Controller and contact details
For the online ordering service described in this policy, the data controller and contracting/payment entity is Global Tech Provider FZ-LLC, Company Registration No. RAKEZ20261421, FDRK9481, Compass Building, Al Shohada Road, Al Hamra Industrial Zone-FZ, Ras Al Khaimah, United Arab Emirates. IDL Bali is the customer-facing service name and its document-preparation operations are based in Bali, Indonesia.
Privacy enquiries and rights requests may be sent to office@idlbali.com or through the contact page.
Information we collect
Application data includes contact details, name, date and country of birth, gender, residence, physical descriptors entered for the translation, national driving-licence details and classes, portrait, licence front/back images, signature, selected product and validity period.
For printed orders we also collect recipient, telephone number, hotel/property, room/unit, address, postcode and delivery instructions. We process payment confirmation and transaction identifiers from Stripe, order status, correspondence, generated files, QR verification records, courier and tracking information.
Security records may include IP address, user agent, timestamps, authentication events and administrator audit logs. Campaign links create an immediate anonymous aggregate click count; persistent visitor recognition and order attribution are used only after the relevant optional consent.
Purposes and legal grounds
- Contract and requested steps: to validate an application, calculate the price, take payment, prepare the translation, generate digital/printed files, deliver the order and provide status information.
- Legal obligations: to maintain payment, accounting, tax, complaint and regulatory records where required.
- Legitimate interests: to secure the service, prevent fraud, diagnose failures, maintain an administrative audit trail, defend claims and improve anonymous service statistics, balanced against individual rights.
- Consent: for optional analytics or marketing technologies where consent is required. Consent can be changed through Cookie settings.
Accuracy and customer responsibility
The customer is responsible for providing lawful, accurate and authorised information. IDL Bali may compare entered fields with uploaded images to prepare the requested translation, but this operational review is not government authentication of the original licence. Information may be corrected by an authorised administrator when a clear transcription error is identified.
Recipients and service providers
Information is shared only as needed with personnel preparing the order and with providers supporting hosting, secure email, payment, document production, customer support and delivery. Stripe receives payment and fraud-prevention data; a courier such as FedEx receives delivery data. Providers may act as processors or independent controllers under their own legal duties.
International processing
The service operates between the United Arab Emirates, Indonesia and customers worldwide. Information may therefore be processed outside the customer's country. Where data-protection law requires a transfer safeguard, the controller will use an available lawful mechanism such as contractual safeguards or a recognised adequacy arrangement.
Payment-card information
Card details are entered directly into Stripe Checkout. IDL Bali does not receive or store the full card number or security code. We receive limited transaction details needed to match payment to the order, issue a receipt, handle refunds and respond to disputes.
Security
Uploaded documents are stored outside the public website, sensitive database fields are encrypted, administrative access requires a password and authenticator code, private-file access is logged, and payment webhooks are signature-verified. Access is limited to authorised operational needs. No internet service can guarantee absolute security.
Retention and controlled deletion
Records are kept while needed to fulfil and verify an order, provide support, meet accounting or legal duties, prevent fraud and establish or defend claims. The present system does not automatically delete personal files solely because a fixed timer expires.
Authorised owners periodically review completed or closed records. Eligible orders can be placed in an AES-256 encrypted archive, downloaded to a protected offline computer and then deleted through a separate confirmed action. Further details are in the Data Retention Notice.
Your rights
Depending on the law that applies, an individual may request access, correction, deletion, restriction, objection or portability and may withdraw consent for optional processing. A request can be refused or limited where identity cannot be verified or where retention is required by law, an active dispute or another lawful ground. Individuals may also complain to the data-protection authority competent for their location.
Private status and verification links
Order-status links and QR verification links contain unique tokens. Customers must keep private status links confidential. The public verification page is intentionally limited and does not expose uploaded identity documents or payment-card details.
Cookies and campaign measurement
Necessary cookies support security and remember privacy choices. Optional analytics and marketing categories remain disabled until enabled. Anonymous aggregate campaign-link clicks do not set a tracking cookie or retain a raw IP address. Details and controls are available in the Cookie Policy.
Changes to this policy
This policy may be updated when the service, providers or legal requirements change. The latest version and date are published here. A renewed choice will be requested where a material change requires new consent.
Contact IDL Bali support and include your order reference when applicable.
