Privacy notice
What personal data we collect, the purpose of each use, the legal basis it rests on, who else receives it, how long we keep it and the rights you hold. Every statement here was written either from what this website actually does or from an obligation Indonesian law places on us, and the two are never blurred.
Version 2.0, effective
1. Identity and contact details of the data controller
1.1 PT. NICO Boulangerie Patisserie, trading as NICO Boulangerie, is the Personal Data Controller for the personal data described in this notice, within the meaning of Law No. 27 of 2022 on Personal Data Protection. Our registered address is Jl. Raya Senggigi No.km.9, Batu Layar, Nusa Tenggara Barat, 83355, Indonesia.
1.2 Every question, request and complaint about your personal data may be addressed to us by email at cs@nicoboulangerie.com, on WhatsApp or by telephone on +62 878 0021 2211, or in writing to the address above. We recommend email, because a request that may have to be evidenced later leaves both sides a written record.
1.3 We have not appointed a data protection officer. Requests and complaints about personal data are handled by the people who read cs@nicoboulangerie.com, and that is the address to use. If we appoint an officer, this clause will name them.
cs@nicoboulangerie.com WhatsApp +62 878 0021 2211
2. The law this notice is given under
2.1 This notice is given under Law No. 27 of 2022 on Personal Data Protection, and it is written to be read alongside Government Regulation No. 71 of 2019 on the Implementation of Electronic Systems and Transactions and Regulation of the Minister of Communication and Informatics No. 20 of 2016 on the Protection of Personal Data in Electronic Systems. Where this notice cites an Article, it is an Article of Law No. 27 of 2022 unless another statute is named.
3. What this notice covers
3.1 This notice covers this website, including your customer account, your basket and the orders you place here. It does not cover what happens once you message us on WhatsApp, which Meta runs under its own terms, or the other companies' sites we link to.
4. The categories of personal data we collect
Five categories, and this is all of them. The table in the next clause says what each is used for; this one answers the simpler question of what we hold at all.
- Identity and contact data
- Your name, your email address and your phone number, and your password - which is held only as a one-way hash and cannot be read back by anyone, ourselves included.
- Address and location data
- Each delivery or invoice address you save: its short name, the street address, city, province, postal code and country, any note for the driver, and the latitude and longitude of the pin you place on the map.
- Transaction data
- Your orders and the documents raised for them: products, packs, quantities and prices, the PPN applied, the date requested, the delivery address or collection point, and the invoices and payment records that follow.
- Technical and security data
- A session identifier, and for actions on your account a security record holding the event, the time, your account number, your IP address, a hash of your session identifier, a hash of your browser's user-agent string, the page and the HTTP method. Separately, Google Analytics holds a random identifier and the pages you view, as the clause on analytics sets out.
- What you write to us
- Any note you add to an order, and whatever you send us when you contact us - including a request made under this notice, which we keep so that we can show what was asked and what we did.
We collect no specific personal data within the meaning of Article 4 of Law No. 27 of 2022: no health or medical data, no biometric or genetic data, no data about your religion, politics or sexual life, and no criminal record. We also hold no payment credentials of yours - no card details and no bank account of yours. If you pay online, you type those details on the payment page run by Midtrans, not on this site, and we receive only the confirmation that the payment was made. If you pay by transfer, it goes to our own account.
5. Purpose of each processing, its legal basis and its retention
One row for each purpose for which we process personal data. There is no eighth row hiding behind a "such as" - this is the whole of it. The legal basis column cites the provision of Article 20(2) of Law No. 27 of 2022 that each processing relies on, so that the table can be checked against the statute rather than taken on trust.
