Privacy Statement

 
 
Privacy & Data Protection

Privacy Statement

This Privacy Statement explains how Kinesiology and Physiotherapy Comprehensive Journal (KPCJ) collects, uses, and protects personal data in accordance with applicable laws and international standards.

UU PDP No. 27/2022 GDPR (EU) 2016/679 PKP/OJS Privacy Policy Effective: January 2025

The names and email addresses entered in this journal site will be used exclusively for the stated purposes of this journal and will not be made available for any other purpose or to any other party. KPCJ is committed to protecting your personal data in compliance with Indonesian Law No. 27 of 2022 on Personal Data Protection (UU PDP), the EU General Data Protection Regulation (GDPR), and the PKP Open Journal Systems privacy framework.

Regulatory Framework

 

UU No. 27 Tahun 2022

Perlindungan Data Pribadi (PDP)

Indonesia's primary data protection law, fully effective October 2024. Mandates lawful basis for data processing, data subject rights, breach notification within 14 days, and sanctions for violations. KPCJ operates in compliance with all provisions of this law.

 

GDPR (EU) 2016/679

General Data Protection Regulation

As an international journal, KPCJ applies GDPR principles as best practice for all users, including those from the European Economic Area (EEA). This includes lawful processing, data minimization, purpose limitation, and the right to erasure.

 

PKP / OJS Privacy Policy

Public Knowledge Project Framework

KPCJ is published on Open Journal Systems (OJS) by PKP. User data is processed within the OJS platform in accordance with PKP's privacy policy, which governs data stored in the journal management system.

Data We Collect

Registration Data

Full name, email address, institution/affiliation, country, and professional title — collected when registering as an author, reviewer, or reader.

Submission Data

Manuscript files, co-author information, funding declarations, conflict of interest statements, and correspondence during the editorial and peer review process.

Technical Data

IP address, browser type, pages visited, and session data — collected automatically by the OJS platform for security and system analytics purposes.

Communication Data

Emails and messages exchanged between authors, editors, and reviewers during the submission, review, and publication process via the OJS system.

Purpose & Legal Basis of Processing

1

Editorial & Publication Management

To manage manuscript submissions, coordinate peer review, communicate editorial decisions, and facilitate publication. Legal basis (UU PDP): Art. 20 — necessity for performance of a task; GDPR: Art. 6(1)(b) — performance of a contract.

2

Author Attribution & Indexing

Author names, affiliations, and ORCID IDs are published as part of the scholarly record and shared with indexing services (Crossref, Garuda, Google Scholar, Dimensions). Legal basis: legitimate interest in disseminating scientific knowledge and consent upon submission.

3

Journal Notifications & Announcements

To send editorial notifications, issue publication announcements, and system updates. Readers who register for notifications may opt out at any time via their OJS user profile. Legal basis: consent (opt-in).

4

Security & Platform Integrity

Technical data (IP address, session logs) is processed to maintain platform security, prevent fraud, and ensure system stability. Legal basis (UU PDP): Art. 20 — legitimate interest; GDPR: Art. 6(1)(f).

5

Legal Compliance

To comply with applicable legal obligations, including data breach reporting requirements under UU PDP Pasal 46 (notification within 14 days) and equivalent provisions under GDPR Art. 33 (72-hour notification to supervisory authority).

Your Rights as a Data Subject

 

Right of Access

Request a copy of personal data we hold about you (UU PDP Ps. 34; GDPR Art. 15).

 

Right to Rectification

Correct inaccurate or incomplete data via your OJS user profile (UU PDP Ps. 35; GDPR Art. 16).

 

Right to Erasure

Request deletion of personal data where no longer necessary, subject to legal retention obligations (UU PDP Ps. 36; GDPR Art. 17).

 

Right to Object

Object to processing based on legitimate interests, including marketing or non-essential communications (UU PDP Ps. 38; GDPR Art. 21).

 

Right to Portability

Receive your data in a structured, machine-readable format where technically feasible (UU PDP Ps. 37; GDPR Art. 20).

 

Right to Withdraw Consent

Withdraw consent for optional processing (e.g., notification emails) at any time without affecting prior lawful processing (UU PDP Ps. 39; GDPR Art. 7).

To exercise any of these rights, contact us at kpc.jurnal@gmail.com. We will respond within 14 working days as required by UU PDP Pasal 42, or within 30 days as required by GDPR Art. 12.

Data Sharing, Security & Retention

 

Third-Party Sharing

Personal data is shared only with trusted third parties essential to journal operations: Crossref (DOI registration), indexing databases, Turnitin (plagiarism screening), and Grammarly (language checking). All third parties are contractually bound to protect your data.

 

Data Security

KPCJ implements appropriate technical and organizational measures including HTTPS/SSL encryption, access controls, and password hashing to protect personal data against unauthorized access, loss, or disclosure, as required by UU PDP Pasal 35 and GDPR Art. 32.

 

Data Retention

Published author data (name, affiliation, email) is retained indefinitely as part of the permanent scholarly record. Reviewer data and submission correspondence are retained for a minimum of 5 years for audit and integrity purposes, unless deletion is lawfully requested.

 

Cookies

OJS uses session cookies essential for platform functionality (login, navigation). No third-party advertising or tracking cookies are used. By continuing to use this site, you consent to the use of strictly necessary session cookies only.

Data Breach Notification

Mandatory Breach Reporting

In the event of a personal data breach, KPCJ is legally required to notify the Komnas PDP (Indonesia) within 14 × 24 hours (UU PDP Pasal 46) and to notify affected data subjects without undue delay. For users covered by GDPR, notification to the relevant supervisory authority will occur within 72 hours (GDPR Art. 33). Affected individuals will be informed as required under both regulations.

Policy Updates

This Privacy Statement may be updated periodically to reflect changes in applicable law or journal practices. Material changes will be announced on this page with an updated effective date. Continued use of the journal system after changes are posted constitutes acceptance of the revised statement. Users are encouraged to review this page regularly.

Last updated: January 2025

Privacy Contact

For questions, data access requests, or complaints regarding this Privacy Statement, please contact the Editorial Office:

kpc.jurnal@gmail.com

ROM Physiotherapy Denpasar, Jl. Raya Puputan No.26a, Denpasar, Bali 80239