Privacy policy
Evance, Jalan Anggrek Raya No. 15, Kemang, Jakarta Selatan 12730, Indonesia, respects the privacy of readers and contacts. This document explains how information is handled when you visit our editorial website or communicate with us. It applies to Evance pages, forms, newsletters if introduced, and ordinary support correspondence. It does not govern third-party websites reached through links.
This policy is written with Indonesia’s Personal Data Protection Law (Law No. 27 of 2022) and related implementing rules in mind, and it is also intended to be understandable to readers visiting from other countries. It covers information handled online, by post and by telephone. It does not cover information you publish yourself on social platforms or in public forums, even if you mention Evance there. Where an external page asks for your details, that page's own privacy notice applies.
1. Scope and responsibility
Evance acts as the publisher and responsible contact for this website. We collect only information reasonably connected with providing, securing and improving the service. We do not sell personal information or build advertising profiles from reading habits. Questions may be sent to the published phone number or postal address.
In practical terms, the publisher decides why and how contact details are used, and it is the publisher who answers requests about them. Editorial staff and a small number of administrative contributors can see correspondence, and access is limited to people who need it to reply or to maintain the site. A visit to an article page on its own does not require you to identify yourself. If responsibility is ever shared with another organisation, this page will be updated to say so before the arrangement begins.
- (a) Publisher and contact point: Evance, Jalan Anggrek Raya No. 15, Kemang, Jakarta Selatan 12730, Indonesia.
- (b) Telephone for privacy questions: +62 817 9345 1820, during ordinary Jakarta business hours (UTC+7).
- (c) Purposes covered: delivering pages, answering messages, securing the site and planning editorial topics.
2. Information you provide
A contact form may collect your name, email address and message. Your message can include information you choose to provide, so please avoid sending medical records, identity documents or confidential material. Phone enquiries may be noted in a basic correspondence record. We do not require an account to read the site.
The contact form fields are limited to what is needed to reply: a name, a reachable email address, a subject line and the message itself. A phone number is optional and is used only if you ask to be called. If you send an attachment or a link, it is treated as part of the message and is subject to the same retention period. A reader who writes about a personal training situation should remember that the text may be read by more than one member of staff.
- (a) Required: name, email address and message text.
- (b) Optional: telephone number and any context you decide to add.
- (c) Not requested: government identity numbers, bank or card details, medical records or photographs of other people.
3. Technical information
Servers may receive an IP address, browser type, device information, requested URL and time of request. This information helps deliver pages, detect abuse and investigate failures. Access logs are normally retained for 30 days and then deleted or aggregated, unless a security investigation requires a documented extension.
Technical records are used for operational purposes, such as noticing a sudden spike of automated requests or finding the cause of a page that fails to load on a particular browser. They are not used to follow an individual reader from one visit to the next, and they are not matched with contact-form content. An IP address is treated as personal information because it can sometimes be linked to a subscriber account. If a log extract must be kept beyond 30 days for a security investigation, the reason, the person who approved it and the new deletion date are written down. Extracts kept in this way are normally deleted within 90 days of the investigation closing.
4. Legal bases
For Indonesian operations, processing is based on providing a requested communication, legitimate interest in website security and, where applicable, consent. We use the minimum information needed for each purpose. Withdrawal of optional consent does not affect processing already completed lawfully, but it will stop the optional activity going forward.
Replying to a message you have sent is based on your request, because the reply cannot be written without reading what you wrote. Keeping the website secure rests on a legitimate interest that is balanced against your privacy: logs are short-lived and used only for protective purposes. Consent is relied on for optional measurement and for any newsletter, which would be offered through a separate sign-up with its own explanation. Where a legal obligation requires us to keep or disclose a record, for example in response to a lawful order from an Indonesian authority, that obligation becomes the basis for that specific step.
- (a) Correspondence: handled to respond to your request.
- (b) Security logs: handled under legitimate interest, with short retention.
