Privacy Statement (EU)

Last updated : January 14, 2022

Last revision : 

Reason modified :

  • Fixing broken links.

 

This policy is will be effective from Monday 17 January 2022

To see prior version, please click here.

This privacy statement applies to citizens and legal permanent residents of the European Economic Area.

In this privacy statement, we explain what we do with the data we obtain about you via https://popitsnack.com. We recommend you carefully read this statement. In our processing we comply with the requirements of privacy legislation. That means, among other things, that:

  • we clearly state the purposes for which we process personal data. We do this by means of this privacy statement;
  • we aim to limit our collection of personal data to only the personal data required for legitimate purposes;
  • we first request your explicit consent to process your personal data in cases requiring your consent;
  • we take appropriate security measures to protect your personal data and also require this from parties that process personal data on our behalf;
  • we respect your right to access your personal data or have it corrected or deleted, at your request.

If you have any questions, or want to know exactly what data we keep of you, please contact us.

1. Purpose, data and retention period

We may collect or receive personal information for a number of purposes connected with our business operations which may include the following: (click to expand)

1.1 Contact - Through phone, mail, email and/or webforms

For this purpose we use the following data:

  • Name, Address and City
  • Marital status
  • Email address
  • Financial data
  • Birth date
  • Username, passwords and other account specific data
  • Sex
  • IP Address
  • Location
  • Medical data
  • Visitor behavior
  • Photos
  • Social media accounts
  • Criminal or legal data
  • Telephone number
  • Other:

Others Personal Data relate to User as real person.

The basis on which we may process these data is:

It is necessary for the execution of a contract or preliminary procedures related to a contract to which the data subject is a party.

Retention period

We determine the retention period according to fixed objective criteria: for the purpose of accelerating and evaluating services.

1.2 Payments

For this purpose we use the following data:

  • Name, Address and City
  • Marital status
  • Email address
  • Financial data
  • Birth date
  • Username, passwords and other account specific data
  • Sex
  • IP Address
  • Location
  • Medical data
  • Visitor behavior
  • Photos
  • Social media accounts
  • Criminal or legal data
  • Telephone number
  • Other:

Others Personal Data relate to User as real person.

The basis on which we may process these data is:

It is necessary for the execution of a contract or preliminary procedures related to a contract to which the data subject is a party.

Retention period

We determine the retention period according to fixed objective criteria: for the purpose of accelerating and evaluating services.

1.3 Registering an account

For this purpose we use the following data:

  • Name, Address and City
  • Marital status
  • Email address
  • Financial data
  • Birth date
  • Username, passwords and other account specific data
  • Sex
  • IP Address
  • Location
  • Medical data
  • Visitor behavior
  • Photos
  • Social media accounts
  • Criminal or legal data
  • Telephone number
  • Other:

Others Personal Data relate to User as real person.

The basis on which we may process these data is:

It is necessary for the execution of a contract or preliminary procedures related to a contract to which the data subject is a party.

Retention period

We determine the retention period according to fixed objective criteria: for the purpose of accelerating and evaluating services.

1.4 Newsletters

For this purpose we use the following data:

  • Name, Address and City
  • Marital status
  • Email address
  • Financial data
  • Birth date
  • Username, passwords and other account specific data
  • Sex
  • IP Address
  • Location
  • Medical data
  • Visitor behavior
  • Photos
  • Social media accounts
  • Criminal or legal data
  • Telephone number
  • Other:

Others Personal Data relate to User as real person.

The basis on which we may process these data is:

Upon the provision of consent.

Retention period

We determine the retention period according to fixed objective criteria: for the purpose of accelerating and evaluating services.

1.5 To support services or products that a customer wants to buy or has purchased

For this purpose we use the following data:

  • Name, Address and City
  • Marital status
  • Email address
  • Financial data
  • Birth date
  • Username, passwords and other account specific data
  • Sex
  • IP Address
  • Location
  • Medical data
  • Visitor behavior
  • Photos
  • Social media accounts
  • Criminal or legal data
  • Telephone number
  • Other:

Others Personal Data relate to User as real person.

