DA

Coralbound Privacy Policy

Date Published: September 29, 2026

Introduction

Language Precedence: These Terms of Use are originally written in English. While translations into other languages may be provided for convenience, the English version is the only legally binding version and shall prevail in the event of any conflict, discrepancy, or difference in interpretation between the English version and any translated version.

PT Tur Tak Terkalahkan ("Coralbound", "we", "us") domiciled at Jl. Sunset Road No 89, Pertokoan Sunset Indah II, Kav 3, No 3B, 80361 Kuta, Bali, Indonesia, operates a liveaboard diving booking platform through the website https://coralbound.com (the "Platform"). The service you book on the Platform is a liveaboard trip. During booking you may ask us for help with related travel, such as a hotel before or after the trip, a domestic flight, or extending the holiday. Those are assistance requests. We do not sell hotel rooms, airline tickets, or tours as bookable inventory, and there is no Coralbound mobile application.

We are committed to respecting and protecting the privacy of our customers, including participants in diving liveaboard experiences, individuals making inquiries, and visitors to our website at coralbound.com.

This Privacy Policy describes how we handle and protect your personal data—any information capable of identifying you as an individual—in our role as data controller. It applies to personal data provided to or obtained by us during interactions such as bookings, inquiries, or website use.

Our diving operator partners, accommodation providers, and destination management company (DMC) partners may act as co-data controllers or processors on our behalf, particularly in booking and service delivery processes.

For additional details on our general terms, please refer to the for the Coralbound website and booking platform.

Summary Of Collection And Use of Information

We collect and use personal data for commercial, legal, and business purposes, subject to applicable laws. This may be based on your consent, our legitimate interests, or other legal grounds. In some cases, collection is required to operate the platform or provide services.

We use your personal data to: fulfill information requests; process liveaboard bookings and any related-travel assistance you request; run the on-site message center; evaluate and improve our services; distribute safety alerts, newsletters, and diving-related materials; analyze platform performance; prevent fraud and spam; enforce our terms of service and agreements; comply with laws and reporting obligations; and accomplish other purposes you initiate.

We may use first- and third-party cookies and other tracking technologies to manage our platform, deliver services, and collect analytics. See the Cookie section below for details.

Please note that data handling may vary by interaction, and the examples provided are not exhaustive.

1. About This Policy

1.1 Who We Are

Coralbound is operated by PT Tur Tak Terkalahkan, a company incorporated in Indonesia with Business Identification Number (NIB): 2806230016874. We are headquartered at Jl. Sunset Road No 89, Pertokoan Sunset Indah II, Kav 3, No 3B, 80361 Kuta, Bali, Indonesia.

Data Controller Information:

1.2 Services Covered

This policy applies to all Coralbound services including:

  • Liveaboard diving trip bookings, including cabins, trip packages or add-ons, gifts, and voucher or gift codes
  • Optional requests for help with hotels, domestic flights, or holiday extensions
  • The website, accounts, and the on-site message center
  • Customer service and support communications

1.3 Legal Framework

We comply with:

  • European Union: General Data Protection Regulation (GDPR)
  • United Kingdom: UK General Data Protection Regulation (UK GDPR)
  • United States: California CCPA/CPRA, Virginia CDPA, Colorado CPA, Connecticut CTDPA
  • International: Canada PIPEDA, Japan APPI, Singapore PDPA, Australia Privacy Act

2. Information We Collect

2.1 Personal Information You Provide

Booking and Account Information:

To complete bookings and comply with Operator/Service Provider requirements, Indonesian tourism regulations, and international travel requirements, we collect extensive personal information including:

Personal Identity Information:

  • Full name, date of birth, gender, and nationality
  • Profile picture (optional)
  • Passport picture (required for operator verification)
  • Passport information and details

Contact Information:

  • Email address and phone number
  • Mailing address, city, postal code, and country
  • Emergency contact name and phone number

Health and Safety Information:

  • Medical fitness declarations (as required for diving activities)
  • Medical issues and health conditions
  • Allergies (food and medication)
  • Dietary restrictions and special meal requirements
  • Accessibility needs

Diving Information:

  • Diving certification details (certification type and level)
  • Number of logged dives
  • Diving experience history

Insurance Information:

  • Travel insurance provider and policy details
  • Insurance coverage information

Travel Preferences:

  • Special requests and preferences
  • Accommodation requirements

Data Transmission Security: All data transmitted between your device and Coralbound is protected using industry-standard transport encryption (for example, TLS/HTTPS) to help prevent interception during transfer. This secures communications while they are in transit; any data stored or processed by Coralbound or our third-party service providers is handled under their respective security practices and policies.

