Privacy Policy of Wafa SSO Portal

Effective date: 5 October 2026  ·  Last updated: 5 October 2026  ·  Applies to: sso.wafaindonesia.or.id and auth.wafaindonesia.or.id

The Wafa SSO Portal is the single sign-on service of Wafa Indonesia. With one Wafa Account you sign in once and open the Wafa applications you have access to, such as SIFA, SiMumtaz and Khidmah, without signing in again for each of them.

This Privacy Policy explains what personal data the Wafa SSO Portal processes, why we process it, who we share it with, how long we keep it and what rights you have. It is written in line with Law of the Republic of Indonesia No. 27 of 2022 on Personal Data Protection (the “PDP Law”) and its implementing regulations.

At a glance

  • We use your name, email address and WhatsApp number to create your Wafa Account and to sign you in, either with a password or with a one-time code sent by WhatsApp.
  • Your Wafa Account is linked to a Wafa ID, a permanent personal code used across Wafa applications and printed on Wafa certificates.
  • We share your identity and roles only with the Wafa applications you use and with a small number of service providers that host our systems and deliver our messages. We never sell your data.
  • We record sign-in sessions and important account changes to keep your account safe. You can see and end your own sessions on the My Devices (Perangkat Saya) page.
  • Our servers are located in Singapore.
  • To access, correct or delete your data, or to exercise any other right, contact [email protected].

1. Who we are

The Wafa SSO Portal is operated by Yayasan Syafa’atul Qur’an Indonesia (YAQIN), known as Wafa Indonesia (“Wafa”, “we”, “us” or “our”), a foundation established under the laws of the Republic of Indonesia. For the purposes of the PDP Law, Wafa Indonesia is the personal data controller for the processing described in this policy. Our contact details are in section 14.

2. Scope of this policy

This policy covers personal data processed when you:

  • create or use a Wafa Account, or an account is created for you by a Wafa administrator;
  • sign in to the portal, or to a Wafa application through the portal;
  • recover your password, set or change your password, add an email address or WhatsApp number, or manage your signed-in devices; and
  • are registered in our Wafa ID registry by another Wafa application (this can happen even if you never sign in yourself).

Each Wafa application has its own privacy policy explaining how it uses your data after you sign in (SIFA, SiMumtaz, Khidmah, HRIS and Sertifikat). Some applications, such as HRIS, currently use their own sign-in and are only linked from the portal for convenience.

3. Personal data we process

Category What it includes Where it comes from
Account and identity Full name; email address; WhatsApp/mobile number; password (never stored in plain text); account status (active or deactivated); whether your email address is still a temporary placeholder; whether you have set a password and when it was last changed; date and time of your last sign-in; internal account identifiers. You, or the Wafa administrator who created your account.
Roles and affiliation Your role(s) in the Wafa ecosystem (Central Staff, Trainer, Partner Institution Contact Person or Participant), who assigned them and when. For Wafa staff: employee number, job title and department. Links to your records in other Wafa applications, for example your professional staff (SDM) profile or your position as contact person of a partner institution or foundation, together with the related institution name, code and your position. Wafa administrators; HRIS; SIFA.
Wafa ID registry Your Wafa ID (a code such as W-4827-1935-9) and the name, phone number and email address used to recognise you across applications. If two records turn out to belong to the same person, we keep a history of the merge: who merged them, when and why. You; SIFA, SiMumtaz and HRIS, which register people to obtain a Wafa ID.
Verification and security data One-time codes; password-reset and invitation links; counters that limit repeated attempts (linked to the email/number entered and to your IP address); sign-in session records (session identifier, IP address, browser and device information, time of sign-in and last activity); markers used to end or refresh sessions. Generated when you use the service.
Audit records Important actions on accounts, such as creating or updating an account, assigning or removing roles, deactivating or reactivating an account, adding an email address or phone number and administrator support access, including who performed the action, when, what changed and the IP address. Generated automatically.
Technical logs Time of the request, the page or function called (without URL parameters), response status, duration, IP address and an internal user identifier. We deliberately do not record your name, email address or URL query strings in these logs. Generated automatically.

The SSO Portal does not ask for specific (sensitive) personal data such as health, biometric or financial data.

4. How we use your data and our legal bases

Under Article 20 of the PDP Law we may only process personal data on a lawful basis. The table below shows each purpose and the basis we rely on.

