Privacy Policy of Wafa SiMumtaz

Effective date: 5 October 2026  ·  Last updated: 5 October 2026  ·  Applies to: simumtaz.wafaindonesia.or.id, including certificate request forms and certificate (syahadah) links

SiMumtaz is Wafa Indonesia’s munaqosyah management system. Munaqosyah is the Quran proficiency examination that concludes learning with the Wafa method. Partner institutions use SiMumtaz to apply for munaqosyah and register their students and teachers as participants. Wafa staff and examiners (munaqisy) use it to schedule examinations, record and validate scores, and issue certificates (sertifikat, syahadah and piagam).

This Privacy Policy explains what personal data SiMumtaz processes, why, who we share it with, how long we keep it and what rights you have. It is written in line with Law of the Republic of Indonesia No. 27 of 2022 on Personal Data Protection (the “PDP Law”).

At a glance

  • Most participants are students of partner institutions, and many of them are children. Institutions provide their data, and we use it only to examine, grade and certify.
  • We record scores, results and certificates. Each certificate carries a Wafa ID and a QR code that anyone can use to check that it is genuine. The public check shows the name, institution and result, but not the date of birth or detailed scores.
  • Certificates are delivered by email (after a request through a Google Form, sent with Brevo) or by WhatsApp (through Fonnte).
  • Within Wafa we share data with SIFA, Khidmah and Wafa SSO. We never sell your data.
  • Our servers are located in Singapore.
  • To exercise your rights, contact [email protected].

1. Who we are

SiMumtaz is operated by Yayasan Syafa’atul Qur’an Indonesia (YAQIN), known as Wafa Indonesia (“Wafa”, “we”, “us” or “our”), a foundation established under the laws of the Republic of Indonesia. Wafa Indonesia is the personal data controller for the processing described in this policy. Sign-in to SiMumtaz is provided by the Wafa SSO Portal, which has its own privacy policy.

2. Whose data we process

  • Users: Wafa staff (administrators, quality managers and score validators), administrators and Quran coordinators of partner institutions, and examiners;
  • participants: students and teachers who take a munaqosyah examination;
  • parents or guardians of student participants, whose phone number is recorded;
  • contacts of external parties: organisations or individuals outside our partner network that apply for munaqosyah; and
  • people who fill in a certificate request form or a certificate link.

3. Personal data we process

Category What it includes Where it comes from
Users Name, email address, phone number, roles and permissions, institution, job title and Wafa ID; session records (IP address, browser information). Wafa SSO.
Participants Category (student or teacher) and level, student number (NIS/NISN), full name, gender, place and date of birth, parent or guardian’s phone number (students), phone number and email address (teachers), status, notes, institution or external party, and Wafa ID. Partner institution or external party; Wafa staff; SIFA.
Applications and activities Applying institution or external party (name, address, city, contact person’s name, phone and email), schedule, venue, participant lists, cost estimates and quotations, and a history of status changes (who did what and when). Institution; Wafa staff.
Examination data Examiner assignments, attendance, scores per aspect (for example tajwid and fluency) per juz, remedial results, final score, predicate, pass or fail, and who graded and validated the scores. Examiners; Wafa staff; spreadsheet imports.
Certificates Certificate number, participant registration number (NIPS), verification code, Wafa ID, participant’s name, place and date of birth, gender and student number, institution, venue and date, test type, predicate and scores, issue and expiry dates, printing records, and delivery status (when sent by email or WhatsApp, and to which address or number). Generated from the data above.
Certificate request form NIPS, name, institution, place and date of birth, phone number, email address and munaqosyah level. The participant (Google Form).
Certificate link for teachers Full name, place and date of birth and WhatsApp number confirmed by the teacher, and when the link was sent and filled in. The teacher.
Audit and technical data Activity and application histories; technical logs (time, function called, response status, IP address and an internal user identifier). Generated automatically.

Students’ data is children’s data, which is specific personal data under Article 4 of the PDP Law. See section 11.

