Privacy Statement (EU)
Table of Contents
Last updated : January 14, 2022
Last revision :
Reason modified :
- Fixing broken links.
This policy is will be effective from Monday 17 January 2022
To see prior version, please click here.
This privacy statement applies to citizens and legal permanent residents of the European Economic Area.
In this privacy statement, we explain what we do with the data we obtain about you via https://popitsnack.com. We recommend you carefully read this statement. In our processing we comply with the requirements of privacy legislation. That means, among other things, that:
- we clearly state the purposes for which we process personal data. We do this by means of this privacy statement;
- we aim to limit our collection of personal data to only the personal data required for legitimate purposes;
- we first request your explicit consent to process your personal data in cases requiring your consent;
- we take appropriate security measures to protect your personal data and also require this from parties that process personal data on our behalf;
- we respect your right to access your personal data or have it corrected or deleted, at your request.
If you have any questions, or want to know exactly what data we keep of you, please contact us.
1. Purpose, data and retention period
We may collect or receive personal information for a number of purposes connected with our business operations which may include the following: (click to expand)
1.1 Contact - Through phone, mail, email and/or webforms
For this purpose we use the following data:
- Name, Address and City
- Marital status
- Email address
- Financial data
- Birth date
- Username, passwords and other account specific data
- Sex
- IP Address
- Location
- Medical data
- Visitor behavior
- Photos
- Social media accounts
- Criminal or legal data
- Telephone number
- Other:
Others Personal Data relate to User as real person.
The basis on which we may process these data is:
Retention period
We determine the retention period according to fixed objective criteria: for the purpose of accelerating and evaluating services.
1.2 Payments
For this purpose we use the following data:
- Name, Address and City
- Marital status
- Email address
- Financial data
- Birth date
- Username, passwords and other account specific data
- Sex
- IP Address
- Location
- Medical data
- Visitor behavior
- Photos
- Social media accounts
- Criminal or legal data
- Telephone number
- Other:
Others Personal Data relate to User as real person.
The basis on which we may process these data is:
Retention period
We determine the retention period according to fixed objective criteria: for the purpose of accelerating and evaluating services.
1.3 Registering an account
For this purpose we use the following data:
- Name, Address and City
- Marital status
- Email address
- Financial data
- Birth date
- Username, passwords and other account specific data
- Sex
- IP Address
- Location
- Medical data
- Visitor behavior
- Photos
- Social media accounts
- Criminal or legal data
- Telephone number
- Other:
Others Personal Data relate to User as real person.
The basis on which we may process these data is:
Retention period
We determine the retention period according to fixed objective criteria: for the purpose of accelerating and evaluating services.
1.4 Newsletters
For this purpose we use the following data:
- Name, Address and City
- Marital status
- Email address
- Financial data
- Birth date
- Username, passwords and other account specific data
- Sex
- IP Address
- Location
- Medical data
- Visitor behavior
- Photos
- Social media accounts
- Criminal or legal data
- Telephone number
- Other:
Others Personal Data relate to User as real person.
The basis on which we may process these data is:
Upon the provision of consent.
Retention period
We determine the retention period according to fixed objective criteria: for the purpose of accelerating and evaluating services.
1.5 To support services or products that a customer wants to buy or has purchased
For this purpose we use the following data:
- Name, Address and City
- Marital status
- Email address
- Financial data
- Birth date
- Username, passwords and other account specific data
- Sex
- IP Address
- Location
- Medical data
- Visitor behavior
- Photos
- Social media accounts
- Criminal or legal data
- Telephone number
- Other:
Others Personal Data relate to User as real person.
The basis on which we may process these data is:
Retention period
We determine the retention period according to fixed objective criteria: for the purpose of accelerating and evaluating services.
1.6 To be able to comply with legal obligations
For this purpose we use the following data:
- Name, Address and City
- Marital status
- Email address
- Financial data
- Birth date
- Username, passwords and other account specific data
- Sex
- IP Address
- Location
- Medical data
- Visitor behavior
- Photos
- Social media accounts
- Criminal or legal data
- Telephone number
- Other:
Others Personal Data relate to User as real person.
The basis on which we may process these data is:
For compliance with a legal or regulatory obligation.
Retention period
We determine the retention period according to fixed objective criteria: for the purpose of accelerating and evaluating services.
1.7 Compiling and analyzing statistics for website improvement.
For this purpose we use the following data:
- Name, Address and City
- Marital status
- Email address
- Financial data
- Birth date
- Username, passwords and other account specific data
- Sex
- IP Address
- Location
- Medical data
- Visitor behavior
- Photos
- Social media accounts
- Criminal or legal data
- Telephone number
- Other:
Others Personal Data relate to User as real person.
The basis on which we may process these data is:
Upon the provision of consent.
Retention period
We determine the retention period according to fixed objective criteria: for the purpose of accelerating and evaluating services.
1.8 To be able to offer personalized products and services
For this purpose we use the following data:
- Name, Address and City
- Marital status
- Email address
- Financial data
- Birth date
- Username, passwords and other account specific data
- Sex
- IP Address
- Location
- Medical data
- Visitor behavior
- Photos
- Social media accounts
- Criminal or legal data
- Telephone number
- Other:
Others Personal Data relate to User as real person.
The basis on which we may process these data is:
Upon the provision of consent.
Retention period
We determine the retention period according to fixed objective criteria: for the purpose of accelerating and evaluating services.
