Privacy Policy
Effective 5 October 2026. This policy explains how Klymer, operating from Jakarta, Indonesia, handles information when you read our editorial website.
1. Scope
This document applies to Klymer pages, contact enquiries, newsletter discussions and ordinary browsing. It does not govern websites linked from our pages. By using the site, you acknowledge this explanation and may contact us if any part is unclear.
2. Information Collected
We may receive your name, email address, phone number and message when you contact us. Technical information such as browser type, approximate location, referring page and access time may be recorded in server logs. We do not ask for health diagnoses to read our articles.
3. Legal Basis
We use information to respond to a request, maintain site security and understand aggregate readership. Where optional analytics are used, consent is the basis. We rely on legitimate interests for fraud prevention and service reliability, balanced against reader privacy.
4. Use
Contact details are used to answer the specific enquiry, manage editorial correspondence and improve clarity. We do not sell personal information or use health information for advertising audiences. We may remove identifying detail from correspondence before using it as an editorial example.
5. Retention
Contact enquiries are normally retained for 24 months after the last meaningful exchange. Security logs may remain for up to 90 days. Consent records may be retained for 24 months so we can demonstrate the choice made, after which they are reviewed for deletion.
6. Processors
Hosting, email delivery, security and analytics vendors may process limited information on our instructions. They are expected to use safeguards and confidentiality obligations. We disclose information when required by Indonesian law or to protect the site and its readers.
7. Cookies
Session cookies may last until a browser closes; preference cookies may last 12 months; optional analytics cookies may last up to 13 months. The cookie banner records a choice in a browser value named cookieChoice. Details appear in cookies.php.
8. International Transfers
Some infrastructure providers may process data outside Indonesia. We select providers with contractual and technical safeguards and limit the information shared. Contact correspondence is not intentionally transferred for unrelated marketing.
9. Your Rights
You may request access, correction, deletion, restriction or a copy of personal information, subject to lawful exceptions. Send a request to the address in contact.php and include enough detail for us to identify the relevant exchange. We aim to respond within 30 calendar days.
10. Complaints
First contact Klymer so we can investigate. You may also raise a concern with the relevant Indonesian data protection or consumer authority. We will preserve relevant records while a complaint is assessed and will communicate the outcome where legally permitted.
11. Children
Klymer is written for adults and does not knowingly collect information from children. If a parent or guardian believes a child has submitted personal information, contact us so we can review and delete it where appropriate.
12. Changes
Revision history: 5 October 2026, initial publication. Future changes will show a new effective date on this page. Material changes will be described near the top so readers can understand what has changed.
Operational details
For transparency, Klymer is based at Jalan Anggrek Raya No. 15, Kemanggisan, Palmerah, Jakarta Barat 11480, Indonesia. The privacy contact route is the contact form or phone +62 813 5792 4680. We normally acknowledge a privacy enquiry within five business days and provide a substantive response within 30 calendar days, subject to identity checks and the complexity of the request.
Depending on the request, we may ask for the email address used in correspondence, the relevant page and a clear description of the concern. We do not request passwords or unnecessary identity documents. Where Indonesian law or another applicable rule requires a different process, we will explain the applicable limit and retain only the record needed to document the decision.
Service providers may include a hosting provider, transactional email provider, consent-management service, security monitoring provider and privacy-conscious analytics provider. Their access is limited to the function they perform, and contracts or service terms are reviewed for confidentiality, security and deletion expectations. Some providers may process information outside Indonesia; where that occurs, Klymer considers contractual safeguards, access controls and applicable transfer requirements.
Readers may request access, correction, deletion, restriction or information about processing, and may withdraw optional analytics consent. Deletion is not absolute where a record is needed for security, legal compliance or the resolution of a documented dispute. Requests can be made through contact.php, and an appeal or complaint may be directed to the relevant Indonesian data-protection authority if a concern is not resolved.
Change record: this version was issued on 5 October 2026. Klymer will review the policy at least annually and will note material changes by date, including changes to vendors, retention periods or reader-rights procedures.
For practical purposes, browsing data is handled in layers. The page request may expose an IP address to the hosting provider, while Klymer generally uses only an approximate location for aggregate reporting. Contact data is separated conceptually from readership statistics, and an email address is not used as a reading-interest label. If a reader sends an attachment, it is reviewed only for the purpose of answering the enquiry and may be deleted sooner when no longer needed.
Our ordinary legal and operational basis depends on the activity. Answering a voluntary enquiry is connected to the reader's request; maintaining security records supports service integrity; optional analytics require a clear choice; and a legal disclosure may be retained where a record is necessary to demonstrate compliance. Where consent is withdrawn, future optional collection stops, although a limited record of the withdrawal may remain for up to 24 months.
Examples of processors may include a Vercel-hosted deployment, a transactional email provider, a security or bot-filtering provider, and an analytics service configured for aggregate measurement. Provider access is limited by role, and credentials are not intended to be shared with editorial writers. Some processing may take place outside Indonesia, in which case Klymer considers contractual confidentiality, access controls and the safeguards available under the provider's service arrangement.
A rights request should identify the relevant email address or enquiry and describe the action requested. Klymer may ask a proportionate verification question to prevent disclosure to the wrong person, but will not ask for a password. We normally acknowledge requests within five business days and aim to respond within 30 calendar days; complex requests or legally required extensions will be explained in writing.
Change record: this policy is effective 5 October 2026. A review is planned for October 2027 or sooner if the contact form, hosting arrangement, analytics settings, retention periods or applicable Indonesian privacy requirements materially change.