    Therapist preferences;

    Spa visit history for service personalization.

  5. In-Room Technology Usage Data:

    Room telephone usage data;

    Hotel Wi-Fi connection data (usage volume, not content);

    In-room interactive TV and streaming service usage data;

    Smart room control system usage data.

     

24.2  Data collected during your stay is used solely to:

  • Provide and improve the quality of hotel services;
  • Process accurate billing and payments;
  • Ensure the safety of guests and the hotel property;
  • Personalize services for your next visit (where you have given consent);
  • Comply with applicable regulations.

 

Article 25
CCTV AND PHYSICAL PROPERTY SECURITY

25.1  CCTV Installation. To maintain the safety of guests, staff, and the hotel property, Artotel Wanderlust installs closed-circuit television (CCTV) cameras in certain areas within the hotel property.

25.2  Areas Where CCTV Is Installed:

  • Lobby and reception area;
  • Hotel entrances and exits;
  • Parking and basement areas;
  • Corridors and common hallways on each floor;
  • Public facilities (gym, swimming pool, restaurant, lounge);
  • Operational areas (kitchen, storage, laundry);
  • Elevators and emergency staircase areas.

25.3  Areas WITHOUT CCTV:

  • Guest rooms (including the area in front of the room door facing into the room);
  • Public bathrooms and toilets;
  • Changing rooms in the spa and gym areas;
  • Prayer rooms;
  • Other areas that could infringe on guest privacy.

25.4  Use of CCTV Recordings:

  • CCTV recordings may only be accessed by authorized hotel security personnel and management;
  • Recordings are used for security purposes, incident investigation, and property protection;
  • Recordings may be provided to law enforcement officials where required by applicable law;
  • Recordings are not used for marketing purposes or shared with unauthorized parties.

25.5  Retention of CCTV Recordings. CCTV recordings are stored for 30 (thirty) to 90 (ninety) days depending on the property's policy, after which the recordings are automatically deleted unless required for an ongoing investigation.

25.6  CCTV Notification. The presence of CCTV cameras is communicated to guests through:

  • CCTV notice signs/stickers installed in monitored areas;
  • Information contained in this Privacy Policy;
  • Provisions in the guest registration form.

 

Article 26
LOYALTY PROGRAM

26.1  Data Collected in the Loyalty Program. If you register for the Artotel Wanderlust loyalty program, we collect and process the following data:

  • Membership data: member number, join date, and membership tier/level;
  • History of reward point accumulation and redemption;
  • Stay and transaction history that generates points;
  • Selected reward preferences;
  • Interaction data with the loyalty program (emails opened, offers clicked);
  • Data of partnering loyalty program affiliates.

26.2  Use of Loyalty Program Data:

  • Managing your membership account and points balance;
  • Processing the accumulation and redemption of reward points;
  • Sending program information, exclusive member offers, and membership updates;
  • Conducting analysis to improve the loyalty program and provide relevant offers;
  • Sharing data with loyalty program partners in accordance with your consent.

26.3  If you choose to terminate your loyalty program membership, any unredeemed points balance will be forfeited in accordance with the applicable loyalty program terms and conditions. Your membership data will be retained in accordance with the applicable retention period.

 

Article 27
BOOKINGS VIA THIRD PARTIES (OTA)

27.1  If you make a booking through an OTA platform (such as Booking.com, Agoda, Expedia, Traveloka, Tiket.com, and similar platforms), your data will be processed by that OTA in accordance with its own privacy policy before being forwarded to us.

27.2  Data We Receive from OTAs:

  • Guest full name and contact information;
  • Booking details (dates, room type, number of guests);
  • Special requests submitted through the OTA;
  • Payment status (payment confirmation without raw card data);
  • Other information you provide to the OTA during the booking process.

27.3  Responsibility for Data Processing:

  • The OTA is responsible for the processing of your data before such information is forwarded to us;
  • Artotel Wanderlust is responsible for the processing of data we carry out after receiving information from the OTA;
  • To exercise your privacy rights regarding data processed by an OTA, please contact the relevant OTA directly.

27.4  We encourage you to book directly through the Artotel Wanderlust website or application to have full control over your Personal Data and enjoy the best prices we offer.

 

Article 28
TRAVEL AND IMMIGRATION DATA

28.1  Guest Data Reporting Obligation. In accordance with Indonesian immigration regulations, all hotels are required to report guest data, in particular foreign national (WNA) guests, to the competent authorities. The data reported includes:

  • Full name as stated in the passport;
  • Passport number and issuing country;
  • Nationality;
  • Date of birth;
  • Arrival and departure dates;
  • Home address in the country of origin.

28.2  Your passport and travel document data is stored in our system in accordance with applicable legal provisions and is used solely for legal compliance and hotel operational purposes.

