Privacy Policy of Wafa Sertifikat

Effective date: 5 October 2026  ·  Last updated: 5 October 2026  ·  Applies to: sertifikat.wafaindonesia.or.id

Wafa Certificate Verification (Sertifikat) is a public website that lets anyone check whether a certificate or other document issued by Wafa Indonesia is genuine. Every verifiable Wafa document carries a QR code and a verification code. Scanning the code opens a page showing the document’s key details and its current status.

The verification site does not store the content of documents. It keeps only a minimal index (which Wafa system issued a code, and whether the document is still valid) and fetches the details directly from the issuing system each time a code is checked. This Privacy Policy explains how the site handles personal data, in line with Law of the Republic of Indonesia No. 27 of 2022 on Personal Data Protection (the “PDP Law”).

At a glance

  • No accounts, no cookies and no tracking.
  • If you hold a Wafa certificate: anyone who has its QR code or verification code can see the details on the verification page, such as your name, institution and result. Your date of birth and detailed scores are not shown.
  • Our index contains no names or other personal details, only codes and their status.
  • If you visit the site: we log your IP address for security and to prevent abuse. Verification codes are never written to our logs.
  • Our servers are located in Singapore. We never sell your data.

1. Who we are

Wafa Certificate Verification is operated by Yayasan Syafa’atul Qur’an Indonesia (YAQIN), known as Wafa Indonesia (“Wafa”, “we”, “us” or “our”), a foundation established under the laws of the Republic of Indonesia. Wafa Indonesia is the personal data controller for the processing described in this policy. Documents are issued by our other systems, currently SiMumtaz (munaqosyah certificates, syahadah and piagam) and SIFA (partner institution certificates), which have their own privacy policies.

2. How verification works

  1. When a document is issued, the issuing system registers its verification code with this site.
  2. When someone scans the QR code or opens the verification link, this site checks the code against its index and then asks the issuing system for the current details.
  3. The page shows the details and the document’s status: active, revoked, suspended, expired or no longer valid.
  4. If the issuing system cannot be reached, the site can still show that a document is revoked or expired, but it never confirms a document as valid without checking with the issuing system first.

3. Personal data we process

Category What it includes Where it comes from
Verification index Verification code, issuing system, document type, status, validity date and an internal reference. No names, dates of birth, scores or other personal details. SiMumtaz; SIFA.
Details shown on the verification page Munaqosyah certificates, syahadah and piagam: certificate number, participant’s name, institution, test type, material covered, predicate, examination date, issue date and expiry date (if any).
Partner institution certificates: institution code and name, region, partnership status and validity.
Fetched live from SiMumtaz or SIFA.
Temporary cache A copy of the details above, kept in server memory: a fresh copy for a few minutes, and a backup copy for up to 24 hours that is used only when the issuing system is temporarily unreachable. SiMumtaz; SIFA.
Visitor data IP address, time, request method, response status and duration. The verification code in the address is replaced in our logs by a short fingerprint that cannot be turned back into the code. Your browser.

Printed certificates also contain the holder’s place and date of birth and detailed scores. This site deliberately leaves them out, even though the issuing system holds them.

4. How we use data and our legal bases

Purpose Legal basis (PDP Law, Art. 20)
Confirm that a Wafa document is genuine and show its current status to holders and to anyone they show it to, such as schools or employers. Legitimate interests of certificate holders and Wafa in preventing forgery; fulfilment of the certification service.
Show when a document has been revoked or suspended so it cannot be passed off as valid. Legitimate interests.
Protect the site against abuse, such as attempts to guess codes, and keep it running. Legal obligations as an electronic system operator; legitimate interests.

We do not use visitor data to identify, profile or advertise to visitors.

5. For certificate holders

Treat your verification code like a key. Anyone who has your certificate, its QR code or its verification code can open the verification page and see the details listed above. Share it only with people who need to check it.

  • If details on the page are wrong, or you think your certificate is being misused, contact us. We can correct the record, reissue the certificate, or suspend or revoke the code.
  • Many munaqosyah certificates belong to children. That is why the page shows only the minimum needed to confirm authenticity, in line with Article 25 of the PDP Law.

6. Who we share data with

  • Issuing Wafa systems (SiMumtaz and SIFA). When a code is checked, the site sends the code to the issuing system through an authenticated, digitally signed request.
  • Anyone who has the code can see the details on the verification page, by design.
Provider What they do Data involved Location
Contabo Cloud servers that host the site. All data described in this policy. Singapore
Google (Google Fonts) Provides the fonts used on the site. IP address and browser information. Global

Singapore has a comprehensive data protection law (the Personal Data Protection Act 2012). We transfer personal data outside Indonesia only in accordance with Article 56 of the PDP Law. We may disclose data where required by law or a lawful request from a competent authority. We do not sell, rent or trade personal data.

7. How long we keep data

Data How long
Verification index Permanently, so documents remain verifiable and revoked codes are never accepted again.
Cached document details A few minutes; backup copy at most 24 hours.
Visitor logs Up to 30 days.
The documents themselves Held by SiMumtaz or SIFA for the periods in their privacy policies.

8. How we protect data

  • All connections are encrypted with HTTPS.
  • Verification codes are long and random, and requests are rate-limited per IP address to stop people from guessing them.
  • Communication with issuing systems is authenticated and digitally signed.
  • The index holds no personal details, and verification codes are removed from our logs.
  • A document is never shown as valid unless the issuing system confirms it, so revocations take effect even if a notification fails.

If a personal data breach occurs, we will notify the affected people and the relevant authority in writing no later than 3 × 24 hours, as required by Article 46 of the PDP Law.

9. Cookies

This site does not use cookies, local storage, analytics or tracking. The only third-party content is the fonts loaded from Google Fonts.

10. Your rights

Under the PDP Law (Articles 5–13) you have the right to be informed, to access and obtain a copy of your data, to correct it, to have it deleted or its processing ended (subject to legal exceptions, such as keeping issued certificates verifiable), to withdraw consent, to object to decisions based solely on automated processing, to delay or restrict processing, to data portability, and to claim compensation for violations in accordance with the law.

Certificate holders, or the parents or guardians of children, can email [email protected] with the subject “Privacy Request – Sertifikat”, stating the certificate number and what they would like us to do. Visitors can ask us about their log data, but because we keep only IP addresses for a short time we may be unable to link a visit to a specific person. We will respond within the time limits set by the PDP Law (for many requests, no later than 3 × 24 hours after we receive a complete and verified request). You may also lodge a complaint with the personal data protection authority in Indonesia.

11. Changes to this policy

We may update this policy when the site or the law changes. We will publish the updated version on this page and change the “Last updated” date.

12. Contact us

Wafa Indonesia – Yayasan Syafa’atul Qur’an Indonesia
Jl. Raya Wisma Pagesangan No. 9, Menanggal, Gayungan, Surabaya, East Java 60234, Indonesia
Email: [email protected]
WhatsApp Helpdesk: +62 811-3058-9310
Phone: +62 31 9904 3404
Office hours: Monday–Friday 08.00–16.00 WIB, Saturday 08.00–12.00 WIB

Privacy Policy of Wafa HRIS

Effective date: 5 October 2026  ·  Last updated: 5 October 2026  ·  Applies to: hris.wafaindonesia.or.id

HRIS Wafa is Wafa Indonesia’s human resource information system for our employees. It handles employee records, attendance (with location and photo verification), leave and permission requests, business trips, overtime, daily work reports and Mutaba’ah, our daily Quran recitation log.

This Privacy Policy explains how HRIS processes the personal data of our employees and of people whose details employees provide, such as emergency contacts. It is written in line with Law of the Republic of Indonesia No. 27 of 2022 on Personal Data Protection (the “PDP Law”).

At a glance

  • HRIS processes the data we need to employ you: identity numbers (NIK, NPWP, family card), contact details, contract and salary, attendance, leave and other requests.
  • Some of it is specific (sensitive) personal data under the PDP Law, such as health-related data (blood type, height and weight, doctors’ certificates) and financial data (salary). Access to it is restricted.
  • Your location is recorded only at the moment you clock in or out, never continuously. A selfie is taken at the same moment to prevent proxy attendance. We do not use facial recognition.
  • Attendance photos and supporting documents are deleted automatically after 100 days.
  • Some attendance statuses are set automatically from your schedule. You can always request a correction.
  • Data is shared only within Wafa and with a few providers (hosting, maps and push notifications). We never sell your data. Our servers are located in Singapore.

1. Who we are

HRIS is operated by Yayasan Syafa’atul Qur’an Indonesia (YAQIN), known as Wafa Indonesia (“Wafa”, “we”, “us” or “our”), a foundation established under the laws of the Republic of Indonesia and your employer. Wafa Indonesia is the personal data controller for the processing described in this policy. HRIS currently uses its own sign-in with your email address and password, separate from the Wafa SSO Portal.

2. Personal data we process

Category What it includes Where it comes from
Identity and personal details Employee number, full name, profile photo, national identity number (NIK), tax number (NPWP), family card (KK) number, place and date of birth, gender, religion, marital status, nationality and Wafa ID. You; HR.
Health-related data Blood type, height and weight; doctors’ certificates and similar documents attached to sick leave or permission requests. You.
Contact details Phone numbers and email addresses, including emergency contacts (label and number), and which one is your primary contact. You; HR.
Employment Branch, department, job position, system role and access level, trainer status, contracts (number, type, start and end dates, salary, notes), work schedule and shift, leave entitlements and balances. HR.
Attendance Date, clock-in and clock-out times, GPS coordinates and selfie photos at clock-in and clock-out, method (GPS or manual), status (present, late, half day, absent, leave, business trip or holiday), minutes late or early and the reasons, supporting documents, overtime minutes, and manual entries with notes. Your device; generated automatically; HR.
Requests and approvals Attendance corrections (original and corrected times, reason); permissions (late arrival, early leave, out of office); leave (type, dates, reason, documents such as medical, marriage or death certificates); business trips (destination, dates, purpose, documents); overtime (planned and actual times, reason, work location); and approvers’ decisions and notes. You; supervisors; HR.
Daily work reports The activities you report for each working day. You.
Mutaba’ah Your daily Quran recitation target (number of pages) and whether and when you submitted it. You.
Account Email address, password (stored only as a one-way hash), role and last sign-in. HR; you.
Notifications In-app notifications and, if you enable push notifications, your browser’s push subscription (endpoint and keys) and delivery status. You; generated automatically.
Audit and technical data Record of changes (who changed which record, old and new values, IP address, browser); technical logs. Generated automatically.

