1. Who We Are
This Privacy Policy explains how PT TOTALINDO HIJAU LESTARI, operating under the Dream Living Management brand, collects and processes Personal Data.
In this Privacy Policy, "Dream Living," "we," "us," and "our" refer to:
Dream Living Management
Batam, Kepulauan Riau, Indonesia
Registered office and privacy contact: Komplek Megacipta Industrial Park Blok A Nomor 3, Batam, Kepulauan Riau, Indonesia — admin@dreamliving.id
Support contact: +62 853-5576-1308
For the processing described in this Privacy Policy, PT TOTALINDO HIJAU LESTARI generally acts as the Personal Data Controller. A third party, such as an online travel agency, payment provider, property owner, or service provider, may act as a separate controller or processor for its own activities.
2. Scope of This Policy
This Privacy Policy applies when you interact with:
- dreamliving.id and its official subdomains;
- the Dream Living web application, accounts, dashboards, and portals;
- direct booking and monthly rental inquiry flows;
- the Guest Portal, Tenant Portal, Landlord Dashboard, and Digital Concierge;
- public and authenticated website chat, including AI-assisted support;
- official email, telephone, OTA messaging, and other approved communication channels; and
- related accommodation, property management, boarding house, guest, tenant, landlord, and support services.
Together, these are called the "Services."
This Privacy Policy does not govern a third-party website or service merely because the Services link to it. Online travel agencies, payment providers, maps, social media platforms, and other third parties apply their own privacy notices to processing they independently control.
The commercial rules for bookings, tenancies, payments, and refunds are set out in our Terms & Conditions and Refund Policy.
3. Key Terms
For this Privacy Policy:
- Personal Data means data about an identified or identifiable individual, whether identified directly or by combining it with other information.
- Data Subject means the individual to whom Personal Data relates.
- Processing includes collecting, recording, organizing, analyzing, storing, changing, displaying, sharing, transferring, restricting, deleting, and destroying Personal Data.
- Controller means the party that determines why and how Personal Data is processed.
- Processor means a party that processes Personal Data for a Controller under documented instructions.
- Sensitive Access Data means door codes, lockbox codes, WiFi credentials, access tokens, and similar information used to enter or use a property or private part of the Services.
- OTA means an online travel agency or rental platform through which a reservation or inquiry is made.
4. Whose Data We Process
We may process Personal Data relating to:
- public website visitors and account users;
- prospective, current, and former short-term rental guests;
- prospective, current, and former boarding house tenants;
- people included in a reservation or tenancy by the primary guest or tenant;
- landlords, property owners, clients, and their authorized representatives;
- property management and guest service prospects;
- people who contact support or use website chat;
- vendors, contractors, personnel, and job applicants; and
- authorized internal users of the Dream Living System.
If you provide Personal Data about another person, you must be authorized to do so and must provide that person with this Privacy Policy when required.
5. Personal Data We Collect
The Personal Data we collect depends on your relationship with us and the feature you use.
5.1 Contact and Account Data
- full name, display name, email address, telephone number, and preferred language;
- account identifier, role, assigned property, and portal access status;
- password hash and other authentication information;
- account recovery, login, activation code, and security event information; and
- communication preferences and consent records.
We do not store account passwords in readable form.
5.2 Reservation and Stay Data
- reservation number, property, booking source, stay dates, guest count, and booking status;
- check-in and checkout details, arrival information, special operational requests, and stay history;
- house-rule acceptance, e-consent or e-contract records, checklist completion, and feedback;
- Digital Concierge access status and activity; and
- records of incidents, damage, complaints, support, safety, or security matters.
5.3 Identity and Verification Data
- name, nationality, date of birth where required, and identity document type;
- KTP, passport, SIM, or another approved identity document;
- identity document number and a copy or image of the document where required;
- verification result, reviewer, submission time, consent time, and accepted terms version; and
- immigration reporting data and reference number for foreign guests where applicable.
Identity documents contain high-risk Personal Data. We limit their collection, access, use, and retention to verified operational and legal needs.
