PT Sukanda Djaya
About UsOur NetworkBrands
Partner with Us
  • For Principals
  • For HORECA
  • General Trade
  • Modern Trade
  • Mitra Diamond
  • Depo Diamond
  • E-Commerce
StoriesContact
Sukanda OneLink
About UsOur NetworkBrands
Partner with Us
  • For Principals
  • For HORECA
  • General Trade
  • Modern Trade
  • Mitra Diamond
  • Depo Diamond
  • E-Commerce
StoriesContactSukanda OneLink
Language
  1. Home
  2. /
  3. Privacy Policy

Privacy Policy

Privacy, in plain language.

This policy explains how PT Sukanda Djaya handles personal data when you visit this website, send us an enquiry, or ask to exercise a privacy right.

No advertising trackers. No sale of website-enquiry data. No hidden marketing opt-in.

Effective
26 July 2026
Last updated
26 July 2026

The short version

01

We collect with a purpose

We ask for the details needed to answer your enquiry, run and secure the website, and meet legal duties.

02

We do not build ad profiles

The public website does not use advertising pixels or subscribe enquiry senders to marketing by default.

03

Your rights should be usable

You can ask for access, correction, deletion, restriction, or another right using one clear contact route.

On this page16 sections
  1. 1. Who this policy covers
  2. 2. Personal data we collect
  3. 3. Where the data comes from
  4. 4. Why we use personal data and our legal bases
  5. 5. What is required and what is optional
  6. 6. Cookies, local storage, and embedded services
  7. 7. Who can receive personal data
  8. 8. Processing outside Indonesia
  9. 9. How long we keep data
  10. 10. How we protect personal data
  11. 11. Your privacy rights
  12. 12. Children and young people
  13. 13. Marketing, profiling, and automated decisions
  14. 14. External links and actions
  15. 15. Changes to this policy
  16. 16. Contact and privacy requests

On this page

  1. 1. Who this policy covers
  2. 2. Personal data we collect
  3. 3. Where the data comes from
  4. 4. Why we use personal data and our legal bases
  5. 5. What is required and what is optional
  6. 6. Cookies, local storage, and embedded services
  7. 7. Who can receive personal data
  8. 8. Processing outside Indonesia
  9. 9. How long we keep data
  10. 10. How we protect personal data
  11. 11. Your privacy rights
  12. 12. Children and young people
  13. 13. Marketing, profiling, and automated decisions
  14. 14. External links and actions
  15. 15. Changes to this policy
  16. 16. Contact and privacy requests
1. Who this policy covers

1. Who this policy covers

This policy applies to personal data handled through the public Sukanda Djaya website, including the contact and partnership enquiry forms, privacy requests, and ordinary website communications. It covers visitors, business contacts, representatives of principals and trade partners, and other people who contact us through the site.

Employment, workforce, supplier onboarding, customer account, and offline campaign data may be covered by a more specific notice provided at the point of collection. If a specific notice conflicts with this policy for that activity, the more specific notice applies.

The data controller

PT Sukanda Djaya is the Personal Data Controller for the processing described in this policy. References to “Sukanda Djaya”, “we”, “us”, and “our” mean PT Sukanda Djaya. Our contact details appear in section 16.

Nothing in this policy removes or limits a right that cannot lawfully be waived. If this policy and mandatory data-protection law differ, the mandatory rule prevails.

2. Personal data we collect

2. Personal data we collect

The data we collect depends on what you do on the website. We apply data minimisation and do not ask for information merely because it may be useful later.

  • Identity and contact data, such as your full name, business email address, and optional phone number.
  • Organisation and business data, such as company name, role or relationship to an organisation, distribution channel, and partnership interest.
  • Enquiry and communication data, including your message, our response, follow-up correspondence, and records needed to manage a privacy request.
  • Technical and security data that hosting and network systems may generate, such as IP address, device and browser information, request time, requested page, referring page, and security-event logs.
  • Choice and consent records where we offer an optional activity that requires consent. The current partnership enquiry form does not opt you into marketing.

