Privacy policy
Effective 5 October 2026. Halcyon, at Jalan Mawar No. 45, Kebayoran Baru, Jakarta Selatan, Jakarta 12160, Indonesia, respects personal information and explains this policy for readers in Indonesia.
This document covers the public website, contact correspondence, editorial enquiries, and ordinary technical operation. It applies whether a reader visits from Indonesia or another country, although local mandatory rights may differ. It does not govern third-party websites linked from Halcyon. The responsible contact point for privacy questions is Halcyon at the address above, by phone at +62 857 2341 9876, or through the contact route published on this site.
Halcyon generally relies on the necessity of responding to an enquiry, site security, and carefully limited operational interests as its processing grounds. Contact correspondence is normally retained for 24 months after the last meaningful exchange, while ordinary security logs are normally retained for 90 days unless an incident requires preservation. Readers may request access, correction, deletion, restriction, or clarification by using the listed contact details. We aim to acknowledge a request within 10 business days and provide a substantive response within 30 days, subject to identity checks and reasonable complexity extensions.
We try to collect only information needed for a stated purpose. We do not ask readers to submit medical records, government identity numbers, financial credentials, or detailed health histories through an ordinary contact form. If such information is sent voluntarily, we will limit access, avoid using it for editorial profiling, and delete it when it is no longer needed for the enquiry.
1. Information and choices
We collect information you voluntarily send through contact forms, such as your name, email address, and message. Server logs may include IP address, browser type, date, and requested page for security and reliability. We use this information to answer enquiries, investigate errors, and improve editorial presentation. We do not sell reader data or use health information to make decisions about individuals.
For example, an email asking about an article may be routed to an editor, while a report of a broken link may be shared with a technical maintainer. Access is limited to people who need the information for that task. We do not combine a reader's message with unrelated browsing activity to create a personal profile. Aggregated technical information may be reviewed to understand page performance, but reports are designed to describe groups rather than identify individuals.
The legal basis is consent for optional communications and legitimate interest for security and basic site operation. Form messages are retained for 24 months after the last correspondence, while security logs are normally deleted within 90 days. You may request access, correction, deletion, restriction, or a copy by contacting Halcyon at the address or phone listed on this site. We will respond within 30 days where reasonably possible.
- Requests should identify the email address or correspondence concerned and the action requested.
- We may ask for proportionate confirmation of identity before releasing or deleting information.
- We may retain a minimal record of a request where required to document compliance, resolve a dispute, or protect security.
- Optional messages can be stopped at any time; stopping them does not affect earlier lawful processing.
Service providers may process limited information on Halcyon's behalf, including the hosting provider, transactional email provider, spam-filtering service, and privacy-conscious analytics provider if measurement is enabled. They receive only the information needed for their function and are expected to apply confidentiality and security controls. Some providers may process data outside Indonesia, including in Singapore, Australia, the European Union, or the United States; where that occurs, Halcyon considers contractual safeguards and the provider's published security commitments.
We retain contact correspondence for up to 24 months after the last meaningful exchange, technical security records for up to 90 days, and consent records for as long as needed to demonstrate the reader's choice and then for a reasonable compliance period. Backups may contain deleted records for up to 35 days before routine rotation. A legal hold, security investigation, or unresolved complaint may require a narrower category of information to remain available for longer.
To raise a concern, contact us first with the relevant page, approximate date, and preferred response method. We aim to acknowledge a privacy request within 10 business days and provide a substantive response within 30 days, subject to complexity and lawful verification. If the outcome is not satisfactory, an Indonesian resident may contact the appropriate consumer or data-protection authority.
2. Information and choices
We collect information you voluntarily send through contact forms, such as your name, email address, and message. Server logs may include IP address, browser type, date, and requested page for security and reliability. We use this information to answer enquiries, investigate errors, and improve editorial presentation. We do not sell reader data or use health information to make decisions about individuals.
For example, an email asking about an article may be routed to an editor, while a report of a broken link may be shared with a technical maintainer. Access is limited to people who need the information for that task. We do not combine a reader's message with unrelated browsing activity to create a personal profile. Aggregated technical information may be reviewed to understand page performance, but reports are designed to describe groups rather than identify individuals.
