Effective Date: May 5, 2025
Last Updated: January 21, 2026
Protecting your Personal Data is a priority for us. We therefore use your Personal Data within the scope of applicable legal regulations, in particular the Singapore Personal Data Protection Act 2012 (PDPA) and, where applicable, the EU General Data Protection Regulation (GDPR). This privacy policy outlines how BALI WATER SPORTS uses and processes your Personal Data when you use our services, such as through our website (https://baliwatersports.com) and any future mobile applications. It also informs you about your rights regarding your Personal Data and how you can contact us. If you are a resident of the United States, please consult the sections pertaining to United States Residents’ Rights for more information regarding your local privacy rights. If you are an Activity Provider or marketing partner, please refer to our Supplier Privacy Policy to understand how Personal Data is processed within the scope of your business relationship. This privacy policy has been drafted, and shall be construed, in the English language. Any translation of this privacy policy is for reference only. In the event of any inconsistency between the English language version and a translated version, the English language version shall prevail.
- Terms
1.1. The following terms are used in this privacy policy: “Activity” refers to the tours, attractions, water sports, or touristic experiences offered by Activity Providers through the BALI WATER SPORTS Platform. “Activity Provider” means the third-party provider of the tours, attractions, water sports, or touristic experiences that are offered on the BALI WATER SPORTS Platform. “PDPA” refers to the Personal Data Protection Act 2012 of Singapore. “GDPR” refers to the General Data Protection Regulation (EU) 2016/679. “BALI WATER SPORTS Platform” refers to the booking platform operated by AURORA FX TECHNOLOGY LLP, accessible via https://baliwatersports.com, related websites, partner websites, tools, and platforms. “Personal Data” refers to any Personally Identifiable Information, meaning any information relating to an identified or identifiable natural person.
- Controller and Contact
2.1. The Data Controller responsible for processing your Personal Data when you use or access our services is AURORA FX TECHNOLOGY LLP, an entity established in the Republic of Singapore. You can reach us via email at info@baliwatersports.com or visit our primary website infrastructure at https://baliwatersports.com. Please note that any data processing by Activity Providers in connection with a booked Activity is outside the control of BALI WATER SPORTS and is subject to the Activity Provider’s own privacy policy. Activity Providers act as separate, independent data controllers.
III. Data Processing Activities
- Automated Data Collection
1.1. When you visit the BALI WATER SPORTS Platform, we automatically collect specific technical and analytical information. This data is stored separately from other personal information you may explicitly transmit to us and includes the URL of the accessed page, the latency of your network connection, the exact date and time of your visit, and information about your device and device-specific settings such as your operating system, internet browser type, application version, language settings, and systematic activity. We also automatically log your navigation behavior, including information about clicks, referral sources, and pages shown to you, alongside your internet protocol (IP) address.
1.2. We collect this automated data to ensure the proper operation, maintenance, optimization, and security of our platform, as well as to prevent fraudulent transactions or system abuse. Our legal basis for this processing rests on our legitimate business interests to safeguard our infrastructure and provide a seamless booking experience. Your IP address is processed using industry-standard security encryption protocols and is stored securely only for as long as necessary for administrative and security reviews before being automatically deleted or anonymized.
- Data Collected in Connection with Your BALI WATER SPORTS Account
2.1. Registration. Registration is not required to use BALI WATER SPORTS’ Services. However, if you choose to create a BALI WATER SPORTS account, you may provide us with your full name, email address, and a secure password. Alternatively, you can log in using your Facebook, Google, or Apple account. In this case, we receive the following Personal Data from Facebook, Google, or Apple, which we use to create your BALI WATER SPORTS account: your name, your email address, your profile photo (from Facebook only), and an authentication token. We process this data to set up, secure, and manage your BALI WATER SPORTS account as outlined in our General Terms and Conditions, on the legal basis of contractual necessity under applicable data protection regulations.
2.2. Wishlists. You have the option to create wishlists that allow you to save water sports tours, excursions, and activities that you are interested in booking at a later point in time. When you add Activities to your wishlist, we use this information to provide you with personalized activity recommendations and targeted advertisements. This processing is based on our legitimate business interests to enhance your user experience, optimize your navigation path, and improve our promotional services.
2.3. Activity Reviews. Our platform offers the possibility to review and rate a booked Activity after you have participated. Your review, along with your rating, comments, uploaded photos, age range, country of origin, and first name, may be displayed in the context of the reviewed activity on the BALI WATER SPORTS Platform, on the websites of our affiliated entities under AURORA FX TECHNOLOGY LLP, or within our marketing and promotional materials. You always have the option to submit your review completely anonymously. You can request your review to be deleted at any time by contacting our customer service team via email at info@baliwatersports.com. You can also object at any time to receiving review request emails by clicking the unsubscribe link included at the bottom of each request email. The processing of your data for these review purposes is conducted based on our legitimate interest to enhance our aquatic and adventure offerings, assist other customers in making informed travel decisions, and optimize our marketing campaigns.
- Customer Service
3.1. Processing of Enquiries. If you contact our customer service team or reach out through our website, WhatsApp channels, or social media platforms, your request will be handled directly by our internal administration team under AURORA FX TECHNOLOGY LLP. When handling your requests, we process any Personal Data provided during the communication, such as your full name, email address, WhatsApp telephone number, booking reference number, and the specific details or text shared within your inquiry. To manage and resolve your support inquiries, customer feedback, and real-time chat interactions efficiently, we may utilize localized customer relationship software and secure cloud-hosting databases. Because our platform facilitates water sports experiences in Indonesia while operating from Singapore, your communication logs and technical contact data may be accessed by our authorized support staff located across these regions. We ensure that all cross-border access to customer service data adheres to strict internal data protection protocols and complies fully with the data transfer requirements enforced under the Singapore PDPA and applicable international frameworks.
