General Privacy Policy for Nobu Bank Services

Effective as per January 1st 2024

PT Bank Nationalnobu Tbk "Nobu Bank" is fully aware that personal information is our Customers' most important asset.

For this reason, Nobu Bank respects the confidentiality and protection of your personal data information in connection with the use of every Nobu Bank banking product and/or service. Your security, comfort and privacy is our top priority.

Nobu Bank implements policies and best practices in protecting and maintaining the confidentiality and security of your personal data in accordance with the Personal Data Protection Regulations, for data processing related to the use of Nobu Bank banking products and/or services ("Privacy Policy").

Nobu Bank always improves services to customers and protects the privacy and security of your personal information.

I. Purpose and Scope of Privacy Policy

This Privacy Policy contains the policies and practices implemented by Nobu Bank in obtaining, correcting, updating, disseminating, displaying, announcing, transferring, disclosing, deleting and destroying (hereinafter referred to as "Processing") your personal data in connection with use of your product services by using Nobu Bank products and/or banking services, including:

  1. ​​​Banking services from Nobu Bank include savings, loans and other banking services, including but not limited to Internet banking, superapp and other Nobu Bank banking services.
  2. Websites, features, applications, social media or other forms of communication media provided or used by Nobu Bank (all hereinafter referred to as "Services")

Furthermore, this Privacy Policy applies to all owners of Personal data (Data Subjects), related to the use of Nobu Bank products and/or banking services. (all of which are then referred to as "You").

II. Purpose of Processing Personal Data

In processing your personal data, Nobu Bank has the following objectives:

  1. To implement the Know Your Customer (KYC) principle and provide personalization to you regarding the use of the Services provided by Nobu Bank;
  2. To carry out the mandate of statutory regulations;
  3. To carry out problem solving related to access to the Service (troubleshoot);
  4. For marketing needs of the services and products offered by Nobu Bank, this includes sending promotions, new products, news, surveys, updates regarding services;
  5. To evaluate and update Nobu Bank Service features from time to time;
  6. For the purposes of processing Personal Data to generate your profile data;
  7. For the purposes of loyalty programs for you such as gifts, raffles, and others; and
  8. To offer advertising/promotions or offers from other parties who collaborate with Nobu Bank.

III. Personal Data Obtained and Collected by Nobu Bank

Nobu Bank obtains and collects information that identifies and/or can be identified individually or in combination with other information either directly or indirectly through electronic and/or non-electronic systems related to that information which in this case is limited to the Service ("Personal Data").

Your Personal Data collected by Nobu Bank may be provided by you directly or from third parties (such as when you register or use the Service, when you contact Nobu Call customer service). Nobu Bank will collect your Personal Data in various forms for purposes, including those permitted by applicable laws and regulations in the Republic of Indonesia. Your Personal Data collected in providing this Service is:

  1. Personal Data required by Nobu Bank to provide Services includes Personal Data of a general and specific nature, as follows:

General Data:

  1. Full Name.;
  2. Address;
  3. Place and date of birth;
  4. Gender;
  5. Nationality;
  6. Birth Mother's Maiden Name;
  7. Religion;
  8. Professions;
  9. Education;
  10. Position;
  11. Identification Number / Pasport / Child Parent Card / Student Card;
  12. Handpone Number;
  13. Email Address;
  14. Office/Home Phone Number; and/ator
  15. Personal Data combined to identify an individual.

Specific Data:

  1. Biometric data that allows unique identification of individuals but is not limited to facial images, fingerprints, speaker recordings;
  2. Personal financial data, but not limited to such as Income and Taxpayer Number; and/or;
  3. Other data is in accordance with the provisions of applicable laws and regulations.

In addition, as long as other information, including personal profiles and/or identification, is associated or incorporated into Personal Data, then that information is also Personal Data. You have the option to provide additional Personal Data to Nobu Bank for account personalization needs beyond those mentioned above.

1. Browsing data is information collected when you use the Services provided by Nobu Bank. Information relating to your Personal Data includes but is not limited to:

  • Search data, browsing history (including recorded dates and times);
  • Your associations or preferences collected from your use of the Services;
  • Photos, voices, contacts, call lists or other interactions within the Service that you are permitted to access via the device you own. Nobu Bank never scans or takes photos in albums and/or cameras on your device.

2. Personal Data created and obtained from the use of Nobu Bank's services, including but not limited to:

  • Technical processed data, such as mobile positioning, location assessment, and advanced profiling;
  • Information about data obtained from the activities of using banking services that you access, such as bill payments and your profiling and segmentation;

3. Personal Data from the Nobu Bank Business Group and/or other third parties who participate in partnership with Nobu Bank or enter into collaboration with Nobu Bank.

