Privacy Policy

This privacy policy applies to the ticketing mobile client (including iOS, Android, and any other current or future mobile clients) of PT Kereta Cepat Indonesia-China (KCIC) 's mobile app ticketing network, as well as other functions and services provided by PT Kereta Cepat Indonesia-China (KCIC). ("we").

Dear user,

We fully recognize the importance of personal privacy and will make every effort to protect your personal information. We are committed to maintaining your trust in us and will protect your personal information based on the following principles: consistency of rights and responsibilities, clear purpose, consent based on choice, minimum necessity, security assurance, subject participation, openness and transparency. We will also take corresponding security measures that comply with mature industry security standards to protect your personal information. When you use our services, the personal information we collect will only be used for the purposes specified in this privacy policy.

The privacy policy will help you understand:

1. How to collect and use your personal information

2. How to share, transfer, and publicly disclose your personal information

3. How to save your personal information

4. Use of Cookies

5. Personal sensitive information reminder

6. Personal Information Security

7. Handling of personal information security incidents

8. Personal Information Protection for Minors

9. Your personal information rights

10. Changes to this Privacy Policy

11. How to contact us

1. How to collect and use your personal information

You understand and agree that:

To provide you with a better product and service experience, we are continuously striving to improve our technology. As a result, we may introduce new or optimized features from time to time, which may require collecting, using new personal information, or changing the purpose or method of using personal information. We will update this privacy policy or explain to you the purpose, scope, and usage of the corresponding personal information through pop-up windows or page prompts. We will collect and use your personal information with your explicit consent.

Personal information "refers to various types of information recorded electronically or in combination with other information that can identify the identity of a specific natural person or reflect the activities of a specific natural person.

Personal sensitive information "refers to personal information that, once leaked, illegally provided, or abused, may endanger personal and property safety, easily lead to damage to personal reputation, physical and mental health, or discriminatory treatment.

The content contained in the above personal information and personal sensitive information is consistent with Appendix A (informative appendix)-Examples of Personal Information and Appendix B (informative appendix)-Determination of Personal Sensitive Information of the latest effective version of the Personal Information Security Regulations.

(1) Basic functions for collecting and using your personal information

Our service includes some basic functions, including those necessary for online ticket purchasing, improving our service, and ensuring transaction security. We need to collect, save, and use the following personal information related to you in order to achieve these basic functions. If you do not provide relevant information, you will not be able to enjoy the services we provide. Please be aware that if necessary, we may verify the identity information you provide with the issuing authority to ensure the unity of the person and certificate, account and personal information security. The basic functions and the types of personal information required are as follows:

(1) Register as our user and log in

If you register as our user, you need to create a username and password so that we can provide you with ticketing and other services. You also need to provide your name, gender, country/region, ID type, ID number, ID validity period, date of birth, as well as a unique phone number, SMS verification code, email, and passenger type that corresponds to your identity information and can be contacted through phone calls.

If you only use information services such as browsing websites, checking remaining tickets, and stopping stations, you do not need to register as our user, nor do you need to provide the above information.

(2) Provide ticketing services for you

If you choose to book a ticket service, you need to provide the passenger's name, ID type, ID number, passenger type, mobile phone number, and email address. If you book a ticket for someone else, you need to provide the aforementioned personal information of the actual subscriber. Once the order is completed, it is deemed that the actual subscriber also agrees to accept this Privacy Policy. Therefore, before ordering products or services for others, you need to ensure that you have obtained their authorized consent.

(3) Ensuring Your Transaction Security

In order to improve the security of your use of the services provided by us and our partners, ensure the security of the operating environment and identify the abnormal status of registered accounts, better protect your or other users or the public's personal and property security from infringement, and better prevent security risks such as phishing websites, fraud, network vulnerabilities, computer virus, network attacks, network intrusion, We may use or integrate your user information, transaction information, device information, location information, log information, as well as information authorized or legally shared by our partners to comprehensively assess your account and transaction risks, conduct identity verification, detect and prevent security incidents, in order to more accurately identify violations of the laws and regulations of the Republic of Indonesia or the relevant agreement rules of the Kereta Cepat Jakarta-Bandung Internet Ticketing Network, And necessary recording, auditing, analysis, and disposal measures shall be taken in accordance with the law.