The legal basis is consent for optional communications and legitimate interest for security and basic site operation. Form messages are retained for 24 months after the last correspondence, while security logs are normally deleted within 90 days. You may request access, correction, deletion, restriction, or a copy by contacting Halcyon at the address or phone listed on this site. We will respond within 30 days where reasonably possible.
- Requests should identify the email address or correspondence concerned and the action requested.
- We may ask for proportionate confirmation of identity before releasing or deleting information.
- We may retain a minimal record of a request where required to document compliance, resolve a dispute, or protect security.
- Optional messages can be stopped at any time; stopping them does not affect earlier lawful processing.
Service providers may process limited information on Halcyon's behalf, including the hosting provider, transactional email provider, spam-filtering service, and privacy-conscious analytics provider if measurement is enabled. They receive only the information needed for their function and are expected to apply confidentiality and security controls. Some providers may process data outside Indonesia, including in Singapore, Australia, the European Union, or the United States; where that occurs, Halcyon considers contractual safeguards and the provider's published security commitments.
We retain contact correspondence for up to 24 months after the last meaningful exchange, technical security records for up to 90 days, and consent records for as long as needed to demonstrate the reader's choice and then for a reasonable compliance period. Backups may contain deleted records for up to 35 days before routine rotation. A legal hold, security investigation, or unresolved complaint may require a narrower category of information to remain available for longer.
To raise a concern, contact us first with the relevant page, approximate date, and preferred response method. We aim to acknowledge a privacy request within 10 business days and provide a substantive response within 30 days, subject to complexity and lawful verification. If the outcome is not satisfactory, an Indonesian resident may contact the appropriate consumer or data-protection authority.
3. Information and choices
We collect information you voluntarily send through contact forms, such as your name, email address, and message. Server logs may include IP address, browser type, date, and requested page for security and reliability. We use this information to answer enquiries, investigate errors, and improve editorial presentation. We do not sell reader data or use health information to make decisions about individuals.
For example, an email asking about an article may be routed to an editor, while a report of a broken link may be shared with a technical maintainer. Access is limited to people who need the information for that task. We do not combine a reader's message with unrelated browsing activity to create a personal profile. Aggregated technical information may be reviewed to understand page performance, but reports are designed to describe groups rather than identify individuals.
The legal basis is consent for optional communications and legitimate interest for security and basic site operation. Form messages are retained for 24 months after the last correspondence, while security logs are normally deleted within 90 days. You may request access, correction, deletion, restriction, or a copy by contacting Halcyon at the address or phone listed on this site. We will respond within 30 days where reasonably possible.
- Requests should identify the email address or correspondence concerned and the action requested.
- We may ask for proportionate confirmation of identity before releasing or deleting information.
- We may retain a minimal record of a request where required to document compliance, resolve a dispute, or protect security.
- Optional messages can be stopped at any time; stopping them does not affect earlier lawful processing.
Service providers may process limited information on Halcyon's behalf, including the hosting provider, transactional email provider, spam-filtering service, and privacy-conscious analytics provider if measurement is enabled. They receive only the information needed for their function and are expected to apply confidentiality and security controls. Some providers may process data outside Indonesia, including in Singapore, Australia, the European Union, or the United States; where that occurs, Halcyon considers contractual safeguards and the provider's published security commitments.
We retain contact correspondence for up to 24 months after the last meaningful exchange, technical security records for up to 90 days, and consent records for as long as needed to demonstrate the reader's choice and then for a reasonable compliance period. Backups may contain deleted records for up to 35 days before routine rotation. A legal hold, security investigation, or unresolved complaint may require a narrower category of information to remain available for longer.
To raise a concern, contact us first with the relevant page, approximate date, and preferred response method. We aim to acknowledge a privacy request within 10 business days and provide a substantive response within 30 days, subject to complexity and lawful verification. If the outcome is not satisfactory, an Indonesian resident may contact the appropriate consumer or data-protection authority.
