Privacy Policy

This policy explains how Xyjecta, operating from Jalan Garuda No. 12, Kebon Sirih, Menteng, Jakarta Pusat 10340, Indonesia, handles information when readers visit our editorial website, contact the desk, or attend an event. We aim to collect only what is useful, explain why it is needed, and retain it for a defined period. This document applies to visitors, contributors, and correspondence received through our public channels. Because Xyjecta publishes in English for an international and Indonesian readership, this notice follows the general principles found in Indonesia's Personal Data Protection Law (Law No. 27 of 2022) even where a specific reader is located outside Indonesia. For example, a reader who completes the contact form to ask about a mobility routine described in an article is covered by this policy from the moment the form is submitted until the correspondence is closed and, where applicable, deleted. We review this document at least once a year, and sooner if we change a processor, add a new event-registration workflow, or receive guidance that affects how we describe our practices. Where a change is more than editorial tidying, we date the revision at the top of the page and summarise what moved in Section 12 below. Readers who only browse articles without submitting a form or attending an event generate the smallest data footprint described here, limited mainly to the technical details set out in Section 2.

1. Scope

The policy covers pages, forms, event registrations, and editorial communications controlled by Xyjecta. It does not govern third-party websites linked from our articles. Those services publish their own notices and should be reviewed before information is shared. This includes every page under the Xyjecta domain, from the training and nutrition guides to the glossary and community listings, regardless of which device or browser is used to reach them. It also includes written correspondence sent to our Jakarta office by post, since a letter referencing a reader's name or query is handled under the same retention logic as a digital message. The policy does not extend to printed materials a reader may create from our pages for personal use, nor to screenshots or quotations a third party republishes elsewhere without our involvement.

  • a) Outbound links inside an article, such as a reference to a public-health resource, are not operated by Xyjecta and are covered by that destination's own notice.
  • b) Social media profiles associated with Xyjecta follow this policy for messages we receive directly, but the platform's own terms govern data the platform itself collects.
  • c) A guest contributor's personal website or social profile, even when linked from a byline on this site, remains that contributor's own responsibility.

2. Information Collected

We may receive a name, email address, message content, accessibility preference, and the technical details ordinarily sent by a browser, such as device type, language, approximate region, and pages requested. We do not ask for health records, financial credentials, or precise location through ordinary forms. When a reader uses the contact form, the fields are limited to name, email address, and the message itself, plus an optional note about accessibility needs if the reader chooses to mention one. Server logs may separately record an IP address and timestamp for a short period, primarily to detect abusive form submissions rather than to identify an individual reader. We do not knowingly collect information from children under 16, and any message that appears to originate from a minor seeking guidance is answered with a general referral to a guardian or local health service rather than processed as an ordinary enquiry. Where an event registration is involved, we may also ask for a preferred session and a dietary or mobility note relevant to attending in person, which is used only for that event's logistics.

  • a) A reader submitting a question about training frequency, where we retain their name and email only to answer that question.
  • b) A browser's language setting, used to decide whether to display a page in English by default.
  • c) An approximate region derived from network information, used in aggregate to understand which cities read the site most, never to pinpoint an individual address.

3. Purpose

Information is used to answer correspondence, investigate corrections, organise requested events, protect the site, understand aggregate readership, and maintain a record of consent. Editorial messages may be retained so a correction can be traced accurately. A correction investigation, for instance, may require us to retrieve an earlier message to confirm what a reader originally asked before an article was amended, which is why correspondence tied to an open correction is kept until the correction is published and briefly afterward. Event organisation purposes include confirming attendance, communicating a venue change, and maintaining a simple attendance record for the Jakarta office's own administrative needs. Security purposes include identifying unusual submission patterns, such as the same message being submitted many times in a short window, so that the form can be temporarily throttled. Aggregate readership understanding never involves building a profile of a named individual; it is limited to counts and percentages used to decide which topics, such as mobility for desk-based professionals, deserve more coverage. Consent records are kept so that, if a reader later asks whether they opted into optional analytics on a given date, we can answer accurately rather than guess.