3.2. Improving our Customer Service. To continuously improve our support capabilities and the quality of your booking experience, we may analyze customer inquiries using internal parameters, operational keywords, and localized data metrics. We may also invite you to participate in customer satisfaction surveys to help us enhance our platform’s responsiveness and operator coordination. The processing of Personal Data required within this context serves our legitimate business interests, as well as the mutual interests of our customers, in the continuous improvement and quality control of our customer service channels. Any survey or feedback data collected internally is stored securely and access is strictly restricted to authorized platform administrators.
3.3. Translating Enquiries. In certain cases, particularly when coordinating bookings and safety requirements between international tourists and local Bali boat or activity operators, it is necessary for us to translate incoming requests, activity queries, or specialized logistical instructions into Indonesian Bahasa or English. This may require the processing of Personal Data necessary to protect our legitimate business interest in providing multi-lingual, international customer service and ensuring tourist safety during water activities. For this purpose, we may utilize secure, automated translation engines, ensuring that your core financial and highly sensitive identifiers are not exposed during the translation process.
3.4. Storage and Evaluation of Telephone and WhatsApp Calls. Voice calls, WhatsApp audio communications, or live telephone interactions are only recorded or stored if you have given us your prior, explicit consent or where required for documented safety, transaction verification, or insurance purposes related to high-risk water sports. We will only use these recorded communications for the purpose of verifying booking agreements or improving our team’s customer service handling. Any such records are kept strictly confidential, stored on encrypted servers, and will be securely deleted or anonymized when no longer required for legal, operational, or safety reviews. You retain the right to revoke your consent regarding recorded communications at any time by contacting our data protection administration at info@baliwatersports.com.
- Technical Service Providers
4.1. Hosting of the Website. For the hosting, cloud storage, and technical infrastructure of our website and booking platform, we utilize secure, enterprise-grade cloud hosting services and data centers. Accordingly, when you interact with the BALI WATER SPORTS Platform, browse tours, or provide your personal data during a booking, that data is processed on secure cloud servers. To optimize website loading speeds and performance for both our international travelers and local operators, we utilize server locations chosen strategically across our core operational regions, including Singapore. In certain administrative situations involving remote technical maintenance or system optimizations, our cloud infrastructure providers may process technical data across global networks. We ensure that all utilized hosting providers maintain strict security protocols, enterprise-grade firewalls, and data transfer safeguards that guarantee your data receives a standard of protection that complies fully with the Singapore PDPA and other international data security frameworks.
4.2. Email and Communication Systems. For the distribution of transaction receipts, booking confirmations, operational updates, and automated notifications, we utilize secure transactional email and messaging service providers. These communication processors handle data on our behalf, which may include your full name, email address, and booking reference details. In providing these delivery services, our technical communication partners may process and route technical data through international infrastructure, including servers located in the United States and Singapore. We ensure that our communication processors are contractually bound to strict data protection regulations and participate in established international data privacy frameworks, guaranteeing that all personal information transferred across borders is adequately protected against unauthorized access or disclosure.
4.3. Protection Against Bots and Cyber Threats. To protect the BALI WATER SPORTS Platform from automated bot attacks, distributed denial-of-service (DDoS) threats, scraping, and similar malicious cyber activities, we utilize advanced security and traffic monitoring solutions. These security systems analyze the technical data automatically transmitted by your browser or device—such as your IP address, browser configuration, and navigation signatures—to evaluate whether the incoming website request originates from a human user or an automated script. This data processing is carried out purely to ensure network security and system integrity, preventing the unauthorized misuse or manipulation of our booking systems. The technical information processed for these security reviews is handled through encrypted protocols and is maintained only for the brief duration necessary to run real-world threat assessments, aligned with our legitimate interest in maintaining a safe, secure e-commerce environment.
- Marketing Newsletters
5.1. Newsletter Subscription and Consent. You can voluntarily subscribe to our promotional newsletter through our website to receive personalized information regarding exclusive offers, specialized water sports tours, marine activities, or seasonal packages in Bali. By subscribing, you provide your explicit consent for us to process your email address and monitor your technical interactions with our newsletters for the purpose of distributing relevant content and analyzing engagement metrics. To legally document and verify your voluntary consent, we automatically store your internet protocol (IP) address along with the exact date and time of your subscription registration, ensuring compliance with statutory record-keeping obligations.
5.2. Post-Booking Communications and Legitimate Interest. If you have successfully booked a water sports experience via our website or if you have registered a BALI WATER SPORTS account, we may periodically send you marketing communications or newsletters to inform you about similar activities, excursions, or complementary rentals that align with your interest profile. This processing is based on our legitimate business interests in promoting related adventure travel services to our active customer base, unless you have explicitly objected to or opted out of such marketing communications. If specialized tracking technologies or cookies are utilized to tailor and personalize your newsletter content based on your historical website browsing behavior, we will obtain your separate, distinct tracking consent.
5.3. Opt-Out and Unsubscription Rights. You retain the absolute right to withdraw your promotional consent and opt out of receiving marketing newsletters at any time. You can execute this right by deselecting the corresponding marketing checkbox during your initial account registration, by clicking the standardized “unsubscribe” link embedded directly into the footer of every marketing email we distribute, or by sending a direct opt-out request to our support team at info@baliwatersports.com. Furthermore, if you maintain a registered user profile on the BALI WATER SPORTS Platform, you can manage your communication preferences and subscribe or unsubscribe from various promotional channels at any time within your profile account settings.
5.4. Third-Party Distribution and Data Protection. For the technical dispatch, formatting, and content personalization of our marketing newsletters, we utilize secure, third-party marketing automation platforms and customer engagement processors. These external service providers act as data processors on our behalf and may process your personal data—including your email address, technical delivery status, open rates, and click-through history—on secure infrastructure located globally, including in Singapore and the United States. We ensure that any utilized marketing platform is contractually bound to strict confidentiality clauses and complies fully with international cross-border data transfer regulations, guaranteeing that your personal information is protected with a standard of security equivalent to the requirements under the Singapore PDPA.
