Indonesia’s Law No. 27 of 2022 on Personal Data Protection (PDP Law) came fully into effect on October 17, 2024 . As a WooCommerce store operator, you are legally classified as a “Data Controller” and must ensure full compliance. This privacy policy is drafted based on authoritative sources including the PDP Law, examples from Indonesian entities, and legal requirements for e-commerce .
PRIVACY POLICY
Website: pnny.tv
Entity: PNNY TV
Contact Email: shop @pnny.tv
Effective Date: [February 2026]
This Privacy Policy (the “Policy”) describes how PNNY TV (“we”, “our”, or “us”) collects, uses, discloses, and protects your personal data when you visit our website pnny.tv (the “Website”) and purchase our products or services. We are committed to protecting your privacy in accordance with Law No. 27 of 2022 concerning Personal Data Protection (“PDP Law”) and other applicable laws and regulations in the Republic of Indonesia .
By accessing or using our Website and making transactions, you acknowledge that you have read and understood this Privacy Policy.
1. Definitions
To help you understand this policy, here are some key legal terms used:
-
Personal Data: Any data about an identified or identifiable natural person (data subject) that can be identified on its own or combined with other information, either directly or indirectly through electronic or non-electronic systems . This includes names, IDs, contact details, and financial data.
-
Processing: Any operation performed on personal data, whether or not by automatic means, including collecting, storing, using, disclosing, and deleting .
-
Data Controller: The party that determines the purpose and means of processing personal data—in this case, PNNY TV .
-
Consent: Your explicit agreement to the processing of your personal data for specific purposes.
2. Types of Personal Data We Collect
We collect data to process your orders and improve your shopping experience. We collect both general personal data and specific personal data (such as financial data) as defined by the PDP Law .
A. Data You Provide Directly
-
Identity Data: Full name, gender, date of birth (if applicable).
-
Contact Data: Email address (shop@pnny.tv is our contact, but we will collect your email), phone number, and shipping/billing address.
-
Financial Data: Bank account numbers, credit/debit card details, or e-wallet information necessary to process your payments . (Note: We use secure payment gateways and do not store full card details on our servers).
-
Account Data: Username, password, and purchase history.
-
Communication Data: Content of messages you send to us via our contact form or email, including customer support queries .
B. Data Collected Automatically (Through Technology)
When you interact with our WooCommerce store, we may automatically collect technical data via cookies and similar technologies :
-
Device Data: IP address, browser type and version, operating system, and device identifiers.
-
Usage Data: Information about how you use our website, such as products viewed, items added to cart, clickstream data, and traffic patterns .
C. Data from Third Parties
We may receive data from third-party service providers we use, such as payment processors (e.g., Midtrans, Xendit, or banks) and shipping couriers (e.g., JNE, SiCepat, J&T), but only to the extent necessary to fulfill your order .
3. Purposes of Data Processing and Legal Basis
Under the PDP Law, we must have a legal basis to process your data . We process your personal data for the following purposes:
| Purpose | Legal Basis |
|---|---|
| To process and deliver your orders (including payment verification and shipping) | Contractual Necessity: Processing is necessary to fulfill our contract with you . |
| To manage your account and provide customer support | Contractual Necessity / Consent |
| To send administrative information (order confirmations, shipping updates, policy changes) | Legal Obligation / Contractual Necessity |
| To personalize your experience and recommend products | Legitimate Interests (to improve your shopping experience) |
| To analyze website usage and improve our store’s performance | Legitimate Interests (to improve our business operations) |
| To send marketing communications (promotions, newsletters) only if you have subscribed | Consent (You have the right to withdraw this consent at any time) |
| To comply with legal obligations (tax reporting, fraud prevention, law enforcement requests) | Legal Obligation |
4. Cookies and Tracking Technologies
Our Website uses cookies to enhance functionality and analyze traffic. Cookies are small text files stored on your device .
-
Types we use: Session cookies (deleted when you close your browser) and persistent cookies (to remember your preferences).
-
Purpose: We use cookies to remember items in your cart, recognize you when you return, and understand which products are popular.
