Data rights and requests
This practical notice explains how readers can ask about personal information connected with Palmus. It complements the privacy policy and applies to correspondence handled from Jakarta. It is written for readers in Indonesia and is framed around Law No. 27 of 2022 on Personal Data Protection, which gives individuals defined rights over information about them. Palmus is a small editorial publication with no reader accounts, so the personal information we hold is limited, mainly to messages sent through the contact page, letters, short-lived security logs and the optional cookie choice stored in a reader’s own browser.
1. Access
Ask what personal information is held and why it is used. We will tell you whether we hold anything about you, which categories it falls into, where it came from and which purposes it serves. Where a message you sent is still within its retention period, we can supply a copy of the message and the date it was received. Access requests are free of charge for ordinary use. If a request is clearly repeated or excessive, we may explain what we can reasonably supply and why.
- (a) Typical records: the name, email address and text of a contact message and our reply.
- (b) Records we usually do not hold: payment details, identity documents, health records or account profiles.
- (c) Cookie choices are stored only in your own browser, so we cannot read or supply them; you can view them in your browser settings.
2. Correction
Tell us when contact details or message context is inaccurate. A common example is a mistyped email address on a message that is still awaiting a reply, which would otherwise send our answer to the wrong person. We will correct the record, confirm the change in writing and, where the inaccurate detail was passed to a service provider such as the mailbox host, ask that the same correction be made. We do not alter the substance of a message you sent, but we can attach a note recording your clarification.
- (a) Say which detail is wrong and what it should read.
- (b) Corrections to published articles are a separate matter and follow the editorial policy.
3. Deletion
Request removal where no legal or operational reason requires retention. Contact messages are normally kept for 24 months after the last meaningful exchange, and security logs for 90 days; a deletion request lets you ask for earlier removal. If a message is part of an open correction or a dispute, we may need to keep it until the matter is closed, and we will say so. Deleted messages are removed from the working mailbox, and copies in routine backups are overwritten in the normal backup cycle instead of being edited individually.
- (a) Messages connected to an unresolved correction may be retained until it is resolved.
- (b) Records we must keep to meet a legal duty are retained for the period the duty requires.
- (c) We confirm in writing once deletion has been carried out.
4. Restriction
Ask us to pause a disputed use while the concern is reviewed. For example, if you believe a message is being kept for longer than necessary, or you dispute its accuracy, we can set it aside so that it is not used for anything except storage until we have reached a conclusion. During a restriction we will not use the record to respond to other enquiries or to prepare aggregate figures. We will tell you before the restriction is lifted and explain the outcome of the review.
- (a) A restriction does not delete the record.
- (b) Restricted records are accessible only to the editor handling the review and the Data Protection Officer.
5. Objection
Object to optional measurement or processing based on operational interest. The clearest case is optional analytics: if you choose reject in the cookie banner, no analytics cookie is set, and you can change that choice at any time by clearing the cookieChoice entry in your browser. You may also object to the use of security logs beyond what is needed to protect the site, and we will weigh your reasons against the security purpose. Where we cannot uphold an objection, we will explain the reason in plain terms.
- (a) Objections to optional cookies take effect as soon as you change your browser setting.
- (b) Objections about other processing are answered in writing within the timing given in section 7.
6. Verification
We may request reasonable confirmation to avoid disclosing information to the wrong person. In most cases it is enough to write from the same email address that sent the original message, or to quote the date and subject of that message. We do not ask for copies of identity cards, passports or family cards unless a request cannot be verified in any other way, and we will say exactly what is needed and why. Documents provided only for verification are used for that purpose alone and are deleted once the request is closed.
- (a) Requests made on behalf of another person need that person’s written authority.
- (b) If we cannot verify a request, we will explain this and describe what would help.
7. Timing
We aim to respond within 30 calendar days and explain any necessary extension. Each request is acknowledged within five business days of arrival, and the acknowledgement states the date by which a full answer is due. If a request is complex or we need to confirm details with you, we may extend the period once, and we will tell you the reason and the new date before the first period ends. Requests received outside office hours are treated as arriving on the next business day.
- (a) Acknowledgement: within five business days.
- (b) Full response: within 30 calendar days.
- (c) Office hours: Monday to Friday, 09:00 to 17:00 Western Indonesia Time, excluding public holidays.
8. Exceptions
Some requests may be limited by legal duties, security needs or another person’s rights. For instance, we may not disclose information that would reveal the identity of another reader who wrote to us, or details of security measures that would weaken the protection of the site. A legal duty to keep a record, such as a requirement connected to a lawful request from an authority, can also prevent deletion. When we decline all or part of a request, we will explain which exception applies and what remains possible.
- (a) Refusals are given in writing with the reason.
- (b) Any part of a request that can be met will still be met.
- (c) You may complain to the relevant Indonesian authority for personal data protection if you remain concerned after our reply.
9. Contact route
Use contact.php or call +62 813 9587 4123. Avoid sending unnecessary identity documents. Requests can also be sent to the Data Protection Officer, Maya Kusumawardani, at [email protected], or by post to Palmus, Data Protection Officer, Jl. Raya Cilandak KKO No.17, RT.1/RW.5, Ragunan, Ps. Minggu, Kota Jakarta Selatan, Daerah Khusus Ibukota Jakarta 12560, Indonesia. The telephone line is answered Monday to Friday between 09:00 and 17:00 Western Indonesia Time, and staff can record a request but cannot release personal information over the phone without verification.
- (a) Include the date and subject of the message the request concerns, where there is one.
- (b) Say which right you wish to use: access, correction, deletion, restriction or objection.
- (c) Tell us how you would like to receive the answer, for example by email or by letter.
10. Review date
This notice was reviewed on 5 October 2026 and may be updated when applicable requirements change. It is checked together with the privacy policy and the cookie policy, so that the retention periods, contact details and response times in the three documents agree. Earlier editions are kept for 36 months and can be supplied on request. Readers who notice a difference between this notice and the privacy policy are asked to tell us.
- (a) 1 July 2026: notice first published.
- (b) 17 August 2026: verification and exceptions wording clarified.
- (c) 5 October 2026: Data Protection Officer contact route and response timings added.