4. How we use your data and our legal bases

Purpose Legal basis (PDP Law, Art. 20)
Receive and process munaqosyah applications; prepare cost estimates and quotations. Fulfilment of an agreement with the institution or applicant.
Manage participants and schedules; assign examiners. Fulfilment of an agreement; legitimate interests.
Conduct examinations, record and validate scores, determine results and run remedial tests. Fulfilment of an agreement; legitimate interests (the integrity of our certification).
Issue certificates, syahadah and piagam, and keep a record of every certificate issued. Fulfilment of an agreement; legitimate interests.
Deliver certificates by email or WhatsApp and let participants confirm the name and date of birth printed on them. Fulfilment of an agreement; your consent when you submit a form.
Register certificates so anyone can check that they are genuine. Legitimate interests (preventing forgery).
Share data with SIFA and Wafa SSO to keep partnership records and Wafa IDs consistent. Legitimate interests.
Statistics and quality assurance of our learning method. Legitimate interests.
Security, audit trails and compliance with the law. Legal obligations; legitimate interests.

For children, we also rely on the consent of a parent or guardian, obtained by the institution (see section 11).

How results are determined: scores are entered by examiners and checked by Wafa validators. SiMumtaz then calculates the final score, predicate and pass/fail result automatically using predefined assessment criteria. If you believe a result is wrong, you or your institution can ask us to review it.

5. Certificates and their delivery

  • Printed details. A certificate shows the participant’s name, place and date of birth, institution, test type, predicate and scores, plus a Wafa ID, a certificate number and a QR code.
  • Public verification. Each certificate is registered with Wafa Certificate Verification (sertifikat.wafaindonesia.or.id). Anyone who scans the QR code or enters the code sees the certificate number, name, institution, test type, material covered, predicate and dates. Date of birth and detailed scores are not shown. Please share your certificate or QR code only with people who need to verify it.
  • Delivery by email. Participants can request their certificate through a Google Form, entering their NIPS, name, institution, place and date of birth, phone number and email address. SiMumtaz updates the certificate with the confirmed details, creates a PDF and emails it through Brevo.
  • Delivery by WhatsApp. Teachers receive a personal link by WhatsApp. After they confirm their name, place and date of birth and WhatsApp number, the certificate PDF is sent to that number through Fonnte. The confirmed details also update the teacher’s participant record.
  • Institutions can download their participants’ certificates in SiMumtaz.

6. Who we share your data with

6.1 Within Wafa

  • Partner institution administrators see only their own institution’s applications, participants, results and certificates.
  • Examiners see only the participants assigned to them, usually through the Khidmah app.
  • Wafa staff have access according to their role.
  • SIFA receives participants, results and certificate details to keep partnership records.
  • Wafa SSO receives participants’ names, and teachers’ own phone number and email address, to assign a Wafa ID.
  • Wafa Certificate Verification receives the details shown on the public verification page, only when a code is checked.

6.2 Service providers

Provider What they do Data involved Location
Contabo Cloud servers that host SiMumtaz and its database. All data described in this policy. Singapore
Google (Google Forms) Hosts the certificate request form and forwards responses to SiMumtaz. The data you enter in the form. Global, including the United States
Brevo (Sendinblue SAS) Delivers certificate emails. Name, email address and the certificate PDF. European Union (France)
Fonnte Sends certificate links and PDFs by WhatsApp (operated by Meta Platforms). Phone number, message content and the certificate PDF. Indonesia; delivery through WhatsApp’s global network
Google (Google Fonts) Provides the fonts used on SiMumtaz pages. IP address and browser information. Global

SiMumtaz also sends our munaqosyah product and price list to Odoo, our accounting system. This does not include any participant data.

6.3 Other disclosures

We may disclose personal data where required by law, a court order or a lawful request from a competent authority, or to protect the rights and safety of Wafa, participants or the public. We do not sell, rent or trade personal data.

7. International data transfers

Our servers are located in Singapore, so SiMumtaz data is stored outside Indonesia. Google and Brevo may also process data in other countries. Singapore (Personal Data Protection Act 2012) and the European Union (General Data Protection Regulation) have comprehensive data protection laws. We transfer personal data outside Indonesia only in accordance with Article 56 of the PDP Law: the destination country provides a level of protection equal to or higher than the PDP Law, or adequate and binding safeguards are in place, or, where neither applies, with your consent.

