Bifarma

Privacy Policy

Privacy Policy
Privacy Policy of www.bifarma.co.id

In effect as of September 30th, 2025
We are PT Bifarma Adiluhung. In order to provide this service, your Personal Data will be managed by PT Medika Komunika Teknologi, a part of Kalbe Group that acts as a Personal Data Controller for the purposes of managing and processing this data. PT Medika Komunika Teknologi can share your Personal Data to other companies in Kalbe Group and/or its affiliates and/or its appointed work partners (herein thereafter will be referred to as “We/Us”), which, at this moment, is committed to protect the interests and comfort of Customers as included within the scope of the Law No. 27 Year 2022 on the Protection of Personal Data (herein thereafter will be referred to as “UU PDP”) and other laws that relate to Personal Data Protection in Indonesia.

This Privacy Policy explains information that relates to the processing of Personal Data that We do, starting from acquisition, collection, processing, analysis, display, sending, disclosure, storing, changing, deletion, and/or all forms of managing that relate to your Personal Data as our form of obedience to UU PDP and other laws that relate to Personal Data Protection in Indonesia. www.bifarma.co.id is a part of Us. By accessing the www.bifarma.co.id website, you state that you have read and understood all types of processing in relations to your Personal Data.

By stating “Agree” when you are in the process of registering for an account or data collection through the consent form that has been given to you, this means that you have agreed to and given your consent to Us to process your Personal Data.

1. Applicable Legal Basis and Regulations
Applicable laws/policy regulations within the Republic of Indonesia that regulate Personal Data Protection as stated in UU PDP along with its succeeding rules. We comply with all the applicable rules of laws and policies of the government of the Republic of Indonesia that relate to Personal Data Protection.

2. Legal Basis of Personal Data Processing
Your Personal Data that We will process is exclusive to Personal Data that has met the following terms and conditions:
a. We have obtained your explicit and legal consent to use your Personal Data in accordance with Our processing purposes through customers’ consent;
b. We fulfil and run Our rights and obligations in the activities of Personal Data processing accordingly to applicable rules of laws; and/or
c. We process by maintaining your rights as Data Owner in accordance to what has been written in customers’ consent

3. The Purposes of Personal Data Processing
Generally, We store and use your Personal Data that you have given to us for the purposes of product procuring and improving Our services to you, which include, but not limited to:
a. The processing of transactions/orders: To send products, send shipping info, provide customer support, and verify transactions. We use your bank account data to process transactions, your e-mail address to provide notifications and communications, and your registered address to ship Our products;
b. The provision of services: To identify you as a user, understand your experience, conduct surveys, providing relevant information, check activity trends, understand you to create recommendations and personalizations. We collect your identity, search, cookies, real location, and history data for these activities;
c. The marketing and analysis in researches: To provide offer and ads information that is relevant to you. We collect your search, cookies, IP address, and history data for these activities;
d. The communication with you through different channels in relation to the services of Kalbe Group’s organizations and to respond to your requests. We process your registered e-mail address, account IDE, name, and address for this purpose;
e. The obedience to obligations: To oblige to laws and prevent frauds. For these purposes, We use your identity, contacts, transactions, and account profile data; and
f. The disclosure and sharing of your information under certain allowable conditions by applicable laws and/or your agreement.

4. Types of Collected Personal Data
The information about your Personal Data that We collect includes, although not limited to:
a. Identity data: Name, gender, date of birth, and nationality
b. Contact data: address, e-mail address, phone number
c. Biometric data with a standardized security level and maximum retention of one year
d. Bank account data with a standardized security level and an encryption plus anonymization process. Inactive/no-longer-used accounts will be deleted or made anonymous accordingly based on needs.
e. Transaction data: Purchasing transactions and purchase receipts.
f. Technical data: IP address, cookies, device ID.
g. Profile data: Account name, account ID.
h. Usage data: Usage history, search history within Our website(s), platform(s), and application(s).
i. Real or estimated location data: GPS, Wi-Fi locations.
j. Health data and information: Health history, special for entities that have been given authorization and are in need of the data.
k. Additional data, however, it is not limited to photos or other uploaded media.

5. Processing Timeline
In processing your Personal Data, We have rules on processing timeline to your data. The rules are as follow:
a. We will continue to process as long as you remain Our customer and are still using Our products, services, and/or assistance in accordance to applicable rules of laws;
b. We could retain your Personal Data as long as necessary to achieve the goals that have been explained in this Privacy Policy; and
c. We can store your Private Data outside of Indonesia by still taking into account the applicable rules of law in Indonesia.

6. Timeline of Private Data Retention
We will delete your data when it is no longer necessary for processing purposes, on which there are the following things that you must pay attention to:
a. We will retain your Private Data for 5 (five) years. After 5 (five) years, your Private Data will be on retention and soon be deleted when it is no longer required to achieve the aforementioned processing purposes;
b. When it is found that on-retention Private Data is still required for the purpose of achieving processing purposes, your Private Data’s retention period will be extended for the next 5 (five) years; and
c. If you close or ask us to close your account, We will immediately delete your Private Data, unless when ruled otherwise by the law.

7. Details of Collected Information
The collection of Private Data is obtained from, but not limited to:
a. Data that has been given by you, directly or indirectly;
b. Data that has been obtained when you register for an account on Our website(s), application(s), or platform(s), or of which that We operate;
c. Data that has been automatically recorded when You use Our website(s), application(s), or platform(s), or of which that We operate;
d. Data that has been recorded when You are contacted by Us through other communication media, according to your consent; and
e. Data that has been collected by Third Parties by taking into account the applicable rules of law in Indonesia.

