Privacy policy

Effective 1 January 2026. This policy explains how Nectar, operating from Jalan Pangeran Diponegoro No. 88, Menteng, Jakarta Pusat 10310, Indonesia, handles information when you read the site, contact the editorial desk or attend an event.

1. Scope

This document covers the public website, correspondence and event administration. It does not govern third-party sites linked from our pages. We apply Indonesian privacy requirements and aim to follow internationally recognised principles of transparency, minimisation and security.

2. Information collected

We may receive your name, email address, telephone number, message and event preferences when you provide them. Server logs can include IP address, browser type, requested page and approximate time. We do not request health records through the public contact form.

3. Purpose and legal basis

We use contact details to answer requests, maintain site security and administer consent-based events. Processing is based on your request, legitimate operational interests and consent where optional cookies or communications are involved. You may withdraw optional consent at any time.

4. Retention

Routine correspondence is retained for 24 months after the last meaningful exchange, then deleted or anonymised. Event registration records are retained for 12 months after the event. Security logs are normally retained for 90 days unless needed to investigate an incident.

5. Cookies

The cookie choice named cookieChoice is stored in your browser until you remove it or clear site data. Essential session data may last for the browser session. Optional analytics cookies, when enabled, are configured with a maximum lifespan of 13 months and are reviewed in our cookie policy.

6. Service providers

Hosting, email and security providers may process limited information under contractual confidentiality duties. We do not sell personal information or allow advertisers to use contact submissions for targeting.

7. International transfers

Some technical providers may operate outside Indonesia. Where information crosses borders, we seek contractual safeguards, access controls and a level of protection appropriate to the purpose. We limit the information shared to what the provider needs.

8. Your rights

You may ask for access, correction, deletion, restriction or an explanation of processing, subject to lawful exceptions. Email [email protected] with the subject “Privacy request”; we may verify identity before responding. We aim to respond within 30 days.

9. Security

We use encrypted connections, restricted administrative access and routine review of account permissions. No internet transmission is risk-free, so please avoid sending sensitive medical information through ordinary email or the public form.

10. Complaints

First contact Nectar so we can investigate. If you remain concerned, you may seek guidance from the relevant Indonesian data protection or consumer authority. We will preserve a record of the issue and our response.

11. Children

The site is intended for adults and is not knowingly directed to children. If a parent or guardian believes a child has submitted information, contact us and we will review and remove it where appropriate.

12. Changes

We review this policy annually. Changes are recorded here with a date and summary: 1 January 2026, initial publication; 1 July 2026, clarified retention and event handling. Material changes will be highlighted on the site.

For clarity, contact information is used only in the context in which it was provided. A message asking about an article is handled by the editorial desk, while event details are used by the person coordinating that event. We do not ask visitors to place medical histories, identity documents or payment information in an ordinary message. If someone sends sensitive information accidentally, we restrict access, record the handling decision and remove it when it is no longer needed.

Our service providers may include a hosting provider, an email delivery provider and a security or traffic-monitoring provider. They receive only the information needed for their contracted function and are expected to apply access controls, confidentiality duties and deletion procedures. Where a provider processes information outside Indonesia, we consider contractual safeguards and the nature of the information before using that service. We do not sell contact submissions or use them to create a behavioural advertising profile.

You may ask what personal information we hold, request correction of inaccurate details, ask for deletion where retention is not required, or withdraw consent for optional processing. Send a clear request to [email protected] or write to Jalan Pangeran Diponegoro No. 88, Menteng, Jakarta Pusat 10310, Indonesia, including enough detail for us to identify the request without sending unnecessary documents. We aim to acknowledge requests within 10 business days and respond within 30 calendar days, subject to lawful extensions for complex requests. We may retain a minimal record of the request to demonstrate compliance.

We review this policy at least every six months and after a material change to the website or a service provider. The current version took effect on 1 January 2026; the next scheduled review is 31 December 2026. Questions that remain unresolved may be directed to the relevant Indonesian data-protection authority or another competent supervisory body.

For practical purposes, this scope includes ordinary browser access, contact messages, event registrations and requests to correct or remove information. It does not include data controlled by an external website merely because Nectar links to it. We do not require a visitor to provide sensitive personal details to read public articles. If such details are sent voluntarily, access is limited to the people handling the message and the material is deleted or anonymised when the stated purpose ends.

Our lawful handling is limited to responding to a request, maintaining service security, meeting an administrative obligation or acting on a clear optional consent. Typical processors may include a hosting provider, an email delivery service and a security monitoring provider; they receive only the fields needed for their function. A provider located outside Indonesia may process technical or correspondence data under contractual confidentiality and security controls. We do not sell contact submissions or use them to create a separate advertising profile.

You may request access, correction, deletion where applicable, restriction of optional processing or information about the source and recipient of your data. Email [email protected] or write to Jalan Pangeran Diponegoro No. 88, Menteng, Jakarta Pusat 10310, Indonesia, and describe the request without sending unnecessary identity documents. We aim to acknowledge a request within 10 business days and respond within 30 calendar days, with a further explanation if a lawful extension is needed.

Records are reviewed against the stated periods rather than retained indefinitely. A minimal compliance record may remain after deletion where needed to document a request, resolve a dispute or meet a legal obligation. This policy was effective on 1 January 2026 and is scheduled for review on 31 December 2026; material changes will carry a new date and a concise explanation.