Legal information
Privacy Policy
We ask only for the data we need, tell you what it is used for, and let you manage it. This page explains everything in plain language.
Last updated:
Who we are
Data controller
This website is run by Perkumpulan Pendaki, Penjelajah dan Pecinta Alam “DIAZ” (“DIAZ”, “we”), an outdoors organization based in Malang, East Java. In this policy, DIAZ is the party that decides why and how your personal data is processed.
Secretariat: Jl. Raya Tlogomas No. A1, Terminal Landungsari, Kec. Dau, Kabupaten Malang, Jawa Timur 65144.
The data we collect
Depending on what you do on the site
You decide how much you share. Here is what we collect, by activity.
- Just reading
- You do not need an account to read this site, and we do not store personal data about you. Visits are counted in aggregate, without cookies and without tracking you across sites. Our hosting provider processes your IP address temporarily so pages can be served and protected.
- Signing in with Google
- The name, email address, and profile photo of your Google account. We never receive your password. Each sign-in records your IP address and browser type, and ends automatically after seven days.
- Commenting
- The text of your comment together with your name and profile photo. Comments appear publicly under the article.
- Membership verification request
- Full name, member number, eagle name, month and year of joining, batch, place and date of birth, current address, and phone number. We match it against the membership archive before approving.
- Membership records
- Once approved, the board manages your membership status, official photo, board position, and archive notes.
- Emergency info (optional)
- Blood type, emergency contact, allergies, medical conditions, medications, and insurance number. Health data is specific personal data, so we store it only if you enter it yourself and explicitly consent. You can delete it at any time.
What the data is used for
And the legal basis
- Managing your account and access rights on the site.
- Verifying membership and issuing the Digital Membership Card, including emailing it to you.
- Showing the author’s name on articles and your name on comments.
- Sending email about your account or membership, and a notice when a new article is published.
- Telling the board, through a messaging app, when a request or data change needs review.
- Keeping the site secure, for example by limiting comments posted repeatedly in a short time.
- Translating articles automatically so they can be read in Indonesian and English.
We process data on the basis of your consent (when you choose to sign in, submit a form, or enter emergency info) and the organization’s legitimate interest in managing membership, in line with Indonesia’s Personal Data Protection Law (Law No. 27 of 2022).
Who can see it
What is public and what is not
Not all of your data is visible to everyone.
- Public to anyone
- Comments together with your name and photo. The name, photo, member number, and eagle name of board members on the Structure page. Author pages for people who write articles (name, photo, member number, eagle name, batch, month and year of joining, field name, position). The verification page linked from the QR code on the membership card (name, member number, eagle name, status, batch, year of joining, photo). Some members’ names also appear as historical fact on the Timeline.
- Only for signed-in members
- Members’ phone numbers and email addresses in the member directory.
- Only for you and the authorized board
- Date of birth, address, and verification request data can be seen by the board members who review requests. Emergency info is not shown on public pages or in the directory; it appears only on the back of your own card, including on the card files emailed to you.
How long data is kept
- Sign-in sessions end automatically after seven days.
- Account and membership data is kept while your account or membership is active and as long as needed for the organization’s archive.
- Emergency info is kept until you delete it.
- Historical records that name a member as a matter of historical fact may be kept as part of the archive; you have the right to object.
Your rights
Under the Personal Data Protection Law
You have the right to:
- know about and request a copy of the personal data we hold about you;
- correct data that is wrong or incomplete — you can edit your profile and emergency info yourself after signing in, and changes to membership data are requested through your account;
- ask for your data to be deleted or for its processing to stop;
- withdraw consent you have given, for example by deleting your emergency info or by no longer receiving new-article notices;
- object or complain about how we process your data.
Make your request through the Contact page. To protect your data we may ask for proof of identity first, and we will respond within a reasonable time.
Security
The connection to the site is encrypted (HTTPS). Access to membership data is limited by role — guest, member, board, and superadmin — and board actions on data are reported to the other board members.
No system is completely immune. If a breach affects personal data, we will notify those affected as required by applicable rules.
Children
This site is not intended for children without the supervision of a parent or guardian. If you are a parent or guardian and know that your child has given personal data without your consent, contact us so it can be deleted.
Changes to this policy
We may update this policy as our services or the rules change. The latest version is always on this page, with the update date at the top.
Contact us
Questions or requests about personal data can be sent through the Contact page, or directly to our secretariat at Jl. Raya Tlogomas No. A1, Terminal Landungsari, Kec. Dau, Kabupaten Malang, Jawa Timur 65144.
Open the Contact page