Privacy Policy

Last updated: 11 August 2026

1. Who we are and what this covers

This policy is issued by PT WELLOPZ TEKNOLOGI SOLUSINDO, of KOMP BALOI MAS GARDEN BLOK J NO 6, Baloi Indah, Lubuk Baja, Batam, Kepulauan Riau, 29432, Indonesia("we", "us"), which operates the WellOpz platform. It explains how we handle personal data under Indonesia's Personal Data Protection Law (Law No. 27 of 2022, "UU PDP").

WellOpz is software used by fitness and wellness venues to run their businesses. Two different relationships are covered here, and the difference affects who you should contact about your data:

  • Venues and their staff. When a venue subscribes to WellOpz, we are the data controller for that business relationship.
  • Venue customers. When you book a class or buy a membership from a venue, that venue decides what to collect about you and why. The venue is the controller and we act as its processor. We are separately the controller for the limited data needed to run the platform itself, such as your login credentials and payment records.

If you are a venue customer and want data corrected or deleted, contact your venue first. If they cannot help, contact us at [email protected] and we will assist.

2. What we collect

We collect only what the platform needs in order to work.

  • Account data: name, email address, and password, stored only as a cryptographic hash and never in readable form.
  • Venue business data: legal entity name, registered address, tax identifier, and business contact details.
  • Customer profile data entered by you or your venue: phone number, date of birth, gender, address, and notes a venue keeps about your membership.
  • Activity data: bookings, class attendance, check-ins, and membership or credit balances.
  • Payment records: amount, currency, the plan or package purchased, and the payment status returned by our payment processor.
  • Consent records: when you authorise a payment we record the date and time, your IP address, your browser identifier, and the exact wording shown to you. We are required to keep this so a disputed charge can be defended.
  • Documents you sign: where a venue uses waivers or health declarations, the completed document and any signature image.

We never see or store your card number. Card details are entered on a payment page hosted by Xendit and never reach our systems.

Date of birth, and any health information a venue asks you to provide, are specific personal data under UU PDP. We process these only where the venue has a lawful basis to collect them, and we apply the controls described in section 6.

3. Why we process it, and on what basis

PurposeLawful basis
Providing bookings, memberships and creditsPerformance of a contract with you
Taking and settling paymentsPerformance of a contract; legal obligation
Sending booking, receipt and renewal noticesPerformance of a contract
Recurring payment authorisation and consent recordsYour consent; our legitimate interest in defending disputes
Keeping invoices and transaction recordsLegal obligation under tax and accounting rules
Security, fraud prevention and abuse investigationLegitimate interest
Health or waiver informationYour explicit consent, given to the venue

We do not use your personal data for advertising, and we do not sell it or share it with data brokers.

4. Who we share it with

We share personal data only with the providers needed to operate the platform, and only the data each one requires:

ProviderPurposeData shared
Xendit (PT Sinar Digital Terdepan)Payment processingName, email, phone number, transaction amount and reference
Cloudflare R2File and image storageUploaded images and signed documents
Resend, or our configured email providerTransactional email deliveryName, email address, and message contents
CloudflareNetwork delivery, TLS termination and protection against attackTraffic metadata such as IP address, browser identifier and request details

We also disclose data where legally required, for example in response to a valid order from a court or authority.

Xendit processes payment data as an independent controller under its own privacy policy and terms, and is licensed and supervised by Bank Indonesia.

5. Transfers outside Indonesia

Some providers operate infrastructure outside Indonesia, so your personal data may be processed abroad. Where that happens we rely on UU PDP Article 56: we confirm the destination country offers an adequate level of protection, or we put contractual safeguards in place with the provider, or we obtain your consent.

You can ask us for details of the safeguards applying to a particular transfer by contacting [email protected].