IV. Display, Announcement, Transfer, Dissemination and Disclosure of Personal Data

Nobu Bank will not sell, exchange, display, publish, transfer, distribute, and/or disclose any Personal Data and information relating to customers, visitors, or use of Nobu Bank Services.

You are responsible for maintaining the confidentiality of your Personal Data details and must always maintain and be responsible for the security of the device you use to access Nobu Bank Services.

The Customer hereby acknowledges, and if required by applicable Personal Data Protection regulations, expressly agrees that Personal Data obtained and collected by Nobu Bank together with relevant transaction-related information, may be disclosed to authorized government agencies, or other authorized parties based on law or cooperation agreement, in terms of:

  1. For applicable legal purposes and/or to respond to ongoing legal processes;
  2. To protect the safety of Nobu Bank, your safety or the safety of others or for the legitimate interests of the context:
      • National security;
      • Law enforcement process;
      • State administration;
      • Interest in monitoring the financial services sector, monetary, payment systems and financial system stability;
      • Aggregate data whose processing is intended for statistical purposes and scientific research in the context of state administration; and/or
      • A state of emergency that has been declared by the Government.
  1. For the purposes of internal audits and/or digital forensics regarding criminal acts or violations of regulations or policies within Nobu Bank and Affiliated Companies;
  2. If necessary in connection with legal proceedings filed against Nobu Bank, its officers, employees, affiliates or related vendors;
  3. To determine, implement, protect, defend and enforce Nobu Bank's legal rights;
  4. In the context of processing personal data with Nobu Bank affiliated companies, Nobu Bank will only provide it in good faith in summary form on the basis of legitimate interests in the eyes of the law. In the event that Nobu Bank carries out Personal Data Processing that reveals your personal profile, Nobu Bank will make its best efforts to protect the privacy of your Personal Data, which is carried out after signing a confidentiality agreement, or additional agreement by providing notification to you before your Personal Data is disclosed to affiliates of Nobu Bank and subject to the Privacy Policy. You are disclosed to affiliates of Nobu Bank and subject to the Privacy Policy and applicable laws and regulations, so as to ensure the confidentiality of your Personal Data; or;

To disclose your Personal Data to other parties, in order to ensure that Nobu Bank can provide services to you and assist the Indonesian Government and its supporting institutions in carrying out State functions.

This disclosure is carried out by considering security aspects so as to ensure that during the disclosure process no data is misused.

V. Storage of Personal Data

Nobu Bank is committed to storing your Personal Data with the best possible protection for as long as necessary to provide this Service. Some of your Personal Data may also be managed, processed and stored by third parties who collaborate with Nobu Bank both in the territory of Indonesia and outside the territory of the Republic of Indonesia in order to maintain the performance of the Service while complying with obligations regarding access and effective supervision in accordance with applicable law.

Nobu Bank will retain Personal Data as stated above as long as this is necessary to achieve the purpose for which the Personal Data was collected, while you are still using the Service, or as long as such storage is required or permitted in accordance with Nobu Bank's data retention policy and applicable laws and regulations. applies in the Republic of Indonesia.

Nobu Bank can transfer Personal Data outside the Territory of the Republic of Indonesia as long as this is necessary for the implementation of Banking Services to customers (for example: remittance services, issuance of foreign trade financing instruments, etc.).

Nobu Bank will cease to store your Personal Data, or eliminate the means by which your Personal Data may be associated with you, as soon as it is reasonable to assume that the purpose for which the Personal Data was collected is no longer fulfilled by the retention of the relevant Personal Data and storage is no longer necessary for legal, and business purposes.

VI. Access to Your Personal Data

Nobu Bank is committed to fulfilling your right to access your Personal Data collected and processed by Nobu Bank. In fulfilling your request for access to your personal data, Nobu Bank may refuse your request if Nobu Bank finds that the request for your Personal Data meets one or more of the following conditions;

  1. Endangers the security or physical health or mental health of the Personal Data Owner and/or other people;
  2. Impact on the disclosure of other people's Personal Data; and/or;
  3. Contrary to national defense and security interests.

For further information regarding requests to access your personal data, you can contact the communication channels available under this Privacy Policy.

VII. Correction and Update of Your Personal Data

In the event that you find errors displayed regarding your personal data due to inaccuracies or updating of your Personal Data is required, then you can ask Nobu Bank to correct, complete and/or update your Personal Data which is under the management of Nobu Bank, by contacting the line communications available under this Privacy Policy. In the event that there are inaccuracies in providing personal data from Data Subjects, Nobu Bank has the right to terminate services and/or transactions based on the Bank's knowledge and consideration.

We urge you to play an active role in ensuring the accuracy and updating of your Personal Data from time to time.