- Booking Activities
6.1. Activity Providers and Data Transfers. When you book an Activity on the BALI WATER SPORTS Platform, we collect the personal data strictly required to organize, verify, and safely carry out your excursion. This data typically includes your first and last name, billing address, email address, telephone or WhatsApp number, the total number of participants, the exact booking date and time, and the specific details of the selected water sports activity. Depending on the nature of the booked Activity and local regulatory or maritime insurance mandates in Indonesia, we may additionally require your passport number, nationality, or the age of the participants to verify safety eligibility. We process this Personal Data to perform our contractual obligations to you, specifically to finalize, manage, and secure your booking. To the extent necessary to execute your experience, we transfer this logistical information directly to the local Activity Provider in Bali responsible for running your tour. The Activity Provider processes your Personal Data as an independent data controller in accordance with their own operational safety and privacy standards. Any cross-border data transfers occurring between our Singapore business infrastructure and operators located in Indonesia are executed under strict contractual safeguards to ensure data security in full compliance with the Singapore PDPA. If you book an Activity through an authorized travel agency or corporate partner site, your initial data is collected by that third party as an independent controller, and they will subsequently forward the required booking data to us so we can complete your reservation on our platform. Once you have finalized a booking, you may share the details with other participants by providing their email addresses or contact details; in doing so, it is your sole responsibility to obtain prior consent from those participants before sharing their personal information with the BALI WATER SPORTS Platform.
6.2. Booking Confirmations and Operational Notifications. To keep you properly informed regarding your reservations, we will transmit automated booking confirmations, logistical reminders, safety notices, and real-time operational updates, such as unexpected schedule alterations due to weather or maritime conditions or local meeting point adjustments. These essential operational confirmations are distributed directly to your registered email address, via SMS or WhatsApp text message if a telephone number was provided, or through platform-based push notifications. If you maintain a registered user profile on the BALI WATER SPORTS Platform, you can customize your communication preferences within your account notification settings. When distributing these critical booking confirmations and logistical updates, we process your Personal Data as a matter of contractual necessity to effectively deliver our adventure travel services to you.
6.3. Booking Cancellations and Refund Processing. In accordance with the platform’s established cancellation terms, eligible bookings may be cancelled up to 24 hours before the scheduled start time of the Activity for a complete refund. To manage, authenticate, and process cancellation requests, credit adjustments, or financial refunds, we utilize our active, secure payment gateway infrastructure. The processing of your Personal Data—including your booking reference, transaction history, and masked billing identifiers—within the scope of handling a cancellation or enforcing our refund policy is conducted as a direct performance of our service contract with you. All transaction data utilized during the cancellation and refund mitigation process is routed through secure, encrypted networks under the corporate administration of AURORA FX TECHNOLOGY LLP, ensuring your financial information remains fully protected throughout the administrative lifecycle.
- Payments
7.1. Financial Transaction Processing. We offer secure online payment methods to pay for your booked water sports activities on the BALI WATER SPORTS Platform. To facilitate your transaction, we process your financial and Personal Data as a matter of contractual necessity to fulfill our obligations to you. When you submit payment information on our platform, that data is transmitted through secure, encrypted connections directly to our active payment gateway provider. The payment providers handle your data both as an independent data controller when offering checkout services to you and as a data processor when handling funds on our behalf under the corporate administration of AURORA FX TECHNOLOGY LLP.
7.2. Credit Card and Gateway Services. For the execution of secure payment processing, we utilize the localized services of Stripe Payments Singapore Pte. Ltd. and its international affiliates (“Stripe”). Stripe forwards the payment data you provide directly to the respective global card networks, banks, or financial institutions to authorize and settle the transaction. To protect your financial security, BALI WATER SPORTS utilizes industry-standard tokenization, meaning we never have access to, nor do we store, your full credit card numbers or sensitive security codes on our servers. We only receive a secure confirmation string indicating whether the payment transaction was successful or declined, alongside limited, masked card identifiers such as the card brand, expiration date, and the final four digits of the credit card number for account verification and internal accounting purposes. The processing of your payment data by Stripe is governed strictly by the Stripe Privacy Policy.
7.3. Fraud Prevention and Chargeback Mitigation. In the event of a payment dispute, unauthorized card use, or a formal chargeback request initiated by a customer or a financial institution, we process relevant transaction and booking data to resolve the matter. For this purpose, AURORA FX TECHNOLOGY LLP may analyze and share specific transaction elements—including your name, email address, transaction dates, IP addresses, and digital booking confirmation records—with our active payment gateway risk assessment tools, banking partners, or legal advisors. This data processing is necessary for the performance of our contract with you, as well as to fulfill our legitimate business interests in preventing e-commerce fraud, mitigating financial risks, and ensuring the effective, lawful processing of transactional disputes.
- Payments
7.1. We offer secure online payment methods to pay for your booked Activity. Depending on the payment method you choose, we will process your Personal Data to facilitate the transaction as described below. This processing is necessary to fulfill our contractual obligations to you under applicable data protection regulations.
7.2. Credit Card Payments. To process credit card and digital gateway payments, we use the localized services of Stripe Payments Singapore and its corporate affiliates (“Stripe”). Stripe forwards the payment data you provide directly to the respective banks, card networks, or financial institutions to process the transaction. We only receive confirmation of whether the payment was successful, along with limited, masked payment identifiers such as the card brand, expiration date, and the final four digits of the credit card number. We do not have access to, nor do we store, your full credit card number on our servers. The providers of our payment services act as both a responsible data controller when providing checkout services to you and as a data processor when directed to process payments on our behalf under the corporate administration of AURORA FX TECHNOLOGY LLP. Regarding data processing as a data controller, the relevant privacy policy of the payment service provider applies to their processing of your data.
