Perma
HomeAboutInsightsJournalResourcesServicesStandardsAssessmentNutritionContact

Privacy Policy

Effective 5 October 2026. Perma respects the privacy of visitors in Indonesia and readers elsewhere. This policy explains what information may be received through this website, why it is used, how long it is retained, and how a person can ask questions about it.

This document covers the public website, editorial correspondence, event enquiries, and ordinary technical operation. It does not replace a notice supplied by a third-party provider. The current version is dated so readers can compare it with later revisions.

1. Scope

This policy applies to perma pages, contact correspondence, event registration, and technical logs generated when a browser requests content. It does not govern third-party websites linked from our pages. Perma is an editorial information service, not a medical record system. Please do not submit sensitive health details through ordinary email or the contact form.

We do not ask readers to provide diagnoses, medication histories, identity numbers, or financial information. If such information is sent voluntarily, it is handled only as needed to secure and delete the message. Questions about a linked provider must be directed to that provider.

2. Information received

We may receive a name, email address, message contents, and optional event preferences when a person chooses to contact us. Our hosting systems may record an IP address, browser type, requested page, referring page, and approximate time. Cookie choices are stored locally in the browser and are not treated as a profile.

We collect only what is supplied or technically necessary to deliver a page. Email headers may show the sending service and time. Access logs can help identify abusive requests, broken links, or unusual traffic patterns, but they are not used to infer a person’s health, income, or personal interests. We do not intentionally collect information from children.

3. Purpose and legal basis

Contact details are used to respond to a request, maintain editorial correspondence, and investigate corrections. The applicable basis is consent where a person submits a form and legitimate interest where limited security logs are needed to keep the service reliable. We do not use health-related inferences for advertising or sell contact lists.

Consent can be withdrawn by contacting us, although this does not affect processing already completed lawfully. Security processing is limited to protecting availability and integrity. Where Indonesian law or another applicable law requires a record to be kept, that obligation may apply alongside the purposes above.

4. Retention

Routine contact messages are retained for 24 months after the last meaningful exchange, then deleted or anonymised. Security logs are normally retained for 90 days. Records needed to document a correction or legal request may remain for seven years with access restricted to the responsible team.

Backups may preserve deleted material for up to 35 days before ordinary rotation. Longer retention is limited to accounting, dispute, legal, or security documentation and is reviewed for necessity. Anonymised editorial statistics are not treated as contact records.

5. User rights

A person may request access, correction, deletion, restriction, or an explanation of processing.

Requests should be sent to the contact details in section 9 and should identify the relevant correspondence without including unnecessary sensitive information. We normally acknowledge a privacy request within five business days and provide a substantive response within 30 calendar days, subject to identity and complexity. A reasonable verification step may be requested to prevent disclosure to the wrong person.

  • Access: a copy or description of relevant personal information.
  • Correction: updating inaccurate contact details or correspondence context.
  • Deletion or restriction: removal or temporary limitation where retention is not required.

6. Service providers

Perma may use hosting, email delivery, security, and domain services to operate the website. These providers receive only the information needed for their defined function and are expected to protect it contractually. Current operational providers may include Vercel for hosting and infrastructure, an email provider used for correspondence, and domain or security vendors selected for reliable delivery.

Providers may process data on our instructions and may keep limited operational logs under their own legal obligations. We do not authorize them to use Perma correspondence to create advertising profiles. A provider list can change when infrastructure changes; material changes will be reflected in a revised policy.

7. International transfers

Infrastructure providers may process technical data in countries outside Indonesia. Before using a provider, Perma considers security controls, contractual safeguards, access limitations, and the nature of the information involved. Visitors may contact us for a current description of the principal transfer locations.

Transfers are limited to what is necessary for hosting, communications, or security. Where applicable, contractual protections and lawful transfer mechanisms are used.

8. Security

We use access controls, limited retention, encrypted transport where supported, and provider security measures appropriate to a small editorial publication. No internet transmission can be described as completely secure. Suspected incidents are assessed, contained, documented, and communicated where applicable law requires.

9. Complaints and contact

Privacy questions may be sent to Jalan Sudirman Kav. 22, Karet Semanggi, Setiabudi, Jakarta Selatan, DKI Jakarta 12930 or +62 813 5792 4680. Please identify the subject of the request and avoid sending sensitive information. We aim to acknowledge correspondence within five business days.

If a concern cannot be resolved, a person may seek guidance from an applicable Indonesian authority or other competent data-protection body. We will provide a response or explain any permitted limitation within 30 calendar days.

