Editorial note: Nebula provides general education. Training decisions should reflect individual medical history and professional advice.
Effective 1 January 2026 · reviewed 1 October 2026

Privacy policy

Nebula respects the privacy of readers visiting this editorial website from Indonesia and elsewhere. This policy explains what information is collected, why it is used and how a person may exercise their rights. It applies to pages, contact forms, cookies and ordinary communications associated with Nebula at Jalan Cendrawasih No. 45, Duren Sawit, Jakarta Timur 13440, Indonesia. The policy is written with Indonesia's Personal Data Protection Law (Law No. 27 of 2022) and the Electronic Information and Transactions framework in mind, and it uses plain language so that a reader does not need legal training to follow it. Where a reader lives outside Indonesia, mandatory local rules may add protections, and Nebula will honour them where they clearly apply. If any sentence below seems unclear, a reader is welcome to ask for an explanation before sending any personal information.

1. Scope and controller

Nebula is the publisher responsible for the website and editorial contact channel. This document covers information supplied directly by a visitor and limited technical information created when a browser requests a page. It does not govern third-party websites linked from our articles. Questions may be sent through contact.php or by calling +62 856 9317 4825. For the purposes of Indonesian data protection rules, Nebula acts as the data controller for the contact channel and for server logs. The policy covers every page of the publication, including articles, the glossary, the resources library and event listings, but it does not cover offline conversations or documents that a reader chooses to publish elsewhere. Telephone enquiries are answered during ordinary Jakarta office hours (WIB, UTC+7), and the desk may make a brief written note of the topic so that the conversation can be followed up if requested.

2. Information collected

We may receive a name, email address and message when a person uses the contact form. Server logs may contain an IP address, date, browser type, requested URL and referrer. We do not ask for medical records, payment-card details or government identity numbers through the site. The following points clarify the categories in practice:

  • (a) Contact form: name, email address, optional subject and the free-text message. A telephone number is stored only if the sender writes it in the message.
  • (b) Server logs: technical records created automatically, such as the HTTP status code, the page requested and the approximate time. These do not reveal a reader's name.
  • (c) Cookie preference: a single value recording whether the cookie notice was accepted or rejected, kept in the visitor's own browser rather than in a Nebula database.
  • (d) Information not collected: precise location, contacts, photographs, biometric data, reader reading history linked to a person, or any profile built from articles viewed.

3. Purpose and legal basis

Contact information is used to answer a request and is processed because communication is requested by the visitor. Security logs are used for legitimate interests in protecting availability and investigating abuse. Optional analytics operate only where the visitor chooses acceptance through the cookie banner. Under Law No. 27 of 2022 these grounds correspond to the data subject's consent or request, and to the controller's legitimate interest where that interest does not override the rights of the reader. Contact details are never used for newsletters, marketing lists or profiling unless the person separately and clearly asks to receive such messages. A reader who objects to security logging may write to the desk, although some technical records cannot be switched off for an individual without weakening protection for all visitors.

4. Retention

Contact messages are normally retained for 24 months after the last meaningful exchange, then deleted or anonymised. Security logs are retained for 90 days unless an incident requires preservation. Cookie choices remain in the browser until removed by the visitor or replaced by a new choice. In practical terms the retention periods work as follows:

  • (a) A message that receives a reply is counted from the date of the final reply, so a later follow-up restarts the 24-month period.
  • (b) A message that raises no further question and needs no answer, such as an obvious automated message, is deleted within 30 days.
  • (c) Backup copies of the mailbox are overwritten on a rolling cycle of up to 35 days after deletion from the live system.
  • (d) Records kept for an investigation, a legal claim or a request from an authority are held only for as long as that matter remains open, and are then removed.

5. Rights

Subject to applicable Indonesian law, a person may ask for access, correction, deletion, restriction or an explanation of processing. Send a clear request with the relevant email address to Nebula; we may ask for reasonable confirmation to avoid disclosing information to the wrong person. A request can be made in English or Bahasa Indonesia, by post to the Jakarta address, through contact.php or by telephone followed by a short written confirmation. Nebula aims to acknowledge a request within 7 business days and to complete it within 30 days, and the period may be extended once for a stated reason when a request is complex. A person may also withdraw consent for a specific purpose at any time, and withdrawal does not affect processing carried out before the withdrawal. No fee is charged for ordinary requests, and if a request is declined in part, the reason will be explained in writing.