7.3. Chargebacks and Fraud Mitigation. In the event of chargebacks, payment disputes, or unauthorized transaction reviews, we process transaction and booking data internally to resolve the matter. For this purpose, AURORA FX TECHNOLOGY LLP may analyze and utilize your booking data, including payment confirmation records, transaction histories, and contact information, to manage the dispute process directly with our banking partners and your financial institution. This processing is necessary for fulfilling our contractual obligations toward you as well as on the basis of our legitimate business interest in the effective processing of chargebacks, risk mitigation, and preventing e-commerce fraud.
- Fraud Prevention
8.1. To safeguard our services and protect ourselves, our Activity Providers, and our customers from financial fraud, identity theft, and malicious cyber activities, we utilize advanced fraud prevention and risk assessment tools, primarily integrated through Stripe Payments Singapore Pte. Ltd. (“Stripe”). These specialized tools automatically analyze your transaction data, metadata, and user behavior patterns to detect potential credit card fraud, unauthorized payment attempts, security threats, and other malicious behavior. We process this data based on our legitimate business interests in preventing fraudulent bookings, protecting merchant accounts, ensuring a secure payment infrastructure, and guaranteeing the overall safety of the BALI WATER SPORTS Platform. All financial and technical data processed for fraud prevention is managed over highly secure, encrypted channels under the corporate administration of AURORA FX TECHNOLOGY LLP.
- Cookies and Tracking Technologies
9.1. Types of Technologies Used. We use so-called “cookies” and other online tracking technologies to offer certain core functions of our website, optimize your navigation experience, and effectively execute our localized marketing and advertising strategies. Specifically, we utilize session cookies, which are temporary files needed to store essential technical data during your active visit to our website, such as maintaining your login status or holding selected excursions in your temporary shopping cart. We also utilize persistent cookies, which remain stored within your device’s browser memory beyond a single session to remember your language preferences, currency choices, or account details for future visits. Furthermore, our platform utilizes web beacons, tags, and tracking pixels to retrieve technical information from your device, such as your operating system, browser type, your internet protocol (IP) address, and the exact time of your visit, which help us serve cookies or measure engagement. We also integrate scripts, which are small computer programs embedded within our web pages that support interactive features, security functions, or analytical tracking. Finally, we use tracking URLs containing unique identifiers to monitor which external marketing campaign, search term, or affiliate partner platform redirected you to our website.
9.2. Categories of Tracking Technologies. We group these tracking technologies into specific categories based on their operational purpose. The first category consists of Strictly Necessary Technologies, which are technically required for the BALI WATER SPORTS Platform to function and execute basic e-commerce processes; these must remain active to allow you to browse our tours, log into accounts, and complete transactions securely. The second category consists of Analytical Technologies, such as Google Analytics, which measure, record, and track how visitors discover and interact with our platform. We use this aggregated information to analyze user journeys, identify broken links, assess page latency, and continuously improve our website performance. The third category consists of Marketing and Source Tracking Technologies, including Sourcebuster systems and Google Ads or Meta trackers, which are utilized by us and our trusted advertising partners to collect data regarding your browsing behavior, monitor how you discover our brand, measure the return on investment of our promotional ads, and display relevant adventure travel content to you.
9.3. Managing Cookie Preferences and Consent. You can find detailed information about each tracking category and freely give, modify, or completely withdraw your consent for Analytical or Marketing Technologies at any time by accessing your browser’s native settings or by clicking the tracking preferences links provided on our platform. Our website utilizes automated consent management practices that enable you to manually activate or deactivate specific groups of non-essential tracking technologies individually. If you choose to configure your internet browser to block or refuse all cookies universally, please note that certain essential parts of the BALI WATER SPORTS Platform may become completely inaccessible or fail to function properly during the checkout and booking sequence. The legal basis for the processing of technical data through strictly necessary cookies is contractual necessity to deliver our services, whereas all non-essential analytical and marketing tracking is performed strictly on the basis of your voluntary, revocable consent.
- Customer Research
10.1. Customer Surveys and Aggregated Product Feedback. We may occasionally invite our customers to participate in localized research studies, voluntary feedback forms, or user experience surveys to evaluate our water sports offerings. Your participation in any detailed feedback initiatives or associated digital records will only occur with your prior explicit consent. Additionally, when navigating the BALI WATER SPORTS Platform, you may be prompted with quick technical questions regarding website usability or feature functionality. Your responses to these basic interface queries are collected exclusively in a highly aggregated format and are not personally linked to your identity or user profile. Participation in these surveys remains entirely voluntary, allowing you to dismiss the requests at your discretion.
10.2. Visitor Journey and Interface Optimization. To identify points of structural interest on our webpage, monitor technical latency, and observe how visitors navigate through our activity listings, we may utilize digital heat mapping and session analytics services. These optimization tools allow us to evaluate anonymous user movements, scrolling behavior, and clicking patterns across select webpages during a random sample of user browsing sessions. The analytical records generated from these technical sessions are retained securely for a standard operational period of up to 365 days before being automatically deleted or completely anonymized. We process this diagnostic data based on your implicit or explicit interaction consent, and you may opt out of browser session tracking at any time by configuring your device browser to distribute generic “Do Not Track” requests or by managing your settings via our platform privacy dashboard.
- Marketing and Remarketing Services
11.1. Advertising Evaluation and Strategy. We utilize advanced marketing, remarketing, and pixel tracking services to evaluate the commercial success of our social media and search engine advertisements. These services help us monitor how users discover the BALI WATER SPORTS Platform, determine which promotional campaigns lead to activity bookings, and optimize our overall marketing expenditures. We execute these tracking activities strictly on the basis of your voluntary consent. You maintain the right to review, alter, or completely withdraw your marketing consent at any time by accessing your internet browser settings or adjusting your choices within the cookie preference tools located in our website footer. Any modification of your tracking choices will immediately halt future processing but will not affect the legal validity of any marketing data processed prior to your revocation.