| Purpose | Personal data | Legal basis | How long |
|---|---|---|---|
| Running your account | Your name, email address and phone number, and your password - which is stored only as a one-way hash and cannot be read back by anyone, us included. | Performance of a contract, Article 20(2)(b). We cannot provide an account without them. | While the account is open, then 12 months after closure. See the retention schedule. |
| Delivering to you | Each delivery address you save: the short name you give it, the street address, city, province, postal code and country, any note you leave for the driver, and the latitude and longitude of the pin you place on the map. | Performance of a contract, Article 20(2)(b). We cannot deliver without them. | With the account. An address you remove is marked as removed and kept for 12 months. |
| Taking and fulfilling your orders | What you ordered - products, packs, quantities and prices - the PPN applied, the date you asked for, the delivery address or collection point, and any note you added. | Performance of a contract, Article 20(2)(b). | 10 years. An order is an accounting record of what we supplied and what was paid for it. |
| Keeping our books and issuing tax documents | Your name, email address, phone number and address, and the orders and invoices raised for you. These are copied into our accounting system. | Compliance with a legal obligation of the controller, Article 20(2)(c). A company is required to keep accounting and tax records. | 10 years, which is the period tax law requires accounting records to be kept for. |
| Security, and an accurate record of what happened | For actions on your account: the event, the time, your account number, your IP address, a hash of your session identifier, a hash of your browser's user-agent string, the page and the HTTP method. | Our legitimate interest in keeping the site secure and our records accurate, Article 20(2)(f); and, where an entry supports an accounting record, a legal obligation under Article 20(2)(c). | 10 years where the entry supports an accounting record; otherwise 24 months. |
| Keeping your basket and your sign-in | A session identifier in a cookie. On our server that session holds your basket and, once you sign in, your account number and the token that protects our forms. | Performance of a contract for the basket and the sign-in, Article 20(2)(b); our legitimate interest under Article 20(2)(f) for the form-protection token, which is set before you sign in. | Expired sessions are deleted from our database automatically. |
| Understanding how the site is used | A random identifier kept in two Google Analytics cookies, the pages you view, the page you came from, your approximate location, and the type of browser and device you use. Your IP address reaches Google with every request, because your own browser contacts Google directly. | Our legitimate interest in knowing which pages are used and how visitors find us, Article 20(2)(f). | 14 months in Google Analytics. |
No row above rests on your consent, and that is deliberate rather than an omission: this site asks for consent nowhere - there is no cookie banner, no checkbox on the registration form and no marketing opt-in. Naming consent as a basis would describe a permission we never sought.
6. The email we send you
6.1 We send exactly two kinds of email, and you have asked for both: the link that activates a new account, and the link that resets a forgotten password. Neither carries your name - our email provider receives your address and nothing else. We do not email an order confirmation; your orders are on your account pages.
6.2 We send no marketing email at all. There is no newsletter, no mailing list and no promotional mail, so there is nothing for you to unsubscribe from.
7. Cookies
This site can set four cookies. The first arrives on your very first page view, before you sign in or put anything in a basket: every page carries a token that protects our forms against forgery, and issuing that token starts a session. The second only ever reaches somebody who opens the site with a preview key. Those two are strictly necessary. The last two belong to Google Analytics, are not necessary to provide anything you ask for, and are also set on your first page view, before you sign in.
| Name | What it does | Lifetime | Set by |
|---|---|---|---|
PHPSESSID |
Holds your basket, keeps you signed in, and carries the token that protects every form on the site. It contains an identifier and nothing else - everything it refers to is stored on our server. | 15 minutes while you are not signed in; 24 hours once you sign in | This site (first party) |
nico_preview |
Unlocks the site before launch for one browser. You will only ever receive it if you open the site with a preview key, and it identifies nobody. | 12 hours | This site (first party) |
_ga |
Tells one browser from another, so that Google Analytics can count how many different people visit. It holds a random identifier and nothing else. | 2 years after it is set or refreshed | Google Analytics |
_ga_X5FGWSXNN0 |
Keeps the pages you view in one visit together, so that Google Analytics counts them as a single visit. | 2 years after it is set or refreshed | Google Analytics |
This site shows no cookie banner and does not ask for your consent before setting the Google Analytics cookies. There are no advertising cookies on this site; the four in the table are all of them. You can block or delete the Google Analytics cookies in your browser at any time, and the site does not depend on them.
8. Analytics: Google Analytics
8.1 This site uses Google Analytics 4, a service of Google LLC, to understand how it is used: which pages are viewed, how visitors reach the site and how many come back. Every page of this website loads Google's tag, which sends Google the page you view, the page you came from, your approximate location, the type of browser and device you use and - because your browser contacts Google directly - your IP address, together with the random identifier in the two Google Analytics cookies. We do not send Google your name, email address, phone number or account number.
