PT Pangan Kreasi Makmur, trading under the Francis brand (“Francis”, “we”, “us”, “our”), respects your privacy and is committed to processing personal data lawfully, proportionately, transparently, securely and responsibly under applicable law.
This Policy explains how we may collect, use, store, disclose, transfer, secure, delete and otherwise process personal data when you use www.francis.co.id, contact us, submit a form, create an account, participate in promotions, receive communications, transact with us, or otherwise interact with Francis.
1. Personal Data Controller
Where we determine the purposes and means of processing, PT Pangan Kreasi Makmur acts as the Personal Data Controller under applicable Indonesian law.
Address: Jl. Raya Cilandak KKO No.410, RT.15/RW.5, Cilandak Timur, Pasar Minggu, Kota Jakarta Selatan, DKI Jakarta 12560
Privacy contact: privacy@francis.co.id
2. Data we may process
Depending on how you interact with us, the categories of personal data we may process include:
name, email address, phone number, delivery or correspondence address;
company/organisation name, job title and business relationship information;
the content of enquiries, correspondence, complaints, claims, photos or documents you send us;
account, transaction, order, payment, voucher, loyalty-points and delivery information;
communication and marketing preferences;
technical and usage data such as IP address, browser/device type, operating system, pages visited, access times, referral source, cookie identifiers and security/log information; and
other information you choose to provide or that we lawfully obtain in the course of the relationship.
We do not ask for specific/sensitive personal data unless it is necessary for a lawful purpose. Please do not send us sensitive data that is not required.
3. Sources of personal data
We may obtain personal data directly from you; from website forms, email, phone, WhatsApp/customer-service channels or official social media; from customers, suppliers, distributors, retailers and business partners; from service providers working for us; and automatically through devices, browsers, servers, cookies and similar technologies.
4. Purposes and lawful bases
We only process personal data for lawful and relevant purposes. These may include:
responding to enquiries, requests, complaints and communications;
providing customer service, processing replacements/refunds where applicable, and carrying out quality investigations;
performing a contract or taking steps at your request before a contract;
processing transactions, payments, orders, delivery and related administration;
managing your account, vouchers and loyalty programme;
managing relationships with customers, prospects, retailers, distributors, suppliers and business partners;
providing information about Francis products and services;
operating, securing, preventing misuse of, fixing and improving our website and systems;
reasonable analytics, performance measurement, market research and business development;
sending marketing communications where we have an appropriate lawful basis;
meeting legal, regulatory, audit, tax and accounting obligations; and
establishing, exercising or defending legal rights and claims.
Our lawful bases may include valid consent, performance of a contract, legal obligation, protection of vital interests, legitimate interests after balancing against the rights of the data subject, and/or other bases permitted by law. Where processing relies on consent you may withdraw it in accordance with the law; withdrawal does not affect processing that was lawful before withdrawal.
5. Marketing communications
We may send promotions, newsletters, product information or other marketing communications where permitted by law and where an appropriate lawful basis exists — for example when you tick the marketing option while creating an account. You can unsubscribe at any time from your account settings, via an unsubscribe link (where available) or by contacting us. We may still send non-marketing communications needed for transactions, service, security, policy changes or an ongoing business relationship.
6. Cookies and similar technologies
Our website may use cookies, local storage, tags and similar technologies provided by us or third parties. The technologies used may change over time and fall into these groups:
Strictly necessary: security, authentication (your sign-in session), the shopping cart, language preference, storing your cookie choice and core site functions. Always active.
Analytics: understanding how the site is used (for example product pages viewed, searches, and visits from campaigns/QR codes) and improving performance. Active only if you allow it.
Advertising/marketing: where used, for ad measurement, remarketing or marketing relevance. Active only if you allow it.
Non-essential technologies stay off until you choose. You can accept all, reject non-essential cookies, or manage your choices, and change them at any time via the “Cookie Preferences” link at the bottom of every page.
7. Disclosure to third parties
To the extent necessary and permitted by law, we may disclose personal data to hosting/cloud/IT and database providers, communication and email providers, analytics or marketing providers, payment providers, logistics/courier providers, customer-service providers, auditors, professional advisers, related distributors/retailers/partners, group companies (if any), and government authorities, regulators, courts or law enforcement where required or permitted by law.
Parties that process personal data for us are expected to be bound by confidentiality, security and use obligations consistent with our instructions or the relevant lawful basis.
We do not sell personal data for monetary consideration.
8. Transfers outside Indonesia
Our service providers may process or store data outside Indonesia. Where personal data is transferred outside Indonesian jurisdiction, we will apply the mechanisms and safeguards required by law, including ensuring an equivalent or higher level of protection, adequate and binding safeguards, or obtaining consent where required.
9. Retention
We keep personal data only as long as necessary for the lawful purpose, to meet legal/accounting/tax obligations, and to handle disputes, security and legal claims. Actual periods vary by data category and context.
general enquiries and correspondence: while the relationship remains relevant and for a reasonable period thereafter;
account data: while the account is active and for a reasonable period after closure;
marketing data: until opt-out/withdrawal or when no longer needed, possibly keeping minimal data to honour a suppression list;
security/technical logs: as long as needed for security and investigation;
transaction, accounting and tax records: for the retention period required by law;
data connected to a dispute or investigation: potentially longer, until resolution and expiry of the applicable claim period.
We may delete, anonymise or destroy data when the purpose and retention period end, unless retention is still required or permitted by law.
10. Security
We apply reasonable and proportionate administrative, organisational and technical measures to protect personal data against unauthorised access, disclosure, alteration, loss, destruction and processing. No electronic system or transmission can be guaranteed completely risk-free.
11. Your rights
Subject to law and applicable exceptions, data subjects may have the right to obtain information about processing; access their data and processing history; correct data; withdraw consent; request cessation, restriction, deletion or destruction in certain circumstances; object to certain automated decisions; and exercise other rights granted by the Indonesian Personal Data Protection Law.
We may ask for reasonable information to verify the identity and authority of the requester. Some obligations under the Personal Data Protection Law run on a 3 x 24 hour clock, so requests are forwarded immediately to our internal privacy owner.
Requests: privacy@francis.co.id
12. Personal data protection failures
Where a personal data protection failure occurs that meets the legal notification criteria, we will handle and notify it as required by law. Law No. 27 of 2022 requires written notification within 3 x 24 hours to the data subject and the competent authority in the relevant circumstances.
13. Children's data
This website is not intended to knowingly collect personal data from children without the parental/guardian consent required by law. If we learn that a child's data has been processed without an appropriate basis, we will take reasonable steps in accordance with the law.
14. Third-party links and services
The website may link to marketplaces, retailers, social media, WhatsApp or third-party services. Those parties have their own privacy practices. Francis does not control the practices of independent parties and this Policy does not replace theirs.
15. Changes to this Policy
We may update this Policy to reflect changes in our operations, technology, vendors, law or business practices. The version published on this page is the version in force. Where the law requires additional notice or consent for material changes, we will provide it.
16. Contact
PT Pangan Kreasi Makmur — Francis brand
Privacy email: privacy@francis.co.id
Customer service: help@francis.co.id
Website: https://www.francis.co.id
Address: Jl. Raya Cilandak KKO No.410, RT.15/RW.5, Cilandak Timur, Pasar Minggu, Kota Jakarta Selatan, DKI Jakarta 12560