Privacy policy
This policy explains how Genesis, operating from Jl. Sudirman 12, Jakarta Pusat, DKI Jakarta 10220, Indonesia, handles personal information when you read, contact or otherwise use this website. It applies to editorial pages, forms, cookies and correspondence. Genesis is an information publisher and does not create medical profiles. Questions may be sent to +62 813 5792 4680.
1. Information and handling principles
Genesis collects only information reasonably connected with the stated purpose. This may include a name, email address, message content, approximate technical information and cookie choices when a reader submits a form or visits the site. We use this information to respond, maintain security, understand broad readership and improve accessibility, not to make health inferences. We retain correspondence for 24 months unless a longer period is necessary to resolve a dispute or comply with Indonesian law, then delete or anonymise it. Optional analytics cookies last up to 13 months and session cookies expire when the browser closes. Service providers may process limited technical data under confidentiality obligations, while international transfers use contractual and organisational safeguards. You may request access, correction, deletion or restriction by contacting the Genesis desk; we respond within 30 calendar days and may verify identity. Complaints can be raised with the relevant Indonesian authority or another competent regulator. This policy was issued on 1 January 2026 and reviewed on 1 June 2026; future changes will show a new dated entry.
Scope of this policy. The policy covers every page published under the Genesis domain, the contact form, correspondence by email, post or telephone, and any cookie choices recorded in your browser. It does not cover websites that we link to, because those publishers set their own rules. If you are reading from outside Indonesia, the same practices apply, although local law in your country may give you additional rights. Where this policy and a mandatory legal requirement differ, the legal requirement prevails.
- Readers who browse articles, guides and the glossary.
- People who write to the editorial desk or telephone +62 813 5792 4680.
- Contributors, event enquirers and members of the press.
Data we collect. When you use the contact form we receive the name, email address, subject and message that you type. Our web server also records an IP address, browser type, requested page and time of request in routine logs, which helps us detect abuse and diagnose faults. If you choose optional cookies, an aggregate analytics identifier is stored as described in the cookie policy. We do not ask for national identity numbers, bank details, medical records or biometric information, and we ask readers not to send them.
- Information you provide: name, email, message content, preferred reply channel.
- Technical information: IP address, device and browser type, pages viewed, referring page.
- Preference records: your Accept or Reject cookie choice.
Legal basis for processing. We process personal data under Law No. 27 of 2022 on Personal Data Protection and its implementing rules. Correspondence is handled because you asked us to respond, which is a form of consent and a contractual-type request. Security logs rely on our legitimate interest in keeping the site available and safe. Some records are kept because Indonesian tax, corporate or electronic-transaction rules require it. Where we rely on consent, you may withdraw it at any time without affecting earlier lawful processing.
- Consent: optional analytics cookies and any newsletter-style correspondence.
- Legitimate interest: security logs, fraud and abuse prevention, accessibility testing.
- Legal obligation: records that must be produced to a competent authority.
Retention periods. Each category of data has a defined lifespan so that information is not kept without a reason. Once a period ends, records are deleted or irreversibly anonymised, and backups are overwritten on their normal cycle. If a dispute, complaint or legal request is open, the relevant records are kept until it is closed and then removed within a further 90 days. Anonymised statistics may be kept longer because they no longer identify anyone.
- Contact messages and replies: 24 months from the last message.
- Server logs with IP addresses: 90 days.
- Optional analytics identifiers: up to 13 months; session cookies end when the browser closes.
- Commissioning and contributor records: 24 months.
- Encrypted backups: overwritten after 35 days.
Your rights and how to use them. You may ask to access the personal data we hold, correct inaccuracies, delete data, restrict or object to processing, withdraw consent and request a copy in a commonly used format. Send the request through contact.php, by post to Jl. Sudirman 12, Jakarta Pusat, DKI Jakarta 10220, Indonesia, or by telephone on +62 813 5792 4680. We may ask for details that let us confirm you are the person concerned, but we will not ask for more than is necessary. We reply within 30 calendar days and, for complex requests, may extend once by up to 30 days after telling you why.
- Access and copy of data.
- Correction and completion.
- Deletion or restriction where no legal reason to retain exists.
- Objection and withdrawal of consent.
Service providers and processors. Genesis uses a small number of providers to run the site. These typically include a web hosting and content delivery provider, a business email provider for correspondence, and an aggregate analytics tool that operates only after optional cookies are accepted. Each provider is bound by written confidentiality and security terms and may use the data only to perform the service for us. We do not sell personal data, rent mailing lists or share contact details for third-party marketing. A current list of provider categories is available on request.
- Hosting and delivery: serves pages and stores server logs.
- Email: receives and stores correspondence.
- Analytics: aggregate page performance, only after consent.
International transfers. Some providers store or process data in data centres outside Indonesia, commonly in Singapore or elsewhere in Asia-Pacific. Before transferring data we check that the destination offers a level of protection comparable to Indonesian law, or that contractual clauses and technical measures provide equivalent safeguards. Data is encrypted in transit using TLS, and access is limited to named staff and provider engineers who need it. If you would like to know where a specific record is held, you can ask the editorial desk.
- Contractual safeguards with each processor.
- Encryption in transit and access controls.
- Transfer reviewed during each annual policy review.
Security and incident handling. We apply reasonable organisational and technical measures, including restricted accounts, strong passwords, regular software updates and logging of administrative access. No online system can be completely free of risk, so we also maintain an incident procedure. If a personal data breach is likely to harm readers, we notify affected individuals and the competent Indonesian authority within 3 x 24 hours of confirmation, as the personal data protection rules require, and explain what happened and what steps they can take.
- Account access reviewed every quarter.
- Software updates applied on a routine schedule.
- Incidents recorded with cause, impact and remedy.
Children and sensitive information. The site is written for adults, in particular men aged 35 and over, and is not directed at people under 18. We do not knowingly collect data from children; if we learn that it has been submitted, we delete it within 30 days. Readers sometimes describe their own health in messages. We do not need this to answer editorial questions, so we remove unnecessary health details from correspondence where practical and never use them to profile or target readers.
- No collection of data from under-18s.
- Health details in messages are minimised and not reused.
- No automated decisions with legal effect are made about readers.
Change log and contact. Changes to this policy are recorded with a date so readers can see what changed and why. Material changes are announced on this page before they take effect, and the effective date at the top is updated. Complaints can be sent to the editorial desk, which acknowledges them within 5 working days and responds substantively within 30 calendar days. If you are not satisfied, you may contact the Indonesian ministry responsible for communications and digital affairs or another competent regulator.
- 1 January 2026: first issue of the policy.
- 1 June 2026: annual review; retention periods and rights procedure set out in greater detail.
- Further reviews take place at least once every twelve months.
Contact and complaints
Write to Genesis at the address above or use contact.php. We do not require sensitive health information to answer ordinary editorial messages. If a request cannot be completed, we will explain the legal or operational reason and identify the available complaint route.