Privacy Policy
How the Secretariat collects, uses, and protects the personal data of those who register for the summit.
Version v2
IBC - IES 2027 Privacy Policy
1. Scope
a. The Indonesian Business Council ("IBC") is committed to protecting the confidentiality of Personal Data of every party who registers and/or participates in the Indonesia Economic Summit ("IES") 2027. IBC will not use such Personal Data for any purpose other than the organization of the event, the provision of services related to IES 2027 activities, and the operations of the IBC organization, unless otherwise specified in this Privacy Policy. Provided that this does not apply to the Personal Data of Users who:
i. a party may prove that it has legally possessed the User's Personal Data prior to its disclosure by such party and that the data was not obtained from the Disclosing Party or any other party bound by an obligation to maintain the confidentiality of information received from the Disclosing Party;
ii. The User's Personal Data has become publicly known without violating any applicable laws;
iii. Has become information that is publicly known, not as a result of any breach by the Receiving Party or its Representatives;
iv. The User's Personal Data was lawfully obtained by another party from other sources without confidentiality restrictions;
v. The User's Personal Data is required to be disclosed pursuant to a court order, court judgment, arbitration award, government agency, government official, or in accordance with applicable law; and/or
vi. The User's Personal Data that can be proven in writing to have been independently developed by the receiving party without utilizing the Confidential Information disclosed by the disclosing party.
b. The scope or coverage of the definition of Personal Data includes all data, details, information, and documents provided by visitors, participants, sponsors, partners, or related parties of participants (such as colleagues, employees, companies, official representatives, proxies, or other interested parties). Such data may encompass identity, contact information, organizational affiliations, as well as participation preferences in the event.
Furthermore, Personal Data may also include information related to patterns or habits in registering, attending event sessions, utilizing event facilities, as well as interactions during official activities of IES 2027, including but not limited to:
i. Data, information, or documents required or obtained by IBC from participants through registration forms or official communication channels of IES 2027.
ii. Data obtained from third parties with the consent of the participants, for example, through service providers of registration, payment, or sponsors.
iii. Data collected by IBC when participants attend events organized by IBC, including documentation in the form of photographs, video recordings, and/or audio recordings.
iv. Data lawfully obtained or accessed by IBC in accordance with the internal policies and procedures governing the organization of IES 2027.
v. Data that is required to be provided or has been voluntarily submitted by participants from time to time in connection with the organization of the event.
2. Purpose
a. IBC shall have the right to process the Participant's Personal Data in connection with or for the purposes of ("Purpose");
i. To verify and manage the accuracy of information provided by participants during registration.
ii. To carry out, manage, and monitor the organization of IES 2027.
iii. To send event-related information, including invitations, registration confirmations, announcements, and reminders, through official communication channels (including email and/or messaging applications).
iv. To facilitate communication and networking among participants, sponsors, and event partners.
v. To conduct surveys, research, evaluations, or development activities aimed at improving the quality of future events.
vi. To provide publication and promotional materials related to IES 2027, including the use of participant documentation (photographs, video recordings, and/or audio) for official IBC publicity purposes.
vii. To comply with legal obligations, directives from government agencies, and applicable laws and regulations.
b. The aforementioned purposes shall remain the basis for IBC to carry out the Processing of Personal Data as governed by this Privacy Policy, and to use, transfer, or disclose such data in good faith to:
i. Event partners, sponsors, or supporting service providers (such as providers of registration services, payment, information technology, documentation, and communication) who are duly appointed and bound by confidentiality obligations.
ii. Individuals and/or other entities cooperating with IBC in the organization of the event, provided that they are bound by confidentiality obligations with respect to the Personal Data.
iii. Government agencies, courts, law enforcement authorities, or other authorities, when required by applicable laws or regulations.
c. The processing of Participants' Personal Data shall be conducted solely by IBC employees, official service providers appointed by IBC, and/or other parties under the supervision and authority of IBC, who are obligated to maintain the confidentiality of the Personal Data.
