Kainos editorial journal · 2026
Privacy policy · updated 5 October 2026
1. Scope
This policy explains how Kainos handles information when readers visit, contact, or subscribe. It applies to the website and editorial correspondence managed from Jakarta. It does not replace advice from a qualified privacy professional for a particular situation.
2. Information collected
We may receive a name, email address, message content, and records needed to respond. Basic technical logs may include browser type, approximate region, requested page, and time. We do not request health records, identity documents, payment details, or biometric information.
3. Legal basis
We use information to respond to a request, provide a newsletter where consent is given, protect the site, and understand aggregate readership. Consent may be withdrawn by contacting the desk. Withdrawal does not affect processing that occurred before it.
4. Retention
Contact correspondence is normally retained for 24 months after the last meaningful exchange. Newsletter subscription data is retained until unsubscribe and removed within 30 days. Security logs may be retained for 90 days unless a longer period is reasonably needed to investigate abuse.
5. Service providers
Limited information may be processed by hosting, email delivery, analytics, and security providers acting under contractual instructions. Providers may access only what their service requires. Kainos does not sell reader data.
6. Cookies
The site uses a cookie choice record named cookieChoice, stored for up to 180 days, and essential session mechanisms where hosting requires them. Optional analytics cookies are used only where permitted and are described in cookies.php.
7. International transfers
Some service providers may process data outside Indonesia. We seek contractual safeguards and reasonable security controls for those transfers. Readers may contact us for a general description of the relevant safeguards.
8. Your rights
Subject to applicable law, you may request access, correction, deletion, restriction, or a copy of information. Send a clear request to the Kainos desk with enough context to locate it. We may verify identity proportionately before responding.
9. Complaints
Questions should first be sent to the address listed on contact.php. We aim to acknowledge a request within 7 business days and provide a substantive response within 30 days. You may also contact an appropriate Indonesian data protection authority or legal adviser.
10. Changes
This policy was reviewed on 5 October 2026. Earlier editorial versions are kept in an internal change record. Material changes will be dated on this page and, where appropriate, noted in a newsletter.
11. Contact
Kainos, Jl. Kebon Jeruk Raya No. 120, RT.005/RW.007, Kebon Jeruk, Jakarta Barat, DKI Jakarta 11530, Indonesia. Phone +62 21 7891 0345.
For practical purposes, a request may also include the date and approximate time of contact, the page from which a form was submitted, and the information needed to verify that the person making a request controls the relevant email address. We use these details to prevent accidental disclosure and to keep a reliable correspondence history. We do not use contact messages to create advertising audiences. Requests are normally acknowledged within 7 business days and completed within 30 days, or we explain why a reasonable extension is needed. Rights may include access, correction, deletion, restriction, objection where applicable, and withdrawal of consent under Indonesian law and other applicable privacy rules.
Our operational processors may include Vercel for hosting and delivery, an email provider for newsletter distribution, and privacy-conscious analytics or security services configured for limited collection. A provider receives only the fields required for its task and must apply its own security controls. International processing is assessed contractually and operationally; where a transfer is necessary, Kainos considers confidentiality, access controls, and the provider's published safeguards. Policy changes are recorded by date, with this version reviewed on 5 October 2026.
For clarity, this scope includes ordinary page requests, contact messages, newsletter administration, consent records, and security review. It does not mean that Kainos creates a sensitive profile from the subjects a reader chooses to open. A contact message may be reviewed by the editorial or site administration desk only when needed to answer the request, investigate abuse, or correct an operational error. If a message contains information that was not requested, it is handled only as long as reasonably necessary and may be removed from the working mailbox after triage. This approach is intended to align collection with the purpose described at the point of contact.
Technical records can include an IP address or similar network identifier in hosting logs, even where Kainos does not use it to identify a person by name. Such records help diagnose failed delivery, unusual request volume, broken links, and security events. Approximate region is used for aggregate reporting and is not treated as a precise location record. We do not ask readers to upload identity documents, health records, financial details, or biometric material through ordinary forms. If a reader sends such material voluntarily, Kainos may redact or securely delete it rather than placing it into an editorial profile.
For newsletter delivery, the lawful basis is the reader's affirmative request and the service relationship created by that request. Operational security processing is based on the legitimate need to protect the website and correspondence systems, subject to applicable Indonesian requirements and reasonable balancing. Aggregate readership measurement is configured to reduce direct identification and may be disabled where consent is required. A reader can unsubscribe through the link in a newsletter or contact the desk, and the request is normally recorded only long enough to prevent an unwanted re-subscription. Rights requests should include the relevant email address and a clear description; Kainos may ask for proportionate verification before disclosing or changing information.
Hosting and delivery may involve Vercel or comparable infrastructure, an email delivery provider, and a security or measurement provider. These providers are selected for the limited service they perform and are not authorised to use Kainos correspondence for unrelated advertising. Where a provider is outside Indonesia, Kainos considers contractual confidentiality, access permissions, encryption in transit, and the provider's security documentation. A transfer may therefore be operational rather than a sale or disclosure to an unrelated party. Readers can ask which category of provider handled a particular request without needing to provide additional sensitive information.
Requests are acknowledged within 7 business days where a working email address is available. Kainos aims to complete a straightforward access, correction, unsubscribe, or deletion request within 30 days, although a complex request may require a reasonable extension with an explanation. Contact details remain: Jl. Kebon Jeruk Raya No. 120, RT.005/RW.007, Kebon Jeruk, Jakarta Barat, DKI Jakarta 11530, Indonesia, phone +62 21 7891 0345. This policy was reviewed on 5 October 2026; a material revision will identify its effective date and a short description of the change.
Data protection contact
For privacy questions, contact the Kainos privacy desk at Jl. Kebon Jeruk Raya No. 120, RT.005/RW.007, Kebon Jeruk, Jakarta Barat, DKI Jakarta 11530, Indonesia, or +62 21 7891 0345. Kainos does not appoint a separate statutory DPO; the privacy desk coordinates requests with the responsible site administrator and will identify the appropriate contact when a request requires specialist review.
Named service categories currently include Vercel for hosting and delivery, the configured transactional or newsletter email provider for correspondence, and the configured analytics or security provider for aggregate measurement and abuse prevention. The active provider configuration is reviewed when a service changes, and readers may ask which provider category handled a specific request.