Effective 1 October 2026
Privacy policy
Ijanos respects the privacy of visitors to our editorial website. This policy explains what information we collect, why we use it, how long we retain it and how to contact us from Indonesia. It applies to pages, contact messages, analytics and advertising relationships operated under the Ijanos name. It does not replace a provider’s own policy when you follow an external link.
1. Scope and controller
Ijanos, Jalan Merdeka Timur No. 11, Gambir, Central Jakarta 10110, Indonesia, is responsible for ordinary site information. The editorial desk can be reached at +62 818 2349 7561. We keep requests limited to the purpose described at collection. We do not intentionally collect information from children.
2. Information collected
Server logs may include IP address, browser type, device type, requested page and time of access. Contact forms collect the name, email address and message fields that a visitor chooses to send. We ask visitors not to submit medical records, identity numbers or financial details. Optional analytics are used only according to the cookie choice recorded by the site.
3. Legal basis
We process contact details to respond to a request and operate the publication. We rely on consent for optional analytics and non-essential cookies. We may use legitimate interest to maintain security, prevent abuse and understand broad readership patterns. Where Indonesian law requires another basis, we apply the applicable requirement.
4. Use of information
Information is used to answer messages, maintain technical security, improve accessibility and understand which editorial topics are useful. It is not used to diagnose health conditions or make eligibility decisions. We do not sell contact lists. Editorial suggestions may be summarised only after personal details are removed.
5. Retention
Contact messages are normally retained for 12 months after the last meaningful exchange, then deleted or anonymised. Security logs are retained for up to 90 days unless needed for an incident investigation. Consent records may be kept for 24 months to demonstrate the choice made. Aggregated analytics may be retained for 26 months without direct identifiers.
6. Processors
Hosting, email delivery, security and analytics providers may process limited information on our instructions. Providers receive only what is necessary for their function. Contracts and access controls are used where available. We review vendors when services or purposes change.
7. International transfers
Some infrastructure providers may process data outside Indonesia. Before using such a provider, Ijanos considers contractual safeguards, security practices and the sensitivity of the information. Visitors may ask for a current description of relevant transfer locations. We do not transfer medical records because we do not request them.
8. Your rights
You may ask for access, correction, deletion, restriction or an explanation of processing, subject to lawful exceptions. Send a request to the address or phone number above and identify the relevant email or message date. We may need reasonable verification to protect another person’s information. We aim to respond within 30 days and explain any extension.
9. Security
We use access limitation, ordinary account controls, encrypted transport where supported and periodic review of contact access. No internet transmission is completely risk-free. If an incident affects personal information, we assess notification duties under applicable Indonesian requirements. Please report suspected misuse promptly.
10. Cookies
The cookie banner stores the choice named cookieChoice so it does not reappear after a decision. Session and security cookies may last for the browsing session, while preference records may last up to 12 months. Optional analytics cookies are not placed when rejected. Full details appear on cookies.php.
11. Complaints
Please contact Ijanos first so we can investigate a concern. Include the page, date, request and preferred response channel. We will review the matter fairly and preserve only necessary correspondence. You may also contact the relevant Indonesian authority or seek independent advice.
12. Changes
This policy was reviewed on 1 October 2026. Material changes will be dated at the top of this page and described in the change record. A future update may reflect a new service, law or processor. The previous version is not represented as current after a replacement is published.
Practical application of this policy
For clarity, the information described above is handled according to purpose and proportionality. A contact message normally contains only the details needed to reply, while a technical log is used to diagnose delivery or security issues. We do not request identity numbers, health records, payment details or precise location for ordinary editorial correspondence. If a visitor sends such information voluntarily, we will avoid using it for unrelated purposes and will remove it when the request no longer requires it, subject to a short security or legal record where necessary.
Contact messages are normally retained for 12 months after the last meaningful exchange, then securely deleted or anonymised. Security logs may be retained for up to 90 days, except where an incident requires preservation for investigation. Consent records associated with the cookie banner may be retained for up to 24 months so that we can demonstrate the choice recorded. These periods are reviewed when the service, legal requirements or security circumstances change.
Where a service provider assists with hosting, email delivery, analytics or security, it receives only the information needed for its stated function and is expected to protect it under written or documented obligations. Possible providers include a hosting infrastructure company, an email transport provider and a privacy-conscious analytics service configured without advertising profiling. We do not permit these providers to use contact messages for their own unrelated marketing.
Some providers may process technical information outside Indonesia. In that situation, Ijanos considers contractual safeguards, access controls, transfer necessity and the provider’s published security commitments. A transfer does not change the visitor’s rights under applicable Indonesian privacy requirements. Visitors may ask which category of recipient was involved and why a transfer was necessary.
To exercise a right, write to the postal address or call the published phone number with a safe reply route and a description of the request. We aim to acknowledge a request within seven calendar days and provide a substantive response within 30 days, unless a lawful extension is needed for complexity or verification. We may ask a proportionate question to prevent disclosure to the wrong person, but we will not request unnecessary sensitive documents. If the response does not resolve a concern, the requester may reply to the editorial desk and may consider contacting the relevant Indonesian authority or consumer protection channel.
The policy was reviewed on 1 October 2026. Earlier operational notes may be retained internally as a change record, but the current version governs present processing. We will publish a new effective date when a material change affects collection, purposes, recipients, retention or user choices.
For practical clarity, ordinary site use does not require an account, identity number, payment information or precise location. A server record is used to deliver the requested page and investigate reliability or security concerns, not to infer a named person’s interests. A contact message is used to answer the question and maintain a limited correspondence history. Visitors should avoid including another person’s information unless it is necessary and lawful.
Our ordinary retention periods are proportionate to the purpose. Contact correspondence is normally kept for 12 months after the last meaningful exchange, consent records for up to 24 months, and security logs for up to 90 days. A record may be preserved longer when needed for a dispute, legal obligation, fraud investigation or correction history. When the period ends, information is deleted or anonymised through the relevant operational process.
Service providers may include hosting infrastructure, email delivery, security monitoring and privacy-conscious analytics. Each provider receives only the category needed for its function and is expected to apply access controls and confidentiality measures. Some technical processing may occur outside Indonesia, subject to contractual safeguards and applicable transfer requirements. Visitors may ask for the recipient category and the reason for a transfer.
Requests to access, correct or delete information can be sent to Jalan Merdeka Timur No. 11, Gambir, Central Jakarta 10110, Indonesia, or +62 818 2349 7561. We aim to acknowledge a request within seven calendar days and provide a substantive response within 30 days. A proportionate verification question may be used to prevent disclosure to the wrong person. The policy was reviewed on 1 October 2026, and material future changes will carry a new effective date.
Third-party data processors
Depending on the active site configuration, limited technical data may be handled by Vercel, Inc. for hosting and delivery, Google Workspace or another configured mail transport provider for editorial correspondence, and a privacy-conscious analytics provider only where optional consent has been recorded. These providers are engaged for defined functions, are not permitted to treat Ijanos contact messages as their own marketing list, and may be replaced after a configuration review. Their own notices describe infrastructure-level processing in more detail.