Privacy & Data Protection

Privacy Policy

Batam Teambuilding is a brand operated by VTL Travel Private Limited. This policy explains how we collect, use, disclose and protect personal data when you enquire about or book services through this website.

About this Privacy Policy

This Privacy Policy explains how VTL Travel Pte. Ltd., trading as Batam Teambuilding (“Batam Teambuilding”, “we”, “us” or “our”), collects, uses, discloses, stores and otherwise processes personal data through batamteambuilding.com and through our enquiries, quotations, bookings, events and customer-support activities.

It is intended to describe our practices under applicable data protection laws, including Singapore’s Personal Data Protection Act 2012 (PDPA) and, where relevant to our activities in Indonesia, Indonesia Law No. 27 of 2022 on Personal Data Protection (PDP Law). If a legal requirement gives you greater protection than this Policy, that requirement will apply.

Who We Are

Batam Teambuilding is a corporate team-building and group-travel brand operated by VTL Travel Pte. Ltd., a Singapore travel agency holding Travel Agent Licence TA03084. We plan and coordinate corporate retreats and group trips between Singapore and Batam, Indonesia, including ferry travel, accommodation, land transport, meals, activities and event support.

For the personal data covered by this Policy, VTL Travel Pte. Ltd. will generally be the organisation responsible for deciding why and how the data is processed. In some corporate-group arrangements, we may process participant information on the instructions of the company, school, church, association or organiser that made the booking.

Scope

This Policy applies when you:

  • visit or interact with our website;
  • submit a quotation or contact form;
  • communicate with us by email, telephone, WhatsApp, social media or in person;
  • request, purchase or participate in a Batam Teambuilding programme;
  • act as an organiser or provide information about other participants; or
  • appear in event photographs, recordings, testimonials or customer stories where the relevant permissions have been obtained.

This Policy does not replace a corporate client’s own employee or participant privacy notice. Where we process data solely on that client’s instructions, the client remains responsible for its own legal obligations and notices.

Personal Data We May Collect

Depending on your interaction with us, we may collect the following categories of personal data.

Contact and organiser information

  • name, company or organisation, job title and organiser role;
  • email address, telephone or WhatsApp number and preferred contact method;
  • postal or billing address where needed for invoicing, contracting or a booking; and
  • correspondence, enquiries, feedback, complaints and customer-service records.

Trip and event-planning information

  • group type, estimated or confirmed participant count, preferred travel dates and trip duration;
  • budget range, team-building objectives, preferred activities, accommodation, transport, meal and meeting requirements;
  • itineraries, rooming arrangements, ferry arrangements and programme schedules; and
  • changes, cancellations, refunds, incident reports and service feedback.

Participant and travel-document information

When necessary to confirm or deliver a booking, we may collect participant names and other details required by ferry operators, hotels, insurers, immigration authorities or other travel partners. These may include nationality, date of birth, gender, passport or other travel-document details and emergency-contact information. We will seek to collect only the information required for the relevant arrangement.

Special requirements

You or your organiser may choose to tell us about dietary requirements, allergies, accessibility needs, medical considerations or other information needed to arrange a safe and suitable programme. Some of this information may be sensitive personal data. We use it only where necessary and with an appropriate legal basis, such as explicit consent, contractual necessity or the protection of a person’s vital interests.

Payment and transaction information

We may hold quotation, invoice, payment-status, refund and transaction-reference information. Where a third-party payment provider processes a payment, that provider may collect payment-card or banking details under its own privacy terms. Unless expressly stated during payment, we do not retain complete payment-card credentials on this website.

Photographs, video and feedback

Where photography or videography forms part of an agreed event service, we may collect a participant’s image, voice and appearance in photographs or recordings. We may also collect testimonials, reviews, company names and logos where permission has been given for a client story or promotional use.

Website and technical information

When you use the website, our systems and authorised service providers may collect technical data such as IP address, browser and device information, approximate location derived from IP address, referring page, pages viewed, link interactions, date and time of access, cookie identifiers and security logs. Details will depend on the cookies and tools active on the website at the time.

How We Collect Personal Data

We may obtain personal data:

  • directly from you through forms, email, telephone, WhatsApp, social media, meetings, booking documents and event participation;
  • from an authorised corporate organiser, HR or administrative contact, group leader, school, church, association, travel companion, parent or guardian;
  • from hotels, ferry operators, transport providers, activity providers and other partners involved in confirming or delivering your arrangements;
  • automatically from the website and related technologies, subject to applicable consent requirements; and
  • from public or professional sources where reasonably necessary to verify corporate information, prevent fraud or communicate with an organisation.

Please provide accurate and current information. If you provide another person’s personal data, you confirm that you are authorised to do so and that you have given that person access to this Policy or another appropriate notice.

