Effective date: 5 October 2026 · Last updated: 5 October 2026 · Applies to: sifa.wafaindonesia.or.id, including the partner registration form and partner certificate links
SIFA (Sistem Informasi Wafa) is Wafa Indonesia’s information system for running our programs. Authorised Wafa staff use it to manage partner institutions (lembaga mitra), foundations (yayasan) and regional Wafa units, our professional staff (trainers, munaqosyah examiners and academy teachers), activities such as trainings and munaqosyah (Quran proficiency examinations), assignments, incentives and the related administration. SIFA also hosts a public form that institutions use to register as Wafa partners.
This Privacy Policy explains what personal data SIFA processes, why, who we share it with, how long we keep it and what rights you have. It is written in line with Law of the Republic of Indonesia No. 27 of 2022 on Personal Data Protection (the “PDP Law”).
At a glance
- SIFA is used only by authorised Wafa staff. Most people whose data is in SIFA, such as contact persons of partner institutions, professional staff, teachers and students, do not use SIFA themselves.
- We process the data needed to run our partnerships and programs: institution contacts, professional staff profiles, activity participants, and data about students and teachers received from SiMumtaz.
- Student data includes data of children. We keep it to a minimum and use it only for Wafa’s learning and certification programs.
- A professional staff member’s competency level is calculated automatically from their recorded qualifications and influences incentive rates. You can ask for a human review.
- We share data with Odoo, our accounting system, for invoices and payments, and send WhatsApp messages through Fonnte. We never sell your data.
- Our servers are located in Singapore.
- To exercise your rights, contact [email protected].
Contents
- Who we are
- Whose data we process
- Personal data we process
- How we use your data and our legal bases
- Automated competency levels
- Who we share your data with
- International data transfers
- How long we keep your data
- How we protect your data
- Cookies and similar technologies
- Children’s data
- Your rights
- Changes to this policy
- Contact us
1. Who we are
SIFA is operated by Yayasan Syafa’atul Qur’an Indonesia (YAQIN), known as Wafa Indonesia (“Wafa”, “we”, “us” or “our”), a foundation established under the laws of the Republic of Indonesia. Wafa Indonesia is the personal data controller for the processing described in this policy. Sign-in to SIFA is provided by the Wafa SSO Portal, which has its own privacy policy.
2. Whose data we process
- Wafa staff who use SIFA;
- professional staff (SDM Profesional): trainers, munaqosyah examiners (munaqisy), academy teachers and others assigned to Wafa activities;
- supporting staff (SDM Pendukung) who help run activities;
- contact persons (PIC) of partner institutions, foundations, regional Wafa units (Wafa Daerah) and regional partnerships (Kemitraan Daerah);
- people who fill in the partner registration form, and the people they name in it;
- students and teachers of partner institutions, and other participants in Wafa activities; and
- contacts of prospective partners recorded in our accounting system.