Purpose Legal basis
Create and administer your Wafa Account; sign you in to the portal and to Wafa applications, and sign you out of all of them at once. Fulfilment of an agreement or service requested by you, your employer or your institution; our legitimate interests.
Give Wafa applications your identity, roles and Wafa ID so they can grant you the right access. Fulfilment of an agreement; legitimate interests.
Assign and maintain a Wafa ID so each person is recorded only once across applications and certificates remain verifiable. Legitimate interests.
Send one-time codes and security notifications by WhatsApp, and password-reset links, invitations and verification codes by email. Fulfilment of an agreement; legitimate interests (account security).
Protect accounts: limit attempts, detect misuse, manage and end sessions, keep audit records. Legal obligations as an electronic system operator; legitimate interests.
Provide support and fix problems. Legitimate interests.
Comply with the law and respond to lawful requests from authorities. Legal obligations.

Where we rely on legitimate interests, we have weighed them against your interests and rights. We do not use your data for advertising, and we do not make decisions about you based solely on automated processing that have legal or similarly significant effects.

5. How sign-in and verification work

  • Password sign-in. You enter your email address or WhatsApp number and your password. The password is checked by our identity service, which we host ourselves using the open-source Zitadel software.
  • WhatsApp one-time code. We send a 6-digit code to the WhatsApp number registered to your account. The code is valid for 5 minutes and can be tried at most 5 times. Requests are limited per number/email and per IP address.
  • Protection against account discovery. The portal answers in the same way whether or not an email address or number is registered, so others cannot use it to find out who has an account.
  • Forgotten password. For accounts with an email address, we email a reset link that is valid for 15 minutes. After a reset, your other portal sessions are signed out.
  • Adding an email address. We email a verification code (valid for 10 minutes) to the new address, and send a WhatsApp notification to your registered number, with the email address partly hidden, so you will know if someone else did it.
  • Adding a WhatsApp number. We send a verification code (valid for 5 minutes) to the new number by WhatsApp.
  • My Devices. You can see where your account is signed in (browser and device, IP address, last activity) and sign out any session. Changing your password signs out your other sessions.
  • Single sign-out. When you sign out of one Wafa application, we end your portal session and notify the other Wafa applications so they end your sessions as well. When an administrator deactivates your account or changes your roles, your sessions are ended or refreshed so the change takes effect quickly.
  • Administrator access for support. In exceptional cases, such as technical support or investigating a problem, a small number of authorised administrators can open a session for an account through a tightly restricted mechanism. Every such access is recorded in the audit log.

6. Who we share your data with

6.1 Wafa applications

When you sign in, or when an application needs to refresh your access rights, we share your name, email address, WhatsApp number, Wafa ID, roles, job title and department (for staff) and links to your profiles with the Wafa application concerned (SIFA, SiMumtaz or Khidmah). HRIS, SIFA and SiMumtaz also use the Wafa ID registry to look up or create Wafa IDs. Each application uses this data as described in its own privacy policy.

6.2 Service providers

We use the following providers to run the service. They process data on our behalf and only for the purposes below.

Provider What they do Data involved Location
Contabo Cloud servers that host the portal, our identity service and databases. All data described in this policy. Singapore
Fonnte or Api.co.id (Chat Gateway, an official WhatsApp Business Solution Provider) Deliver one-time codes and security notifications through WhatsApp, which is operated by Meta Platforms. Your WhatsApp number and the message content. Indonesia; delivery through WhatsApp’s global network
Brevo (Sendinblue SAS) Deliver emails: password resets, invitations and email verification codes. Your email address and the email content. European Union (France)
Cloudinary Hosts the preview images of Wafa applications shown on the portal. Your browser loads them directly. Your IP address and browser information only. No account data. Global content delivery network

6.3 Legal requirements

We may disclose personal data where required by law, a court order or a lawful request from a competent authority, or where necessary to protect the rights, property or safety of Wafa, our users or the public.

We do not sell, rent or trade personal data.

7. International data transfers

Our servers are located in Singapore, so data processed by the SSO Portal is stored outside Indonesia. Some service providers, such as Brevo (European Union) and Cloudinary (global network), may also process data in other countries. Singapore (Personal Data Protection Act 2012) and the European Union (General Data Protection Regulation) have comprehensive data protection laws. We transfer personal data outside Indonesia only in accordance with Article 56 of the PDP Law: the destination country provides a level of protection equal to or higher than the PDP Law, or adequate and binding safeguards are in place, or, where neither applies, with your consent.