6. How we protect it

  • All traffic is encrypted in transit using TLS.
  • Passwords are stored only as salted cryptographic hashes.
  • Card details never reach our systems; payment pages are hosted by Xendit, which is certified to the Payment Card Industry Data Security Standard.
  • Each venue's data is isolated, and access is limited by role so staff see only what their role requires.
  • Access to production systems is restricted to personnel who need it.

No system is perfectly secure and we cannot guarantee absolute security. UU PDP Article 46 requires the data controller to notify affected people and the supervisory institution in writing within 3×24 hours of becoming aware of a personal data breach.

Where we are the controller — your account and payment data — we make that notification ourselves. Where your venue is the controller, we alert the venue without delay so it can meet its own deadline, and we support it in doing so.

7. How long we keep it

We keep personal data for as long as it is needed for the purposes described in section 3, and for as long as we are required to keep it by Indonesian law — in particular tax and company record-keeping rules, which oblige us to retain financial records for a period set by that legislation.

DataHow long
Account and profile dataWhile the account is open. You may ask us to delete it, and we will do so as quickly as we reasonably can, unless we are legally required to keep it
Bookings and attendanceWhile your venue needs it to run its business and to evidence services delivered. Your venue decides this, as controller of that data
Invoices, receipts and transaction recordsFor the period Indonesian tax and company record-keeping law requires. We cannot delete these earlier, even on request
Payment authorisation and consent recordsWith the transaction they authorise, so a disputed charge can be defended
Signed waivers and health declarationsAs set by your venue, and while a related claim could still be brought

We do not currently run automated deletion on a fixed schedule. Data is deleted when you ask us to and we have no legal reason to keep it, or when we no longer need it for the purpose it was collected for. If you want to know what we hold about you or want it removed, contact [email protected] and we will tell you what we can and cannot delete, and why.

8. Your rights

UU PDP gives you the following rights:

  • Information about who is processing your data, on what legal basis, and for what purpose.
  • Accessto your personal data and a copy of it — we respond within 3×24 hours.
  • Correctionof data that is wrong, incomplete or out of date — within 3×24 hours.
  • Deletion or destruction of your data, and to end processing of it. UU PDP does not set a fixed deadline for this one; we act within a reasonable time.
  • Withdrawal of consent, where we relied on your consent — we stop that processing within 3×24 hours.
  • Restriction— asking us to suspend or limit processing — within 3×24 hours.
  • Objection to automated decisions made solely by automated processing, including profiling, where they have a legal or similarly significant effect on you.
  • Portability — asking to receive your data in a commonly used, machine-readable format.
  • Compensation — you may claim for loss caused by unlawful processing of your data.

Send requests to [email protected]. Where UU PDP sets a 3×24 hour deadline we will meet it; for the other rights we will respond as quickly as we reasonably can. We verify your identity first, so that nobody else can obtain your data.

Two limits are worth stating plainly. Withdrawing consent does not undo processing that has already taken place. And we cannot delete invoices, receipts or payment authorisation records before their retention period ends, because we are legally required to keep them; we will restrict their use instead.

If you are unhappy with our response you may complain to Indonesia's personal data protection supervisory authority.

9. Cookies

We use cookies to keep you signed in, protect your session, and remember basic interface preferences such as menu state. We do not use advertising cookies, analytics trackers or third-party tracking pixels, so there is no tracking for you to opt out of. Blocking our cookies will prevent you from signing in.

10. Children

WellOpz accounts are intended for adults. Where a venue enrols a minor, UU PDP requires the consent of a parent or guardian, and obtaining it is the venue's responsibility.

11. Changes to this policy

If we make a change that materially affects how we handle your data, we will make reasonable efforts to notify account holders by email at least 30 days before it takes effect. Other changes apply when published. The date at the top of this page always shows the current version.

12. Contact us

For any question about this policy, or to exercise your rights, contact [email protected].

PT WELLOPZ TEKNOLOGI SOLUSINDO, KOMP BALOI MAS GARDEN BLOK J NO 6, Baloi Indah, Lubuk Baja, Batam, Kepulauan Riau, 29432, Indonesia.