5.4 Tenant and Rental Data
- room and property assignment, move-in and move-out dates, rental amount, and due date;
- rental inquiry, monthly budget, requested room type, and application status;
- signed contract, deposit, billing, invoice, payment, and refund information;
- tenant activation code status and portal history; and
- internal operational notes that are relevant to the tenancy.
5.5 Landlord and Property Owner Data
- identity and contact details;
- property ownership, assignment, agreement, and management-fee information;
- Owner Payable, payout, bank, transaction, tax, and financial reporting information; and
- account assignment, dashboard access, and communications.
5.6 Transaction and Payment Data
- amount, currency, invoice, billing period, payment date, payment status, source, and reference number;
- deposit, refund, chargeback, owner settlement, and accounting allocation information; and
- limited payment-provider response data needed to verify a transaction.
When an online payment function is enabled, payment providers process payment credentials under their own terms and privacy notices. Dream Living must not store a complete payment card number or card verification value.
5.7 Communications and Support Data
- email, support form, telephone, OTA message, and approved messaging-channel content;
- website and portal chat messages, attachments, conversation summaries, and feedback;
- page, property, reservation, billing, or account context connected to a support request; and
- AI response, escalation reason, human handoff record, and support outcome.
Do not submit full payment card details, account passwords, or unnecessary identity documents in a chat message.
5.8 Technical, Device, and Usage Data
- IP address, browser, device type, operating system, language, time zone, and general location inferred from IP address;
- login time, access logs, error logs, security events, session identifiers, and referral page;
- pages and features used, Digital Concierge events, notification preferences, and interaction timestamps; and
- cookie, local-storage, and similar technology data described in Section 12.
We do not collect precise device location unless a feature clearly requests it and a valid legal basis applies.
5.9 Recruitment and Personnel Data
If you apply to work with us or work for us, we may process your application, employment history, identity, contact, compensation, attendance, tax, banking, performance, contract, benefit, and emergency-contact information for recruitment, personnel administration, payroll, legal compliance, and workplace management.
5.10 Digital Concierge Portal Data
The Digital Concierge is a per-reservation web portal opened through a unique tokenized link that we send to the guest. There is no guest account and no guest password, so the link itself is the credential. Anyone holding the link can open the non-secret parts of the portal. Keep the link private and tell us immediately if it is forwarded or lost, so we can revoke it.
- guest name, email address, and the portal language you select;
- acceptance of the house rules and stay terms, recorded with the acceptance time and the exact version of the text shown to you;
- the identity document you upload, stored in private storage with no public address and opened by an authorized person only through a short-lived link;
- onboarding progress across the welcome, email, terms, and identity steps;
- portal activity events, limited to portal visit, terms accepted, document uploaded, verification complete, access code revealed, and feedback submitted, each with a timestamp;
- feedback, ratings, and any issue you report through the portal; and
- machine translation of portal content into your selected language, cached so the same text is not sent for translation again.
Access codes. Lockbox codes, WiFi credentials, and smart-lock instructions are never included in the page data sent to your device when the portal loads. A value is delivered only when you press the reveal control, after a separate server check of the link, your verification status, and the time window. Access opens 15 minutes before the effective check-in time, the value hides itself again after 20 seconds, and reveal requests are rate limited. We record that a reveal happened. We do not record the value.
5.11 Tenant Portal, Billing, and Payment Flow Data
Boarding house tenants receive portal access on an email address assigned by our team. There is no public self-signup for the Tenant Portal.
- monthly invoices, billing period, due date, prorated date range and number of nights charged, deposits held as Dana Titipan, payment history, and printable invoices;
- contract information attached to an invoice, such as room, property, and rental amount;
- checkout data created with our payment provider, including the payment link, its expiry, the status returned to us, and the reference number; and
- portal notifications, such as invoice issued, payment reminder, payment confirmed, and deposit updates.
