Privacy policy

Effective 5 October 2026. This policy explains how Navlin, operating from Jalan Sudirman No. 18, Senayan, South Jakarta 12190, Indonesia, handles information connected with this website. It applies to readers, contributors, and people who contact the reader desk. It does not replace any rights provided by Indonesian law.

1. Scope and responsibility

Navlin is responsible for the editorial website and reader communications described here. We collect only information needed to operate, secure, measure, and respond to the service. We do not sell personal information. Questions may be sent to the address or phone number published on this site.

2. Information you provide

A contact message may include your name, email address, telephone details, and the content of your enquiry. You decide what additional context to include. Please do not send medical records or emergency information. We use the information to understand and answer the request.

3. Automatically recorded information

Servers may record an IP address, browser type, device category, requested page, timestamp, and referring page. These records support security and basic technical troubleshooting. They are not used to infer sensitive health characteristics. Logs are normally retained for up to 90 days.

4. Legal basis and purpose

We process contact information to respond to a request and operate the service. Limited measurement is based on consent where a non-essential analytics cookie is offered. Security processing is based on legitimate operational interest. We do not make decisions about people solely by automated means.

5. Retention periods

Reader correspondence is retained for 24 months after the last meaningful exchange, unless a longer period is needed for a legal complaint. Suppression requests are retained as a minimal record for five years. Security logs are retained for 90 days. Aggregated statistics may remain when they no longer identify a person.

6. Service providers

Hosting, email, security, and analytics providers may process limited information on our instructions. Providers receive only the data needed for their function. Contracts require confidentiality and appropriate safeguards. We do not permit providers to use Navlin enquiries for their own advertising.

7. International transfers

Some technical providers may process data in countries outside Indonesia. Where this occurs, we assess contractual and organisational safeguards appropriate to the service. A transfer does not change the purposes listed in this policy. Contact us if you need information about a particular provider.

8. Your rights

You may ask for access, correction, deletion, restriction, or a copy of information you supplied. You may withdraw consent for optional analytics at any time. Identity checks may be required to protect another person’s information. We aim to respond within 30 days.

9. Children and sensitive information

Navlin is intended for adults and is not directed to children. We do not intentionally request health diagnoses, biometric records, or government identity numbers. If you send sensitive information, we may delete it rather than retain it. Parents or guardians can contact the reader desk about an accidental submission.

10. Complaints and contact

Begin by contacting Navlin at Jalan Sudirman No. 18, Senayan, South Jakarta 12190, Indonesia or +62 21 7123 8945. Explain the request, relevant page, and preferred response channel. We will investigate in good faith and keep a record of the outcome. You may also contact the Indonesian authority or another competent regulator where applicable.

11. Security

We use access controls, encrypted transport where available, limited staff access, and routine review of service accounts. No internet transmission can be promised completely secure. We investigate suspected incidents and notify affected people where required. Do not send secrets through a public contact form.

12. Changes

This policy was reviewed and published on 5 October 2026. Earlier material wording was consolidated on 12 August 2026. Future changes will show a new date at the top of this page. A material change will be highlighted for a reasonable period.

Practical handling details

Navlin receives information through ordinary website interactions, including contact forms, email correspondence, telephone enquiries, and technical requests. A message is accessible only to people who need it to respond, maintain security, or manage the website. We do not request information that is unrelated to the reader desk. If a message contains more detail than necessary, it may be minimised in the working record.

Contact records are generally kept for 24 months after the last meaningful exchange, while server security logs are normally kept for up to 90 days. Consent records may be retained for 180 days so that a previously recorded choice can be respected. Where a dispute, legal request, or security investigation is active, relevant records may be held until the matter is closed and the applicable review period has passed. Records are then deleted, anonymised, or securely destroyed using ordinary administrative controls.

Navlin may use service providers for hosting, form delivery, email routing, security monitoring, analytics, and website maintenance. Current processor categories and named companies are Vercel Inc. for hosting and deployment, Resend Inc. for transactional email where enabled, and Plausible Analytics OÜ for privacy-focused measurement where enabled. These providers receive only the information required for their stated service and remain subject to their own security and privacy documentation. These providers act on instructions, receive only the information needed for their service, and are expected to maintain confidentiality and appropriate safeguards. Current categories include the website host, transactional email provider, and privacy-conscious analytics provider. We do not permit providers to use reader correspondence for unrelated advertising.

Some providers may process information outside Indonesia. Where that occurs, Navlin considers contractual safeguards, access controls, data minimisation, and the provider’s published security commitments. International processing does not change the purposes described in this policy. Readers may ask which provider category handled a particular enquiry without requesting another person’s information.

You may ask for access, correction, deletion, restriction, or clarification about information connected with your enquiry. Send a request to the reader desk using the contact details on this website and include enough information to identify the request without sending unnecessary sensitive material. Navlin normally acknowledges a rights request within 7 calendar days and aims to provide a substantive response within 30 calendar days. A request may be extended where it is complex, and the reason will be explained.

For identity and security, we may ask for confirmation from the email address used to contact us or other reasonable verification. We will not disclose personal information to a person whose authority cannot be established. If a request cannot be completed, we will explain the relevant reason and identify any available complaint route. You may also contact the Indonesian data protection authority or another competent regulator where you consider that local law provides that option.

Changes and contact

This policy was reviewed on 5 October 2026. Earlier operational notes are superseded by the effective version displayed on this page. Material changes will be described near the top of the page, with the new effective date, before the revised practices apply. Questions may be sent to Navlin, Jalan Sudirman No. 18, Senayan, South Jakarta 12190, Indonesia, or by phone at +62 21 7123 8945.

For clarity, this policy applies to Navlin’s public website, its contact channels, ordinary newsletters if offered, and related administrative records. It does not govern an external website linked from Navlin, a device account, or a service that has its own privacy notice. Technical information may include an IP address, browser type, approximate region, requested page, referring page, and security events. These details are used for availability, abuse detection, aggregate readership measurement, and troubleshooting, not to infer sensitive characteristics about a reader.

The legal basis for handling an enquiry is ordinarily the reader’s request for a response or the steps needed to provide that response. Security logs are retained for the legitimate operational purpose of protecting the service, while optional measurement is based on consent where consent is required. A reader may withdraw optional consent without affecting earlier lawful processing, although withdrawal cannot undo a record that was already used to answer a question. We retain only the minimum working context needed to explain what was done.

Requests concerning another person require evidence of authority, such as a written authorisation or a formally recognised representative relationship. A deletion request may be limited where a record must be retained for legal compliance, fraud prevention, dispute handling, or the establishment of a legal position. In those cases, access is restricted and the retained material is deleted when the reason ends. These safeguards are intended to protect both the requesting reader and people whose information may appear in correspondence.

Navlin may use hosting, email delivery, form processing, security monitoring, and analytics providers, but does not sell contact messages or create advertising audiences from them. Provider access is limited by account permissions, contractual instructions, and operational need. Where a provider acts outside Indonesia, Navlin considers transfer safeguards and records the relevant processing category. A reader may request a general description of the processor involved without receiving confidential security details or another person’s data.

The policy was reviewed on 5 October 2026, following an earlier review on 15 May 2026 that confirmed the same contact and retention approach. The next review will consider changes in the site’s forms, analytics configuration, applicable Indonesian requirements, and reader feedback. A material change will show the effective date and a plain-language summary near the policy introduction. Questions remain welcome at Jalan Sudirman No. 18, Senayan, South Jakarta 12190, Indonesia, or +62 21 7123 8945.