Health-related data and personal financial data are specific personal data under Article 4 of the PDP Law. We process them only where necessary, for example to administer sick leave or salary as required by law, and restrict access to HR and authorised approvers. Religion and marital status are recorded for HR administration only.

If you give us details of other people, such as emergency contacts or family members named in leave documents, please make sure they know about it.

3. How we use your data and our legal bases

Purpose Legal basis (PDP Law, Art. 20)
Administer your employment: records, contracts, positions and organisational structure. Fulfilment of your employment agreement; legal obligations (manpower law).
Record attendance and working hours, check your location against the office area and take a photo to prevent proxy attendance. Fulfilment of your employment agreement; legitimate interests (reliable attendance records).
Process leave, permissions, business trips and overtime, including approvals and supporting documents. Fulfilment of your employment agreement; legal obligations (leave entitlements).
Calculate leave balances and overtime and prepare data for payroll. Fulfilment of your employment agreement; legal obligations.
Meet tax and statutory obligations (NIK, NPWP, family card, salary). Legal obligations.
Daily work reports and performance management. Fulfilment of your employment agreement; legitimate interests.
Run the Mutaba’ah program that supports staff’s daily Quran recitation. Legitimate interests as an Islamic educational foundation, in line with our internal staff development policy.
Send reminders and updates (clock-in and clock-out, prayer times, approvals). Legitimate interests; push notifications only with your permission (consent).
Contact someone close to you in an emergency. Vital interests; legitimate interests.
Register you in the Wafa ID registry of Wafa SSO. Legitimate interests.
HR reports, dashboards and exports for management. Legitimate interests; legal obligations.
Security, audit trails and compliance with the law. Legal obligations; legitimate interests.

4. Location and photos at clock-in

  • Location only when you clock in or out. Your browser asks for permission to use your location. HRIS reads it once at clock-in and once at clock-out. It does not track you at any other time.
  • Office area check. Your coordinates are compared with your branch’s location and permitted radius (100 metres by default). During an approved business trip the area check is switched off, but your coordinates are still recorded as evidence of attendance.
  • Selfie photo. A photo is taken with your device’s camera at clock-in and clock-out and uploaded directly to our private storage through a link that is valid for 5 minutes. Authorised HR staff can view it through links valid for 15 minutes. Photos are used only for manual checks against proxy attendance. We do not use facial recognition or any other biometric identification.
  • Automatic deletion. Attendance photos and supporting documents are deleted automatically 100 days after upload.
  • Maps. When you or HR view the location of an attendance record, the map is loaded from OpenStreetMap, so those coordinates are sent to OpenStreetMap to display it.
  • If you refuse permission. You can refuse location or camera access, but GPS attendance will not work. Please contact HR, who can record your attendance manually.

5. Automatic attendance records

HRIS sets your attendance status (for example present, late or half day) automatically from your schedule. Every night at 23:59, it creates an “absent” record for scheduled employees who did not clock in on a working day that is not a holiday, and it creates the day’s daily report and Mutaba’ah entries. These records may be used for leave, overtime and payroll. If a record is wrong, you can submit an attendance correction or a permission request, which is reviewed by a person (your supervisor or HR). You also have the right to object to decisions based solely on automated processing (Article 10 of the PDP Law).

6. Who can see your data within Wafa

  • You can see your own data, requests and their approval timeline.
  • Supervisors and leaders see the data of their own team needed to approve requests and monitor attendance.
  • HR administrators see employee data needed for HR administration, including the history of changes.
  • Super administrators have full access, including system records, and are limited to a small number of people.

7. Who we share your data with

7.1 Within Wafa

HRIS sends your name, phone number, email address and employee number to Wafa SSO so that you receive a Wafa ID. Your job title and department may also be recorded in your Wafa Account to set your access rights in other Wafa applications, as described in the Wafa SSO Portal privacy policy.

7.2 Service providers

Provider What they do Data involved Location
Contabo Cloud servers that host HRIS, its database and our private file storage. All data described in this policy. Singapore
OpenStreetMap Foundation Map images, the map showing an attendance location, and address search when HR sets up branch locations. Coordinates of the area shown, search terms, IP address and browser information. United Kingdom / European Union
Browser push services (Google Firebase Cloud Messaging, Apple Push Notification service, Mozilla Push Service) Deliver push notifications to your device, only if you enable them. Your device’s push address and the notification, whose content is encrypted end-to-end. Global
Google (Google Fonts) Provides the fonts used in HRIS. IP address and browser information. Global
Api.co.id Provides public holidays and prayer times for scheduling. No personal data. Indonesia

7.3 Authorities

We may disclose personal data where required by law, for example to tax or employment authorities, or in response to a court order or a lawful request from a competent authority. We do not sell, rent or trade personal data.

8. International data transfers

Our servers are located in Singapore, so HRIS data is stored outside Indonesia. Map and push notification providers may also process limited data in other countries. Singapore has a comprehensive data protection law (the Personal Data Protection Act 2012). We transfer personal data outside Indonesia only in accordance with Article 56 of the PDP Law: the destination country provides a level of protection equal to or higher than the PDP Law, or adequate and binding safeguards are in place, or, where neither applies, with your consent.

9. How long we keep your data

Data How long
Employee records, attendance records, requests, reports, Mutaba’ah and audit records For the duration of your employment and up to 5 years after it ends.
Salary and other records needed for tax and accounting 10 years, as required by Indonesian tax, accounting and company document laws.
Attendance photos and supporting documents (leave, permissions, business trips, Mutaba’ah) Deleted automatically 100 days after upload.
Profile photo While you are employed; deleted with your employee record.
Sign-in Access for 7 days, renewable for up to 30 days, or until you sign out.
Push subscriptions Until you turn off notifications or the subscription expires.
Technical logs 30 days (performance traces: 7 days).

When the period ends, we delete the data or anonymise it so it can no longer identify you.

10. How we protect your data

  • All connections are encrypted with HTTPS. Passwords are stored only as a one-way hash (bcrypt) and cannot be read by anyone, including Wafa staff.
  • Access is role-based and limited by level, as described in section 6.
  • Photos and documents are kept in private storage that is not publicly accessible. They can only be opened through links that expire after 15 minutes, and they are deleted automatically after 100 days.
  • Changes to employee data, contracts, attendance, leave balances, overtime and corrections are recorded in an audit trail, and original attendance times are kept when a correction is approved.
  • Push notification content is encrypted so that push services cannot read it.

Your sign-in is stored in your browser, so please sign out when using a shared device. If a personal data breach occurs, we will notify you and the relevant authority in writing no later than 3 × 24 hours, as required by Article 46 of the PDP Law.

11. Data stored in your browser

Item Type Purpose Duration
Sign-in tokens and account details Local storage (strictly necessary) Keep you signed in and remember your profile and permissions. Until you sign out (at most 30 days without renewal).
Preferences Local storage Remember light/dark mode and sidebar state. Until you clear browser data.
App cache and push subscription Service worker Lets HRIS be installed, load quickly and receive notifications. Until updated, removed or notifications are turned off.

HRIS does not use advertising, analytics or tracking cookies.

12. Your rights

Under the PDP Law (Articles 5–13) you have the right to:

  • be informed about who processes your data, why and on what basis;
  • access your personal data and obtain a copy;
  • correct or update data that is inaccurate or incomplete;
  • end processing, delete or destroy your data, subject to legal exceptions (for example, records we must keep under employment, tax or accounting laws);
  • withdraw consent where processing is based on consent, such as push notifications;
  • object to decisions based solely on automated processing, such as automatic attendance statuses;
  • delay or restrict processing in proportion to its purpose;
  • data portability: receive your data in a commonly used, machine-readable format and have it sent to another controller where technically feasible; and
  • claim compensation for violations in the processing of your personal data, in accordance with the law.

You can view most of your data in HRIS, change your password, turn notifications on or off, and submit attendance corrections. For anything else, contact HR or email [email protected] with the subject “Privacy Request – HRIS”, stating your name, employee number and what you would like us to do. We will respond within the time limits set by the PDP Law (for many requests, no later than 3 × 24 hours after we receive a complete and verified request). If we cannot fulfil a request, we will explain why. You may also lodge a complaint with the personal data protection authority in Indonesia.

13. Changes to this policy

We may update this policy when HRIS or the law changes. We will publish the updated version on this page, change the “Last updated” date and inform employees of significant changes before they take effect.

14. Contact us

Wafa Indonesia – Yayasan Syafa’atul Qur’an Indonesia
Jl. Raya Wisma Pagesangan No. 9, Menanggal, Gayungan, Surabaya, East Java 60234, Indonesia
Email: [email protected]
WhatsApp Helpdesk: +62 811-3058-9310
Phone: +62 31 9904 3404
Office hours: Monday–Friday 08.00–16.00 WIB, Saturday 08.00–12.00 WIB

Privacy Policy of Wafa Khidmah

Effective date: 5 October 2026  ·  Last updated: 5 October 2026  ·  Applies to: khidmah.wafaindonesia.or.id

Khidmah Wafa is the work app for Wafa Indonesia’s professional staff (SDM Profesional): munaqosyah examiners (munaqisy), trainers, academy teachers and others assigned to Wafa activities. It brings your profile, your schedule and your munaqosyah grading together in one app that works on your phone, tablet or computer.

Khidmah does not keep its own database. It shows and updates data held in three other Wafa systems: Wafa SSO (your account), SIFA (your professional profile and assignments) and SiMumtaz (munaqosyah participants and scores). This Privacy Policy explains how Khidmah handles personal data, in line with Law of the Republic of Indonesia No. 27 of 2022 on Personal Data Protection (the “PDP Law”).

At a glance

  • You sign in with your Wafa Account, and Khidmah reads your name, contact details and Wafa ID from Wafa SSO.
  • Your biodata, fields of expertise and competency levels come from SIFA. You can update some of them in the app.
  • When you grade a munaqosyah, you see the participants assigned to you, who are often children. The scores you enter are saved in SiMumtaz.
  • If your connection drops while grading, scores wait on your device and are sent automatically when you are back online.
  • Khidmah keeps only your sign-in session and a short-lived cache on our servers. We never sell your data.
  • Our servers are located in Singapore.
  • To exercise your rights, contact [email protected].

1. Who we are

Khidmah is operated by Yayasan Syafa’atul Qur’an Indonesia (YAQIN), known as Wafa Indonesia (“Wafa”, “we”, “us” or “our”), a foundation established under the laws of the Republic of Indonesia. Wafa Indonesia is the personal data controller for the processing described in this policy. The Wafa SSO Portal, SIFA and SiMumtaz each have their own privacy policy describing how they store your data.

