Effective date: 5 October 2026 · Last updated: 5 October 2026 · Applies to: sertifikat.wafaindonesia.or.id
Wafa Certificate Verification (Sertifikat) is a public website that lets anyone check whether a certificate or other document issued by Wafa Indonesia is genuine. Every verifiable Wafa document carries a QR code and a verification code. Scanning the code opens a page showing the document’s key details and its current status.
The verification site does not store the content of documents. It keeps only a minimal index (which Wafa system issued a code, and whether the document is still valid) and fetches the details directly from the issuing system each time a code is checked. This Privacy Policy explains how the site handles personal data, in line with Law of the Republic of Indonesia No. 27 of 2022 on Personal Data Protection (the “PDP Law”).
At a glance
- No accounts, no cookies and no tracking.
- If you hold a Wafa certificate: anyone who has its QR code or verification code can see the details on the verification page, such as your name, institution and result. Your date of birth and detailed scores are not shown.
- Our index contains no names or other personal details, only codes and their status.
- If you visit the site: we log your IP address for security and to prevent abuse. Verification codes are never written to our logs.
- Our servers are located in Singapore. We never sell your data.
Contents
1. Who we are
Wafa Certificate Verification is operated by Yayasan Syafa’atul Qur’an Indonesia (YAQIN), known as Wafa Indonesia (“Wafa”, “we”, “us” or “our”), a foundation established under the laws of the Republic of Indonesia. Wafa Indonesia is the personal data controller for the processing described in this policy. Documents are issued by our other systems, currently SiMumtaz (munaqosyah certificates, syahadah and piagam) and SIFA (partner institution certificates), which have their own privacy policies.
2. How verification works
- When a document is issued, the issuing system registers its verification code with this site.
- When someone scans the QR code or opens the verification link, this site checks the code against its index and then asks the issuing system for the current details.
- The page shows the details and the document’s status: active, revoked, suspended, expired or no longer valid.
- If the issuing system cannot be reached, the site can still show that a document is revoked or expired, but it never confirms a document as valid without checking with the issuing system first.
3. Personal data we process
| Category | What it includes | Where it comes from |
|---|---|---|
| Verification index | Verification code, issuing system, document type, status, validity date and an internal reference. No names, dates of birth, scores or other personal details. | SiMumtaz; SIFA. |
| Details shown on the verification page | Munaqosyah certificates, syahadah and piagam: certificate number, participant’s name, institution, test type, material covered, predicate, examination date, issue date and expiry date (if any). Partner institution certificates: institution code and name, region, partnership status and validity. |
Fetched live from SiMumtaz or SIFA. |
| Temporary cache | A copy of the details above, kept in server memory: a fresh copy for a few minutes, and a backup copy for up to 24 hours that is used only when the issuing system is temporarily unreachable. | SiMumtaz; SIFA. |
| Visitor data | IP address, time, request method, response status and duration. The verification code in the address is replaced in our logs by a short fingerprint that cannot be turned back into the code. | Your browser. |
Printed certificates also contain the holder’s place and date of birth and detailed scores. This site deliberately leaves them out, even though the issuing system holds them.
4. How we use data and our legal bases
| Purpose | Legal basis (PDP Law, Art. 20) |
|---|---|
| Confirm that a Wafa document is genuine and show its current status to holders and to anyone they show it to, such as schools or employers. | Legitimate interests of certificate holders and Wafa in preventing forgery; fulfilment of the certification service. |
| Show when a document has been revoked or suspended so it cannot be passed off as valid. | Legitimate interests. |
| Protect the site against abuse, such as attempts to guess codes, and keep it running. | Legal obligations as an electronic system operator; legitimate interests. |
We do not use visitor data to identify, profile or advertise to visitors.
5. For certificate holders
Treat your verification code like a key. Anyone who has your certificate, its QR code or its verification code can open the verification page and see the details listed above. Share it only with people who need to check it.
- If details on the page are wrong, or you think your certificate is being misused, contact us. We can correct the record, reissue the certificate, or suspend or revoke the code.
- Many munaqosyah certificates belong to children. That is why the page shows only the minimum needed to confirm authenticity, in line with Article 25 of the PDP Law.
6. Who we share data with
- Issuing Wafa systems (SiMumtaz and SIFA). When a code is checked, the site sends the code to the issuing system through an authenticated, digitally signed request.
- Anyone who has the code can see the details on the verification page, by design.
| Provider | What they do | Data involved | Location |
|---|---|---|---|
| Contabo | Cloud servers that host the site. | All data described in this policy. | Singapore |
| Google (Google Fonts) | Provides the fonts used on the site. | IP address and browser information. | Global |
Singapore has a comprehensive data protection law (the Personal Data Protection Act 2012). We transfer personal data outside Indonesia only in accordance with Article 56 of the PDP Law. We may disclose data where required by law or a lawful request from a competent authority. We do not sell, rent or trade personal data.
7. How long we keep data
| Data | How long |
|---|---|
| Verification index | Permanently, so documents remain verifiable and revoked codes are never accepted again. |
| Cached document details | A few minutes; backup copy at most 24 hours. |
| Visitor logs | Up to 30 days. |
| The documents themselves | Held by SiMumtaz or SIFA for the periods in their privacy policies. |
8. How we protect data
- All connections are encrypted with HTTPS.
- Verification codes are long and random, and requests are rate-limited per IP address to stop people from guessing them.
- Communication with issuing systems is authenticated and digitally signed.
- The index holds no personal details, and verification codes are removed from our logs.
- A document is never shown as valid unless the issuing system confirms it, so revocations take effect even if a notification fails.
If a personal data breach occurs, we will notify the affected people and the relevant authority in writing no later than 3 × 24 hours, as required by Article 46 of the PDP Law.
9. Cookies
This site does not use cookies, local storage, analytics or tracking. The only third-party content is the fonts loaded from Google Fonts.
10. Your rights
Under the PDP Law (Articles 5–13) you have the right to be informed, to access and obtain a copy of your data, to correct it, to have it deleted or its processing ended (subject to legal exceptions, such as keeping issued certificates verifiable), to withdraw consent, to object to decisions based solely on automated processing, to delay or restrict processing, to data portability, and to claim compensation for violations in accordance with the law.
Certificate holders, or the parents or guardians of children, can email [email protected] with the subject “Privacy Request – Sertifikat”, stating the certificate number and what they would like us to do. Visitors can ask us about their log data, but because we keep only IP addresses for a short time we may be unable to link a visit to a specific person. We will respond within the time limits set by the PDP Law (for many requests, no later than 3 × 24 hours after we receive a complete and verified request). You may also lodge a complaint with the personal data protection authority in Indonesia.
11. Changes to this policy
We may update this policy when the site or the law changes. We will publish the updated version on this page and change the “Last updated” date.
12. Contact us
Wafa Indonesia – Yayasan Syafa’atul Qur’an Indonesia
Jl. Raya Wisma Pagesangan No. 9, Menanggal, Gayungan, Surabaya, East Java 60234, Indonesia
Email: [email protected]
WhatsApp Helpdesk: +62 811-3058-9310
Phone: +62 31 9904 3404
Office hours: Monday–Friday 08.00–16.00 WIB, Saturday 08.00–12.00 WIB