Data we do not ask you to submit

Please do not put passwords, payment-card details, government identification numbers, health information, biometric data, precise location, information about children, or other specific or sensitive personal data in a free-text enquiry. If such data is sent when it is not needed, we will restrict access and delete or return it where appropriate and legally permitted.

3. Where the data comes from

3. Where the data comes from

  • Directly from you when you complete a form, contact us, or exercise a right.
  • From your organisation, employer, principal, or authorised representative when they identify you as a business contact.
  • Automatically from your browser, device, and our website infrastructure when a request reaches the site.
  • From public business sources only when reasonably necessary to verify an organisation or respond to a business enquiry.

If you give us personal data about another person, you must be authorised to do so and should make this policy available to them. We will provide any further notice required by law.

4. Why we use personal data and our legal bases

4. Why we use personal data and our legal bases

We link each purpose to a lawful basis under applicable Indonesian data-protection law. We do not reuse the data for an incompatible purpose without a new legal basis and any notice or consent that the law requires.

  • To receive, route, and respond to an enquiry, and to take steps you request before a possible business relationship. The basis is the steps requested by you before entering an agreement, or performance of an agreement where one exists.
  • To maintain business correspondence and manage relationships with organisations. The basis is performance of an agreement or our legitimate interests in responsible business communication, after considering the impact on you.
  • To operate, diagnose, secure, and prevent misuse of the website and forms. The basis is our legitimate interests in providing a reliable and secure service and, where applicable, compliance with a legal obligation.
  • To establish, exercise, or defend legal claims; comply with lawful requests; maintain required records; and meet regulatory duties. The basis is compliance with a legal obligation or another basis expressly allowed by law.
  • To handle privacy requests and prove how we responded. The basis is compliance with data-protection duties and our legitimate interests in accountable request management.
  • For a genuinely optional purpose, such as future direct marketing, only where we identify that purpose and request a separate valid consent or can rely on another lawful basis. Refusing or withdrawing optional consent will not affect the core enquiry service.

Our legitimate-interest test

Before relying on legitimate interests, we identify the interest, test whether the processing is necessary, and balance it against your interests, rights, and reasonable expectations. You may object. We will stop unless we can demonstrate a lawful overriding reason or the data is needed for a legal claim.

5. What is required and what is optional

5. What is required and what is optional

The enquiry form marks required fields. At present, your full name and business email address are required so we can identify and answer the enquiry. Company name, phone number, partnership interest, and message are optional unless the context makes them necessary for the next step.

If required data is not provided, the form may not be submitted or we may be unable to respond. Choosing not to provide optional data does not prevent submission. We will explain if information becomes legally or contractually necessary later.

6. Cookies, local storage, and embedded services

6. Cookies, local storage, and embedded services

The public website does not intentionally use advertising cookies, advertising pixels, behavioural analytics, or browser storage to build a visitor profile. Essential infrastructure may still process ordinary request and security information needed to deliver and protect a page.

Google Maps is click to load

The contact page does not load the interactive Google Maps frame until you choose to load it. If you do, your browser connects directly to Google. Google may receive your IP address, browser and device information, the referring page, and may read or set its own cookies according to its policies. You can use the written address without loading the map.

If we later add non-essential analytics, advertising technology, or another optional tracker, we will update this notice and request consent before activation where required. A future feature is not authorised merely because it is mentioned in a revised policy.

7. Who can receive personal data

7. Who can receive personal data

Access is limited by role and purpose. We do not sell or rent personal data submitted through the website, and we do not provide it to data brokers or use it to create third-party advertising audiences.