11.2. Google Services. We integrate various digital marketing and data evaluation products provided by Google Ireland Limited (“Google”). Google processes technical and behavioral information on our behalf, which may involve routing data across global networks, including secure infrastructure located in the United States. Google complies with established international data protection and privacy frameworks, ensuring all cross-border transfers are heavily protected.
11.2.1. Google Analytics. Subject to your consent, our website utilizes Google Analytics (including Google Analytics 360 frameworks) to compile pseudonymized statistics regarding how users interact with our platform. This web analytics tool automatically tracks shortened, anonymized internet protocol (IP) addresses, device types, referral paths, and navigation timelines. Google uses this information to compile aggregated operational reports concerning overall website and application activity. Your specific analytics cookie data is retained by Google for a standard duration of up to 26 months, after which it is deleted from their active systems, leaving only high-level statistical summaries. You can permanently prevent this analytics tracking by installing the official Google Analytics Opt-out Browser Add-on, or by disabling analytical technologies within our platform’s cookie manager.
11.2.2. Google Ads and Campaign Manager. If you grant your marketing consent, we utilize Google’s advanced advertising networks, including Google Ads, Display & Video 360, and Google Campaign Manager. To improve your overall promotional experience, we analyze your interaction history on our website through remarketing cookies, tracking tags, and server-to-server data connections. This allows us to understand your specific water sports preferences so we can display highly relevant advertisements for our tours when you browse external websites within the global Google advertising network, including Google Search and YouTube. We share specific hashed tracking identifiers with Google and its approved ad partners to manage this personalization. Extended personalization will only occur if you have separately consented within your personal Google Account settings to let Google link your web browsing history to your profile. You can permanently deactivate Google’s personalized ads by modifying your configurations directly within your global Google Ad Settings dashboard.
11.3. Meta Services (Facebook and Instagram). We utilize the advertising and audience matching services provided by Meta Platforms Ireland Limited (“Meta”) to enhance our social media outreach. Meta processes personal data on our behalf and may transfer tracking logs to secure servers located internationally, including the United States, under strict global privacy framework safeguards.
11.3.1. Meta Pixel and Server-to-Server Tracking. We share specific behavioral data regarding your interactions on the BALI WATER SPORTS Platform with Meta to serve relevant, interest-based advertisements on Facebook and Instagram, and to build lookalike audience models to find similar adventure travelers. AURORA FX TECHNOLOGY LLP and Meta act as joint data controllers for the initial technical collection and transmission of this data. With your consent, the Meta Pixel and integrated server-to-server connections transmit standardized usage data—such as specific page URLs, referrer tracking links, IP addresses, browser characteristics, and timestamps—associated with securely hashed customer identifiers or Facebook profile IDs where available. Meta uses this data to evaluate ad performance and deliver tailored marketing directly to you when you log into your Meta social profiles. For web visitors who do not maintain an active Facebook or Instagram account, Meta automatically discards the transmitted tracking string without further utilization or profiling.
11.4. TikTok and Alternative Remarketing Networks. If you provide your explicit tracking consent, we may also utilize the targeted advertising services of TikTok Technology Ltd. (“TikTok”) and alternative remarketing or affiliate networks to expand our digital reach. These platforms use localized tracking technologies and specialized marketing cookies to analyze your interaction patterns on our site. This tracking data helps us measure the conversion success of our social media campaigns, calculate affiliate partner referrals, and deliver relevant, interest-based water sports ads to you when you browse third-party video applications or content networks. All utilized networks are contractually restricted from selling your information and must process your data securely in accordance with strict international data protection agreements and cross-border transfer safeguards that match the standards of the Singapore PDPA.
- Integrated Third-Party Content
12.1. We embed third-party content and digital media assets on our platform to enhance website functionality, provide immersive previews of our water sports excursions, and display real-world activity locations. This content is loaded dynamically from the external servers of the respective multimedia and infrastructure providers, meaning your internet-connected device automatically transmits technically necessary data, such as your IP address and browser type, to these third parties during your browsing session. The processing of personal data within this context is governed strictly by the individual privacy policies of the respective third-party content providers. Our integration of these elements is based on our legitimate business interests in delivering engaging, informative media content and rich functionalities to our users while maintaining an economically optimized website structure.
- Social Media and Communication Channels
13.1. Facebook and Instagram Pages. We maintain business profiles and brand pages on Facebook and Instagram, which are operated globally by Meta Platforms. If you visit, follow, interact with, or “like” our official social media pages as a registered user, Meta collects and processes your Personal Data. Even if you do not possess an active account with Meta but browse our public social profiles, Meta may collect pseudonymous usage information and technical identifiers from your device. As part of our social profile management, we are jointly responsible with Meta for the processing of aggregated demographic data known as Page Insights. Meta analyzes your interactions on our profiles and provides us with anonymized statistical summaries that do not personally identify you. Under our joint controller frameworks, Meta assumes primary administrative responsibility for handling these analytical metrics and protecting your information. Your Personal Data may be shared among Meta corporate affiliates and routed through international infrastructure, including secure data centers in the United States, utilizing robust data protection safeguards that align with global compliance models and the standards of the Singapore PDPA.
13.2. X (formerly Twitter) and Pinterest Profiles. You can access our official brand profiles on X (operated by X Corp.) and Pinterest (operated by Pinterest Europe Ltd). When you interact with our posts, follow our accounts, or view our boards, these networks process your personal data in accordance with their respective corporate privacy policies. Please note that these platforms manage extensive international data networks and may transfer technical profile information to servers located outside of your home country, including the United States. We receive non-personal analytical data and engagement metrics from these platforms regarding how audiences view and discover our marketing content. This statistical feedback allows us to evaluate, refine, and optimize the effectiveness of our public marketing campaigns based on our legitimate business interests.
