Privacy

Privacy, explained without hiding behind legal language.

We do not want this page to sound safe simply because it is formal. This policy explains what the Digvation website actually processes, why it is needed, where data may go, and how you can ask for access, correction, restriction, or deletion.

Updated 21 August 2026

Who handles the data

In this policy, “Digvation” means the operator of digvation.id and services using the Digvation brand. The current privacy contact is hello@digvation.id.

We do not display a legal entity, address, or phone number that has not been configured and verified. This policy should be updated when official business details are added.

Data we process

An inquiry can include your name, email, optional contact number, optional organization name, and the need/context you choose to write.

For form security, Cloudflare may make the connection IP available to the Pages Function for abuse protection and Turnstile verification. If Turnstile is enabled, its token is validated server-side through Cloudflare Siteverify.

  • Do not submit passwords, API keys, credentials, payment card data, or system secrets through the form.
  • Do not include another person’s personal data unless it is necessary and you are authorized to share it.

Purpose and processing basis

Inquiry data is used to respond to your request, understand context before a potential engagement, secure the form, and carry out the follow-up you requested.

Optional analytics uses the visitor’s choice when consent mode is enabled. You can decline analytics and still access the main website content and submit an inquiry.

Analytics and interaction measurement

The website supports Google Analytics 4 for page/event measurement, Google Tag Manager as the entry point for campaign tags, and Microsoft Clarity for interaction patterns such as scrolling. Optional providers only run when configured; the project defaults to consent mode.

The inquiry form is marked for Clarity masking so the form content is not captured as readable content in session recordings. If Google Ads, Meta Pixel, or other campaign tags are enabled later, they must follow the configured consent and privacy controls.

Providers and data transfers

Depending on production configuration, data may be processed by providers needed for a specific function, such as Cloudflare Pages/Turnstile, Resend for email, an internal/automation webhook, Google Analytics, Google Tag Manager, Microsoft Clarity, or advertising platforms that are actually enabled.

Some providers may process data on infrastructure outside Indonesia. Production provider selection should therefore consider applicable transfer and protection requirements, not only technical convenience.

Retention and deletion

The current website application does not use a public inquiry database as its primary storage. Inquiry data may remain in the delivery provider, inbox, or operational workflow used to follow up.

We retain data only while needed for the conversation, project delivery, administration, security, or legal obligations. You may request earlier deletion by email and provide enough information for us to locate the relevant record.

Security controls that actually exist

We do not claim that any system is “100% secure”. The controls implemented in this website include server validation in a Pages Function, a request-size limit, a honeypot, optional Turnstile with server-side verification, server-only provider secrets, Clarity form masking, and application error logging that does not intentionally log the inquiry payload. Additional rate limiting can be configured at the Cloudflare edge.

If a data incident occurs, response and notification should follow the impact of the incident and applicable legal obligations.

Your data requests

Contact hello@digvation.id to request information about your data, correction, relevant consent withdrawal, restriction, or deletion where applicable.

We may use proportionate verification before fulfilling certain requests so that personal data is not disclosed to the wrong person.

Policy changes

If the website materially changes how it collects data, its providers, analytics, or inquiry flow, this policy should change with it. The update date is shown at the top of the page.