Healthcare providers
Owners, managers, administrators, doctors, health professionals, staff, and operational partners using the services.
This policy explains how PT Aplikasi Alday Indonesia processes and protects data across AIBIZ.ID, Aibiz Medical, Aibiz Wagen, Meta channels, and all connected modules and integrations.
Owners, managers, administrators, doctors, health professionals, staff, and operational partners using the services.
Patients, prospective patients, companions, guardians, or authorized representatives whose data is processed through a provider.
Consumers, prospects, business contacts, and users of WhatsApp, Instagram, Facebook, email, forms, or other channels.
Website visitors, developers, system providers, medical-device providers, and parties connecting services through APIs.
This policy is issued by PT Aplikasi Alday Indonesia as the provider of AIBIZ.ID and applies to websites, web and mobile applications, APIs, dashboards, communication channels, implementation services, support, and integrations operating under the Aibiz brand.
It covers Aibiz Medical and EMR modules; Aibiz Scribe; Aibiz Imaging, RIS, PACS, DICOM, viewers, and Modality Worklist; Aibiz Lab and LIS; Aibiz Scan; Aibiz Wagen, CRM, team inbox, booking, reminders, follow-up, and owner assistant; Aibiz directories and Insights; and any other feature stated to be governed by this policy.
Healthcare providers determine the purposes of care, legal basis, authorized users, medical-record content, patient communications, and workspace operating policies. In this context, the provider generally acts as controller of patient data and Aibiz as processor or service provider acting on lawful instructions.
Aibiz may act as controller for account, prospect, contract, payment, security, audit, support, website analytics, and direct Aibiz communication data. Specific roles may be further defined in a proposal, service agreement, NDA, DPA, SLA, or implementation document.
Name, email, phone number, organization, position, role, encrypted credentials, professional identity, licenses or permits, preferences, and access history.
Patient identity, demographics, complaints, history, examinations, diagnoses, procedures, prescriptions, allergies, lab results, imaging, documents, referrals, summaries, consent, and other care data.
Message content, attachments, audio, transcripts, delivery status, timing, channel identifiers, conversation notes, agent assignments, and human-handoff history.
Bookings, schedules, queues, inventory, pharmacy, billing, invoices, payments, transaction status, reports, CRM activities, reminders, follow-up, and lawful campaigns.
DICOM, accession numbers, worklists, radiology images and reports, laboratory orders and results, device identifiers, device messages, and local-server metadata.
IP address, device and browser type, access time, cookies, session tokens, application logs, audit trails, API logs, telemetry, errors, backups, and anti-abuse signals.
Data may come directly from users; healthcare providers or professionals; patients, representatives, or consumers; medical devices and local servers; enabled integrations; Meta or communications providers; official government sources; and lawful public sources used for directories or professional verification.
The legal basis may include performance of a contract, legal obligations, consent, protection of vital interests, performance of lawful functions, and permitted legitimate interests. The applicable basis depends on the context, data, and relationship between the parties.
Creating accounts and workspaces and operating EMR, booking, queues, documentation, prescriptions, billing, CRM, communications, imaging, labs, integrations, reporting, and support.
Authenticating users, enforcing permissions, preventing abuse, diagnosing incidents, retaining audit trails, recovering data, and maintaining continuity.
Meeting contractual, medical-record, privacy, electronic-system, tax, rights-enforcement, lawful government-request, and audit requirements.
Measuring performance, fixing features, testing quality, and developing services using minimized, aggregated, anonymized, or otherwise properly authorized data.
Health data is personal data requiring heightened protection. Aibiz Medical provides the technical means to record and exchange data; healthcare professionals and providers remain responsible for content, accuracy, completeness, authorization, access, correction, disclosure, and clinical use of medical records.
Access is restricted by role and workspace. Users may not view, copy, export, or share patient data without authority and a lawful purpose. Medical-record corrections must preserve traceability under provider policy and applicable rules.
Aibiz Scribe may convert audio or conversations into structured transcripts and clinical-documentation drafts. The output may be normalized for the EMR context but must be reviewed and approved by an authorized user before becoming a final record.
Aibiz Wagen may classify messages, answer questions, support booking, reminders, follow-up, task assignment, and operational insights. Human handoff is supported. AI output is assistive and does not replace diagnosis, professional judgment, clinical consent, or emergency care.