13.3. TikTok Platform Operations. Our official video channel is managed on the TikTok platform. Because we operate globally via a Singapore entity, our regional data processing and user interactions outside of the Western hemisphere are primarily administered under the data control of TikTok Pte. Ltd., located in Singapore. TikTok processes your profile identifiers, viewing histories, and advertising engagement metrics when you consume our video content. To the extent that cross-border data transfers occur across TikTok’s infrastructure to regional operations or third countries, appropriate data protection measures, such as enterprise-grade encryption and standardized data clauses, are implemented. We utilize non-identifiable TikTok Analytics to measure video engagement and optimize our creative outreach, which aligns with our legitimate interests in brand development and aquatic tourism promotion.
13.4. YouTube Video Integration. We embed promotional videos and activity previews directly from our official YouTube channel, which is operated by Google Ireland Limited (“Google”). When you stream these integrated videos on the BALI WATER SPORTS Platform, Google automatically registers the interaction and handles the technical data transmission under the terms of the comprehensive Google Privacy Policy. If you are logged into a personal Google Account while browsing our site, Google may merge your video interaction history with your broader profile activities (such as Gmail or Google Search) depending on your account’s personalization settings. We receive non-personal, aggregated audience analytics from Google to evaluate video performance, watch times, and geographic reach to improve our content presentation.
13.5. WhatsApp Communication and Inquiries. To provide responsive, real-time booking assistance, we allow users to connect with our support team directly via WhatsApp, which is operated by Meta. When you initiate a communication through this channel, we collect and process your WhatsApp telephone number, profile name, and any specific text, booking references, or media you explicitly share with us during the conversation. We process this information purely to address, manage, and resolve your direct booking requests, pricing inquiries, and reservation modifications. Any subsequent storage of this communication history within our secure internal systems is conducted based on our legitimate business interests in maintaining accurate corporate documentation, validating booking agreements, and safeguarding our legal position in the event of transactional disputes.
13.6. Social Media Competitions and Tagging. Occasionally, we may organize promotional contests or interactive sweepstakes across our active social media channels. To participate in these events, you may be required to execute specific actions such as liking our promotional content, writing public comments, or tagging our official brand accounts. We process the specific profile data and contact information you provide within this context to manage the competition logistics, verify compliance with entry rules, and directly notify the verified winners. Additionally, to measure the viral reach of our brand, we track instances where the BALI WATER SPORTS Platform or AURORA FX TECHNOLOGY LLP is publicly tagged across social networks, processing basic profile usernames to evaluate our public engagement based on our legitimate interest in continuous marketing optimization.
- Customer Relationship Management (CRM) System
14.1. To effectively manage our customer relationships, maintain accurate booking history, and optimize support communications, we store your Personal Data within our secure cloud-based Customer Relationship Management (CRM) database infrastructure. Utilizing a centralized CRM system enables our administration team under AURORA FX TECHNOLOGY LLP to respond to your inquiries in a highly targeted manner, track reservation statuses, coordinate logistics seamlessly with local Bali tour operators, and deliver contextual promotional content within the permissible boundaries of applicable local marketing laws. The data processing that takes place within this context is conducted based on our legitimate business interests in maintaining efficient customer relationships, streamlining e-commerce communication workflows, and offering high-quality support services.
14.2. If you have provided your explicit, voluntary tracking and promotional consent via our platform’s cookie manager or registration frameworks, we may utilize our integrated CRM mechanisms to distribute tailored newsletters, localized push notifications, or platform-based messaging alerts customized to your specific travel dates, interests, and interaction history on our website. To maintain strict data integrity, any technical or personal information processed for these relationship management activities is handled over secure, encrypted networks. We ensure that our underlying database infrastructure complies fully with international cross-border data transfer regulations, guaranteeing that all customer profiles are stored with a standard of data security that meets or exceeds the strict requirements enforced under the Singapore PDPA.
- Personalization of Website Content
15.1. We automatically process technical, behavioral, and location-based data to display personalized content and tailored activity layouts across the BALI WATER SPORTS Platform. The legal basis for this processing rests on our legitimate business interests to deliver a dynamic, relevant user experience, minimize navigation friction, and showcase water sports packages, marine excursions, and beach activities that directly align with your demonstrated interests and browsing patterns. By analyzing high-level, pseudonymized data—such as your preferred currency, language settings, and previously viewed activities—we can dynamically organize our homepage and category listings to display the most relevant seasonal offerings, ensuring an efficient and optimized reservation process.
- Further Sharing of Data
16.1. Legal Enforcement and Public Authorities. Beyond the specific cases described elsewhere in this privacy policy, your Personal Data will only be passed on to third parties without your express prior consent under exceptional operational or legal circumstances. If it becomes necessary to investigate, prevent, or clarify the illegal or unauthorized use of our booking infrastructure, or to pursue formal legal prosecution, your Personal Data will be forwarded to competent law enforcement authorities, regulatory bodies, and, where applicable, injured third parties. This disclosure will only occur if there are credible, specific indications of unlawful, fraudulent, or abusive behavior. Data transfers may also take place to enforce our platform’s General Terms and Conditions, booking rules, or other binding service agreements. Furthermore, AURORA FX TECHNOLOGY LLP is legally obliged to provide information to certain public, judicial, or statutory authorities upon official request, including maritime safety boards, immigration agencies, and tax authorities. This data is disclosed on the basis of our legitimate business interests in combating e-commerce abuse, prosecuting criminal offenses, and securing, asserting, and enforcing valid legal claims, or on the basis of a binding statutory obligation under the laws of Singapore.
16.2. Professional Advisors and Corporate Governance. We disclose necessary elements of your Personal Data to our retained professional advisors—including independent financial auditors, external accounting service providers, legal counsel, banking institutions, insurance underwriters, and corporate tax consultants—insofar as such sharing is strictly required for the optimal provision of our travel services, the proper and secure management of our commercial business operations, or to comply with mandatory corporate reporting standards.