When you pay, you leave the portal for the payment provider's own checkout page and return afterwards. The provider processes your payment credentials under its own privacy notice. We receive the outcome, not your card or bank credentials. If a payment link has expired, a new one can be generated, and the portal re-checks payment status when you return so a completed payment appears without contacting us.
5.12 Owner and Landlord Portal Data
- portal login identifier, activation and revocation status, and session activity;
- reservation, occupancy, Total Dana Diterima, Management Fee PT, Hak Owner, payout, and owner-borne expense information for the properties assigned to you;
- notification preferences, weekly digest settings, and unsubscribe records; and
- calendar export and channel synchronization data, where an export address lets an OTA or calendar application read booked and blocked dates for your property.
An owner or landlord never receives guest identity documents, access codes, guest support conversations, or another owner's data.
5.13 Notification, Email, and Messaging Data
- email delivery data for booking confirmations, invoices, receipts, reminders, portal invitations, and digests, including the message sent, its delivery status, and unsubscribe events;
- browser push subscriptions, held as an anonymous delivery address issued by your browser vendor and used only for notifications you enabled; and
- internal operational alerts to our own staff channel, including automated check-in reminders seven days, three days, and one day before arrival.
The internal alert channel is staff-only. It is not a guest or tenant communication channel, and it carries operational reservation details, never identity documents or access codes. Essential service, billing, safety, and legal messages are still sent after you unsubscribe from optional updates.
6. How We Collect Personal Data
We may collect Personal Data:
- directly from you when you browse, create an account, make a booking, submit an inquiry, upload a document, accept terms, make a payment, use a portal, or contact us;
- from the primary guest, tenant, property owner, or authorized representative who provides information about you;
- from an OTA or rental platform when it sends us reservation or inquiry details;
- from payment, fraud-prevention, authentication, communication, and security providers;
- from a property owner or landlord where needed to perform a property management agreement;
- from government bodies or lawful requests; and
- automatically from your device when you use the Services.
We do not collect Personal Data from social media merely because it is publicly visible. If we use public information for a legitimate business purpose, we will assess its legality, necessity, and effect on your rights first.
7. Why We Process Personal Data and Our Legal Bases
We process Personal Data only when we have a valid legal basis under applicable law.
| Purpose | Typical Data | Legal Basis |
|---|---|---|
| Provide account registration, authentication, recovery, and assigned portal access | Contact, account, authentication, role, and security data | Contract performance, steps requested before a contract, legal obligation, and legitimate interests in access security |
| Process reservations, rental inquiries, stays, tenancies, and property services | Contact, reservation, stay, tenant, property, and contract data | Contract performance and steps requested before a contract |
| Verify guest or tenant identity and protect a property | Identity document, verification, reservation, tenancy, and security data | Contract performance, legal obligation, and legitimate interests in fraud prevention, safety, and property security |
| Meet immigration, tax, accounting, consumer, and other legal duties | Identity, foreign guest, transaction, invoice, contract, and accounting data | Legal obligation |
| Process and verify payments, deposits, refunds, and owner settlements | Transaction, payment status, billing, deposit, and payout data | Contract performance, legal obligation, and legitimate interests in preventing fraud and resolving disputes |
| Deliver the Guest Portal, Tenant Portal, Landlord Dashboard, and Digital Concierge | Account, assignment, reservation, tenancy, report, verification, and usage data | Contract performance and legitimate interests in delivering secure, relevant access |
| Provide support, AI-assisted chat, and human handoff | Contact, chat, page context, reservation or billing context, and support outcome | Contract performance, steps requested by you, and legitimate interests in service quality and support continuity |
| Secure, monitor, test, maintain, and improve the Services | Device, log, error, security, usage, and de-identified analytics data | Legal obligation and legitimate interests in reliable and secure Services |
| Send operational messages | Contact, booking, billing, portal, and service status data | Contract performance and legal obligation |
| Send marketing messages | Contact and preference data | Separate, explicit consent where required |
| Use non-essential analytics or advertising technologies | Cookie identifiers and usage data | Consent |
| Establish, exercise, or defend legal claims and respond to lawful requests | Relevant account, transaction, communication, identity, incident, and log data | Legal obligation and legitimate interests in protecting legal rights |