3. Methods of Obtaining, Collecting, and Storing Users' Personal Data
a. IBC is committed to processing Personal Data in accordance with the principles of personal data protection, which include:
i. Conducted in a limited and specific manner, lawful, and transparent.
ii. Conducted in accordance with the Purposes that have been disclosed.
iii. Conducted with the assurance of participants' rights over their Personal Data.
iv. Conducted in an accurate, complete, up-to-date, and accountable manner.
v. Conducted by protecting the security of Personal Data from unauthorized access, disclosure, alteration, misuse, destruction, and/or loss.
vi. Conducted by notifying the purposes and activities of processing, as well as any failure to protect Personal Data should it occur.
vii. Destroyed and/or deleted when no longer required, upon a legitimate request from the participant, or in accordance with the provisions of applicable laws and regulations.
viii. Conducted in a responsible manner and capable of being clearly demonstrated.
b. IBC may process Participants' Personal Data (in encrypted form) obtained through:
i. The official registration form for IES 2027 (both online and offline).
ii. Communication with IBC through official channels (email, telephone, or messaging applications).
iii. Official event documentation (photographs, videos, or audio recordings).
iv. Authorized event support service providers bound by confidentiality obligations, based on the participant's consent.
4. Representations and Warranties
a. The participant hereby represents and warrants that all information and Personal Data disclosed and submitted to IBC are true, complete, and accurate.
b. The participant hereby represents and warrants that they shall comply with all applicable laws and regulations related to the organization of and participation in the IES 2027 event.
c. The participant hereby represents and warrants that they have obtained all necessary consents from the relevant parties (such as colleagues, employers, or other represented parties) in the event that the participant discloses or submits Personal Data belonging to such parties to IBC. Accordingly, IBC shall have the right to obtain, collect, process, store, and use the said Personal Data for the Purposes as outlined in this Privacy Policy.
5. IBC's Commitment to Participant's Personal Data
a. IBC shall process Participants' Personal Data solely in accordance with the Purposes stated in this Privacy Policy.
b. Should there be any other intentions and purposes beyond those previously specified, IBC shall explicitly disclose such purposes and shall not process any Personal Data without the Participants' lawful consent.
c. IBC is committed to providing information regarding the processing of Participant's Personal Data in a transparent and easily comprehensible manner through IBC's official communication channels.
d. IBC carries out the processing of Participants' Personal Data in full compliance with the applicable laws and regulations.
6. Limitations and Indemnification
IBC is committed to not selling Participants' Personal Data to any party and to ensure that all parties working for and/or on behalf of IBC are not involved in any activities related to the trade of Participants' Personal Data. However, IBC shall not be held liable for any form of loss, including risks associated with Personal Data, such as failures in confidentiality protection, disclosure, access, acquisition, processing, storage, use, or transfer of Personal Data, insofar as such losses are not proven to be caused by the fault or negligence of IBC or any party lawfully appointed by IBC ("Losses and Legal Issues"). For the sake of clarity, legal certainty, and transparency:
a. IBC shall not be liable to indemnify, respond to, or be held accountable, whether through its employees, representatives, or IBC affiliated parties for any claims, demands, or assertions arising out of or in connection with any loss or legal issues, unless such claims are supported by a precise and accountable assessment, accompanied by concrete evidence of factual and direct damages suffered by the Participant, as well as legally admissible and convincing proof of fault or negligence on the part of IBC.
b. IBC shall not be responsible for the accuracy, completeness, or legality of the Personal Data provided by the Participant and is under no obligation to verify the truthfulness of such information unless required by law.
c. IBC shall not be held liable for any legal violations committed by the Participant or any third party arising from the provision or disclosure of Personal Data by the Participant.
d. In the event that a third party is appointed to support the storage or processing of Personal Data, the Participant acknowledges that the primary responsibility remains with the third party, and IBC shall not be held liable for any violations or failures in the protection of Personal Data proven to have originated from such third party. However, IBC will make reasonable efforts to promptly notify the Participant upon becoming aware of any confidentiality breaches committed by the third party.
7. User Rights Over Their Personal Data
a. Participants have the right to submit a request to IBC to:
i. Complete, update, and/or correct any errors or inaccuracies in the Personal Data that has been submitted.
ii. Access and obtain a copy of their own Personal Data.
iii. Submit a request for the deletion and/or destruction of Personal Data, or withdraw consent for the processing of Personal Data previously given to IBC.
iv. Raise objections in the event of discrepancies regarding the results of the Personal Data processing conducted automatically.
v. Request a delay and/or restriction of the processing of Personal Data if such processing is carried out beyond the established Purpose.
b. Requests related to the Participants' right as mentioned above may be submitted via email to IBC's official email address and will be processed by IBC in accordance with the applicable laws and regulations.
c. In the event that the Personal Data provided belongs to a minor (under 18 years of age), the parent or guardian of the child has the right to submit a request for the deletion of the Personal Data by contacting IBC through the same procedure.