8. Rights of Subjects of Personal Data
Examples of the rights that you have as a user in regards to your Personal Data are:
a. The right to Data information: you have the right to obtain information on your personal data that We Process, on the legal basis of it, and on the purpose of requests to use your Personal Data.
b. The right to Data Correction: you have the right to complete, update, and/or correct errors and/or inaccuracies about You.
c. The right to Obtain Access and/or Copies: You have the right to obtain access and copies of your Personal Data in accordance with the applicable rules of law. We will give the access through official media that We have provided. When there is found that there will be applicable fees to process the copies of your data, the fees will be charged to you.
d. The right to Data Deletion: you have the right to end the processing, to delete, and/or to erase your Personal Data based on the applicable rules of law. However, there is an exception for:
· The purpose of national defense and security;
· The purpose of law enforcement;
· The general purpose of running a country; or
· The purpose of monitoring for the field of financial, monetary, payment system, and financial system stability services that are taken to run a country.
e. The right to Withdrawal of Consent: you have the right to withdraw the consent for the processing of your Personal Data that you have given to Us. However, it needs to be noted that the withdrawal of consent can and will affect Us in providing products, services, and assistance for you, along with other consequences in the fields that might be affected.
f. The right to State Objection on Processing: you have the right to state your objection for the actions of decision making that are taken based on automatic processing, including profiling, that may result in lawful consequences or significant impact to you.
g. The right to Limitation: you have the right to delay or limit the processing of your Personal Data in proportion in accordance to the purpose of processing of your Personal Data. However, it needs to be understood that requesting the delay or limitation can and will influence Our ability to provide products, services, and assistance for you, along with other consequences in the areas that might be affected.
h. Other rights: you have the right to exercise other rights on the processing of your Personal Data for as long as the right is regulated in the applicable rules of law in the region of the Republic of Indonesia

9. The Sharing and Disclosure of Personal Data
We will only share and disclose your Personal Data in scenarios such as:
a. It is necessary to use the features of services of the Kalbe Group organization, or applications, services, or devices of Third Parties that you have chosen to use;
b. It is required by the lawful order of the Court; and
c. If you have given us permission to share your Personal Data on your consent.
The followings are the categories of the recipients of your Personal Data, with the reasons of the sharing, which include, but not limited to:
a. The group of companies of PT Medika Komunika Teknologi, with the reason of sharing is due to Us having an office that runs Our day-to-day business operations to maintain the quality of Our services for you;
b. Service providers, with the reason of sharing is to help Us in providing the best services for you through infrastructure, system security, marketing, and other services;
c. Payment processors, with the reason of sharing is for your payment process to be done legally and trustfully in order to avoid scams;
d. Advertising partners, with the reason of sharing is to help Us in providing more relevant ads for you;
e. Advertising partners, with the reason of sharing is to help promote Our products, services, and assistance. Our Partners can also combine your Personal Data with other data that they collect that can be used for offers, promotions, or other marketing activities that We believe to be relevant for You;
f. Academic researchers, with the reason of sharing is to share activities such as statistical analysis and academical study, exclusively in pseudonym formatting;
g. Law enforcement officers and other authorities, with the reason of sharing is to abide by the law in fulfilling the purposes such as national security, law enforcement, litigation, investigations, security protection, to prevent deaths or physical harm (vital interest of Data Subject); and
h. Our business buyers, with the reason of sharing is in the situation when We sell or negotiate on Our business with the buyer(s) or prospective buyer(s) of Our business. We will send a notice to you before your Personal Data is handed to the buyer(s) or when a different Privacy Policy has started to be enforced.

10. The Security of Personal Data
As Our commitment in protecting your Personal Data as Our customers, the followings are the security measures that We and You need to take in order to protect your Personal Data:
a. We will try to provide the best security level to protect your Personal Data, however, we cannot guarantee the wholeness and accuracy of Personal Data that you give to Us, or guarantee that the Personal Data will not or can be halted, accessed, disclosed, changed, or destroyed by other unauthorized parties due to risks that are outside of Our control;
b. We suggest you to safeguard your private data such as password(s), One Time Password (OTP), Personal Identification Number (PIN), and not to share the details of your account to anyone, and you have the obligation to safeguard the security of your used devices;
c. The use of Personal Data by Third Parties in order to collaborate with Us, which will be done based on agreements;
d. We will try to ensure that every data processing that is done by Third Parties that have been appointed by us will be in accordance with the terms and purposes of processing that We have stated in this Privacy Policy. However, We cannot guarantee that the processing that is done by Third Parties are in line with the purposes of processing that We have decided. When, in processing your data, the Third Parties are not following this Privacy Policy and the agreement of those Third Parties with Us, We will take lawful steps in accordance to the agreement between Us and those Third Parties and applicable rules of law;
e. The use of Personal Data by Third Parties without Our consent and outside of the scope of the stated purposes to You is the responsibility of the Third Parties. You have the right to seek legal recourse on these actions.
f. Third Parties Platforms that have been linked to Us may have their own Privacy Policies and designated, independent securities that are outside of Our power. Therefore, you are encouraged to always study the Privacy Policy of those Third Parties; and
g. We will try to provide the best security to protect your Personal Data, however we will not be responsible of force majeure conditions that are outside of Our power. We will still be responsible to inform about this through the communication media that has been decided.

11. Updates of The Privacy Policy
We can, at any time, do changes or updates to this Privacy Policy. We will let you know on every change or update of this Privacy Policy. However, it is suggested that you read and check this Privacy Policy thoroughly from time to time to be aware of any changes. By continuing access and use of Our services, you will be considered that you have agreed to the changes of this Privacy Policy from time to time.

12. Contact Us
We are always committed to protect your Personal Data as our loyal and precious customers. If you have further questions about this Privacy Policy, please contact us through this e-mail: it@bifarma.co.id.

Thank you for your trust in becoming our loyal customers by using our products, services, and assistance.