Effective 5 October 2026

Privacy policy

This policy explains how Gorland handles information when readers visit an editorial website operated from Jakarta, Indonesia. It applies to pages, contact messages, correction requests, and ordinary technical records. Gorland is an informational publication and does not ask readers to create an account. We aim to collect only what is reasonably needed to operate, secure, and improve the publication. The document is organised so that each numbered section addresses one practical question, from what we collect to how a reader can exercise a right, rather than presenting a single undivided block of legal language. It is reviewed at least once a year and whenever a material change is made to the contact form, the cookie banner, or the hosting arrangement described in Section 6. Where this policy refers to Indonesian law, the primary reference is Law No. 27 of 2022 concerning Personal Data Protection, which has been in force since its transitional period concluded in October 2024. Readers accessing the site from outside Indonesia should also note Section 7 on international transfers, since routine hosting and security functions may involve infrastructure located in more than one country. For a plain-language summary of the storage technologies referenced throughout this policy, see cookies.php, which lists each value by name and retention period.

1. Scope and controller

Gorland is the responsible publication for the processing described here. The contact address is Jalan Gatot Subroto Kav. 36, Kuningan, Jakarta Selatan, 12950, Indonesia. This document applies to visitors in Indonesia and international readers who access the English-language site. It does not govern third-party pages reached through an external link. Gorland does not operate as a registered financial or healthcare provider, and the processing described in this document is limited to the ordinary operation of an editorial website rather than any regulated service. Where a reader submits a message through contact.php, Gorland acts as the party deciding why and how that message is used, which is the role Indonesian and comparable international frameworks describe as a data controller. A separate entity may act as a processor on Gorland's instructions, for example by hosting the site or relaying email, and Section 6 names the categories of processor involved. This scope section does not cover information a reader discloses directly to a third party, such as a social media platform used only to share a link to an article. Readers who are uncertain whether a particular interaction falls inside or outside this policy may ask the editorial desk for clarification before sending further information.

  • (a) Applies to: the public pages of the Gorland website and its subpages.
  • (b) Applies to: messages sent via the contact form or to the published email address.
  • (c) Does not apply to: third-party advertising networks, analytics vendors' own privacy notices, or any external site linked from an article.

2. Information collected

Technical logs may include IP address, browser family, device type, requested page, referring page, and time of access. If a reader contacts us, we receive the name, email address, message, and any information voluntarily included. We do not intentionally request health records, identity documents, payment details, or precise location. These technical logs are generated automatically by the web server software and are not cross-referenced with a reader's name unless the same person separately sends a message through the contact form. A browser family such as Chrome, Safari, or Firefox is recorded only as a general category, not as a unique fingerprint, and Gorland does not deploy device-fingerprinting scripts to re-identify a returning visitor. When a message is submitted, the optional subject field and any attachment description are also retained for as long as the correspondence file is open. A reader who voluntarily mentions a health condition in a message does so outside what this policy requests, and Section 10 explains how that kind of information is handled if it is received. No cookie or script on Gorland is configured to capture precise GPS coordinates, and IP-based location data, where it appears at all, is resolved only to city or country level for basic security review.

  • (a) Collected automatically: IP address, timestamp, page requested, referrer, device and browser category.
  • (b) Collected only if submitted: name, email address, free-text message, optional phone number.
  • (c) Never requested: payment card data, government identity numbers, precise GPS location, biometric data.

3. Purpose and legal basis

We use technical information to deliver pages, detect abuse, and maintain security. We use contact information to answer a message, assess a correction, or consider a topic suggestion. Where Indonesian law applies, processing is based on consent, legitimate operational interest, contract-like steps requested by the sender, or a legal obligation as appropriate. In practice, most technical processing relies on a legitimate interest in keeping the publication available and resistant to automated abuse, an interest that is balanced against the limited and non-identifying nature of the data involved. Consent is the relevant basis for the optional cookie categories described in cookies.php, and that consent can be withdrawn at any time by changing the stored choice or clearing browser storage. When a reader sends a correction request, processing the message is necessary to take the steps the reader has asked for, which mirrors the contract-like basis recognised for actions requested by the data subject. A legal obligation basis would apply only in a narrow situation, such as responding to a lawful request from a competent Indonesian authority. Gorland does not use any of these bases to justify sending unsolicited marketing email to a reader who has only submitted a correction or a factual question.