16.3. Partner Networks and Campaign Evaluation. Where necessary to maintain strategic commercial collaborations, we may share basic, non-sensitive booking events and conversion indicators with our trusted marketing and affiliate partners. This sharing occurs exclusively when the booking events are directly related to promotional content, referral links, or specialized discounts displayed on the partners’ own websites or mobile applications. This transmission is based on our legitimate business interests to measure the technical effectiveness of specific marketing partnerships, audit traffic sources, and accurately calculate or reimburse partner commissions.
16.4. Third-Party Data Processors. We rely on contractually affiliated third-party companies, localized technology vendors, and external service providers (“processors”) to execute our daily platform services. In these instances, personal data is transferred to these processors solely to enable them to perform specialized technical tasks on our behalf. These processors are carefully selected and routinely evaluated by us to ensure your privacy rights are heavily protected. Our data processors are contractually prohibited from using your data for any unauthorized secondary purposes, and they are contractually bound to treat your personal information exclusively in accordance with this privacy policy and the strict data protection laws of Singapore. We ensure via data protection agreements that any cross-border processing of your Personal Data outside of Singapore only occurs if the destination territory guarantees an equivalent level of data security or if alternative appropriate safeguards, such as standard data transfer clauses, are securely established.
16.5. Business Transcripts and Corporate Restructuring. As we continue to develop, expand, and optimize our business operations, the corporate structure of AURORA FX TECHNOLOGY LLP may occasionally evolve through changes in legal form, corporate mergers, asset acquisitions, or the sale of specific business components. In the event of such structural transactions, customer databases, historical booking logs, and operational communication records are typically transferred alongside the underlying business assets. Whenever personal information is disclosed to surviving corporate entities or prospective third-party buyers to the extent described above, we contractually guarantee that the receiving parties remain bound by the terms of this privacy policy and applicable data protection legislation. Any such transfer of data is justified by our legitimate business interest in adapting our corporate structure to shifting economic, legal, and operational circumstances.
- Automated Individual Decisions or Profiling Measures
17.1. We may utilize automated decision-making and electronic risk-profiling technologies to enhance the digital security of our booking infrastructure, protect local activity operators, and prevent fraudulent e-commerce activities. This specialized evaluation involves the real-time calculation of risk and fraud scores provided by our integrated transaction security tools (as detailed in Section 8), which automatically flag or block payment attempts deemed to carry an abnormally high risk of financial fraud or unauthorized card use. If your transaction is automatically blocked by these security protocols, you will be unable to finalize your booking directly on our platform. However, you maintain the absolute right to request manual human intervention, express your point of view, and formally contest the automated decision by submitting a review request to our platform administration team at info@baliwatersports.com.
- Erasure and Retention of Your Data
18.1. General Deletion and Anonymization. We systematically delete or permanently anonymize your Personal Data as soon as it is no longer strictly necessary to fulfill the operational purposes for which we originally collected or processed it, in accordance with the timelines outlined throughout this privacy policy. We will, however, continue to retain specific elements of your personal data if we are legally obligated to do so under statutory record-keeping laws—such as corporate tax, accounting, or maritime safety regulations—or if the data is required for an extended period to assist in active law enforcement investigations, support criminal prosecutions, or secure, assert, and enforce valid legal claims.
18.2. Account Deletion and Backup Frameworks. If you choose to voluntarily close or delete your registered user profile on the BALI WATER SPORTS Platform, your primary account dashboard, profile configurations, and active wishlists will be deleted completely and permanently. Notwithstanding your account closure, we will securely retain archived backup copies of your administrative data to the extent and for the precise duration that this information remains necessary to fulfill statutory legal obligations, verify historical financial transactions, or defend our legal position against potential disputes, rooted in our legitimate business interests.
18.3. Restriction of Processing. In any scenario where personal information must be retained exclusively for statutory or legal compliance reasons beyond its standard operational lifecycle, the processing of that data will be heavily restricted. This means the restricted records are securely isolated on encrypted servers and remain completely unavailable for further commercial use, everyday marketing distribution, or customer relationship management.
- Your Rights as a Data Subject and Data Protection Administration
19.1. General Rights and Points of Contact. You possess specific statutory rights regarding the collection, use, disclosure, access, and correction of your Personal Data under applicable data protection frameworks, including the Singapore Personal Data Protection Act (PDPA). To exercise any of your administrative rights, submit a formal data request, or seek clarity regarding our data handling protocols, you may contact our dedicated data privacy administration team directly via email at info@baliwatersports.com. We will acknowledge and process all valid verification and data subject requests promptly and in accordance with statutory timelines.
19.2. Right of Access and Information. You have the right to request access to the specific pieces of Personal Data we currently hold or process about you, along with detailed information regarding the ways in which your data has been utilized or disclosed by our platform within the past year. Upon receiving a verified request, we will provide this information in a clear, accessible format, subject to any specific exemptions or reasonable administrative fee allocations permitted under applicable local laws.
19.3. Right to Correction and Accuracy. You have the right to request that we correct, update, or rectify any inaccurate, incomplete, or outdated Personal Data relating to you that is maintained within our active systems. Upon your notification and our subsequent verification, we will amend your record without undue delay and ensure that the corrected data is transmitted to any necessary third-party activity operators or service providers who handle data on our behalf.
19.4. Right to Withdrawal of Consent. You maintain the absolute right to withdraw your consent for the collection, use, distribution, or cross-border disclosure of your Personal Data at any time (for example, opting out of promotional newsletters or disabling non-essential analytical cookies). Upon receiving your valid revocation notice, we will cease processing your information for those specific activities, unless an alternative legal obligation or legitimate business exception permits or requires us to retain it. Please note that withdrawing consent for core operational data may restrict our ability to fulfill active bookings or provide full platform functionalities.