Payment Information:

  • The payment method you choose on the book page: credit or debit card, or bank transfer
  • Amounts, currency, payment status, and booking references we record
  • Card numbers are entered on the payment page linked from your booking. We do not store full card numbers on our servers
  • For bank transfer, we show our Permata Bank account in the name of PT Tur Tak Terkalahkan in your booking payment instructions. We record that you chose this method and the booking reference

Communication Data:

  • Messages you send in the on-site message center, including the page you opened messages from
  • Files you attach to a message (images and PDFs). These are stored in private file storage and are not published on the website
  • Browser push subscription data if you allow message notifications on your device
  • Customer service interactions
  • Review and feedback submissions
  • Marketing communication preferences
  • Social media interactions with our accounts

2.2 Information Collected Automatically

2.3 Site Analytics Tools

To understand how the website is used and to measure advertising, we use Google Tag Manager, Google Analytics 4, Google Ads, and Meta Pixel (ID: 25303170292707457). Google Analytics collects usage data such as page views, session duration, interactions (for example clicks and scrolls), device information, and general location derived from IP addresses. Google Tag Manager loads and manages those tags. Google measurement requests on coralbound.com are routed through our first-party path at coralbound.com/nautilus (Cloudflare Google Tag Gateway). Meta Pixel is described in Section 5.5.

Analytics and advertising tags run only after you accept them in the cookie banner. You can reject them, or change that choice later in Cookie Preferences. You can also use your browser, the Google Analytics Opt-Out Browser Add-on (https://tools.google.com/dlpage/gaoptout), Google ad settings, and Meta ad settings, or contact [email protected]. For how Google processes data, see https://policies.google.com/privacy.

Technical Data:

  • IP address, device identifiers, browser type and version
  • Operating system, screen resolution, time zone settings
  • Website navigation patterns and click-through data
  • Cookie and tracking technology data (see Section 6)

Location Data:

  • General location derived from IP address for currency and language preferences
  • Location-based service preferences

Usage Analytics:

  • Pages visited, time spent on site, bounce rates
  • Search queries and booking abandonment data
  • Feature usage patterns and performance metrics
  • Platform interaction data for service improvement

2.4 Authentication and Account Management

For secure user authentication and account management, we partner with Clerk, a third-party service that handles all aspects of user login, registration, and session management on our platform. When you create an account or log in (including via social media platforms), Clerk securely stores and processes your account data, such as email addresses, usernames, and authentication tokens, while we do not retain passwords, social media connection details, or any sensitive authentication credentials on our servers. This data minimization approach ensures that Coralbound only accesses the minimum information necessary for service delivery, such as confirming your identity for bookings or personalized recommendations. Clerk acts as a data processor on our behalf, complying with GDPR and other applicable laws through measures like encryption, secure data centers, and strict access controls. Processing is based on contract performance (GDPR Article 6(1)(b)) for enabling access to our services, with data retained only as long as your account is active or as required by law. If you delete your account or request data erasure, we will coordinate with Clerk to fulfill your request; you can manage your authentication preferences directly through Clerk's settings or contact us at [email protected] for assistance.

2.5 Error Monitoring Tools

To maintain the reliability and security of our platform, we use Sentry.io, a third-party error monitoring and performance management tool, which helps us detect, diagnose, and resolve technical issues in real-time. Sentry collects anonymized or pseudonymized data related to errors and crashes, such as stack traces, browser/console logs, device information, IP addresses (which may be masked for privacy), and contextual details about user sessions (e.g., actions leading to an error during booking or navigation). This processing does not involve collecting sensitive personal data unless it's inadvertently included in error logs, in which case we promptly anonymize or delete it. As our data processor, Sentry operates with GDPR-compliant practices, including EU data hosting options, encryption, and short retention periods (typically 90 days), with processing based on our legitimate interests under GDPR Article 6(1)(f) for platform improvement and fraud prevention. We do not use Sentry for marketing or profiling; users can limit data sharing by opting out of non-essential tracking via browser settings, though error monitoring is essential for service functionality. For questions or to exercise data rights (e.g., access to any captured data), contact us at [email protected].