3. Personal data we process
| Category | What it includes | Where it comes from |
|---|---|---|
| SIFA users | Name, email address, phone number, account identifiers, roles and permissions, last sign-in; session records (IP address, browser information). | Wafa SSO; you. |
| Professional staff profile | Full name, gender, place and date of birth, phone and WhatsApp numbers, email address, address (province, city, street), employment status (internal, freelance or partner), category, affiliated institution, status (active, inactive, on leave), date joined, notes and Wafa ID. | You (directly or through Khidmah); Wafa staff. |
| Qualifications and competency | Fields of expertise and scores, certification dates, Quran memorisation (juz), training-of-trainers certification, education history (level, major, institution, grades, years, certificate numbers and links to proof documents), qualifications, competency levels (jenjang) and their history. | You; Wafa staff; calculated by SIFA. |
| Assignments and incentives | Activities and roles assigned to you, days and duration, number of participants, incentive calculations (grade, quantities, amounts and communication allowance) and incentive proposal documents. | Wafa staff; calculated by SIFA. |
| Supporting staff | Name, category, phone number, email address, origin institution, bank name, account number and account holder name (to pay incentives), the Wafa contact person responsible and Wafa ID. | You; Wafa staff. |
| Contact persons (PIC) | Name, position, phone number, email address, whether you are the primary contact, and Wafa ID, for partner institutions, foundations, regional Wafa units and regional partnerships. | The institution; the registration form; Wafa staff. |
| Partner institutions | Institution name, level, address, phone, email, social media accounts, numbers of students and teachers, learning profile and preferences, partnership status history (including the name and position of the person who confirmed a change and any proof files), internal notes and the Wafa unit or person who recommended the institution. | The institution; Wafa staff. |
| Partner registration form | Everything entered in the form (institution details and address; name and position of the person registering; name, position, phone and email of the foundation chair, the head of the institution and the Quran coordinator; recommender’s name and contact; social media; notes), plus the IP address, browser information and time of submission, and the outcome of our review. | The person submitting the form. |
| Students | Student number (NIS/NISN), full name, gender, place and date of birth, parent or guardian’s name and phone number, status (active, graduated, left, deceased), notes and Wafa ID. | Partner institutions, mostly through SiMumtaz. |
| Teachers of partner institutions | Teacher code, employee number (NIP), full name, gender, place and date of birth, phone number, email address, position, status and Wafa ID. | Partner institutions, mostly through SiMumtaz. |
| Activity participants | Name, gender, identity number, participant type and notes. | Institutions; Wafa staff. |
| Munaqosyah results | Participant name and student number, institution, test type and level, result (pass/fail, predicate, final score), certificate number and dates. | SiMumtaz. |
| Financial and commercial records | Activity costs; cost approval workflow (names of staff who proposed, approved or rejected); quotations; invoices; payment receipts (payer’s name, amount, receiving bank account); purchases of Wafa products by institutions. | Wafa staff; Odoo. |
| Prospective partners | Name, email address, phone number and address of customers in our accounting system who are not yet linked to a partner institution. | Odoo. |
| Audit and technical data | Record of changes (who, what, when, values before and after, IP address); technical logs (time, function called, response status, IP address and an internal user identifier). | Generated automatically. |
Some of this data is specific personal data under Article 4 of the PDP Law: children’s data and personal financial data (bank accounts and incentive amounts). We give it extra protection and restrict access to staff who need it.
If you give us data about other people, for example the contacts you name in the registration form, please make sure they know about it and about this policy.
4. How we use your data and our legal bases
| Purpose | Legal basis (PDP Law, Art. 20) |
|---|---|
| Manage partnerships: register, review and approve institutions; keep contacts, status, preferences and history up to date; issue partner certificates. | Fulfilment of an agreement, or steps requested before entering one; legitimate interests. |
| Process partner registrations, including WhatsApp messages confirming the starter kit delivery address and payment details, and announcing approval with a link to the partner certificate. | Steps requested before entering an agreement; fulfilment of an agreement. |
| Plan and run activities (trainings, munaqosyah, academy programs), including participants and schedules. | Fulfilment of an agreement; legitimate interests. |
| Manage professional and supporting staff: profiles, qualifications, competency levels and assignments. | Fulfilment of an agreement (your engagement with Wafa); legitimate interests. |
| Calculate and pay incentives; prepare incentive and cost proposals; pay into bank accounts. | Fulfilment of an agreement; legal obligations (tax and accounting). |
| Prepare documents (work orders, quotations, invoices, receipts, certificates) and record sales and payments in our accounting system. | Fulfilment of an agreement; legal obligations. |
| Keep records of students, teachers, munaqosyah results and certificates for the services requested by partner institutions. | Fulfilment of an agreement with the institution; legitimate interests; for children, the consent of a parent or guardian obtained by the institution. |
| Register partner certificates so anyone can check that they are genuine. | Legitimate interests (preventing forgery). |
| Assign Wafa IDs and avoid duplicate records of the same person. | Legitimate interests. |
| Reports and dashboards, mostly as aggregated statistics, to plan and improve our programs. | Legitimate interests. |
| Security, audit trails and compliance with the law. | Legal obligations; legitimate interests. |
We do not use personal data in SIFA for advertising.