2. Personal data we process

Category What it includes Where it comes from
Your account Name, email address, WhatsApp number, Wafa ID, roles, and whether you have set a password or still have a temporary email address. Wafa SSO.
Your professional profile Full name, gender, place and date of birth, address, province and city, fields of expertise, competency levels, qualifications and education history. SIFA; you, when you edit your biodata.
Assignments and schedule Activities you are assigned to, your role, dates, places and institutions. SIFA; SiMumtaz.
Munaqosyah grading Participants assigned to you (name, institution, category, test type and target material), attendance, the scores you enter per aspect and juz, participants you add at the last minute (name, gender, category, test type and target), and your grading history and statistics. SiMumtaz; you.
Contact details you add A new email address or WhatsApp number and the one-time code that confirms it (handled by Wafa SSO). You.
Session and technical data Session identifier, IP address (passed on to SIFA and SiMumtaz for their security logs), request identifiers and technical logs. Generated automatically.

Your email address and WhatsApp number belong to your Wafa Account, so Khidmah shows them but does not change them. You can add a missing email address or number in the app. To change an existing one, use the Wafa SSO Portal or contact us.

3. How we use your data and our legal bases

Purpose Legal basis (PDP Law, Art. 20)
Sign you in and show your profile, schedule, competency levels and tasks. Fulfilment of an agreement (your engagement with Wafa); legitimate interests.
Let you keep your biodata in SIFA accurate. Fulfilment of an agreement; legitimate interests (accurate records).
Let you grade munaqosyah participants, including without an internet connection. Fulfilment of an agreement; legitimate interests.
Let you add an email address or WhatsApp number to your Wafa Account. Fulfilment of an agreement; legitimate interests (account security).
Keep the app secure and fix problems. Legal obligations as an electronic system operator; legitimate interests.

Your competency levels and incentive rates are calculated in SIFA, as explained in the SIFA privacy policy. Khidmah only displays them. We do not use your data for advertising.

4. Who we share your data with

4.1 Within Wafa

Khidmah exchanges data only with Wafa SSO, SIFA and SiMumtaz, and only through a fixed list of permitted functions. It sends your sign-in token, IP address and a request identifier with each request. It does not pass on cookies.

4.2 Service providers

Provider What they do Data involved Location
Contabo Cloud servers that host Khidmah. Sessions, short-lived cache and the data passing through the app. Singapore
Google (Google Fonts) Provides the fonts used in the app. IP address and browser information. Global

One-time codes for adding an email address or WhatsApp number are sent by Wafa SSO through its email and WhatsApp providers, as described in the Wafa SSO Portal privacy policy.

We may disclose personal data where required by law, a court order or a lawful request from a competent authority. We do not sell, rent or trade personal data.

5. International data transfers

Our servers are located in Singapore, which has a comprehensive data protection law (the Personal Data Protection Act 2012). We transfer personal data outside Indonesia only in accordance with Article 56 of the PDP Law: the destination country provides a level of protection equal to or higher than the PDP Law, or adequate and binding safeguards are in place, or, where neither applies, with your consent.

6. How long we keep your data

Data How long
Sign-in session Up to 30 days, or until you sign out or your Wafa Account session is ended.
Profile cache on our server 5 minutes.
Scores waiting on your device Until they are sent successfully, then removed automatically.
Technical logs 30 days (performance traces: 7 days).
Your profile, assignments and scores Kept in SIFA, SiMumtaz and Wafa SSO for the periods set out in their privacy policies.

7. How we protect your data

  • All connections are encrypted with HTTPS, and sign-in uses your Wafa Account.
  • Your session is held in an HttpOnly, Secure cookie. When your Wafa Account is signed out elsewhere or deactivated, your Khidmah session ends too.
  • Khidmah can only reach a fixed list of functions in SIFA and SiMumtaz, so it cannot be used to read other data held there.
  • You see only your own profile and the participants of activities assigned to you.
  • Scores are never stored in the app’s offline cache. Only unsent scores wait in a dedicated queue on your device.

Please help us: use a screen lock on your device, do not share your account, sign out on shared devices, and do not copy, photograph or share participants’ data outside the app. If a personal data breach occurs, we will notify the affected people and the relevant authority in writing no later than 3 × 24 hours, as required by Article 46 of the PDP Law.

8. Cookies and data stored on your device

Name Type Purpose Duration
khidmah_session Strictly necessary cookie Keeps you signed in. Up to 30 days, or until sign-out.
Unsent score queue IndexedDB on your device Holds scores entered while offline until they can be sent. Until sent successfully.
App cache Service worker Stores application files, images, fonts and reference lists so the app loads quickly and can be installed. It does not store scores. Until updated or removed.
Preferences Local and session storage Remembers light/dark mode, and briefly notes your last sign-in attempt to avoid repeated redirects. Until you clear browser data (session storage: until you close the tab).

We do not use advertising, analytics or tracking cookies in Khidmah.

9. Participants’ data and children

Many munaqosyah participants you grade are children. Their data comes from their institutions through SiMumtaz and is handled as described in the SiMumtaz privacy policy, in line with Article 25 of the PDP Law. In Khidmah you see only the participants of activities assigned to you, and only the data needed to grade them. As an examiner, you must use this data only for your assignment and keep it confidential.

10. Your rights

Under the PDP Law (Articles 5–13) you have the right to:

  • be informed about who processes your data, why and on what basis;
  • access your personal data and obtain a copy;
  • correct or update data that is inaccurate or incomplete;
  • end processing, delete or destroy your data, subject to legal exceptions;
  • withdraw consent where processing is based on consent;
  • object to decisions based solely on automated processing;
  • delay or restrict processing in proportion to its purpose;
  • data portability: receive your data in a commonly used, machine-readable format and have it sent to another controller where technically feasible; and
  • claim compensation for violations in the processing of your personal data, in accordance with the law.

You can view your data and update parts of your biodata directly in the app. For anything else, email [email protected] with the subject “Privacy Request – Khidmah”, stating your name, your Wafa ID if you know it, and what you would like us to do. We may need to verify your identity first. We will respond within the time limits set by the PDP Law (for many requests, no later than 3 × 24 hours after we receive a complete and verified request). You may also lodge a complaint with the personal data protection authority in Indonesia.

11. Changes to this policy

We may update this policy when the app or the law changes. We will publish the updated version on this page and change the “Last updated” date. For significant changes, we will also notify you in the app or by WhatsApp or email.

12. Contact us

Wafa Indonesia – Yayasan Syafa’atul Qur’an Indonesia
Jl. Raya Wisma Pagesangan No. 9, Menanggal, Gayungan, Surabaya, East Java 60234, Indonesia
Email: [email protected]
WhatsApp Helpdesk: +62 811-3058-9310
Phone: +62 31 9904 3404
Office hours: Monday–Friday 08.00–16.00 WIB, Saturday 08.00–12.00 WIB

Privacy Policy of Wafa SiMumtaz

Effective date: 5 October 2026  ·  Last updated: 5 October 2026  ·  Applies to: simumtaz.wafaindonesia.or.id, including certificate request forms and certificate (syahadah) links

SiMumtaz is Wafa Indonesia’s munaqosyah management system. Munaqosyah is the Quran proficiency examination that concludes learning with the Wafa method. Partner institutions use SiMumtaz to apply for munaqosyah and register their students and teachers as participants. Wafa staff and examiners (munaqisy) use it to schedule examinations, record and validate scores, and issue certificates (sertifikat, syahadah and piagam).

This Privacy Policy explains what personal data SiMumtaz processes, why, who we share it with, how long we keep it and what rights you have. It is written in line with Law of the Republic of Indonesia No. 27 of 2022 on Personal Data Protection (the “PDP Law”).

At a glance

  • Most participants are students of partner institutions, and many of them are children. Institutions provide their data, and we use it only to examine, grade and certify.
  • We record scores, results and certificates. Each certificate carries a Wafa ID and a QR code that anyone can use to check that it is genuine. The public check shows the name, institution and result, but not the date of birth or detailed scores.
  • Certificates are delivered by email (after a request through a Google Form, sent with Brevo) or by WhatsApp (through Fonnte).
  • Within Wafa we share data with SIFA, Khidmah and Wafa SSO. We never sell your data.
  • Our servers are located in Singapore.
  • To exercise your rights, contact [email protected].

1. Who we are

SiMumtaz is operated by Yayasan Syafa’atul Qur’an Indonesia (YAQIN), known as Wafa Indonesia (“Wafa”, “we”, “us” or “our”), a foundation established under the laws of the Republic of Indonesia. Wafa Indonesia is the personal data controller for the processing described in this policy. Sign-in to SiMumtaz is provided by the Wafa SSO Portal, which has its own privacy policy.

2. Whose data we process

  • Users: Wafa staff (administrators, quality managers and score validators), administrators and Quran coordinators of partner institutions, and examiners;
  • participants: students and teachers who take a munaqosyah examination;
  • parents or guardians of student participants, whose phone number is recorded;
  • contacts of external parties: organisations or individuals outside our partner network that apply for munaqosyah; and
  • people who fill in a certificate request form or a certificate link.

3. Personal data we process

Category What it includes Where it comes from
Users Name, email address, phone number, roles and permissions, institution, job title and Wafa ID; session records (IP address, browser information). Wafa SSO.
Participants Category (student or teacher) and level, student number (NIS/NISN), full name, gender, place and date of birth, parent or guardian’s phone number (students), phone number and email address (teachers), status, notes, institution or external party, and Wafa ID. Partner institution or external party; Wafa staff; SIFA.
Applications and activities Applying institution or external party (name, address, city, contact person’s name, phone and email), schedule, venue, participant lists, cost estimates and quotations, and a history of status changes (who did what and when). Institution; Wafa staff.
Examination data Examiner assignments, attendance, scores per aspect (for example tajwid and fluency) per juz, remedial results, final score, predicate, pass or fail, and who graded and validated the scores. Examiners; Wafa staff; spreadsheet imports.
Certificates Certificate number, participant registration number (NIPS), verification code, Wafa ID, participant’s name, place and date of birth, gender and student number, institution, venue and date, test type, predicate and scores, issue and expiry dates, printing records, and delivery status (when sent by email or WhatsApp, and to which address or number). Generated from the data above.
Certificate request form NIPS, name, institution, place and date of birth, phone number, email address and munaqosyah level. The participant (Google Form).
Certificate link for teachers Full name, place and date of birth and WhatsApp number confirmed by the teacher, and when the link was sent and filled in. The teacher.
Audit and technical data Activity and application histories; technical logs (time, function called, response status, IP address and an internal user identifier). Generated automatically.