  • Authorised Sukanda Djaya teams that need the information to route and respond to an enquiry, manage a relationship, keep the service secure, or fulfil a legal duty.
  • Service providers acting for us in categories such as website hosting and delivery, form and data storage, security, communications, and public-media delivery, subject to appropriate instructions and safeguards.
  • Professional advisers, auditors, insurers, and security specialists where access is necessary and subject to confidentiality or an equivalent duty.
  • A principal, distributor, group company, or business partner when this is necessary to address the specific request. The website does not automatically send the contents of an enquiry to every principal or partner.
  • Courts, regulators, law-enforcement bodies, or other recipients when disclosure is required or expressly permitted by law and the request is valid.
  • A successor in a merger, restructuring, financing, or transfer of a business, subject to confidentiality, due diligence limits, and continued protection. This is not a sale of data for advertising.

We remain responsible for processing we carry out and for processors acting on our documented instructions. A recipient that determines its own separate purposes may be an independent controller and must explain its processing.

8. Processing outside Indonesia

8. Processing outside Indonesia

Some infrastructure or support providers may process data from locations outside Indonesia. Before a cross-border transfer, we assess and use the transfer condition required by Indonesian law: an adequate level of protection, appropriate and binding safeguards, or valid consent when the first two conditions cannot be met and consent is legally available.

We also limit the data transferred, apply security controls, and contractually require relevant providers to protect it. You may contact us for information about the applicable destination and safeguard, subject to lawful confidentiality limits.

9. How long we keep data

9. How long we keep data

We do not use one blanket period for every record. Retention is determined by the purpose, the status of the enquiry or relationship, legal and accounting duties, limitation periods, dispute or investigation needs, security requirements, and whether the record can be safely deleted or anonymised.

  • Enquiry records are reviewed after the enquiry is resolved or inactive and are kept only while needed for follow-up, an ongoing relationship, accountability, or a legal requirement.
  • Technical and security logs are kept for the shorter operational period needed to diagnose incidents, prevent abuse, and meet applicable electronic-system duties.
  • Consent and privacy-request records may be retained as evidence of the choice made and our response, but not used to revive a purpose that has ended.
  • When a legal hold or dispute applies, deletion may be suspended only for the relevant data and only for as long as that reason continues.

When retention ends, we delete, destroy, or irreversibly anonymise the data. Residual copies in protected backups are isolated from ordinary use and removed through the backup rotation, unless preservation is legally required.

10. How we protect personal data

10. How we protect personal data

We use organisational and technical safeguards appropriate to the data and risk. Access is limited to people and service providers with an authorised purpose, and safeguards are reviewed as risks, technology, and processing change. We do not publish operational security configurations.

No internet service can promise absolute security. We therefore review safeguards and improve them as risks, technology, and our processing change. If a personal-data protection failure occurs, we will investigate, contain, document, and notify affected people and the competent authority within 3 x 24 hours where Indonesian law requires it. The notice will include the information required by law.

11. Your privacy rights

11. Your privacy rights

Subject to the conditions and exceptions in applicable law, you may exercise the following rights:

  • Be informed about our identity, the legal basis and purpose, accountability, and other required details.
  • Access and obtain a copy of personal data about you and information about how it is processed.
  • Correct or complete inaccurate or incomplete personal data.
  • End processing, erase, or destroy personal data when the legal conditions are met.
  • Withdraw a consent at any time. Withdrawal does not make earlier lawful processing unlawful.
  • Object to a decision based solely on automated processing, including profiling, that produces legal or similarly significant effects.
  • Delay or restrict processing in accordance with the purpose and conditions provided by law.
  • Obtain and use your personal data in a structured, commonly used, machine-readable format, and request transfer to another controller where the systems can securely communicate and the legal conditions are met.
  • Object to processing based on legitimate interests and seek compensation or another remedy where the law provides it.

How to make a request

Email the address in section 16 with the subject “Privacy Request”. Describe the right and the data or interaction involved. You may write in English or Bahasa Indonesia. An authorised representative may apply with proof of authority.