8.2 We have set up our Google Analytics property with Google signals switched off: your visits are not linked to any Google account you may be signed in to, and they are not used to follow you across your devices. We have set Google to keep the data about individual visits for 14 months. We use the reports to see totals and patterns across all visitors, and we take no decision about any individual from them.
8.3 You do not need Google Analytics to use this site. You can block or delete its cookies in your browser, or install Google's Analytics Opt-out Browser Add-on, and the site does not depend on it. You can also object to this processing under Article 10; see the clause on your rights.
9. Who else receives your data
Six companies handle some of your data so that this business can run. Each one is named below with what it receives and why, because a list that says "trusted partners" tells you nothing you can check. The last of them hosts the site rather than doing anything with your data of its own.
| Who | What they receive | What for | Where they are |
|---|---|---|---|
| Mailjet | Your email address. Nothing else - the messages carry no name, no order and no address. | Delivering the account activation and password reset emails. | France |
| Google Maps Platform | When you add or edit a delivery address: the coordinates of the pin you place, and - because the map runs in your own browser rather than on our servers - your IP address and browser details, which reach Google directly. The street address you type is never sent. | Drawing the map you place your delivery pin on, and turning that pin into place names so we can work out which delivery zone serves you. | United States |
| Mekari Jurnal | Your name, email address, phone number and postal address, and the orders and invoices raised for you. | Our accounting system. Our staff sync customer and document records into it; nothing you do on this site sends anything there. | Indonesia |
| Midtrans (PT Midtrans) | When you choose to pay online: your name, email address and phone number, the amount to pay, and our reference for the payment. The card, e-wallet or bank details you use are typed on Midtrans' own payment page and never reach this site. | Our payment provider. It runs the payment page you are sent to, takes the payment and tells us whether it was made. | Indonesia |
| Google Analytics (Google LLC) | Every page you view on this site: the page, the page you came from, your approximate location, your browser and device type, and the random identifier from the Google Analytics cookies. Because your own browser contacts Google, your IP address reaches it too. We send no name, email address, phone number or account number. | Website analytics: showing us how the site is used, in totals across all visitors. | United States. Google, not us, chooses which of its data centres hold this data. |
| Google Cloud | Everything this site stores - your account, your addresses and your orders - because the servers and the database run on infrastructure we rent. Google is a United States company, but the machines holding this data are in its Jakarta region. | Running this website and its database. | Indonesia (Jakarta) |
The first four companies above act as our Personal Data Processors: they process your data on our instructions and for the purpose stated beside them, and not for their own purposes. We remain responsible to you for their processing. The fifth, Google Analytics, is described in the clause on analytics. The sixth provides the infrastructure the site and its database run on.
We do not sell personal data. Disclosure beyond the recipients listed above occurs only where required by law. Analytics data is additionally processed by Google LLC for its own product development purposes under the account-level data sharing setting for Google products and services, which is enabled on our account. Google states that data shared under that setting is not used for advertising personalisation or ad targeting. The remaining three account-level data sharing settings - modelling contributions and business insights, technical support, and recommendations for your business - are disabled.
10. Where your data is kept, and what leaves Indonesia
10.1 Your data is collected in Indonesia and it is stored in Indonesia. This website and its database run on Google Cloud infrastructure in Jakarta, so the records themselves - your account, your addresses, your orders and the security log - do not leave the country.
10.2 Some of your data still reaches companies based abroad, and that is a separate question from where the servers are. Our email provider is a French company and receives your email address. Google is a United States company: it operates the Jakarta data centre our systems run in, and it separately receives your IP address and browser details straight from your own browser when you place a map pin and, through Google Analytics, on every page you view. Indonesia's Personal Data Protection Law governs those transfers and requires an appropriate basis for each. If you want to know what covers a particular provider, email cs@nicoboulangerie.com and we will tell you.
10.3 Articles 55 and 56 of Law No. 27 of 2022 govern a transfer of personal data outside Indonesia and require an appropriate basis for each one. Where we transfer data to a recipient abroad we rely on the level of protection in the receiving country being at least equivalent to that of Indonesian law, and otherwise on binding contractual safeguards with that recipient. If you want to know which basis covers a particular provider, ask us and we will tell you.