Why We Collect, Use and Disclose Personal Data

We may process personal data for the following purposes:

  • responding to enquiries, requests, applications, complaints and feedback;
  • preparing personalised quotations and recommending suitable hotels, ferries, transfers, meals, activities, venues and itineraries;
  • verifying booking or participant information where reasonably required;
  • creating, administering and fulfilling contracts, bookings and requested services;
  • coordinating suppliers, programme logistics, participant communications, on-trip support and emergency response;
  • managing payments, invoices, accounting, changes, cancellations, refunds and disputes;
  • accommodating dietary, accessibility, medical or safety requirements;
  • providing event photographs or video to the client and, with an appropriate permission, publishing client stories or promotional material;
  • managing our relationship with customers, organisers, suppliers and partners;
  • maintaining business records, carrying out audits and complying with tax, travel, immigration, regulatory, court and law-enforcement requirements;
  • detecting and preventing fraud, misuse, security threats and unauthorised access;
  • improving our website, packages, operations and customer experience through appropriate analytics and aggregated reporting;
  • establishing, exercising or defending legal rights; and
  • other purposes that are reasonably related to the circumstances or that we explain when collecting the data.

Depending on the circumstances and applicable law, we may process personal data because you have consented; because processing is reasonably necessary to take steps at your request or perform a contract; because we must meet a legal obligation; because it is necessary to protect a person’s vital interests; or because another exception or lawful basis applies.

This Policy is a notice explaining our practices. It does not, by itself, create consent for optional marketing, public promotional media or another use for which separate consent is required.

Where permitted by law, we may rely on legitimate interests for activities such as protecting our customers and systems, preventing fraud or misuse, maintaining essential business records, improving services using proportionate analytics, and establishing or defending legal claims. Before relying on legitimate interests where an assessment is required, we will consider the purpose, necessity and potential effect on individuals and implement reasonable safeguards.

We do not currently rely on deemed consent by notification for unrelated secondary purposes such as direct marketing. If we propose to rely on that basis in the future, we will carry out the required assessment and provide an appropriate notice and opportunity to opt out before the processing begins.

Corporate Organisers and Participant Data

A company, school, church, association or group organiser may provide participant data so that we can arrange ferry tickets, rooms, transport, meals, activities or safety support. The organiser should:

  • collect and share only the data reasonably needed for the trip;
  • have authority, consent or another lawful basis to provide the data;
  • give participants this Policy or an equivalent notice before sharing their information;
  • keep participant information accurate and promptly notify us of changes; and
  • use secure methods when sending passports, rooming lists, medical information or other sensitive data.

Where we act only on an organiser’s documented instructions, requests concerning that participant data may need to be handled together with the organiser.

Cookies and Similar Technologies

Our website may use cookies and similar technologies needed for site operation, security, user preferences, performance measurement, analytics or advertising. Non-essential cookies will be used in accordance with applicable consent requirements. You may be able to accept, reject or change non-essential cookie choices through the site’s cookie controls and your browser settings.

Third-party video, map, social-media or messaging features may also process information when you interact with them or leave our website. Their privacy practices are governed by their own notices. The exact tools and cookie categories depend on the website configuration and will be described in our cookie notice or settings where provided.

Marketing Communications

We may send news, travel ideas, package updates or offers where you have consented or where another lawful basis permits it. You can unsubscribe using the link in an email or contact us to change your preferences. We will continue to send necessary service messages about active enquiries or bookings even if you opt out of marketing.

Marketing to Singapore telephone numbers will be conducted subject to applicable consent and Do Not Call requirements. We do not sell or rent personal data or contact lists to third parties for their own independent marketing.

Event Photography and Video

Where photography or video is planned, we will work with the organiser to provide an appropriate notice and to identify participants who should not be recorded. Media delivered privately to the contracting client may be processed as part of the agreed service. Public advertising, social-media posts, testimonials and client stories will be handled under an appropriate permission or other lawful basis.

You may raise an objection or withdraw a relevant consent by contacting the organiser or us. Withdrawal will apply to future use after it takes effect, but it may not require removal of material already lawfully published, printed or incorporated into completed work where removal is impossible or legally unnecessary. We will nevertheless consider reasonable removal requests.

When We Disclose Personal Data

We may disclose relevant personal data, on a need-to-know basis, to:

  • our employees, authorised representatives, Batam-based operations team, facilitators and guides;
  • the corporate organiser and other contacts authorised for the group;
  • ferry operators, hotels and resorts, transport providers, restaurants and caterers, venues, attractions, activity providers and event suppliers;
  • photography, videography or media-production providers engaged for the event;
  • insurers, assistance providers, medical services or emergency responders where needed;
  • payment, banking, accounting and fraud-prevention providers where relevant to a transaction;
  • website hosting, cloud storage, form, email, messaging, CRM, security, analytics and other technology providers acting for us;
  • auditors, insurers, lawyers and other professional advisers;
  • government departments, immigration or tourism authorities, regulators, courts and law-enforcement bodies where required or permitted by law; and
  • a purchaser, successor or adviser involved in a genuine business reorganisation, merger or transfer, subject to appropriate confidentiality and legal safeguards.

We provide only the information reasonably necessary for the recipient’s role and require service providers to protect it through contractual or other appropriate controls where applicable.

International Transfers

Delivering Singapore-to-Batam travel requires information to move between Singapore and Indonesia. Some technology, communications or service providers may also process data in other countries. When personal data is transferred outside Singapore or another relevant jurisdiction, we will take steps required by applicable law to ensure an appropriate standard of protection, such as contractual safeguards, due diligence, access restrictions and limiting the data transferred.