8. Changes to the Privacy Policy
IBC may amend or update this Privacy Policy from time to time in accordance with operational needs and applicable laws and regulations. Any material changes will be notified to Participants through the official IES 2027 website and/or IBC's official communication channels. By continuing to use the registration services and participate in IES 2027 activities after such changes, Participants are deemed to have read, understood, and agreed to the updated Privacy Policy.
9. Applicable Law
1. This Privacy Policy is subject to the laws of the Republic of Indonesia.
2. This Privacy Policy is made in Indonesian and English. If there is any difference or contradiction between the Indonesian and English version, the Indonesian version will be applied.
10. Data Collected at IES 2027 Registration
a. The IES 2027 registration form collects the following data, and only the following data:
i. Identity and contact details: salutation, full name, badge name, email address, telephone number, and nationality.
ii. Organisational details: organisation name, job title, department, organisation country, and organisation website.
iii. Identity documents are not collected for IES 2027 registration. Neither a national identity card nor a passport is requested, and no photograph of an identity document is uploaded. Attendance at the venue is verified with a QR credential issued by the Secretariat. Identity documents received for registrations completed before this provision took effect remain stored and are handled in accordance with paragraphs b and c below, and with section 12 paragraph b.
iv. For media registrations: a press card or equivalent letter of assignment, together with its validity date.
v. Dietary restrictions, allergies, and other personal requirements are not requested for IES 2027 registration. Such information received before this provision took effect remains stored and is handled like other registration data.
b. Stored identity document numbers are never displayed in full on any screen, including Secretariat screens. What is displayed is a masked form, for example C09xxxx28. The full number can only be revealed by an authorised verification officer, and every such reveal is logged.
c. Stored photographs of identity documents, and photographs of press cards, are held in restricted storage, never carry a public link, and can only be opened through a signed link valid for no longer than fifteen minutes.
11. Consents Requested
a. IES 2027 registration requests two consents:
i. Consent to this Privacy Policy. This is the only mandatory consent, because without it the registration cannot be processed at all.
ii. Consent to listing the Participant's name, job title, and organisation in a participant directory visible to other participants, together with consent to being contacted by official event partners and sponsors about their programmes. This consent is optional, and withholding it does not affect the registration. The two uses are requested as a single decision at the organiser's instruction, and are recorded as two separate entries, so that either may be withdrawn without withdrawing the other.
b. The recording of photographs, video, and audio during the event, and their use in official IBC documentation and publications, is not requested as a consent but given as a notice, on the basis of IBC's legitimate interest in documenting its own event. That notice is posted at the entrances to the venue and stated on the event page. A Participant who objects to the use of their image in official publications may notify the Secretariat, and IBC will endeavour not to use that image.
c. The time at which each consent was given, and the version of this Privacy Policy in force at that moment, are stored alongside the consent. The version in force is shown on this page.
d. The consent under paragraph a item ii may be withdrawn at any time by contacting the Secretariat. Withdrawal does not apply retroactively to processing already carried out, and cannot recall material already published.
12. Storage, Service Providers, and Retention
a. Registration data is held in a managed database located in Southeast Asia. Official email is sent through a transactional email provider, and the website is delivered through a content delivery network. Each of these providers acts as a processor on behalf of IBC, is bound by confidentiality obligations, and has no right to use the data for its own purposes.
b. Stored photographs of identity documents, and photographs of press cards, are destroyed once IES 2027 has concluded and all reporting obligations have been met, unless the Participant requests their deletion earlier.
c. Registration data other than identity documents is retained for as long as it is needed for the organisation of the following edition, unless the Participant requests its deletion.
13. Event Credential
a. The event credential takes the form of a QR code. Its contents consist solely of a random identifier, a digital signature, and a validity period. It contains no name, email address, job title, or identity document number.
b. Consequently, a photographed and circulated QR code does not reveal a Participant's Personal Data. The credential nonetheless remains personal and cannot be transferred to another person.
14. Contacting the Secretariat
a. Automated email from the registration platform is sent from an address that does not accept replies. All requests concerning Personal Data under Article 7, including requests for access, correction, deletion, withdrawal of consent, and objection, are to be sent to the Secretariat address shown on this page.
b. The Secretariat responds to such requests within the period prescribed by applicable laws and regulations.
Questions about this document: [email protected]