5. Automated competency levels
SIFA calculates each professional staff member’s competency level per field (from OJT through ahli) automatically, based on the qualifications recorded in their profile. The level, together with the role in an activity, determines the incentive grade and therefore the incentive rate. If you think your level is wrong, you can ask us to check the qualifications used, correct them and review the result. You also have the right to object to decisions based solely on automated processing (Article 10 of the PDP Law).
6. Who we share your data with
6.1 Within Wafa
- Authorised Wafa staff, each with access limited to what their role requires.
- Wafa SSO: links between your account and your SIFA records, and name and contact details for the Wafa ID registry.
- SiMumtaz: institution and professional staff data needed to run munaqosyah; SiMumtaz in turn sends participants, results and certificates to SIFA.
- Khidmah: professional staff can see and update their own profile.
- Wafa Certificate Verification (Sertifikat): when someone checks a partner certificate, it shows the institution’s code, name, region and partnership status.
6.2 Service providers
| Provider | What they do | Data involved | Location |
|---|---|---|---|
| Contabo | Cloud servers that host SIFA and its database. | All data described in this policy. | Singapore |
| Odoo S.A. | Cloud accounting and sales system. | Names and contact details of partner institutions and foundations (name, email, phone, address, city, postal code); sales orders and invoices for activities; payments; prospective partner details. | Odoo’s cloud servers, which may be outside Indonesia |
| Fonnte | Sends WhatsApp messages to people who register an institution (WhatsApp is operated by Meta Platforms). | Phone number and message content (institution name, address, partner code, certificate link). | Indonesia; delivery through WhatsApp’s global network |
| Google (Google Fonts) | Provides the fonts used on SIFA pages; your browser loads them from Google. | IP address and browser information. | Global |
| Api.co.id | Provides Indonesia’s public holiday calendar for scheduling. | No personal data. | Indonesia |
6.3 Other disclosures
Partner certificates can be downloaded through a link containing a long, hard-to-guess code, which we send to the institution. Anyone who has the link can download that certificate, so please share it with care. We may also disclose personal data where required by law, a court order or a lawful request from a competent authority, or to protect the rights and safety of Wafa, our partners or the public.
We do not sell, rent or trade personal data.
7. International data transfers
Our servers are located in Singapore, so SIFA data is stored outside Indonesia. Odoo and Google may also process data in other countries. Singapore has a comprehensive data protection law (the Personal Data Protection Act 2012). We transfer personal data outside Indonesia only in accordance with Article 56 of the PDP Law: the destination country provides a level of protection equal to or higher than the PDP Law, or adequate and binding safeguards are in place, or, where neither applies, with your consent.
8. How long we keep your data
| Data | How long |
|---|---|
| Professional and supporting staff data | While you are engaged with Wafa and up to 5 years after the engagement ends. |
| Partner institutions, contacts and status history | While the partnership is active and up to 5 years after it ends. |
| Partner registrations | Approved registrations become part of the partner record. Rejected or withdrawn registrations are kept for up to 5 years after the decision. |
| Students, teachers and activity participants | As long as needed for our programs and up to 5 years after the person leaves the institution or the partnership ends. |
| Certificates, certificate numbers and Wafa IDs | Permanently, so that certificates remain verifiable. |
| Financial records (incentives, quotations, invoices, receipts, cost proposals) | 10 years, as required by Indonesian accounting, tax and company document laws. |
| Audit records | As long as the related record exists and up to 5 years afterwards. |
| Sign-in sessions | Up to 30 days, or until you sign out. |
| Technical logs | 30 days (performance traces: 7 days). |
When the period ends, we delete the data or anonymise it so it can no longer identify you.