Students’ data is children’s data, which is specific personal data under Article 4 of the PDP Law. See section 11.

4. How we use your data and our legal bases

Purpose Legal basis (PDP Law, Art. 20)
Receive and process munaqosyah applications; prepare cost estimates and quotations. Fulfilment of an agreement with the institution or applicant.
Manage participants and schedules; assign examiners. Fulfilment of an agreement; legitimate interests.
Conduct examinations, record and validate scores, determine results and run remedial tests. Fulfilment of an agreement; legitimate interests (the integrity of our certification).
Issue certificates, syahadah and piagam, and keep a record of every certificate issued. Fulfilment of an agreement; legitimate interests.
Deliver certificates by email or WhatsApp and let participants confirm the name and date of birth printed on them. Fulfilment of an agreement; your consent when you submit a form.
Register certificates so anyone can check that they are genuine. Legitimate interests (preventing forgery).
Share data with SIFA and Wafa SSO to keep partnership records and Wafa IDs consistent. Legitimate interests.
Statistics and quality assurance of our learning method. Legitimate interests.
Security, audit trails and compliance with the law. Legal obligations; legitimate interests.

For children, we also rely on the consent of a parent or guardian, obtained by the institution (see section 11).

How results are determined: scores are entered by examiners and checked by Wafa validators. SiMumtaz then calculates the final score, predicate and pass/fail result automatically using predefined assessment criteria. If you believe a result is wrong, you or your institution can ask us to review it.

5. Certificates and their delivery

  • Printed details. A certificate shows the participant’s name, place and date of birth, institution, test type, predicate and scores, plus a Wafa ID, a certificate number and a QR code.
  • Public verification. Each certificate is registered with Wafa Certificate Verification (sertifikat.wafaindonesia.or.id). Anyone who scans the QR code or enters the code sees the certificate number, name, institution, test type, material covered, predicate and dates. Date of birth and detailed scores are not shown. Please share your certificate or QR code only with people who need to verify it.
  • Delivery by email. Participants can request their certificate through a Google Form, entering their NIPS, name, institution, place and date of birth, phone number and email address. SiMumtaz updates the certificate with the confirmed details, creates a PDF and emails it through Brevo.
  • Delivery by WhatsApp. Teachers receive a personal link by WhatsApp. After they confirm their name, place and date of birth and WhatsApp number, the certificate PDF is sent to that number through Fonnte. The confirmed details also update the teacher’s participant record.
  • Institutions can download their participants’ certificates in SiMumtaz.

6. Who we share your data with

6.1 Within Wafa

  • Partner institution administrators see only their own institution’s applications, participants, results and certificates.
  • Examiners see only the participants assigned to them, usually through the Khidmah app.
  • Wafa staff have access according to their role.
  • SIFA receives participants, results and certificate details to keep partnership records.
  • Wafa SSO receives participants’ names, and teachers’ own phone number and email address, to assign a Wafa ID.
  • Wafa Certificate Verification receives the details shown on the public verification page, only when a code is checked.

6.2 Service providers

Provider What they do Data involved Location
Contabo Cloud servers that host SiMumtaz and its database. All data described in this policy. Singapore
Google (Google Forms) Hosts the certificate request form and forwards responses to SiMumtaz. The data you enter in the form. Global, including the United States
Brevo (Sendinblue SAS) Delivers certificate emails. Name, email address and the certificate PDF. European Union (France)
Fonnte Sends certificate links and PDFs by WhatsApp (operated by Meta Platforms). Phone number, message content and the certificate PDF. Indonesia; delivery through WhatsApp’s global network
Google (Google Fonts) Provides the fonts used on SiMumtaz pages. IP address and browser information. Global

SiMumtaz also sends our munaqosyah product and price list to Odoo, our accounting system. This does not include any participant data.

6.3 Other disclosures

We may disclose personal data where required by law, a court order or a lawful request from a competent authority, or to protect the rights and safety of Wafa, participants or the public. We do not sell, rent or trade personal data.

7. International data transfers

Our servers are located in Singapore, so SiMumtaz data is stored outside Indonesia. Google and Brevo may also process data in other countries. Singapore (Personal Data Protection Act 2012) and the European Union (General Data Protection Regulation) have comprehensive data protection laws. We transfer personal data outside Indonesia only in accordance with Article 56 of the PDP Law: the destination country provides a level of protection equal to or higher than the PDP Law, or adequate and binding safeguards are in place, or, where neither applies, with your consent.

8. How long we keep your data

Data How long
Participants, applications and examination data As long as the participant takes part in Wafa programs through the institution, and up to 5 years after the last examination or after the partnership ends.
Certificates (as printed), certificate numbers, verification codes and Wafa IDs Permanently, so certificates remain verifiable and can be reissued if lost.
Quotations and other financial records 10 years, as required by Indonesian accounting, tax and company document laws.
Certificate request form responses The same periods as the participant data above, including the copy kept in Google Forms under our account.
Users’ data and histories While the user has access and up to 5 years afterwards.
Sign-in sessions Up to 30 days, or until you sign out.
Technical logs 30 days (performance traces: 7 days).

When the period ends, we delete the data or anonymise it so it can no longer identify anyone.

9. How we protect your data

  • All connections are encrypted with HTTPS. Sign-in uses the Wafa SSO, and sessions are held in an HttpOnly, Secure cookie.
  • Access is role-based: institutions see only their own data and examiners see only the participants assigned to them.
  • Public forms and certificate links use long, random codes and are rate-limited to prevent guessing and abuse.
  • Communication between Wafa systems is authenticated, digitally signed and runs over internal networks.
  • The public verification page deliberately leaves out dates of birth and detailed scores.

If a personal data breach occurs, we will notify the affected people and the relevant authority in writing no later than 3 × 24 hours, as required by Article 46 of the PDP Law.

10. Cookies and similar technologies

Name Type Purpose Duration
mis_session Strictly necessary cookie Keeps you signed in to SiMumtaz. Up to 30 days, or until sign-out.
Profile and permissions Local storage Keeps a copy of your name, role and permissions so the menus load quickly. Until sign-out or you clear browser data.
Application draft Local storage Saves your progress while filling in a munaqosyah application. Until the application is submitted or you clear browser data.
Display preferences Local and session storage Remember light/dark mode, sidebar state and scroll position. Until you clear browser data (session storage: until you close the tab).

We do not use advertising, analytics or tracking cookies in SiMumtaz. On a shared computer, always sign out when you finish.

11. Children’s data

Many munaqosyah participants are children. Under Article 25 of the PDP Law, processing children’s data requires special care and the consent of a parent or guardian. Children’s data reaches us from their institution, and the institution is responsible for informing parents or guardians and obtaining any consent required before registering a child in SiMumtaz.

We protect children’s data by:

  • collecting only what the examination and certificate need;
  • not recording a child’s own phone number or email address: we use the parent’s or guardian’s phone number instead;
  • limiting access to the child’s institution, the assigned examiner and authorised Wafa staff; and
  • never showing a child’s date of birth or detailed scores on the public verification page.

Parents or guardians can exercise their child’s rights by contacting us directly or through the institution.

12. Your rights

Under the PDP Law (Articles 5–13) you have the right to:

  • be informed about who processes your data, why and on what basis;
  • access your personal data and obtain a copy;
  • correct or update data that is inaccurate or incomplete, for example a misspelled name on a certificate;
  • end processing, delete or destroy your data, subject to legal exceptions (for example, the record of an issued certificate, which we must keep so it can be verified);
  • withdraw consent where processing is based on consent;
  • object to decisions based solely on automated processing;
  • delay or restrict processing in proportion to its purpose;
  • data portability: receive your data in a commonly used, machine-readable format and have it sent to another controller where technically feasible; and
  • claim compensation for violations in the processing of your personal data, in accordance with the law.

To make a request, email [email protected] with the subject “Privacy Request – SiMumtaz”, stating the participant’s name, institution, NIPS or certificate number if known, your relationship to the participant, and what you would like us to do. Institutions may also forward requests on behalf of their students and teachers. We may need to verify your identity first. We will respond within the time limits set by the PDP Law (for many requests, no later than 3 × 24 hours after we receive a complete and verified request). If we cannot fulfil a request, we will explain why. You may also lodge a complaint with the personal data protection authority in Indonesia.

13. Changes to this policy

We may update this policy when our services or the law change. We will publish the updated version on this page and change the “Last updated” date. For significant changes, we will also inform partner institutions before the changes take effect.

14. Contact us

Wafa Indonesia – Yayasan Syafa’atul Qur’an Indonesia
Jl. Raya Wisma Pagesangan No. 9, Menanggal, Gayungan, Surabaya, East Java 60234, Indonesia
Email: [email protected]
WhatsApp Helpdesk: +62 811-3058-9310
Phone: +62 31 9904 3404
Office hours: Monday–Friday 08.00–16.00 WIB, Saturday 08.00–12.00 WIB

Privacy Policy of Wafa SIFA

Effective date: 5 October 2026  ·  Last updated: 5 October 2026  ·  Applies to: sifa.wafaindonesia.or.id, including the partner registration form and partner certificate links

SIFA (Sistem Informasi Wafa) is Wafa Indonesia’s information system for running our programs. Authorised Wafa staff use it to manage partner institutions (lembaga mitra), foundations (yayasan) and regional Wafa units, our professional staff (trainers, munaqosyah examiners and academy teachers), activities such as trainings and munaqosyah (Quran proficiency examinations), assignments, incentives and the related administration. SIFA also hosts a public form that institutions use to register as Wafa partners.

This Privacy Policy explains what personal data SIFA processes, why, who we share it with, how long we keep it and what rights you have. It is written in line with Law of the Republic of Indonesia No. 27 of 2022 on Personal Data Protection (the “PDP Law”).

At a glance

  • SIFA is used only by authorised Wafa staff. Most people whose data is in SIFA, such as contact persons of partner institutions, professional staff, teachers and students, do not use SIFA themselves.
  • We process the data needed to run our partnerships and programs: institution contacts, professional staff profiles, activity participants, and data about students and teachers received from SiMumtaz.
  • Student data includes data of children. We keep it to a minimum and use it only for Wafa’s learning and certification programs.
  • A professional staff member’s competency level is calculated automatically from their recorded qualifications and influences incentive rates. You can ask for a human review.
  • We share data with Odoo, our accounting system, for invoices and payments, and send WhatsApp messages through Fonnte. We never sell your data.
  • Our servers are located in Singapore.
  • To exercise your rights, contact [email protected].