8. How long we keep your data

Data How long
Account, roles and profile links While your account is active. After your account is deactivated or your relationship with Wafa ends, up to 5 years, after which we delete or anonymise it, unless the law requires a longer period.
Wafa ID Permanently. A Wafa ID is never reused or deleted because it appears on certificates that must remain verifiable. If you ask us to erase your data, we remove or anonymise contact details we no longer need and keep only the minimum record needed to verify documents already issued to you.
One-time and verification codes 5 minutes (10 minutes for email verification codes), or until used.
Password-reset and invitation links 15 minutes, or until used.
Attempt counters Up to 24 hours.
Portal sessions Until you sign out or the session is ended; automatically after 30 days without activity, and no later than 90 days after sign-in.
Audit records As long as the account exists and up to 5 years afterwards.
Technical logs 30 days (performance traces: 7 days).

9. How we protect your data

  • All connections to the portal and identity service are encrypted with HTTPS.
  • Passwords are never stored in plain text; they are protected with strong cryptography. Secrets used between Wafa systems are stored encrypted.
  • Sign-in is protected by attempt limits, cooldown periods, rate limiting by number/email and IP address, and uniform responses that prevent account discovery.
  • The session cookie is HttpOnly and Secure, so it cannot be read by scripts on the page. Sessions can be listed and ended at any time.
  • Communication between Wafa systems is authenticated, digitally signed and runs over internal networks.
  • Only authorised central staff can manage accounts and roles, and their actions are recorded in the audit log.
  • Our logs are kept to the minimum needed to run and secure the service.

If a personal data breach occurs, we will notify you and the relevant authority in writing no later than 3 × 24 hours, as required by Article 46 of the PDP Law. No system is completely secure, so please keep your password and one-time codes to yourself. Wafa staff will never ask you for them.

10. Cookies and similar technologies

Name Type Purpose Duration
sso_token Strictly necessary cookie Keeps you signed in to the portal and lets Wafa applications sign you in without asking for your credentials again. Until sign-out; at most 90 days, and invalid after 30 days of inactivity.
theme Local storage (preference) Remembers whether you prefer light or dark mode. Until you clear your browser data.

Our identity service at auth.wafaindonesia.or.id may also use strictly necessary cookies during sign-in. We do not use advertising, analytics or tracking cookies, and the portal’s fonts are served from our own servers. You can block or delete cookies in your browser, but without the session cookie the portal cannot keep you signed in.

11. Children

Wafa Accounts are intended for adults: Wafa staff, trainers, representatives of partner institutions and other adult participants. We do not knowingly create sign-in accounts for children without the involvement of a parent or guardian. The Wafa ID registry may contain records of children, for example students who take a munaqosyah examination, created by SiMumtaz or SIFA so that a Wafa ID can be printed on their certificates. These records cannot be used to sign in and are handled as described in the SiMumtaz and SIFA privacy policies, in line with Article 25 of the PDP Law.

12. Your rights

Under the PDP Law (Articles 5–13) you have the right to:

  • be informed about who processes your data, why and on what basis;
  • access your personal data and obtain a copy;
  • correct or update data that is inaccurate or incomplete;
  • end processing, delete or destroy your data, subject to legal exceptions (for example, records we must keep by law, or the minimum record needed to keep certificates verifiable);
  • withdraw consent where processing is based on consent;
  • object to decisions based solely on automated processing, including profiling, that have legal or similarly significant effects on you;
  • delay or restrict processing in proportion to its purpose;
  • data portability: receive your data in a commonly used, machine-readable format and have it sent to another controller where technically feasible; and
  • claim compensation for violations in the processing of your personal data, in accordance with the law.

What you can do yourself: view and end your sessions on My Devices, set or change your password, and add an email address or WhatsApp number. To change or remove an existing email address or number, or for any other request, please contact us.

How to make a request: email [email protected] with the subject “Privacy Request – Wafa SSO Portal”, stating your name, the email address or number on your account, your Wafa ID if you know it, and what you would like us to do. We may need to verify your identity first. We will respond within the time limits set by the PDP Law (for many requests, no later than 3 × 24 hours after we receive a complete and verified request). If we cannot fulfil a request, for example because the law requires us to keep the data, we will explain why.

If you are not satisfied with our response, you may lodge a complaint with the personal data protection authority in Indonesia.

13. Changes to this policy

We may update this policy when our services or the law change. We will publish the updated version on this page and change the “Last updated” date. For significant changes, we will also notify you through the portal, WhatsApp or email before the changes take effect.

14. Contact us

Wafa Indonesia – Yayasan Syafa’atul Qur’an Indonesia
Jl. Raya Wisma Pagesangan No. 9, Menanggal, Gayungan, Surabaya, East Java 60234, Indonesia
Email: [email protected]
WhatsApp Helpdesk: +62 811-3058-9310
Phone: +62 31 9904 3404
Office hours: Monday–Friday 08.00–16.00 WIB, Saturday 08.00–12.00 WIB

Leave a Reply