01
We collect with a purpose
We ask for the details needed to answer your enquiry, run and secure the website, and meet legal duties.
Privacy Policy
This policy explains how PT Sukanda Djaya handles personal data when you visit this website, send us an enquiry, or ask to exercise a privacy right.
No advertising trackers. No sale of website-enquiry data. No hidden marketing opt-in.
01
We ask for the details needed to answer your enquiry, run and secure the website, and meet legal duties.
02
The public website does not use advertising pixels or subscribe enquiry senders to marketing by default.
03
You can ask for access, correction, deletion, restriction, or another right using one clear contact route.
This policy applies to personal data handled through the public Sukanda Djaya website, including the contact and partnership enquiry forms, privacy requests, and ordinary website communications. It covers visitors, business contacts, representatives of principals and trade partners, and other people who contact us through the site.
Employment, workforce, supplier onboarding, customer account, and offline campaign data may be covered by a more specific notice provided at the point of collection. If a specific notice conflicts with this policy for that activity, the more specific notice applies.
PT Sukanda Djaya is the Personal Data Controller for the processing described in this policy. References to “Sukanda Djaya”, “we”, “us”, and “our” mean PT Sukanda Djaya. Our contact details appear in section 16.
Nothing in this policy removes or limits a right that cannot lawfully be waived. If this policy and mandatory data-protection law differ, the mandatory rule prevails.
The data we collect depends on what you do on the website. We apply data minimisation and do not ask for information merely because it may be useful later.
Please do not put passwords, payment-card details, government identification numbers, health information, biometric data, precise location, information about children, or other specific or sensitive personal data in a free-text enquiry. If such data is sent when it is not needed, we will restrict access and delete or return it where appropriate and legally permitted.
If you give us personal data about another person, you must be authorised to do so and should make this policy available to them. We will provide any further notice required by law.
We link each purpose to a lawful basis under applicable Indonesian data-protection law. We do not reuse the data for an incompatible purpose without a new legal basis and any notice or consent that the law requires.
Before relying on legitimate interests, we identify the interest, test whether the processing is necessary, and balance it against your interests, rights, and reasonable expectations. You may object. We will stop unless we can demonstrate a lawful overriding reason or the data is needed for a legal claim.
The enquiry form marks required fields. At present, your full name and business email address are required so we can identify and answer the enquiry. Company name, phone number, partnership interest, and message are optional unless the context makes them necessary for the next step.
If required data is not provided, the form may not be submitted or we may be unable to respond. Choosing not to provide optional data does not prevent submission. We will explain if information becomes legally or contractually necessary later.
Access is limited by role and purpose. We do not sell or rent personal data submitted through the website, and we do not provide it to data brokers or use it to create third-party advertising audiences.
We remain responsible for processing we carry out and for processors acting on our documented instructions. A recipient that determines its own separate purposes may be an independent controller and must explain its processing.
Some infrastructure or support providers may process data from locations outside Indonesia. Before a cross-border transfer, we assess and use the transfer condition required by Indonesian law: an adequate level of protection, appropriate and binding safeguards, or valid consent when the first two conditions cannot be met and consent is legally available.
We also limit the data transferred, apply security controls, and contractually require relevant providers to protect it. You may contact us for information about the applicable destination and safeguard, subject to lawful confidentiality limits.
We do not use one blanket period for every record. Retention is determined by the purpose, the status of the enquiry or relationship, legal and accounting duties, limitation periods, dispute or investigation needs, security requirements, and whether the record can be safely deleted or anonymised.
When retention ends, we delete, destroy, or irreversibly anonymise the data. Residual copies in protected backups are isolated from ordinary use and removed through the backup rotation, unless preservation is legally required.
We use organisational and technical safeguards appropriate to the data and risk. Access is limited to people and service providers with an authorised purpose, and safeguards are reviewed as risks, technology, and processing change. We do not publish operational security configurations.
No internet service can promise absolute security. We therefore review safeguards and improve them as risks, technology, and our processing change. If a personal-data protection failure occurs, we will investigate, contain, document, and notify affected people and the competent authority within 3 x 24 hours where Indonesian law requires it. The notice will include the information required by law.
Subject to the conditions and exceptions in applicable law, you may exercise the following rights:
Email the address in section 16 with the subject “Privacy Request”. Describe the right and the data or interaction involved. You may write in English or Bahasa Indonesia. An authorised representative may apply with proof of authority.
We may ask for proportionate information to verify identity and protect your data from disclosure to the wrong person. We will not request more verification data than reasonably needed, and verification will not be used to reset or unnecessarily extend a statutory deadline. We will acknowledge and act within the period required for the specific right. Where UU Pelindungan Data Pribadi sets a 3 x 24 hour action period, we apply it from the point and in the manner the law requires, subject only to lawful exceptions.
If we cannot fulfil all or part of a request, we will explain the decision and its legal basis unless the law prohibits that explanation. You may challenge our response and lodge a complaint or seek a remedy through the competent authority or court.
The website is a general company website and may describe products enjoyed by families, but its enquiry forms are intended for adult business contacts. We do not knowingly use this site to profile children, serve targeted advertising to children, collect precise location from children, or ask a child for specific personal data.
If you are under 18, do not submit an enquiry yourself. Ask a parent or legal guardian to contact us. If we learn that a child submitted personal data without the consent or other protection required by law, we will restrict the data and delete it unless retention is legally required. A parent or guardian can contact us through section 16.
Submitting a contact or partnership enquiry does not subscribe you to marketing. The website does not currently use enquiry data for behavioural advertising, lead scoring, or profiling, and it does not make decisions based solely on automated processing that produce legal or similarly significant effects.
If we offer optional direct marketing later, we will identify the sender and channel, provide the required choice at collection, and include a simple way to stop. A marketing withdrawal will not stop service messages that remain necessary for an enquiry or relationship.
The website links to services such as WhatsApp, Google Maps, Sukanda OneLink, and social networks. We do not send your form submission to those services merely because a link is displayed. When you choose an external link or load an external frame, that provider receives the data your browser sends and applies its own privacy terms.
This does not remove our responsibility for data we choose to disclose or for a provider acting on our instructions. We assess those activities according to the role each party actually performs.
We may update this policy when our practices, providers, or legal duties change. We will publish the revised date and make material changes reasonably prominent. We will not treat an update as retroactive consent or use previously collected data for a new incompatible purpose without the legal basis, notice, and consent required at that time.
Where a change materially affects your rights or how already-collected data is used, we will provide an additional notice through an appropriate channel. Previous versions can be requested using the contact details below.
For a question, complaint, or request about personal data, contact PT Sukanda Djaya using the email, phone number, or postal address shown below. Use “Privacy Request” in the email subject so it reaches the right team. Please do not send identity documents until we ask for the minimum information needed to verify a request.
Privacy requests
Questions, concerns, and rights requests all use the same contact route. We will direct your message to the team responsible for privacy.
Email a privacy request