We may ask for proportionate information to verify identity and protect your data from disclosure to the wrong person. We will not request more verification data than reasonably needed, and verification will not be used to reset or unnecessarily extend a statutory deadline. We will acknowledge and act within the period required for the specific right. Where UU Pelindungan Data Pribadi sets a 3 x 24 hour action period, we apply it from the point and in the manner the law requires, subject only to lawful exceptions.

If we cannot fulfil all or part of a request, we will explain the decision and its legal basis unless the law prohibits that explanation. You may challenge our response and lodge a complaint or seek a remedy through the competent authority or court.

12. Children and young people

12. Children and young people

The website is a general company website and may describe products enjoyed by families, but its enquiry forms are intended for adult business contacts. We do not knowingly use this site to profile children, serve targeted advertising to children, collect precise location from children, or ask a child for specific personal data.

If you are under 18, do not submit an enquiry yourself. Ask a parent or legal guardian to contact us. If we learn that a child submitted personal data without the consent or other protection required by law, we will restrict the data and delete it unless retention is legally required. A parent or guardian can contact us through section 16.

13. Marketing, profiling, and automated decisions

13. Marketing, profiling, and automated decisions

Submitting a contact or partnership enquiry does not subscribe you to marketing. The website does not currently use enquiry data for behavioural advertising, lead scoring, or profiling, and it does not make decisions based solely on automated processing that produce legal or similarly significant effects.

If we offer optional direct marketing later, we will identify the sender and channel, provide the required choice at collection, and include a simple way to stop. A marketing withdrawal will not stop service messages that remain necessary for an enquiry or relationship.

14. External links and actions

14. External links and actions

The website links to services such as WhatsApp, Google Maps, Sukanda OneLink, and social networks. We do not send your form submission to those services merely because a link is displayed. When you choose an external link or load an external frame, that provider receives the data your browser sends and applies its own privacy terms.

This does not remove our responsibility for data we choose to disclose or for a provider acting on our instructions. We assess those activities according to the role each party actually performs.

15. Changes to this policy

15. Changes to this policy

We may update this policy when our practices, providers, or legal duties change. We will publish the revised date and make material changes reasonably prominent. We will not treat an update as retroactive consent or use previously collected data for a new incompatible purpose without the legal basis, notice, and consent required at that time.

Where a change materially affects your rights or how already-collected data is used, we will provide an additional notice through an appropriate channel. Previous versions can be requested using the contact details below.

16. Contact and privacy requests

16. Contact and privacy requests

For a question, complaint, or request about personal data, contact PT Sukanda Djaya using the email, phone number, or postal address shown below. Use “Privacy Request” in the email subject so it reaches the right team. Please do not send identity documents until we ask for the minimum information needed to verify a request.

Privacy requests

A clear route to a real person.

Questions, concerns, and rights requests all use the same contact route. We will direct your message to the team responsible for privacy.

Email a privacy request
Privacy email
halosukandadjaya@diamond.co.id
Phone
+62 21 2864 9888
Postal address
PT Sukanda DjayaGedung TCC Batavia Tower One, 15th floor, Unit 03 & 05Jl. KH Mas Mansyur Kav 126, Central Jakarta, 10220, Indonesia

Delivering joyacross Indonesia,since 1974.

Company

  • •Our Story
  • •Our Network
  • •Contact

Brands

  • •All Brands
  • •Dairy & Frozen
  • •Gourmet & Snacks
  • •Beverages
  • •Equipment

Partner With Us

  • •For Principals
  • •For Trade Partners
  • •Mitra Sukanda
  • •Sukanda OneLink

Shop & Connect

  • •Where to Buy
  • •Stories
  • •Instagram
  • •LinkedIn
  • •TikTok

Legal

  • •Privacy Policy
  • •Cookie Policy
© 2026 PT Sukanda Djaya · Keeping Indonesia’s joy moving since 1974.Terms of UsePrivacy PolicyAccessibilitySite Map