The basis on which we may process these data is:

It is necessary for the execution of a contract or preliminary procedures related to a contract to which the data subject is a party.

Retention period

We determine the retention period according to fixed objective criteria: for the purpose of accelerating and evaluating services.

1.6 To be able to comply with legal obligations

For this purpose we use the following data:

  • Name, Address and City
  • Marital status
  • Email address
  • Financial data
  • Birth date
  • Username, passwords and other account specific data
  • Sex
  • IP Address
  • Location
  • Medical data
  • Visitor behavior
  • Photos
  • Social media accounts
  • Criminal or legal data
  • Telephone number
  • Other:

Others Personal Data relate to User as real person.

The basis on which we may process these data is:

For compliance with a legal or regulatory obligation.

Retention period

We determine the retention period according to fixed objective criteria: for the purpose of accelerating and evaluating services.

1.7 Compiling and analyzing statistics for website improvement.

For this purpose we use the following data:

  • Name, Address and City
  • Marital status
  • Email address
  • Financial data
  • Birth date
  • Username, passwords and other account specific data
  • Sex
  • IP Address
  • Location
  • Medical data
  • Visitor behavior
  • Photos
  • Social media accounts
  • Criminal or legal data
  • Telephone number
  • Other:

Others Personal Data relate to User as real person.

The basis on which we may process these data is:

Upon the provision of consent.

Retention period

We determine the retention period according to fixed objective criteria: for the purpose of accelerating and evaluating services.

1.8 To be able to offer personalized products and services

For this purpose we use the following data:

  • Name, Address and City
  • Marital status
  • Email address
  • Financial data
  • Birth date
  • Username, passwords and other account specific data
  • Sex
  • IP Address
  • Location
  • Medical data
  • Visitor behavior
  • Photos
  • Social media accounts
  • Criminal or legal data
  • Telephone number
  • Other:

Others Personal Data relate to User as real person.

The basis on which we may process these data is:

Upon the provision of consent.

Retention period

We determine the retention period according to fixed objective criteria: for the purpose of accelerating and evaluating services.

1.9 Deliveries

For this purpose we use the following data:

  • Name, Address and City
  • Marital status
  • Email address
  • Financial data
  • Birth date
  • Username, passwords and other account specific data
  • Sex
  • IP Address
  • Location
  • Medical data
  • Visitor behavior
  • Photos
  • Social media accounts
  • Criminal or legal data
  • Telephone number
  • Other:

Others Personal Data relate to User as real person.

The basis on which we may process these data is:

It is necessary for the execution of a contract or preliminary procedures related to a contract to which the data subject is a party.

Retention period

We determine the retention period according to fixed objective criteria: for the purpose of accelerating, managing, evaluating, and improving Our services.

2. Sharing with other parties

We only share or disclose this data to processors for the following purposes:

Processors

For the provision of specific services We use following categories of processors, which support Us in the performance of Our business processes. Specifically, these include companies in the following categories:

  • Tracking service providers
  • Web agencies
  • Hosting providers
  • Customer service
  • Shipping service providers
  • Print service providers
  • Archiving service providers
  • IT Service Providers

(Sub-)processors

We (may) make use of (sub-)processors. (Sub-)processors only process personal data limited to the extent that it is necessary for them to complete their specific task or service. We only provide Your personal data with relevant protection measures in place. Those measures can be: a data processing agreement to ensure confidentiality; technical measures to ensure security while transferring the data; the obligation for the (sub-)processor to use all information in accordance with applicable privacy legislation and to not use the data for its own purposes.

3. Cookies

To provide the best experiences, we and our partners use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us and our partners to process personal data such as browsing behaviour or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions. For more information about these technologies and partners, please refer to our Cookie Policy.

PT. Mandiri Tunggal Sejahtera Berkarya / MTS Group Holding, LLC. participates in the IAB Europe Transparency & Consent Framework and complies with its Specifications and Policies. It uses the Consent Management Platform with the identification number 332.

