Introduction & Scope
This Privacy Policy explains how PT Digivo Kreatif Indonesia ("we", "us", "our") collects, uses, stores, shares, and deletes personal data when you use the products we operate under the WatZap brand. It is one policy for every WatZap surface:
- the watzap.id website and all of its pages;
- the app.watzap.id application, the WatZap broadcast and automation platform;
- the watzap.chat website and web application, the WatZap.chat CRM and Team Inbox;
- the WatZap.chat mobile app for Android and iOS;
- the WatZap public API and the integrations built on it;
- and the support services we provide to subscribers of any of the above.
Some sections apply to only one surface. Those sections say so at the top (for example, "Applies to the watzap.id website"). Everything else applies to all of them.
An identical copy of this policy is published at watzap.id/privacy-policy and at watzap.chat/privacy-policy. Both are generated from the same source document and carry the effective date shown at the top of this page.
This policy stands on its own for everything concerning personal data. The Terms & Conditions govern the commercial relationship; where this policy speaks about how data is collected, used, or protected, this policy applies.
By using any of these products, you accept this policy. If you do not agree with it, please do not use them.
Data Controller
The party responsible for the personal data described in this policy is:
- Company: PT Digivo Kreatif Indonesia
- Products: WatZap (watzap.id, app.watzap.id, and the WatZap API) and WatZap.chat (watzap.chat and the WatZap.chat mobile app)
- Registered address: Jl. Inpres Raya (Griya Niaga) A-11, Larangan Utara, Larangan, Tangerang, Banten 15154, Indonesia
- Privacy contact: privacy@watzap.id
- Websites: https://watzap.id and https://watzap.chat
"WatZap" and "WatZap.chat" are product and brand names of PT Digivo Kreatif Indonesia, not separate legal entities. Wherever this policy says "WatZap", it means the product; the party responsible for your data is always PT Digivo Kreatif Indonesia.
Our Roles: Controller and Processor
Two kinds of personal data flow through WatZap, and we play a different role for each. Keeping them apart is what most of this policy rests on.
Where we are the controller
- Your WatZap account data: name, email address, phone number, company name, password, billing and payment records, usage records, and the support conversations you have with us. We decide why and how this data is processed, and this policy describes it in full.
Where you are the controller and we are the processor
- Your end-customers' data: the contact numbers you upload or sync, the names and labels you give them, the content of the conversations you have with them, and the messages you send them. For this data you are the controller: you decide what to collect and what to send. We act only as your processor, on your instructions, to deliver the service you subscribed to.
What follows from that
- We process end-customer data only to provide the service to you, and never for our own purposes (sections 5 and 10).
- You are responsible for having a lawful basis to contact those people, and for the content you send them (section 9).
- If an end-customer contacts us about their data, we forward the request to you, unless the law requires us to act ourselves (section 9).
Data We Collect
Data you give us
- Account data: name, email address, phone number, password (stored only as a hash), company name, and profile picture.
- Billing data: the payment method you choose and the transaction records that result. Card and bank details are entered on, and processed by, our payment providers (section 11); we do not store full card numbers on our servers.
- Business data: your WhatsApp Business Account (WABA) credentials, phone number ID, business display name, and the integration tokens you connect.
- Content: the contact databases you upload or sync, the broadcast messages and attachments you send, the chat messages and media exchanged in WatZap.chat, and the labels, notes, and tags you create.
- Support communications: anything you send us when you ask for help.
Registration happens at app.watzap.id or watzap.chat. The watzap.id website itself has no forms, so no registration data is collected there.
Data collected automatically
- Device data: device model, operating system version, app version, language, and time zone (mobile app and web app).
- Log data: IP address, access times, pages or screens opened, crashes, and performance data.
- Usage data: which features you use, how many messages you send, delivery status, broadcast timestamps, and contact import history. This is what makes your plan quota countable and abuse traceable.
- Session data: the authentication tokens and identifiers that keep you signed in.
