USCM Conference
Home Privacy

Legal & Data

Privacy
Policy

How PT Bintan Resorts Cakrawala collects, uses, and protects personal data for the ASEAN Future Skills & Leadership Summit 2026.

Effective 16 July 2026 · aseanfuturessummit.com

This Privacy Policy explains how PT Bintan Resorts Cakrawala, trading as Bintan Resorts, collects, uses, discloses, stores, and protects personal data in connection with the ASEAN Future Skills & Leadership Summit 2026 (the “Event”). It should be read together with the Event Terms and Conditions and any consent notice displayed at the point of data collection.

1. Scope of This Policy

This Policy applies when you visit www.aseanfuturessummit.com, submit an enquiry, register or are registered for the Event, purchase an Event package or add-on, communicate with the Organizer, attend the Event, or interact with related digital services that link to this Policy.

“Personal data” means information relating to an identified or identifiable individual. References to “you” include website visitors, prospective participants, registered participants, speakers, invited guests, and individuals nominated by a corporate purchaser or sponsor.

This Policy does not govern a third party’s independent processing of personal data under its own privacy notice, including a hotel, payment provider, airline, ferry operator, academic institution, or external activity provider acting for its own purposes.

Applicable law. This Policy is governed by the laws of the Republic of Indonesia, including Law No. 27 of 2022 on Personal Data Protection and Government Regulation No. 71 of 2019 on the Operation of Electronic Systems and Transactions, together with other applicable requirements. Nothing in this Policy limits rights that cannot lawfully be excluded.

2. Who Is Responsible for Your Personal Data

PT Bintan Resorts Cakrawala, trading as Bintan Resorts, is the Organizer and the personal data controller for the processing described in this Policy, unless another entity is identified at the point of collection.

The Organizer may appoint service providers to process personal data on its instructions. Certain partners may also act as separate or joint controllers for specific activities. Where relevant, their identity and privacy information will be provided separately.

3. Personal Data We Collect

Information you provide

Depending on how you use the website or participate in the Event, we may collect:

  • Identity and contact information, such as name, title, nationality, date of birth where required, email address, telephone number, address, and emergency-contact details.
  • Professional information, such as employer, industry, job title, seniority, professional biography, business contact details, and areas of interest.
  • Registration information, including selected package, participant category, attendance status, session preferences, certificate details, discount or sponsorship eligibility, and acceptance of Event terms.
  • Accommodation and add-on information, including hotel selection, room category, bed preference, room upgrade, extra-bed request, companion information, additional nights, and other special requests.
  • Billing and transaction information, such as billing name and address, tax information, invoice details, payment method category, transaction reference, payment status, and refund or exception-review records.
  • Travel and logistics information, such as ferry or flight details, arrival and departure times, passport or visa-support information where necessary, and transfer requirements.
  • Dietary, accessibility, health, and safety information that you choose or are required to provide so that we can make reasonable arrangements and respond to emergencies.
  • Communications and submissions, including enquiries, complaints, survey responses, supporting documents for exceptional circumstances, and other correspondence.
  • Marketing and consent preferences, including whether you wish to receive information about this Event or related programs and whether you have agreed to optional uses of your image or information.

Payment-card information

Where payment is processed through an authorized third-party payment provider, the payment provider processes card or account credentials under its own security and privacy terms. The Organizer generally receives confirmation, a transaction reference, payment status, and limited billing information rather than full payment-card details. You should not send full card details by ordinary email or messaging applications.

Information collected automatically

When you use the website, we and authorized technology providers may automatically collect IP address, device identifiers, browser type, operating system, language, approximate location derived from IP address, referring and exit pages, pages viewed, links clicked, access times, session information, error logs, and cookie or similar-technology identifiers.

Information from other sources

We may receive personal data from your employer or corporate purchaser, sponsor, authorized representative, referral partner, payment provider, hotel, transportation provider, academic collaborator, or another Event supplier. A person or organization registering you must be authorized to provide your information and should make this Policy available to you.

4. Specific Personal Data

Health, disability, accessibility, dietary, religious, passport, and other information may be classified as specific or sensitive personal data depending on its content and applicable law. We collect only what is reasonably necessary, restrict access, and apply additional safeguards. Where consent is the applicable basis, you may withdraw it, although doing so may limit our ability to provide a requested accommodation or service.

Please do not provide medical records, identity documents, or other sensitive material unless the Organizer specifically requests them through an approved channel.