1. Who we are

SIFA is operated by Yayasan Syafa’atul Qur’an Indonesia (YAQIN), known as Wafa Indonesia (“Wafa”, “we”, “us” or “our”), a foundation established under the laws of the Republic of Indonesia. Wafa Indonesia is the personal data controller for the processing described in this policy. Sign-in to SIFA is provided by the Wafa SSO Portal, which has its own privacy policy.

2. Whose data we process

  • Wafa staff who use SIFA;
  • professional staff (SDM Profesional): trainers, munaqosyah examiners (munaqisy), academy teachers and others assigned to Wafa activities;
  • supporting staff (SDM Pendukung) who help run activities;
  • contact persons (PIC) of partner institutions, foundations, regional Wafa units (Wafa Daerah) and regional partnerships (Kemitraan Daerah);
  • people who fill in the partner registration form, and the people they name in it;
  • students and teachers of partner institutions, and other participants in Wafa activities; and
  • contacts of prospective partners recorded in our accounting system.

3. Personal data we process

Category What it includes Where it comes from
SIFA users Name, email address, phone number, account identifiers, roles and permissions, last sign-in; session records (IP address, browser information). Wafa SSO; you.
Professional staff profile Full name, gender, place and date of birth, phone and WhatsApp numbers, email address, address (province, city, street), employment status (internal, freelance or partner), category, affiliated institution, status (active, inactive, on leave), date joined, notes and Wafa ID. You (directly or through Khidmah); Wafa staff.
Qualifications and competency Fields of expertise and scores, certification dates, Quran memorisation (juz), training-of-trainers certification, education history (level, major, institution, grades, years, certificate numbers and links to proof documents), qualifications, competency levels (jenjang) and their history. You; Wafa staff; calculated by SIFA.
Assignments and incentives Activities and roles assigned to you, days and duration, number of participants, incentive calculations (grade, quantities, amounts and communication allowance) and incentive proposal documents. Wafa staff; calculated by SIFA.
Supporting staff Name, category, phone number, email address, origin institution, bank name, account number and account holder name (to pay incentives), the Wafa contact person responsible and Wafa ID. You; Wafa staff.
Contact persons (PIC) Name, position, phone number, email address, whether you are the primary contact, and Wafa ID, for partner institutions, foundations, regional Wafa units and regional partnerships. The institution; the registration form; Wafa staff.
Partner institutions Institution name, level, address, phone, email, social media accounts, numbers of students and teachers, learning profile and preferences, partnership status history (including the name and position of the person who confirmed a change and any proof files), internal notes and the Wafa unit or person who recommended the institution. The institution; Wafa staff.
Partner registration form Everything entered in the form (institution details and address; name and position of the person registering; name, position, phone and email of the foundation chair, the head of the institution and the Quran coordinator; recommender’s name and contact; social media; notes), plus the IP address, browser information and time of submission, and the outcome of our review. The person submitting the form.
Students Student number (NIS/NISN), full name, gender, place and date of birth, parent or guardian’s name and phone number, status (active, graduated, left, deceased), notes and Wafa ID. Partner institutions, mostly through SiMumtaz.
Teachers of partner institutions Teacher code, employee number (NIP), full name, gender, place and date of birth, phone number, email address, position, status and Wafa ID. Partner institutions, mostly through SiMumtaz.
Activity participants Name, gender, identity number, participant type and notes. Institutions; Wafa staff.
Munaqosyah results Participant name and student number, institution, test type and level, result (pass/fail, predicate, final score), certificate number and dates. SiMumtaz.
Financial and commercial records Activity costs; cost approval workflow (names of staff who proposed, approved or rejected); quotations; invoices; payment receipts (payer’s name, amount, receiving bank account); purchases of Wafa products by institutions. Wafa staff; Odoo.
Prospective partners Name, email address, phone number and address of customers in our accounting system who are not yet linked to a partner institution. Odoo.
Audit and technical data Record of changes (who, what, when, values before and after, IP address); technical logs (time, function called, response status, IP address and an internal user identifier). Generated automatically.

Some of this data is specific personal data under Article 4 of the PDP Law: children’s data and personal financial data (bank accounts and incentive amounts). We give it extra protection and restrict access to staff who need it.

If you give us data about other people, for example the contacts you name in the registration form, please make sure they know about it and about this policy.

4. How we use your data and our legal bases

Purpose Legal basis (PDP Law, Art. 20)
Manage partnerships: register, review and approve institutions; keep contacts, status, preferences and history up to date; issue partner certificates. Fulfilment of an agreement, or steps requested before entering one; legitimate interests.
Process partner registrations, including WhatsApp messages confirming the starter kit delivery address and payment details, and announcing approval with a link to the partner certificate. Steps requested before entering an agreement; fulfilment of an agreement.
Plan and run activities (trainings, munaqosyah, academy programs), including participants and schedules. Fulfilment of an agreement; legitimate interests.
Manage professional and supporting staff: profiles, qualifications, competency levels and assignments. Fulfilment of an agreement (your engagement with Wafa); legitimate interests.
Calculate and pay incentives; prepare incentive and cost proposals; pay into bank accounts. Fulfilment of an agreement; legal obligations (tax and accounting).
Prepare documents (work orders, quotations, invoices, receipts, certificates) and record sales and payments in our accounting system. Fulfilment of an agreement; legal obligations.
Keep records of students, teachers, munaqosyah results and certificates for the services requested by partner institutions. Fulfilment of an agreement with the institution; legitimate interests; for children, the consent of a parent or guardian obtained by the institution.
Register partner certificates so anyone can check that they are genuine. Legitimate interests (preventing forgery).
Assign Wafa IDs and avoid duplicate records of the same person. Legitimate interests.
Reports and dashboards, mostly as aggregated statistics, to plan and improve our programs. Legitimate interests.
Security, audit trails and compliance with the law. Legal obligations; legitimate interests.

We do not use personal data in SIFA for advertising.

5. Automated competency levels

SIFA calculates each professional staff member’s competency level per field (from OJT through ahli) automatically, based on the qualifications recorded in their profile. The level, together with the role in an activity, determines the incentive grade and therefore the incentive rate. If you think your level is wrong, you can ask us to check the qualifications used, correct them and review the result. You also have the right to object to decisions based solely on automated processing (Article 10 of the PDP Law).

6. Who we share your data with

6.1 Within Wafa

  • Authorised Wafa staff, each with access limited to what their role requires.
  • Wafa SSO: links between your account and your SIFA records, and name and contact details for the Wafa ID registry.
  • SiMumtaz: institution and professional staff data needed to run munaqosyah; SiMumtaz in turn sends participants, results and certificates to SIFA.
  • Khidmah: professional staff can see and update their own profile.
  • Wafa Certificate Verification (Sertifikat): when someone checks a partner certificate, it shows the institution’s code, name, region and partnership status.

6.2 Service providers

Provider What they do Data involved Location
Contabo Cloud servers that host SIFA and its database. All data described in this policy. Singapore
Odoo S.A. Cloud accounting and sales system. Names and contact details of partner institutions and foundations (name, email, phone, address, city, postal code); sales orders and invoices for activities; payments; prospective partner details. Odoo’s cloud servers, which may be outside Indonesia
Fonnte Sends WhatsApp messages to people who register an institution (WhatsApp is operated by Meta Platforms). Phone number and message content (institution name, address, partner code, certificate link). Indonesia; delivery through WhatsApp’s global network
Google (Google Fonts) Provides the fonts used on SIFA pages; your browser loads them from Google. IP address and browser information. Global
Api.co.id Provides Indonesia’s public holiday calendar for scheduling. No personal data. Indonesia

6.3 Other disclosures

Partner certificates can be downloaded through a link containing a long, hard-to-guess code, which we send to the institution. Anyone who has the link can download that certificate, so please share it with care. We may also disclose personal data where required by law, a court order or a lawful request from a competent authority, or to protect the rights and safety of Wafa, our partners or the public.

We do not sell, rent or trade personal data.

7. International data transfers

Our servers are located in Singapore, so SIFA data is stored outside Indonesia. Odoo and Google may also process data in other countries. Singapore has a comprehensive data protection law (the Personal Data Protection Act 2012). We transfer personal data outside Indonesia only in accordance with Article 56 of the PDP Law: the destination country provides a level of protection equal to or higher than the PDP Law, or adequate and binding safeguards are in place, or, where neither applies, with your consent.

8. How long we keep your data

Data How long
Professional and supporting staff data While you are engaged with Wafa and up to 5 years after the engagement ends.
Partner institutions, contacts and status history While the partnership is active and up to 5 years after it ends.
Partner registrations Approved registrations become part of the partner record. Rejected or withdrawn registrations are kept for up to 5 years after the decision.
Students, teachers and activity participants As long as needed for our programs and up to 5 years after the person leaves the institution or the partnership ends.
Certificates, certificate numbers and Wafa IDs Permanently, so that certificates remain verifiable.
Financial records (incentives, quotations, invoices, receipts, cost proposals) 10 years, as required by Indonesian accounting, tax and company document laws.
Audit records As long as the related record exists and up to 5 years afterwards.
Sign-in sessions Up to 30 days, or until you sign out.
Technical logs 30 days (performance traces: 7 days).

When the period ends, we delete the data or anonymise it so it can no longer identify you.

9. How we protect your data

  • All connections are encrypted with HTTPS. Sign-in uses the Wafa SSO, and sessions are held in an HttpOnly, Secure cookie.
  • Access is role-based: each staff member can only see and change what their job requires.
  • Changes to important records are kept in an audit trail showing who changed what and when.
  • Communication between Wafa systems is authenticated, digitally signed and runs over internal networks.
  • The public registration form only works through an invitation link and is protected against automated abuse with rate limits and spam protection.

If a personal data breach occurs, we will notify the affected people and the relevant authority in writing no later than 3 × 24 hours, as required by Article 46 of the PDP Law.

10. Cookies and similar technologies

Name Type Purpose Duration
sifa_session Strictly necessary cookie Keeps you signed in to SIFA. Up to 30 days, or until sign-out.
Registration form draft (pendaftaran-mitra-draft:*) Local storage on your device Saves your progress in the partner registration form so you do not lose what you typed. It stays on your device and is not sent to us until you submit. Deleted after submission, or when the invitation link expires (at most 30 days).
Display preferences Local and session storage Remember light/dark mode, sidebar state and scroll position, and the signature options you chose for printed documents. Until you clear browser data (session storage: until you close the tab).
App cache Service worker Stores SIFA’s application files so it loads faster and can be installed on your device. Until updated or removed.