- Visit-source data on watzap.id: if you arrive from an ad or an affiliate link, the campaign parameters (
utm_source,utm_medium,utm_campaign, and similar), ad click IDs (fbclid,gclid,ttclid, and similar), and the affiliate code, so that your sign-up is credited to the right ad or affiliate. Section 6 has the details. - Technical data on watzap.id: the site is served through the Cloudflare network, which processes your IP address, browser and device type, and request timing to deliver the page and block abuse.
Data we receive from third parties
- WhatsApp Business API (Meta Platforms): the Platform Data described in section 5, for the WhatsApp Business Account you connect.
- Google Sheets: when you connect a spreadsheet as a contact source, we read that spreadsheet, read-only, on your instruction.
- Ad platforms: the click identifiers that Meta or Google attach to the links people follow into your WhatsApp threads, when you enable ad tracking.
Platform Data from the WhatsApp Business API
"Platform Data" means the data we receive from Meta through the WhatsApp Business API on behalf of a client who has connected their WhatsApp Business Account to WatZap. It includes:
- message metadata and delivery status (sent, delivered, read, failed);
- conversation data: the messages, media, and contact identifiers exchanged in those conversations;
- message template approval status;
- the WhatsApp Business Account ID (WABA ID), the phone number ID, and the business display name.
We use Platform Data received from the WhatsApp Business API solely to provide our services to the client on whose behalf we process it. We do not sell Platform Data, use it for advertising targeting or profiling, use it to train artificial intelligence models, or combine it across clients. Platform Data is deleted when a client closes their account, disconnects the integration, or when our access is revoked by Meta.
In full:
- Platform Data is used only to provide the service to the client who owns the WhatsApp Business Account it came from: delivering and displaying messages, showing delivery status, managing templates, and running the features that client has subscribed to.
- We do not sell, rent, or trade Platform Data.
- We do not use Platform Data for advertising targeting, profiling, creditworthiness assessment, insurance, employment, or any similar eligibility or decision-making purpose.
- We do not use Platform Data to train, fine-tune, or improve artificial intelligence or machine learning models, ours or anyone else's. When a client uses the AI Summary feature in WatZap.chat, the content of the conversation being summarised is sent to the AI sub-processor named in section 11 to produce a summary for that client alone, and under its API terms that sub-processor does not use the content to train its models.
- We do not combine Platform Data across clients, and we do not use it to market our own products to a client's end-customers.
- We do not transfer Platform Data to anyone other than the sub-processors listed in section 11, and only as far as needed to run the service.
- Platform Data is deleted when the client closes their account, disconnects the WhatsApp integration, or when Meta revokes our access, subject only to the backup window in section 13.
- We comply with the Meta Platform Terms, the WhatsApp Business Solution Terms, and the Meta Developer Policies, and we will honour any request from Meta to delete Platform Data or to demonstrate how it is handled.
Cookies & Browser Storage
Applies to the watzap.id website.
The watzap.id website stores a few things in your browser. This is the complete list:
_wz_track(local storage, 30 days): where your visit came from, meaning campaign parameters, ad click IDs, and the affiliate code. Used so your sign-up is credited to the ad or affiliate that brought you.wz-lang(local storage, no expiry): your language choice for the site, so you do not have to pick it again on every visit.WZPCouponDeadline,WZPExitIntentLastClose,WZPHasBeenShownCoupon(cookies, up to 30 days): so the coupon popup does not reappear over and over and the same code is not handed twice to the same browser.- Google Tag Manager cookies (container
GTM-PV7XX8N), which loads Google Analytics 4, Google Ads, and the Meta Pixel, including_ga,_gcl_*,_fbp, and_fbc. All three are third-party services governed by their own providers' privacy policies.
What leaves the site
The coupon popup sends one request to our server. It carries only the list of coupon codes already shown to this browser: no name, no email, no phone number, because the site never asks for any of them.
How to turn it off
Clear or block cookies and site storage in your browser settings. The site works fully without every item above; what you lose is the remembered language choice, and affiliate tracking, which can cost the affiliate who recommended WatZap to you their commission.
The applications
app.watzap.id and watzap.chat use the session and authentication storage needed to keep you signed in and to remember your preferences, such as your language. app.watzap.id also loads the same Google Tag Manager container to measure sign-ups and payments. watzap.chat loads no analytics or advertising tags.