- (c) Optional analytics or newsletters: handled only with your consent, which you can withdraw at any time.
5. Retention
Contact correspondence is retained for 24 months after the last meaningful exchange, then securely deleted unless a longer period is necessary for a legal claim. Consent records may be kept for 36 months so that preferences can be demonstrated. Aggregated statistics may be kept without direct identifiers for editorial planning.
The 24-month period starts on the date of the last meaningful exchange, not the date of the first message. A thread that ends with a reader's thanks does not extend the period, whereas a new question does. When the period ends, the email thread, any notes and the form entry are deleted from active systems, and copies in routine backups are overwritten in the next backup cycle, normally within 60 days. A record that must be kept for a legal claim is held separately and reviewed every 12 months so that it is not kept longer than the claim requires.
- (a) Server access logs: about 30 days.
- (b) Contact correspondence: 24 months after the last meaningful exchange.
- (c) Consent records: 36 months.
- (d) Internal change record of this policy: 36 months.
- (e) Backups: overwritten within about 60 days after deletion from live systems.
6. Service providers
Hosting, security, form delivery and limited analytics providers may process information under written instructions. They may access data only for the service supplied and must apply appropriate safeguards. Evance does not authorize providers to use contact messages for their own marketing.
The categories of provider currently or prospectively involved are a web hosting company, a content-delivery and security service, an email delivery service used to forward form messages to a staff mailbox, and, only after consent, a privacy-conscious analytics tool. Each is engaged under written terms that limit the use of data to providing the service, require confidentiality and require prompt notice of a security incident. We review the list of provider categories at least once a year, and a new category is described here before it begins to handle personal information. A provider is removed from use if it cannot show appropriate safeguards.
7. Cookies
Essential session cookies may last until the browser closes. The cookie-choice record named cookieChoice may remain for 180 days. If analytics is enabled, its measurement cookie settings and lifespan will be described in the cookie notice before activation. You can reject optional cookies without losing access to editorial pages.
The cookie policy lists each storage item by name and lifespan, so this page does not repeat the full table. In summary, essential items support navigation and security, the choice record remembers what you selected, and no advertising cookies are placed on editorial pages. If you clear your browser storage, the cookie notice will appear again and you can make a fresh choice. Changing your mind later does not require any explanation to us.
8. International transfers
Some hosting or technical suppliers may process data in jurisdictions outside Indonesia. Before using such a supplier, Evance considers contractual confidentiality, access controls and an appropriate transfer mechanism. We do not intentionally transfer sensitive health information because the contact form is not designed to collect it.
Under Indonesian law, a transfer of personal data abroad is considered in light of the protection level in the receiving country and the safeguards in place. In practice, a hosting or email supplier may keep servers in Singapore or elsewhere in Southeast Asia, and some suppliers use infrastructure in other regions. Before using a supplier outside Indonesia, we look for written confidentiality terms, encryption in transit, restricted staff access and a clear process for deletion at the end of the contract. If you want to know which country currently holds your correspondence, you can ask and we will tell you in our reply.
9. Your choices and rights
You may request access, correction or deletion of personal information held about you, and may object to optional processing. Send a clear request describing the email address or correspondence involved to Evance at the address above or by phone at +62 817 9345 1820. We may verify identity proportionately and respond within 30 days, subject to lawful exceptions.
A request does not need to use legal wording. It helps to say which right you are using, the email address or phone number you used when writing, and an approximate date. Identity checks are proportionate: for a reply to an email address you already used, confirming from that address is usually enough, whereas a deletion request may need one additional confirming detail. If a request is complex or we receive several at once, we may extend the response by a further 30 days and will tell you the reason within the first 30. There is no charge for a reasonable request.
- (a) Access: a copy of the personal information we hold about you and a short explanation of how it is used.
- (b) Correction: updating details that are inaccurate or incomplete.
- (c) Deletion: removal of correspondence and records, except where a lawful reason to keep them applies.