| Recruit and manage personnel | Application, contract, payroll, tax, attendance, and employment data | Steps before a contract, contract performance, legal obligation, consent where required, and legitimate interests in personnel administration |
| Handle cancellations, refunds, deposit deductions, damage claims, and payment disputes | Reservation, contract, payment, refund, deposit, evidence, and correspondence data | Contract performance, legal obligation, and legitimate interests in resolving disputes and defending legal claims |
| Deliver tokenized Digital Concierge access and release property access codes at the correct time | Portal link identifier, verification status, stay times, and reveal events | Contract performance and legitimate interests in property and guest security |
| Translate portal content into the language you select | Portal content shown to you and your language choice | Contract performance and legitimate interests in accessible service |
| Send portal, email, and browser push notifications | Contact data, notification preferences, and push subscription | Contract performance, legal obligation for essential notices, and consent for browser push |
| Send internal operational alerts to our own staff channel | Reservation, property, and schedule data | Legitimate interests in reliable operations and guest arrival readiness |
Consent is not the legal basis for every activity. When we rely on consent, the request will be specific, clearly separated from other matters, understandable, accessible, and recorded. You may withdraw consent, but withdrawal does not invalidate processing already performed and does not stop processing that is required under another legal basis.
If required information is not provided, we may be unable to create an account, verify identity, complete a booking, provide property access, activate a tenant portal, process a payment, or meet a legal obligation.
7.1 Cancellations, Refunds, Deposits, and Disputes
When a booking or tenancy is cancelled, shortened, or disputed, we process the reservation or contract record, the cancellation terms shown for that property at the time of booking, payment and refund records, deposit deductions, damage or incident evidence, and the related correspondence. The legal bases are contract performance, legal obligation for accounting and tax records, and our legitimate interests in resolving the matter and defending a legal claim.
Deposits are held as Dana Titipan, a liability owed back to you, and every deduction is recorded with its reason and amount. Evidence collected for a damage or dispute claim is limited to what that claim requires, is shared only with the people who must assess it, and follows the retention schedule in Section 13. The commercial cancellation and refund terms are part of your booking or tenancy agreement. This section explains only how we handle the data those terms generate.
8. AI-Assisted Support and Automated Processing
Dream Living may use AI to answer approved questions, guide users through the Services, summarize a conversation, and identify when a human should take over.
AI must not independently:
- approve a refund or cancellation;
- change a reservation, tenancy, payment, deposit, or contract;
- make a decision that produces a legal or similarly significant effect;
- disclose another person's Personal Data or landlord financial data;
- reveal a door code, password, or other secret outside the approved access flow; or
- use raw identity-document images or complete payment credentials as chat knowledge.
We also use an AI provider to translate Digital Concierge content into the language a guest selects. Translated text is cached so the same content is not sent for translation again. We do not send identity documents, access codes, or payment credentials to an AI provider, and we do not authorize a provider to use our data to train its general models.
High-risk issues, including payment disputes, identity concerns, safety matters, property damage, and unresolved access problems, are escalated to an authorized person. We retain AI and human support records according to Section 13.
If we introduce automated decision-making that has a legal or similarly significant effect, we will complete the required impact assessment, update this Privacy Policy, and provide the rights required by law before enabling it.
9. When We Share Personal Data
We may disclose Personal Data only to the extent necessary for a documented purpose.
9.1 Service Providers We Use
We keep the provider list short and purpose-bound. We currently use:
- Our cloud application platform, for hosting, the database, authentication, and private file storage, including uploaded identity documents;
- Xendit, our payment provider, for checkout, payment status, and settlement of short-term rental payments and boarding house invoices;
- Mapbox, for maps on public listing pages and for converting a property address into map coordinates;
- An AI provider reached through our platform's AI gateway, currently a Google Gemini model, for Digital Concierge translation and assisted support;
- An email delivery provider, for transactional email such as confirmations, invoices, receipts, reminders, and portal invitations;
- Web push delivery through your own browser vendor, for notifications you enabled; and
- Telegram, for internal operational alerts to our own staff channel only.