4. Security

We are committed to the security of personal data. We take appropriate security measures to limit abuse of and unauthorized access to personal data. This ensures that only the necessary persons have access to your data, that access to the data is protected, and that our security measures are regularly reviewed.

The security measures we use consist of:

  • Username and Password
  • DNSSEC
  • TLS / SSL
  • DKIM, SPF en DMARC
  • Physical security measures of systems which contain personal data.
  • Security software
  • ISO27001/27002 certified
  • HTTP Strict Transport Security
  • X-Content-Type-Options
  • X-XSS-Protection
  • X-Frame-Options
  • Expect-CT
  • No Referrer When Downgrade header
  • Content Security Policy
  • STARTTLS and DANE
  • WPA2 Enterprise
  • Permissions Policy

5. Third-party websites

This privacy statement does not apply to third-party websites connected by links on our website. We cannot guarantee that these third parties handle your personal data in a reliable or secure manner. We recommend you read the privacy statements of these websites prior to making use of these websites.

6. Amendments to this privacy statement

We reserve the right to make amendments to this privacy statement. It is recommended that you consult this privacy statement regularly in order to be aware of any changes. In addition, we will actively inform you wherever possible.

7. Accessing and modifying your data

If you have any questions or want to know which personal data we have about you, please contact us. You can contact us by using the information below. You have the following rights:

  • You have the right to know why your personal data is needed, what will happen to it, and how long it will be retained for.
  • Right of access: You have the right to access your personal data that is known to us.
  • Right to rectification: you have the right to supplement, correct, have deleted or blocked your personal data whenever you wish.
  • If you give us your consent to process your data, you have the right to revoke that consent and to have your personal data deleted.
  • Right to transfer your data: you have the right to request all your personal data from the controller and transfer it in its entirety to another controller.
  • Right to object: you may object to the processing of your data. We comply with this, unless there are justified grounds for processing.

Please make sure to always clearly state who you are, so that we can be certain that we do not modify or delete any data of the wrong person.

8. Automated decision-making

We make decisions on the basis of automated processing with respect to matters that may have (significant) consequences for individuals. These are decisions taken by computer programs or systems without human intervention.

Legal bases and purposes of data processing and consumer protection – Wordwide
We process the data you provide, including your contact details (name, address, telephone number, email address), on the basis of your consent (Article 6 (1a) of the General Data Protection Regulation – GDPR) so that we can contact you, to perform the tasks for the responsible of (Article 6 (1e) of the GDPR, Section 3 of the Federal Data Protection Act – BDSG), to comply with legal obligations (Article 6 (1c) of the GDPR), to comply with legal obligations of the The California Consumer Privacy Act of 2018 (CCPA).

Legal bases and purposes of data processing and consumer protection – Indonesia
Mandatory to comply Indonesian government regulation as describe on The Information Security Index (Indeks KAMI) and Indonesia’s Stardard Electronic System Operator (Penyelenggara Sistem Elektronik/ PSE).

For futher information reffer to this page Certification and Compliance Statements page, address at https://popitsnack.com/documents/compliance-documents/certification-and-compliance-statements/

9. Submitting a complaint

If you are not satisfied with the way in which we handle (a complaint about) the processing of your personal data, you have the right to submit a complaint to the Data Protection Authority.

10. Contact details

PT. Mandiri Tunggal Sejahtera Berkarya / MTS Group Holding, LLC.
Seroja Home Residence 2 Blok B No. 40
Sekarwangi, Soreang, Kabupaten Bandung,
Jawa Barat 40922
Indonesia
Website: https://popitsnack.com
Phone number: 622258999811

Annex

Complianz | The Privacy Suite for The Platform

This platform uses the Privacy Suite from Complianz to collect records of consent. For this functionality your IP address is anonymized and stored in our database. For more information, see the Complianz Privacy Statement.

Privacy Notice Addendum


This privacy statement was last updated on 23 June 2022 and applies to citizens and legal permanent residents of the European Economic Area and Switzerland.

