Data request policy
Reviewed 1 October 2026. This page explains how Ijanos handles requests to access, correct or delete personal information. The process is designed for readers in Indonesia and follows the principles described in our privacy policy. We do not require health records for an ordinary request.
1. Who may request
A person may ask about information connected with their own contact message or consent choice. An authorised representative may write with evidence of authority. We protect other people’s details. Requests are handled carefully even when no record is found.
2. How to submit
Write to Jalan Merdeka Timur No. 11, Gambir, Central Jakarta 10110, Indonesia, or call +62 818 2349 7561. Include your name, a safe reply route, approximate date and the action requested. Do not send identity documents unless a secure verification route is agreed. Ordinary email should not contain sensitive medical information.
3. Verification
We may ask a reasonable follow-up question to confirm that a request belongs to the person concerned. Verification information is used only for that purpose. If identity cannot be confirmed, we may provide a general explanation instead. This protects readers from unauthorised disclosure.
4. Access
An access response may describe contact fields, consent records, retention and recipients. Some security details or another person’s information may be withheld where lawfully required. We aim to respond within 30 days. Complex requests may require a written extension.
5. Correction
Tell us which information is inaccurate and what should replace it. We may retain a correction history where necessary for accountability. Editorial opinion is not treated as a factual profile. We confirm the result when the update is complete.
6. Deletion
We delete or anonymise information when there is no continuing lawful purpose, subject to security, legal or dispute records. Contact messages normally expire after 12 months from meaningful exchange. Deletion from a browser does not erase a message already sent. We explain exceptions.
7. Restriction
A person may ask us to pause a disputed use while accuracy or lawfulness is reviewed. The site can still deliver ordinary public pages. Essential security processing may continue. We record the request and its outcome.
8. Third parties
If a processor holds relevant data, we coordinate a request through our service relationship. External websites linked from Ijanos must be contacted directly under their own policies. We do not control their records. A request may therefore have more than one destination.
9. Fees
Ordinary requests are handled without a fee. A manifestly excessive or repetitive request may require a lawful administrative charge or be declined after explanation. We consider accessibility and reasonable assistance. No person is charged merely for asking a question.
10. Review and complaint
Requests are reviewed by the Ijanos desk and may be escalated for privacy advice. If you are dissatisfied, contact us again with the response and concern. You may seek guidance from an applicable Indonesian authority. This policy was reviewed 1 October 2026.
Practical request handling
A request can concern a contact message, a cookie choice, a correction or a deletion question. It does not need to be written in legal language. A clear description of the approximate date, page or reply route helps us locate the relevant record without asking for more information than necessary.
We usually acknowledge a request within seven calendar days and aim to complete an ordinary access, correction or deletion response within 30 days. A complex request, a request covering multiple systems or a request requiring careful identity checks may need a written extension. We will explain the reason, the expected next step and any information still needed.
Identity checks are proportionate to the sensitivity of the request. We may compare the reply route with the contact details already supplied or ask a short question about the earlier exchange. We do not ask people to email passports, identity cards, medical records or financial statements to an ordinary inbox. If stronger verification is necessary, we will describe a safer route before proceeding.
Contact messages are normally retained for 12 months after the last meaningful exchange. Consent records may be retained for up to 24 months, and security records for up to 90 days unless an incident requires preservation. A deletion request may be limited where a record is needed for legal compliance, fraud prevention, dispute resolution or the integrity of a correction history; in those cases, access is restricted and the reason is explained.
Responses may identify categories of recipients such as hosting, email delivery, security or analytics providers, without exposing another person’s information or confidential security controls. Some technical processing may occur outside Indonesia, subject to appropriate contractual and organisational safeguards. The policy was reviewed on 1 October 2026, and questions can be sent to Jalan Merdeka Timur No. 11, Gambir, Central Jakarta 10110, Indonesia, or +62 818 2349 7561.
A request may concern a contact message, a cookie choice, a correction or deletion question. It does not need legal wording, and a clear approximate date, page or reply route helps locate the relevant record. We do not require health records for ordinary verification. A request involving another person’s information may be limited to protect that person’s privacy.
We aim to acknowledge a request within seven calendar days and complete an ordinary access, correction or deletion response within 30 days. A complex request or one involving multiple systems may require a written extension with the reason and expected next step. We may compare the reply route with information already supplied or ask a proportionate follow-up question. Identity documents should not be emailed unless a safer route has first been agreed.
Contact messages are normally retained for 12 months after the last meaningful exchange, consent records for up to 24 months and security records for up to 90 days. A deletion request may be limited where a record is needed for legal compliance, fraud prevention, dispute resolution or the integrity of a correction history. In that case access is restricted and the reason is explained. Service providers may include hosting, email delivery, security and analytics providers, each limited to the function required.
Some technical processing may occur outside Indonesia, subject to contractual and organisational safeguards. Responses can describe recipient categories and retention without exposing another person’s details or confidential security controls. This policy was reviewed on 1 October 2026. Questions can be sent to Jalan Merdeka Timur No. 11, Gambir, Central Jakarta 10110, Indonesia, or +62 818 2349 7561.