Privacy policy
Effective 1 January 2026; reviewed 1 October 2026. Bliro, operating from Jakarta, Indonesia, explains how this editorial website handles personal information. This notice applies to the Bliro domain and to any subdomain used for editorial publishing, contact handling, or event registration. It is written for general readers rather than legal specialists, so some concepts are simplified without changing their practical effect. Where Indonesian Law No. 27 of 2022 on Personal Data Protection sets a stricter standard than described on this page, the stricter standard governs our practice. If a translated or printed copy of this notice ever conflicts with the version published on this page, the version on the live Bliro website is controlling.
1. Scope
Bliro is published under Nomor Induk Berusaha (NIB) 0812026004571 and Nomor Pokok Wajib Pajak (NPWP) 03.147.882.6-016.000, registered to the editorial office at Jalan Cempaka Putih Raya No. 15, RT.005/RW.001, Cempaka Putih Timur, Jakarta Pusat 10510, Indonesia. This policy covers visitors, contributors, contact correspondents, and event participants using Bliro pages. It does not govern websites linked from Bliro. By using the site, you acknowledge this notice and its limits. A reader who submits a question through the contact form is covered from the moment the message is sent until the retention period described in Section 4 expires. A contributor commissioned to write a guest article is covered for correspondence tied to that assignment, though any separate freelance agreement is governed by its own written terms. Event participants registering interest in a Bliro-hosted discussion are covered only for the registration details collected, not for anything shared privately among attendees afterward. This policy does not extend to information you provide directly to a third-party advertiser, payment processor, or social platform, even when you reached that service through a link on this site.
- a) Pages published under the Bliro domain, including articles, resource listings, and the contact form.
- b) Correspondence initiated by a visitor through the published email address, postal address, or telephone number.
- c) Registration details for Bliro-organized community discussions described on the events page, limited to name, contact method, and stated topic interest.
2. Information collected
We may receive your name, email address, message content, topic suggestion, accessibility request, and technical information such as browser type, approximate region, and requested page. We do not request health records for ordinary contact. Please avoid sending sensitive medical details. For example, if you write to ask whether a future article will cover a specific topic, we retain only your message and reply address, not any personal health details you might volunteer unprompted. Technical information such as approximate region is derived from standard web request headers rather than precise device location services. If a message happens to contain sensitive information you were not asked to provide, our editorial desk limits internal access to that message and does not forward it beyond the staff needed to respond. We do not knowingly combine contact-form data with any advertising identifier.
- a) Identity and contact details: name, email address, and any postal address you choose to include.
- b) Content you submit: message text, topic suggestions, and accessibility requests.
- c) Device and request data: browser type, approximate region inferred from network address, and the page requested.
3. Legal basis
We process contact information to respond to requests, maintain editorial correspondence, protect the site, and meet legal duties. Where optional analytics are enabled, the basis is consent. You may withdraw optional consent at any time through your browser settings or by contacting us. For instance, responding to a reader question relies on our legitimate interest in operating a functional editorial contact channel, balanced against your reasonable expectation of a reply. Protecting the site against abuse, such as automated spam submissions, relies on a legitimate security interest that is reviewed periodically to confirm it remains proportionate. Legal duties may include responding to a lawful request from an Indonesian authority or retaining limited records needed to demonstrate compliance with consumer protection rules. Where consent is the basis, as with optional analytics, withdrawing it does not affect processing that already occurred before withdrawal.
- a) Legitimate interest: responding to messages and maintaining a secure, functioning website.
- b) Consent: optional analytics cookies, which you may decline without losing access to editorial content.
- c) Legal obligation: retaining limited records where required by applicable Indonesian law.
4. Retention
Editorial correspondence is normally retained for 24 months after the last meaningful exchange. Accessibility requests may be retained for 36 months when needed to document improvements. Security logs are retained for up to 90 days unless a longer period is necessary to investigate abuse. A meaningful exchange means a two-way conversation rather than a single unanswered message, which is instead deleted or anonymized after 12 months of inactivity. Accessibility requests are kept longer because they often document a change applied across several pages over time, and the record helps confirm the improvement remains in place during a later review. Where an investigation into suspected abuse or fraud is open, relevant security logs may be retained beyond 90 days until the matter is resolved, after which routine deletion resumes. At the end of each retention period, records are deleted or irreversibly anonymized rather than archived indefinitely.
