Privacy Policy
Last updated: 11 August 2026
1. Who we are and what this covers
This policy is issued by PT WELLOPZ TEKNOLOGI SOLUSINDO, of KOMP BALOI MAS GARDEN BLOK J NO 6, Baloi Indah, Lubuk Baja, Batam, Kepulauan Riau, 29432, Indonesia("we", "us"), which operates the WellOpz platform. It explains how we handle personal data under Indonesia's Personal Data Protection Law (Law No. 27 of 2022, "UU PDP").
WellOpz is software used by fitness and wellness venues to run their businesses. Two different relationships are covered here, and the difference affects who you should contact about your data:
- Venues and their staff. When a venue subscribes to WellOpz, we are the data controller for that business relationship.
- Venue customers. When you book a class or buy a membership from a venue, that venue decides what to collect about you and why. The venue is the controller and we act as its processor. We are separately the controller for the limited data needed to run the platform itself, such as your login credentials and payment records.
If you are a venue customer and want data corrected or deleted, contact your venue first. If they cannot help, contact us at [email protected] and we will assist.
2. What we collect
We collect only what the platform needs in order to work.
- Account data: name, email address, and password, stored only as a cryptographic hash and never in readable form.
- Venue business data: legal entity name, registered address, tax identifier, and business contact details.
- Customer profile data entered by you or your venue: phone number, date of birth, gender, address, and notes a venue keeps about your membership.
- Activity data: bookings, class attendance, check-ins, and membership or credit balances.
- Payment records: amount, currency, the plan or package purchased, and the payment status returned by our payment processor.
- Consent records: when you authorise a payment we record the date and time, your IP address, your browser identifier, and the exact wording shown to you. We are required to keep this so a disputed charge can be defended.
- Documents you sign: where a venue uses waivers or health declarations, the completed document and any signature image.
We never see or store your card number. Card details are entered on a payment page hosted by Xendit and never reach our systems.
Date of birth, and any health information a venue asks you to provide, are specific personal data under UU PDP. We process these only where the venue has a lawful basis to collect them, and we apply the controls described in section 6.
3. Why we process it, and on what basis
| Purpose | Lawful basis |
|---|---|
| Providing bookings, memberships and credits | Performance of a contract with you |
| Taking and settling payments | Performance of a contract; legal obligation |
| Sending booking, receipt and renewal notices | Performance of a contract |
| Recurring payment authorisation and consent records | Your consent; our legitimate interest in defending disputes |
| Keeping invoices and transaction records | Legal obligation under tax and accounting rules |
| Security, fraud prevention and abuse investigation | Legitimate interest |
| Health or waiver information | Your explicit consent, given to the venue |
We do not use your personal data for advertising, and we do not sell it or share it with data brokers.
4. Who we share it with
We share personal data only with the providers needed to operate the platform, and only the data each one requires:
| Provider | Purpose | Data shared |
|---|---|---|
| Xendit (PT Sinar Digital Terdepan) | Payment processing | Name, email, phone number, transaction amount and reference |
| Cloudflare R2 | File and image storage | Uploaded images and signed documents |
| Resend, or our configured email provider | Transactional email delivery | Name, email address, and message contents |
| Cloudflare | Network delivery, TLS termination and protection against attack | Traffic metadata such as IP address, browser identifier and request details |
We also disclose data where legally required, for example in response to a valid order from a court or authority.
Xendit processes payment data as an independent controller under its own privacy policy and terms, and is licensed and supervised by Bank Indonesia.
5. Transfers outside Indonesia
Some providers operate infrastructure outside Indonesia, so your personal data may be processed abroad. Where that happens we rely on UU PDP Article 56: we confirm the destination country offers an adequate level of protection, or we put contractual safeguards in place with the provider, or we obtain your consent.
You can ask us for details of the safeguards applying to a particular transfer by contacting [email protected].
6. How we protect it
- All traffic is encrypted in transit using TLS.
- Passwords are stored only as salted cryptographic hashes.