28.3  Itinerary Data and Travel Services. If you use additional travel services provided through the Artotel Wanderlust application (airport transfers, tours, activities, etc.), your itinerary data will be shared with the relevant service provider solely for the purpose of performing the service.

28.4  Privacy Considerations for International Guests. If you are a citizen or resident of a jurisdiction with specific data protection regulations (such as the European Union, Singapore, or other jurisdictions), we will endeavor to fulfill any additional rights you may have under such regulations, including but not limited to the GDPR (General Data Protection Regulation) for guests from the European region.

 

PART V: CLOSING PROVISIONS

Article 29
AMENDMENTS TO THE PRIVACY POLICY

29.1  We reserve the right to update or amend this Privacy Policy from time to time to reflect changes in our data processing practices, technological developments, or changes in applicable regulations.

29.2  Any changes to this Privacy Policy will be notified to you through:

  • A notice displayed on the homepage of our website and/or application;
  • An email to your registered email address;
  • An in-app notification (for significant changes);
  • An update to this Privacy Policy page with an updated "Last Updated" date.

29.3  Where changes are material or significant, we will provide clearer notice and, where required by law, request your renewed consent.

29.4  Your continued use of our services after the amended Privacy Policy takes effect will be deemed as your acceptance of such changes. If you do not agree with the changes made, please discontinue use of our services and contact us to request the deletion of your account and Personal Data.

29.5  Privacy Policy Change History:

VERSION

DATE

SUMMARY OF CHANGES

1.0

1 September 2026

Initial Artotel Wanderlust Privacy Policy covering the website and mobile application. Prepared in accordance with PDP Law No. 27 of 2022.

 

Article 30
DISPUTE RESOLUTION

30.1  Internal Complaints Procedure. If you have a complaint or objection regarding the processing of your Personal Data, we invite you to first resolve it through our internal complaints procedure:

  • Step 1 — Submit a Complaint: Submit your complaint in writing to our DPO via email at legal@artotelgroup.com or the online form available on our website/application;
  • Step 2 — Acknowledgment of Receipt: We will acknowledge receipt of your complaint within 3 (three) business days;
  • Step 3 — Investigation: We will thoroughly investigate your complaint within a maximum of 14 (fourteen) business days;
  • Step 4 — Response: We will provide a written response on the outcome of the investigation and the steps that have been or will be taken;
  • Step 5 — Escalation: If you are not satisfied with our response, the complaint may be escalated to senior management and/or the competent data protection authority.

30.2  External Dispute Resolution. If a dispute cannot be resolved through the internal procedure, you are entitled to:

  • Lodge a complaint with the Ministry of Communication and Informatics of the Republic of Indonesia as the competent authority in the field of personal data protection;
  • Pursue mediation through a recognized mediation institution in accordance with applicable legal provisions;
  • File a civil lawsuit through the competent court in accordance with Indonesian civil procedural law;
  • Pursue arbitration through the Indonesian National Arbitration Board (BANI) where the parties agree to do so.

30.3  Time Limit for Filing. Complaints and/or lawsuits relating to a breach of this Privacy Policy must be filed within a maximum period of 2 (two) years from the date you became aware, or should reasonably have become aware, of the breach.

 

Article 31
GOVERNING LAW

31.1  This Privacy Policy is made, interpreted, and implemented in accordance with the laws in force in the Republic of Indonesia.

31.2  Any dispute arising out of or relating to this Privacy Policy, including disputes regarding the validity, interpretation, implementation, or breach of its provisions, will be resolved in accordance with the applicable laws and regulations of Indonesia.

31.3  The parties agree that the competent court to resolve disputes is the South Jakarta District Court as the court of first and primary instance, without prejudice to the parties' right to choose another dispute resolution forum by agreement.

 

Article 32
CONTACT US

If you have any questions, concerns, or requests regarding this Privacy Policy or the processing of your Personal Data, please contact us through:

COMMUNICATION CHANNEL

CONTACT DETAILS

OPERATING HOURS

Data Protection Officer
(DPO)

legal@artotelgroup.com

Monday - Friday
09:00 - 17:00 WIB

Customer Service Email

hotline@artotelgroup.com

Monday - Sunday
09.00 - 20.00 WIB

WhatsApp

+62 811-9220-911

Monday - Sunday
09.00 - 20.00 WIB

Written Letter

PT Artotel Petualang Indonesia

Attn: Data Protection Officer
Jl. Bunga Mawar No. 42, Cipete Selatan, Cilandak, Jakarta Selatan, DKI Jakarta
Indonesia 12410

Monday - Friday
09:00 - 17:00 WIB

 

We are committed to responding to your questions and requests within a reasonable time, being no later than 30 (thirty) days from the date the request is received in full.

Privacy Policy in Bahasa