  • a) Keeping a two-year correspondence record to resolve a question about what advice was actually given.
  • b) Using an event sign-up list solely to prepare a one-page attendance sheet for the Jakarta venue.
  • c) Reviewing anonymised traffic reports monthly to help plan the editorial calendar referenced in our editorial policy.

4. Legal Basis

Where Indonesian law applies, processing is based on consent, contractual steps requested by a correspondent, legitimate interests in security and publishing, or a legal obligation. Optional analytics are not required to read Xyjecta and can be rejected through the cookie banner. Consent is the basis for optional analytics and for any email update a reader actively chooses to receive, and it can be withdrawn at any time without affecting past lawful processing. Contractual necessity applies narrowly, for example when a reader asks us to reserve a seat at an event and we need their name to prepare a badge. Legitimate interests cover routine security logging, abuse prevention, and the editorial need to retain enough context to issue an accurate correction, balanced against the limited sensitivity of the information involved. A legal obligation basis would apply if a Jakarta administrative authority lawfully required disclosure of a specific record, in which case we would disclose only what is strictly required and keep an internal note of the request.

  • a) Consent for the optional cookieChoice-linked analytics identifier described in Section 6.
  • b) Legitimate interest for keeping a 90-day security log to investigate a suspected automated submission.
  • c) Contractual necessity for processing an event registrant's name solely to issue entry at the door.

5. Retention

Contact correspondence is normally retained for 24 months after the last meaningful exchange. Event administration records are retained for 12 months after an event. Security logs may remain for up to 90 days, while aggregated readership statistics may be kept without a direct identifier for five years. These periods are reviewed whenever we revise our processors or event format, and a shorter period is applied automatically if the original purpose is fulfilled sooner, such as when a correspondence thread is resolved within a week and the message is no longer needed once the correction is published. Security logs beyond 90 days are deleted automatically by our hosting provider's standard log rotation rather than archived indefinitely. Aggregated readership statistics kept for five years are stripped of any field capable of identifying a specific visitor before that five-year clock begins, and are used only for long-range trend comparison. If a reader requests earlier deletion under Section 9, we apply that request to correspondence and event records even where the general period above has not yet elapsed, subject to any narrow legal reason to keep a specific record longer.

  • a) Contact-form correspondence: 24 months from the last reply.
  • b) Event administration records: 12 months from the event date.
  • c) Security logs: up to 90 days; aggregated statistics: up to five years without direct identifiers.

6. Cookies

The cookieChoice item records an accept or reject choice for 180 days. Essential session technologies may last until the browser closes. Optional analytics, where enabled, use a short-lived measurement identifier with a 13-month maximum retention. Details are described in cookies.php. The cookieChoice value itself contains no name, email address, or message content, only a simple accept or reject flag and the date it was set, so it cannot be used on its own to identify a visitor. Essential session technologies exist purely to keep a multi-step form, such as an event registration, functioning correctly as a reader moves between steps, and they are not used for advertising. Where optional analytics are enabled, the measurement identifier is rotated periodically and is never combined with the contact-form database. A reader who rejects optional cookies when the banner first appears can change that choice later by clearing the cookieChoice value in their browser, which causes the banner to reappear on the next visit.

7. Processors

We may use hosting, email delivery, form protection, analytics, and event-registration providers. They receive only the information needed for their service, operate under contractual confidentiality obligations, and may process data in jurisdictions outside Indonesia. Our hosting provider stores the website files and server logs described in Section 5 and is contractually required to apply reasonable technical safeguards, including restricted administrative access. An email delivery service is used only to route messages submitted through the contact form to our editorial inbox and does not independently market to readers. Where optional analytics are active, the analytics processor receives only aggregated or pseudonymous technical data, never a reader's name or message content. We periodically review this list of processors as part of the annual policy review mentioned at the start of this page, and we remove a processor's access promptly if the service is discontinued.