- Card details never reach our systems; payment pages are hosted by Xendit, which is certified to the Payment Card Industry Data Security Standard.
- Each venue's data is isolated, and access is limited by role so staff see only what their role requires.
- Access to production systems is restricted to personnel who need it.
No system is perfectly secure and we cannot guarantee absolute security. UU PDP Article 46 requires the data controller to notify affected people and the supervisory institution in writing within 3×24 hours of becoming aware of a personal data breach.
Where we are the controller — your account and payment data — we make that notification ourselves. Where your venue is the controller, we alert the venue without delay so it can meet its own deadline, and we support it in doing so.
7. How long we keep it
We keep personal data for as long as it is needed for the purposes described in section 3, and for as long as we are required to keep it by Indonesian law — in particular tax and company record-keeping rules, which oblige us to retain financial records for a period set by that legislation.
| Data | How long |
|---|---|
| Account and profile data | While the account is open. You may ask us to delete it, and we will do so as quickly as we reasonably can, unless we are legally required to keep it |
| Bookings and attendance | While your venue needs it to run its business and to evidence services delivered. Your venue decides this, as controller of that data |
| Invoices, receipts and transaction records | For the period Indonesian tax and company record-keeping law requires. We cannot delete these earlier, even on request |
| Payment authorisation and consent records | With the transaction they authorise, so a disputed charge can be defended |
| Signed waivers and health declarations | As set by your venue, and while a related claim could still be brought |
We do not currently run automated deletion on a fixed schedule. Data is deleted when you ask us to and we have no legal reason to keep it, or when we no longer need it for the purpose it was collected for. If you want to know what we hold about you or want it removed, contact [email protected] and we will tell you what we can and cannot delete, and why.
8. Your rights
UU PDP gives you the following rights:
- Information about who is processing your data, on what legal basis, and for what purpose.
- Accessto your personal data and a copy of it — we respond within 3×24 hours.
- Correctionof data that is wrong, incomplete or out of date — within 3×24 hours.
- Deletion or destruction of your data, and to end processing of it. UU PDP does not set a fixed deadline for this one; we act within a reasonable time.
- Withdrawal of consent, where we relied on your consent — we stop that processing within 3×24 hours.
- Restriction— asking us to suspend or limit processing — within 3×24 hours.
- Objection to automated decisions made solely by automated processing, including profiling, where they have a legal or similarly significant effect on you.
- Portability — asking to receive your data in a commonly used, machine-readable format.
- Compensation — you may claim for loss caused by unlawful processing of your data.
Send requests to [email protected]. Where UU PDP sets a 3×24 hour deadline we will meet it; for the other rights we will respond as quickly as we reasonably can. We verify your identity first, so that nobody else can obtain your data.
Two limits are worth stating plainly. Withdrawing consent does not undo processing that has already taken place. And we cannot delete invoices, receipts or payment authorisation records before their retention period ends, because we are legally required to keep them; we will restrict their use instead.
If you are unhappy with our response you may complain to Indonesia's personal data protection supervisory authority.
9. Cookies
We use cookies to keep you signed in, protect your session, and remember basic interface preferences such as menu state. We do not use advertising cookies, analytics trackers or third-party tracking pixels, so there is no tracking for you to opt out of. Blocking our cookies will prevent you from signing in.
10. Children
WellOpz accounts are intended for adults. Where a venue enrols a minor, UU PDP requires the consent of a parent or guardian, and obtaining it is the venue's responsibility.
11. Changes to this policy
If we make a change that materially affects how we handle your data, we will make reasonable efforts to notify account holders by email at least 30 days before it takes effect. Other changes apply when published. The date at the top of this page always shows the current version.
12. Contact us
For any question about this policy, or to exercise your rights, contact [email protected].
PT WELLOPZ TEKNOLOGI SOLUSINDO, KOMP BALOI MAS GARDEN BLOK J NO 6, Baloi Indah, Lubuk Baja, Batam, Kepulauan Riau, 29432, Indonesia.