2.6 Third-Party Information

  • Social media profile data (when you connect accounts)
  • Partner-provided information (dive operators, hotels, DMCs)
  • Public business directories and travel databases
  • Identity verification services (where required by applicable law)

2.7 Service Providers Who Process Data For Us

We use the following providers to run the Platform. They process personal data only for the purposes described in this policy:

  • Clerk — account login, registration, and sessions (see Section 2.4)
  • Cloudflare — website delivery, security, bot checks (Turnstile) on public forms and anonymous messages, private file storage (R2) for guest photos, passport photos, and message attachments, and the AI gateway used for the features in Section 4.2
  • Railway — application hosting and the MongoDB database that stores Platform records
  • SendGrid — transactional email (booking messages, account messages, and similar mail)
  • Sentry — error monitoring (see Section 2.5)
  • Google — Tag Manager, Analytics, Ads, and Maps cookies described in this policy
  • Meta — Meta Pixel, as an independent controller for advertising data (see Section 5.5)
  • OpenRouter, and the model providers it routes to (including Google and Anthropic) — the artificial intelligence features in Section 4.2. Prompts are sent through the Cloudflare AI gateway. We do not use guest data to train our own models

Card payments are completed on a payment page we link from the booking. That provider receives the card details. We receive payment status, not the full card number.

2.8 Special Considerations Regarding Children

Age Restrictions: You must be at least 13 years of age (16 years of age in the EU) to register for a Coralbound account. Children under 18 years of age require parental consent for certain diving activities and may need additional parental approval for booking services.

Parental Consent Requirements: In consideration for use of Coralbound's services, parents/guardians agree to provide true and accurate information in registration forms for their children and to update registration information as necessary to keep it accurate and current. If false, inaccurate, not current or incomplete information is provided, or if Coralbound, in its sole discretion, determines that such information may be false, inaccurate, not current or incomplete, Coralbound has the right to suspend or terminate the account and refuse present or future use of Coralbound's services.

3. Emergency Data Sharing

3.1 Medical Emergencies

Immediate Medical Response: When you experience a medical emergency during a Coralbound-booked service, we may need to share your personal information immediately to protect your vital interests:

  • Emergency Contact Notification: Immediate contact of your designated emergency contacts using information provided during booking
  • Medical Information Sharing: Sharing relevant medical fitness declarations and health information with local medical facilities, dive emergency services (such as DAN - Divers Alert Network), and emergency responders
  • Hospital Coordination: Providing identification, insurance information, and medical history to receiving medical facilities
  • Evacuation Services: Coordinating with medical evacuation services and sharing necessary personal and medical information

Medical Information Shared:

  • Full name, nationality, and identification information
  • Emergency contact details and relationships
  • Medical fitness declarations and known health conditions
  • Diving certification level and experience (relevant for diving-related medical emergencies)
  • Insurance information and policy details
  • Medication allergies and current medications (if provided)
  • Blood type and other critical medical information (if provided)

Legal Basis: Vital interests protection under GDPR Article 6(1)(d) and legitimate interests for emergency response

3.2 Safety and Security Incidents

Maritime and Diving Emergencies:

  • Coast Guard and Maritime Authorities: Sharing passenger manifests, diving experience levels, and emergency contact information with Indonesian Coast Guard, harbor authorities, and international maritime rescue coordination centers
  • Dive Emergency Services: Immediate sharing with DAN (Divers Alert Network), local dive emergency response teams, and hyperbaric chamber facilities
  • Search and Rescue Operations: Providing location data, personal identification, and emergency contacts to search and rescue authorities
  • Vessel Emergency Response: Coordinating with vessel operators and emergency services for evacuation or rescue operations

Natural Disasters and Crisis Situations:

  • Government Authorities: Sharing guest information with local emergency management authorities during natural disasters (earthquakes, tsunamis, volcanic eruptions)
  • Embassy and Consular Services: Providing citizen information to relevant embassies and consulates for citizen welfare and evacuation assistance
  • Family Notification: Immediate notification of emergency contacts and family members about safety status and location
  • Evacuation Coordination: Sharing travel documents and identification information with evacuation services and transportation authorities

3.3 Law Enforcement and Security

Legal Requirements:

  • Criminal Investigations: Cooperation with law enforcement agencies when required by valid legal process or court orders
  • Immigration and Border Control: Sharing passenger information with immigration authorities as required by law
  • Anti-Terrorism and National Security: Compliance with security screening requirements and watch list checking
  • Customs and Border Protection: Providing travel information to customs authorities when legally required

Fraud and Safety Protection:

  • Financial Crime Prevention: Sharing transaction information with financial crime prevention agencies and payment processors
  • Safety Threat Response: Immediate sharing with authorities when credible safety threats are identified
  • Missing Persons: Cooperation with law enforcement in missing person investigations
  • Child Protection: Mandatory reporting to appropriate authorities when child safety concerns are identified

4. How We Use Your Information

4.1 Primary Processing Purposes

Service Delivery (Legal Basis: Contract Performance):

  • Processing and confirming your liveaboard bookings, including cabins, packages, gifts, and codes
  • Passing booking details to the liveaboard operator, and passing any related-travel request you made
  • Recording the payment method you chose and, for cards, sending you a payment link. Card details are collected by the payment provider, not stored by us
  • Providing customer support and trip assistance
  • Sending booking confirmations, vouchers, and travel documentation

Legal Compliance (Legal Basis: Legal Obligation):

  • Safety and emergency response coordination with relevant authorities
  • Compliance with travel and tourism regulations in service destinations

Legitimate Business Interests (Legal Basis: Article 6(1)(f) GDPR):

  • Website functionality and security improvements
  • Fraud detection and prevention systems
  • Business analytics and performance optimization for service delivery
  • Basic service personalization and safety-based recommendations
  • Platform development and feature enhancement for user experience
  • Customer service quality improvement and training
  • Safety monitoring and emergency response capability
  • Payment processing and transaction security

4.2 Automated Decision-Making and Artificial Intelligence

We use automated systems and artificial intelligence in the ways below. We do not run dynamic pricing, and we do not make solely automated decisions that produce legal effects or similarly significant effects for you. You can object to automated processing by contacting [email protected].

Message Center replies. Staff can leave AI off, ask it to draft a reply, send one automatic first reply, or let it answer later messages. Replies are shown as Coralbound Support. An AI reply is marked with a small bot icon next to the time. In the fullest mode the model can look up published catalog facts (boats, trips, cabins, destinations, deals, FAQs, and the trip's booking and cancellation text). It is not given other people's bookings, guests, files, payments, or message threads. A human can turn AI off for a conversation.

Translation. We use AI to translate site content, legal pages, and message text into other languages. English remains the binding version of this policy.

Internal trip preparation. We use AI to read operator spreadsheets and files when preparing trip listings. That work uses operator material, not your account profile.

Calls go through Cloudflare AI Gateway to OpenRouter and then to the model provider (Google or Anthropic, depending on the feature). We do not sell message contents to those providers for their advertising.

5. Cookies and Tracking Technologies

5.1 Consent Management Tool

We show a cookie banner on the website. It stores your choice in a first-party cookie named cc_coralbound for about 6 months. Categories are strictly necessary, analytics, and advertising. You can reopen Cookie Preferences and change the choice. Necessary cookies (sign-in, the affiliate referral cookie, the currency rate cache, Cloudflare security, and this preference cookie) are set so the site can function. Analytics and advertising cookies are set only if you accept them.

5.1 Cookie Categories

Strictly Necessary Cookies:

  • Session management and user authentication
  • Security and fraud prevention
  • Basic website functionality and navigation
  • Booking process management
  • Affiliate referral tracking (coralbound_referral - 30 days)

Preference Cookies:

  • Language and currency preferences
  • Personalized content delivery
  • Location-based service enhancements
  • Social media integration features

Statistics Cookies:

  • Error tracking and performance monitoring
  • A/B testing for feature improvements
  • User experience research and heat mapping

Marketing Cookies:

  • Retargeting and remarketing campaigns through various third-party advertising platforms
  • Conversion tracking and attribution across advertising networks
  • Interest-based advertising and audience segmentation
  • Cross-platform marketing coordination and customer journey tracking
  • Custom audience creation and lookalike audience development

5.2 Cookie Management

  • Granular Controls: Accept, reject, or change analytics and advertising cookies in Cookie Preferences
  • Browser Settings: Configure cookie acceptance in your browser settings
  • Regular Review: Update your preferences anytime through Cookie Consent Settings

5.3 Third-Party Cookies and Remarketing

We work with various third-party advertising partners for remarketing and personalized advertising campaigns. These may include but are not limited to Google, Meta, X, and other advertising networks and platforms.