5. Why We Use Personal Data and Our Legal Bases

We process personal data only for specified and lawful purposes. Depending on the activity, our legal basis may be your consent, steps taken at your request before entering into an agreement, performance of the registration agreement, compliance with a legal obligation, protection of vital interests, performance of a task under applicable law, or another legitimate interest recognized by law.

We may use personal data to:

  • Respond to enquiries, evaluate registrations, confirm eligibility, issue invoices, receive payments, and administer cancellations or documented exceptional-circumstance requests.
  • Deliver the Event, including program access, participant communications, learning materials, certificates, accommodation, meals, transfers, security, networking activities, and selected executive experiences.
  • Coordinate with hotels, transport providers, academic collaborators, speakers, sponsors, activity providers, and other parties necessary to deliver the services you request.
  • Provide visa-support or invitation documentation where appropriate, without guaranteeing visa issuance or entry approval.
  • Protect participants, investigate misconduct or fraud, secure the website and payment process, prevent unauthorized access, and manage incidents or emergencies.
  • Comply with accounting, tax, reporting, recordkeeping, law-enforcement, court, and regulatory requirements.
  • Measure website and Event performance, understand participant needs, improve future programs, and maintain appropriate business and historical records.
  • Send operational communications and, where permitted, information about related programs. You may opt out of promotional communications at any time.
  • Create Event documentation and publicity materials as described in Section 11.

If we intend to use personal data for a materially different purpose, we will provide additional information and obtain consent where required.

6. Cookies and Similar Technologies

The website may use cookies, pixels, local storage, and similar technologies. These may include:

  • Strictly necessary technologies required for security, session management, registration, payment routing, and core website functions.
  • Functional technologies that remember preferences and improve website usability.
  • Analytics technologies that help us understand website traffic, performance, and user journeys.
  • Advertising or social-media technologies used to measure campaigns or deliver relevant communications, where enabled.

Non-essential technologies will be used only where permitted and, when required, after you make a choice through the website’s cookie preference tool. You can change your choices through that tool or your browser settings. Blocking certain technologies may affect website functionality.

Information about specific non-essential tools, their providers, purposes, and duration may also be presented through the website’s cookie preference tool.

7. When We Share Personal Data

We do not sell personal data. We may disclose only relevant information to:

  • Event hotels, including Holiday Inn Resort Bintan Lagoi Beach and Hotel Indigo Bintan Lagoi Beach, for accommodation, room upgrades, extra beds, dietary needs, and guest services.
  • Transportation providers, activity operators, caterers, venue teams, security and medical providers, and other operational suppliers.
  • Academic collaborators, faculty, speakers, moderators, and program administrators where necessary for program delivery, participant engagement, or certificates.
  • Payment providers, banks, accounting providers, insurers, fraud-prevention providers, and financial advisers.
  • Website hosting, cloud storage, email, communications, registration, customer-management, analytics, and cybersecurity providers.
  • Professional advisers, auditors, prospective transaction advisers, courts, regulators, law-enforcement authorities, and other persons where required or permitted by law.
  • Your employer, corporate purchaser, sponsor, or authorized representative for registration administration, payment, attendance confirmation, and agreed reporting.

We require service providers acting on our instructions to use personal data only for authorized purposes, apply appropriate security measures, and maintain confidentiality. We will not provide participant contact details to sponsors, other participants, or external marketers for their independent marketing without appropriate notice and consent.

8. International Data Transfers

Some academic collaborators, technology providers, payment providers, or other recipients may be located outside Indonesia. Where personal data is transferred internationally, we will assess the destination’s level of protection and use the transfer mechanism required by applicable law, which may include an adequate level of protection, appropriate and binding safeguards, or your consent where permitted. You may contact us for further information about safeguards relevant to your data.

9. How Long We Keep Personal Data

We retain personal data only for as long as reasonably necessary for the purpose for which it was collected, including Event delivery, legal and accounting obligations, dispute management, fraud prevention, security, and legitimate business records. Retention is determined by the nature and sensitivity of the information, legal requirements, contractual commitments, and the risk of harm from continued retention.

