Privacy
This notice describes what this website does with personal data. It is short because the website does very little: there is no database, no analytics, and no advertising. Where an obligation comes from the Personal Data Protection Act, the article is cited, so you can check it rather than take our word for it.
Last updated
PT RoneAI Teknologi Internasional, trading as RoneAI, is the Personal Data Controller for everything described here. The company is registered in Indonesia under Ministry of Law decree AHU-A113097.AH.01.30.Tahun 2026, registration number 4701130820260086, and is domiciled in Boyolali Regency, Central Java, Indonesia.
Indonesian Law No. 27 of 2022 on Personal Data Protection governs us. It applies to anyone carrying out a regulated act inside Indonesia, and also outside it where the effect is felt in Indonesia or falls on an Indonesian citizen abroad (Article 2). It has been fully in force since 17 October 2024.
If you are in the European Union or the United Kingdom, the GDPR may apply to your data as well. Where the two differ, this notice follows whichever gives you more — which, on response times, is Indonesian law. Questions and requests go to hello@rone.dev.
The Act creates a dedicated supervisory body, Lembaga Pelindungan Data Pribadi. As of this revision it has not been established and the implementing government regulations have not been signed; the Ministry of Communication and Digital Affairs supervises in the meantime. This notice will change when that does.
Only two things reach us: what you type into the contact form, and what any web server necessarily sees when your browser makes a request. Article 20(1) requires a controller to hold a lawful basis for each, so each one is named below.
| Data | Why | Lawful basis | How long |
|---|---|---|---|
| Name, email address, message | To read your enquiry and answer it | Your own request ahead of any agreement — Article 20(2)(b) | Held in correspondence; see Retention |
| IP address | Rate limiting the contact form, and passed to Cloudflare Turnstile to distinguish you from a bot | Legitimate interest in keeping the form usable — Article 20(2)(f) | In memory only, for at most ten minutes, and lost whenever the server restarts |
| A Turnstile token | Proving the submission came from a browser rather than a script | Legitimate interest in preventing abuse — Article 20(2)(f) | Not stored. It is single-use and checked once |
| Your theme preference | Remembering light or dark mode | Necessary to provide the feature you asked for | Stored in your own browser and never sent to us |
None of this rests on consent, which is worth stating rather than glossing. A basis of consent would carry a right to withdraw it under Article 9, and withdrawing consent for the only details that let us reply would leave you without a reply. Your right to object and your right to erasure do not depend on consent, and both are below.
The fields the form accepts are defined in lib/contact-schema.ts. The rate limiter, including the ten-minute window, is lib/rate-limit.ts.
This section names specifics rather than reassurances, because a privacy notice written in generalities tells you nothing about the system it describes.
One qualification, because precision matters more than a clean claim: the Turnstile widget on the contact page is loaded from Cloudflare, and Cloudflare may set its own storage against its own domains when it runs. That is outside this site and is covered by Cloudflare’s privacy policy.
This is also why there is no cookie banner. A banner exists to collect consent for non-essential storage, and there is none here to consent to. Adding one anyway would be theatre.
These are properties of the code, not policies applied by hand: no analytics in app/layout.tsx, and no data store anywhere in the project. This site’s repository is private, so you cannot read it yourself — ask us and we will show you any part of it that bears on a claim here.
Three parties are involved in a contact form submission, and no others. Messaging us on WhatsApp instead adds one, which the next section covers.
| Who | What they receive | Why |
|---|---|---|
| Cloudflare | Your IP address and request metadata for every page you load; your IP and the Turnstile token when you submit the form | This site runs on Cloudflare Workers, is served through its network, and uses Turnstile for the bot check and Email Routing for our inboxes |
| Resend | Your name, email address and message | It delivers two emails: your enquiry to us, and an acknowledgement to you |
| Our own mailbox | The same enquiry, as ordinary email | Somebody has to read it and reply |
Both providers are established outside Indonesia, so answering you means transferring your data out of the jurisdiction. Article 56 sets out when that is allowed. Indonesia has not yet published a list of countries meeting the equivalent-protection test in Article 56(2), because the implementing regulation that would establish one has not been issued — so we rely on Article 56(3): binding contractual protection with each provider, under their published data processing terms.
Both were chosen partly on that basis. If either stops offering adequate binding protection, the honest options are to replace it or to fall back on asking you first under Article 56(4), and this page would say so before we did either.
The full path a submission takes — validation, honeypot, Turnstile, then two sends — is app/api/contact/route.ts.
We publish a company WhatsApp number, and choosing it puts a fourth party in the middle: WhatsApp is operated by Meta, which handles the message, your phone number, and the metadata around both under its own terms. That happens before anything reaches us and is outside our control.
What we then hold is your number and whatever you sent, kept on the same terms as email correspondence and deleted on the same schedule. WhatsApp messages are end-to-end encrypted in transit, which protects the content but not the fact that you contacted us.