(2) Extended functionality for collecting and using your personal information

To make the services you enjoy more convenient or enrich your experience, we have provided the following extended functions, which may collect and use your personal information. If you do not provide these personal information, you can still use the basic functions listed in Article (1). These extended functions and the types of personal information required are as follows:

(1) For your convenience in using products or services

(a) Device Information: We will receive and record device related information based on the specific permissions you have granted during software installation and use, which can be used to identify your device (such as device model, operating system version, device settings, unique device identifier, device MAC address, application installation list, and other software and hardware feature information) to provide you with security guarantees. Please understand that when you switch the application to the device background for operation, due to network abnormalities or system reasons, the information collection behavior generated by your previous use of the application may not be immediately stopped, resulting in a brief background information collection behavior.

(b) Log information: When you use products or services provided by our website or client, in order to provide you with convenient services, we will automatically collect your usage of our services and save them as relevant network logs. Used for operational analysis and reporting of performance security vulnerabilities. For example, your search, etc.

Please note that individual device information and log information cannot identify a specific natural person. If we combine this type of non personal information with other information to identify a specific natural person, or use it in conjunction with personal information, during the combined use period, this type of non personal information will be considered personal information. Unless authorized by you or otherwise specified by laws and regulations, we will process and protect this type of personal information in accordance with this privacy policy.

(2) Provide you with specific products or services that you purchase or use

If you order any of the following products or services for others, you may need to provide the personal information of the actual subscriber. Once the order is completed, it is deemed that the actual subscriber also agrees to accept this Privacy Policy. Therefore, before ordering products or services for others, you need to ensure that you have obtained their authorized consent.

To display the order information of your account, we will collect the order information generated during your use of our services for display and easy management of your orders.

When you contact us, we may save your communication/call records and content, or the contact information you left behind, in order to contact you or help you solve problems, or record the solutions and results of related issues.

You can use the products or services provided by us and our business partners through the link entrance provided by the Kereta Cepat Jakarta-Bandung Mobile App Ticketing Network. When you use the above services through our products or services, you authorize us to receive, summarize, and analyze your personal or transaction information from our affiliated companies based on actual business and cooperation needs. We confirm that its source is legal or you authorize us to agree to its provision of your personal or transaction information to us. Before using the services provided by a third party, please ensure that you have fully understood the personal information collection and usage rules of the third party. If you encounter any problems, please consult the customer service of the company.

(3) Exceptions to obtaining authorized consent

According to relevant laws, regulations, and national standards of the Republic of Indonesia, collecting your personal information does not require your authorized consent in the following situations:

1) Related to our obligations under laws and regulations;

2) Directly related to the national security and national defense security of the Republic of Indonesia;

3) Directly related to public safety, public health, and major public interests;

4) Directly related to criminal investigation, prosecution, trial, and execution of judgments;

5) For the purpose of safeguarding your or other individuals' significant legitimate rights and interests such as life and property, but it is difficult to obtain my consent;

6) The personal information collected is publicly available to the public on your own;

7) Necessary for signing and fulfilling the contract according to your requirements;

8) Collect your personal information from legally disclosed information, such as legitimate news reports, government information disclosure, and other channels;

9) Necessary for maintaining the safe and stable operation of the provided products or services, such as detecting and handling malfunctions in the products or services.

10) As an academic research institution, it is necessary to conduct statistical or academic research in the public interest, and when providing academic research or descriptive results to the public, the personal information contained in the results is de labeled.

