Privacy Policy
semeru.online by Sinar Kencana B.V.
Effective: 1 April 2026 · Version: 1.0
Governed by Dutch law and the GDPR
1. Who We Are
Semeru.online is a cloud-based Property Management System (PMS) developed and operated by Sinar Kencana B.V., a private limited company incorporated under the laws of the Kingdom of the Netherlands (KvK: 93803583, registered address: Rochussenstraat 9-2, 1051 JK Amsterdam, the Netherlands). Our platform serves hotels, guesthouses, vacation rentals, and serviced apartments primarily in Indonesia.
Sinar Kencana B.V. acts as the Data Controller for operator account data and platform operations. Property operators act as independent Data Controllers for guest data collected through their properties; Sinar Kencana B.V. acts as Data Processor on their behalf for that data.
Data Controller contact: privacy@semeru.online
2. Legal Basis for Processing (GDPR)
Where the GDPR applies, we process personal data on the following legal bases:
- Contract (Art. 6(1)(b) GDPR) — processing necessary to perform the subscription contract with operators and to fulfill guest reservations.
- Legal obligation (Art. 6(1)(c) GDPR) — compliance with EU, Dutch, and Indonesian legal obligations including tax, financial record-keeping, and anti-money-laundering regulations.
- Legitimate interests (Art. 6(1)(f) GDPR) — fraud prevention, platform security, profiling of operator and user activity data to improve product features and tailor our service offering, and direct B2B marketing to existing operator customers.
- Consent (Art. 6(1)(a) GDPR) — for optional communications such as product newsletters, and for WhatsApp marketing messages to guests where operator-configured.
3. Data We Collect
3.1 Property Operator Data
When you register a property on Semeru.online, we collect:
- Account information — name, email address, phone number, hashed password.
- Business information — property name and address, property type, Dutch VAT number (if applicable), Indonesian NPWP (if provided), and bank account details for payout.
- Property configuration — room types, pricing, policies, images, and videos.
- Team member data — names and email addresses of staff accounts.
- Usage and activity logs — actions performed within the platform for audit, support, and legal compliance purposes.
3.2 Guest Data (processed on behalf of operators)
When a guest makes a reservation or is manually registered by staff, we process:
- Identity — full name, email address, phone number, and optionally nationality and identity document number (KTP/passport).
- Reservation details — check-in/check-out dates, room type, guest count, special requests.
- Payment data — transaction identifiers and payment status only. Full card numbers are never stored — handled entirely by Stripe and Xendit (PCI-DSS Level 1 compliant).
- Communication records — booking confirmation emails and WhatsApp messages exchanged through the platform.
3.3 Automatically Collected Technical Data
Cloudflare, our infrastructure provider, automatically collects IP addresses, browser type, device type, pages visited, and request timestamps for security, performance, and DDoS protection purposes.
We use PostHog (PostHog Cloud EU, hosted within the EEA) as our product analytics platform, configured differently per surface:
- Operator dashboard — identified session data, page views, click events, and feature interaction events linked to the logged-in operator, for user-level product analysis.
- Guest booking portal — fully anonymous mode: person profiles disabled, IP addresses masked, no identification. Only anonymous event counts with no link to any individual.
4. How We Use Your Data
- Service delivery — operating the PMS, processing reservations, generating invoices, collecting payments, and synchronizing availability with OTA channels.
- Guest communication — booking confirmations, pre-arrival reminders, check-in instructions, and post-stay review requests via email and WhatsApp.
- Payment processing — transmitting payment data to Stripe (international) and Xendit (Indonesia) for transaction processing.
- Platform improvement — analyzing operator dashboard usage to understand platform usage, identify friction points, and develop new capabilities.
- Legal compliance — fulfilling obligations under Dutch, EU, and Indonesian law.
- Security and fraud prevention — detecting and preventing unauthorized access, abuse, and fraudulent transactions.
5. Who We Share Data With
We do not sell personal data. We share data only as necessary to operate the platform, under Data Processing Agreements (DPAs) with each sub-processor as required by GDPR Art. 28.