11. How long we keep things
11.1 These are the periods we keep each kind of personal data for. Some are fixed by law and we cannot go under them; some the software enforces by itself; the rest are our own judgement about how long the data stays useful, and you are free to argue with those - the last column says which is which.
| Personal data | How long we keep it | What that rests on |
|---|---|---|
| Orders, invoices, payment records and the accounting entries behind them, with the name and contact details that appear on them | 10 years | Fixed by law, twice over. Article 28(11) of the General Provisions and Tax Procedures Law requires books and the documents underlying them to be kept for ten years in Indonesia, and the rules on trade through electronic systems require financial transaction data to be kept for the same ten years. We cannot delete these earlier, even if you ask us to. |
| Security and audit records | 10 years for an entry that supports an accounting record, 5 years for one that records something about an order, 24 months for the rest | Partly fixed by law. An entry that evidences an order is transaction data, which the rules on trade through electronic systems require to be kept - ten years where it is financial, five years where it is not. Entries that record only a failed sign-in or a rate-limit refusal are not transaction data at all, and 24 months is our own judgement of how long they stay useful. We do not delete a record while a dispute or an investigation it bears on is still open. |
| Your account: name, email address, phone number and password hash | While the account is open, then 12 months after you close it | Our judgement. The 12 months leave time to settle anything outstanding and to restore an account closed by mistake. Where your name or contact details also appear on an accounting record, that copy follows the ten-year row above. |
| Delivery and invoice addresses, including the map coordinates | With the account, and 5 years for an address a delivery actually went to. An address you remove that was never used is kept, marked as removed, for 12 months | Partly fixed by law. An address a delivery went to is part of the record of that transaction, which the rules on trade through electronic systems require to be kept for five years. An address you saved and never used is nobody's transaction record, and the 12 months is our own judgement. |
| What you write to us, and the notes you add to an order | 5 years for a note on an order; 24 months for everything else | Partly fixed by law. A note written on an order is part of that transaction's record, which the rules on trade through electronic systems require to be kept for five years where it is not financial data. Other correspondence is not transaction data, and the 24 months is our own judgement of how long a query about an order can come back. |
| Google Analytics usage data: the pages you view, how you arrived, your approximate location, your browser and device type, and the random identifier in the Google Analytics cookies | 14 months | Our judgement. The period is a setting on our Google Analytics account that Google applies; our own software does not enforce it. |
| The activation and password-reset links we email you | 24 hours for an activation link, 15 minutes for a password reset, and single use | Enforced by the software. We store only a one-way hash of each link rather than the link itself, so nothing usable survives its expiry or its use. |
| Session records | Deleted once they pass their expiry | Enforced by the software, which clears expired sessions from the database on its own. |
11.2 Two of those periods are kept by the software itself: expired sessions are cleared from our database, and an emailed link stops working when it expires or is used. One more period, for Google Analytics, is applied by Google under a setting we chose. The rest are a policy our people apply - when we review records, and whenever you ask us to. We are not going to describe an automatic purge we do not run. If you want your data removed sooner than the table says, ask us, and we will delete what is not held under the ten-year row.
12. Your rights as a data subject, and how to exercise them
Articles 5 to 13 of Law No. 27 of 2022 on Personal Data Protection give you the rights below. Each entry names the Article it comes from and then says how to exercise it on this site rather than only naming it - and where there is no button for it, it says so.
- Information and access, Articles 5 and 6 - a copy of what we hold about you
- There is no download button on this site. Ask us and we will gather what we hold on your account, your addresses and your orders, and send it to you.
- Correction, Article 7 - putting right what is wrong or out of date
- You can change your delivery addresses yourself, at any time, on your account. There is no page here for changing your name, your email address or your phone number, so ask us and a member of staff will correct them.
- Ending processing, deletion and destruction, Article 8
- There is no self-service way to close your account here, and we will not pretend otherwise. Ask us and we will delete what we are able to delete. We cannot delete everything: invoices, payments and the accounting entries behind them have to be kept as accounting records, and the security log is what lets us establish what happened to an order.
- Delaying or limiting processing, Article 11 - having us pause
- Ask us. While a correction or an objection is being settled we will keep the data but stop using it for anything else.
- Portability, Article 13 - your data in a reusable form
- Ask us. We will supply the account, address and order data you gave us as a structured, machine-readable file.
