Privacy Policy

Effective and last updated 27 September 2026

This policy explains how [Owner's full name], doing business in Indonesia as Wellbook (“Wellbook”, “we”, “us”), collects, uses, discloses and protects personal data in connection with the Wellbook service (the “Service”). We serve businesses in Indonesia, Singapore and elsewhere, so it is written to meet Indonesia’s Personal Data Protection Law (Law No. 27 of 2022, the “PDP Law”), Singapore’s Personal Data Protection Act 2012 (the “PDPA”) and, for people in the European Economic Area or the United Kingdom, the GDPR. Where these laws differ, we follow the one that protects you more, and section 11 sets out the rights each gives.

1. Our two roles

Wellbook is software that wellness, fitness and sports businesses use to run their bookings. We handle personal data in two different roles:

  • As an organisation responsible for the data: for the people who use the Service on behalf of a business (owners, managers and front-desk staff, together “users”) and for anyone who contacts us. This policy describes how we handle that data.
  • As a data intermediary: for the data a business puts into the Service about its own clients and staff (for example names and preferred names, contact details, birth dates and gender where the business records them, bookings, class attendance, notes, packages, payment records, and staff contact, personal, emergency-contact and payroll details). We process that data only on the business’s behalf and under our Terms of Service. The business decides what is collected and why, and is responsible for giving notice and obtaining consent. See section 13.

2. Personal data we collect about users

  • Account details: name, email address, password (stored only as a one-way hash), the business you belong to and your role.
  • Business details you enter at sign-up, such as the business’s name, country, time zone and currency.
  • Billing details: the billing contact’s name and email, the address and tax number (NPWP) to print on invoices, and the invoices and payments for your subscription.
  • Usage and technical data: IP address, browser and device details, pages visited, and the date and time of requests, as recorded in our hosting and security logs.
  • Analytics data, only if you accept analytics cookies: see section 5.
  • Correspondence: what you tell us when you email us.

We collect this from you, from the business that invites you to join its workspace (your name, email address and role), and automatically as you use the Service.

3. Why we use it

  • to create and run your account, sign you in and keep your session secure;
  • to provide the Service to the business you work for, including sending the emails it relies on (verification, password reset, invitations);
  • to prevent fraud and abuse, including limiting repeated sign-in and sign-up attempts;
  • to find and fix errors, and to understand how the Service is used so we can improve it;
  • to answer your questions and give support;
  • to send you news about the Service, only as described in section 12; and
  • to meet our legal obligations and enforce our agreements.

We use personal data only for these purposes, or for others we tell you about before we use it. We do not sell personal data, and we do not use it for third-party advertising.

4. Consent

We process your personal data only on a basis the law recognises. Under the PDP Law these are, for us: your consent; performing our contract with you or your business; meeting a legal obligation; and our legitimate interests. Other laws use similar bases (the PDPA’s “deemed consent” and exceptions, the GDPR’s lawful bases). In practice:

  • Our contract: running your account and the Service for your business, including the emails it relies on (verification, password reset, invitations, invoices).
  • Consent: optional analytics cookies are used only if you click Accept, and you can withdraw that at any time in Cookie settings.
  • Legitimate interests and legal obligations: protecting the Service, detecting fraud and investigating misuse, improving the Service, and keeping the records tax law requires, in each case only after weighing that the benefit outweighs any adverse effect on you.

5. Cookies and similar technologies

  • Strictly necessary (always on): a sign-in session cookie (it expires after 7 days without use), security cookies used by the sign-in process, and a cookie remembering which business workspace you last opened (12 months). The Service cannot work without these.
  • Preferences (always on, stored in your browser only): your light or dark theme, and your analytics choice.
  • Analytics (only if you click Accept): PostHog cookies and browser storage that record the pages you visit and actions you take, linked to your account, your name, email address and business so we can understand how businesses use the Service. If session recording is switched on, it records the layout of the screen and where you click and scroll; all text on screen and everything typed is masked, so clients’ details are not captured. If you click Decline, or make no choice, none of this is loaded.

To change your analytics choice at any time, use Cookie settings (at the foot of our sign-in and policy pages, and on the Your account page). You can also ask us to delete analytics data about you (section 11).

6. Who we share it with

The administrators of a business’s workspace can see its users’ names, email addresses and roles. Outside it, we share personal data only with the service providers below (our “sub-processors”), who process it on our instructions under written data-protection terms; with professional advisers under a duty of confidence; with a buyer or successor if our business is transferred, who must honour this policy; and where the law, a court or a regulator requires it.

Vercel Inc.
Hosts the application. Our server functions run in Singapore (region sin1); pages and requests pass through Vercel’s global network, and Vercel’s platform logs (including IP addresses) may be processed in the United States.
Neon (database)
Stores the Service’s database, on Amazon Web Services in Singapore (ap-southeast-1).
Resend, Inc.
Sends email: account emails to users, and booking confirmations, reminders and receipts to clients of the businesses that use Wellbook. Processed in the United States.
Functional Software, Inc. (Sentry)
Error monitoring, only when we switch it on. Receives technical details of errors (such as the page, browser and device, and possibly an IP address). Processed in the European Union (Germany).
PostHog, Inc.
Product analytics and, where switched on, session recordings. Loaded only in browsers that accept analytics cookies. Processed in the European Union (Germany).

We will update this list before adding or replacing a sub-processor, and give businesses notice as our Terms of Service require.