4. Information and choices
We collect information you voluntarily send through contact forms, such as your name, email address, and message. Server logs may include IP address, browser type, date, and requested page for security and reliability. We use this information to answer enquiries, investigate errors, and improve editorial presentation. We do not sell reader data or use health information to make decisions about individuals.
For example, an email asking about an article may be routed to an editor, while a report of a broken link may be shared with a technical maintainer. Access is limited to people who need the information for that task. We do not combine a reader's message with unrelated browsing activity to create a personal profile. Aggregated technical information may be reviewed to understand page performance, but reports are designed to describe groups rather than identify individuals.
The legal basis is consent for optional communications and legitimate interest for security and basic site operation. Form messages are retained for 24 months after the last correspondence, while security logs are normally deleted within 90 days. You may request access, correction, deletion, restriction, or a copy by contacting Halcyon at the address or phone listed on this site. We will respond within 30 days where reasonably possible.
- Requests should identify the email address or correspondence concerned and the action requested.
- We may ask for proportionate confirmation of identity before releasing or deleting information.
- We may retain a minimal record of a request where required to document compliance, resolve a dispute, or protect security.
- Optional messages can be stopped at any time; stopping them does not affect earlier lawful processing.
Service providers may process limited information on Halcyon's behalf, including the hosting provider, transactional email provider, spam-filtering service, and privacy-conscious analytics provider if measurement is enabled. They receive only the information needed for their function and are expected to apply confidentiality and security controls. Some providers may process data outside Indonesia, including in Singapore, Australia, the European Union, or the United States; where that occurs, Halcyon considers contractual safeguards and the provider's published security commitments.
We retain contact correspondence for up to 24 months after the last meaningful exchange, technical security records for up to 90 days, and consent records for as long as needed to demonstrate the reader's choice and then for a reasonable compliance period. Backups may contain deleted records for up to 35 days before routine rotation. A legal hold, security investigation, or unresolved complaint may require a narrower category of information to remain available for longer.
To raise a concern, contact us first with the relevant page, approximate date, and preferred response method. We aim to acknowledge a privacy request within 10 business days and provide a substantive response within 30 days, subject to complexity and lawful verification. If the outcome is not satisfactory, an Indonesian resident may contact the appropriate consumer or data-protection authority.
5. Information and choices
We collect information you voluntarily send through contact forms, such as your name, email address, and message. Server logs may include IP address, browser type, date, and requested page for security and reliability. We use this information to answer enquiries, investigate errors, and improve editorial presentation. We do not sell reader data or use health information to make decisions about individuals.
For example, an email asking about an article may be routed to an editor, while a report of a broken link may be shared with a technical maintainer. Access is limited to people who need the information for that task. We do not combine a reader's message with unrelated browsing activity to create a personal profile. Aggregated technical information may be reviewed to understand page performance, but reports are designed to describe groups rather than identify individuals.
The legal basis is consent for optional communications and legitimate interest for security and basic site operation. Form messages are retained for 24 months after the last correspondence, while security logs are normally deleted within 90 days. You may request access, correction, deletion, restriction, or a copy by contacting Halcyon at the address or phone listed on this site. We will respond within 30 days where reasonably possible.
- Requests should identify the email address or correspondence concerned and the action requested.
- We may ask for proportionate confirmation of identity before releasing or deleting information.
- We may retain a minimal record of a request where required to document compliance, resolve a dispute, or protect security.
- Optional messages can be stopped at any time; stopping them does not affect earlier lawful processing.
Service providers may process limited information on Halcyon's behalf, including the hosting provider, transactional email provider, spam-filtering service, and privacy-conscious analytics provider if measurement is enabled. They receive only the information needed for their function and are expected to apply confidentiality and security controls. Some providers may process data outside Indonesia, including in Singapore, Australia, the European Union, or the United States; where that occurs, Halcyon considers contractual safeguards and the provider's published security commitments.
We retain contact correspondence for up to 24 months after the last meaningful exchange, technical security records for up to 90 days, and consent records for as long as needed to demonstrate the reader's choice and then for a reasonable compliance period. Backups may contain deleted records for up to 35 days before routine rotation. A legal hold, security investigation, or unresolved complaint may require a narrower category of information to remain available for longer.
