1. Who we are
IKIGAI Wellness Indonesia ("IKIGAI", "we", "us") designs and handcrafts saunas and ice baths in Jepara, Indonesia, for homes, villas, hotels and resorts. This policy explains what personal data we collect when you visit weareikigai.co, contact us, request a quote, buy from us or follow us on social media, and how we handle it.
The data controller is PT IKIGAI Wellness, Indonesia. We process personal data in line with Indonesia's Personal Data Protection Law (Law No. 27 of 2022, "PDP Law"). Because we serve clients and visitors worldwide, we also follow the data protection laws that apply where you are, including the EU General Data Protection Regulation (GDPR), the UK GDPR, the California Consumer Privacy Act as amended by the CPRA (CCPA), Australia's Privacy Act 1988 and Singapore's Personal Data Protection Act 2012 (PDPA). Section 7 sets out the extra rights you may have under those laws.
By using our website or services, you acknowledge this policy. If you do not agree with it, please do not submit personal data to us.
2. Information we collect
| Category | Examples | How we get it |
|---|---|---|
| Contact details | Name, email, phone or WhatsApp number | Forms, WhatsApp, email, quote requests |
| Order and delivery details | Billing and shipping address, order history, installation site details | Checkout, consultations, site surveys |
| Business details (B2B) | Company or property name, job title, project scope | Quote requests, meetings, proposals |
| Communications | Messages, call notes, feedback, reviews | WhatsApp, email, social media, in person |
| Technical and usage data | IP address, device and browser type, pages viewed, referral source | Cookies and analytics tools |
| Photos and video | Images of your installation, event or venue | Shoots, only with your consent |
We do not collect, process or store your payment data. Card numbers, bank account details and other payment information are never collected through our website or forms, and are never used by IKIGAI for any purpose.
We collect only what we need for the purposes in Section 3. We do not knowingly collect sensitive personal data (called "specific" data under the PDP Law and "special category" data under the GDPR), such as health or biometric data. Please do not send it to us.
3. How we use your information
| Purpose | Legal basis (PDP Law and GDPR) |
|---|---|
| Answer enquiries, prepare quotes and proposals | Steps before entering a contract |
| Process orders, production, delivery and installation | Performance of a contract |
| Provide warranty, maintenance and after-sales support | Performance of a contract |
| Send newsletters, offers and event invitations | Your consent (withdraw any time) |
| Show relevant ads and measure campaign performance | Your consent via cookie settings |
| Improve our website, products and service | Legitimate interest |
| Keep tax, accounting and business records | Legal obligation |
| Prevent fraud and protect our rights | Legitimate interest |
We will not use your data for a new purpose without telling you first and, where required, asking for your consent. Feature photos of your installation are only published with your permission.
5. Cookies, retention and security
Cookies. We use essential cookies to run the site and the cart, plus analytics and advertising cookies (such as Google Analytics and the Meta Pixel) to understand traffic and show relevant ads. You can accept or decline non-essential cookies in our cookie banner, or block them in your browser settings. Some site features may not work without essential cookies.
Retention. We keep personal data only as long as we need it:
- Order, invoice and tax records: as long as Indonesian tax and accounting law requires (generally 10 years).
- Warranty and after-sales records: for the warranty period of your product, plus a reasonable period after.
- Enquiries that did not become orders: up to 2 years from last contact.
- Marketing contacts: until you unsubscribe or withdraw consent.
After that, we delete or anonymise the data.
Security. We use access controls, encrypted connections (HTTPS) and trusted service providers to protect your data. No system is fully secure, but if a data breach affects you, we will notify you and the relevant authority within 3 x 24 hours as the PDP Law requires, and within the timeframes set by other applicable laws (for example, 72 hours to the supervisory authority under the GDPR).
6. Your rights
Under the PDP Law, you can ask us to:
- Tell you what personal data we hold about you and give you a copy
- Correct or update inaccurate data
- Delete your data or stop processing it, where we have no legal reason to keep it
- Withdraw consent you gave (for example, to marketing), without affecting past processing
- Object to automated decisions or profiling that significantly affect you
- Transfer your data to another controller
Questions? Talk to us.
If you have any question about your privacy or your information, message us on Instagram.
Message us on Instagram