Each provider processes Personal Data under appropriate contractual, confidentiality, security, and data-protection requirements, and only for the purpose stated above. If we add or change a provider, we will update this list.
9.2 OTAs and Rental Platforms
When you book or inquire through an OTA or rental platform, that platform and Dream Living may each process Personal Data for their respective purposes. The platform's privacy notice applies to its own processing.
9.3 Property Owners, Landlords, and Operational Personnel
We may provide an assigned property owner, landlord, housekeeping worker, maintenance worker, or other authorized operational person with the minimum information required to manage the property or provide the service.
Property owners and landlords receive only assigned, approved owner-facing information. Raw identity documents, account passwords, complete payment credentials, private support chats, and live access codes are not provided to them unless disclosure is specifically required by law or a documented, necessary arrangement.
9.4 Professional Advisers and Authorities
We may disclose relevant Personal Data to auditors, accountants, insurers, banks, lawyers, courts, law enforcement, immigration authorities, tax authorities, regulators, or other competent bodies when required by law or reasonably necessary to protect lawful rights, safety, or security.
9.5 Business Changes
If the Company is involved in a merger, acquisition, restructuring, asset transfer, or dissolution, Personal Data may be transferred under applicable law. We will provide the required notice before and after a qualifying corporate transfer.
We do not sell Personal Data. We do not disclose Personal Data to advertisers for their independent targeted advertising unless you have given the required separate consent and this Privacy Policy has been updated before that activity begins.
10. International Data Transfers
Some service providers may process Personal Data outside Indonesia. Before transferring Personal Data outside Indonesia, we will apply the mechanism required by Indonesian law. This may include confirming an equivalent or higher level of protection, using adequate and binding safeguards, or obtaining valid consent when the first two mechanisms are not available.
We also require appropriate security, confidentiality, and processor controls. You may contact us for information about the safeguards applicable to a relevant transfer, subject to lawful confidentiality limits.
11. Security
We apply technical and organizational measures based on the nature, context, and risk of the Personal Data. These measures include, as appropriate:
- encryption in transit and protected storage;
- access controls, least-privilege access, and account authentication;
- multi-factor authentication and enhanced controls for authorized internal access;
- private document storage and time-limited access to sensitive files;
- separation of public, guest, tenant, landlord, and internal data;
- secure payment-provider integration without storing complete card credentials;
- activity, security, and Personal Data processing records;
- vulnerability management, backups, incident response, and vendor oversight; and
- confidentiality duties and training for people who handle Personal Data.
No system can guarantee absolute security. If a Personal Data protection failure occurs, we will investigate, contain, document, and provide written notification to affected Data Subjects and the competent institution within the period required by law. Under the Indonesian Personal Data Protection Law, the applicable notification period is no later than 3 x 24 hours.
12. Cookies, Local Storage, and Similar Technologies
We keep browser storage deliberately small. The Services currently use:
- Authentication and session storage, required to keep you signed in to a portal or dashboard;
- Language and locale, which also determines whether you see the English or Indonesian address of a page;
- Display preferences, such as area units and other optional viewing choices;
- Guest portal state, which keeps your place in the Digital Concierge steps on the device you opened the link with;
- Web push subscription, stored by your browser when you enable notifications; and
- Map session data, set by our map provider when a map is displayed.
We do not currently run third-party advertising, remarketing, or cross-site tracking technologies on the Services, so no advertising profile is built from your visit. If a non-essential analytics or advertising technology is introduced later, it will remain disabled until it is listed here, legally assessed, and enabled through a valid consent choice. Disabling essential browser storage may prevent login or secure portal functions.
We do not place raw identity-document content, complete payment card details, account passwords, or door codes in cookies or browser local storage.
