Effective October 1, 2026

Privacy policy

This policy explains how Placid handles information when visitors read our editorial website, contact the desk, or exercise a privacy right. It applies to placid.id and its public pages from October 1, 2026.

1. Scope and responsibility

Placid is responsible for the editorial website and correspondence received at Jl. Cendrawasih No. 88, RT.003/RW.007, Kebayoran Baru, South Jakarta, Jakarta 12120, Indonesia. We do not ask readers to submit medical records and recommend removing sensitive health details from messages. This document covers website information, contact messages, security records, and limited measurement information. It does not govern third-party websites linked from our pages.

In practice, the editorial team working from the Kebayoran Baru address decides why and how correspondence is handled, and one team member acts as the point of contact for privacy questions. Where a hosting or email provider processes information on our behalf, it works under written instructions and may not use the information for its own purposes. The framework we consider most often is Indonesia’s Personal Data Protection Law (Law No. 27 of 2022), together with the Electronic Information and Transactions Law where it applies. The site is written for adults and is not directed at children. Linked websites, such as public health bodies, keep their own privacy notices, which readers should review separately.

  • (a) Website information covers pages requested, device type and technical logs.
  • (b) Contact messages cover the details a reader chooses to type into the form or an email.
  • (c) Security records cover entries needed to detect misuse, such as repeated failed requests.

2. Information we receive

We may receive a name, email address, telephone number, and message when a reader contacts us. Basic technical information such as an IP address, browser type, approximate country, requested page, and time may appear in server logs. We do not intentionally collect precise location, biometric data, or children’s information. If a message contains sensitive information, we use it only to respond and may advise the sender to contact a professional.

An IP address is treated as technical information that is used for security and is not combined with reading interests to build a profile. If a reader writes about a personal health situation, we read the message only to decide how to reply, and we normally respond with general editorial pointers and a suggestion to speak with a qualified professional. Fields in the contact form are limited to what is needed to answer: name, email address, an optional telephone number, a topic and the message. Telephone calls to +62 813 7755 3399 are not recorded, although a staff member may note the date, the topic and any follow-up that was promised. Messages that are clearly spam or contain malicious files may be deleted without a reply.

  • (a) Required details: a name or alias, an email address and the message text.
  • (b) Optional details: a telephone number and the page the question refers to.
  • (c) Details we ask readers not to send: identity card numbers, medical records, bank details and photographs of other people.

3. Legal bases

We use information to respond to correspondence, maintain site security, and provide pages requested by visitors. Where consent is required for optional analytics or cookies, we ask through the cookie banner. We may rely on legitimate interests for basic security and editorial administration after considering impact on visitors. A person may withdraw optional consent without affecting earlier lawful processing.

Under Indonesian law, processing generally needs a lawful basis such as the data subject’s consent, a legitimate interest, or a legal obligation, and we match each activity to one of these. Replying to a message rests on the reader’s request and our legitimate interest in answering it. Security logging rests on our legitimate interest in keeping the site available, and we limit it to what is proportionate. Optional measurement or preference storage, if offered, rests on consent given through the banner. When consent is withdrawn, the optional activity stops from that point and any related identifiers are removed within the periods set out in the cookies policy.

  • (a) Consent can be withdrawn by changing the cookie choice or by writing to [email protected].
  • (b) A legitimate interest assessment is reviewed whenever a new type of logging is introduced.
  • (c) A legal obligation, such as a lawful request from an Indonesian authority, is handled by the editor in charge after checking its validity.

4. Retention periods

Contact correspondence is normally retained for 24 months after the last exchange, then deleted or anonymised. Security logs are retained for up to 90 days unless needed to investigate abuse or comply with a lawful request. Consent records are retained for 24 months so we can remember a choice. Backups may persist for up to 35 days before routine deletion.

5. Your rights

Subject to applicable Indonesian law, you may ask for access, correction, deletion, restriction, or information about processing. Send a request to [email protected] with enough detail to locate the record; we may request reasonable verification. We aim to respond within 30 calendar days and will explain an extension when a request is complex. You may complain to the relevant Indonesian authority if you believe your rights were not respected.

6. Processors

Hosting, security, email delivery, and privacy-respecting measurement providers may process limited information on our instructions. They may access only what is necessary for their service and must maintain appropriate safeguards. We do not sell contact details or provide them to advertisers for behavioural targeting. Vendors may change, and material changes will be reflected in this policy.

