Skip to content
DIAZSince 1975

Legal information

Privacy Policy

We ask only for the data we need, tell you what it is used for, and let you manage it. This page explains everything in plain language.

Last updated:

Who we are

Data controller

This website is run by Perkumpulan Pendaki, Penjelajah dan Pecinta Alam “DIAZ” (“DIAZ”, “we”), an outdoors organization based in Malang, East Java. In this policy, DIAZ is the party that decides why and how your personal data is processed.

Secretariat: Jl. Raya Tlogomas No. A1, Terminal Landungsari, Kec. Dau, Kabupaten Malang, Jawa Timur 65144.

The data we collect

Depending on what you do on the site

You decide how much you share. Here is what we collect, by activity.

Just reading
You do not need an account to read this site, and we do not store personal data about you. Visits are counted in aggregate, without cookies and without tracking you across sites. Our hosting provider processes your IP address temporarily so pages can be served and protected.
Signing in with Google
The name, email address, and profile photo of your Google account. We never receive your password. Each sign-in records your IP address and browser type, and ends automatically after seven days.
Commenting
The text of your comment together with your name and profile photo. Comments appear publicly under the article.
Membership verification request
Full name, member number, eagle name, month and year of joining, batch, place and date of birth, current address, and phone number. We match it against the membership archive before approving.
Membership records
Once approved, the board manages your membership status, official photo, board position, and archive notes.
Emergency info (optional)
Blood type, emergency contact, allergies, medical conditions, medications, and insurance number. Health data is specific personal data, so we store it only if you enter it yourself and explicitly consent. You can delete it at any time.

What the data is used for

And the legal basis

  • Managing your account and access rights on the site.
  • Verifying membership and issuing the Digital Membership Card, including emailing it to you.
  • Showing the author’s name on articles and your name on comments.
  • Sending email about your account or membership, and a notice when a new article is published.
  • Telling the board, through a messaging app, when a request or data change needs review.
  • Keeping the site secure, for example by limiting comments posted repeatedly in a short time.
  • Translating articles automatically so they can be read in Indonesian and English.

We process data on the basis of your consent (when you choose to sign in, submit a form, or enter emergency info) and the organization’s legitimate interest in managing membership, in line with Indonesia’s Personal Data Protection Law (Law No. 27 of 2022).

Who can see it

What is public and what is not

Not all of your data is visible to everyone.

Public to anyone
Comments together with your name and photo. The name, photo, member number, and eagle name of board members on the Structure page. Author pages for people who write articles (name, photo, member number, eagle name, batch, month and year of joining, field name, position). The verification page linked from the QR code on the membership card (name, member number, eagle name, status, batch, year of joining, photo). Some members’ names also appear as historical fact on the Timeline.
Only for signed-in members
Members’ phone numbers and email addresses in the member directory.
Only for you and the authorized board
Date of birth, address, and verification request data can be seen by the board members who review requests. Emergency info is not shown on public pages or in the directory; it appears only on the back of your own card, including on the card files emailed to you.

Who the data is shared with

We do not sell personal data

We do not sell or rent your personal data, and we do not use it for advertising. Data is shared only as far as needed with the service providers below, who perform technical functions for us. Some of them process data outside Indonesia.

Service providers involved

  • Google

    Purpose
    Signing in with a Google account
    Data involved
    Name, email address, profile photo
  • Vercel

    Purpose
    Website hosting, storage of uploaded photos and images, cookie-free visit statistics
    Data involved
    IP address (temporarily), photos and images you upload
  • Neon

    Purpose
    Database
    Data involved
    All the account and membership data described above
  • Zoho ZeptoMail

    Purpose
    Sending email
    Data involved
    Email address, name, member number, and the attached membership card
  • Telegram

    Purpose
    Internal notifications to the board
    Data involved
    Applicant’s name, member number, and batch; records of board actions
  • Anthropic

    Purpose
    Automatic translation of articles
    Data involved
    Text of published articles (not account data)

Cookies

Only the necessary ones

We use only the cookies the site needs to work: your language choice (diaz_locale), and a session cookie set after you sign in. We do not use advertising cookies or third-party trackers.

How long data is kept

  • Sign-in sessions end automatically after seven days.
  • Account and membership data is kept while your account or membership is active and as long as needed for the organization’s archive.
  • Emergency info is kept until you delete it.
  • Historical records that name a member as a matter of historical fact may be kept as part of the archive; you have the right to object.

Your rights

Under the Personal Data Protection Law

You have the right to:

  • know about and request a copy of the personal data we hold about you;
  • correct data that is wrong or incomplete — you can edit your profile and emergency info yourself after signing in, and changes to membership data are requested through your account;
  • ask for your data to be deleted or for its processing to stop;
  • withdraw consent you have given, for example by deleting your emergency info or by no longer receiving new-article notices;
  • object or complain about how we process your data.

Make your request through the Contact page. To protect your data we may ask for proof of identity first, and we will respond within a reasonable time.

Security

The connection to the site is encrypted (HTTPS). Access to membership data is limited by role — guest, member, board, and superadmin — and board actions on data are reported to the other board members.

No system is completely immune. If a breach affects personal data, we will notify those affected as required by applicable rules.

Children

This site is not intended for children without the supervision of a parent or guardian. If you are a parent or guardian and know that your child has given personal data without your consent, contact us so it can be deleted.

Changes to this policy

We may update this policy as our services or the rules change. The latest version is always on this page, with the update date at the top.

Contact us

Questions or requests about personal data can be sent through the Contact page, or directly to our secretariat at Jl. Raya Tlogomas No. A1, Terminal Landungsari, Kec. Dau, Kabupaten Malang, Jawa Timur 65144.

Open the Contact page