Privacy Policy
Privacy Policy
The short version: this site sets one cookie to remember your language, runs no tracking or advertising, and only receives personal data if you choose to send it through the contact form.
Last updated:
Who is responsible
Yudhi Armyndharis is the data controller — "Pengendali Data Pribadi" under Indonesia's Law No. 27 of 2022 on Personal Data Protection (UU PDP), and "controller" under Article 4(7) of the GDPR.
For any question or request about your data, write to yudhi@rmyndharis.com. Access, correction, restriction, and withdrawal of consent are carried out within 3×24 hours, the deadline the PDP Law sets. Anything more involved is answered without undue delay, and in any event inside the one-month period Article 12(3) of the GDPR sets, without taking the extension that article permits.
What is collected
Only one of these is something you actively send. Nothing is inferred, enriched, or bought from anyone else.
Please keep sensitive details out of the message — health, religion, political views, or anything similar. None of it is asked for and none of it is needed to answer an enquiry. If a message does contain such details, it is not kept on the ordinary 24-month clock: it is deleted as soon as the enquiry has been dealt with, and sooner if you ask.
- Contact form — the name, email address, optional company, and message you type. Nothing is added to it.
- Technical request data — your IP address and browser user-agent, seen by the hosting layer on every page you open, not only when you submit the form. When you do submit, your IP becomes a rate-limit counter that expires within minutes so the form cannot be abused. It is never stored alongside your message, and no profile is built from it.
- Language cookie — one first-party cookie named "locale", holding either "id" or "en". It is written only when you press the language button in the navigation, never merely because you visited a page. It carries no identifier and cannot be used to recognise you on a later visit.
- Aggregate analytics — page-view counts and performance timings, collected without cookies and without building a profile of any individual visitor.
The legal basis for it
Sending an enquiry is a request for a service, so your message is processed in order to answer it. That is Article 6(1)(b) of the GDPR (steps taken at your request before a contract) and Article 20(2)(b) of the PDP Law, which recognises the same ground.
Rate-limiting and abuse prevention rest on legitimate interest — Article 6(1)(f) of the GDPR and Article 20(2)(f) of the PDP Law. Without it, the form could be used to send mail in someone else's name.
Aggregate analytics rest on the same legitimate interest. The counts carry no cookie and never resolve to a person, which is why nothing is asked of you before they are taken.
How long it is kept
Contact messages are kept for 24 months from the day they are sent, then deleted. That is long enough for a prospective client who comes back after a year, and short enough not to hold anything longer than it is useful.
The language cookie expires one year after you last pressed the language button. Rate-limit counters live for minutes at most and hold no message content.
You do not have to wait out the 24 months. Ask at any time and the message is deleted from the inbox; residual copies in Apple's backups fall away on Apple's own rotation, which I do not control.
Who else handles it
No data is sold, rented, or shared for advertising, ever. These providers necessarily process it in order for the site to work, and each sees only what its job needs:
- Vercel — hosting and request delivery. The contact form runs on Vercel's servers, so it sees everything you typed as that data passes through, along with your IP address and user-agent. It also runs the cookieless page counts.
- Resend — delivers your contact-form message. Sees the name, email address, company, and message you typed.
- Upstash — holds the short-lived rate-limit counter keyed to your IP address. Never sees your message.
- Apple iCloud Mail — hosts the inbox your message is delivered to. Sees everything you sent, and holds it for the full 24 months.
Transfers outside Indonesia and the EEA
Vercel, Resend, and Upstash run infrastructure outside Indonesia and, in some cases, outside the European Economic Area. Those transfers rely on standard contractual clauses and equivalent-protection commitments — the route required by Article 56 of the PDP Law and Chapter V of the GDPR — and each of the three publishes its own data-processing terms, so you can read them without going through me. The mailbox your message finally rests in is likewise hosted outside Indonesia.
Emailing me directly instead of using the form keeps your message away from Vercel, Resend, and Upstash — but not inside the country. My mailbox is hosted abroad either way, so that route changes who handles your message, not where it comes to rest.
Your rights
The PDP Law (Articles 5 to 13) and the GDPR (Articles 15 to 22) grant overlapping rights. Every one of them is honoured for every visitor, wherever you live, subject only to the narrow limits set out in the next section:
- Be told what is held about you, and receive a copy of it.
- Correct anything inaccurate, outdated, or incomplete.
- Have your data erased and the processing of it ended.
- Restrict or postpone processing while a dispute is being resolved.
- Receive your data in a portable format, or have it transmitted to another controller.
- Object to processing that rests on legitimate interest.
- Withdraw consent, in the cases where consent was the basis.
- Seek compensation for loss caused by unlawful processing.
Making a request or a complaint
Email yudhi@rmyndharis.com saying what you want done. No particular form or wording is needed, and there is no charge.
If it is not obvious that the request comes from the person the data is about, I will ask enough to confirm it before acting — normally just something only you would know from our correspondence, and never more than the check actually requires.
A right can be limited in two cases: a message needed to establish or defend a legal claim, or one the law requires me to keep. If either applies to you, you will be told which right, and why.
No automated decision-making or profiling happens on this site, so the rights specific to that never come into play.
If you are not satisfied with the outcome, you may complain to a supervisory authority: in the EEA, the one in your country of residence; in Indonesia, the authority designated under the PDP Law.
Security and data breaches
The site is served only over HTTPS with HSTS, a strict Content-Security-Policy, and a fresh nonce on every request so injected scripts cannot execute. Form submissions are validated, sanitised, and rate-limited.
In plain terms: the connection is encrypted, your browser is told to load scripts, styles, images, and fonts only from this site, and the form accepts only a few submissions a minute. Data is encrypted in transit between providers, and your message is stored in encrypted form in the inbox that holds it. Only one person holds the credentials to that inbox — there is no colleague, contractor, or shared login.
Should a breach ever affect your personal data, you and the relevant authority will be notified within 3×24 hours, as Article 46 of the PDP Law requires.
Cookies, in one paragraph
This site sets exactly one cookie: "locale", and only at the moment you press the language button in the navigation. Browsing alone stores nothing on your device. There are no analytics, advertising, or third-party cookies, nothing is kept in local storage, and no request leaves this domain.
That is why there is no consent banner to dismiss. Under the ePrivacy Directive, a preference cookie set as the result of an explicit choice you made is exempt from consent — and a banner offering nothing to refuse would be theatre, not protection.
You can delete the cookie from your browser settings whenever you like. Nothing breaks: /id or /en in the address bar decides the language, and only the bare address falls back to what your browser asks for.
Children
This site is aimed at businesses and is not directed at children. Article 25 of the PDP Law allows a child's personal data to be processed only with the consent of a parent or guardian. If you believe a child has sent something through the form, email me and it will be deleted.
Changes to this policy
If anything here changes materially, the date at the top changes with it and the previous version is replaced. Changes take effect the day they are published, and are never applied backwards to a message you already sent. There is no mailing list, so check that date if this matters to you.