2. How to share, transfer, and publicly disclose your personal information
(1) Sharing

Based on your choice and authorization, or in accordance with the exception of obtaining authorization consent before sharing, transferring, or publicly disclosing personal information, we may share your order information, account information, contact information, and location information with third parties to ensure the smooth completion of the services provided to you. But we will only share your personal information for legitimate, legitimate, necessary, specific, and clear purposes, and only share personal information necessary for providing services. Our partners have no right to use the shared personal information for any other purpose.

Our partners include suppliers of products or technical services for various functions in this privacy policy, third-party merchants, and institutions, including but not limited to infrastructure technology services, logistics delivery services, payment and other services. The purpose of sharing this information is to achieve the functionality of the products or services you choose to use. For example, we need to share your order number and amount with third-party payment institutions to confirm your payment instructions and complete the payment; Alternatively, we need to share your order information and necessary information related to the transaction with third-party merchants to meet your purchasing needs for products or services, and enable them to complete subsequent after-sales services for you; Alternatively, you may authorize banks, credit reporting agencies, and other third parties to inquire and collect your information from us. We will share your information with the third party within the scope permitted by laws, regulations, and regulatory policies, as well as within the scope of your authorization to the third party. We will confirm the legality of the authorized personal information source based on our agreement with the third party, and process your personal information in accordance with laws, regulations, and regulatory policies.

In order for you to receive information push, use services provided by third-party platforms, use third-party payments, use map services, and use facial recognition functions, our application will embed authorized partner software tool development kits (SDKs) or similar other applications. We use these SDKs through interface calls provided by the operating system. You can check the names of these third-party SDKs by clicking here The provider, purpose and category of collecting personal information. Before using the services provided by a third party, please ensure that you have fully understood the personal information collection and usage rules of the third party. If you encounter any problems, please consult the customer service of the company.

If you would like to learn more about the privacy policy or development document link of third-party SDKs, please click here. Please note that the developer documentation or privacy policy pages in the above links are created and published by the corresponding SDK developers/providers. The relevant SDK developers/providers may make changes or adjustments to the links and link webpage content within the scope allowed by law. Please refer to the latest published link and link webpage content of the relevant SDK developers/providers. Due to some SDK developers/providers not providing online documentation, we are unable to provide links to privacy policies corresponding to all third-party SDK development documents.

In some cases, we may also be entrusted with processing your personal information, and our situation as a trustee usually includes:

The partner who commissioned us for promotion. Sometimes we provide promotional services on behalf of other companies to the user groups who use our products or services. After you agree, we will provide these partners with information about their promotion coverage and effectiveness, without providing your personal identification information, or we will summarize this information so that it does not identify you personally. For example, we can inform the client how many people have read their promotional information or purchased the client's products after seeing this information, or provide them with personally identifiable statistical information to help them understand their audience or customers.

We will sign strict confidentiality agreements with companies and organizations with which we share personal information, requiring them to handle personal information in accordance with this privacy policy and our other relevant confidentiality and security measures. Our partners have no right to use the shared personal information for any other purpose. If we want to change the purpose of processing personal information, we will seek your authorization and consent again. If we share children's personal information with third parties, we will conduct security assessments and use methods such as encryption, anonymization, and de identification to ensure the security of children's information.

(2) Transfer

We will not transfer your personal information to any company, organization, or individual, except in cases where authorized consent is obtained in advance when sharing, transferring, or publicly disclosing personal information.

When it comes to acquisitions, mergers, reorganizations, bankruptcies, or similar transactions or situations involving the transfer of personal information, we will inform you of the relevant situation and require new companies or organizations that hold your personal information to continue to be bound by this privacy policy. If the purpose of using personal information is changed, we will require the company or organization to seek authorization and consent from you again. If you go bankrupt without a receiver, we will delete your personal information in accordance with legal regulations.

