Legal

Privacy Policy

This policy explains how Safar Nova processes Personal Data under the laws of the Republic of Indonesia, especially the Personal Data Protection Law.

Last updated: July 2026

1. Legal basis

This Privacy Policy is prepared with reference to the laws and regulations of the Republic of Indonesia, including:

  • Law No. 27 of 2022 on Personal Data Protection (“PDP Law”);
  • Law No. 11 of 2008 on Electronic Information and Transactions as amended by Law No. 19 of 2016 and subsequent amendments (“ITE Law”);
  • Government Regulation No. 71 of 2019 on the Operation of Electronic Systems and Transactions (“GR 71/2019”);
  • Consumer protection provisions to the extent applicable, including Law No. 8 of 1999.

The terms “Personal Data”, “Personal Data Subject”, “Personal Data Controller”, and “Personal Data Processor” in this policy follow the meanings in Article 1 of the PDP Law.

2. Scope & Safar Nova’s role

This policy applies to the website, pilgrim app, agent dashboard, API, and related Safar Nova services (the “Services”). It complements the Terms of Use.

In day-to-day operations, our role may differ:

  • As Personal Data Controller — for Service user account data (agents, travel owners, pilgrims who create accounts), sales/support communications, and technical data we process to provide and secure the Services.
  • As Personal Data Processor — for pilgrim/operational Personal Data uploaded, managed, or processed on the instructions of travel agencies/agents as our customers (for example pilgrim lists, hotel rooms, group data, and location while location sharing is active). In that case, the travel agency/agent acts as Controller and must have a lawful basis toward the Personal Data Subject.

3. Types of Personal Data processed

Depending on how the Services are used, we may process:

  • Identity & account data: name, email, phone number, role, login credentials, and profile data.
  • Business data: travel/company name, branch, contact person, business address, and plan/subscription information.
  • Pilgrim operational data: name, passport (if provided), WhatsApp, hotel room, rooming, trip notes, and claim/QR codes.
  • Location data: GPS coordinates/estimated position while location sharing or in-app navigation is active (Personal Data that can identify an individual).
  • Communication data: group chat messages, SOS reports, and messages via forms, email, or WhatsApp.
  • Technical data: IP address, device/browser type, access logs, and diagnostic data for security and Service improvement.

If specific Personal Data as defined in the PDP Law is involved (for example certain health-related data), processing is only carried out if necessary for the Services and a lawful basis exists, including explicit consent where required.

4. Purposes of processing

  • Provide, operate, maintain, and improve the Services.
  • Account authentication, authorization, and security.
  • Group features, live tracking, chat, SOS, itinerary, and trip-data claim.
  • Customer support, onboarding, and Service-related communications.
  • Billing, subscription administration, and contract performance.
  • Prevent abuse, fraud, unauthorized access, or system security threats.
  • Comply with legal obligations under applicable laws and regulations.

5. Legal bases for processing (Article 20 PDP Law)

Under Article 20(2) of the PDP Law, our processing of Personal Data is based on one or more of the following:

  • Valid explicit consent of the Personal Data Subject for specific purposes (Article 20(2)(a));
  • Performance of a contract, where the Personal Data Subject is a party or to fulfill a request prior to entering into a contract (letter b);
  • Compliance with a legal obligation of the Controller under laws and regulations (letter c);
  • Protection of the vital interests of the Personal Data Subject (letter d), for example in the context of SOS/field safety features;
  • Legitimate interests of the Controller, taking into account purpose, necessity, and the balance of the Subject’s rights (letter f), for example system security and abuse prevention.

Where processing is based on consent, we provide the information required under Article 21 of the PDP Law, and the Personal Data Subject may withdraw consent in accordance with the PDP Law.

6. Sharing & disclosure

We do not sell Personal Data. Disclosure is limited to:

  • Infrastructure/support providers (hosting, email, notifications) bound by confidentiality and processing data only on instruction;
  • Group/family members authorized to view data under the Service visibility settings;
  • Competent authorities when required by law or lawful legal process;
  • Other parties with the Personal Data Subject’s consent, or on the Controller’s (travel/agent) instructions when we act as Processor.

Any transfer of Personal Data outside the territory of the Republic of Indonesia (if it occurs) will observe PDP Law rules on cross-border transfers and adequate protection safeguards.

7. Retention & deletion

Data is retained as long as necessary for processing purposes, contract performance, dispute resolution, and legal obligations. When no longer needed, data will be deleted, destroyed, and/or anonymized according to reasonable technical capability and our retention policy (including operational location history retention).

Deletion requests may be submitted under Personal Data Subject rights (including Articles 8 and 9 of the PDP Law), subject to statutory exceptions (for example law-enforcement interests).

8. Personal Data security

In line with Controller/Processor duties under the PDP Law and security principles in GR 71/2019, we apply reasonable technical and organizational measures to protect the confidentiality, integrity, and availability of Personal Data, including access controls, encryption in transit (HTTPS/TLS where available), and security monitoring.

No system is 100% secure. If a Personal Data protection failure occurs that may harm the Personal Data Subject, we will take notification steps required by the PDP Law (including mandated timelines) to the competent authority and/or the Personal Data Subject to the extent required.

9. Personal Data Subject rights (Chapter IV PDP Law)

Under the PDP Law (including Articles 5–13), Personal Data Subjects have rights including to:

  • Obtain information on the clarity of identity, legal interest basis, purpose, and accountability of the party requesting Personal Data (Article 5);
  • Complete, update, and/or correct Personal Data (Article 6);
  • Access Personal Data about themselves (Article 7);
  • End processing, delete, and/or destroy Personal Data in certain conditions (Article 8);
  • Withdraw consent to Personal Data processing (Article 9);
  • Object to decisions based solely on automated processing (Article 10), where relevant;
  • Suspend or restrict Personal Data processing (Article 11);
  • Obtain and/or use Personal Data in a commonly used format (Article 13), to the extent applicable.

Rights are exercised through a recorded request submitted electronically or non-electronically to the Personal Data Controller (Article 14 PDP Law).

  • For Safar Nova account data: send requests to the contact below (we act as Controller).
  • For pilgrim data managed by a travel agency in the system: submit requests to the relevant travel/agent as Controller; we will assist in our Processor role.

10. Cookies & similar technologies

The website/app may use cookies, local storage, or similar technologies needed for login sessions, language preferences, and security. You may configure your device/browser to limit cookies, noting that some features may not work optimally.

11. Children & minors

The Services are intended for travel operations and adult pilgrims. If a child’s Personal Data is processed (for example as a group member), the Controller must ensure a lawful basis and valid consent under the PDP Law and related rules.

12. Policy changes

This policy may be updated to reflect Service developments or changes in law. The update date will be shown on this page. Continued use of the Services after changes means you understand the applicable policy, without limiting your rights under the law.

13. Contact us

For questions, complaints, or requests related to Personal Data Protection:

Also see About Us and Terms of Use.

Note: this document is general information on Safar Nova’s privacy practices and is not formal legal advice. For business-specific compliance, consult legal counsel.