Mobile App Permissions
Applies to the WatZap.chat mobile app (Android and iOS).
The WatZap.chat app asks the operating system only for what its features need. Permissions that require your consent are requested when you first use the feature, and you can revoke them at any time in your device settings.
Android
INTERNET: connect to our servers and, through them, to the WhatsApp Business API.POST_NOTIFICATIONS: show alerts for incoming messages and assignments.FOREGROUND_SERVICE,FOREGROUND_SERVICE_DATA_SYNC: keep message delivery reliable while the app is syncing in the background.
Photos and videos you attach are picked through the system picker, which does not require a storage permission.
iOS
- Camera: take a photo or video to send in a conversation.
- Microphone: record and send voice notes.
- Photo library (add only): save media you receive to your photo library.
- Notifications: requested through the standard system prompt.
Neither app reads your contacts, your location, or the content of other apps.
Purposes & Legal Basis
What we use your data for
- Running the service: storing contacts, sending and receiving messages, and operating the features included in your plan.
- Authenticating your account and securing access to it.
- Delivering, receiving, and synchronising WhatsApp messages between you and your customers.
- Billing and processing payments, including the renewal invoice that is generated automatically as your subscription nears its expiry date.
- Sending service notifications: expiry reminders 7 days and 3 days before your account ends, security alerts, and updates about features you use.
- Sending commercial information about WatZap products and services, as you agreed when you signed up. You can opt out at any time (section 17).
- Providing customer support and answering your questions.
- Analysing usage patterns to improve performance, stability, and user experience, using account, device, and usage data, never message content (section 10).
- Keeping the service safe: the user selection process, SPAM investigation, and enforcement against breaches of the Terms & Conditions.
- Measuring advertising effectiveness and calculating affiliate commissions (watzap.id only).
- Meeting legal obligations, including responding to lawful requests from competent authorities.
The legal basis
Under Indonesian Law No. 27 of 2022 on Personal Data Protection (the "PDP Law") and, where it applies, other data protection law, we rely on:
- Performance of a contract: for anything without which the service cannot run at all.
- Your consent: for commercial information, for advertising measurement cookies on watzap.id, and for any optional integration you connect. You can withdraw consent at any time; section 17 explains how.
- Our legitimate interests: for service security, abuse prevention, billing, and product improvement, always weighed against your rights.
- Legal obligation: for anything the regulations actually require, such as keeping financial records.
The Contact Database You Upload
Someone else's WhatsApp number is that person's personal data, not yours, and not ours. This is the section where responsibility moves.
What is your responsibility
- You may only import a contact database that its owners have permitted you to contact.
- You must own your WhatsApp contact numbers, obtained knowingly and legally.
- You are answerable to the number's owner for the content of the messages you send them.
Databases we treat as illegal
WatZap forbids importing an illegal database, by the following criteria:
- WhatsApp numbers published on social media.
- WhatsApp numbers published on someone's website or blog.
- WhatsApp numbers handed over by another party rather than by the number's actual owner.
When we find irregularities in the data, our system can stop the import, and your account may be suspended under the Terms & Conditions.
What we do with that database
- Store it in your account and process it to carry out your instructions: sending broadcasts, replying to conversations, filtering, and grouping.
- Clean out numbers that never interact, automatically, every month (section 13).
- We do not use your contact database to market WatZap products to the people in it, and we do not merge it with any other client's database.
If the number's owner contacts us
If someone who received your message contacts us and asks for their data to be deleted, we forward that request to you as the controller of that data, unless the regulations require us to act ourselves. You are the one who can delete it, because the database sits in your account.
Our Access to Message Content
The content of your broadcasts and conversations, including every message sent and received through WatZap.chat and the WhatsApp Business API, belongs to you and your customers. We store it so that the service can deliver, display, and search it for you. We do not read it as a matter of course.
When our personnel may access it
Only personnel who are specifically authorised may access message content, and only for one of these reasons:
- investigating an abuse or SPAM report, or a suspected breach of the Terms & Conditions;
- enforcing the Terms & Conditions;
- keeping the system secure, including diagnosing a fault you have reported to us;
- complying with a legal obligation or a lawful request from a competent authority.