  • (a) Legitimate interest: fraud and abuse prevention, basic traffic review, page delivery.
  • (b) Consent: optional analytics cookies, where introduced in future.
  • (c) Requested-action basis: responding to a correction, topic suggestion, or accessibility report.
  • (d) Legal obligation: responding to a lawful authority request.

4. Retention

Routine security logs are normally retained for up to 90 days. Editorial correspondence is retained for up to 24 months after the last meaningful exchange, unless a longer period is necessary to document a correction or resolve a dispute. Deletion may occur sooner when the information no longer serves its stated purpose. A 90-day window for routine security logs reflects a practical balance between being able to investigate a recent incident, such as a spike in automated traffic, and avoiding the indefinite accumulation of IP-level data. Correspondence tied to a published correction is treated differently from an ordinary question, because the underlying article may be revisited by an editor months later, so the 24-month figure is a minimum rather than a fixed deletion date in that specific case. Where a complaint or dispute is still open at the 24-month mark, the relevant file is retained only until the matter is concluded and is then scheduled for deletion within a further 90 days. Backup copies of the site, which exist mainly for disaster-recovery purposes, may persist for a short additional period after a live deletion before they are themselves overwritten in the ordinary backup cycle. Gorland does not retain contact information merely because it might become useful for an unrelated future purpose.

  • (a) Security and server logs: up to 90 days.
  • (b) Ordinary contact messages: up to 24 months after the last reply.
  • (c) Correction-related correspondence: retained alongside the related editorial record, reviewed at each anniversary of the correction.
  • (d) Backup media: removed in the next scheduled backup rotation after a live deletion, normally within 30 to 60 days.

5. Cookies

The site uses a cookie-choice value named cookieChoice to remember whether a visitor selected Accept or Reject; it lasts for 180 days. Essential session-like technical storage may expire when the browser closes. If optional analytics are enabled in a future release, their names, purposes, and lifespans will be listed on cookies.php before use. The cookieChoice value stores only the word accepted or rejected and a timestamp; it does not contain a reader's name, email address, or browsing history. Because it is a first-party value set directly by Gorland rather than by an advertising network, it is not shared with or readable by an unrelated third-party domain. A small number of short-lived technical values, such as a navigation-state flag used by the mobile menu, are classed as strictly necessary and are exempt from the accept-or-reject choice because the site could not function correctly without them. If a future version of the site introduces audience-measurement analytics, Gorland intends to run that category only after a reader has actively accepted it, consistent with the consent-first approach already used for the existing banner. The full, current list of storage names, first-party or third-party status, and retention periods is kept on cookies.php rather than duplicated here, so that a single page remains the authoritative reference as the list changes.

  • (a) Strictly necessary: menu state and basic security tokens, exempt from the accept-or-reject choice, expiring at the end of the session or within 24 hours.
  • (b) Preference: cookieChoice, 180 days, first-party.
  • (c) Optional analytics: none currently active; any future addition will be named individually on cookies.php.

6. Processors

Hosting, security, email delivery, and aggregated measurement may be provided by carefully selected processors. They receive only the information needed for their service and must follow confidentiality and security duties. Gorland does not sell contact lists or use reader messages for unrelated advertising. A hosting provider, for example, receives the technical logs and page files needed to serve the site but does not receive the content of a reader's contact message unless that message is stored on the same infrastructure as part of ordinary operation. An email-delivery provider used to relay a reply from the editorial desk sees the message content necessary to deliver it but is contractually limited from using that content for its own marketing. Where Gorland engages a processor, the arrangement is expected to include confidentiality, data-security, and deletion obligations consistent with the relationship Indonesia's Personal Data Protection Law describes between a controller and a processor. Gorland reviews a processor's publicly available security documentation before relying on it for a function that touches reader information, and it does not add a new processor to a core function without updating this section at the next review. No processor is authorised to combine Gorland's logs with data from unrelated clients to build a cross-site advertising profile of a reader. Gorland's website hosting and content-delivery infrastructure is provided by Vercel Inc., a United States-based hosting company, which stores page files and server logs on its infrastructure and does not have separate access to contact-form content beyond what is needed to operate the site.

