Privacy and security

This Privacy Notice (“Notice”) applies to personal data and information held by PT Bank HSBC Indonesia (“HSBC”, “we”, “our” or “us”) and any members of the HSBC Group (“HSBC Group” and any “member of the HSBC Group” means HSBC Holdings plc and/or its affiliates, subsidiaries, associated entities and any of their branches and offices).

It explains what information we collect about you, how we’ll use that information, who we’ll share it with, the circumstances when we’ll share it and what steps we’ll take to make sure it stays private and secure.

Our Privacy Principles

Our business has been built on trust between our customers and ourselves. To preserve the confidentiality of all data and information you provide to us, we maintain the following privacy principles:

  1. We only collect personal data and information of customers, individuals connected to customers’ business and anyone who access this website, in line with relevant laws and regulations. Such customers and such individuals may include persons listed in Our Information Collection Statement or any of them (collectively “you”or “your”).
  2. We may use, transfer and disclose personal information in connection with purposes set out in Our Information Collection Statement below (the “Purpose”).
  3. We may pass personal information to other HSBC Group companies or agents, or other recipients set out in this Notice, as necessary and appropriate for the Purpose and to the extent permitted by laws and regulations applicable.
  4. We will not disclose personal information to anyone unless we have the necessary consent or are required by laws or public duty or have previously informed the relevant individual or have legitimate business purposes that require disclosure.
  5. We may be required from time to time to disclose data and information to governmental or judicial bodies or agencies or our regulators, but we will only do so under proper authority and/or with legitimate interest/purpose.
  6. We aim to keep personal information on our records accurate and up to date.
  7. We maintain strict security systems designed to prevent unauthorised access to personal information by anyone, including our staff.
  8. All HSBC Group companies, all our staff and all third parties with permitted access to personal information are specifically required to observe our confidentiality and data privacy related obligations.

By maintaining our commitment to these principles, we at HSBC will ensure that we respect the inherent trust placed in us.

Your privacy matters to us

This section provides specific details of how we treat any personal information you might provide or share to us, including when you visit this site.

Data Security

  • Security is our top priority. HSBC will strive at all times to ensure that your personal data will be protected against unauthorised or accidental access, processing or erasure. We maintain this commitment to data security by implementing appropriate physical, electronic and managerial measures to safeguard and secure your personal data.
  • The secure area of our website supports the use of Secure SocketLayer (SSL) protocol and 128-encryption technology — an industry standard for encryption over the Internet to protect data. When you provide sensitive information such as credit card details, it will be automatically converted into codes before being securely dispatched over the internet.
  • Our web servers are protected behind "firewalls" and our systems are monitored to prevent any unauthorised access. We will not send personal information to you by ordinary email. As the security of ordinary email cannot be guaranteed, you should only send email to us using the secure email facility on our website.

All practical steps will be taken to ensure that personal data will not be kept longer than necessary and that we will comply with all statutory and regulatory requirements in Indonesia concerning the retention of personally identifiable information.

Security Assurance

  • Both you and HSBC play an important role in protecting against online fraud. You should be careful that your bank account details including any of your user ID and/or password are not compromised by ensuring that you do not knowingly or accidentally share, provide or facilitate unauthorised use of it. Do not share your user ID and/or password or allow access or use of it by others. We endeavor to put in place high standards of security to protect your interests.
  • You should safeguard your unique user ID and password by keeping it secret and confidential. Never write them down or share these details with anyone. HSBC will never ask you for your Internet Banking password, in order to ensure that you are the only person who knows this information. When choosing your unique user ID and password for the first time, do not create it using easily identifiable information such as your birthday, telephone number or a recognisable part of your name. If you think your user ID and/or password has been disclosed to a third party, is lost or stolen and unauthorised transactions may have been conducted, you are responsible to inform us immediately.

Collection of Personal Information

  • Use of Cookies, Spotlight Tags and Web Beacons, etc.