- (d) Objection and withdrawal: stopping optional processing such as analytics or newsletters.
10. Children and sensitive information
The website is intended for adults interested in general training information. Do not submit information about a child or another person without lawful authority. Do not use the contact form for urgent medical concerns, diagnosis, treatment decisions or emergency communication.
Evance does not knowingly collect information from people under 18. If we learn that a message was written by or about a child without the authority of a parent or guardian, we will delete it and, where appropriate, tell the sender. Health information is sensitive by nature, and the site is not a place to share diagnoses, test results or injury reports. If a message contains such information anyway, we limit access to it, answer only in general editorial terms and delete it earlier than the standard period when the sender asks.
11. Security and incidents
We use access controls, limited retention and reputable hosting practices. No internet transmission is risk-free. If Evance confirms a personal-data incident that requires notice, we will assess its scope, take containment steps and contact affected people or the relevant authority where required.
Measures include restricting administrative access to named staff, using strong unique credentials, keeping site software up to date and encrypting connections with HTTPS. Staff who handle correspondence are reminded to keep it confidential and not to forward it to personal accounts. Under Law No. 27 of 2022, a failure of personal-data protection must be notified in writing to the affected person and the authority within 3 x 24 hours where the legal threshold is met. We keep a short internal record of each incident, the steps taken and the lessons applied, for 36 months.
12. Complaints and escalation
Start by contacting Evance so we can understand and resolve the concern. Include the date, channel and nature of the request. You may also contact the competent Indonesian data-protection or consumer authority if you believe our response does not address your concern.
We acknowledge a complaint within five business days and aim to send a reasoned answer within 30 days. The answer will explain what we found, what we changed if anything, and what further options remain open to you. A complaint about how a request was handled is reviewed by a staff member who was not involved in the original reply, where staffing allows. Raising a complaint does not affect your ability to read the site or to contact us again in future.
13. Changes
This policy was published on 1 January 2026 and reviewed on 1 October 2026. Material changes will be shown on this page with a new effective date. Earlier versions may be retained in an internal change record for 36 months to explain the basis of past processing.
Changes are classified as minor, such as a corrected typo or clearer wording, or material, such as a new provider category, a new purpose or a longer retention period. A minor change updates the review date. A material change updates the effective date, is summarised in the dated log below, and takes effect for new information only after the page has been public for at least 14 days.
- 1 January 2026: first version published.
- 1 October 2026: scheduled annual review completed; retention periods, rights procedure and transfer wording confirmed as accurate.
14. Contact
Privacy questions can be posted to Jalan Anggrek Raya No. 15, Kemang, Jakarta Selatan 12730, Indonesia, or raised at +62 817 9345 1820. Please do not include passwords or payment details. We aim to acknowledge requests within five business days and provide a substantive response within the period described above.
When you write, mention the page or form you used and the best way to reach you, so that the reply goes to the right place. Telephone enquiries are answered during ordinary Jakarta business hours, and if no one can answer, a short message with your name and number is enough for a call back. For a written request, a reply is sent by the same channel unless you ask for another. If you are unsure whether something is a privacy matter, contact us anyway and we will route it appropriately.
Named third-party processors
The following providers process limited data on behalf of Evance. This list names them so that readers can review each provider's own terms.
- Google Fonts (Google LLC, United States): serves the Lato and Roboto Slab typefaces. Your browser sends your IP address and user-agent to Google when a page loads.
- Web hosting provider: Vercel Inc. (United States) hosts the site and keeps standard server logs for security and reliability, normally for no more than 30 days.
- Email service: messages sent to [email protected] are handled through Google Workspace (Google Ireland Limited and Google LLC) and retained as described in this policy.
- Analytics: Google Analytics 4 (Google LLC) is loaded only if you accept analytics cookies in the cookie banner.
Transfers outside Indonesia take place under Law No. 27 of 2022 on Personal Data Protection. If a provider on this list changes, the list and the policy's review date are updated.