The rules that apply to every access
- Each access is recorded in an audit log: who, when, which account, and why.
- Access is limited to what the reason requires, and it stops when the reason is resolved.
- Message content accessed this way is never used for commercial or marketing purposes, never published, never reused as training or teaching material, and never used to train or improve any model.
- Automated processing of message content, such as delivery, search, filtering, keyword-triggered replies, AI summaries, and similar features, happens only on your instruction and only inside your own account.
Messages you send also pass through WhatsApp to reach their recipients. From that point on, their handling by Meta is governed by Meta's own privacy policy.
Data Sharing & Sub-processors
We do not sell your personal data or your end-customers' data to anyone. We share data only in the situations below, and only as far as needed.
Sub-processors
These are the companies that process data on our behalf so that the service can run. This is the complete list. Each is bound by a contract that limits its use of the data to the service it provides to us, and we update this policy before engaging a new sub-processor.
- Meta Platforms, Inc.: WhatsApp Business Platform and Instagram messaging: message delivery and the Platform Data described in section 5.
- HostHatch LLC: the virtual servers in Singapore that run our applications and databases.
- Cloudflare, Inc.: content delivery, DNS, and attack protection for watzap.id and app.watzap.id.
- Bunny.net (BunnyWay d.o.o.): media storage and content delivery in Singapore for files exchanged in WatZap.chat, and for static assets.
- DigitalOcean, LLC: object storage for media files of app.watzap.id.
- Amazon Web Services, Inc. (Amazon SES): transactional email: verification codes, invoices, and service notifications.
- Google LLC: Firebase Cloud Messaging (push notifications to the mobile app); Google Tag Manager, Google Analytics 4, and Google Ads (visit measurement on watzap.id, section 6); Google Sheets API (only when you connect a spreadsheet).
- Supabase, Inc.: product usage analytics for app.watzap.id: account identifier, event name, IP address, platform, browser, and device type. No message content.
- OpenRouter, Inc. and OpenAI (via OpenRouter): the AI Summary feature of WatZap.chat. When a client uses it, the content of the conversation being summarised is sent to generate a summary for that client alone. Under their API terms, neither provider uses that content to train its models, and we do not store the prompt or the request on our side beyond the summary itself.
- Payment providers: Faspay, Winpay, Youtap, and PayPal, to process subscription and renewal payments. They receive your name, email address, and the transaction amount; card and bank details are entered directly with them.
Meta Platforms (WhatsApp Business API)
To deliver WhatsApp messaging, we exchange the data described in section 5 with Meta Platforms, Inc., in accordance with the WhatsApp Business Solution Terms. Meta's handling of that data is governed by Meta's own policies. When you enable ad tracking, we also send conversion events containing hashed phone numbers to Meta's Conversions API, on your instruction and for your own advertising account only.
Legal Requirements
We may disclose information if required to do so by law, subpoena, court order, or other legal process, or to protect the rights, property, or safety of PT Digivo Kreatif Indonesia, our users, or others.
When we receive a request for user data from a public authority, we review the request to confirm that it comes from a competent authority, is based on a valid legal instrument, and is properly issued. We disclose only the specific data we are legally required to provide, and no more. Where a request appears unlawful, overly broad, or improperly issued, we may challenge it or seek that it be narrowed. Every such request is documented, including the legal basis, our response, and the reasoning behind it. Where the law permits, we notify the affected user before disclosing their data.
Business transfers
If we are involved in a merger, acquisition, or sale of assets, your account data may be transferred as part of that transaction, and we will notify you before it becomes subject to a different privacy policy. Platform Data is transferred only to the extent the Meta Platform Terms permit, and any recipient must accept the same restrictions set out in section 5.
With your consent
We may share your account data for other purposes with your explicit consent. This does not extend to Platform Data or to your end-customers' data: your consent as our client cannot be the basis for using that data beyond providing the service to you, and we will not ask you for such consent.
What we never share
- The affiliate who recommended WatZap to you receives a commission record only, never your contact database, your message content, or the contents of your account.
- No advertiser or data broker receives Platform Data, contact databases, or message content, in any form.