The WhatsApp channel is a different thing and collects nothing for us. It is a one-way broadcast: following it does not open a conversation, and WhatsApp does not disclose followers to the channel owner, so we see a follower count and no identities. Your relationship there is with Meta, under its terms, and we cannot see, export or delete anything about it — leaving the channel is done in your own app.
If you would rather Meta had nothing to do with it, use the contact form or email instead. Both reach the same person, and neither involves them.
The website itself keeps nothing. The only durable copy of your message is email.
You do not have to wait for any of those periods to run out. Ask us to delete your data and we will, under Article 8.
The Act gives you each of the following in its own article. This is the list rather than a summary of the general idea, with the article you can hold us to and the deadline the law sets.
| Right | Article | Our deadline |
|---|---|---|
| Be told who we are, on what basis we process, and why | Article 5 | This page |
| Complete, update, or correct your data | Article 6 | 3 × 24 hours (Article 30) |
| Access and a copy of what we hold, free of charge | Article 7 | 3 × 24 hours (Article 31) |
| End processing, and have your data erased or destroyed | Article 8 | Without delay |
| Withdraw consent, where consent is what we relied on | Article 9 | 3 × 24 hours (Article 40) |
| Object to a decision made solely by automated processing | Article 10 | Not applicable — we make none |
| Postpone or restrict processing | Article 11 | 3 × 24 hours (Article 41) |
| Claim compensation for a breach | Article 12 | Through the courts |
| Receive your data in a portable, machine-readable form | Article 13 | On request |
Article 14 asks for these requests in writing, and an email is writing. Send one to hello@rone.dev saying what you want. There is no charge, and you will not be asked to justify the request.
Three days is a short deadline, and we would rather be measured against it than against a comfortable one imported from another jurisdiction. In practice the answer is usually the same day, because there is very little here to look up.
A narrow set of exemptions applies to some of these rights under Article 15, chiefly national security and law enforcement. None has ever been relevant to an enquiry sent through this website, and if one ever were, we would tell you we were relying on it.
If our answer does not satisfy you, you can complain to the Ministry of Communication and Digital Affairs, which supervises data protection until Lembaga PDP exists. If you are in the EU or the UK, you can go to your own national supervisory authority instead.
Article 46 requires written notice to both the affected people and the supervisory authority within 3 × 24 hours of a personal data protection failure. That is our commitment, not an aspiration.
The notice has to say what data was exposed, when and how it happened, and what is being done about it. If we ever have to send you one, it will say those three things plainly rather than describe an incident in the passive voice.
Articles 35 and 39 require technical and operational measures proportionate to the nature and risk of the data. Ours are proportionate to a contact form — deliberately modest — and the most effective of them is that there is almost nothing to protect.
We also publish what our defences do not do. The contact form’s rate limiter runs in memory per server instance and is a speed bump rather than a security boundary — Turnstile is the real gate. That is stated in the source and repeated on our security page, which also explains how to report a vulnerability.
Article 53 requires a controller to appoint a personal data protection officer where processing serves a public service, where the core activity requires large-scale regular and systematic monitoring, or where the core activity is large-scale processing of specific-category or criminal data. The Constitutional Court confirmed in decision 151/PUU-XXII/2024 that these are alternatives rather than a cumulative test.
None of the three applies to us: a micro enterprise, monitoring nobody, processing no special-category data. So no officer is appointed. That is stated rather than left silent, so you can check the reasoning instead of wondering about the omission. Data protection questions go to the director, at hello@rone.dev.
This notice covers rone.dev and nothing else. The services we operate handle different data on different terms, so each publishes its own, linked from its own footer.
| Service | Notice | Because it handles |
|---|---|---|
| Arena Card | arena-card.rone.dev/privacy | A signed-in game session: in-game id and zone, a verification code, and a session token in a signed cookie |
| Arena Academy | arena-academy.rone.dev/privacy | An optional signed-in session, held in your own browser rather than on a server |
| igstats | igstats.rone.dev/privacy | A file you upload that names other people, processed for seconds and never stored |
The public APIs — Rone Arena, Sivitas, SpaceX and Wilayah Indonesia — read public data and hold no account of anyone, so they publish hosted service terms in their repositories rather than a privacy notice.
This is a business website and is not directed at children. Processing a child’s data under the Act requires verified parental consent, which we are not set up to obtain and do not want to hold. We do not knowingly collect data from anyone under 18. If you believe a child has sent us personal data, tell us and we will delete it.
If what the site does changes, this page changes with it and the date at the top moves. If a change materially affects data you have already sent us, we will email you rather than rely on you noticing a new date here.
The implementing regulations under the Act have not yet been issued and the supervisory body has not been established. Both will change what a compliant notice must say, and this page will be revised when they do.