19.5. Right to Deletion or Erasure. Under applicable international standards and localized retention frameworks, you may request the deletion, destruction, or permanent anonymization of your Personal Data from our active production databases. We will execute your request if the underlying information is no longer strictly necessary for the operational purposes for which it was collected, if your tracking consent has been successfully withdrawn, or if the data is no longer bound by statutory record-keeping, tax, or legal defense obligations administered by AURORA FX TECHNOLOGY LLP.
19.6. Right to Data Portability. Where technically feasible and legally recognized, you have the right to request that we compile the specific Personal Data you directly provided to us and transmit it to you or another digital platform operator in a structured, commonly used, and machine-readable electronic format to facilitate secure data portability.
19.7. Right to Object and Restrict Processing. You have the right to object to or request the restriction of the processing of your Personal Data on grounds relating to your particular situation, especially where data is processed based on our legitimate business interests rather than direct contractual necessity. Upon a valid objection, we will suspend the targeted processing activities unless we can demonstrate compelling, overriding legitimate business grounds that supersede your individual privacy interests, or where the continued processing is mandatory to assert, exercise, or defend valid legal claims.
19.8. Right to Lodge a Complaint. If you believe that our handling or processing of your Personal Data infringes upon your statutory privacy rights, fails to satisfy the requirements of the Singapore PDPA, or disregards international compliance frameworks, you have the right to lodge a formal complaint with the Personal Data Protection Commission (PDPC) of Singapore or the relevant supervisory authority in your country of residence.
19.9. Data Processing When Exercising Your Rights. Finally, we explicitly note that when you initiate a request to exercise your statutory data protection rights, we are legally required to collect and process the specific Personal Data you provide within that context (such as identity verification documents, email confirmations, or specific account records) solely for the purpose of verifying your authorization, executing your request, and maintaining permanent compliance records. This specific administrative processing is conducted to fulfill our binding statutory record-keeping obligations and ensure robust corporate accountability.
- United States Residents’ Rights
20.1. General Disclosures and Scope. If you are a resident of certain United States jurisdictions that have enacted comprehensive state data protection laws—including California, Colorado, Connecticut, Utah, or Virginia—you may possess specific statutory rights regarding your personal information. The additional disclosures and legal mechanisms set out below describe these rights and outline how you can exercise them on the BALI WATER SPORTS Platform. This specialized section aligns with frameworks such as the California Consumer Privacy Act of 2018 (“CCPA”), the California Privacy Rights Act of 2020 (“CPRA”), and corresponding state codes, but does not apply to publicly available or de-identified information. Personal information is collected when you create an account, leave activity reviews, engage customer support, subscribe to marketing newsletters, buy water sports tours, or interact with our social media channels. If technically necessary to execute a request, we or our partners collect or process limited sensitive personal information, such as account access credentials or passport numbers, which are occasionally mandated by local Indonesian maritime operators for safety verification, ticketing, and insurance registration during checkout.
20.2. “Selling” and “Sharing” Thresholds. We do not “sell” your personal information for monetary or financial compensation as defined under the CCPA, CPRA, Virginia Consumer Data Protection Act (“VCDPA”), or alternative state statutes. However, depending on your voluntary tracking preferences, we may “share” or disclose specific network identifiers or behavioral analytics with trusted advertising partners for cross-context behavioral advertising or targeted marketing purposes, as detailed in our tracking disclosures. We do not knowingly sell or share the personal information or tracking profiles of website visitors under 16 years of age.
20.3. Right to Access and Specific Information. You have the right to request that we disclose clear details regarding how we collected, utilized, and shared your personal information over the preceding 12-month period. Once we receive and verify your consumer request, we will disclose the categories of personal information collected, the explicit categories of sources from which the data was compiled, our business or commercial purpose for gathering or sharing that data, the categories of third parties with whom that information was shared, and the specific categories of personal information disclosed for a business purpose to external service providers.
20.4. Right to Deletion, Correction, and Limitation. You have the right to request that we permanently delete the personal information we have collected from you, subject to specific regulatory exceptions—such as when the information is required to finalize an active booking, detect security threats, prevent fraud, or satisfy statutory financial record-keeping laws. Additionally, you have the right to request that we rectify inaccurate or outdated personal information maintained within our databases. You also possess the right to limit the use or disclosure of your sensitive personal information if it is being utilized for cross-context profiling outside of the primary scope required to deliver the core services you explicitly requested.
20.5. Non-Discrimination Guarantees. We will never discriminate against you, deny you access to services, alter booking prices, or provide a different quality of user experience on the BALI WATER SPORTS Platform because you chose to exercise any of your statutory privacy rights.
20.6. Opting Out of Targeted Advertising and Data Sharing. You are free to modify your device preferences at any time to opt out of the cross-context behavioral sharing or targeted advertising tracked on our platform. We and our marketing partners place tracking pixels, scripts, and cookies on our website to analyze user journeys and serve interest-based advertisements across external digital networks. If you decide to opt out of this data sharing, you can immediately update your configurations by adjusting the cookie and tracking preference tools located in our website footer, or by modifying your internet browser to automatically send an opt-out signal.
20.7. Exercising and Verifying Your Rights. To exercise your US state privacy rights, please submit a clear, detailed request to our privacy team via email at info@baliwatersports.com. To protect your security and privacy, we will take reasonable steps to verify your identity before fulfilling any data access, correction, or deletion requests, which may include matching your name and email address against our active booking records. If you are a resident of California, Colorado, or Connecticut, you may formally designate an authorized agent registered with your respective Secretary of State to submit a privacy request on your behalf, provided you supply the agent with signed, written permission to act. Parents or legal guardians may also submit a verifiable consumer request on behalf of their minor children.
Changes to This Privacy Policy
The current, legally binding version of this privacy policy will always be accessible on our official platform. We reserve the right to modify or update this document at any time to reflect changes in our operational procedures, payment gateway setups, or global data protection regulations.
Last updated: June 2026