We do not use advertising, analytics or tracking cookies in SIFA. If you use a shared computer, delete the registration form draft by clearing your browser data, or submit the form before leaving.

11. Children’s data

SIFA contains data about students of partner institutions, many of whom are children. Under Article 25 of the PDP Law, processing children’s data requires special care and the consent of a parent or guardian. Students’ data reaches us from their institution, mostly through SiMumtaz, and the institution is responsible for informing parents or guardians and obtaining any consent required before sharing it with us. We collect only what our programs need: we do not record a child’s own phone number or email (we use the parent’s or guardian’s contact instead), access is limited to authorised staff, and the public certificate check never shows a child’s date of birth or detailed scores. Parents or guardians can exercise their child’s rights by contacting us directly or through the institution.

12. Your rights

Under the PDP Law (Articles 5–13) you have the right to:

  • be informed about who processes your data, why and on what basis;
  • access your personal data and obtain a copy;
  • correct or update data that is inaccurate or incomplete;
  • end processing, delete or destroy your data, subject to legal exceptions (for example, financial records we must keep, or certificates that must remain verifiable);
  • withdraw consent where processing is based on consent;
  • object to decisions based solely on automated processing, such as the competency level calculation described in section 5;
  • delay or restrict processing in proportion to its purpose;
  • data portability: receive your data in a commonly used, machine-readable format and have it sent to another controller where technically feasible; and
  • claim compensation for violations in the processing of your personal data, in accordance with the law.

Professional staff can view and update parts of their own profile in the Khidmah app. For anything else, email [email protected] with the subject “Privacy Request – SIFA”, stating your name, how you are connected to Wafa (for example, the institution you represent) and what you would like us to do. We may need to verify your identity first. We will respond within the time limits set by the PDP Law (for many requests, no later than 3 × 24 hours after we receive a complete and verified request). If we cannot fulfil a request, we will explain why. You may also lodge a complaint with the personal data protection authority in Indonesia.

13. Changes to this policy

We may update this policy when our services or the law change. We will publish the updated version on this page and change the “Last updated” date. For significant changes, we will also inform affected users and partners before the changes take effect.

14. Contact us

Wafa Indonesia – Yayasan Syafa’atul Qur’an Indonesia
Jl. Raya Wisma Pagesangan No. 9, Menanggal, Gayungan, Surabaya, East Java 60234, Indonesia
Email: [email protected]
WhatsApp Helpdesk: +62 811-3058-9310
Phone: +62 31 9904 3404
Office hours: Monday–Friday 08.00–16.00 WIB, Saturday 08.00–12.00 WIB

Privacy Policy of Wafa SSO Portal

Effective date: 5 October 2026  ·  Last updated: 5 October 2026  ·  Applies to: sso.wafaindonesia.or.id and auth.wafaindonesia.or.id

The Wafa SSO Portal is the single sign-on service of Wafa Indonesia. With one Wafa Account you sign in once and open the Wafa applications you have access to, such as SIFA, SiMumtaz and Khidmah, without signing in again for each of them.

This Privacy Policy explains what personal data the Wafa SSO Portal processes, why we process it, who we share it with, how long we keep it and what rights you have. It is written in line with Law of the Republic of Indonesia No. 27 of 2022 on Personal Data Protection (the “PDP Law”) and its implementing regulations.

At a glance

  • We use your name, email address and WhatsApp number to create your Wafa Account and to sign you in, either with a password or with a one-time code sent by WhatsApp.
  • Your Wafa Account is linked to a Wafa ID, a permanent personal code used across Wafa applications and printed on Wafa certificates.
  • We share your identity and roles only with the Wafa applications you use and with a small number of service providers that host our systems and deliver our messages. We never sell your data.
  • We record sign-in sessions and important account changes to keep your account safe. You can see and end your own sessions on the My Devices (Perangkat Saya) page.
  • Our servers are located in Singapore.
  • To access, correct or delete your data, or to exercise any other right, contact [email protected].

1. Who we are

The Wafa SSO Portal is operated by Yayasan Syafa’atul Qur’an Indonesia (YAQIN), known as Wafa Indonesia (“Wafa”, “we”, “us” or “our”), a foundation established under the laws of the Republic of Indonesia. For the purposes of the PDP Law, Wafa Indonesia is the personal data controller for the processing described in this policy. Our contact details are in section 14.

2. Scope of this policy

This policy covers personal data processed when you:

  • create or use a Wafa Account, or an account is created for you by a Wafa administrator;
  • sign in to the portal, or to a Wafa application through the portal;
  • recover your password, set or change your password, add an email address or WhatsApp number, or manage your signed-in devices; and
  • are registered in our Wafa ID registry by another Wafa application (this can happen even if you never sign in yourself).

Each Wafa application has its own privacy policy explaining how it uses your data after you sign in (SIFA, SiMumtaz, Khidmah, HRIS and Sertifikat). Some applications, such as HRIS, currently use their own sign-in and are only linked from the portal for convenience.

3. Personal data we process

Category What it includes Where it comes from
Account and identity Full name; email address; WhatsApp/mobile number; password (never stored in plain text); account status (active or deactivated); whether your email address is still a temporary placeholder; whether you have set a password and when it was last changed; date and time of your last sign-in; internal account identifiers. You, or the Wafa administrator who created your account.
Roles and affiliation Your role(s) in the Wafa ecosystem (Central Staff, Trainer, Partner Institution Contact Person or Participant), who assigned them and when. For Wafa staff: employee number, job title and department. Links to your records in other Wafa applications, for example your professional staff (SDM) profile or your position as contact person of a partner institution or foundation, together with the related institution name, code and your position. Wafa administrators; HRIS; SIFA.
Wafa ID registry Your Wafa ID (a code such as W-4827-1935-9) and the name, phone number and email address used to recognise you across applications. If two records turn out to belong to the same person, we keep a history of the merge: who merged them, when and why. You; SIFA, SiMumtaz and HRIS, which register people to obtain a Wafa ID.
Verification and security data One-time codes; password-reset and invitation links; counters that limit repeated attempts (linked to the email/number entered and to your IP address); sign-in session records (session identifier, IP address, browser and device information, time of sign-in and last activity); markers used to end or refresh sessions. Generated when you use the service.
Audit records Important actions on accounts, such as creating or updating an account, assigning or removing roles, deactivating or reactivating an account, adding an email address or phone number and administrator support access, including who performed the action, when, what changed and the IP address. Generated automatically.
Technical logs Time of the request, the page or function called (without URL parameters), response status, duration, IP address and an internal user identifier. We deliberately do not record your name, email address or URL query strings in these logs. Generated automatically.

The SSO Portal does not ask for specific (sensitive) personal data such as health, biometric or financial data.

4. How we use your data and our legal bases

Under Article 20 of the PDP Law we may only process personal data on a lawful basis. The table below shows each purpose and the basis we rely on.

Purpose Legal basis
Create and administer your Wafa Account; sign you in to the portal and to Wafa applications, and sign you out of all of them at once. Fulfilment of an agreement or service requested by you, your employer or your institution; our legitimate interests.
Give Wafa applications your identity, roles and Wafa ID so they can grant you the right access. Fulfilment of an agreement; legitimate interests.
Assign and maintain a Wafa ID so each person is recorded only once across applications and certificates remain verifiable. Legitimate interests.
Send one-time codes and security notifications by WhatsApp, and password-reset links, invitations and verification codes by email. Fulfilment of an agreement; legitimate interests (account security).
Protect accounts: limit attempts, detect misuse, manage and end sessions, keep audit records. Legal obligations as an electronic system operator; legitimate interests.
Provide support and fix problems. Legitimate interests.
Comply with the law and respond to lawful requests from authorities. Legal obligations.

Where we rely on legitimate interests, we have weighed them against your interests and rights. We do not use your data for advertising, and we do not make decisions about you based solely on automated processing that have legal or similarly significant effects.

5. How sign-in and verification work

  • Password sign-in. You enter your email address or WhatsApp number and your password. The password is checked by our identity service, which we host ourselves using the open-source Zitadel software.
  • WhatsApp one-time code. We send a 6-digit code to the WhatsApp number registered to your account. The code is valid for 5 minutes and can be tried at most 5 times. Requests are limited per number/email and per IP address.
  • Protection against account discovery. The portal answers in the same way whether or not an email address or number is registered, so others cannot use it to find out who has an account.
  • Forgotten password. For accounts with an email address, we email a reset link that is valid for 15 minutes. After a reset, your other portal sessions are signed out.
  • Adding an email address. We email a verification code (valid for 10 minutes) to the new address, and send a WhatsApp notification to your registered number, with the email address partly hidden, so you will know if someone else did it.
  • Adding a WhatsApp number. We send a verification code (valid for 5 minutes) to the new number by WhatsApp.
  • My Devices. You can see where your account is signed in (browser and device, IP address, last activity) and sign out any session. Changing your password signs out your other sessions.
  • Single sign-out. When you sign out of one Wafa application, we end your portal session and notify the other Wafa applications so they end your sessions as well. When an administrator deactivates your account or changes your roles, your sessions are ended or refreshed so the change takes effect quickly.
  • Administrator access for support. In exceptional cases, such as technical support or investigating a problem, a small number of authorised administrators can open a session for an account through a tightly restricted mechanism. Every such access is recorded in the audit log.

6. Who we share your data with

6.1 Wafa applications

When you sign in, or when an application needs to refresh your access rights, we share your name, email address, WhatsApp number, Wafa ID, roles, job title and department (for staff) and links to your profiles with the Wafa application concerned (SIFA, SiMumtaz or Khidmah). HRIS, SIFA and SiMumtaz also use the Wafa ID registry to look up or create Wafa IDs. Each application uses this data as described in its own privacy policy.

6.2 Service providers

We use the following providers to run the service. They process data on our behalf and only for the purposes below.

Provider What they do Data involved Location
Contabo Cloud servers that host the portal, our identity service and databases. All data described in this policy. Singapore
Fonnte or Api.co.id (Chat Gateway, an official WhatsApp Business Solution Provider) Deliver one-time codes and security notifications through WhatsApp, which is operated by Meta Platforms. Your WhatsApp number and the message content. Indonesia; delivery through WhatsApp’s global network
Brevo (Sendinblue SAS) Deliver emails: password resets, invitations and email verification codes. Your email address and the email content. European Union (France)
Cloudinary Hosts the preview images of Wafa applications shown on the portal. Your browser loads them directly. Your IP address and browser information only. No account data. Global content delivery network

6.3 Legal requirements

We may disclose personal data where required by law, a court order or a lawful request from a competent authority, or where necessary to protect the rights, property or safety of Wafa, our users or the public.