9. How we protect your data
- All connections are encrypted with HTTPS. Sign-in uses the Wafa SSO, and sessions are held in an HttpOnly, Secure cookie.
- Access is role-based: each staff member can only see and change what their job requires.
- Changes to important records are kept in an audit trail showing who changed what and when.
- Communication between Wafa systems is authenticated, digitally signed and runs over internal networks.
- The public registration form only works through an invitation link and is protected against automated abuse with rate limits and spam protection.
If a personal data breach occurs, we will notify the affected people and the relevant authority in writing no later than 3 × 24 hours, as required by Article 46 of the PDP Law.
10. Cookies and similar technologies
| Name | Type | Purpose | Duration |
|---|---|---|---|
sifa_session |
Strictly necessary cookie | Keeps you signed in to SIFA. | Up to 30 days, or until sign-out. |
Registration form draft (pendaftaran-mitra-draft:*) |
Local storage on your device | Saves your progress in the partner registration form so you do not lose what you typed. It stays on your device and is not sent to us until you submit. | Deleted after submission, or when the invitation link expires (at most 30 days). |
| Display preferences | Local and session storage | Remember light/dark mode, sidebar state and scroll position, and the signature options you chose for printed documents. | Until you clear browser data (session storage: until you close the tab). |
| App cache | Service worker | Stores SIFA’s application files so it loads faster and can be installed on your device. | Until updated or removed. |
We do not use advertising, analytics or tracking cookies in SIFA. If you use a shared computer, delete the registration form draft by clearing your browser data, or submit the form before leaving.
11. Children’s data
SIFA contains data about students of partner institutions, many of whom are children. Under Article 25 of the PDP Law, processing children’s data requires special care and the consent of a parent or guardian. Students’ data reaches us from their institution, mostly through SiMumtaz, and the institution is responsible for informing parents or guardians and obtaining any consent required before sharing it with us. We collect only what our programs need: we do not record a child’s own phone number or email (we use the parent’s or guardian’s contact instead), access is limited to authorised staff, and the public certificate check never shows a child’s date of birth or detailed scores. Parents or guardians can exercise their child’s rights by contacting us directly or through the institution.
12. Your rights
Under the PDP Law (Articles 5–13) you have the right to:
- be informed about who processes your data, why and on what basis;
- access your personal data and obtain a copy;
- correct or update data that is inaccurate or incomplete;
- end processing, delete or destroy your data, subject to legal exceptions (for example, financial records we must keep, or certificates that must remain verifiable);
- withdraw consent where processing is based on consent;
- object to decisions based solely on automated processing, such as the competency level calculation described in section 5;
- delay or restrict processing in proportion to its purpose;
- data portability: receive your data in a commonly used, machine-readable format and have it sent to another controller where technically feasible; and
- claim compensation for violations in the processing of your personal data, in accordance with the law.
Professional staff can view and update parts of their own profile in the Khidmah app. For anything else, email [email protected] with the subject “Privacy Request – SIFA”, stating your name, how you are connected to Wafa (for example, the institution you represent) and what you would like us to do. We may need to verify your identity first. We will respond within the time limits set by the PDP Law (for many requests, no later than 3 × 24 hours after we receive a complete and verified request). If we cannot fulfil a request, we will explain why. You may also lodge a complaint with the personal data protection authority in Indonesia.
13. Changes to this policy
We may update this policy when our services or the law change. We will publish the updated version on this page and change the “Last updated” date. For significant changes, we will also inform affected users and partners before the changes take effect.
14. Contact us
Wafa Indonesia – Yayasan Syafa’atul Qur’an Indonesia
Jl. Raya Wisma Pagesangan No. 9, Menanggal, Gayungan, Surabaya, East Java 60234, Indonesia
Email: [email protected]
WhatsApp Helpdesk: +62 811-3058-9310
Phone: +62 31 9904 3404
Office hours: Monday–Friday 08.00–16.00 WIB, Saturday 08.00–12.00 WIB
