Policy · updated 5 October 2026
Privacy policy
This policy explains how Nymera handles information when you read, contact, or interact with this publication in Indonesia.
1. Scope and controller
This policy applies to Nymera pages, forms, editorial correspondence, and ordinary website logs. Nymera operates from Jl. Gatot Subroto Kav. 36, Jakarta Selatan, DKI Jakarta 12950, Indonesia. The publication is responsible for deciding why limited personal information is handled. This document was reviewed on 5 October 2026 and uses the laws and practical expectations applicable to our Indonesian operations. The policy covers visitors who read articles, people who write to the editorial desk through contact.php, and individuals who telephone the published number. It does not extend to external websites that Nymera links to, which operate under their own notices. For the purposes of Indonesian Law No. 27 of 2022 on Personal Data Protection (UU PDP), Nymera acts as the data controller for the limited information described below. Questions about who is responsible for a particular piece of information can be sent to the desk, and we will answer in writing. Where this document says "we", it means the Nymera editorial and administrative team working from the Jakarta address above.
2. Information collected
When you contact the desk, we may receive your name, email address, phone number if supplied, message, and the context you choose to provide. Server logs may include an IP address, browser type, requested page, referring page, and timestamp. We do not request health records, diagnoses, financial details, identity documents, or precise location. Please avoid placing sensitive medical information in a general enquiry. Specifically, (a) identity details are limited to the name you type into a form, (b) contact details are the email address or telephone number you choose to give, and (c) technical details are generated automatically when your browser requests a page. For example, if you write to ask about a correction on an article, we will see the article address you mention, your message, and the time it was received. We do not combine this information with data from other sources to build a profile of you. Information that you volunteer beyond what the form asks for, such as an employer name or a training history, is handled in the same way as the rest of the message, although we may delete clearly unnecessary detail when we reply. If you send us information about another person, please make sure that you have a reasonable basis for doing so.
3. Purposes
We use correspondence to answer enquiries, investigate corrections, respond to accessibility requests, and maintain an accountable editorial record. Technical logs help protect the site, diagnose broken links, and understand broad page reliability. Optional analytics, where enabled, are used in aggregated form to understand which public resources are useful. We do not sell personal information or use it to make decisions about access to healthcare, employment, credit, or insurance. In practice this means that (a) a question about a correction is used to review the passage and to reply to you, (b) an accessibility report is used to locate and examine the barrier you describe, and (c) a general enquiry is used to point you to the relevant page or to explain the editorial approach. Logs are reviewed when something fails, for example when a page returns an error or a form does not respond, and are not examined to follow individual readers. Aggregated figures, such as the number of visits to a page in a month, may inform which topics receive updates, but they do not identify a person. We do not use automated decision-making that produces legal or similarly significant effects on readers. If we wished to use information for a materially different purpose, we would update this page and, where required, ask for fresh consent.
4. Legal basis
We rely on consent for optional cookies and voluntary contact information, contractual or pre-contractual necessity where you ask us to respond to a service enquiry, and legitimate interests for security and basic publication administration. You may withdraw optional cookie consent at any time by clearing the site choice and contacting us. Withdrawal does not affect processing already completed lawfully. Consent is requested through the cookie banner for optional cookies and is inferred from your action when you choose to submit a form. Legitimate interests are limited to keeping the site secure, keeping an editorial record that can be audited, and managing the publication, and we weigh those interests against your reasonable expectations before relying on them. Where Indonesian law requires a specific basis for a particular category of information, we follow that requirement. For example, specific personal data such as health information is not requested, and if it arrives unprompted we treat it with extra care and may delete it. You can ask us to explain the basis that applies to a specific piece of information, and we will describe it in plain language.
5. Retention
Contact messages are normally retained for 24 months after the last meaningful exchange so that corrections and follow-up questions can be understood. Editorial correction records may be retained for seven years because they document the publication history. Security logs are normally deleted or aggregated within 90 days. Backups may persist for up to 35 days before rotation. Longer retention occurs only where a legal claim, complaint, or statutory obligation requires it. In concrete terms, (a) a message from a reader whose last reply was sent in March 2026 would normally be deleted around March 2028, (b) a correction record about a published article stays in the editorial history for seven years, and (c) a web server log entry is normally removed or reduced to aggregate counts within 90 days. Deleted items may remain in encrypted backups until those backups rotate, which is why the backup period of up to 35 days is stated separately. If you ask for deletion earlier, we will remove the message from active systems and tell you if a legal or editorial reason requires us to keep any part of it. Retention periods are reviewed at least once a year and shortened where an item is no longer useful.
6. Processors
Nymera may use hosting, email delivery, spam prevention, analytics, and form infrastructure providers acting on documented instructions. Providers receive only the information needed for their function and are expected to apply security controls and confidentiality obligations. We do not authorize processors to sell contact data. A current provider description can be requested from the desk, subject to security considerations. Typical categories include (a) a cloud hosting provider that serves the pages from data centres in the Asia-Pacific region, (b) a transactional email service that delivers replies, (c) a spam-filtering service that screens form submissions, and (d) an analytics service that is active only when you accept optional cookies. Each arrangement is documented in an agreement that covers confidentiality, security measures, assistance with rights requests, and deletion or return of information at the end of the service. Providers may engage sub-processors only under equivalent obligations. When we change a provider in a way that materially affects how your information is handled, we update this page and note the date in the change record below.