(3) Public Disclosure

We will only publicly disclose your personal information in the following circumstances:

We may publicly disclose the personal information you specify with your explicit consent or voluntary choice;

In cases where it is necessary to provide your personal information in accordance with the laws and regulations of the Republic of Indonesia, mandatory administrative enforcement or judicial requirements, we may publicly disclose your personal information in accordance with the requirements. On the premise of complying with laws and regulations, when we receive the request for disclosure of information mentioned above, we will require the issuance of corresponding legal documents, such as subpoenas or investigation letters.

(4) Exceptions to obtaining prior authorization and consent when sharing, transferring, or publicly disclosing personal information
According to relevant laws, regulations, and national standards of the Republic of Indonesia, sharing, transferring, and publicly disclosing your personal information does not require your prior authorization and consent in the following situations:

1) Related to our obligations under laws and regulations;

2) Directly related to national security and national defense security;

3) Directly related to public safety, public health, and major public interests;

4) Directly related to criminal investigation, prosecution, trial, and execution of judgments;

5) For the purpose of safeguarding your or other individuals' significant legitimate rights and interests such as life and property, but it is difficult to obtain your own authorization and consent;

6) The personal information involved is personal information that you disclose to the public on your own;

7) Necessary for signing and fulfilling the contract according to your requirements;

8) Collecting personal information from legally disclosed information, such as legitimate news reports, government information disclosure, and other channels.

9) Necessary for maintaining the safe and stable operation of the products or services we provide, such as detecting and handling malfunctions in the products or services.

According to the laws and regulations of the Republic of Indonesia, sharing or transferring personal information that has undergone deidentification processing, and ensuring that the data recipient cannot recover and re identify the personal information subject, does not constitute external sharing, transfer, or public disclosure of personal information. The storage and processing of such data will not require separate notice to you and your consent.

3. How to save your personal information

Even if you visit our website from outside Indonesia, please note that your information will be stored and processed in Indonesia.

Generally speaking, we only retain your personal information for the shortest period necessary to achieve the above purposes. After the expiration date, we will delete or anonymize your personal information. If we cease to operate the Kereta Cepat Jakarta-Bandung Internet Ticketing Network products or services, we will promptly stop collecting your personal information, notify you of the cessation of operation in the form of individual delivery or announcement, and delete or anonymize the personal information held after the termination of service or operation.

4. Use of Cookies

Cookies are text files placed on your accessing device by a web server, which will help you recall information during subsequent visits and simplify the process of recording your personal information. You have the right to accept or reject cookies. If the browser automatically receives cookies, you can modify the browser's settings according to your own needs to reject cookies. Please note that if you choose to refuse cookies, you may not be able to fully experience the services provided by the Kereta Cepat Jakarta-Bandung Internet Ticketing Network.

5. Personal sensitive information reminder

Kereta Cepat Jakarta-Bandung Internet Ticketing Network reminds you that the content and information you upload or publish in the products and services provided by Kereta Cepat Jakarta-Bandung Mobile App Ticketing Network may involve your personal sensitive information. Including but not limited to ID number, personal biometric information (facial information, fingerprint information), travel information, and personal information of children under 14 years old (including). Therefore, you need to carefully consider before using the products or services we provide for you. You agree that these personal sensitive information will be processed in accordance with the purposes and methods outlined in this privacy policy.

6. Personal Information Security

(1) The Yawan high-speed railway mobile app ticketing website attaches great importance to information security and has established a dedicated team responsible for it. We strive to provide you with information protection by adopting appropriate management, technical, and physical security measures. We have established an information security guarantee system that is suitable for business development, referring to domestic and foreign information security standards and best practices.

(2) From the perspective of the data lifecycle, we have established security measures in various aspects such as data collection, storage, display, processing, use, and destruction. Different control measures are taken based on the level of information sensitivity, including but not limited to access control, SSL (Secure Socket Layer) encrypted transmission for encrypted storage, and sensitive information desensitization display. We have taken reasonable and feasible security measures that comply with industry standards to protect the security of the personal information you provide, using encryption technology to improve the security of personal information, using trusted protection mechanisms to prevent malicious attacks on personal information, and preventing unauthorized access, public disclosure, use, modification, damage, or loss of personal information.