Health data is not sold. Customer data is used to train a general-purpose model outside service delivery only where the required legal basis, authority, and written arrangement are in place.
When a provider or business connects a Meta account, Aibiz may process business-account identity, phone number, account identifiers, available public profile data, messages, media, templates, webhooks, sent or read status, authorized comments or interactions, and API-provided metrics.
WhatsApp, Instagram, Facebook, and Meta also process data under their own terms and privacy policies. Some processing may occur on Meta's global infrastructure. Aibiz requests only the permissions and data required for enabled features.
Depending on enabled features, data may be processed by or exchanged with infrastructure and cloud providers, Meta and communications channels, the Ministry of Health SATUSEHAT platform, hospital or clinic systems, LIS, RIS, PACS, Orthanc, medical devices, local servers, email, calendars, payments, notifications, analytics, security, and support services.
Aibiz's primary infrastructure operates on servers in the Jakarta region, Indonesia. Some data may remain on a provider's local device or server for medical-device integration and operational continuity.
Third parties, including Meta, may process data outside Indonesia as part of their global operations. For cross-border processing, Aibiz and customers apply applicable legal and contractual requirements, protection assessments, and safeguards according to their roles.
Aibiz applies technical and organizational measures appropriate to risk, including encrypted connections, authentication, role-based access, workspace isolation, audit trails, activity logging, backups, recovery procedures, credential controls, monitoring, testing, and incident management.
Data is retained as needed for care, contracts, security, audits, disputes, tax obligations, and medical-record retention. Clinical-data retention follows health regulations and the provider's policy as data controller.
After the purpose and retention period end, data may be deleted, destroyed, or anonymized through reasonable procedures. Backup copies may remain until the backup cycle expires and are not used for ordinary operations unless required for recovery, security, legal defense, or a lawful obligation.
Subject to law and context, individuals may request information, access, a copy, correction, updating, restriction, cessation, deletion, withdrawal of consent, objection, portability, or review of automated decisions. A right may be limited by medical-record retention, evidence, security, other persons' rights, and applicable law.
Data relating to children, patients who cannot act for themselves, or represented patients is processed in a lawful care context through the healthcare provider and an authorized parent, guardian, companion, or representative. The provider is responsible for verifying authority and applying safeguards appropriate to the patient's interests.
Aibiz websites may use cookies or local storage for sessions, security, language selection, preferences, technical measurement, and user experience. Browser settings may restrict cookies, although some functions may not operate correctly.
Aibiz Insights provides educational material. Directories may include professional or facility information obtained from profile owners, public sources, and official sources. Data owners may request correction or updating with appropriate proof of authority.
This policy may be updated to reflect changes in services, integrations, technology, agreements, or law. The revision date appears at the top. Material changes may be communicated through the application, email, messaging, or another appropriate channel.
These links help users inspect the regulatory basis and external platform terms referenced in this policy.
https://peraturan.bpk.go.id/Details/229798/uu-no-27-tahun-2022.12UUDGovernment Regulation No. 71 of 2019 on Electronic Systems and TransactionsRules governing electronic systems and transactions in Indonesia.https://peraturan.bpk.go.id/Details/122030/pp-no-71-tahun-2019?id=fnbMinistry of Health Regulation No. 24 of 2022 on Medical RecordsRules for electronic medical records, retention, confidentiality, and record administration.https://jdih.kemkes.go.id/documents/peraturan-menteri-kesehatan-nomor-24-tahun-2022WhatsApp Business Terms of ServiceOfficial terms for WhatsApp applications, services, and APIs used by businesses.https://www.whatsapp.com/legal/business-terms/WhatsApp Business Messaging PolicyOfficial requirements for consent, message categories, quality, and business communication.https://business.whatsapp.com/policyMeta Privacy PolicyMeta's explanation of data processing across Meta products, including Facebook and Instagram.https://www.facebook.com/privacy/policy/Meta Platform TermsOfficial terms governing third-party use of Meta APIs and technologies.https://developers.facebook.com/terms/PT Aplikasi Alday Indonesia · AIBIZ.ID · Indonesia. Privacy requests, security questions, or incident notifications may be sent to support@aibiz.id with a subject identifying the relevant provider, account, and request type.