1. Introduction
1.1 At Zen Resort Bali, respect for your privacy is part of how we care for the people who stay with us. This Privacy Policy (the "Policy") explains how we collect, use, store, share, and protect your personal information when you interact with us — through our website, our enquiry and booking channels, our wellness consultations, and during your stay.
1.2 This Policy forms an integral part of our Terms of Use. Any capitalised terms not defined in this Policy have the meanings given in the Terms of Use.
2. Data Controller
2.1 The data controller responsible for your personal information is Zen Resort Bali, PT AYUR ZEN PURI JATI RESORT. Contact details are set out in Part A, Section 29.
3. Information We Collect
3.1 The categories of information we collect depend on how you interact with us and the Services you request.
3.2 Personal Information may include:
• Name and title;
• Email address;
• Postal address;
• Telephone number;
• Nationality and passport or identity document details;
• Travel and arrival details (including flight information);
• Payment and billing details;
• Insurance information;
• Emergency contact details;
• Photographic or video images (e.g., CCTV, event photography).
3.3 Additional Information, shared voluntarily to enhance your stay, may include:
• Travel and retreat preferences;
• In-resort preferences;
• Dietary requirements and food preferences;
• Feedback, reviews, and survey responses;
• Booking history.
3.4 Health-Related Information (Sensitive Data). Where relevant to our Wellness Services and only with your explicit, informed, and freely given consent (which is collected separately from your general booking consent where required by applicable law), we may collect: general health background; medical conditions, injuries, and disabilities; allergies and food intolerances; pregnancy status; current medications; mental health conditions relevant to activity suitability; and Ayurvedic consultation notes. This is treated as sensitive personal data and given enhanced protection (see Section 8).
3.5 Device and Technical Information, collected automatically when you visit our website, may include: IP address, browser type, operating system, device identifiers, time zone, referring URL, pages visited, and interaction data, collected through cookies and similar technologies (see Section 9).
3.6 We do not intentionally collect information about your race or ethnicity, religious or philosophical beliefs, political opinions, sexual orientation, genetic or biometric data, trade union membership, orcriminal records.
3.7 All of the above is referred to collectively as "Information."
4. How We Collect Information
4.1 We collect Information through: (a) our website,email, and social media; (b) enquiry, booking, and transfer forms; (c) in-person interactions during your stay; (d) wellness consultations and healthscreening forms; (e) cookies and similar technologies on our website; (f) CCTVand security systems on the resort premises; and (g) trusted third parties such as travel agents, booking platforms (SiteMinder), and payment processors.
4.2 Providing certain Information is necessary for us to confirm your reservation, deliver our Services, ensure your safety, or meet legal requirements. Choosing not to provide it may limit our ability to assistyou fully or to permit your participation in certain activities.
5. How We Use Your Information
5.1 We use your Information for the following purposes: (a) managing your reservation and guest services; (b) personalising your wellness programme and experience; (c) processing payments and confirmations;(d) conducting health screening and assessing activity suitability; (e) responding to your enquiries, feedback, and reviews; (f) improving our Services and website; (g) maintaining safety, security, and legal compliance; (h) fulfilling legal and regulatory obligations; and (i) enforcing these Terms.
5.2 Purpose Limitation. We process your Information only for the purposes described in this Policy or as otherwise permitted by applicable law. We do not use health-related Information for marketing purposes.
5.3 Data Minimisation. We collect only the Information reasonably necessary for the purposes identified, and we do not retain Information longer than required (see Section 10).
5.4 Marketing. We send marketing communications only where you have given specific consent. You can withdraw marketing consent at any time using the unsubscribe link in our emailsor by contacting us. Withdrawal of marketing consent does not affect the lawfulness of processing based on consent before its withdrawal.
6. Consent and Legal Bases for Processing
6.1 Where applicable law requires it (including for Guests subject to EU GDPR, UK GDPR, or Indonesian personal data protection law), we process your Information on one or more of the following bases: (a) performance of a contract with you; (b) your consent; (c) compliance with a legal obligation; (d) protection of vital interests; and (e) our legitimate interests, where these are not overridden by your rights.
6.2 Separate Consent for Sensitive Data. Consent for the collection and processing of health-related and other sensitive personal data is collected separately from your general booking consent and is not bundled with consent for other purposes, where separate consent is required by applicable law. You may refuse or withdraw consent for the processing of sensitive data at any time; however, this may limit our ability to provide certain Wellness Services.
6.3 Withdrawal of Consent. Where processing is based on consent, you may withdraw consent at any time by contacting us at contact@zenresortbali.com. Withdrawal does not affect the lawfulness of processing carried out before the withdrawal, nor does it affect processing based on other lawful grounds.
7. Sharing, Service Providers, and International Transfers
7.1 We may share your Information with trusted service providers who support our operations and who are contractually required to handle it securely and lawfully. These include:
• SiteMinder, our booking platform, which processes your reservation details;
• PT NUSA SATU INTI ARTHA (DOKU), which handles your payment information;
• Google (Google Analytics), for website analytics;
• Other service providers engaged from time to time for IT support, communications, or marketing, subject to appropriate data protection agreements.
7.2 We may also disclose Information where required to comply with applicable law, regulation, legal process, or enforceable governmental request, or to protect the rights, property, or safety of Zen, our Guests, or others.