  • (a) Hosting and infrastructure processor: receives server logs and site files.
  • (b) Email-delivery processor: receives message content only when relaying a reply.
  • (c) Security or anti-abuse processor, if used: receives IP addresses and request patterns only.

7. International transfers

Some infrastructure providers may process technical records outside Indonesia. Before such processing, Gorland considers contractual safeguards, access controls, and the provider's security documentation. Readers may contact the desk to ask which category of provider is relevant to a particular request. A transfer of this kind typically occurs because a hosting or security provider operates data centres in a small number of regional locations rather than exclusively within Indonesia, which is a common pattern for smaller editorial publications that do not operate their own infrastructure. Where Indonesia's Personal Data Protection Law requires an adequacy assessment, a contractual clause, or another recognised safeguard for a transfer outside the country, Gorland expects its provider agreements to reflect that requirement rather than leaving it unaddressed. The categories of information most likely to be affected are the routine technical logs described in Section 2, since Gorland does not operate a database of reader profiles that would otherwise need to move between jurisdictions. A reader who wants to know, in general terms, which regions a given function is hosted in may send that specific question to the contact address, and the desk will answer to the extent that doing so does not compromise site security. This section will be updated if Gorland adopts a materially different hosting arrangement.

  • (a) Likely transfer scenario: server logs processed in a regional data centre used by the hosting provider.
  • (b) Safeguard expected: contractual data-protection terms consistent with Indonesian cross-border transfer requirements.
  • (c) Not transferred: reader correspondence is answered from Indonesia and is not routinely exported to a third country.

8. User rights

Subject to applicable law, a reader may ask for access, correction, deletion, restriction, or information about processing. Requests should identify the relevant email address and be sent to [email protected] or +62 857 2309 4185. We may need to verify the request without asking for unnecessary identity documents. An access request can be answered, in most cases, by confirming what is held against the email address or name the reader provides, since Gorland does not maintain a searchable account system that would require a password reset or login step. A correction request under this section is distinct from the editorial correction process described on corrections.php: this section concerns fixing a reader's own personal details, such as an email address recorded incorrectly in a reply, while corrections.php concerns factual errors in published articles. Gorland aims to acknowledge a rights request within 5 business days and to provide a substantive response within 30 calendar days, extending that period only where the request is unusually complex and after explaining the delay to the reader. Verification is proportionate to the request: confirming the sending email address is normally sufficient, and Gorland will not ask a reader to send a copy of a national identity card or passport for a routine deletion request. If a request cannot be completed, for example because a log has already been deleted under the retention schedule in Section 4, the reader will be told rather than left without a response.

  • (a) Access: confirmation of what is held, usually within 30 days.
  • (b) Correction: updating an email address or contact detail on file.
  • (c) Deletion: removing a correspondence record once any open matter is resolved.
  • (d) Restriction: pausing further use of a record while a complaint is under review.

9. Security

Gorland uses access limitation, reasonable retention controls, encrypted transport where available, and editorial confidentiality practices. No internet transmission is guaranteed to be risk-free. If a security incident materially affects personal information, we will assess notification duties and communicate through an appropriate channel. Access to the systems that store contact correspondence is limited to the small editorial team responsible for responding to readers, rather than being available to every contributor who writes for the site. Transport encryption, typically HTTPS, protects a message in transit between a reader's browser and Gorland's server, though the phrase "where available" acknowledges that a third-party link a reader follows away from the site is outside Gorland's control. Editorial confidentiality practice means that a correspondence file is not shared with a contributor researching an unrelated article unless the reader's own message is directly relevant to a correction under review. If an incident were to expose personal information in a way that creates a meaningful risk to a reader, Gorland would assess the notification duties under the Personal Data Protection Law, which can include informing both the affected individual and the relevant supervisory authority within the timeframe the law specifies. Notification, where required, would describe what happened, what information was involved, and what a reader can reasonably do in response, rather than being delayed until a full investigation is complete.