As a general rule:

  • Registration, contract, attendance, and operational records may be retained for up to five years after the Event or longer where a claim, investigation, or legal obligation requires it.
  • Invoices, tax, accounting, and transaction records are retained for the period required under applicable financial and tax laws.
  • Passport copies, visa-support documents, detailed travel information, and health or accessibility information should normally be deleted or irreversibly anonymized within 90 days after the Event, unless a longer period is necessary for an unresolved request, incident, claim, consented purpose, or legal obligation.
  • Unsuccessful enquiries and incomplete registration records may be retained for up to 24 months for follow-up, administration, and fraud prevention, unless you request earlier deletion and no lawful reason requires continued retention.
  • Marketing contact information is retained until you opt out or the Organizer determines that it is no longer current or necessary.
  • Technical logs and analytics information are retained according to the security and analytics configuration disclosed through the website’s cookie information.

When retention is no longer necessary, we will delete, destroy, anonymize, or place the information beyond operational use in accordance with applicable requirements.

10. Security and Personal Data Breaches

We use reasonable administrative, organizational, physical, and technical safeguards appropriate to the nature of the personal data and the risks involved. Measures may include access controls, authentication, encryption in transit, secure backups, logging and monitoring, role-based permissions, staff confidentiality obligations, supplier controls, and incident-response procedures.

No website or transmission method is completely secure. If a personal data breach occurs, we will investigate, take reasonable containment and remediation measures, and notify affected individuals and the relevant authority within the period required by applicable law when notification is required.

11. Event Photography, Recording, and Publicity

The Event may be photographed, filmed, livestreamed, or otherwise recorded for documentation, reporting, security, publicity, and promotion of the Event and related programs. Notices may be provided during registration and at the venue. Where consent is required, we will request it through an appropriate mechanism.

If you do not wish to be featured in identifiable promotional content, contact us before the Event and follow any onsite identification procedure communicated by the Organizer. We will make reasonable efforts to respect the request, but exclusion from incidental crowd, background, or public-area footage may not always be practicable. We will not use sensitive personal data or misleadingly endorse a product or service through your image without an appropriate basis.

12. Direct Marketing

Operational messages about your registration, payment, accommodation, schedule, safety, or Event changes are not promotional and may be sent where necessary to deliver the Event. Promotional email or messaging communications will be sent only where permitted. You may opt out at any time using an unsubscribe link or by contacting us. Opting out of marketing will not stop necessary Event-service communications.

13. Your Personal Data Rights

Subject to applicable law and any lawful limitations, you may have the right to:

  • Obtain information about the identity, accountability, legal basis, and purpose of the processing of your personal data.
  • Access and obtain a copy of personal data concerning you.
  • Complete, update, or correct inaccurate personal data.
  • Request termination of processing, deletion, or destruction of personal data where the legal requirements are met.
  • Withdraw consent where processing is based on consent, without affecting processing lawfully carried out before withdrawal.
  • Object to a decision based solely on automated processing that produces legal consequences or a significant impact.
  • Request restriction or postponement of processing in accordance with applicable law.
  • Obtain and transmit personal data in a commonly used, machine-readable format where the relevant portability requirements apply.
  • Claim compensation or submit a complaint through the remedies available under applicable law.

To exercise a right, contact us using Section 18. We may need to verify your identity and authority before acting. We will respond within the period required by law. A request may be limited or refused where permitted by law, including where necessary to protect another person’s rights, comply with a legal obligation, establish or defend a legal claim, or prevent fraud. We will explain the applicable reason where required.

14. Automated Decision-Making

We do not currently intend to make decisions about Event access or participation based solely on automated processing where the decision produces legal or similarly significant effects. If this changes, we will provide appropriate notice and safeguards.

15. Children

The website and Event are primarily intended for adults aged 18 and above. If participation by a person under 18 is exceptionally approved, we will obtain and verify the consent of a parent or lawful guardian and apply additional safeguards as required by law.

16. Third-Party Websites and Services

The website may link to third-party websites, payment pages, social-media services, hotel pages, or other external services. Their privacy practices are governed by their own notices. We encourage you to review them before submitting personal data.

17. Changes to This Policy

We may update this Policy to reflect changes in law, technology, website functionality, Event arrangements, or our processing practices. The revised version will be posted on the website with an updated effective date. Where a change materially affects your rights or the way we use previously collected data, we will provide additional notice and obtain consent if required.

18. Contact Us

For questions, requests, complaints, consent withdrawals, or concerns about personal data, contact:

PT Bintan Resorts Cakrawala
ASEAN Future Skills & Leadership Summit 2026
Email: info@aseanfuturessummit.com
Website: www.aseanfuturessummit.com