Skip to content

Legal

Privacy Policy

How we collect, use, store, share and protect personal information when you use this website, request quotes or make bookings.

Effective May 2026 · Last updated May 2026

1. Who we are

Baliem Valley (operated by PT Juara Holding Group, the controlling entity; “Baliem Valley”, “we”, “us” or “our”) is an Indonesia-based tourism curator that respects your privacy. By using this website you agree to the practices described in this policy.

The legal controller of personal data on this site is PT Juara Holding Group, registered in the Republic of Indonesia. Contact: [email protected].

We are registered as an Electronic System Operator (Penyelenggara Sistem Elektronik / PSE) with the Indonesian Ministry of Communications and Informatics (Kominfo), in accordance with Government Regulation No. 71/2019 and Ministerial Regulation 5/2020 on Private Scope Electronic System Operators.

2. What information we collect

  • Information you give us: name, email, phone number, country of residence, passport country, travel dates, party size, accommodation preferences, dietary requirements, and any message you send through our contact or quote-request forms.
  • Booking information: when you confirm a booking, details such as full passport name, date of birth, emergency contact, dietary or medical considerations relevant to running the trip safely, and arrival and departure flight details.
  • Payment information: we do not collect or store full card numbers on this website. Payments are processed by third-party gateways (Xendit, Midtrans or international card processors). We keep only the transaction reference, timestamp, currency and amount needed to reconcile bookings.
  • Automatically collected data: IP address, approximate location (country/region), browser type and version, device type, referrer URL, pages viewed, time on page and similar technical data from server logs and analytics tools.
  • Cookies and similar technologies: see section 7.

3. Lawful basis for processing

Where applicable under Indonesian law (UU No. 27 Tahun 2022 tentang Pelindungan Data Pribadi, the Personal Data Protection Law) and the EU General Data Protection Regulation 2016/679 (“GDPR”), we process data on these bases:

  • Consent — for marketing communications, optional cookies and any processing of sensitive data.
  • Contract — to provide the booking and travel-curation services you request.
  • Legal obligation — to keep transaction records under Indonesian tax law (Undang-Undang Pajak) and accounting regulations.
  • Legitimate interests — to run the website, prevent fraud and improve our service, without overriding your rights and freedoms.

4. How we use your information

  • To respond to enquiries, send proposals and carry out bookings.
  • To coordinate with on-the-ground partners (such as hotels, vessel owners, ground transport, dive masters and captains) strictly as far as needed to deliver the service you requested.
  • To issue invoices, process refunds and meet legal record-keeping obligations.
  • To send operational updates (itinerary changes, weather advisories, pickup confirmations).
  • With your separate opt-in, to send occasional marketing about new destinations or seasonal offers. You can unsubscribe at any time using the link in any marketing email.
  • To detect, investigate and prevent fraud, abuse or breaches of our Terms of Service.

5. Sharing your information

We do not sell, rent or trade your personal information. We share it only with:

  • Travel suppliers needed to deliver your booking (for example the specific yacht, hotel, dive operator or driver assigned to your trip).
  • Payment processors (Xendit, Midtrans, Stripe, Wise) under their own data-processing agreements.
  • Government authorities when legally required (for example immigration manifests for vessels, or mandatory tourism reporting under Peraturan Menteri Pariwisata).
  • Professional advisers (legal, accounting, audit) bound by confidentiality.

Where suppliers are outside Indonesia, transfers are covered by appropriate safeguards under Indonesian law and, for EU residents, the GDPR Chapter V cross-border transfer rules.

6. International visitors — GDPR & CCPA notice

EU/EEA/UK visitors (GDPR): you have the right to access, rectify and erase your data, to restrict processing, to data portability, to object, and to withdraw consent at any time. Contact [email protected] to exercise these rights. You may also complain to your national supervisory authority.

California residents (CCPA / CPRA): you have the right to know which categories of personal information we collect, to request deletion, to opt out of any “sale” or “sharing” (we do neither), and not to be discriminated against for exercising these rights.

Children (COPPA & UU PA): we do not knowingly collect personal information from children under 13. A parent or guardian who believes we hold such information should contact us immediately, and we will delete it.

7. Cookies

This site uses functional cookies (session, security, language preference), analytics cookies (visit counts, page paths, anonymised aggregates) and — only with your consent — marketing cookies (re-marketing pixels). You can manage cookie preferences in your browser; rejecting non-essential cookies will not stop you browsing or contacting us.

8. Data retention

We keep enquiry records for 24 months, executed booking records for 10 years (to meet Indonesian tax-law retention requirements), and accounting records for the period required under Undang-Undang No. 28 Tahun 2007 on General Provisions and Tax Procedures. Marketing-list data is kept until you unsubscribe.

9. Security

We use industry-standard transport security (HTTPS / TLS 1.3), restricted database access, encrypted backups and strict role-based access for staff. No system can be guaranteed 100% secure. If a personal-data breach affects you, we will notify the relevant authority and the affected individuals within 72 hours where applicable law requires it.

10. Refund & cancellation

Refunds and cancellations are governed primarily by our Terms of Service. Personal information related to a refund is processed to complete the refund and to meet tax obligations.

11. Force majeure

The operation of this site, the bookings made through it and the personal data processed for those bookings may be affected by force-majeure events, including natural disasters, volcanic activity, public-health emergencies, civil unrest, government action or maritime advisory closures. In such events we handle personal data under the principles of this policy, with reasonable adjustments required by safety and legal obligations.

12. Your rights — Indonesia UU PDP

Under Indonesia’s Personal Data Protection Law (UU No. 27/2022) you have the rights to information, access, correction, deletion, restriction of processing, data portability, withdrawal of consent, objection to automated decision-making, and compensation. Send requests to [email protected]; we will respond within 30 calendar days, as required by Article 7 of UU PDP.

13. Changes to this policy

We may revise this Privacy Policy from time to time. The “last updated” date at the top of this page shows the latest revision. Material changes will be announced by a banner on the home page or by email to active customers.

14. Contact

Privacy questions, requests and complaints: [email protected]

Postal: PT Juara Holding Group, Bali, Indonesia. Phone: +62 811-3941-4563.