ISTPIndustrial Security & Terrorism Preparedness
Home › Privacy Policy

Privacy Policy

How the ISTP Programme collects, uses, stores and protects personal data under Law No. 27/2022.

This policy explains the processing of personal data by the organisers of the ISTP Programme in accordance with Law No. 27 of 2022 on Personal Data Protection (the PDP Law).

1. Data controller

The controllers of participant data are PT HRM Multi Sinergy (INDOGUARD.org), domiciled in South Jakarta, and Universitas Indonesia through the Pranata Pembangunan Research Centre (UKK), under the Cooperation Agreement for delivery of the ISTP Programme. PT Sandi Satria Solo (3S) processes participant data only to the extent required to carry out its role. Data protection contact: hello@istp.online.

2. Data collected

  • Registration/partnership forms: name, position, company/institution, sector, email, telephone/WhatsApp number, type of enquiry, number of participants, notes.
  • During the programme: attendance records, pre-test/post-test results, assignment marks, activity documentation, and the data required for personal accident insurance.
  • Technical: IP address in hashed form and browser type, solely to prevent abuse of the forms.

3. Purposes and legal basis for processing

  • To follow up on your enquiry and send programme information — basis: your consent when submitting the form.
  • Administration of registration, payment, delivery, assessment, and the issuance and verification of certificates — basis: performance of a contract with the participant.
  • Compliance with legal obligations, including taxation — basis: legal obligation.
  • Evaluation and quality improvement of the programme using aggregated or anonymised data.

We do not sell personal data and do not use it for profiling on ethnic, religious or racial grounds.

4. Data sharing

Data is shared only with: the organising parties, in line with their respective roles; lecturers (limited to attendance lists and assignment results); the insurance provider (data required by the policy); and technology service providers (website and email hosting). The alumni directory and reports to sponsors contain only the data of participants who have given separate consent, or anonymised data.

5. Storage and retention

  • Enquiry data that does not proceed to registration: retained for a maximum of 12 months, then deleted.
  • Participant data: retained for as long as required for programme administration and certificate verification; the completion verification archive is held by Universitas Indonesia as an academic record.
  • Financial data: for the period required by tax regulation.

6. Security

Form data is stored outside the server's public directory, access is restricted to authorised personnel, and it is transmitted over an encrypted connection (HTTPS). In the event of a personal data breach, we notify affected data subjects within 3×24 hours as required by the PDP Law.

7. Your rights

You have the right to request information, to access and obtain a copy, to rectify, update, erase or restrict the processing of your personal data, to withdraw consent, and to object. Send requests to hello@istp.online; we respond within 3×24 hours and act in accordance with the PDP Law.

8. Cookies and tracking

This site uses no advertising cookies, tracking pixels or third-party analytics. Fonts are served from our own server. Linked third-party sites (e.g. WhatsApp) are subject to their own privacy policies.

9. Data transfers

Hosting and email servers may be located outside Indonesia. Where that is the case, we ensure the provider offers a level of data protection equivalent to or higher than that required by the PDP Law.

10. Changes to this policy

Changes are published on this page under a new version number.

Version 1.0 · effective 27 September 2026

WhatsApp