7. Cookies
The site uses a cookie-choice value called cookieChoice to remember whether optional cookies were accepted or rejected; it lasts until you remove it. Essential session and security mechanisms may last for a browsing session or up to 30 days. Optional analytics cookies, if enabled, are configured with lifespans no longer than 13 months and are not required to read Nymera. Details appear in cookies.php, and browser settings can block or remove cookies. For transparency, the values fall into three groups: (a) the cookieChoice preference set by Nymera, (b) essential session and security values set by the hosting layer, and (c) optional analytics identifiers that appear only after you accept optional cookies. If you reject optional cookies, group (c) is not set, and the pages remain fully readable. The cookie policy lists the purpose and lifespan of each group in more detail and is updated whenever the arrangement changes.
8. International transfers
Hosting or service providers may process information in countries outside Indonesia. Where that occurs, Nymera seeks contractual confidentiality, access controls, and appropriate transfer safeguards from the provider. The practical risk depends on the information involved, which is why the contact form asks readers not to submit sensitive health records. You may ask for the broad location of a processor without requesting another person’s confidential information. For example, a message sent through the contact form may be delivered by an email provider whose servers are located in Singapore or elsewhere in the Asia-Pacific region, and page requests may be answered from a content delivery location closer to the reader. Indonesian law, including UU PDP, allows transfers where the receiving country offers an equivalent level of protection or where adequate and binding safeguards are in place. We therefore prefer providers who publish their security practices, support encryption in transit, and limit staff access to what is needed. If a provider cannot show suitable safeguards, we will choose another or restrict what is sent to it. Questions about a specific transfer can be sent through contact.php.
9. Your rights
Subject to applicable law, you may ask what personal information we hold, request correction, ask for deletion, object to certain processing, or withdraw consent. Send a request to the address or phone number listed on contact.php and describe the request clearly. We may need to verify that the request relates to you before disclosing or changing information. We aim to acknowledge requests within seven days and respond within 30 days, explaining any lawful limitation. In practice, (a) an access request allows you to receive a copy or summary of the information we hold about you, (b) a correction request allows you to fix inaccurate details, (c) a deletion request asks us to remove information that is no longer needed, and (d) an objection or withdrawal asks us to stop a specific use. To help us locate your information quickly, include the email address or telephone number you used and the approximate date of your message. We do not charge a fee for ordinary requests, although we may decline a request that is clearly repetitive or abusive and will explain the reason. If a request is complex, we will tell you within the 30-day period that we need a reasonable extension and why. Where we cannot comply in full, for example because a legal obligation requires retention, we will tell you which part we can fulfil.
10. Children
Nymera is written for adults and does not knowingly invite children to submit personal information. If a parent or guardian believes a child has contacted us, they may write to the desk with enough information to locate the message. We will review the request and remove information where appropriate. We do not knowingly profile children or serve behavioral advertising to them. If a young person under 18 writes to us, we will not use the message for any purpose other than replying and, where appropriate, suggesting that they speak with a parent or guardian. Because the topics on the site concern adult training, we do not direct the pages at younger audiences. A guardian who contacts the desk should state the approximate date of the message and the email address used, so that it can be found and removed within 14 days of verification. We do not collect age information routinely, and we do not ask readers to prove their age in order to read articles.
11. Security
We use access controls, encrypted connections where available, limited administrator access, and routine updates appropriate to a small editorial publication. No internet transmission is risk-free, and we cannot promise absolute security. If you believe a message or account has been exposed, contact Nymera promptly using the published phone number. We will assess the report, contain the issue where possible, and document material changes. Examples of the measures involved are (a) restricting administrator accounts to named staff, (b) using strong, unique credentials and separate access for hosting and email, (c) applying software and server updates on a regular schedule, and (d) reviewing access when a team member changes role. If we discover a security incident that is likely to affect personal information, we will assess it promptly, take steps to limit it, and notify affected people and the competent Indonesian authority within the period required by applicable law. You can help by using a private device when you write to us and by avoiding sending sensitive documents.
12. Complaints and changes
First contact Nymera so we can investigate a concern and provide a written explanation. You may also contact the relevant Indonesian data protection or consumer authority if you believe our response is inadequate. Policy changes are recorded here with a date and a short description. The current version is dated 5 October 2026; a future revision may clarify providers, cookies, or rights without reducing protections retroactively. We aim to send a written response to a complaint within 14 days and to resolve it, or explain what remains open, within 30 days. If you remain dissatisfied, you may raise the matter with the Ministry of Communication and Digital Affairs (Komdigi), with the authority designated under UU PDP, or with the consumer dispute resolution body that applies to your location. Revision log: 5 October 2026 - descriptions of retention periods, processors, cookie groups, international transfers, and the rights procedure were expanded and response times were clarified; 12 January 2026 - first publication of the policy for the Nymera editorial site. Earlier versions can be requested from the desk, and a dated summary of changes is kept for at least three years.