To raise a concern, contact us first with the relevant page, approximate date, and preferred response method. We aim to acknowledge a privacy request within 10 business days and provide a substantive response within 30 days, subject to complexity and lawful verification. If the outcome is not satisfactory, an Indonesian resident may contact the appropriate consumer or data-protection authority.
6. Information and choices
We collect information you voluntarily send through contact forms, such as your name, email address, and message. Server logs may include IP address, browser type, date, and requested page for security and reliability. We use this information to answer enquiries, investigate errors, and improve editorial presentation. We do not sell reader data or use health information to make decisions about individuals.
For example, an email asking about an article may be routed to an editor, while a report of a broken link may be shared with a technical maintainer. Access is limited to people who need the information for that task. We do not combine a reader's message with unrelated browsing activity to create a personal profile. Aggregated technical information may be reviewed to understand page performance, but reports are designed to describe groups rather than identify individuals.
The legal basis is consent for optional communications and legitimate interest for security and basic site operation. Form messages are retained for 24 months after the last correspondence, while security logs are normally deleted within 90 days. You may request access, correction, deletion, restriction, or a copy by contacting Halcyon at the address or phone listed on this site. We will respond within 30 days where reasonably possible.
- Requests should identify the email address or correspondence concerned and the action requested.
- We may ask for proportionate confirmation of identity before releasing or deleting information.
- We may retain a minimal record of a request where required to document compliance, resolve a dispute, or protect security.
- Optional messages can be stopped at any time; stopping them does not affect earlier lawful processing.
Service providers may process limited information on Halcyon's behalf, including the hosting provider, transactional email provider, spam-filtering service, and privacy-conscious analytics provider if measurement is enabled. They receive only the information needed for their function and are expected to apply confidentiality and security controls. Some providers may process data outside Indonesia, including in Singapore, Australia, the European Union, or the United States; where that occurs, Halcyon considers contractual safeguards and the provider's published security commitments.
We retain contact correspondence for up to 24 months after the last meaningful exchange, technical security records for up to 90 days, and consent records for as long as needed to demonstrate the reader's choice and then for a reasonable compliance period. Backups may contain deleted records for up to 35 days before routine rotation. A legal hold, security investigation, or unresolved complaint may require a narrower category of information to remain available for longer.
To raise a concern, contact us first with the relevant page, approximate date, and preferred response method. We aim to acknowledge a privacy request within 10 business days and provide a substantive response within 30 days, subject to complexity and lawful verification. If the outcome is not satisfactory, an Indonesian resident may contact the appropriate consumer or data-protection authority.
7. Information and choices
We collect information you voluntarily send through contact forms, such as your name, email address, and message. Server logs may include IP address, browser type, date, and requested page for security and reliability. We use this information to answer enquiries, investigate errors, and improve editorial presentation. We do not sell reader data or use health information to make decisions about individuals.
For example, an email asking about an article may be routed to an editor, while a report of a broken link may be shared with a technical maintainer. Access is limited to people who need the information for that task. We do not combine a reader's message with unrelated browsing activity to create a personal profile. Aggregated technical information may be reviewed to understand page performance, but reports are designed to describe groups rather than identify individuals.
The legal basis is consent for optional communications and legitimate interest for security and basic site operation. Form messages are retained for 24 months after the last correspondence, while security logs are normally deleted within 90 days. You may request access, correction, deletion, restriction, or a copy by contacting Halcyon at the address or phone listed on this site. We will respond within 30 days where reasonably possible.
- Requests should identify the email address or correspondence concerned and the action requested.
- We may ask for proportionate confirmation of identity before releasing or deleting information.
- We may retain a minimal record of a request where required to document compliance, resolve a dispute, or protect security.
- Optional messages can be stopped at any time; stopping them does not affect earlier lawful processing.