We operate our own first-party, cookie-less measurement of public pages. For each visit to a public page we record only the page path, the country reported by our network provider, a coarse device category, the referring website host, and the browser language. Your IP address is never stored: it is used once, together with your browser agent string and a server-side secret, to derive a daily one-way code that lets us count unique visitors without identifying you. These records are aggregated for internal reporting only, are never sold or shared for advertising, and are deleted automatically after 180 days. Pages inside signed-in areas such as owner portals, tenant portals, guest concierge portals, and the internal dashboard are excluded from this measurement.
If a non-essential analytics technology, marketing pixel, or remarketing service is introduced later, it must not operate until it is listed here with its provider, purpose, category, and duration, legally assessed, and enabled through valid consent.
13. Data Retention
We retain Personal Data only for a defined operational, contractual, legal, security, or evidentiary need. We then delete, destroy, or irreversibly anonymize it unless a law requires continued retention.
The following schedule is the Dream Living baseline:
| Data Category | Standard Retention |
|---|---|
| Public inquiry or unconverted rental application | 12 months after the last meaningful interaction |
| Account profile and portal assignment | While active, then up to 2 years after account closure or last activity, except data retained separately under another category |
| Booking, billing, invoice, payment, tax, accounting, deposit, refund, owner payout, and supporting business records | 10 years from the relevant transaction or tax period, or longer if law requires |
| Raw guest identity-document file | No more than 90 days after checkout and completion of required verification or reporting, unless an incident, dispute, fraud review, legal hold, or law requires longer retention |
| Raw tenant identity-document file | During the active tenancy and no more than 90 days after move-out, unless an incident, dispute, fraud review, legal hold, or law requires longer retention |
| Identity-verification metadata, accepted terms version, consent evidence, and immigration reporting reference | 5 years after checkout or move-out, or longer where required for a legal claim or legal obligation |
| Tenant contracts, landlord agreements, and records supporting financial or tax entries | 10 years after the relevant period or end of the relationship, as applicable |
| Website, portal, AI, and human support conversations | 24 months after closure, unless linked to an active booking, tenancy, dispute, safety matter, or legal obligation |
| Digital Concierge access and activity records | 12 months after checkout; live access secrets must be hidden at checkout and revoked or rotated according to property access procedures |
| General security and access logs | 12 months, unless needed for an active security investigation |
| Security incident and legal-claim records | For the duration of the matter and the applicable legal limitation or retention period |
| Recruitment records for an unsuccessful applicant | 12 months after the recruitment process ends, unless the applicant separately agrees to a longer talent-pool period |
| Marketing consent and opt-out evidence | While marketing continues, then a minimal compliance record for 5 years after withdrawal or opt-out |
| Digital Concierge portal activity events | 12 months after checkout |
| Cached machine translation of portal content | While the related property content exists, then removed together with it |
| Browser push subscription | Until you disable notifications, the subscription expires, or portal access ends |
| Tenant portal notification records | 24 months, or shorter when the related invoice or payment record is deleted |
| Payment checkout link and payment-provider response data | Kept with the related invoice or reservation under the 10 year financial retention rule |
| Deleted data remaining in protected backups | Removed through the backup cycle, normally within 90 days, and not restored to active use except for disaster recovery |
Our systems keep only two record states, created and permanently deleted. There is no archive, no soft delete, and no restore feature, so a deletion in our system is permanent apart from protected backups and records we must keep for the financial, tax, and legal periods above.
When a valid deletion request applies, we remove the data from active use and notify you as required. We may retain specific records when tax, accounting, immigration, employment, dispute, fraud, safety, or other law requires it. Retained data will be limited, access-restricted, and used only for the applicable reason.
14. Your Rights
Subject to applicable law, you may have the right to:
- receive clear information about our identity, legal basis, purposes, and accountability;
- complete, update, or correct inaccurate Personal Data;
- access and obtain a copy of your Personal Data and its processing record;
- end Processing and request deletion or destruction;
- withdraw consent for Processing based on consent;
- request a proportionate delay or restriction of Processing;
- object to a decision based solely on automated Processing that has a legal or significant effect;
- obtain Personal Data in a commonly used, machine-readable format and transmit it where the law and systems allow;
- submit a complaint, pursue dispute resolution, or claim compensation as permitted by law; and
- receive notice when Personal Data is deleted or destroyed as required by law.