- Objection, Article 10 - including to a decision taken by automated means
- Ask us. Article 10 covers a decision produced solely by automated processing that has a legal effect on you or a significant effect of the same kind; we take no such decision, as the clause on automated decisions sets out. The right also reaches what we do on the basis of our own legitimate interest, which here means our security logging and our analytics. We do no direct marketing, so there is nothing to object to on that front.
- Claim and compensation, Article 12
- You may sue and claim compensation for a breach of the law about your personal data. Tell us first if you are willing to, so that we can put right what can be put right; that is a request, not a condition, and it takes nothing away from the right.
- Complaint - taking it above us
- You may complain to the authority responsible for personal data protection in Indonesia. You do not have to come to us first, though we would rather you did, so that we get the chance to put it right.
One right on the statutory list is missing from ours, and its absence is the honest answer rather than an oversight: Article 9 gives you the right to withdraw your consent, and nothing we do with your personal data rests on consent, so there is no consent here for you to withdraw. If that ever changes, this notice will change with it and will say how to withdraw.
Two of these you can act on yourself, right now and without asking anyone: change your password, and add, edit or remove a delivery address. Both are on your account pages.
For everything else, email cs@nicoboulangerie.com, or reach us on WhatsApp or by telephone on +62 878 0021 2211. Tell us what you want and enough about yourself for us to find your account. Where the law fixes the time we answer within 3 x 24 hours of receiving your request - that covers giving you access to your personal data and correcting or updating it - and we act as quickly as we can on anything else.
13. Automated decisions and profiling
13.1 For the purposes of Article 10 of Law No. 27 of 2022, we take no decision about you based solely on automated processing, and we do not profile you. Nothing here scores you, ranks you, sorts you into segments, credit-checks you, or approves or refuses you automatically. Payment terms are agreed with you by a person and are never set by software. The only automatic refusals on this site are technical, and they look at requests rather than at people: a limit on repeated failed sign-in and password-reset attempts from the same internet address, and a check that refuses an order line below that pack's minimum order quantity.
14. Children
14.1 Article 25 of Law No. 27 of 2022 requires the personal data of a child to be processed with the consent of a parent or guardian. This site sells to businesses and to adults buying for themselves. It is not aimed at children, it does not knowingly collect a child's personal data, and it never asks for a date of birth or an age - so we have no means of telling that an account belongs to a child. If you believe a child has created an account here, tell us and we will delete it and the data behind it.
15. How we protect it
15.1 Passwords are stored only as a one-way hash, never in readable form, and must be at least 12 characters. Sessions live on our server; the cookie in your browser carries an identifier and nothing more, it is marked so that scripts cannot read it, it is not sent when another site makes a background request to us, and it is marked secure when you are on an encrypted connection. Your session identifier is replaced when you sign in and again when you change your password, and changing your password ends every other session on your account. Every form carries a token we check in constant time. Sign-in, registration and password-reset attempts share a rate limit per internet address. The links we email are stored only as hashes, expire, and work once. Our security log strips password-like and token-like values before writing, stores a hash of your browser's user-agent rather than the string itself, and records a failed sign-in against a hash of the email address rather than the address.
15.2 And what we do not claim. Your name, email address, phone number and delivery addresses are held in ordinary readable columns in our database; they are not individually encrypted. No system is perfectly secure, and nothing above is a guarantee that a breach cannot happen. This paragraph states a fact about our systems; it is not an exclusion of our liability, and nothing in this notice limits a liability we bear under Indonesian law.
16. If your personal data is ever exposed
16.1 Article 46 of Law No. 27 of 2022 requires us, where the protection of personal data fails, to give written notice within three times twenty-four hours to each person affected and to the supervisory authority. We undertake to do that. The notice will state the personal data exposed, when and how it happened, and what we have done and are doing about it. This is an undertaking we give under the statute, not a description of an automatic alert: no part of this website detects or reports a breach on its own.
17. Language of this notice
17.1 This notice is published in Indonesian and in English. In the event of any difference or inconsistency between the two versions, the Indonesian version prevails, in accordance with Article 31 of Law No. 24 of 2009 on the Flag, Language, National Emblem and Anthem.
18. Changes to this notice
18.1 When we change this notice we change the version number and the date at the top of it, and the new wording takes effect on that date. We do not keep an archive of earlier versions on this site; if you need to know what this notice said on a particular day, ask us.