(3) We have deployed access control mechanisms to ensure that only authorized personnel can access personal information. We have also implemented strict management for employees who may come into contact with your information, monitoring their operations, establishing approval mechanisms for important operations such as data access, internal and external transmission and use, desensitization, decryption, and signing confidentiality agreements with the aforementioned employees. At the same time, we also regularly provide information security training to employees, requiring them to form good operating habits in their daily work and enhance their awareness of data protection.

(4) Despite the aforementioned security measures, please also understand that there are no "comprehensive security measures" on the network. We will provide corresponding security measures based on existing technology to protect your information and provide reasonable security guarantees. We will do our best to prevent your information from being leaked, damaged, or lost.

(5) Your account has security protection functions. Please keep your account and password information safe and do not disclose your password to others or other websites. If you find that your personal information has been leaked, especially if your account and password have been leaked, please contact our customer service immediately so that we can take corresponding measures.

(6) Please save or backup your text, images, and other information in a timely manner. You need to understand and accept that the system and communication network you use to access our services may encounter problems due to factors beyond our control.

7. Handling of personal information security incidents

After an unfortunate personal information security incident occurs, we will initiate an emergency plan to prevent the expansion of the security incident. We will inform you of the basic situation and potential impact of the security incident in accordance with the requirements of the laws and regulations of the Republic of Indonesia, the measures we have taken or will take, suggestions for you to independently prevent and reduce risks, and remedial measures for you. We will inform you of the relevant situation of the event through email, phone call, push notifications, etc. When it is difficult to inform the personal information subject one by one, we will take reasonable and effective measures to publish the announcement. At the same time, we will also proactively report the handling of information security incidents in accordance with regulatory requirements.

8. Personal Information Protection for Minors

According to relevant laws and regulations of the Republic of Indonesia, minors under the age of 19 are considered minors, and minors under the age of 14 are considered children.

The Kereta Cepat Jakarta-Bandung Mobile App Ticketing Network is mainly aimed at adults. Without the consent of parents or guardians, minors, especially children under the age of 14, should not create their own personal information subject accounts. If you are the guardian of a minor, we remind you to fulfill your guardianship responsibilities correctly and protect the personal information security of the minor. If the minors under your supervision use our services, you should provide correct guidance and supervision. If you are a minor, please read this privacy policy carefully with the help and companionship of your parents or guardians before using the services of the Yawan high-speed rail mobile app ticketing website. Please use our services or provide information to us with the consent of your parents or guardians.

For the collection of personal information about minors, especially children, using our products or services with the consent of our parents or guardians, we will only use, share, transfer or disclose this information when permitted by laws and regulations, explicitly agreed by our parents or guardians, or necessary to protect minors. If we find ourselves collecting personal information about a child without the prior consent of our parents or guardians, we will try to delete the relevant data as soon as possible.

For children's personal information, we will further take the following measures:

(1) For the collected personal information of children, in addition to complying with the provisions of this privacy policy regarding user personal information, we will adhere to the principles of legitimate necessity, informed consent, clear purpose, security protection, and lawful use, strictly follow the requirements of laws and regulations such as the "Children's Personal Information Network Protection Regulations" for storage, use, and disclosure, and will not exceed the period necessary to achieve the purpose of collection and use, After the expiration, we will delete or anonymize the personal information of children.

(2) When you, as a guardian, choose to use the Kereta Cepat Jakarta-Bandung mobile app ticketing network related services for your child under guardianship, we may need to collect personal information of the child under guardianship from you for the necessary purpose of fulfilling relevant services. If personal information about children needs to be collected from you in specific services, we will obtain your authorization and consent in advance, and inform you of the purpose and purpose of the collection. If you do not provide the aforementioned information, you will not be able to enjoy the relevant services we provide. As a guardian, you should correctly fulfill your guardianship responsibilities and protect the security of children's personal information. If children themselves need to register or use our products or services, you should provide proper guidance and supervision.

