Privacy Policy
What data we collect, why, how long we keep it, and the rights you have over it.
In short
This policy explains what data we collect when you use Masyarakat Indonesia, what it is used for, who it is shared with, how long it is kept, and what rights you have over it.
We have tried to write it plainly: what is described here is what our systems actually do — not a list of possibilities drawn as widely as possible just in case.
Data controller
The data controller for this site is PT Masyarakat Indonesia Digital Diaspora & Community Platform, Kota Tangerang Selatan, Banten, Indonesia.
All requests about personal data — access, correction, deletion, objection — are sent through the Contact page. We deliberately do not publish an email address on the site so that it cannot be harvested by bots.
What we collect
Account data, which you provide yourself when registering:
- Username and email address
- Password — stored as a hash, never as plain text
- Your language preference
- Optional profile details: date of birth, gender, country, profile picture, short bio
Content you create yourself:
- Articles, comments, forum topics and replies
- Events you create and attendance you mark
- Private messages between members
- Likes and reactions
Technical data that arises automatically as you use the site:
- IP address and browser/device details in the session record when you sign in
- Access times and pages opened, as aggregate counters
- Technical error records when something goes wrong
- Push notification subscriptions, only if you allow them
What the data is used for
- Providing your account and keeping you signed in
- Displaying the content you create and attributing it to your name
- Sending service email: verification, password reset, notifications
- Moderation and security: spam, abuse, bot attacks
- Understanding which pages are read, as aggregate statistics
- Meeting applicable legal obligations
We do not sell your personal data and we do not hand it to data brokers.
Legal basis for processing
We process data under Indonesian Law No. 27 of 2022 on Personal Data Protection. For visitors from the European Union and the United Kingdom, the equivalent bases under the GDPR apply.
- Performing the service you asked for — account, forum, messages
- Your consent — push notifications, visit statistics, non-service email
- Our legitimate interests — system security and abuse prevention
- Legal obligations
Cookies and similar technologies
- Session and authentication cookies — required; without them you cannot stay signed in
- Preference cookies — language and display theme
- Cloudflare security cookies — telling visitors apart from bots
- Google Analytics statistics cookies — aggregate visit counts
Required cookies cannot be switched off, because without them the service does not work. Statistics cookies can be blocked through your browser settings.
A cookie consent banner is not yet available on this site. Once it is in place, non-essential cookies will only be set after you agree to them, and this section will be updated.
Third parties
The following services are used to run the site. Each receives only the data it needs for its task:
- Google Analytics (Google) — aggregate visit statistics. It runs in your browser and sends the page opened, the language, an approximate location, and the device type.
- Cloudflare — content delivery network, attack filtering, and bot protection; every request to the site passes through it. Cloudflare Turnstile is used to confirm that forms are filled in by a human, and Cloudflare R2 stores media files.
- Brevo — email delivery. We also record whether an email was opened and whether links in it were clicked, so that we can tell whether our mail actually arrives.
- Browser push services — Google, Mozilla, or Apple depending on your browser; only if you allow notifications.
We do not serve advertising
This site runs no advertising network. There are no ad scripts, no advertiser tracking pixels, and no profile of you is built for advertising purposes.
We also no longer run our own visitor analytics. What remains is a read counter per page, which holds no personal data.
Where the data is stored
Our database is replicated across three regions — the Americas, Europe, and Asia-Pacific — so that the site stays fast from anywhere and stays up if one region has a problem.
This means your data is also copied outside Indonesia and may be processed in other countries. Those copies sit on infrastructure we control ourselves and are protected by the same access controls.
How long data is kept
- Account data: for as long as your account exists
- Session records, including the IP address at sign-in: 1 day for an ordinary session and 30 days if you choose to stay signed in; deleted when you sign out
- Technical error records: 90 days
- Content you have published: for as long as it remains online — see the account deletion section
- Read counters: aggregate and without personal data, kept without a time limit
- Messages sent through the contact form, including the sender IP address: 2 years from sending, then deleted automatically
Your rights
- To know what data we hold and to obtain a copy of it
- To correct data that is wrong or incomplete
- To request deletion of your data
- To withdraw consent you have given, for example push notifications or email subscriptions
- To object to certain processing
- To lodge a complaint with the competent data protection authority
Send your request through the Contact page. We respond within 30 days at the latest. If we need to be sure the request really comes from the account holder, we will ask first.
Account deletion
Account deletion is currently done on request: send a request through the Contact page and we process it manually.
Once an account is deleted, its account data is removed and the username is recorded on a closed list so that it cannot be reused by someone else. Public content that has become part of a conversation — a forum answer other members refer to, for example — may remain in a form that is no longer tied to your identity.
Public content, forum, and messages
What you write in public areas — articles, comments, the forum, events — can be read by anyone, search engines included.
Private messages between members are not end-to-end encrypted. They are stored in our database and, in cases of suspected abuse or legal obligation, can be accessed by administrators. Please do not send highly sensitive information through messages.
Minimum age
Membership is intended for people aged 13 and above. If you are under 18, use the service with the knowledge of a parent or guardian; for the processing of children's data, parental or guardian consent is required under the Personal Data Protection Law.
If we learn that an account was created by a child under the minimum age, we will close it.
Security
- Passwords are stored as hashes, never as plain text
- All site traffic runs over HTTPS
- Public forms are protected by rate limiting and human verification
- Administrative access is restricted by role and written to an audit log
- The database is backed up regularly in encrypted form
No system is completely safe. If a data breach occurs that poses a risk to you, we will notify you as required by the applicable rules.
Changes to this policy
This policy may be updated when the service changes. The version number and effective date appear at the top of this page; for significant changes we will announce them on the site.
Questions
Questions about this policy, or requests concerning your personal data, can be sent through the Contact page.
The Indonesian text is the authoritative version. Translations are provided for convenience; in case of any discrepancy, the Indonesian text prevails.