Infrastructure & Cloud
- Cloudflare, Inc. (USA/EU) — Hosting, CDN, DDoS protection, image/video storage. EU–U.S. DPF certified.
- Neon, Inc. (USA) — Managed PostgreSQL database. SCCs (Decision 2021/914).
Analytics
- PostHog, Inc. (EU Cloud, EEA) — Product analytics. No transfer required (within EEA).
Payment Processors
- Stripe, Inc. (USA / Ireland) — International card payments. SCCs + Irish entity within EEA.
- PT Xendit Payments Indonesia (Indonesia) — Virtual accounts, QRIS, e-wallets, retail. SCCs.
Communication Services
- Resend, Inc. (USA) — Transactional email. SCCs.
- Meta Platforms Ireland Ltd. (Ireland, EEA) — WhatsApp Cloud API (when enabled by operator). No transfer required.
6. Data Retention
- Operator account data — subscription period + 7 years after closure (Dutch BW Book 2 Art. 10 & Indonesian tax law).
- Guest reservation records — 7 years from check-out (Dutch civil limitation period).
- Payment transaction records — 7 years (Dutch bookkeeping law).
- WhatsApp message logs — 90 days (operational necessity).
- Technical access & error logs — 90 days (security & performance).
On permanent account closure, data not subject to a legal retention obligation will be anonymized or securely deleted within 30 days.
7. Data Security
We implement appropriate technical and organizational measures (TOMs) per GDPR Art. 32:
- All data transmission encrypted via TLS 1.2 or higher.
- Passwords stored using bcrypt/Argon2 — no plaintext passwords ever stored.
- Access to production systems restricted to authorized personnel with role-based access control and full audit logging.
- Payment card data never stored on our servers — delegated entirely to Stripe and Xendit (PCI-DSS Level 1 compliant).
- Database connections via encrypted tunnels through Cloudflare Hyperdrive — no direct public database access.
In the event of a personal data breach, we will notify the Autoriteit Persoonsgegevens within 72 hours (GDPR Art. 33) and notify affected data subjects without undue delay where the breach poses a high risk to individuals (GDPR Art. 34).
8. Your Rights
Under the GDPR you have the following rights. Users in Indonesia additionally hold rights under UU No. 27/2022 on Personal Data Protection, which we honour equally.
- Access (Art. 15) — request a copy of the personal data we hold about you.
- Rectification (Art. 16) — request correction of inaccurate or incomplete data.
- Erasure (Art. 17) — request deletion of your data, subject to legal retention obligations.
- Restriction (Art. 18) — request that we limit how we process your data.
- Portability (Art. 20) — receive your data in a structured, machine-readable format.
- Object (Art. 21) — object to processing based on legitimate interests, including direct marketing and profiling.
- Withdraw consent — where processing is based on consent, withdraw it at any time.
- Lodge a complaint — with the Autoriteit Persoonsgegevens or the supervisory authority of your EU member state.
To exercise these rights, contact privacy@semeru.online. We will respond within 30 days.
9. International Data Transfers
As a Dutch company, transfers of personal data from the EEA to third countries are governed by GDPR Chapter V. For each sub-processor outside the EEA, we rely on EU Standard Contractual Clauses (SCCs), EU–U.S. Data Privacy Framework (DPF), or European Commission adequacy decisions. A full record is available on request at privacy@semeru.online.
11. Children's Privacy
Semeru.online is a B2B platform. Our services are not directed at children under the age of 16. We do not knowingly process personal data of minors. If you believe we have inadvertently collected such data, contact us immediately at privacy@semeru.online.
12. Changes to This Policy
We may update this Privacy Policy periodically. For material changes, we will notify operators by email and display a prominent notice on the platform at least 14 days before the changes take effect. The current version is always available at semeru.online/privacy.
13. Contact & Supervisory Authority
For privacy requests or concerns:
- Company: Sinar Kencana B.V.
- KvK number: 93803583
- Registered address: Rochussenstraat 9-2, 1051 JK Amsterdam, the Netherlands
- Email: privacy@semeru.online
- EU supervisory authority: Autoriteit Persoonsgegevens