(3) Children or their guardians have the right to access and correct their personal information at any time, and can also request correction and deletion from us.

We have designated a dedicated person to be responsible for protecting children's personal information. If you have any opinions, suggestions, complaints, or reports regarding children's personal information, please contact us through the contact information listed in this privacy policy. We will provide you with timely assistance.

9. Your personal information rights

We attach great importance to your attention to personal information and do our best to protect your rights to your personal information, unless otherwise stipulated by laws and regulations. To ensure security, we may require you to provide a written request or other means of proving your identity. Typically, we will process your request within 15 working days after receiving your feedback and verifying your identity. We do not charge any fees for your reasonable requests in principle, but for requests that are repeated multiple times and exceed reasonable limits, we will charge a certain cost according to the situation. We may refuse requests that are unfounded, require excessive technical means, pose risks to the legitimate rights and interests of others, or are highly impractical.

(1) You can enter the personal center, common information and other functional modules to access, correct, and delete your account information, including personal information, permission settings, security settings, common contacts, passwords, email, etc.

(2) You can log out of the Kereta Cepat Jakarta-Bandung mobile app ticketing network account through the following path:

1) You can log out of your account by logging into the Kereta Cepat Jakarta-Bandung mobile app ticketing website. The specific path is: click "My" click on "Logout";

2) Bring the original valid ID card filled out during registration to the nearest train station window for cancellation.

After canceling the Kereta Cepat Jakarta-Bandung Mobile App Ticketing Network account, we will stop providing services to you and will delete your personal information or anonymize it according to applicable laws and regulations, unless otherwise specified by laws and regulations.

(3) You can revoke your authorization by turning off device functionality. You can also revoke our full authorization to continue collecting your personal information by canceling your account.

(4) In the following situations, according to the requirements of laws, regulations, and national standards, we will not be able to respond to your request:

1) Related to our obligations under laws and regulations;

2) Directly related to national security and national defense security;

3) Directly related to public safety, public health, and major public interests;

4) Directly related to criminal investigation, prosecution, trial, and execution of judgments;

5) There is sufficient evidence to indicate that you have subjective malice or abused your rights;

6) For the purpose of safeguarding your or other individuals' significant legitimate rights and interests such as life and property, but it is difficult to obtain your own authorization and consent;

7) Responding to your request will cause serious damage to the legitimate rights and interests of you or other individuals or organizations;

8) Involving trade secrets.

10. Changes to this Privacy Policy

The content of this privacy policy may be updated from time to time to adapt to legal, technological, or commercial developments. The updated privacy policy will be announced on the Yawan high-speed rail internet ticketing website, and major changes will be notified to users in appropriate forms such as website announcements and user notifications. The significant changes referred to in this privacy policy include:

(1) Our service model has undergone significant changes, such as the purpose of processing personal information, the type of personal information processed, and the way personal information is used;

(2) We have undergone significant changes in ownership structure, organizational structure, and other aspects, such as changes in ownership caused by business adjustments, bankruptcy mergers and acquisitions, etc;

(3) Changes in the main objects of personal information sharing, transfer, or public disclosure;

(4) Your right to participate in personal information processing and the way you exercise it have undergone significant changes;

(5) When there are changes in the responsible department, contact information, and complaint channels for handling personal information security;

(6) When the personal information security impact assessment report indicates a high risk.

11. How to contact us

You can contact us through the following methods. Generally, we will accept and process your request for personal information within 15 working days.

Email:itoperation.kcic@gmail.com

If you are not satisfied with our response and believe that our personal information processing behavior has harmed your legitimate rights and interests, you can file a complaint with the customer service of the Kereta Cepat Jakarta-Bandungway Mobile App Ticketing Network, or file a complaint or report with the public security organs or regulatory departments such as network information, telecommunications, and marketing, or file a lawsuit with the people's court with jurisdiction in the defendant's place of residence.