Your visit to this site may be recorded for analysis on the number of visitors to the site and general usage patterns. Some of this information will be gathered through the use of "cookies". Cookies are small bits of information that are automatically stored on a person's web browser in their computer that can be retrieved by this site. Should you wish to disable these cookies you may do so by changing the setting on your browser.

Cookies allow us to recognise your device, and they store information about your use of this site/app. This information enables us to provide more features that you may find useful, to tailor the content of our website and mobile applications to suit your interests and, if your marketing preference settings allow, to provide you with promotional materials or direct marketing based on your usage patterns. Most browsers are initially set to accept cookies. If you would prefer, you can set your browser to disable cookies or inform you when they are set. However, by disabling them, you may not be able to take full advantage of our website, including HSBC Internet Banking.

If you accept cookies during your use of this site or you continue to use this app, you will be acknowledging that your information is being collected, stored, accessed and used as outlined above.

HSBC may also work with third parties including data management agencies and ad networks (such as Eloqua) to research certain usage and activities on parts of our web site on our behalf. Eloqua use technologies such as spotlight monitoring, web beacons and cookies to collect information for this research. The information collected through technologies such as cookies, spotlight tags and web beacons etc are used to find out more about our users, including user demographics and behaviour and usage patterns, for more accurate reporting and to improve the effectiveness of our marketing. Information recorded through the use of these devices are aggregated and then shared with us. As part of the information that we share with them, we may share your advertising identifier and "installation event" (which means the data in relation to when you first install or use this site). No personally identifiable information about you is collected or shared with HSBC by Eloqua with HSBC as a result of this research. Should you wish to disable the cookies associated with these technologies such as spotlight tags and/or web beacons etc, you may do so by changing the setting on your browser. However, you may not be able to enter certain part(s) of our website, including HSBC Internet Banking.

Marketing Promotions

Occasionally we may collect personal information from visitors to this site. Such information is only collected from individuals who voluntarily provide us with their personal information.

You can choose to receive marketing and other promotional materials by email and you will always have an opportunity to opt-out.

If at any time you would like us to cease sending you direct mailings, please contact our Corporate Call Center on 1500237 / (62-21) 25514777 or please fill in the online form. We will then, at no cost to you, act on your request within 30 days and ensure that you are not included in future direct marketing promotions.

If we do ask you to provide personal information, we will always specify the purpose for which such personal information is collected and ensure that it is only used for the purpose specified at the time of collection.

Our Information Collection Statement

This statement is made by HSBC in accordance with the applicable laws and regulations including but not limited to law and regulations on Personal Data Protection, regulations on the implementation of Anti-Money Laundering (APU) and Prevention of Terrorism Financing (PPT) programs. This statement is intended to notify you why personal data is collected, how it will be used and to whom data access requests are to be addressed.

Collection of Data

a. We may collect data of customers, third parties and/or related individuals in connection with the purposes set out in this Notice. These customers, third parties and other individuals may include the following or any of them:

  • applicants for banking or financial services;
  • persons giving or proposing to give guarantees or security for obligations owed to us;
  • persons linked to a customer or an applicant that is not an individual, including the beneficial owners and officers of that customer or applicant, or in the case of a trust, including the trustees, settlors, protectors and beneficiaries of the trust; and
  • other persons who are relevant to a customer’s relationship with us, including third party service providers with whom the customer interacts in connection with the marketing of our products and services and in connection with the customer’s application for our products and services (including credit references).

b. If the data requested by us is not provided, we may be unable to provide (or continue to provide) products or services to you or to the relevant customer or applicant linked to you.

c. Data may be:

  1. collected from you directly, from someone acting on your behalf or from another source; and
  2. combined with other data available to members of the HSBC Group.