Types of Remarketing Activities:

  • Website visitor remarketing and conversion tracking
  • Custom audience creation based on customer data
  • Lookalike audience development for similar customer targeting
  • Cross-platform advertising coordination and optimization
  • Interest-based advertising based on user behavior and preferences

5.4 Advertising and Remarketing

We use Google Ads and Meta Pixel (Facebook/Instagram) to promote liveaboard trips and measure advertising. We do not currently run X, TikTok, or LinkedIn advertising pixels. These platforms use cookies for conversion tracking, remarketing, and audience building after you accept advertising cookies. If you visit the Platform, you may see Coralbound advertisements elsewhere based on those cookies. You can reject them in Cookie Preferences, in Google's Ad Settings (https://adssettings.google.com), in the Meta settings in Section 5.5, or in your browser.

5.5 Meta Pixel Tracking

We use Meta Pixel (formerly Facebook Pixel) to measure advertising effectiveness, optimize ad campaigns, and build audiences for liveaboard trips. Meta Pixel is a tracking code (ID: 25303170292707457) implemented through Google Tag Manager that collects information about your interactions with our platform after you accept advertising cookies.

Information Collected by Meta Pixel:

Meta Pixel automatically collects and sends data to Meta, including:

  • Browser and device information (user agent, screen resolution, browser type)
  • Page views and button clicks on our platform
  • Standard and custom events (e.g., PageView, Purchase, InitiateCheckout, Contact)
  • Transaction data for conversions, including booking values and currency
  • IP address (which Meta may use to derive general location)
  • Referrer URL and landing page information
  • Facebook click identifier (fbclid) if you arrived via a Facebook/Instagram ad
  • Cookie identifiers (fbp, _fbc) for cross-device tracking and attribution

How Meta Pixel Data Is Used:

Meta uses this data to:

  • Measure the effectiveness of our Facebook and Instagram advertising campaigns
  • Deliver personalized advertisements to you on Facebook, Instagram, Messenger, and Audience Network
  • Create Custom Audiences of users who have visited our platform or completed specific actions
  • Build Lookalike Audiences to reach new potential customers similar to our existing users
  • Optimize ad delivery for conversions (bookings, inquiries, page views)
  • Provide us with aggregated analytics and reporting on ad performance
  • Track cross-device behavior to understand customer journeys

Events Tracked:

We track the following Meta Pixel events for advertising optimization:

  • PageView: Automatically fires on every page visit (after consent)
  • Purchase: Fires when a booking request is successfully submitted, including transaction value and currency
  • InitiateCheckout: Fires when users view the booking page
  • Contact: Fires when you start contact by WhatsApp, Facebook, Discord, the contact form, or the on-site message center

Data Sharing with Meta:

When Meta Pixel is active (after you grant advertising consent), your interaction data is transmitted to Meta's servers, which may be located in the United States and other countries outside the European Economic Area (EEA). Meta acts as an independent data controller for this data, subject to Meta's Privacy Policy (https://www.facebook.com/privacy/policy/). We do not control Meta's subsequent use of your data for their own purposes, such as improving their services or targeting you with ads from other businesses.

Legal Basis for Processing:

Processing is based on your consent for advertising cookies, which you give in the cookie banner. You can withdraw that consent in Cookie Preferences. That blocks further Meta Pixel tracking from our site.

Your Rights and Opt-Out Options:

You can control Meta Pixel tracking through several methods:

Note: Opting out will not stop Meta from showing you ads, but ads will be less relevant to your interests.

Data Retention:

Meta retains pixel event data according to their data retention policies, typically for up to 2 years depending on data type. Cookie identifiers (fbp, _fbc) are stored in your browser for 3 months to 2 years. When you withdraw consent via our Cookie Settings, these cookies are automatically cleared from your device.

International Data Transfers:

Meta Pixel data may be transferred to and processed in the United States and other countries where Meta operates. Meta relies on Standard Contractual Clauses (SCCs) and other legal mechanisms approved by the European Commission for international transfers. For more information, see Meta's Data Transfer documentation.

For Questions:

If you have questions about our use of Meta Pixel or how your data is processed, contact us at [email protected]. For questions about Meta's data practices, consult Meta's Privacy Policy or contact Meta directly.