VIII. Removal and Destruction of Personal Data

In accordance with applicable laws and regulations or Nobu Bank's data retention policy or at your request/request, Nobu Bank can delete and/or destroy your Personal Data from the system (right to erase) so that the data no longer identifies you, except in matter:

  1. If it is necessary to store Personal Data to fulfill legal obligations, future evidentiary needs, tax, audit and accounting, Nobu Bank will submit the Personal Data required as long as you use Nobu Bank's services or according to the time period required by applicable laws and regulations. valid; and/or
  2. Personal Data in Personal Data still has a retention period based on applicable laws and regulations.

Regarding the need to destroy your personal data from the system (right to erase), a written request is required from you to Nobu Bank Head Office so that we can destroy Personal Data in Nobu Bank's system.

IX. Personal data security

The confidentiality of your Personal Data is the most important thing for Nobu Bank. Nobu Bank is committed to making its best efforts to protect and secure your Personal Data from access to collection, processing, analysis, storage, disclosure, correction and deletion by unauthorized parties.

In the event of illegal access and activities regarding the confidentiality of your Personal Information which are beyond Nobu Bank's control, Nobu Bank will immediately notify you at the first opportunity so that you can reduce the risks arising from this.

You are responsible for maintaining the confidentiality of your detailed Personal Data, including information regarding username, password, email and OTP to anyone and for always maintaining and being responsible for the security of the device you use.

X. Acknowledgment and Consent

This Privacy Policy may be changed and/or updated from time to time. Nobu Bank advises you to always read carefully and check this page from time to time for any changes it may cause.

You can withdraw your consent to any or all collection, use, disclosure of your Personal Data at any time by providing reasonable written notice to the contact listed below.

Depending on the circumstances and nature of the consent you withdraw, you must understand and acknowledge that Nobu Bank has the authority to fulfill or not fulfill the request to withdraw consent, then you will no longer be able to use the Service. Withdrawal of your consent may result in termination of your account or your contractual relationship with the relevant Nobu Bank, where all rights and obligations of each party are still fully protected.

XI. Service Settings

You can choose not to receive marketing services, advertising or other activities related to the processing of Personal Data above by contacting Nobu Bank via the contact details provided at the bottom of this notice or through other mechanisms provided by each of our Services. Please note, if you choose not to receive one Service, Nobu Bank still has the right to send you messages regarding Nobu Bank services, for other Services that you use.

XII. Language

This Privacy Policy is prepared and published in English and Indonesian. You may find a different language for this privacy policy when you change the language settings on the Nobu Bank website or application. If there is a discrepancy between these two languages, the Indonesian version shall prevail.

XIII. Contact Us

If you have any questions about this Privacy Policy, please contact our customer service via the following contact information:

  • Nobu Call: 1500 278
  • Email: nobucall@nobubank.com
  • FB Messenger: Nobu Bank
  • Instagram : nobubank
  • Whatsapp : 0811 8512 728

Security Policy

The following are the policies and practices carried out by Nobu Bank to show its commitment to safeguarding and maintaining your security when you visit the site and web.nobubank.com.

1. Security System

Nobu Bank uses 2 (two) layers of security system to protect your access at https://www.nobubank.com, namely:

  1. SSL is a security technology that 'scrambles' the path between computers so that it cannot be read by other parties.
  2. Due to the large variety of internet browsers that exist, it is difficult to provide services that adhere to the security of each browser. Currently Nobu Bank only provides the facility https:// www.nobubank.com which is more suitable for access using Microsoft Internet Explorer version 10 and above, Mozilla Firefox version 2.0.0 and above, Google Chrome or Safari version 4.0.3 and above.

2. Website Communication Protection.web.nobubank.com

Nobu Bank uses 256 bit Secure Socket Layer (SSL) encryption technology to protect communications between your computer and the Nobu Bank server as long as you access https://www.nobubank.com

To ensure communication protection while you access https://www.nobubank.com, you can do the following:

  • Check SSL certificates regularly to ensure that you are receiving a valid SSL certificate that has been registered for https://www. nobubank.com
  • If you receive a message explaining that the certificate is invalid, please do not continue accessing https://www. nobubank.com.
  • Make sure that you have typed the correct address i.e. https://www. nobubank.com
  • Make sure that your browser has a padlock/key image that identifies what you are accessing as encrypted using SSL. If you exchange personal information.
  • You should not access networks that are not secure.

3. Nobu Bank Site

On the Nobu Bank site, Nobu Bank provides URL links to other sites that are not controlled by Nobu Bank. Nobu Bank is not responsible for the content and security of these sites. If you access such sites, please check their privacy policies and safeguards.

In the event that you access the site via a URL link from another site, ensure that the address you are accessing is correct, namely https://www.nobubank.com

Nobu Bank can change this privacy policy and security information at any time to keep up with the latest situations and technology. You can always review Nobu Bank's latest information and privacy policy at https://www.nobubank.com.​