Use of Data

d. We will use data for the following purposes or any of them (which may vary depending on the nature of your relationship with us):

  1. considering and processing applications for products and services and the daily operation of products and services (including credit facilities provided to you or the relevant customer linked to you);
  2. conducting credit checks whenever appropriate (including upon an application for consumer credit (including mortgage loans) and when we review credit which normally takes place one or more times each year);
  3. creating and maintaining our credit and risk related models;
  4. assisting other credit providers in Indonesia to conduct credit checks and collect debts;
  5. ensuring your ongoing credit worthiness and good standing;
  6. designing financial products and services (including insurance, credit card, securities, commodities, investment, banking and related products and services) for your use;
  7. determining the amount of indebtedness owed to or by you;
  8. exercising our rights under contracts with you, including collecting amounts outstanding from you;
  9. meeting our obligations, requirements or arrangements or those of any member of the HSBC Group, whether compulsory or voluntary, to comply with or in connection with:
    1. any law, regulation, judgment, court order, sanctions regime, within or outside Indonesia existing currently and in the future (“Laws”);
    2. any guidelines, guidance or requests given or issued by any legal, regulatory, governmental, tax, law enforcement or other authorities, or self-regulatory or industry bodies or associations of financial services providers within or outside Indonesia existing currently and in the future and any international guidance, internal policies or procedures;
    3. any present or future contractual or other commitment with legal, regulatory, judicial, administrative, public or law enforcement body, or governmental, tax, revenue, monetary, securities or futures exchange, court, central bank or other authorities, or self-regulatory or industry bodies or associations of financial service providers or any of their agents with jurisdiction over all or any part of the HSBC Group (together the “Authorities” and each an “Authority”) that is assumed by, imposed on or applicable to us or any member of the HSBC Group; or
    4. any agreement or treaty between Authorities;

  10. complying with any obligations, requirements, policies, procedures, measures or arrangements for sharing data and information within the HSBC Group and/or any other use of data and information in accordance with any programmes for compliance with sanctions or prevention or detection of money laundering, terrorist financing or other unlawful activities;
  11. conducting any action to meet our obligations or those of any member of the HSBC Group to comply with Laws or international guidance or regulatory requests relating to or in connection with the detection, investigation and prevention of money laundering, terrorist financing, bribery, corruption, tax evasion, fraud, evasion of economic or trade sanctions and/or any acts or attempts to circumvent or violate any Laws relating to these matters;
  12. meeting our obligations or those of any member of the HSBC Group to comply with any demand or request from the Authorities;
  13. enabling actual or proposed assignee(s) of all or any part of our business and/or assets, or participant(s) or sub-participant(s) of our rights in respect of you to evaluate the transaction intended to be the subject of the assignment, participation or sub-participation and enabling the actual assignee(s) to use your data in the operation of the business or rights assigned; and
  14. any other purposes relating to the purposes listed above.

Disclosure of Data

e. Data held by us or a member of the HSBC Group will be kept confidential but we or a member of the HSBC Group may provide data to the following parties or any of them (whether within or outside Indonesia) for the purposes set out in paragraph (d) above:

  1. any agents, contractors, sub-contractors or associates of the HSBC Group (including their employees, officers, agents, contractors, service providers and professional advisers);
  2. any third party service providers who provide services to us or any member of the HSBC Group in connection with the operation or maintenance of our business (including their employees and officers);
  3. any Authorities;
  4. any persons under a duty of confidentiality to us or a member of the HSBC Group which have undertaken to keep such data confidential;
  5. the drawee bank providing a copy of a paid cheque (which may contain data about the payee) to the drawer;
  6. any persons acting on your behalf whose data are provided, payment recipients, beneficiaries, account nominees, intermediary, correspondent and agent banks, clearing houses, clearing or settlement systems, market counterparties, upstream withholding agents, swap or trade repositories, stock exchanges, companies in which you have an interest in securities (where such securities are held by us or any member of the HSBC Group) or any persons making any payment into a customer’s account;
  7. credit reference agencies (including the operator of any centralized database used by credit reference agencies), and, in the event of default, to debt collection agencies;
  8. any persons to whom we are or any member of the HSBC Group is under an obligation or required or expected to make disclosure for the purposes set out in, or in connection with, paragraph d.10, d.11 or d.12 above;
  9. any actual or proposed assignee(s) of ours or participant(s) or sub-participant(s) or transferee(s) of our rights in respect of you;
  10. any persons giving or proposing to give a guarantee or security to guarantee or secure your obligations to us; and
    1. any member of the HSBC Group;
    2. third party financial institutions, insurers, credit card companies, securities and investment services providers;
    3. third party reward, loyalty, co-branding and privileges programme providers;
    4. co-branding partners of ours or any member of the HSBC Group (the names of such co-branding partners will be provided during the application process for the relevant products and services, as the case may be);
    5. charitable or non-profit making organisations and
    6. external service providers that we or any member of the HSBC Group engage(s) for the purposes set out in paragraph d.9 above.

Transferring overseas

f. Your data and information and data and information relating to individuals connected to your business may be transferred to and stored in locations outside Indonesia, including countries that may not have the same level of protection for personal information. When we do this, we’ll make sure it has an appropriate level of protection and that the transfer is lawful. We may need to transfer information in this way to carry out our contract with you, to fulfil a legal obligation, to protect the public interest and/or for your or our legitimate interests. In some countries, the law may compel us to share certain information (for example, with tax authorities). Even in these cases, we’ll only share information with people who have the right to see it and we will only do it in line with the prevailing laws and regulations.

How long we’ll keep your data and information

g. We’ll keep personal data and information in line with our data retention policy as well prevailing laws and regulations. This enables us to comply with legal and regulatory requirements.

We may need to retain your personal data and information for longer period where we need the information to comply with regulatory or legal requirements or where we may need it for our legitimate purposes (for example, to help us respond to queries or complaints, fighting fraud and financial crime, responding to requests from regulators or to manage your account and deal with any disputes or concerns that may arise).

If we don’t need to retain data and information for certain period of time, we may destroy, delete or anonymise it more promptly.

Where you receive products and services from third parties (for example, insurance) to whom HSBC with your consent has introduced you, those third parties may keep your data and information, and data and information relating to individuals connected to your business, in line with additional terms and conditions that apply to their product and services.

Use of Data in Direct Marketing

h. Where you are a customer, we may use your data in direct marketing activities. For such purpose, we will seek your consent in advance and in writing. Please note that:

  1. your name, contact details, products and other service portfolio information, transaction pattern and behavior, financial background and demographic data held by us from time to time may be used by us in direct marketing;
  2. the following classes of products, services and subjects may be marketed:
    1. financial, insurance, credit card, banking and related products and services;
    2. reward, loyalty, co-branding or privileges programmes and related products and services;
    3. products and services offered by our co-branding partners (the names of such co-branding partners will be provided during the application for the relevant products and services, as the case may be); and
    4. donations and contributions for charitable and/or non-profit making purposes;

  3. the above products, services and subjects may be provided by or (in the case of donations and contributions) solicited by us and/or:
    1. any member of the HSBC Group;
    2. third party financial institutions, insurers, credit card companies, securities and investment services providers;
    3. third party reward, loyalty, co-branding or privileges programme providers;
    4. co-branding partners of ours or any member of the HSBC Group (the names of such co-branding partners will be provided during the application of the relevant products and services, as the case may be); and
    5. charitable or non-profit making organisations;

  4. in addition to marketing the above products, services and subjects ourselves, we may provide the data described in paragraph h.1 above to all or any of the persons described in paragraph h.3 above for use by them in marketing those products, services and subjects, and we require your written consent for such purpose, which consent will be requested in advance separately and in writing by us.

If you do not wish us to continue using or providing to other persons your data for use in direct marketing as described above, you may withdraw your consent by notifying us as described in this Notice.

