Effective date: 5 October 2026 · Last updated: 5 October 2026 · Applies to: hris.wafaindonesia.or.id
HRIS Wafa is Wafa Indonesia’s human resource information system for our employees. It handles employee records, attendance (with location and photo verification), leave and permission requests, business trips, overtime, daily work reports and Mutaba’ah, our daily Quran recitation log.
This Privacy Policy explains how HRIS processes the personal data of our employees and of people whose details employees provide, such as emergency contacts. It is written in line with Law of the Republic of Indonesia No. 27 of 2022 on Personal Data Protection (the “PDP Law”).
At a glance
- HRIS processes the data we need to employ you: identity numbers (NIK, NPWP, family card), contact details, contract and salary, attendance, leave and other requests.
- Some of it is specific (sensitive) personal data under the PDP Law, such as health-related data (blood type, height and weight, doctors’ certificates) and financial data (salary). Access to it is restricted.
- Your location is recorded only at the moment you clock in or out, never continuously. A selfie is taken at the same moment to prevent proxy attendance. We do not use facial recognition.
- Attendance photos and supporting documents are deleted automatically after 100 days.
- Some attendance statuses are set automatically from your schedule. You can always request a correction.
- Data is shared only within Wafa and with a few providers (hosting, maps and push notifications). We never sell your data. Our servers are located in Singapore.
Contents
- Who we are
- Personal data we process
- How we use your data and our legal bases
- Location and photos at clock-in
- Automatic attendance records
- Who can see your data within Wafa
- Who we share your data with
- International data transfers
- How long we keep your data
- How we protect your data
- Data stored in your browser
- Your rights
- Changes to this policy
- Contact us
1. Who we are
HRIS is operated by Yayasan Syafa’atul Qur’an Indonesia (YAQIN), known as Wafa Indonesia (“Wafa”, “we”, “us” or “our”), a foundation established under the laws of the Republic of Indonesia and your employer. Wafa Indonesia is the personal data controller for the processing described in this policy. HRIS currently uses its own sign-in with your email address and password, separate from the Wafa SSO Portal.
2. Personal data we process
| Category | What it includes | Where it comes from |
|---|---|---|
| Identity and personal details | Employee number, full name, profile photo, national identity number (NIK), tax number (NPWP), family card (KK) number, place and date of birth, gender, religion, marital status, nationality and Wafa ID. | You; HR. |
| Health-related data | Blood type, height and weight; doctors’ certificates and similar documents attached to sick leave or permission requests. | You. |
| Contact details | Phone numbers and email addresses, including emergency contacts (label and number), and which one is your primary contact. | You; HR. |
| Employment | Branch, department, job position, system role and access level, trainer status, contracts (number, type, start and end dates, salary, notes), work schedule and shift, leave entitlements and balances. | HR. |
| Attendance | Date, clock-in and clock-out times, GPS coordinates and selfie photos at clock-in and clock-out, method (GPS or manual), status (present, late, half day, absent, leave, business trip or holiday), minutes late or early and the reasons, supporting documents, overtime minutes, and manual entries with notes. | Your device; generated automatically; HR. |
| Requests and approvals | Attendance corrections (original and corrected times, reason); permissions (late arrival, early leave, out of office); leave (type, dates, reason, documents such as medical, marriage or death certificates); business trips (destination, dates, purpose, documents); overtime (planned and actual times, reason, work location); and approvers’ decisions and notes. | You; supervisors; HR. |
| Daily work reports | The activities you report for each working day. | You. |
| Mutaba’ah | Your daily Quran recitation target (number of pages) and whether and when you submitted it. | You. |
| Account | Email address, password (stored only as a one-way hash), role and last sign-in. | HR; you. |
| Notifications | In-app notifications and, if you enable push notifications, your browser’s push subscription (endpoint and keys) and delivery status. | You; generated automatically. |
| Audit and technical data | Record of changes (who changed which record, old and new values, IP address, browser); technical logs. | Generated automatically. |
Health-related data and personal financial data are specific personal data under Article 4 of the PDP Law. We process them only where necessary, for example to administer sick leave or salary as required by law, and restrict access to HR and authorised approvers. Religion and marital status are recorded for HR administration only.
If you give us details of other people, such as emergency contacts or family members named in leave documents, please make sure they know about it.