- a) Unanswered single messages: anonymized or deleted after 12 months.
- b) Ongoing editorial correspondence: retained 24 months from the last reply.
- c) Accessibility documentation: retained up to 36 months to verify a fix remains effective.
5. Cookies
The cookieChoice preference lasts for 12 months in local storage. Essential session technologies, if used by hosting infrastructure, expire when the session ends. Optional analytics cookies are used only where consent exists and have a maximum lifespan of 13 months. The cookieChoice value stores only your Accept or Reject selection and does not contain your name or message content. Essential session identifiers, where the hosting provider assigns them, typically expire the moment you close the browser tab or after a short period of inactivity, whichever comes first. The 13-month ceiling on analytics cookies follows common regional practice for annual reporting cycles and is reviewed whenever the underlying analytics tool changes its default settings. See the dedicated cookie policy page for the complete list of technologies, their names, and their individual lifespans.
- a) cookieChoice: records your banner selection, lifespan up to 12 months.
- b) Session identifiers: essential, expire at the end of the browsing session.
- c) Analytics identifiers: optional, consent-based, lifespan up to 13 months.
6. Processors
Hosting, security, email, and analytics providers may process limited information on our instructions. Providers are selected for appropriate safeguards and may be located in Indonesia or other jurisdictions. We do not sell personal information. A hosting provider, for example, may temporarily process request logs to keep the site available and to guard against denial-of-service activity. An email delivery provider may process your message and reply address solely to transmit correspondence between you and the editorial desk. Analytics providers, where enabled, receive only aggregated or pseudonymous technical data and are contractually restricted from using it for their own independent marketing. Each processor is bound by a written agreement describing the permitted purpose, confidentiality duties, and deletion obligations at the end of the engagement.
- a) Hosting and security infrastructure, processing request logs for delivery and abuse prevention.
- b) Email delivery services, processing message content solely to transmit correspondence.
- c) Optional analytics providers, processing pseudonymous technical data only after consent.
For transparency, the categories described above currently correspond to the following named service providers acting under our instructions: Vercel Inc. (application hosting and content delivery), Google LLC, operating Google Analytics (optional, consent-based visit measurement only), and Resend (transactional email delivery used to relay contact-form correspondence to the editorial desk). None of these providers is authorized to use Bliro visitor data for their own independent marketing purposes. Bliro's appointed Data Protection Officer, Rafi Hartono, can be reached at [email protected] or by post at the address in Section 9 for any processor-specific question, a request to see a current list of sub-processors, or a question about a specific data transfer.
| Provider | Category | Purpose |
|---|---|---|
| Vercel Inc. | Hosting | Application delivery and request logging |
| Google LLC (Google Analytics) | Analytics | Optional, consent-based visit measurement |
| Resend | Email delivery | Transmitting contact-form correspondence |
7. International transfers
If a service provider processes data outside Indonesia, Bliro seeks contractual or organizational safeguards appropriate to the transfer. You may ask which categories of providers are involved. We keep transfers limited to operational necessity. For example, a hosting or analytics provider may operate data centers in Singapore or another regional jurisdiction with comparable data protection standards, rather than storing every record exclusively within Indonesia. Where a transfer occurs, the receiving provider is contractually required to apply safeguards consistent with Indonesian Law No. 27 of 2022, including confidentiality and deletion commitments. We do not transfer personal information to a jurisdiction solely to avoid applicable data protection requirements. If you would like to know the general region where a specific category of provider operates, you may ask using the contact details in Section 8.
- a) Regional hosting: infrastructure located within Southeast Asia where feasible.
- b) Contractual safeguards: written commitments covering confidentiality and deletion.
- c) Necessity limitation: transfers restricted to what the relevant service genuinely requires.