Transfer of Data to Third Party Service Providers Using Bank Application Programming Interfaces (API)

i. We may, in accordance with your instructions to us or third-party service providers engaged by you, transfer your data to third party service providers using our API for the purposes notified to you by us or third-party service providers and/or as consented to by you.

Provision of Another Person’s Data

j. Before you (or anyone on your behalf) provides data and information about an individual connected to your business to us, or a member of the HSBC Group, you must make sure that you have a legitimate interest, lawful purpose or the agreement of the relevant individual. Your action in sharing such data and information would be deem as your confirmation on the existence of the same. You must also make sure they’ve been provided with this Notice, which explains the way in which their information will be processed and their rights in relation to their data and information for such purpose.

Rights on Personal Data

k. Any individual has the right:

  1. to check whether we holds data about them and to obtain information on the clarity on the identity, basis of the legitimate interest, purpose of the data processing as well as our accountability with respect to such data;
  2. of access to and to obtain copies of data on him/herself in accordance with the prevailing laws and regulations;
  3. to require HSBC to complete, update and/or correct any error or inaccuracy to any data on his/herself;
  4. to ascertain HSBC’s policies and practices in relation to data and to be informed of the kind of personal data held by HSBC;
  5. to end the processing of data on his/herself, to delete and/or destroy such data in accordance with the prevailing laws and regulations, as well as to withdraw his/her consent to the processing of such data;
  6. to objects to any decision-making process based solely on automated processing, including profilling, that causes legal implication or significantly impacting the individual;
  7. to delay or limit the processing of his/her data proportionally in accordance with the purpose of processing of such data;
  8. to obtain and/or use data on his/herself in such a form that allign with the structure and/or format commonly used or otherwise readable by an electronic system, and to use and send such data to other data controllers, to the extent that the system use can communicate securely with each other in accordance with data privacy principles set out in the relevant laws and regulations;
  9. in relation to consumer credit, to request to be informed which items of data are routinely disclosed to credit reference agencies or debt collection agencies and be provided with further information to enable the making of an access and correction request to the relevant credit reference agency or debt collection agency.

Nothing in this Notice shall limit your rights upon your personal data and information under the applicable laws and regulations of Indonesia.

Exercising Data Privacy Rights

HSBC honors and will always honor each and all rights granted to you as personal data subject putsuant to the prevailing laws and regulations on personal data privacy in Indonesia.

Request on Data Privacy Right

Any request with respect to the implementation of data subject rights should be made in writing by submitting this completed form to us via registered mail, duly signed by our customer’s authorised representative(s) then registered in HSBC’s system.

In certain cases, there are certain rights of individual which if implemented may limit HSBC’s ability in providing certain or otherwise all banking services to the relevant customers, for instance in the case of data processing consent withdrawal, request to end processing, for deletion or destruction of the relevant data. This is due to HSBC’s need to be able to process your information and data, including those of relevant individuals connected to your business, to meet our compliance obligations, to comply with laws and regulations that HSBC and/or HSBC Group companies are subject to and to share with our regulators and other regulators and authorities. This may include using information to help detect or prevent crime (including terrorism financing, money laundering and other financial crimes). We’ll only do this on the basis that it’s needed to comply with a legal obligation or it’s in our legitimate interests and that of others or to prevent or detect unlawful acts.

This Notice is made in two languages, i.e Bahasa Indonesia text and English text. In the event of inconsistency between two texts, the Bahasa Indonesia text will prevail

This Notice may be updated from time to time, and you’ll always be able to find the most recent version on this site.

Last update: AUGUST 2024

PT Bank HSBC Indonesia is licensed and regulated by the Indonesian Financial Services Authority in doing its business in Indonesia. PT Bank HSBC Indonesia is an LPS guarantee participant.

Contact us

Enquiries and feedback

1500237

or

+62 21 25514777

(from overseas)

GPN Logo