3. How we use your data and our legal bases
| Purpose | Legal basis (PDP Law, Art. 20) |
|---|---|
| Administer your employment: records, contracts, positions and organisational structure. | Fulfilment of your employment agreement; legal obligations (manpower law). |
| Record attendance and working hours, check your location against the office area and take a photo to prevent proxy attendance. | Fulfilment of your employment agreement; legitimate interests (reliable attendance records). |
| Process leave, permissions, business trips and overtime, including approvals and supporting documents. | Fulfilment of your employment agreement; legal obligations (leave entitlements). |
| Calculate leave balances and overtime and prepare data for payroll. | Fulfilment of your employment agreement; legal obligations. |
| Meet tax and statutory obligations (NIK, NPWP, family card, salary). | Legal obligations. |
| Daily work reports and performance management. | Fulfilment of your employment agreement; legitimate interests. |
| Run the Mutaba’ah program that supports staff’s daily Quran recitation. | Legitimate interests as an Islamic educational foundation, in line with our internal staff development policy. |
| Send reminders and updates (clock-in and clock-out, prayer times, approvals). | Legitimate interests; push notifications only with your permission (consent). |
| Contact someone close to you in an emergency. | Vital interests; legitimate interests. |
| Register you in the Wafa ID registry of Wafa SSO. | Legitimate interests. |
| HR reports, dashboards and exports for management. | Legitimate interests; legal obligations. |
| Security, audit trails and compliance with the law. | Legal obligations; legitimate interests. |
4. Location and photos at clock-in
- Location only when you clock in or out. Your browser asks for permission to use your location. HRIS reads it once at clock-in and once at clock-out. It does not track you at any other time.
- Office area check. Your coordinates are compared with your branch’s location and permitted radius (100 metres by default). During an approved business trip the area check is switched off, but your coordinates are still recorded as evidence of attendance.
- Selfie photo. A photo is taken with your device’s camera at clock-in and clock-out and uploaded directly to our private storage through a link that is valid for 5 minutes. Authorised HR staff can view it through links valid for 15 minutes. Photos are used only for manual checks against proxy attendance. We do not use facial recognition or any other biometric identification.
- Automatic deletion. Attendance photos and supporting documents are deleted automatically 100 days after upload.
- Maps. When you or HR view the location of an attendance record, the map is loaded from OpenStreetMap, so those coordinates are sent to OpenStreetMap to display it.
- If you refuse permission. You can refuse location or camera access, but GPS attendance will not work. Please contact HR, who can record your attendance manually.
5. Automatic attendance records
HRIS sets your attendance status (for example present, late or half day) automatically from your schedule. Every night at 23:59, it creates an “absent” record for scheduled employees who did not clock in on a working day that is not a holiday, and it creates the day’s daily report and Mutaba’ah entries. These records may be used for leave, overtime and payroll. If a record is wrong, you can submit an attendance correction or a permission request, which is reviewed by a person (your supervisor or HR). You also have the right to object to decisions based solely on automated processing (Article 10 of the PDP Law).
6. Who can see your data within Wafa
- You can see your own data, requests and their approval timeline.
- Supervisors and leaders see the data of their own team needed to approve requests and monitor attendance.
- HR administrators see employee data needed for HR administration, including the history of changes.
- Super administrators have full access, including system records, and are limited to a small number of people.
7. Who we share your data with
7.1 Within Wafa
HRIS sends your name, phone number, email address and employee number to Wafa SSO so that you receive a Wafa ID. Your job title and department may also be recorded in your Wafa Account to set your access rights in other Wafa applications, as described in the Wafa SSO Portal privacy policy.
7.2 Service providers
| Provider | What they do | Data involved | Location |
|---|---|---|---|
| Contabo | Cloud servers that host HRIS, its database and our private file storage. | All data described in this policy. | Singapore |
| OpenStreetMap Foundation | Map images, the map showing an attendance location, and address search when HR sets up branch locations. | Coordinates of the area shown, search terms, IP address and browser information. | United Kingdom / European Union |
| Browser push services (Google Firebase Cloud Messaging, Apple Push Notification service, Mozilla Push Service) | Deliver push notifications to your device, only if you enable them. | Your device’s push address and the notification, whose content is encrypted end-to-end. | Global |
| Google (Google Fonts) | Provides the fonts used in HRIS. | IP address and browser information. | Global |
| Api.co.id | Provides public holidays and prayer times for scheduling. | No personal data. | Indonesia |
7.3 Authorities
We may disclose personal data where required by law, for example to tax or employment authorities, or in response to a court order or a lawful request from a competent authority. We do not sell, rent or trade personal data.