- The only AI provider that ever receives message content is the AI Summary sub-processor named above, on your instruction, for your own summary alone, and never for training.
Where Data Is Stored & International Transfers
Our application servers and databases run on virtual servers operated by HostHatch LLC in Singapore. Some sub-processors store or process data in other countries:
- Bunny.net: media storage in Singapore (storage region SG).
- DigitalOcean Spaces: media storage in Frankfurt, Germany (region fra1).
- Amazon SES: transactional email through the US East (N. Virginia) region.
- OpenRouter and OpenAI: AI summaries generated in the United States.
- Faspay, Winpay, and Youtap: payment processing in Indonesia; PayPal on global infrastructure that includes the United States.
- Meta Platforms, Google, Cloudflare, and Supabase: global infrastructure that may be located outside Indonesia, including the United States.
Wherever personal data leaves Indonesia, we do so under Article 56 of the PDP Law: the recipient is bound by contract to a level of protection equivalent to this policy, or you have consented to the transfer. Platform Data is transferred only to the sub-processors in section 11 and only for the purposes in section 5.
Data Retention
We keep personal data only as long as it is needed for the purposes in section 8, then delete or anonymise it. The rules, by type of data:
Account data
- Kept while your account is active, and deleted under section 14 after it is closed.
Message and conversation data (WatZap.chat)
Conversation history is kept for a fixed period that depends on your plan. Messages older than the chat-history window leave the inbox and are deleted automatically at the end of the grace period that follows:
| Plan | Chat history in the inbox | Grace period | Maximum retention |
|---|---|---|---|
| Lite | 15 days | 15 days | 30 days |
| Pro | 6 months (180 days) | 30 days | 7 months (210 days) |
| Business | 2 years (730 days) | 30 days | 25 months (760 days) |
- Nothing is kept longer than the longest of those periods, 760 days, unless you export it yourself.
- Ad tracking event logs are kept for 7 days on Pro and 30 days on Business; Lite does not include ad tracking.
Broadcast data (app.watzap.id)
- Contact numbers that never interact with you, for example never open a broadcast, are cleaned from your database automatically every month, without prior notice.
- If your account stays inactive for 2 months after its expiry date, all data in it, including the number database and everything else, is deleted automatically. We send reminders by email and WhatsApp 7 days and 3 days before expiry.
Platform Data
- Deleted when you close your account, disconnect the WhatsApp integration, or when Meta revokes our access (section 5).
Billing records
- Kept for the period required by Indonesian tax and accounting law, even after your account is closed, and used for nothing else.
Backups
- Deleted data can persist in backups for up to 90 days before it is permanently purged. Backups are never used to restore data into a live account after that account has been deleted.
Account & Data Deletion
You may ask for your account and the personal data in it to be deleted at any time, without signing in:
- by sending a written request from the email address registered on your account to privacy@watzap.id;
- by following the steps at watzap.chat/account-deletion, which lists what to include in the request and what happens next.
What happens next:
- We verify that the request comes from the account owner, then delete the account and its personal data within 30 days.
- Data we must keep by law, such as financial records, is kept for the legally required period only and is used for nothing else.
- Your end-customers' data and the Platform Data in the account are deleted together with it; copies in backups are purged within 90 days (section 13).
- Deleting your account also disconnects your WhatsApp Business Account from WatZap. It does not delete anything from Meta's systems or from your customers' phones.
Before you ask for deletion, export anything you still need: once it is gone, it cannot be restored.
Data Security
We apply technical and organisational measures to protect the data we hold:
- Encryption in transit: TLS/HTTPS for all traffic between your browser or the app and our servers, and between our servers and the WhatsApp Business API.
- Password hashing: passwords are stored only as bcrypt hashes, never in plain text.
- Role-based access control: granular permissions for admin, manager, and agent roles inside your WatZap.chat account, so team members see only what their role needs.
- Session management: active sessions are tracked and can be revoked at any time from your WatZap.chat account.
- Two-factor authentication: optional TOTP-based 2FA with single-use backup codes in WatZap.chat, and one-time codes by email or WhatsApp at sign-in to app.watzap.id.