7. Cookies

Essential session mechanisms may last until a browser session ends. The cookie choice named cookieChoice is stored locally and may remain for 24 months. Optional analytics cookies, when enabled, use a 13-month lifespan and are not required to read Placid. See cookies.php for categories, controls, and the meaning of rejection.

8. International transfers

Some infrastructure providers may process information outside Indonesia. Before using such providers, Placid seeks contractual confidentiality, access controls, encryption in transit, and a reasonable transfer assessment. A visitor may ask where a particular message was handled. We do not knowingly transfer more information than the service requires.

9. Security

We use access controls, HTTPS where available, limited administrative access, and routine review of public forms. No internet transmission is guaranteed to be perfectly secure. If we identify a material incident affecting contact information, we will assess notification duties and communicate through the address available to us.

10. Children and sensitive data

Placid is written for adults and is not directed to children under 16. We do not knowingly build profiles about health, sexuality, religion, or political views. Please avoid sending detailed medical information through the contact form. If a parent or guardian believes a child’s information was submitted, contact us for review.

11. Complaints and contact

Privacy questions can be sent to [email protected] or +62 813 7755 3399. Postal correspondence may be addressed to Jl. Cendrawasih No. 88, RT.003/RW.007, Kebayoran Baru, South Jakarta, Jakarta 12120, Indonesia. Include the request category and preferred reply channel. We will treat complaints seriously and keep a record of resolution steps.

12. Change log

This edition was published October 1, 2026. It replaced the prior draft by clarifying retention periods, cookie names, and rights procedures. Future revisions will show a date and a brief explanation near the top of this page. Continued use after a published change means the revised policy applies to future visits, subject to consent requirements.

Further detail on retention, rights, processors, transfers and complaints

The retention, rights, processor, transfer, complaint and revision sections above apply together with the practical points below. They explain how those sections operate day to day and do not replace them.

  • (a) Retention in practice: correspondence is reviewed once a year, and messages that have passed their retention period are deleted from the mailbox and from backups at the next scheduled rotation, which takes no longer than 35 days. Server and security logs are kept for a short operational window, normally 90 days, unless an incident requires longer review. Records of a privacy request, such as its date and outcome, may be kept for up to 36 months so that the desk can show it responded properly.
  • (b) Rights: under Law No. 27 of 2022 a person may ask for access to, correction of, deletion of, or a restriction on the processing of their personal data, and may withdraw consent or object to certain processing. To make a request, write to [email protected] or to the Kebayoran Baru address, and state which right you wish to use. We may ask for reasonable proof of identity, such as replying from the same email address, before releasing anything. We aim to acknowledge a request within 3 working days and to give a full answer within 30 days, and we explain any refusal in writing.
  • (c) Processors: processing is carried out by service providers in three categories, namely website hosting, email handling and security filtering. Each provider is bound by a written agreement covering confidentiality, security measures and deletion at the end of the service. The providers do not receive contact details for their own marketing.
  • (d) International transfers: some infrastructure used by these providers may be located outside Indonesia. Where information leaves Indonesia, we check that the recipient offers a level of protection comparable to Indonesian requirements, or that contractual safeguards are in place, and we limit the transfer to what the service needs.
  • (e) Security: access to the mailbox is limited to editorial staff, passwords are unique and protected with a second step, and devices used for correspondence are kept updated. If a personal data breach occurs, we assess the risk, notify affected people and the competent authority within 3 x 24 hours where the law requires it, and record the corrective steps taken.
  • (f) Complaints: a concern can be sent to [email protected] or by telephone to +62 813 7755 3399 during office hours, Monday to Friday. We acknowledge it within 3 working days and aim to reply fully within 30 days. If the reply is not satisfactory, the person may contact Indonesia’s ministry responsible for communication and digital affairs or another competent authority.
  • (g) Revision log: October 1, 2026 – current edition published, with scope, rights procedure and retention periods set out as above. Material changes are shown with a new date at the top of this page, and earlier editions can be requested from the desk.

Data protection officer

Placid's data protection officer can be reached at [email protected], by telephone on +62 813 7755 3399, or by post at Jl. Cendrawasih No. 88, RT.003/RW.007, Kebayoran Baru, South Jakarta, Jakarta 12120, Indonesia. Requests are acknowledged within 3 working days and answered in about 30 days.