How We Protect Personal Data

We use reasonable administrative, technical and physical safeguards appropriate to the nature of the data and the risks involved. Depending on the system and circumstances, safeguards may include:

  • collecting only data reasonably needed for an identified purpose;
  • role-based or need-to-know access controls and appropriate authentication;
  • password practices and multi-factor authentication where supported;
  • encryption in transit and other suitable encryption measures;
  • security updates, malware protection, backups and monitoring;
  • staff procedures, confidentiality expectations and incident escalation;
  • service-provider review and contractual data-protection requirements; and
  • secure deletion, disposal or anonymisation when data is no longer required.

No method of internet transmission or electronic storage is completely secure. We therefore cannot guarantee absolute security, but we will investigate and manage suspected breaches and make notifications where required by law.

Personal Data Breaches

If we become aware of a suspected personal data breach, we will assess and contain it, preserve relevant information, take reasonable remedial steps and make any legally required notifications. Where Singapore’s PDPA applies, a notifiable breach will be reported to the Personal Data Protection Commission as soon as practicable and no later than the applicable statutory deadline after we determine that it is notifiable, and affected individuals will be notified where required. Where Indonesia’s PDP Law applies, written notification will be made within the applicable period, including 3 × 24 hours where required.

Accuracy and Data Minimisation

We take reasonable steps to keep personal data accurate and complete where it may affect a decision or be disclosed to another organisation. Please tell us promptly if contact, passport, rooming, dietary, accessibility or other booking information changes. We seek to collect only information relevant to the stated purpose.

Retention

We retain personal data only for as long as reasonably necessary for the purpose for which it was collected and for legitimate business or legal needs, such as completing travel, handling complaints, maintaining accounting or tax records, resolving disputes and meeting regulatory obligations. Retention periods vary by record type.

Passport, identity, medical and other higher-risk information will be reviewed for deletion or secure disposal when it is no longer needed for the relevant booking, legal requirement or unresolved issue. When data no longer needs to identify a person, we may delete it or convert it into anonymised information. Residual copies may remain temporarily in protected backups until they are overwritten under normal backup cycles.

Your Rights and Choices

Depending on applicable law and any permitted exceptions, you may ask us to:

  • provide access to personal data we hold about you and information about how it has been used or disclosed;
  • correct inaccurate or incomplete personal data;
  • withdraw consent to specified collection, use or disclosure;
  • stop or restrict certain processing;
  • delete personal data that is no longer lawfully required;
  • provide a portable copy where a portability right applies; or
  • review a complaint or objection about our processing.

To protect you and other individuals, we may request information to verify identity and authority before acting. We may refuse, limit or charge a reasonable fee for a request where applicable law permits, and we will explain this where required.

Access and Correction Requests

We aim to acknowledge requests promptly and ordinarily complete straightforward access or correction requests within 14 business days after receiving the information needed to process them. Complex requests may take longer. This internal target does not extend any shorter statutory deadline. For requests governed by Singapore law, we will respond within the applicable period and notify you if additional time is required. For requests governed by Indonesia’s PDP Law, we will take action within the applicable statutory period, including 3 × 24 hours where that period applies.

You may withdraw consent by giving reasonable notice and identifying the processing you want to stop. We will explain likely consequences, which may include being unable to arrange or continue part of a booking. We aim to act within 14 business days after receiving sufficient information, but any shorter legal deadline applies, including Indonesia’s applicable 3 × 24-hour period where relevant. Withdrawal does not affect prior lawful processing or information that must be retained for legal or legitimate purposes.

Children and Young Participants

Our website is not directed at children who make bookings independently. If a programme includes a child or young participant, the school, organisation, group leader, parent or guardian responsible for the booking should provide the necessary notice and obtain any required authority or consent before sharing the child’s data. We will apply additional care to identity, health, safety and media information relating to minors. If we learn that data was provided without appropriate authority, we will take reasonable steps to restrict or delete it.

Third-Party Websites and Services

Our website may link to third-party websites, messaging services, video platforms, maps, social networks, ferry operators, hotels or other partners. We do not control their independent privacy practices. Review the relevant privacy notice before providing data directly to another organisation.

Changes to this Policy

We may update this Policy when our services, technology, partners or legal obligations change. The revised version will be posted on this page with a new effective or last-updated date. Where a change materially affects how we use previously collected data, we will provide additional notice or obtain consent where required.

Contact Our Data Protection Officer

For questions, access or correction requests, withdrawal of consent, complaints or other privacy matters, please contact:

Data protection contact
Data Protection Officer, VTL Travel Pte. Ltd.
Email
hello@vtltravel.com
Telephone / WhatsApp
+65 8295 5180
Business address
15 Beach Road, Beach Centre, #02-01, Singapore 189677
Website
batamteambuilding.com

Please provide enough information for us to verify your identity and understand the request. Contact us first so that we can investigate; you may also approach the relevant data protection regulator if you remain dissatisfied and are entitled to do so.