In this privacy statement, we explain what we do with the data we obtain about you via https://popitsnack.com. We recommend you carefully read this statement. In our processing we comply with the requirements of privacy legislation. That means, among other things, that:

  • we clearly state the purposes for which we process personal data. We do this by means of this privacy statement;
  • we aim to limit our collection of personal data to only the personal data required for legitimate purposes;
  • we first request your explicit consent to process your personal data in cases requiring your consent;
  • we take appropriate security measures to protect your personal data and also require this from parties that process personal data on our behalf;
  • we respect your right to access your personal data or have it corrected or deleted, at your request.

If you have any questions, or want to know exactly what data we keep of you, please contact us.

1. Purpose, data and retention period

We may collect or receive personal information for a number of purposes connected with our business operations which may include the following: (click to expand) 

2. Sharing with other parties

We only share or disclose this data to processors for the following purposes:

Processors

Name: Midtrans (PT. Midtrans Indonesia)
Country: Indonesia
Purpose: Patment Gateway Service Provider
Name: Duitku (PT Kharisma Catur Mandala)
Country: Indonesia
Purpose: Patment Gateway Service Provider
Name: NicePay (PT IONPay Networks)
Country: Indonesia
Purpose: Patment Gateway Service Provider
Name: Jenius (PT. Bank BTPN, Tbk.)
Country: Indonesia
Purpose: Patment Gateway Service Provider
Name: Paypal
Country: United States
Purpose: Patment Gateway Service Provider
Name: Apple Pay
Country: United States
Purpose: Patment Gateway Service Provider
Name: Amazon Pay
Country: United States
Purpose: Patment Gateway Service Provider
Name: Google Pay
Country: United States
Purpose: Patment Gateway Service Provider
Name: Metamask
Country: United States
Purpose: Patment Gateway Service Provider
Name: Alibaba Cloud Indonesia
Country: Indonesia
Purpose: Hosting Service Provider
Name: Rumah Web Indonesia
Country: Indonesia
Purpose: Hosting Service Provider
Name: PT. Mandiri Tunggal Sejahtera Logistic and Fullfilment Partners
Country: Indonesia
Purpose: Logistic and Fullfilment Service Provider

3. Cookies

To provide the best experiences, we and our partners use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us and our partners to process personal data such as browsing behaviour or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions. For more information about these technologies and partners, please refer to our Cookie Policy

PT. Mandiri Tunggal Sejahtera Berkarya / MTS Group Holding, LLC. participates in the IAB Europe Transparency & Consent Framework and complies with its Specifications and Policies. It uses the Consent Management Platform with the identification number 332. 

We have concluded a data Processing Agreement with Google.

Google may not use the data for any other Google services.

The inclusion of full IP addresses is blocked by us.

4. Security

We are committed to the security of personal data. We take appropriate security measures to limit abuse of and unauthorized access to personal data. This ensures that only the necessary persons have access to your data, that access to the data is protected, and that our security measures are regularly reviewed.

The security measures we use consist of:

  • Username and Password
  • DNSSEC
  • TLS / SSL
  • DKIM, SPF en DMARC
  • Physical security measures of systems which contain personal data.
  • Security software
  • ISO27001/27002 certified
  • HTTP Strict Transport Security
  • X-Content-Type-Options
  • X-XSS-Protection
  • X-Frame-Options
  • Content Security Policy
  • STARTTLS and DANE
  • WPA2 Enterprise
  • Permissions Policy

5. Third-party websites

This privacy statement does not apply to third-party websites connected by links on our website. We cannot guarantee that these third parties handle your personal data in a reliable or secure manner. We recommend you read the privacy statements of these websites prior to making use of these websites.

6. Amendments to this privacy statement

We reserve the right to make amendments to this privacy statement. It is recommended that you consult this privacy statement regularly in order to be aware of any changes. In addition, we will actively inform you wherever possible.