8. How long we keep your data

Data How long
Participants, applications and examination data As long as the participant takes part in Wafa programs through the institution, and up to 5 years after the last examination or after the partnership ends.
Certificates (as printed), certificate numbers, verification codes and Wafa IDs Permanently, so certificates remain verifiable and can be reissued if lost.
Quotations and other financial records 10 years, as required by Indonesian accounting, tax and company document laws.
Certificate request form responses The same periods as the participant data above, including the copy kept in Google Forms under our account.
Users’ data and histories While the user has access and up to 5 years afterwards.
Sign-in sessions Up to 30 days, or until you sign out.
Technical logs 30 days (performance traces: 7 days).

When the period ends, we delete the data or anonymise it so it can no longer identify anyone.

9. How we protect your data

  • All connections are encrypted with HTTPS. Sign-in uses the Wafa SSO, and sessions are held in an HttpOnly, Secure cookie.
  • Access is role-based: institutions see only their own data and examiners see only the participants assigned to them.
  • Public forms and certificate links use long, random codes and are rate-limited to prevent guessing and abuse.
  • Communication between Wafa systems is authenticated, digitally signed and runs over internal networks.
  • The public verification page deliberately leaves out dates of birth and detailed scores.

If a personal data breach occurs, we will notify the affected people and the relevant authority in writing no later than 3 × 24 hours, as required by Article 46 of the PDP Law.

10. Cookies and similar technologies

Name Type Purpose Duration
mis_session Strictly necessary cookie Keeps you signed in to SiMumtaz. Up to 30 days, or until sign-out.
Profile and permissions Local storage Keeps a copy of your name, role and permissions so the menus load quickly. Until sign-out or you clear browser data.
Application draft Local storage Saves your progress while filling in a munaqosyah application. Until the application is submitted or you clear browser data.
Display preferences Local and session storage Remember light/dark mode, sidebar state and scroll position. Until you clear browser data (session storage: until you close the tab).

We do not use advertising, analytics or tracking cookies in SiMumtaz. On a shared computer, always sign out when you finish.

11. Children’s data

Many munaqosyah participants are children. Under Article 25 of the PDP Law, processing children’s data requires special care and the consent of a parent or guardian. Children’s data reaches us from their institution, and the institution is responsible for informing parents or guardians and obtaining any consent required before registering a child in SiMumtaz.

We protect children’s data by:

  • collecting only what the examination and certificate need;
  • not recording a child’s own phone number or email address: we use the parent’s or guardian’s phone number instead;
  • limiting access to the child’s institution, the assigned examiner and authorised Wafa staff; and
  • never showing a child’s date of birth or detailed scores on the public verification page.

Parents or guardians can exercise their child’s rights by contacting us directly or through the institution.

12. Your rights

Under the PDP Law (Articles 5–13) you have the right to:

  • be informed about who processes your data, why and on what basis;
  • access your personal data and obtain a copy;
  • correct or update data that is inaccurate or incomplete, for example a misspelled name on a certificate;
  • end processing, delete or destroy your data, subject to legal exceptions (for example, the record of an issued certificate, which we must keep so it can be verified);
  • withdraw consent where processing is based on consent;
  • object to decisions based solely on automated processing;
  • delay or restrict processing in proportion to its purpose;
  • data portability: receive your data in a commonly used, machine-readable format and have it sent to another controller where technically feasible; and
  • claim compensation for violations in the processing of your personal data, in accordance with the law.

To make a request, email [email protected] with the subject “Privacy Request – SiMumtaz”, stating the participant’s name, institution, NIPS or certificate number if known, your relationship to the participant, and what you would like us to do. Institutions may also forward requests on behalf of their students and teachers. We may need to verify your identity first. We will respond within the time limits set by the PDP Law (for many requests, no later than 3 × 24 hours after we receive a complete and verified request). If we cannot fulfil a request, we will explain why. You may also lodge a complaint with the personal data protection authority in Indonesia.

13. Changes to this policy

We may update this policy when our services or the law change. We will publish the updated version on this page and change the “Last updated” date. For significant changes, we will also inform partner institutions before the changes take effect.

14. Contact us

Wafa Indonesia – Yayasan Syafa’atul Qur’an Indonesia
Jl. Raya Wisma Pagesangan No. 9, Menanggal, Gayungan, Surabaya, East Java 60234, Indonesia
Email: [email protected]
WhatsApp Helpdesk: +62 811-3058-9310
Phone: +62 31 9904 3404
Office hours: Monday–Friday 08.00–16.00 WIB, Saturday 08.00–12.00 WIB

Leave a Reply