10. Changes

This policy was issued on 5 October 2026. The next scheduled review is 5 January 2027, or sooner if the website, providers, or applicable requirements change. A dated revision note will explain material changes.

For practical purposes, Perma’s privacy approach is based on data minimisation. A contact message is used to understand and answer the question actually asked, rather than to build a broader profile. For example, a request about an article correction may be retained with the relevant page reference while unrelated personal details are removed. Access is limited to people who need the correspondence to respond, maintain the publication, or address a security matter. Where a processor operates outside Indonesia, the transfer is limited to the service function and governed by the provider’s security and privacy terms.

Requests concerning personal information can include the email address used for correspondence, the approximate date of contact, and the relevant page or subject. We may ask for a limited confirmation of identity where disclosure to another person would be possible, but we do not request identity numbers or unnecessary sensitive records. A request is normally acknowledged within five business days, reviewed within 30 calendar days, and extended only where the request is unusually complex or applicable law permits additional time. If information cannot be deleted because it is needed for a legal, security, or accounting purpose, we will explain that limitation.

Perma reviews operational retention at least once during each annual policy review. The 5 October 2026 review recorded the 24-month correspondence period, 90-day security-log period, and 35-day backup rotation described above. Material changes to providers, cookies, international processing, or user rights will be dated in the next published version. Questions may be sent to Jalan Sudirman Kav. 22, Karet Semanggi, Setiabudi, Jakarta Selatan, DKI Jakarta 12930 or +62 813 5792 4680.

Additional privacy detail

Perma collects the information a visitor chooses to provide, such as an email address, telephone number, name, and the contents of a message. Technical data may include browser type, approximate access time, referring page, and security information needed to keep the site functioning. The publication does not require sensitive personal information to read ordinary articles and asks visitors not to send identity documents, passwords, or detailed personal records through a general contact form.

Processing is based on responding to correspondence, maintaining site security, meeting a stated request, or pursuing a legitimate operational interest that does not override the visitor’s rights. Consent is used where an optional cookie or similar feature requires it, and a preference can be withdrawn through the available browser or site control. Data is not sold as a reader list, and a contact message is not used to infer a person’s training status.

Retention and service providers

Ordinary correspondence is retained for up to 24 months after the last meaningful exchange, security records for up to 90 days, and routine backup copies for up to 35 days. Longer retention may apply to a correction, accounting record, dispute, or legal request where the record is genuinely needed. Access is restricted to Perma personnel and service providers who need it for hosting, email delivery, security, or maintenance.

Infrastructure providers may process information outside Indonesia. Where that occurs, the transfer is limited to the stated service, governed by contractual privacy terms, and subject to access controls appropriate to the information. A provider may be located in another jurisdiction and may disclose information where required by a valid legal process.

Rights and contact procedure

A person may ask for access, correction, deletion, restriction, portability where applicable, or an explanation of processing. Send the request to Jalan Sudirman Kav. 22, Karet Semanggi, Setiabudi, Jakarta Selatan, DKI Jakarta 12930 or +62 813 5792 4680, including the relevant email address and approximate date without unnecessary sensitive details. Perma aims to acknowledge a request within five business days and respond within 30 calendar days, subject to lawful extensions or limits.

  • Requests may be narrowed to a particular page, message, or processing purpose.
  • Deletion may be limited where retention is required for security, accounting, or legal reasons.
  • Identity confirmation may be requested where disclosure to another person is possible.
  • A concern about handling may be raised with the relevant Indonesian privacy authority.

This policy was reviewed on 5 October 2026. Material changes to processors, cookies, transfers, rights, or retention will be dated in the next published version.

Perma

Independent editorial guidance on resilient performance and informed movement.

Explore

AboutInsightsJournalGlossaryEvents

Topics

PhysiologyCardiovascular staminaFunctional trainingRecoveryResourcesServicesStandardsAssessmentNutrition

Information

ContactPrivacyTermsCookiesDisclaimerAccessibilityEditorial policyAdvertising
© 2026 Perma · Jalan Sudirman Kav. 22, Karet Semanggi, Setiabudi, Jakarta Selatan, DKI Jakarta 12930 · +62 813 5792 4680
Editorial note: Perma may use generative AI tools for early drafting, translation assistance, or layout preparation. Published material is reviewed and edited by the Perma editorial team before publication.

Perma uses essential and optional cookies to improve this editorial site. Read our cookie policy.