Privacy Statement
Last updated: June 22, 2026
Bali Property Advisory ("BPA", "we", "us") respects your privacy and is responsible for the processing of personal data collected via this website. This statement explains what data we collect, why, and what your rights are.
1. Who are we?
Data Controller:
- Bali Property Advisory
- PT Bali Property Advisory
- [[David: registered office address]]
- [[David: NIB / KvK registration number]]
- Email: privacy@balipropertyadvisory.com
Data Protection Officer (DPO)
We are not required to appoint a DPO. For privacy questions, please use the email above.
2. What data do we process?
When you use our ROI calculator, we process:
| Category | Examples | Source |
|---|---|---|
| Identification data | First name, email address | Provided by you in the form |
| Location data | Latitude/longitude of villa location, region name | Indicated by you via map pin |
| Investment data | Purchase price, property type, number of bedrooms | Provided by you |
| Calculated outcomes | Gross yield, net ROI, break-even year | Calculated by our ROI engine |
| Marketing consent | Opt-in checkbox status | Indicated by you |
| Technical data | IP address (truncated), browser type, language preference, visit timestamp | Automatic from your browser |
| Marketing attribution | UTM parameters (source, medium, campaign), referrer URL | Automatic from URL and browser |
We do not collect special-category personal data (health, religion, political views, etc.).
3. Why do we process this data?
| Purpose | Legal basis (GDPR Art. 6) |
|---|---|
| Generate and send your requested ROI report | Performance of contract (Art. 6.1.b) |
| Reach out for a non-binding conversation about Bali property | Consent via opt-in (Art. 6.1.a) |
| Site operation and fraud prevention | Legitimate interest (Art. 6.1.f) |
| Site improvement via anonymized analytics | Consent via cookie banner (Art. 6.1.a) |
| Marketing attribution (which ad brought you here) | Consent via cookie banner (Art. 6.1.a) |
| Comply with legal obligations (accounting, tax) | Legal obligation (Art. 6.1.c) |
4. How long do we retain your data?
| Category | Retention period |
|---|---|
| Lead data in CRM (GoHighLevel) | 24 months after last contact, or as long as the customer relationship is active |
| ROI calculation logs | 6 months (technical troubleshooting) |
| Analytics data (Google Analytics) | 14 months (GA4 default) |
| Email delivery logs (Resend) | 30 days after delivery |
| Marketing opt-in records | Until withdrawal + 5 years (proof of consent) |
After this period, data is anonymized or deleted.
5. With whom do we share your data?
We share your data with the following processors (sub-processors), each under a Data Processing Agreement:
| Service | Purpose | Location |
|---|---|---|
| Vercel Inc. | Website hosting | EU (Frankfurt) |
| Railway | Backend worker hosting | EU (Amsterdam) |
| GoHighLevel | CRM for lead management | US (under DPF/SCCs) |
| Resend | Email delivery of the ROI report | EU/US (under DPF/SCCs) |
| Anthropic / OpenAI | AI text generation for the report | US (under DPF/SCCs) |
| Mapbox | Reverse geocoding (location name) | US (under DPF/SCCs) |
| Google Analytics 4 | Anonymized site analytics | US (under DPF/SCCs) |
| Sentry | Error detection and monitoring | EU (Frankfurt) |
| Cloudflare Turnstile | Bot protection | US (under DPF/SCCs) |
For transfers to the US, we rely on the EU-US Data Privacy Framework (DPF) or Standard Contractual Clauses (SCCs).
We never sell your data to third parties.
6. What are your rights?
Under the GDPR, you have the right to:
- Access: know what data we process about you
- Rectification: correct inaccurate data
- Erasure: request deletion ("right to be forgotten")
- Restriction: limit how your data is processed
- Object: object to the processing
- Data portability: receive your data in a structured format
- Withdraw consent: for marketing emails via the unsubscribe link in every email or via the privacy email
Send a request to privacy@balipropertyadvisory.com. We will respond within 30 days.
Not satisfied with our response? You can lodge a complaint with the Dutch Data Protection Authority (https://autoriteitpersoonsgegevens.nl) or any other EU supervisory authority.
7. Security
We take technical and organizational measures to protect your data:
- HTTPS encryption on all pages
- Limited access to lead data (only David and RNT system administration)
- Password managers and two-factor authentication on all system accounts
- Monthly security audits of our dependencies
- Log redaction: email addresses and names are hashed in error logs
8. Cookies
See our cookie statement for the full list of cookies we use.
9. Changes
We may update this privacy statement. The "Last updated" date at the top shows the latest version. For substantial changes, we will request fresh consent via the cookie banner.
10. Contact
Privacy questions? Email privacy@balipropertyadvisory.com.