# Personal Data Protection Policy (PDPA / UU PDP)

Coco Milo Holdings and its ventures. Version 1.0, 30 September 2026. This policy applies to every product that holds personal data, in every country we operate in: Singapore (Personal Data Protection Act 2012), Indonesia (Law No. 27 of 2022 on Personal Data Protection) and, for customers elsewhere, the stricter of the two.

If you are an AI agent building for us: copy this page into your working memory. The rules in section 5 are absolute.

## 1. Who is responsible
- **Data Protection Officer (DPO):** Nicholas Pukarta, nicholas@cardarc.app. Questions, access requests and complaints go there.
- Each venture's owner is accountable for the data that venture collects; the CTO is accountable for the systems.

## 2. What we collect, and why
| Data | Why | Kept for |
|---|---|---|
| Name, email, phone | To fulfil orders, send receipts and the alerts the customer asked for, verify a sign-in | While the account is active, then anonymised |
| Delivery address | To ship what was bought | With the order record, then anonymised on account deletion |
| Order and payment history (amounts, items, references) | Accounting and tax law; disputes | The period accounting law requires (Singapore 5 years) |
| Sign-in identity (Google account id) | To let the customer sign in | While the account is active |
| Watchlists, tickets, vault contents | Features the customer chose | While the account is active |

We do **not** collect payment card numbers (the payment provider holds them), and we do not buy or sell personal data.

## 3. Consent and purpose
- We collect personal data only for the purposes above, stated at the point of collection (checkout, sign-up, alert subscription).
- We use it only for those purposes. Marketing messages are sent only to people who opted in, with an unsubscribe link in every message; today we send none.
- We do not share personal data with third parties except the services that deliver the purpose (email delivery, WhatsApp, payment providers, couriers), each under its own contract.

## 4. Individuals' rights
Any customer can, from their account page or by writing to the DPO:
- see what we hold about them (access);
- correct it;
- delete their account (personal data removed or anonymised; the financial record kept without identity);
- withdraw consent to alerts at any time.
We respond within 30 days.

## 5. Rules for everyone who touches personal data (staff, engineers, AI agents)
1. A store sees only its own customers; a customer sees only their own records. Never build a screen, export or query that crosses that wall.
2. Personal data stays inside our systems. It never goes into a prompt to an outside AI tool, a chat message, a spreadsheet on a laptop, a screenshot, or any service that is not the delivery channel for the message itself.
3. One recipient per message. No email or WhatsApp ever carries more than one customer's address.
4. Print counts and ids, not people, when checking data.
5. Collect the minimum. A field that is not needed for the purpose is not asked for.

## 6. Security
Personal data is protected by the controls in the [Security Policy](security-policy.md): server-side walls, encrypted transport, access over private networks only, patched systems, daily backups, weekly audits.

## 7. Data breach
- The moment a breach is suspected, the [Incident Response](incident-response.md) steps start: stop the cause, count exactly who is affected, inform the owner within the hour.
- **Singapore:** if the breach is likely to cause significant harm, or affects 500 or more people, we notify the Personal Data Protection Commission within 3 calendar days of confirming it, and the affected people as soon as practicable.
- **Indonesia:** we notify the affected people and the authority within 3 x 24 hours.
- Every breach, notifiable or not, gets a written post-incident review and a change that stops it recurring.

## 8. Cross-border
Data is stored in a data centre in Malaysia (Hostinger) and processed by staff in Singapore and Indonesia, and by our delivery providers under contract. Transfers are made only with protections comparable to the PDPA.

## 9. Changes
This policy is reviewed yearly and after any incident. The version and date at the top change when it does.