7. Accessing and modifying your data

If you have any questions or want to know which personal data we have about you, please contact us. You can contact us by using the information below. You have the following rights:

  • You have the right to know why your personal data is needed, what will happen to it, and how long it will be retained for.
  • Right of access: You have the right to access your personal data that is known to us.
  • Right to rectification: you have the right to supplement, correct, have deleted or blocked your personal data whenever you wish.
  • If you give us your consent to process your data, you have the right to revoke that consent and to have your personal data deleted.
  • Right to transfer your data: you have the right to request all your personal data from the controller and transfer it in its entirety to another controller.
  • Right to object: you may object to the processing of your data. We comply with this, unless there are justified grounds for processing.

Please make sure to always clearly state who you are, so that we can be certain that we do not modify or delete any data of the wrong person.

8. Automated decision-making

We make decisions on the basis of automated processing with respect to matters that may have (significant) consequences for individuals. These are decisions taken by computer programs or systems without human intervention.

Legal bases and purposes of data processing and consumer protection – Wordwide
We process the data you provide, including your contact details (name, address, telephone number, email address), on the basis of your consent (Article 6 (1a) of the General Data Protection Regulation – GDPR) so that we can contact you, to perform the tasks for the responsible of (Article 6 (1e) of the GDPR, Section 3 of the Federal Data Protection Act – BDSG), to comply with legal obligations (Article 6 (1c) of the GDPR), to comply with legal obligations of the The California Consumer Privacy Act of 2018 (CCPA).

Legal bases and purposes of data processing and consumer protection – Indonesia
Mandatory to comply Indonesian government regulation as describe on The Information Security Index (Indeks KAMI) and Indonesia’s Stardard Electronic System Operator (Penyelenggara Sistem Elektronik/ PSE).

For futher information reffer to this page Certification and Compliance Statements page, address at https://popitsnack.com/documents/compliance-documents/certification-and-compliance-statements/

9. Submitting a complaint

If you are not satisfied with the way in which we handle (a complaint about) the processing of your personal data, you have the right to submit a complaint to the Data Protection Authority.

10. Contact details

PT. Mandiri Tunggal Sejahtera Berkarya / MTS Group Holding, LLC.
Seroja Home Residence 2 Blok B No. 40
Sekarwangi, Soreang, Kabupaten Bandung,
Jawa Barat 40922
Indonesia
Website: https://popitsnack.com
Email: moc.kcanstipop@opd
Phone number: 622258999811

11. Data requests

For the most frequently submitted requests, we also offer you the possibility to use our data request form

×

Annex

Complianz

This platform uses the Privacy Suite from Complianz to collect records of consent. For this functionality your IP address is anonymized and stored in our database. For more information, see the Complianz Privacy Statement.

Burst Statistics

This website uses Burst Statistics, a Privacy-Friendly Statistics Tool to analyze visitor behavior. For this functionality we (this website) collect anonymized data, stored locally without sharing it with other parties. For more information, please read the Burst Statistics Privacy Statement from Burst official website.

Really Simple SSL

Really Simple SSL and Really Simple SSL add-ons do not process any personal identifiable information, so the GDPR does not apply to these plugins or usage of these plugins on your website. You can find our privacy policy here.

MailPoet

MailPoet Newsletter & Emails

If you have subscribed to our newsletter or if you are a member of our website (you can log in) or if you have purchased on our website, there is a good chance you will receive emails from us.

We will only send you emails which you have signed up to receive, or which pertain to the services we provided to you.

To send you emails, we use the name and email address you provide us. Our site also logs the IP address you used when you signed up for the service to prevent abuse of the system.

This website can send emails through the MailPoet sending service. This service allows us to track opens and clicks on our emails. We use this information to improve the content of our newsletters.

No identifiable information is otherwise tracked outside this website except for the email address.


 

Did the information shown in this page help you solve your problem?

The purpose is receiving the feedback from the visitors, so we can make necessary changes to our informations which increase trust and customer satisfaction and make our platform better. For futher information about Customer Research: Designing for Transparency and Trust, please visit our Trust and Transparency Principles. .