7. Transfers to other countries

Our database and application servers are in Singapore, so personal data from Indonesia and other countries is stored there, and some sub-processors above process data in the United States. Before any transfer, we make sure the recipient is bound by legally enforceable obligations (through its contract with us) to protect it to a standard at least comparable to the law of the country it came from: the PDP Law (which allows transfers to a country with equal or better protection, or with appropriate safeguards), the PDPA’s transfer limitation obligation, and, for data from Europe, the European Commission’s standard contractual clauses.

8. How we protect it

  • all traffic is encrypted in transit (HTTPS/TLS), and our database provider encrypts data at rest;
  • passwords are stored as bcrypt hashes; links for password reset, email verification and invitations are single-use, expire, and are stored only as hashes;
  • each business’s data is kept separate, and every request is checked against the business and role of the signed-in user;
  • resetting or changing a password signs out every session, and the account holder is told by email;
  • administrators can limit a team member to the locations they work at, and every change to settings, the team and money records, and every data export, is kept in an activity log;
  • sensitive staff fields, such as bank and identification details, are visible only to a business’s administrators, and are left out of lists, search and exports other than the full export of the business’s own data that an administrator can download;
  • repeated sign-in, sign-up and reset attempts are rate limited; and
  • access to production systems is limited to the personnel who need it.

No system is completely secure, but we review and improve these arrangements as the Service grows.

9. Accuracy and retention

Administrators can update a business’s details in Settings at any time. To correct your own name or email address, or anything else we hold about you, contact us (section 11). We keep personal data only as long as it serves the purposes above or the law requires, then delete or anonymise it. Our Data Retention Policy gives the details.

10. Data breaches

Where the PDP Law applies, we notify the people affected and the Indonesian data protection authority in writing within 3 × 24 hours of a failure to protect personal data, saying what was affected, when and how, and what we are doing about it; where the GDPR applies, we notify the supervisory authority within 72 hours. Under the PDPA, if we have reason to believe a data breach has occurred, we will contain it and assess, promptly and in any case within 30 days, whether it is notifiable under the PDPA: that is, whether it is likely to cause significant harm to the people affected, or affects 500 or more people. If it is notifiable, we will notify the Personal Data Protection Commission (PDPC) as soon as practicable and no later than 3 calendar days after that assessment, and notify affected individuals as soon as practicable, unless the PDPA says we must not or need not (for example, where the PDPC or a law enforcement agency directs us not to).

If a breach affects data we hold for a business as its data intermediary, we will tell that business without undue delay and help it meet its own obligations.

11. Your rights

Wherever you are, you can ask us to:

  • give you a copy of the personal data we hold about you, and tell you how it has been used and disclosed;
  • correct or complete it;
  • delete it, or stop or pause using it, where we no longer need it or have no right to keep it;
  • stop using it for a purpose you consented to (withdrawing consent), and tell you what that means for your account;
  • give it to you in a structured, commonly used format, or send it to another service, where it is processed by automated means; and
  • explain any decision about you made solely by automated means (we do not make any).

How quickly we act depends on the law that protects you:

  • Indonesia (PDP Law): we give access, correct data and stop processing after consent is withdrawn within 3 × 24 hours of receiving your request.
  • Singapore (PDPA): within 30 days; if we need longer, we tell you within those 30 days when we will respond.
  • Europe and the United Kingdom (GDPR): within one month, which may be extended by two months for complex requests, in which case we tell you why within the first month. There, we rely on performing our contract with you, our legitimate interests (keeping the Service secure and improving it) and, for analytics, your consent.

We do not charge for requests, unless one is clearly unfounded or excessive. We may need to confirm your identity first. If we cannot do what you ask, we tell you why, as far as the law allows. Send requests to our Data Protection Officer at privacy@hibeckon.com.

12. Marketing messages

  • Emails that are part of the Service (verification, password resets, invitations, and notices about your account or these policies) are not marketing, and you will receive them while you have an account.
  • We send news and offers only with your consent (and, in Singapore, only as the Spam Control Act 2007 allows). Every marketing email says it comes from us, has a working unsubscribe link, and is labelled as required for unsolicited messages; we act on an unsubscribe within 10 business days.
  • We will not send marketing calls, text messages or faxes to a Singapore telephone number unless you have given clear and unambiguous consent in writing or another accessible form, or we have first checked the number against the Do Not Call Registry, as the PDPA requires.
  • The booking messages a business sends its clients through the Service (confirmations, reminders, changes, cancellations and receipts) are sent on that business’s behalf. A client can stop them with the unsubscribe link in any booking email, or by asking the business; a receipt the client asks for is still sent.

13. If a business holds your data in the Service

If you are a client or staff member of a business that uses Wellbook, that business is responsible for your data. Please contact it directly to ask what it holds, to correct it, to withdraw consent or to stop booking messages. If you contact us instead, we will pass your request on to the business promptly and help it respond.

14. Minors

Users of the Service must be at least 18. Businesses may hold data about clients who are minors, for example children attending classes; each business is responsible for obtaining consent from a parent or guardian where needed.

15. Changes to this policy

We may update this policy. We will change the date at the top, and tell users by email or in the Service before a material change takes effect.

16. Contact and complaints

Our Data Protection Officer can be reached at privacy@hibeckon.com, or by post at [Owner's full name], [Business address], Indonesia, marked “Data Protection Officer”. If you are not satisfied with our response to a complaint, you may complain to the data protection authority where you live or work: in Indonesia, the authority responsible for personal data protection under the PDP Law; in Singapore, the Personal Data Protection Commission (www.pdpc.gov.sg); in Europe or the United Kingdom, your local supervisory authority.