We do not sell, rent or trade personal data.

7. International data transfers

Our servers are located in Singapore, so data processed by the SSO Portal is stored outside Indonesia. Some service providers, such as Brevo (European Union) and Cloudinary (global network), may also process data in other countries. Singapore (Personal Data Protection Act 2012) and the European Union (General Data Protection Regulation) have comprehensive data protection laws. We transfer personal data outside Indonesia only in accordance with Article 56 of the PDP Law: the destination country provides a level of protection equal to or higher than the PDP Law, or adequate and binding safeguards are in place, or, where neither applies, with your consent.

8. How long we keep your data

Data How long
Account, roles and profile links While your account is active. After your account is deactivated or your relationship with Wafa ends, up to 5 years, after which we delete or anonymise it, unless the law requires a longer period.
Wafa ID Permanently. A Wafa ID is never reused or deleted because it appears on certificates that must remain verifiable. If you ask us to erase your data, we remove or anonymise contact details we no longer need and keep only the minimum record needed to verify documents already issued to you.
One-time and verification codes 5 minutes (10 minutes for email verification codes), or until used.
Password-reset and invitation links 15 minutes, or until used.
Attempt counters Up to 24 hours.
Portal sessions Until you sign out or the session is ended; automatically after 30 days without activity, and no later than 90 days after sign-in.
Audit records As long as the account exists and up to 5 years afterwards.
Technical logs 30 days (performance traces: 7 days).

9. How we protect your data

  • All connections to the portal and identity service are encrypted with HTTPS.
  • Passwords are never stored in plain text; they are protected with strong cryptography. Secrets used between Wafa systems are stored encrypted.
  • Sign-in is protected by attempt limits, cooldown periods, rate limiting by number/email and IP address, and uniform responses that prevent account discovery.
  • The session cookie is HttpOnly and Secure, so it cannot be read by scripts on the page. Sessions can be listed and ended at any time.
  • Communication between Wafa systems is authenticated, digitally signed and runs over internal networks.
  • Only authorised central staff can manage accounts and roles, and their actions are recorded in the audit log.
  • Our logs are kept to the minimum needed to run and secure the service.

If a personal data breach occurs, we will notify you and the relevant authority in writing no later than 3 × 24 hours, as required by Article 46 of the PDP Law. No system is completely secure, so please keep your password and one-time codes to yourself. Wafa staff will never ask you for them.

10. Cookies and similar technologies

Name Type Purpose Duration
sso_token Strictly necessary cookie Keeps you signed in to the portal and lets Wafa applications sign you in without asking for your credentials again. Until sign-out; at most 90 days, and invalid after 30 days of inactivity.
theme Local storage (preference) Remembers whether you prefer light or dark mode. Until you clear your browser data.

Our identity service at auth.wafaindonesia.or.id may also use strictly necessary cookies during sign-in. We do not use advertising, analytics or tracking cookies, and the portal’s fonts are served from our own servers. You can block or delete cookies in your browser, but without the session cookie the portal cannot keep you signed in.

11. Children

Wafa Accounts are intended for adults: Wafa staff, trainers, representatives of partner institutions and other adult participants. We do not knowingly create sign-in accounts for children without the involvement of a parent or guardian. The Wafa ID registry may contain records of children, for example students who take a munaqosyah examination, created by SiMumtaz or SIFA so that a Wafa ID can be printed on their certificates. These records cannot be used to sign in and are handled as described in the SiMumtaz and SIFA privacy policies, in line with Article 25 of the PDP Law.

12. Your rights

Under the PDP Law (Articles 5–13) you have the right to:

  • be informed about who processes your data, why and on what basis;
  • access your personal data and obtain a copy;
  • correct or update data that is inaccurate or incomplete;
  • end processing, delete or destroy your data, subject to legal exceptions (for example, records we must keep by law, or the minimum record needed to keep certificates verifiable);
  • withdraw consent where processing is based on consent;
  • object to decisions based solely on automated processing, including profiling, that have legal or similarly significant effects on you;
  • delay or restrict processing in proportion to its purpose;
  • data portability: receive your data in a commonly used, machine-readable format and have it sent to another controller where technically feasible; and
  • claim compensation for violations in the processing of your personal data, in accordance with the law.

What you can do yourself: view and end your sessions on My Devices, set or change your password, and add an email address or WhatsApp number. To change or remove an existing email address or number, or for any other request, please contact us.

How to make a request: email [email protected] with the subject “Privacy Request – Wafa SSO Portal”, stating your name, the email address or number on your account, your Wafa ID if you know it, and what you would like us to do. We may need to verify your identity first. We will respond within the time limits set by the PDP Law (for many requests, no later than 3 × 24 hours after we receive a complete and verified request). If we cannot fulfil a request, for example because the law requires us to keep the data, we will explain why.

If you are not satisfied with our response, you may lodge a complaint with the personal data protection authority in Indonesia.

13. Changes to this policy

We may update this policy when our services or the law change. We will publish the updated version on this page and change the “Last updated” date. For significant changes, we will also notify you through the portal, WhatsApp or email before the changes take effect.

14. Contact us

Wafa Indonesia – Yayasan Syafa’atul Qur’an Indonesia
Jl. Raya Wisma Pagesangan No. 9, Menanggal, Gayungan, Surabaya, East Java 60234, Indonesia
Email: [email protected]
WhatsApp Helpdesk: +62 811-3058-9310
Phone: +62 31 9904 3404
Office hours: Monday–Friday 08.00–16.00 WIB, Saturday 08.00–12.00 WIB

Privacy Policy of Wafa Tilawah 5

Privacy Policy of Wafa Tilawah 5

Wafa Indonesia operates Wafa Tilawah 5 app, which provides the SERVICE.

This page is used to inform visitors regarding our policies with the collection, use, and disclosure of Personal Information if anyone decided to use our Service, Wafa Tilawah 5 app.

If you choose to use our Service, then you agree to the collection and use of information in relation with this policy. The Personal Information that we collect are used for providing and improving the Service. We will not use or share your information with anyone except as described in this Privacy Policy.

The terms used in this Privacy Policy have the same meanings as in our Terms and Conditions, which is accessible at Wafa Tilawah 5 app, unless otherwise defined in this Privacy Policy.

Information Collection and Use

For a better experience, while using our Service, we may require you to provide us with certain personally identifiable information. The information that we request will be retained by us and used as described in this privacy policy.

The app does use third-party services that may collect information used to identify you.

Link to the privacy policy of third-party service providers used by the app

Log Data

Collection of Personal Data:

Our app “Wafa Tilawah 5” does not collect any personal data from our users. We do not collect any personally identifiable information such as name, email address, phone number, or location.

Non-Personal Data Collection:

We may collect non-personal data such as device type, operating system, game progress, and game settings. This data is collected solely to improve the gaming experience and is not shared with any third-party entities. In a case of an error in the app we collect data and information (through third-party products) on your phone called Log Data. This Log Data may include information such as your device Internet Protocol (“IP”) address, device name, operating system version, the configuration of the app when utilizing our Service, the time and date of your use of the Service, and other statistics.

Use of Data:

The non-personal data we collect is used solely for the purpose of enhancing the game experience. We do not share any data with third parties or use it for any other purpose.

Cookies

Cookies are files with small amount of data that is commonly used an anonymous unique identifier. These are sent to your browser from the website that you visit and are stored on your computer’s hard drive.

Our Services uses these “cookies” to collection information and to improve our Service. You have the option to either accept or refuse these cookies, and know when a cookie is being sent to your computer. If you choose to refuse our cookies, you may not be able to use some portions of our Service.

Service Providers

We may employ third-party companies and individuals due to the following reasons:

  • To facilitate our Service;
  • To provide the Service on our behalf;
  • To perform Service-related services; or
  • To assist us in analyzing how our Service is used.

We want to inform our Service users that these third parties have access to your Personal Information. The reason is to perform the tasks assigned to them on our behalf. However, they are obligated not to disclose or use the information for any other purpose.

Security

We value your trust in providing us your Personal Information, thus we are striving to use commercially acceptable means of protecting it. But remember that no method of transmission over the internet, or method of electronic storage is 100% secure and reliable, and we cannot guarantee its absolute security.

Links to Other Sites

Our Service may contain links to other sites. If you click on a third-party link, you will be directed to that site. Note that these external sites are not operated by us. Therefore, we strongly advise you to review the Privacy Policy of these websites. We have no control over, and assume no responsibility for the content, privacy policies, or practices of any third-party sites or services.

Children’s Privacy

We are committed to protecting the privacy of children who use our app. This privacy policy explains how we collect, use, and protect personal information from children under the age of of 13.

No Information Collection:

Our app does not collect any information from children, such as name, address, phone number, or email address. We do not track or store any information about the children who use our app.

Parental Consent:

We do not require any information from children to use our app. However, we encourage parents or legal guardians to monitor and supervise their children’s use of our app. If we ever plan to collect personal information from children in the future, we will seek parental consent beforehand.

Changes to This Privacy Policy

We may update our Privacy Policy from time to time. Thus, we advise you to review this page periodically for any changes. We will notify you of any changes by posting the new Privacy Policy on this page. These changes are effective immediately, after they are posted on this page.

This policy is effective as of 2023-10-18

Contact Us

If you have any questions or suggestions about our Privacy Policy, do not hesitate to contact us at [email protected]

Privacy Policy of Wafa Tilawah 4

Privacy Policy of Wafa Tilawah 4

Wafa Indonesia operates Wafa Tilawah 4 app, which provides the SERVICE.

This page is used to inform visitors regarding our policies with the collection, use, and disclosure of Personal Information if anyone decided to use our Service, Wafa Tilawah 4 app.

If you choose to use our Service, then you agree to the collection and use of information in relation with this policy. The Personal Information that we collect are used for providing and improving the Service. We will not use or share your information with anyone except as described in this Privacy Policy.

The terms used in this Privacy Policy have the same meanings as in our Terms and Conditions, which is accessible at Wafa Tilawah 4 app, unless otherwise defined in this Privacy Policy.

Information Collection and Use

For a better experience, while using our Service, we may require you to provide us with certain personally identifiable information. The information that we request will be retained by us and used as described in this privacy policy.

The app does use third-party services that may collect information used to identify you.