6. Service-Specific Data Collection and Use

6.1 Liveaboard Diving Experience Participants

What information does Coralbound obtain? For participants in liveaboard diving experiences, Coralbound may obtain participant name, email address, phone number, postal address, nationality, date of birth, passport information, diving certification level and number, dive experience history, medical fitness declarations, dietary restrictions, emergency contact information, and associated dive operator/liveaboard vessel information.

How is the information used? Coralbound uses participant information to coordinate with dive operators and liveaboard vessels for booking fulfillment, send booking confirmations and travel documentation, provide customer support throughout the diving experience, distribute diving safety alerts and important operational updates, and for quality management processes including post-trip evaluation forms and related correspondence.

Marketing and Promotional Use (Requires Explicit Consent): With your separate, explicit consent, participant information may be used by Coralbound to:

  • Promote additional diving experiences and travel opportunities
  • Send newsletters and diving industry updates
  • Provide personalized recommendations based on your diving experience
  • Share information with our trusted dive operator partners for marketing purposes (separate consent required)
  • Include you in partner promotions for diving, training and dive-related products and services

Service Delivery (Legitimate Interests - No Consent Required):

  • Booking coordination and confirmation
  • Safety communications and emergency alerts
  • Customer service and support
  • Quality assurance and feedback collection
  • Fraud prevention and payment security

6.2 Related Travel Requests

What information does Coralbound obtain? If you ask for help with a hotel, a domestic flight, or extending the holiday, we use the contact and booking details you already gave us, plus the request itself.

How is the information used? We use it to discuss that request with you and, where needed, with the operator or another provider. A hotel, flight, or extension is not a separate product sold as inventory on the Platform unless your booking confirmation says otherwise.

6.3 Trip Packages On A Liveaboard Booking

Some trips ask you to choose a package or add-on for each guest (for example a diving or equipment option configured on that trip). We store the choice on the booking and share it with the operator as part of the liveaboard reservation. This is not a separate tour product.

6.4 Website Visitors

What information does Coralbound obtain? When someone visits coralbound.com, we may obtain an email address and name if you provide them, browsing behavior, search preferences, device information, a currency preference stored in your browser, and general location derived from your IP address. We do not offer a Coralbound mobile app.

Service Delivery and Functionality:

  • Website performance optimization and technical functionality
  • Basic personalization for user experience (language, currency preferences)
  • Security monitoring and fraud prevention
  • Analytics for service improvement and platform development
  • Error tracking and technical support

Marketing: With your separate consent, we may send newsletters and promotional email. You can opt out as described in the Terms of Service. Advertising and analytics cookies run only if you accept them in the banner. We do not sell visitor information. We may share aggregate statistics that do not identify you.

Email addresses you send us are used to reply. We do not share them for another company's marketing unless you have agreed or we say so in this policy.

What does Coralbound use to track information from users? Coralbound uses Google Analytics 4, Google Tag Manager, Google Ads, and Meta Pixel, as described above, and only after you accept the matching cookie category. We do not use Facebook Analytics. You can reject those cookies in the banner or use the Google Analytics Opt-Out Browser Add-on.

6.5 Customer Service and Support Interactions

What information does Coralbound obtain? Through the message center and other support contacts, Coralbound obtains contact information, message text, attachments, booking details, service inquiries, feedback, complaint details, and resolution preferences. Anonymous visitors may be asked to complete a bot check (Cloudflare Turnstile) before a message is accepted.

How is the information used? This information is used to provide customer support, including AI-assisted replies described in Section 4.2, resolve booking issues, improve service quality, and keep records for quality assurance and dispute resolution. Message files stay in private storage.

7. Limits on Coralbound's Abilities to Protect Personal Information

Your privacy is very important to Coralbound. However, due to the existing legal and technical environment, Coralbound cannot ensure that your personally identifiable information will not be disclosed to third parties in ways not described in this Privacy Policy. For example, Coralbound may be forced to disclose information to the government or third parties under certain circumstances, or third parties may unlawfully intercept or access transmissions or private communications.

Additionally, Coralbound can (and you authorize Coralbound to) disclose any information about you to private entities, law enforcement or other government officials as Coralbound, in its sole discretion, believes necessary or appropriate to address or resolve inquiries or problems, prevent fraud, or protect the safety of our customers and partners.