  • (a) Technical measure: HTTPS transport encryption for page and form delivery.
  • (b) Organisational measure: limited internal access to correspondence files.
  • (c) Incident response: documented assessment within days of discovery, not weeks.

10. Children and sensitive information

The publication is intended for adults and does not knowingly build profiles of children. Please do not send diagnoses, medical records, or other sensitive health material through the contact form. If such information is received unnecessarily, it will be restricted and deleted according to the incident and retention assessment. Gorland's subject matter, athletic physiology and training for men aged 35 and above, is not designed or marketed to attract a child audience, and the site does not include features such as account creation or public comments that would typically collect a child's personal information. If a message indicates it was sent by someone under the age of majority in their jurisdiction, the editorial desk will respond only to the extent necessary to address the message and will not retain the correspondence longer than needed to do so. Sensitive categories under Indonesian law include health data, biometric data, and genetic data, among others, and Gorland does not ask for any of these through its ordinary contact channel. On the rare occasion a reader includes such detail voluntarily, for example describing a medical history while asking a general training question, the desk will redact or delete the sensitive portion once it is no longer needed to understand the question being asked. This approach reflects the heightened protection Indonesian law gives to specific categories of personal data rather than treating all information as equivalent.

  • (a) Not requested: diagnosis, medication names, lab results, biometric identifiers.
  • (b) If volunteered unnecessarily: redacted or deleted once the underlying question is answered.
  • (c) Minors: correspondence handled narrowly and not retained beyond the immediate reply.

11. Complaints

Readers should first contact the Gorland desk so we can understand and address the concern. A complaint should include the relevant page, date, and desired remedy where possible. Readers may also contact the competent Indonesian authority or another regulator available in their place of residence. Gorland aims to acknowledge a complaint within 5 business days of receipt and to provide either a resolution or a clear explanation of next steps within 30 calendar days, which mirrors the response period described in Section 8 for rights requests. A complaint that concerns the handling of personal information specifically, as opposed to an editorial disagreement, is logged separately so that it can be reviewed against this policy rather than against general editorial standards. If a reader in Indonesia remains unsatisfied after contacting Gorland directly, the relevant supervisory body under the Personal Data Protection Law is the ministry responsible for communications and digital affairs, which maintains a channel for data-protection complaints. A reader located outside Indonesia may instead have access to a local data-protection authority in their own country, depending on how that authority's jurisdiction is defined, and Gorland will not treat use of that channel as a breach of any agreement with the reader. Keeping a dated record of the original message helps both sides track the complaint through to its resolution.

  • (a) Step 1: contact [email protected] or +62 857 2309 4185 with the page, date, and desired outcome.
  • (b) Step 2: acknowledgement within 5 business days.
  • (c) Step 3: substantive response within 30 calendar days.
  • (d) Step 4: escalation to the competent Indonesian authority or a reader's local regulator if unresolved.

12. Changes

On 5 October 2026, this policy was reviewed for the current site structure, cookie banner, and contact process. Future revisions will show a new date and describe material changes near the beginning. Continued use after a revision does not remove rights that apply under mandatory law. The 5 October 2026 review confirmed that the cookie categories, retention periods, and contact routes described throughout this document matched what the site actually does at that date, rather than being a cosmetic date change. A material revision, such as adding a new analytics provider or changing a retention period, will be flagged in a short changelog note at the top of the page so a returning reader does not have to compare the entire document line by line. A non-material revision, such as correcting a typographical error or updating a cross-reference to another page, will update the review date without a separate changelog note. Gorland keeps an internal copy of each prior version of this policy for its own records, and a reader may ask whether a specific provision has changed since an earlier date they recall visiting. Because certain rights, such as the right to lodge a complaint with a supervisory authority, exist independently of this document under the Personal Data Protection Law, no revision to this policy can reduce a right a reader already holds under mandatory legislation.

  • (a) 5 October 2026: initial structured review of the current policy.
  • (b) Future material change: noted with a dated changelog line at the top of the page.
  • (c) Future non-material change: review date updated without a separate note.