- Restricted internal access: access to message content is limited to authorised personnel, for the reasons and under the audit-logging rules in section 10.
- Rate limiting on sign-in and other public endpoints, to slow down credential-guessing and abuse.
- Backups under the retention rules in section 13.
Your part
- Keep your credentials confidential: anyone holding your login information can use the account.
- Register with a real, actively used email address, so that the account can be recovered.
- Enable two-factor authentication, and remove team members who no longer need access.
No system is completely secure. If, despite these measures, a breach affects you, section 16 describes what we do.
Personal Data Breaches
If a failure of personal data protection occurs that affects you, we will notify you and the competent authority in writing no later than 3 × 24 hours after we become aware of it, as required by Article 46 of Indonesian Law No. 27 of 2022. The notice states what data was affected, when and how it happened, what we have done to contain it, and what you can do.
If the affected data belongs to your end-customers, we notify you as their controller within the same period and support you in meeting your own obligations to them.
Your Rights under the PDP Law
Indonesian Law No. 27 of 2022 on Personal Data Protection gives you the following rights over your personal data:
- To be informed of our identity, the legal basis, and the purpose of using your data.
- To access and obtain a copy of your personal data.
- To correct data that is wrong or inaccurate.
- To end the processing of, delete, and/or destroy your personal data.
- To withdraw a consent you previously gave.
- To postpone or restrict the processing of your personal data proportionately.
- To object to a decision based solely on automated processing.
- To claim and receive compensation for breaches of personal data protection rules.
- To lodge a complaint with the competent data protection authority.
How to exercise them
- Access and portability: your profile shows the account data we hold; in WatZap.chat you can export your contacts and analytics as CSV.
- Correction: edit your profile directly, or ask us.
- Deletion: section 14.
- Withdrawing consent: write to us to stop commercial emails; sign out and revoke sessions to end an active session; disconnect an integration to stop the data flow it created.
- Everything else: write to us.
How to make a request
Reach us on WhatsApp or email privacy@watzap.id, and include the email address you use as your WatZap account so we can match the request to it. Customer service operates during working hours, 09.00 to 18.00 WIB. We respond to verified requests within the time the PDP Law allows.
What we cannot always grant
- Requests that conflict with our legal obligations, or that would obstruct law enforcement.
- Requests about the contact database you uploaded yourself: for that data you are the controller (section 9), and you can delete it straight from the application without asking us.
- Deleting your account data while you are still subscribed, because the service cannot run without it.
Children's Privacy
WatZap and WatZap.chat are business tools and are not intended for use by children under the age of 13, or the minimum age required in your jurisdiction. We do not knowingly collect personal data from children. If we become aware that we have collected personal data from a child without parental consent, we delete it promptly. If you believe a child has provided us with personal data, please contact us at privacy@watzap.id.
Third-Party Links & Services
Our products may contain links to third-party websites, and they let you connect third-party services, for example Google Sheets, n8n, or e-commerce platforms, to your account. This policy does not apply to those third parties. Data sent to a service you connect is sent on your instruction and is governed by that service's own privacy policy; review it before connecting.
Changes to This Policy
We may update this policy from time to time. When we make material changes, we notify you through the application, by email, or by posting a prominent notice on our websites before the change takes effect. The effective date at the top of this page identifies the version currently in force. Your continued use of the products after a change takes effect constitutes acceptance of the updated policy.
Governing Law
This policy is governed by the laws of the Republic of Indonesia, including Law No. 27 of 2022 on Personal Data Protection, without regard to conflict-of-law principles. Any dispute arising from or relating to this policy shall be resolved in the competent courts of Indonesia.
Contact Us
If you have questions, concerns, or requests about this policy or our data practices, contact us:
- PT Digivo Kreatif Indonesia
- Registered address: Jl. Inpres Raya (Griya Niaga) A-11, Larangan Utara, Larangan, Tangerang, Banten 15154, Indonesia
- Privacy requests: privacy@watzap.id
- General support: support@watzap.id
- WhatsApp: wa.watzap.id, working hours 09.00 to 18.00 WIB
- Websites: https://watzap.id and https://watzap.chat