Service providers may process limited information on Halcyon's behalf, including the hosting provider, transactional email provider, spam-filtering service, and privacy-conscious analytics provider if measurement is enabled. They receive only the information needed for their function and are expected to apply confidentiality and security controls. Some providers may process data outside Indonesia, including in Singapore, Australia, the European Union, or the United States; where that occurs, Halcyon considers contractual safeguards and the provider's published security commitments.
We retain contact correspondence for up to 24 months after the last meaningful exchange, technical security records for up to 90 days, and consent records for as long as needed to demonstrate the reader's choice and then for a reasonable compliance period. Backups may contain deleted records for up to 35 days before routine rotation. A legal hold, security investigation, or unresolved complaint may require a narrower category of information to remain available for longer.
To raise a concern, contact us first with the relevant page, approximate date, and preferred response method. We aim to acknowledge a privacy request within 10 business days and provide a substantive response within 30 days, subject to complexity and lawful verification. If the outcome is not satisfactory, an Indonesian resident may contact the appropriate consumer or data-protection authority.
8. Information and choices
We collect information you voluntarily send through contact forms, such as your name, email address, and message. Server logs may include IP address, browser type, date, and requested page for security and reliability. We use this information to answer enquiries, investigate errors, and improve editorial presentation. We do not sell reader data or use health information to make decisions about individuals.
For example, an email asking about an article may be routed to an editor, while a report of a broken link may be shared with a technical maintainer. Access is limited to people who need the information for that task. We do not combine a reader's message with unrelated browsing activity to create a personal profile. Aggregated technical information may be reviewed to understand page performance, but reports are designed to describe groups rather than identify individuals.
The legal basis is consent for optional communications and legitimate interest for security and basic site operation. Form messages are retained for 24 months after the last correspondence, while security logs are normally deleted within 90 days. You may request access, correction, deletion, restriction, or a copy by contacting Halcyon at the address or phone listed on this site. We will respond within 30 days where reasonably possible.
- Requests should identify the email address or correspondence concerned and the action requested.
- We may ask for proportionate confirmation of identity before releasing or deleting information.
- We may retain a minimal record of a request where required to document compliance, resolve a dispute, or protect security.
- Optional messages can be stopped at any time; stopping them does not affect earlier lawful processing.
Service providers may process limited information on Halcyon's behalf, including the hosting provider, transactional email provider, spam-filtering service, and privacy-conscious analytics provider if measurement is enabled. They receive only the information needed for their function and are expected to apply confidentiality and security controls. Some providers may process data outside Indonesia, including in Singapore, Australia, the European Union, or the United States; where that occurs, Halcyon considers contractual safeguards and the provider's published security commitments.
We retain contact correspondence for up to 24 months after the last meaningful exchange, technical security records for up to 90 days, and consent records for as long as needed to demonstrate the reader's choice and then for a reasonable compliance period. Backups may contain deleted records for up to 35 days before routine rotation. A legal hold, security investigation, or unresolved complaint may require a narrower category of information to remain available for longer.
To raise a concern, contact us first with the relevant page, approximate date, and preferred response method. We aim to acknowledge a privacy request within 10 business days and provide a substantive response within 30 days, subject to complexity and lawful verification. If the outcome is not satisfactory, an Indonesian resident may contact the appropriate consumer or data-protection authority.
9. Information and choices
We collect information you voluntarily send through contact forms, such as your name, email address, and message. Server logs may include IP address, browser type, date, and requested page for security and reliability. We use this information to answer enquiries, investigate errors, and improve editorial presentation. We do not sell reader data or use health information to make decisions about individuals.
For example, an email asking about an article may be routed to an editor, while a report of a broken link may be shared with a technical maintainer. Access is limited to people who need the information for that task. We do not combine a reader's message with unrelated browsing activity to create a personal profile. Aggregated technical information may be reviewed to understand page performance, but reports are designed to describe groups rather than identify individuals.
The legal basis is consent for optional communications and legitimate interest for security and basic site operation. Form messages are retained for 24 months after the last correspondence, while security logs are normally deleted within 90 days. You may request access, correction, deletion, restriction, or a copy by contacting Halcyon at the address or phone listed on this site. We will respond within 30 days where reasonably possible.
