Last updated: 26 August 2026

ASSA (“we”, “us”, “our”) operates the online store at assa-korea.com, where we sell Korean fashion, beauty and lifestyle products in Indonesia. This policy explains what personal data we collect when you browse, register, or shop with us, why we collect it, who we share it with, and what control you have over it.

We process personal data in accordance with Law No. 27 of 2022 on Personal Data Protection (UU PDP) and other applicable Indonesian regulations on electronic systems and transactions.

By using this website or placing an order, you confirm that you have read and understood this policy.

1. Who we are

ASSA is a Korean fashion, beauty and lifestyle retailer with its head office at Lippo Thamrin, Jl. M.H. Thamrin No. 20–8, Kec. Menteng, Jakarta 10350, Indonesia. We act as the data controller for the personal data collected through this website.

For any question about this policy or your data, email cs@assa-korea.com or message us on WhatsApp at 0822-8921-1855 (Monday to Friday, 09:00–17:00 WIB).

2. What we collect

2.1 Information you give us

  • Account details — name, email address, password, and phone number when you register or sign up as a New Member.
  • Order details — the items you buy, order value, delivery and billing addresses, recipient name and phone number, and any notes you add to an order.
  • Payment details — the payment method you choose and the confirmation returned by our payment provider. Full card numbers and banking credentials are entered on the payment provider’s secure page and are never stored on our servers.
  • Communications — messages you send us by email, WhatsApp, contact form or social media, including any attachments.
  • Marketing preferences — the email address you give when subscribing to our newsletter, and whether you have opted in or out.
  • Reviews, comments and wishlists — the content you submit, the name shown with it, and the products you save.

2.2 Information collected automatically

  • IP address, browser type and version, device type, operating system, and screen size.
  • Pages viewed, products opened, time spent on the site, and the link or search that brought you here.
  • Cart and session data needed to keep your basket and login active as you move between pages.
  • Cookie identifiers, as described in section 4.

If you leave a comment on the site, we also record your IP address and browser user agent string to help detect spam.

2.3 Information from other sources

We may receive data about you from our payment providers (transaction status and fraud checks), our delivery partners (tracking and delivery confirmation), and advertising or social platforms where you have engaged with our campaigns.

3. Why we use your data

PurposeBasis under UU PDP
Processing and delivering your order, and handling returns or refundsPerformance of a contract with you
Creating and maintaining your account and membership benefitsPerformance of a contract with you
Answering enquiries and providing customer supportPerformance of a contract / legitimate interest
Sending newsletters, promotions and product newsYour consent (withdrawable at any time)
Preventing fraud, abuse and spam, and keeping the site secureLegitimate interest / legal obligation
Measuring site performance and improving the storeLegitimate interest / your consent for analytics cookies
Keeping tax, accounting and transaction recordsLegal obligation

4. Cookies

Cookies are small files stored on your device. We use them in four ways:

  • Essential — keep you logged in, remember your cart, and process checkout. The site cannot work without these.
  • Functional — remember your language, currency display, wishlist and comparison selections.
  • Analytics — help us understand which pages and products people use, in aggregate.
  • Marketing — allow us and our advertising partners to show you relevant ads and measure campaign results.

Typical durations: a temporary cookie set when you visit the login page is deleted when you close your browser; login cookies last two days, or two weeks if you select “Remember Me”; display preference cookies last one year. If you opt in when leaving a comment, your name, email and website are stored in cookies for one year so you do not have to type them again. If you publish or edit an article as a site administrator, an additional cookie storing only the post ID is set for one day.

You can block or delete cookies in your browser settings. Blocking essential cookies will stop the cart and checkout from working.

5. Payments

Payments are handled by licensed payment service providers and the banks and e-wallets shown at checkout, including bank transfer, virtual account, card, GoPay and ShopeePay. When you pay, the data needed to complete the transaction is passed to the relevant provider, which processes it under its own privacy policy and applicable Bank Indonesia regulations. We receive confirmation of the result, not your full payment credentials.

6. Shipping and delivery

To deliver your order we share your recipient name, address, phone number and order reference with the courier you select, which may include JNE, J&T Express, POS Indonesia, AnterAja, GoSend, Grab Express or Lion Parcel. Couriers use this data to complete delivery and provide tracking updates.

7. Who else we share data with

We do not sell your personal data. We share it only with parties that help us run the store, and only to the extent they need it:

  • Payment providers and delivery partners, as described above.
  • Hosting, email, CRM and analytics providers that operate our technical infrastructure.
  • Our appointed website development partner (see section 8).
  • Professional advisers, auditors, or authorities where we are required to disclose data by law or valid legal process.