8. Links to Third-Party Sites

Coralbound's website may provide links to third-party websites or information as a service to users. If you use these links, you will leave the Coralbound website. Such links do not constitute or imply an endorsement, sponsorship or recommendation by Coralbound of the third party, the third-party website or the information contained therein, and Coralbound shall not be responsible or liable for your use thereof. Such use shall be subject to the terms of use and privacy policies applicable to those sites.

8. User Forums and Public Disclosure

You should be aware that whenever you publicly disclose information online through reviews, forums, or social media interactions with Coralbound, that information could be collected and used by others. Coralbound is not responsible for any action or policies of any third parties who collect information that users publicly disclose in any such forums or platforms.

9. Business Transfers and Corporate Changes

9.1 Merger, Acquisition, or Asset Sale

Data Transfer in Business Transactions: In the event that PT Tur Tak Terkalahkan undergoes a business transition such as a merger, acquisition by another company, or sale of all or a portion of its assets, your personal data may be transferred to the successor entity as part of the transaction.

Your Rights and Protections:

  • Advance notification: Minimum 30 days' notice via email and prominent website notice
  • Privacy policy continuity: The acquiring entity must honor this Privacy Policy for a minimum transition period of 90 days
  • Enhanced protections: If the new entity's privacy practices are materially less protective, you will have the right to request deletion of your personal data before the transfer, opt-out of the data transfer (where legally permissible), and receive detailed information about the new entity's privacy practices

Due Diligence Requirements: We commit to conducting appropriate due diligence to ensure the acquiring entity maintains adequate data protection standards comparable to ours, has proper legal basis for the data transfer under applicable privacy laws, implements appropriate technical and organizational security measures, and respects all existing user consent preferences and opt-out choices.

10. Contact Information and Complaints

10.1 Privacy Contact Details

Primary Contact:

  • Email: [email protected]
  • Address: PT Tur Tak Terkalahkan, Jl. Sunset Road No 89, Pertokoan Sunset Indah II, Kav 3, No 3B, 80361 Kuta, Bali, Indonesia
  • Business Hours: Monday-Friday, 9:00 AM - 6:00 PM WITA

10.2 Complaint Procedures

  1. Submit complaint through any contact method above
  2. Acknowledgment within 72 hours
  3. Investigation and response within 30 days
  4. Appeal process for unsatisfactory resolutions

10.3 Language Support and Translation Disclaimer

  • Official Language: English is the official language of this Privacy Policy
  • AI Translations: This policy may be translated into other languages using artificial intelligence or automated translation services for user convenience
  • Translation Accuracy: While we strive for accuracy, automated translations may contain errors or inaccuracies
  • Legal Precedence: In the event of any conflict, discrepancy, or difference in interpretation between the English version and any translated version of this Privacy Policy, the English version shall prevail and be considered the authoritative and legally binding document
  • Human Translation: For critical legal matters, we recommend consulting the English version or seeking professional human translation services
  • Translation Updates: Translated versions may not be immediately updated when the English version is revised. Always refer to the English version for the most current and accurate information

11. Policy Updates and Changes

11.1 Change Notification and Consent

By using Coralbound's services and website, you consent to the collection, use, and storage of your personal data by Coralbound in the manner described in this Privacy Policy. Coralbound reserves the right to make changes to this Privacy Policy from time to time.

11.2 Version Control and Historical Access

  • Previous versions of this Privacy Policy archived and available upon request
  • Effective date tracking for all modifications
  • Users may request historical versions for their records

12. Non-Agency Disclosure and Acknowledgment

As a user of Coralbound's platform and services, you are informed, understand and agree that diving operators, liveaboard vessels, hotels, resorts, and DMC partners are independent businesses that are licensed to provide services booked through Coralbound, but are not agents, employees or franchisees of Coralbound.

You are further informed, understand and agree that the business activities of these service providers are independent, and are neither owned nor operated by Coralbound. While Coralbound establishes standards for service providers on our platform and facilitates bookings, we are not responsible for, nor do we have the right to control, the day-to-day operations of these independent businesses or their staff's conduct during service delivery.

Coralbound acts as a booking platform and facilitator, connecting travelers with qualified service providers, but the actual diving, accommodation, and tour services are provided by independent third parties who maintain their own insurance, certifications, and operational standards.

This privacy policy describes Coralbound's data processing practices and your privacy rights. We process personal data in accordance with applicable privacy laws and provide transparency about our data handling practices.

Policy Owner: PT Tur Tak Terkalahkan