6. Processors

Hosting, email delivery and security providers may process technical data only as needed to provide their services. Nebula selects providers with appropriate contractual and technical safeguards. We do not sell personal information or provide reader lists to advertisers. In the current publication the categories of processor are a managed web-hosting provider whose infrastructure is located in Indonesia and the wider Southeast Asia region, an email service used to receive and answer messages, and a network security service that filters abusive traffic. Each is bound by written terms limiting use of the data to the stated service, requiring confidentiality and requiring prompt notice of a security incident. A reader may ask the desk for the current list of processor names, and the list will be provided in writing within the response periods described in section 5.

7. Cookies

The cookie named cookieChoice records accept or reject for the cookie banner. It is a first-party preference and has no advertising purpose. If optional analytics are enabled in a future release, the relevant provider, purpose and lifespan will be disclosed before activation. The cookieChoice value is stored for up to 12 months and contains only the word accept or reject. It is not shared with other organisations and is not linked to the contact form or to server logs. Further information, including how to remove the value, is set out in the separate cookie policy.

8. International transfers

Website infrastructure may process data in jurisdictions outside Indonesia. Where this occurs, Nebula seeks contractual safeguards, access controls and a transfer arrangement appropriate to the service. A visitor may ask where a particular message is stored. Under Law No. 27 of 2022, a transfer abroad is expected to meet a comparable level of protection, or to be supported by binding contractual terms, or to rest on the consent of the person concerned. In practice Nebula prefers regional hosting where it is available, limits the fields shared with any foreign service, and avoids transferring message content unless the service needs it to deliver email. If a reader is uncomfortable with a transfer, the reader can instead telephone the desk or write by post.

9. Children and sensitive information

The publication is not directed to children and does not knowingly collect their personal information. Please do not submit health details, diagnoses or treatment documents through the contact form. If sensitive data is sent accidentally, request deletion promptly. On receiving such a request, the desk will remove the message from the live mailbox within 7 business days and will not use the content for any other purpose. Where a parent or guardian reports that a child has used the form, Nebula will confirm the report, delete the message and note the date of deletion in the internal request log, which contains no message content.

10. Complaints

We encourage a direct written complaint so the editorial desk can investigate. A complaint should identify the request, relevant date and desired resolution. Nebula aims to acknowledge within 7 business days and respond within 30 days, subject to complexity. The reply will state what was found, what action has been taken and, where relevant, how to escalate. A reader who remains dissatisfied may contact the Indonesian personal data protection authority, currently administered through the Ministry of Communication and Digital Affairs (Komdigi), and may also seek advice from a legal adviser of their choice. Raising a complaint with Nebula first is encouraged but is not required before contacting an authority.

11. Security

Access is limited to people who need it, services are configured with ordinary security controls and suspicious traffic may be blocked. No internet transmission is guaranteed to be completely secure, so visitors should avoid sending confidential material. Examples of the controls in use include encrypted connections (HTTPS) for the website, individual rather than shared mailbox access, passwords combined with a second verification step for administrative accounts, and prompt installation of security updates. If a security incident is likely to affect personal data, Nebula will assess it quickly, notify affected persons and the competent authority within the period required by Indonesian law (currently 3 x 24 hours for notification to the authority), and record the steps taken to reduce harm.

12. Changes

Version 1.0 was published on 1 January 2026. This review was recorded on 1 October 2026. Material changes will be shown on this page with a new date, while older versions may be retained for accountability. The change log below summarises the dated entries in plain terms:

  • 1 January 2026 (version 1.0): first publication of the policy, covering the contact form, server logs and the cookieChoice preference.
  • 1 October 2026 (review): wording on retention, processors, transfers and complaint times reviewed; no new category of data was added.

Minor corrections to spelling or formatting do not change the effective date, whereas any change to purposes, retention or recipients will be dated and described at the top of the page.