-
Your Control: You can manage your cookie preferences through your browser settings. However, disabling cookies may affect the functionality of our store, such as the ability to add items to your cart .
5. Data Sharing and Disclosure
We respect your privacy. We do not sell your personal data to third parties . However, we need to share data with trusted partners to operate our store:
-
Service Providers:
-
Payment Processors: To process your payments securely.
-
Shipping Couriers: To deliver your orders (they receive your name, address, and phone number).
-
IT and Hosting Providers: Such as our web host and WooCommerce infrastructure providers.
-
Analytics Providers: To help us understand how our site is used.
-
-
Compliance with Law:
We may disclose your data if required to do so by law or in response to valid requests by public authorities (e.g., a court or government agency) .
All third parties are contractually obligated to protect your data and process it only according to our instructions, in line with the PDP Law .
6. International Data Transfers
As a website accessible globally, your personal data may be transferred to, and processed in, countries other than Indonesia (for example, if our hosting servers or email marketing platform are located overseas).
-
If we transfer your data outside Indonesia, we ensure it is protected by appropriate safeguards, such as Standard Contractual Clauses or ensuring the recipient country has adequate data protection laws, in compliance with the PDP Law .
7. Data Retention
We will retain your personal data only for as long as necessary to fulfill the purposes outlined in this policy, unless a longer retention period is required or permitted by law (for example, for tax or accounting purposes, or to defend against legal claims) .
-
Order Data: Retained for the duration of our business relationship plus the period required by Indonesian tax and commercial laws.
-
Marketing Data: Retained until you withdraw your consent (unsubscribe).
When data is no longer needed, we will securely delete or anonymize it .
8. Your Rights as a Data Subject
Under Indonesia’s PDP Law, you have significant rights regarding your personal data . You have the right to:
-
Right to Information: To be informed about how your data is collected and used (as provided in this policy).
-
Right to Access: To request access to and obtain a copy of your personal data that we hold .
-
Right to Rectification: To request correction of inaccurate or incomplete personal data .
-
Right to Erasure (Right to be Forgotten): To request the deletion or destruction of your personal data, subject to certain legal exceptions .
-
Right to Restriction: To request the suspension of personal data processing .
-
Right to Data Portability: To request your data in a commonly used electronic format to be transferred to another data controller .
-
Right to Object: To object to certain processing activities, such as direct marketing .
-
Right to Withdraw Consent: If we process your data based on consent (e.g., for marketing), you can withdraw it at any time. Withdrawal does not affect the lawfulness of processing based on consent before its withdrawal .
How to Exercise Your Rights:
To exercise any of these rights, please contact us at shop @pnny.tv. We will respond to your request within the timeframe required by law (typically a maximum of 3×24 hours for certain requests) . We may need to request specific information from you to confirm your identity before processing your request .
9. Data Security
We take the security of your personal data seriously. We implement appropriate technical and organizational security measures to protect your data from unauthorized access, loss, misuse, alteration, or destruction . These measures include:
-
SSL encryption on our website to protect data in transit.
-
Firewalls and access controls.
-
Restricted access to personal data to only those employees and partners who need it to perform their jobs .
However, please remember that no method of transmission over the Internet or method of electronic storage is 100% secure.
10. Children’s Privacy
Our Website and services are not intended for individuals under the age of 18. We do not knowingly collect personal data from children. If you are a parent or guardian and believe your child has provided us with personal data, please contact us. If we become aware that we have collected personal data from a child without verification of parental consent, we will take steps to delete that information .
11. Changes to This Privacy Policy
We may update this Privacy Policy from time to time to reflect changes in our practices, legal requirements, or operational needs . Any changes will be posted on this page with an updated “Effective Date.” We encourage you to review this policy periodically. In case of material changes, we may notify you via email or a prominent notice on our Website .
12. Contact Us
If you have any questions about this Privacy Policy, wish to report a concern, or wish to exercise your data protection rights, please contact us at:
Email: shop @pnny.tv
Website: pnny.tv
Attention: Data Protection / Privacy Officer