8. Your rights
You may request access, correction, deletion, restriction, or a copy of information you supplied, subject to lawful exceptions. Send a request to the address or phone number in the footer. We aim to respond within 30 days and may request reasonable identity confirmation. An access request lets you ask what information we hold about you and why; a correction request lets you fix an inaccurate email address or name on file. A deletion request will generally be honored unless a shorter retention conflicts with an open security investigation or a legal record-keeping duty described in Section 4. Identity confirmation for a postal or phone request may involve matching the contact details you originally used, so that information is not disclosed to someone impersonating you. If we cannot complete a request within 30 days because it is complex, we will tell you the reason and the revised expected timeframe.
- a) Access: a description of the categories of data held and their purpose.
- b) Correction or deletion: subject to the retention limits described in Section 4.
- c) Restriction: a temporary pause on further processing while a dispute is reviewed.
9. Complaints
First contact Bliro so we can review the concern. Privacy and data-handling questions can be directed to our designated data protection contact, Dewi Lestari, Copy and Standards Editor, reachable at the postal address and phone number listed at the foot of this page; this contact also coordinates any correction, deletion, or access request described in Section 5. You may also contact the relevant Indonesian data protection or consumer authority where you live. We will preserve a record of the complaint and response. We aim to acknowledge a complaint within 10 business days and to provide a substantive response within 30 calendar days of receipt. If the matter concerns a possible breach of Law No. 27 of 2022, you may separately raise it with the Ministry of Communication and Digital Affairs, which oversees personal data protection matters in Indonesia. Keeping a record of the complaint and our response allows us to track recurring issues and demonstrate accountability if a regulator later asks how the concern was handled. Escalating directly to an authority does not require you to wait for our internal response, though we encourage contacting us first so straightforward issues can be resolved quickly.
- a) Internal review: acknowledged within 10 business days.
- b) Substantive response: provided within 30 calendar days where reasonably possible.
- c) External escalation: available at any time to the relevant Indonesian authority.
10. Children
Bliro is written for adults and does not knowingly collect information from children. If a parent or guardian believes a child has contacted us, please notify the editorial desk so we can review and remove information when appropriate. The site's editorial focus on adult wellness topics means its contact form and event registrations are not designed or marketed toward minors. If we become aware that a message was sent by someone who appears to be a child, we remove the submitted information promptly rather than retaining it for the periods described in Section 4. A parent or guardian notifying us should include enough detail, such as the approximate date of the message, to help us locate and remove the relevant record. We do not use children's information for any analytics or communication purpose under any circumstance.
- a) No intentional collection from users known to be minors.
- b) Prompt removal upon notification from a parent or guardian.
- c) No analytics, newsletter, or marketing use of children's information.
11. Security
We use access controls, limited retention, encrypted transport where supported, and careful handling procedures. No internet transmission is risk-free. Suspected incidents are reviewed and addressed according to their seriousness. Access to the contact inbox and any stored correspondence is limited to editorial staff who need it to respond, rather than being broadly shared across the organization. Encrypted transport, such as HTTPS, protects information while it travels between your browser and our hosting provider, though it cannot guarantee the security of a device that has already been compromised. If a suspected incident involves personal information, we assess the scope and likely impact before deciding whether individual notification or a regulatory report is appropriate. We periodically review these procedures as hosting infrastructure or threats change, and material improvements are reflected in future revisions of this notice.
- a) Access controls: limited to staff who require the information to perform their role.
- b) Encrypted transport: applied to the connection between your browser and our hosting provider.
- c) Incident response: scoped assessment followed by notification where appropriate.
12. Changes
We updated this policy on 1 October 2026 to clarify retention and optional analytics. Future changes will show a new date and a short explanation. The current version remains available on this page. The 1 October 2026 review added the specific retention durations in Section 4 and the processor categories in Section 6, which earlier drafts described only in general terms. A material change, such as a new category of data collected, will be announced with a visible notice on this page for at least 30 days after publication. Minor edits, such as correcting a typographical error, are not separately announced but are still reflected in the reviewed date shown at the top of the page. Readers who want to track revisions over time may contact the editorial desk to ask about the history of this document.
- a) 1 January 2026: initial publication of this policy.
- b) 1 October 2026: added specific retention periods and named processor categories.
- c) Future revisions: announced on this page with a visible notice for at least 30 days.