7.3 International Transfers. Because we operate in Indonesia and serve international Guests, your Information may be transferred to and stored in countries outside your own, including outside the EU/EEA/UK. Where this happens, we take reasonable steps to ensure appropriate safeguards are in place, which may include standard contractual clauses, adequacy decisions, or other transfer mechanisms recognised under applicable law. We do not, however, guarantee that the data protection laws of every country to which data may be transferred will provide the same level of protection as those in your home jurisdiction.
8. Enhanced Protection for Sensitive Health Data
8.1 Health-related and wellness consultation informationis treated as sensitive personal data and is subject to the following enhanced protections:
• Collected only with yourexplicit, separate consent;
• Accessed strictly on a need-to-know basis by authorised practitioners and relevant staff;
• Never used for marketing purposes;
• Never shared with third parties without your consent unless required by law or in a medical emergency to protect your vital interests;
• Stored securely with access controls appropriate to its sensitive nature;
• Retained only for the period necessary for wellness service delivery and legal compliance (see Section 10).
9. Cookies and Analytics
9.1 Our website uses cookies and similar technologies to understand how visitors use the site, improve usability, and enhance content. We use Google Analytics, a web analytics service provided by Google, which uses cookies to help us analyse how visitors use our site; the information generated (including your IP address) is transmitted to and stored by Google on servers that may be located outside your country of residence. You can read about Google's practices in Google's Privacy Policy.
9.2 When you first visit our website, our cookie-consent banner lets you accept or decline non-essential cookies, and you can change your preferences at any time. You can also manage or disable cookies through your browser settings. Disabling cookies may limit some website functionality but will not prevent basic access.
9.3 We do not use cookies to collect health-related orsensitive personal data.
10. Data Retention
10.1 We retain your Information only for as long as necessary for the purposes for which it was collected, or as required by legal, tax, accounting, or regulatory obligations. General retention periods include:
• Booking and guest records: retained for the duration of the business relationship and for a period thereafter as required by Indonesian tax and commercial law;
• Health and wellness records: retained for the minimum period necessary for service delivery and follow-up, then securely deleted or anonymised;
• Marketing consent records: retained for as long as the consent remains active, plus a reasonable period to demonstrate compliance;
• Website analytics data: retained in accordance with Google Analytics' default retention settings or as configured by Zen.
10.2 Where data is no longer needed, it is securely deleted or anonymised in accordance with our data retention schedule.
11. Data Breach Response
11.1 In the unlikely event of a personal data breach, Zen will: (a) take immediate steps to contain and investigate the breach; (b) assess the risk to affected individuals; (c) notify affected individuals without undue delay where the breach is likely to result in a high risk to their rights and freedoms; and (d) notify relevant data protection authorities where required by applicable law.
11.2 Zen maintains incident response procedures proportionate to the nature and sensitivity of the data it processes. However, no system of data storage or transmission can be guaranteed to be 100% secure, and Zen does not warrant or guarantee the absolute security of your Information.
12. Your Rights
12.1 Subject to applicable law (including, where applicable, EU GDPR, UK GDPR, and Indonesian personal data protection law), you may have the right to:
• Access the Information we hold about you;
• Request correction of inaccurate or incomplete Information;
• Request deletion of your Information (subject to legal retention requirements);
• Withdraw consent at any time (without affecting the lawfulness of prior processing);
• Object to processing based on legitimate interests or for direct marketing;
• Request restriction of processing in certain circumstances;
• Request data portability (where technically feasible and required by law);
• Lodge a complaint with a relevant data protection authority.
12.2 To exercise any of these rights, please contact us at contact@zenresortbali.com. We will respond within the time frames required by applicable law.
13. Children's Data
13.1 Children and families are welcome at Zen. Where we collect any Information relating to a child (under 18 or such lower age as defined by applicable law), we do so only from and with the explicit consent of a parent or legal guardian. Children's data is treated with the same care and protections as all personal Information and is not used for marketing purposes.
14. Security Measures and Limitations
14.1 We apply appropriate technical and organisational measures to protect your Information against unauthorised access, loss, destruction, or misuse, including access controls, encryption where appropriate, staff training, and confidentiality obligations for authorised personnel.
14.2 We endeavour to align our practices with internationally recognised data protection principles, including relevant local laws applicable to our operations. As we are based in Indonesia, the data protection framework governing your Information may differ from that of your home jurisdiction. We commit to handling your Information responsibly, respecting your privacy rights, and to continuously improving our data protection practices.
14.3 Third-Party Systems. We are not responsible for the security practices or data protection standards of third-party service providers, booking platforms, payment processors, or analytics services. While we select reputable providers and require contractual commitments, we cannot guarantee the security of data once it is in their possession.
15. Third-Party Links
15.1 Our website may link to third-party platforms such as booking engines, mapping services, or social media. We are not responsible for the privacy practices, content, or security of these external providers and encourage you to review their privacy policies separately.
16. Changes to This Policy
16.1 We may update this Policy from time to time to reflect changes in our practices, legal requirements, or operational needs. Any updates will be posted on our website. Where changes are material, we will endeavour to provide notice (such as a banner on our website or direct communication). Your continued use of our Services following an update indicates acceptance of the revised Policy.
17. Contact
If you have questions about this Policy or how your information is handled, or wish to make a request or complaint, please contact us:
Zen Resort Bali
PT AYUR ZEN PURI JATI RESORT
Address: PO Box18, Ds. Umeanyar, Seririt, Singaraja, North Bali 81153, Indonesia
Email: contact@zenresortbali.com
WhatsApp / Phone: +62 813 3779 3038
This Policy is effective from 1st September 2026.