8. International data transfers
Our servers are located in Singapore, so HRIS data is stored outside Indonesia. Map and push notification providers may also process limited data in other countries. Singapore has a comprehensive data protection law (the Personal Data Protection Act 2012). We transfer personal data outside Indonesia only in accordance with Article 56 of the PDP Law: the destination country provides a level of protection equal to or higher than the PDP Law, or adequate and binding safeguards are in place, or, where neither applies, with your consent.
9. How long we keep your data
| Data | How long |
|---|---|
| Employee records, attendance records, requests, reports, Mutaba’ah and audit records | For the duration of your employment and up to 5 years after it ends. |
| Salary and other records needed for tax and accounting | 10 years, as required by Indonesian tax, accounting and company document laws. |
| Attendance photos and supporting documents (leave, permissions, business trips, Mutaba’ah) | Deleted automatically 100 days after upload. |
| Profile photo | While you are employed; deleted with your employee record. |
| Sign-in | Access for 7 days, renewable for up to 30 days, or until you sign out. |
| Push subscriptions | Until you turn off notifications or the subscription expires. |
| Technical logs | 30 days (performance traces: 7 days). |
When the period ends, we delete the data or anonymise it so it can no longer identify you.
10. How we protect your data
- All connections are encrypted with HTTPS. Passwords are stored only as a one-way hash (bcrypt) and cannot be read by anyone, including Wafa staff.
- Access is role-based and limited by level, as described in section 6.
- Photos and documents are kept in private storage that is not publicly accessible. They can only be opened through links that expire after 15 minutes, and they are deleted automatically after 100 days.
- Changes to employee data, contracts, attendance, leave balances, overtime and corrections are recorded in an audit trail, and original attendance times are kept when a correction is approved.
- Push notification content is encrypted so that push services cannot read it.
Your sign-in is stored in your browser, so please sign out when using a shared device. If a personal data breach occurs, we will notify you and the relevant authority in writing no later than 3 × 24 hours, as required by Article 46 of the PDP Law.
11. Data stored in your browser
| Item | Type | Purpose | Duration |
|---|---|---|---|
| Sign-in tokens and account details | Local storage (strictly necessary) | Keep you signed in and remember your profile and permissions. | Until you sign out (at most 30 days without renewal). |
| Preferences | Local storage | Remember light/dark mode and sidebar state. | Until you clear browser data. |
| App cache and push subscription | Service worker | Lets HRIS be installed, load quickly and receive notifications. | Until updated, removed or notifications are turned off. |
HRIS does not use advertising, analytics or tracking cookies.
12. Your rights
Under the PDP Law (Articles 5–13) you have the right to:
- be informed about who processes your data, why and on what basis;
- access your personal data and obtain a copy;
- correct or update data that is inaccurate or incomplete;
- end processing, delete or destroy your data, subject to legal exceptions (for example, records we must keep under employment, tax or accounting laws);
- withdraw consent where processing is based on consent, such as push notifications;
- object to decisions based solely on automated processing, such as automatic attendance statuses;
- delay or restrict processing in proportion to its purpose;
- data portability: receive your data in a commonly used, machine-readable format and have it sent to another controller where technically feasible; and
- claim compensation for violations in the processing of your personal data, in accordance with the law.
You can view most of your data in HRIS, change your password, turn notifications on or off, and submit attendance corrections. For anything else, contact HR or email [email protected] with the subject “Privacy Request – HRIS”, stating your name, employee number and what you would like us to do. We will respond within the time limits set by the PDP Law (for many requests, no later than 3 × 24 hours after we receive a complete and verified request). If we cannot fulfil a request, we will explain why. You may also lodge a complaint with the personal data protection authority in Indonesia.
13. Changes to this policy
We may update this policy when HRIS or the law changes. We will publish the updated version on this page, change the “Last updated” date and inform employees of significant changes before they take effect.
14. Contact us
Wafa Indonesia – Yayasan Syafa’atul Qur’an Indonesia
Jl. Raya Wisma Pagesangan No. 9, Menanggal, Gayungan, Surabaya, East Java 60234, Indonesia
Email: [email protected]
WhatsApp Helpdesk: +62 811-3058-9310
Phone: +62 31 9904 3404
Office hours: Monday–Friday 08.00–16.00 WIB, Saturday 08.00–12.00 WIB