Link to the privacy policy of third-party service providers used by the app

Log Data

Collection of Personal Data:

Our app “Wafa Tilawah 4” does not collect any personal data from our users. We do not collect any personally identifiable information such as name, email address, phone number, or location.

Non-Personal Data Collection:

We may collect non-personal data such as device type, operating system, game progress, and game settings. This data is collected solely to improve the gaming experience and is not shared with any third-party entities. In a case of an error in the app we collect data and information (through third-party products) on your phone called Log Data. This Log Data may include information such as your device Internet Protocol (“IP”) address, device name, operating system version, the configuration of the app when utilizing our Service, the time and date of your use of the Service, and other statistics.

Use of Data:

The non-personal data we collect is used solely for the purpose of enhancing the game experience. We do not share any data with third parties or use it for any other purpose.

Cookies

Cookies are files with small amount of data that is commonly used an anonymous unique identifier. These are sent to your browser from the website that you visit and are stored on your computer’s hard drive.

Our Services uses these “cookies” to collection information and to improve our Service. You have the option to either accept or refuse these cookies, and know when a cookie is being sent to your computer. If you choose to refuse our cookies, you may not be able to use some portions of our Service.

Service Providers

We may employ third-party companies and individuals due to the following reasons:

  • To facilitate our Service;
  • To provide the Service on our behalf;
  • To perform Service-related services; or
  • To assist us in analyzing how our Service is used.

We want to inform our Service users that these third parties have access to your Personal Information. The reason is to perform the tasks assigned to them on our behalf. However, they are obligated not to disclose or use the information for any other purpose.

Security

We value your trust in providing us your Personal Information, thus we are striving to use commercially acceptable means of protecting it. But remember that no method of transmission over the internet, or method of electronic storage is 100% secure and reliable, and we cannot guarantee its absolute security.

Links to Other Sites

Our Service may contain links to other sites. If you click on a third-party link, you will be directed to that site. Note that these external sites are not operated by us. Therefore, we strongly advise you to review the Privacy Policy of these websites. We have no control over, and assume no responsibility for the content, privacy policies, or practices of any third-party sites or services.

Children’s Privacy

We are committed to protecting the privacy of children who use our app. This privacy policy explains how we collect, use, and protect personal information from children under the age of of 13.

No Information Collection:

Our app does not collect any information from children, such as name, address, phone number, or email address. We do not track or store any information about the children who use our app.

Parental Consent:

We do not require any information from children to use our app. However, we encourage parents or legal guardians to monitor and supervise their children’s use of our app. If we ever plan to collect personal information from children in the future, we will seek parental consent beforehand.

Changes to This Privacy Policy

We may update our Privacy Policy from time to time. Thus, we advise you to review this page periodically for any changes. We will notify you of any changes by posting the new Privacy Policy on this page. These changes are effective immediately, after they are posted on this page.

This policy is effective as of 2023-10-18

Contact Us

If you have any questions or suggestions about our Privacy Policy, do not hesitate to contact us at [email protected]

Privacy Policy of Wafa Tilawah 3

Privacy Policy of Wafa Tilawah 3

Wafa Indonesia operates Wafa Tilawah 3 app, which provides the SERVICE.

This page is used to inform visitors regarding our policies with the collection, use, and disclosure of Personal Information if anyone decided to use our Service, Wafa Tilawah 3 app.

If you choose to use our Service, then you agree to the collection and use of information in relation with this policy. The Personal Information that we collect are used for providing and improving the Service. We will not use or share your information with anyone except as described in this Privacy Policy.

The terms used in this Privacy Policy have the same meanings as in our Terms and Conditions, which is accessible at Wafa Tilawah 3 app, unless otherwise defined in this Privacy Policy.

Information Collection and Use

For a better experience, while using our Service, we may require you to provide us with certain personally identifiable information. The information that we request will be retained by us and used as described in this privacy policy.

The app does use third-party services that may collect information used to identify you.

Link to the privacy policy of third-party service providers used by the app

Log Data

Collection of Personal Data:

Our app “Wafa Tilawah 3” does not collect any personal data from our users. We do not collect any personally identifiable information such as name, email address, phone number, or location.

Non-Personal Data Collection:

We may collect non-personal data such as device type, operating system, game progress, and game settings. This data is collected solely to improve the gaming experience and is not shared with any third-party entities. In a case of an error in the app we collect data and information (through third-party products) on your phone called Log Data. This Log Data may include information such as your device Internet Protocol (“IP”) address, device name, operating system version, the configuration of the app when utilizing our Service, the time and date of your use of the Service, and other statistics.

Use of Data:

The non-personal data we collect is used solely for the purpose of enhancing the game experience. We do not share any data with third parties or use it for any other purpose.

Cookies

Cookies are files with small amount of data that is commonly used an anonymous unique identifier. These are sent to your browser from the website that you visit and are stored on your computer’s hard drive.

Our Services uses these “cookies” to collection information and to improve our Service. You have the option to either accept or refuse these cookies, and know when a cookie is being sent to your computer. If you choose to refuse our cookies, you may not be able to use some portions of our Service.

Service Providers

We may employ third-party companies and individuals due to the following reasons:

  • To facilitate our Service;
  • To provide the Service on our behalf;
  • To perform Service-related services; or
  • To assist us in analyzing how our Service is used.

We want to inform our Service users that these third parties have access to your Personal Information. The reason is to perform the tasks assigned to them on our behalf. However, they are obligated not to disclose or use the information for any other purpose.

Security

We value your trust in providing us your Personal Information, thus we are striving to use commercially acceptable means of protecting it. But remember that no method of transmission over the internet, or method of electronic storage is 100% secure and reliable, and we cannot guarantee its absolute security.

Links to Other Sites

Our Service may contain links to other sites. If you click on a third-party link, you will be directed to that site. Note that these external sites are not operated by us. Therefore, we strongly advise you to review the Privacy Policy of these websites. We have no control over, and assume no responsibility for the content, privacy policies, or practices of any third-party sites or services.

Children’s Privacy

We are committed to protecting the privacy of children who use our app. This privacy policy explains how we collect, use, and protect personal information from children under the age of of 13.

No Information Collection:

Our app does not collect any information from children, such as name, address, phone number, or email address. We do not track or store any information about the children who use our app.

Parental Consent:

We do not require any information from children to use our app. However, we encourage parents or legal guardians to monitor and supervise their children’s use of our app. If we ever plan to collect personal information from children in the future, we will seek parental consent beforehand.

Changes to This Privacy Policy

We may update our Privacy Policy from time to time. Thus, we advise you to review this page periodically for any changes. We will notify you of any changes by posting the new Privacy Policy on this page. These changes are effective immediately, after they are posted on this page.

This policy is effective as of 2023-10-18

Contact Us

If you have any questions or suggestions about our Privacy Policy, do not hesitate to contact us at [email protected]

Privacy Policy of Wafa Tilawah 2

Privacy Policy of Wafa Tilawah 2

Wafa Indonesia operates Wafa Tilawah 2 app, which provides the SERVICE.

This page is used to inform visitors regarding our policies with the collection, use, and disclosure of Personal Information if anyone decided to use our Service, Wafa Tilawah 2 app.

If you choose to use our Service, then you agree to the collection and use of information in relation with this policy. The Personal Information that we collect are used for providing and improving the Service. We will not use or share your information with anyone except as described in this Privacy Policy.

The terms used in this Privacy Policy have the same meanings as in our Terms and Conditions, which is accessible at Wafa Tilawah 2 app, unless otherwise defined in this Privacy Policy.

Information Collection and Use

For a better experience, while using our Service, we may require you to provide us with certain personally identifiable information. The information that we request will be retained by us and used as described in this privacy policy.

The app does use third-party services that may collect information used to identify you.

Link to the privacy policy of third-party service providers used by the app

Log Data

Collection of Personal Data:

Our app “Wafa Tilawah 2” does not collect any personal data from our users. We do not collect any personally identifiable information such as name, email address, phone number, or location.

Non-Personal Data Collection:

We may collect non-personal data such as device type, operating system, game progress, and game settings. This data is collected solely to improve the gaming experience and is not shared with any third-party entities. In a case of an error in the app we collect data and information (through third-party products) on your phone called Log Data. This Log Data may include information such as your device Internet Protocol (“IP”) address, device name, operating system version, the configuration of the app when utilizing our Service, the time and date of your use of the Service, and other statistics.

Use of Data:

The non-personal data we collect is used solely for the purpose of enhancing the game experience. We do not share any data with third parties or use it for any other purpose.

Cookies

Cookies are files with small amount of data that is commonly used an anonymous unique identifier. These are sent to your browser from the website that you visit and are stored on your computer’s hard drive.

Our Services uses these “cookies” to collection information and to improve our Service. You have the option to either accept or refuse these cookies, and know when a cookie is being sent to your computer. If you choose to refuse our cookies, you may not be able to use some portions of our Service.

Service Providers

We may employ third-party companies and individuals due to the following reasons:

  • To facilitate our Service;
  • To provide the Service on our behalf;
  • To perform Service-related services; or
  • To assist us in analyzing how our Service is used.

We want to inform our Service users that these third parties have access to your Personal Information. The reason is to perform the tasks assigned to them on our behalf. However, they are obligated not to disclose or use the information for any other purpose.

Security

We value your trust in providing us your Personal Information, thus we are striving to use commercially acceptable means of protecting it. But remember that no method of transmission over the internet, or method of electronic storage is 100% secure and reliable, and we cannot guarantee its absolute security.

Links to Other Sites

Our Service may contain links to other sites. If you click on a third-party link, you will be directed to that site. Note that these external sites are not operated by us. Therefore, we strongly advise you to review the Privacy Policy of these websites. We have no control over, and assume no responsibility for the content, privacy policies, or practices of any third-party sites or services.

Children’s Privacy

We are committed to protecting the privacy of children who use our app. This privacy policy explains how we collect, use, and protect personal information from children under the age of of 13.

No Information Collection:

Our app does not collect any information from children, such as name, address, phone number, or email address. We do not track or store any information about the children who use our app.

Parental Consent:

We do not require any information from children to use our app. However, we encourage parents or legal guardians to monitor and supervise their children’s use of our app. If we ever plan to collect personal information from children in the future, we will seek parental consent beforehand.

Changes to This Privacy Policy

We may update our Privacy Policy from time to time. Thus, we advise you to review this page periodically for any changes. We will notify you of any changes by posting the new Privacy Policy on this page. These changes are effective immediately, after they are posted on this page.

This policy is effective as of 2023-10-18

Contact Us

If you have any questions or suggestions about our Privacy Policy, do not hesitate to contact us at [email protected]