1.9 Deliveries
For this purpose we use the following data:
- Name, Address and City
- Marital status
- Email address
- Financial data
- Birth date
- Username, passwords and other account specific data
- Sex
- IP Address
- Location
- Medical data
- Visitor behavior
- Photos
- Social media accounts
- Criminal or legal data
- Telephone number
- Other:
Others Personal Data relate to User as real person.
The basis on which we may process these data is:
Retention period
We determine the retention period according to fixed objective criteria: for the purpose of accelerating, managing, evaluating, and improving Our services.
2. Sharing with other parties
We only share or disclose this data to processors for the following purposes:
Processors
For the provision of specific services We use following categories of processors, which support Us in the performance of Our business processes. Specifically, these include companies in the following categories:
- Tracking service providers
- Web agencies
- Hosting providers
- Customer service
- Shipping service providers
- Print service providers
- Archiving service providers
- IT Service Providers
(Sub-)processors
We (may) make use of (sub-)processors. (Sub-)processors only process personal data limited to the extent that it is necessary for them to complete their specific task or service. We only provide Your personal data with relevant protection measures in place. Those measures can be: a data processing agreement to ensure confidentiality; technical measures to ensure security while transferring the data; the obligation for the (sub-)processor to use all information in accordance with applicable privacy legislation and to not use the data for its own purposes.
3. Cookies
To provide the best experiences, we and our partners use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us and our partners to process personal data such as browsing behaviour or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions. For more information about these technologies and partners, please refer to our Cookie Policy.
PT. Mandiri Tunggal Sejahtera Berkarya / MTS Group Holding, LLC. participates in the IAB Europe Transparency & Consent Framework and complies with its Specifications and Policies. It uses the Consent Management Platform with the identification number 332.
4. Security
We are committed to the security of personal data. We take appropriate security measures to limit abuse of and unauthorized access to personal data. This ensures that only the necessary persons have access to your data, that access to the data is protected, and that our security measures are regularly reviewed.
The security measures we use consist of:
- Username and Password
- DNSSEC
- TLS / SSL
- DKIM, SPF en DMARC
- Physical security measures of systems which contain personal data.
- Security software
- ISO27001/27002 certified
- HTTP Strict Transport Security
- X-Content-Type-Options
- X-XSS-Protection
- X-Frame-Options
- Expect-CT
- No Referrer When Downgrade header
- Content Security Policy
- STARTTLS and DANE
- WPA2 Enterprise
- Permissions Policy
5. Third-party websites
This privacy statement does not apply to third-party websites connected by links on our website. We cannot guarantee that these third parties handle your personal data in a reliable or secure manner. We recommend you read the privacy statements of these websites prior to making use of these websites.
6. Amendments to this privacy statement
We reserve the right to make amendments to this privacy statement. It is recommended that you consult this privacy statement regularly in order to be aware of any changes. In addition, we will actively inform you wherever possible.
7. Accessing and modifying your data
If you have any questions or want to know which personal data we have about you, please contact us. You can contact us by using the information below. You have the following rights:
- You have the right to know why your personal data is needed, what will happen to it, and how long it will be retained for.
- Right of access: You have the right to access your personal data that is known to us.
- Right to rectification: you have the right to supplement, correct, have deleted or blocked your personal data whenever you wish.
- If you give us your consent to process your data, you have the right to revoke that consent and to have your personal data deleted.
- Right to transfer your data: you have the right to request all your personal data from the controller and transfer it in its entirety to another controller.
- Right to object: you may object to the processing of your data. We comply with this, unless there are justified grounds for processing.
Please make sure to always clearly state who you are, so that we can be certain that we do not modify or delete any data of the wrong person.
8. Automated decision-making
We make decisions on the basis of automated processing with respect to matters that may have (significant) consequences for individuals. These are decisions taken by computer programs or systems without human intervention.
Legal bases and purposes of data processing and consumer protection – Wordwide
We process the data you provide, including your contact details (name, address, telephone number, email address), on the basis of your consent (Article 6 (1a) of the General Data Protection Regulation – GDPR) so that we can contact you, to perform the tasks for the responsible of (Article 6 (1e) of the GDPR, Section 3 of the Federal Data Protection Act – BDSG), to comply with legal obligations (Article 6 (1c) of the GDPR), to comply with legal obligations of the The California Consumer Privacy Act of 2018 (CCPA).
Legal bases and purposes of data processing and consumer protection – Indonesia
Mandatory to comply Indonesian government regulation as describe on The Information Security Index (Indeks KAMI) and Indonesia’s Stardard Electronic System Operator (Penyelenggara Sistem Elektronik/ PSE).
For futher information reffer to this page Certification and Compliance Statements page, address at https://popitsnack.com/documents/compliance-documents/certification-and-compliance-statements/
9. Submitting a complaint
If you are not satisfied with the way in which we handle (a complaint about) the processing of your personal data, you have the right to submit a complaint to the Data Protection Authority.
10. Contact details
PT. Mandiri Tunggal Sejahtera Berkarya / MTS Group Holding, LLC.
Seroja Home Residence 2 Blok B No. 40
Sekarwangi, Soreang, Kabupaten Bandung,
Jawa Barat 40922
Indonesia
Website: https://popitsnack.com
Phone number: 622258999811
Annex
Complianz | The Privacy Suite for The Platform
This platform uses the Privacy Suite from Complianz to collect records of consent. For this functionality your IP address is anonymized and stored in our database. For more information, see the Complianz Privacy Statement.