Effective and last updated: August 30, 2026

Privacy Policy

This policy explains how Wafinix collects, uses, stores, shares, and protects personal data when you use our website or communicate with us.

If an agreed proposal, Statement of Work (SOW), SLA, or specific contract differs from these general documents, the specific document will prevail.

1. Data controller and scope

Wafinix manages personal data collected through wafinix.com, order and consultation forms, email, WhatsApp, and project communications. This processing is designed with regard to Indonesia's Law No. 27 of 2022 on Personal Data Protection, Government Regulation No. 71 of 2019 on Electronic Systems and Transactions, and applicable Electronic Information and Transactions rules.

This policy does not govern client-owned websites or systems we build; their operators are responsible for their own privacy notices unless Wafinix is specifically appointed as a processor by contract.

2. Data we collect

The data depends on your interaction, and we aim to request only what is relevant.

  • Identity and contact data: name, email, WhatsApp number, company, role, and communication language.
  • Request information: package interest, budget, target timing, requirements, features, materials, notes, and communication history.
  • Project and transaction data: proposals, approvals, invoices, payment status, contracts, granted access, and support records.
  • Limited technical data: pages viewed, locale, device, referring source, access time, user-agent, and a daily hashed visitor identifier.
  • Other information you choose to provide. Please avoid submitting unnecessary sensitive data.

3. How data is collected

We receive data directly when you complete a form, contact us, approve documents, make a payment, or use a service. Technical data is generated automatically when the website is accessed. We may also receive data from your employer, a referral partner, a payment provider, or a service you connect with your knowledge.

4. Purposes and legal bases

We process data to answer consultations, prepare proposals, perform contracts, build and support products, administer payments, maintain security, prevent misuse, understand website performance, comply with legal obligations, and establish or defend legal rights.

The legal basis may be consent, pre-contract steps, contract performance, legal obligations, or proportionate legitimate interests. Where processing relies on consent, you may withdraw it without affecting earlier lawful processing.

5. Analytics, cookies, and technical logs

Wafinix uses first-party analytics to count visits and understand page usage. An IP address may be processed momentarily by the server for security and to create a visitor hash with a salt that changes daily, but the raw IP address is not stored in the analytics table. The daily hash is not designed to identify you across days.

The public website currently does not use advertising cookies or cross-site trackers. A necessary session cookie is used in the restricted admin area. If we add non-essential cookies or analytics, we will update this policy and provide consent controls where required.

6. Payments

Website prices are estimates and the order form does not immediately process payment. After agreement, payment may be made through a bank or payment provider named on the invoice. That provider handles data under its own privacy policy. Wafinix retains necessary transaction records but does not store complete card numbers or payment credentials.

7. Who may receive data

We do not sell or rent personal data. Data is shared only as needed with:

  • Personnel, developers, or project partners who need access and are subject to confidentiality obligations.
  • Hosting, database, email, communications, domain, cloud, analytics, and security providers supporting operations.
  • Banks or payment providers processing and reconciling transactions.
  • Professional advisers, auditors, or authorities where needed for law, security, disputes, or rights protection.
  • A party to a business restructuring, subject to appropriate safeguards and notice.

8. External services and international transfers

If you choose to open WhatsApp, LinkedIn, Instagram, a payment provider, or another external link, that provider will receive technical data and information you submit under its own policy. Some cloud or communications providers may process data outside Indonesia. Wafinix will use reasonable providers and apply protections required by law for cross-border transfers.

9. Retention

Data is retained only as long as needed for its collection purpose. Consultation requests or leads that do not proceed are generally retained for up to 24 months after the last interaction so we can follow up and understand request history. Project, contract, transaction, and invoice data is kept during the relationship and for periods required for accounting, tax, audit, disputes, or legal duties.

Detailed analytics is generally reviewed for deletion or aggregation after 12 months. Data may be deleted sooner following a valid request or kept longer where required for law, disputes, security, or with your consent.

10. Data security

We use proportionate technical and organizational measures, including access restrictions, admin authentication, secure connections where available, dependency updates, operational records, service-specific backups, and keeping secrets outside public code. Access is granted on a need-to-work basis.

No system is completely risk-free. You are also responsible for securing your devices, accounts, and credentials and promptly notifying us of suspected misuse.

11. Your rights

Subject to applicable law, you may request information about processing, access or a copy, correction, updating, deletion, cessation or restriction of processing, withdrawal of consent, objection to automated decisions, and other rights granted by data-protection rules.

Send requests to habibwafi96@gmail.com. We may verify identity and cannot fulfill a request that conflicts with legal duties, third-party rights, security, or the need to establish or defend claims.

12. Children's data

Wafinix services are intended for businesses and persons able to enter agreements, not for children submitting data without supervision. If you learn that a child's data was provided without required authorization, contact us so it can be reviewed and deleted as required by law.

13. Personal-data incidents

If a personal-data protection failure triggers a notification duty, Wafinix will take containment measures and notify affected parties and authorities within the time and with the information required by law. For data in client systems, incident responsibilities follow the parties' roles and project contract.

14. Changes and contact

This policy may be updated because of changes in services, technology, or regulation. Material changes will be shown here with a revised date and, where required, communicated through an appropriate channel.

For privacy questions or data-rights requests, contact habibwafi96@gmail.com or WhatsApp +62 813-8446-7988.

Back to home