Send a recorded request to admin@dreamliving.id. We may verify your identity and authority using information proportionate to the request. We will not disclose another person's data or provide access that would create a security risk.
Indonesian law specifies a 3 x 24 hour period for certain actions, including eligible access, correction, consent-withdrawal, and processing-restriction requests. We will apply the legally required period to each eligible request. Other requests will be handled within the period required by applicable law.
You may unsubscribe from promotional email through its unsubscribe control. An unsubscribe request does not stop service, payment, safety, legal, or booking messages.
15. Children
Dream Living accounts, direct bookings, rental applications, payments, and contracts are intended for people who are at least 18 years old and legally able to enter the relevant agreement.
A person under 18 must not create an account, make a booking, submit a rental application, use payment functions, or provide Personal Data through interactive support without the involvement and valid consent of a parent or legal guardian where required.
An adult may provide limited information about a child who is an accompanying guest when it is necessary for occupancy, safety, legal compliance, or service delivery. The adult must be authorized to provide that information. We do not use a child's Personal Data for targeted advertising or independent profiling.
If you believe a child provided Personal Data contrary to this section, contact us so we can restrict and assess the data promptly.
16. Third-Party Links and Services
The Services may link to maps, OTAs, payment providers, social media pages, or other external services. We do not control a third party's independent Processing. Review the third party's privacy notice before submitting Personal Data to it.
17. Changes to This Privacy Policy
We may update this Privacy Policy to reflect changes to the Services, vendors, law, or Processing. The current version and effective date will appear on the policy page.
For a material change, we will provide notice before the change takes effect through an appropriate channel, such as the website, account, portal, or email. If a new activity requires consent, we will request fresh consent rather than treating continued use as consent.
18. Governing Law and Disputes
This Privacy Policy and the Processing it describes are governed by the laws of the Republic of Indonesia, including Law Number 27 of 2022 on Personal Data Protection and other applicable electronic-system, immigration, tax, consumer, and sectoral requirements.
Privacy disputes may be resolved through the courts, arbitration, or another lawful dispute-resolution mechanism as applicable. Nothing in this section removes a mandatory right available to a Data Subject under applicable law.
19. Contact Us
For a privacy question, rights request, complaint, or security concern, contact:
Dream Living Management
Batam, Kepulauan Riau, Indonesia
Registered office and privacy contact: Komplek Megacipta Industrial Park Blok A Nomor 3, Batam, Kepulauan Riau, Indonesia — admin@dreamliving.id
Support contact: +62 853-5576-1308
Please do not send a raw identity document by ordinary email unless we specifically request it through an approved secure method.
20. Service Surfaces at a Glance
This summary is a reading aid. Where it is shorter than the sections above, those sections prevail.
| Service Surface | What We Process There |
|---|---|
| Public website and listing pages | Browsing and device data, language and display preferences, map interaction, and any inquiry you submit |
| Daily Rentals booking | Guest contact details, stay dates, reservation record, payment through our payment provider, and confirmation, invoice, and receipt email |
| Digital Concierge | Tokenized portal link, guest name and email, house-rule acceptance with its version, identity document, portal events, feedback, and time-limited access codes |
| Monthly Rentals and BH Tenant Portal | Tenant identity and contract, room assignment, monthly and prorated invoices, deposits held as Dana Titipan, payments, and portal notifications |
| STR Guest Portal | Your own paid reservation, stay information, and account details |
| Owner and Landlord Portal | Your assigned properties, reservations, revenue share, payouts, expenses, calendar export, and notification settings |
| Email, browser push, and internal alerts | Delivery records, notification preferences, unsubscribe events, and staff-only operational reminders |
| Support and AI assistance | Your messages, the page or booking context, AI responses, escalation, and outcome |
For any surface, a privacy question or rights request goes to admin@dreamliving.id.