If you request a password reset, your IP address is included in the reset email for security verification.

8. Website development and maintenance partner

Core Freelancers is our appointed digital partner for the development, maintenance and ongoing improvement of assa-korea.com. In that role, Core Freelancers has authorised technical access to the website — including the content management system, hosting environment, plugins and, where necessary for troubleshooting or improvement, the data held within them.

Core Freelancers processes this data only on our instruction, solely to build, secure, fix and improve the website, and is bound by confidentiality obligations. It does not use your personal data for its own purposes and does not sell or share it.

Found a bug or a display problem? If a page loads incorrectly, a button does not work, or something looks broken, you can report it directly to our development partner. The same channel handles website layout, design and development enquiries.

Report a bug or send a website development enquiry to Core Freelancers →

9. Embedded content and external links

Pages on this site may include embedded content such as videos, images, product widgets or social posts. Embedded content from another website behaves exactly as if you had visited that website: it may collect data about you, set its own cookies, embed additional third-party tracking, and monitor your interaction with it — including where you are logged in to that service. Our site also links to external pages we do not control. This policy does not cover them, so please read theirs.

If you upload an image to the site, avoid files containing embedded location data (EXIF GPS), because visitors can download the image and extract that data.

10. Marketing communications

We send promotional emails and messages only to people who have opted in, or who have bought from us and have not opted out. Every marketing email includes an unsubscribe link, and you can stop WhatsApp promotions by replying STOP or contacting customer service. Opting out of marketing does not stop transactional messages such as order confirmations and shipping updates.

11. How long we keep your data

  • Order and transaction records — kept for as long as required by Indonesian tax and accounting rules, generally ten years.
  • Account data — kept while your account is active, and removed on request unless we must retain part of it for legal reasons.
  • Customer service messages — normally kept up to two years after the enquiry is closed.
  • Marketing data — kept until you unsubscribe, plus a short suppression record so we do not contact you again.
  • Comments and their metadata — retained indefinitely so follow-up comments can be recognised and approved automatically rather than held in a queue.
  • Analytics and log data — generally kept in aggregated or shortened form for up to 26 months.

Registered users can see, edit or delete the personal information in their profile at any time, except the username. Site administrators can also see and edit that information.

12. Your rights

Under UU PDP you have the right to:

  • Be told what data we hold about you and why.
  • Access your data and request a copy in a usable format.
  • Correct or complete data that is inaccurate or out of date.
  • Ask us to delete data we no longer need, or that you gave us with consent.
  • Withdraw consent for marketing or analytics at any time.
  • Object to or restrict certain processing.
  • Lodge a complaint with the relevant supervisory authority.

To exercise any of these, email cs@assa-korea.com from the address linked to your account. We may ask for proof of identity, and will respond within the period set by applicable law. We cannot delete data we are obliged to keep for administrative, legal, tax or security purposes.

13. Security

We protect the site with an encrypted HTTPS connection, restricted administrator access, regular software updates, and monitoring for suspicious activity. Payment data is handled on the secure systems of our payment providers. No system is completely secure, so please use a strong, unique password and tell us immediately if you suspect your account has been accessed by someone else.

14. Children

This store is intended for adults. Anyone under 18 should use the site and make purchases only with the involvement of a parent or guardian, who is responsible for the data provided. If you believe a child has given us personal data without that consent, contact us and we will remove it.

15. Transfers outside Indonesia

Some of our service providers — hosting, email, analytics and advertising platforms — process data on servers outside Indonesia. Where that happens, we take reasonable steps to ensure your data receives a level of protection consistent with UU PDP, including contractual safeguards with those providers.

16. Changes to this policy

We may update this policy as our services, technology or legal obligations change. The revised version takes effect when published on this page, and the date at the top always shows the latest revision. Significant changes will be highlighted on the site or sent to registered customers.

17. Contact us

ASSA

Lippo Thamrin, Jl. M.H. Thamrin No. 20–8, Kec. Menteng, Jakarta 10350, Indonesia

Email: cs@assa-korea.com

WhatsApp: 0822-8921-1855 — Monday to Friday, 09:00–17:00 WIB

Website issues and development enquiries: Core Freelancers

Search for products (0)

Back to Top
Product has been added to your cart
Category UP TO 70% Promo Home Cart My
Compare (0)