8. International Transfers

If information crosses a national border, Xyjecta seeks contractual safeguards and limits the transfer to the stated purpose. Readers may contact us for a general description of the destination and safeguard used, subject to security and confidentiality limits. A transfer can occur, for example, if our hosting or email-delivery infrastructure operates servers located outside Indonesia, which is common for widely used web-hosting services. In such cases we select providers that publish their own security and confidentiality commitments and we limit what is shared to the minimum needed for the service to function. We do not sell or rent information to a third party for that party's own marketing purposes, regardless of where that party is located. A reader based inside Indonesia and a reader based abroad are treated under the same transfer safeguards described here, since the policy does not vary protection by the reader's location.

9. Your Rights

You may request access, correction, deletion, restriction, or a copy of information, and may withdraw optional consent. Send a request to the address above or call +62 21 6853 0927. We may ask for reasonable verification and normally respond within 30 calendar days. Access requests are answered with a plain-language summary of what we hold about the requester, rather than raw database output, unless the requester specifically asks for the underlying fields. A correction request is useful when, for example, an event attendee's name was recorded with a typographical error on a registration list. Deletion requests are honoured except where a short retention is still required for an open correction investigation or a narrow legal reason, in which case we explain why. Restriction allows a reader to ask us to pause active use of their information, for instance while a question about accuracy is being resolved, without requiring full deletion.

  • a) Asking us to delete a prior contact-form message once a related correction has already been published.
  • b) Requesting a copy of the information tied to a specific event registration.
  • c) Withdrawing consent to optional analytics at any time via the cookie banner, with no effect on correspondence already answered.

10. Complaints

We encourage readers to contact the editorial desk first so an issue can be investigated. A complaint should include the relevant page, date, and preferred response channel. Nothing here removes a person's right to contact an Indonesian supervisory authority or seek another remedy available under law. We ask for the relevant page so that, if the concern relates to a specific article or form, we can check the exact version a reader saw at the time. Including a date helps us locate the correspondence or session referenced in the complaint more quickly, particularly where a reader contacted us more than once. We aim to acknowledge a complaint within five business days and to provide a substantive response within 30 calendar days, consistent with the timeframe described in Section 9. If a reader remains unsatisfied after our internal review, this section does not limit their ability to raise the matter with the applicable Indonesian authority responsible for personal data protection matters, or to pursue another remedy available under law.

11. Security

Access is limited by role, transmission is protected where supported, and operational systems are reviewed periodically. No internet service can promise absolute security, so please avoid sending sensitive medical or financial information through the contact form. Role-based access means that only the small number of staff who need to answer correspondence or manage events can view the related records, rather than the information being broadly visible across the organisation. Where our hosting and email infrastructure support encrypted transmission, it is enabled by default for form submissions and administrative access. We periodically check that software used to run the site is kept reasonably current, reducing exposure to known vulnerabilities. In the unlikely event of a security incident that is likely to affect a reader's personal information meaningfully, we intend to notify affected individuals and, where required, the applicable authority, within a timeframe consistent with Indonesian practice.

12. Changes

We revised this policy on 1 September 2026 to clarify retention and international transfers. Future material changes will be dated at the top of this page and, where appropriate, announced through the site. The current version governs information collected after publication. The 1 September 2026 revision clarified the specific retention periods described in Section 5 and added the international transfer language in Section 8, neither of which materially changed how information is actually handled but both of which make our existing practice easier to understand. We expect to conduct the next scheduled review around the first quarter of 2027, consistent with the annual cadence mentioned at the top of this page, though an earlier review would be triggered by a new processor or a change in applicable law. Where a future change would meaningfully reduce a reader's rights, we intend to provide more prominent notice than a simple date update, such as a short banner on the homepage. Continued use of the site after a dated revision indicates acceptance of the then-current version for new information collected from that point forward.