- Requests should identify the email address or correspondence concerned and the action requested.
- We may ask for proportionate confirmation of identity before releasing or deleting information.
- We may retain a minimal record of a request where required to document compliance, resolve a dispute, or protect security.
- Optional messages can be stopped at any time; stopping them does not affect earlier lawful processing.
Service providers may process limited information on Halcyon's behalf, including the hosting provider, transactional email provider, spam-filtering service, and privacy-conscious analytics provider if measurement is enabled. They receive only the information needed for their function and are expected to apply confidentiality and security controls. Some providers may process data outside Indonesia, including in Singapore, Australia, the European Union, or the United States; where that occurs, Halcyon considers contractual safeguards and the provider's published security commitments.
We retain contact correspondence for up to 24 months after the last meaningful exchange, technical security records for up to 90 days, and consent records for as long as needed to demonstrate the reader's choice and then for a reasonable compliance period. Backups may contain deleted records for up to 35 days before routine rotation. A legal hold, security investigation, or unresolved complaint may require a narrower category of information to remain available for longer.
To raise a concern, contact us first with the relevant page, approximate date, and preferred response method. We aim to acknowledge a privacy request within 10 business days and provide a substantive response within 30 days, subject to complexity and lawful verification. If the outcome is not satisfactory, an Indonesian resident may contact the appropriate consumer or data-protection authority.
10. Information and choices
We collect information you voluntarily send through contact forms, such as your name, email address, and message. Server logs may include IP address, browser type, date, and requested page for security and reliability. We use this information to answer enquiries, investigate errors, and improve editorial presentation. We do not sell reader data or use health information to make decisions about individuals.
For example, an email asking about an article may be routed to an editor, while a report of a broken link may be shared with a technical maintainer. Access is limited to people who need the information for that task. We do not combine a reader's message with unrelated browsing activity to create a personal profile. Aggregated technical information may be reviewed to understand page performance, but reports are designed to describe groups rather than identify individuals.
The legal basis is consent for optional communications and legitimate interest for security and basic site operation. Form messages are retained for 24 months after the last correspondence, while security logs are normally deleted within 90 days. You may request access, correction, deletion, restriction, or a copy by contacting Halcyon at the address or phone listed on this site. We will respond within 30 days where reasonably possible.
- Requests should identify the email address or correspondence concerned and the action requested.
- We may ask for proportionate confirmation of identity before releasing or deleting information.
- We may retain a minimal record of a request where required to document compliance, resolve a dispute, or protect security.
- Optional messages can be stopped at any time; stopping them does not affect earlier lawful processing.
Service providers may process limited information on Halcyon's behalf, including the hosting provider, transactional email provider, spam-filtering service, and privacy-conscious analytics provider if measurement is enabled. They receive only the information needed for their function and are expected to apply confidentiality and security controls. Some providers may process data outside Indonesia, including in Singapore, Australia, the European Union, or the United States; where that occurs, Halcyon considers contractual safeguards and the provider's published security commitments.
We retain contact correspondence for up to 24 months after the last meaningful exchange, technical security records for up to 90 days, and consent records for as long as needed to demonstrate the reader's choice and then for a reasonable compliance period. Backups may contain deleted records for up to 35 days before routine rotation. A legal hold, security investigation, or unresolved complaint may require a narrower category of information to remain available for longer.
To raise a concern, contact us first with the relevant page, approximate date, and preferred response method. We aim to acknowledge a privacy request within 10 business days and provide a substantive response within 30 days, subject to complexity and lawful verification. If the outcome is not satisfactory, an Indonesian resident may contact the appropriate consumer or data-protection authority.
Changes and complaints
This policy was reviewed on 5 October 2026. Material changes will be dated on this page. Indonesian residents may contact the relevant data-protection or consumer authority if a concern is not resolved after contacting us.
The 5 October 2026 version clarifies retention periods, international service-provider processing, and the practical route for rights requests. A later revision will show its effective date and a short description of what changed. Earlier versions may be retained internally for accountability, but the version displayed on this page is the operative public notice.