Aibiz Privacy

Privacy Policy for every Aibiz service.

This policy explains how PT Aplikasi Alday Indonesia processes and protects data across AIBIZ.ID, Aibiz Medical, Aibiz Wagen, Meta channels, and all connected modules and integrations.

Updated 14 August 2026Covers healthcare users and patientssupport@aibiz.id

One policy for a connected ecosystem

Aibiz separates processing roles by context. For commercial relationships, websites, accounts, security, and support, Aibiz may act as a data controller. For patient and care data managed in a healthcare provider's workspace, the healthcare provider generally determines the purposes and Aibiz processes the data under documented instructions, agreements, and applicable law.

Who is covered

01

Healthcare providers

Owners, managers, administrators, doctors, health professionals, staff, and operational partners using the services.

02

Patients and representatives

Patients, prospective patients, companions, guardians, or authorized representatives whose data is processed through a provider.

03

Business-channel users

Consumers, prospects, business contacts, and users of WhatsApp, Instagram, Facebook, email, forms, or other channels.

04

Visitors and integrators

Website visitors, developers, system providers, medical-device providers, and parties connecting services through APIs.

Contents
Identity and scopeRoles of Aibiz, healthcare providers, and usersCategories of data we may processSources of dataPurposes and legal basesElectronic medical records and health dataAI, Aibiz Scribe, and automationWhatsApp, Instagram, Facebook, and Meta servicesIntegrations and recipientsStorage location and international transfersSecurity and access restrictionsRetention, deletion, and destructionData-subject rights and requestsChildren, represented patients, and special circumstancesWebsites, cookies, Insights, and directoriesPolicy changes and contact

1. Identity and scope

This policy is issued by PT Aplikasi Alday Indonesia as the provider of AIBIZ.ID and applies to websites, web and mobile applications, APIs, dashboards, communication channels, implementation services, support, and integrations operating under the Aibiz brand.

It covers Aibiz Medical and EMR modules; Aibiz Scribe; Aibiz Imaging, RIS, PACS, DICOM, viewers, and Modality Worklist; Aibiz Lab and LIS; Aibiz Scan; Aibiz Wagen, CRM, team inbox, booking, reminders, follow-up, and owner assistant; Aibiz directories and Insights; and any other feature stated to be governed by this policy.

2. Roles of Aibiz, healthcare providers, and users

Healthcare providers determine the purposes of care, legal basis, authorized users, medical-record content, patient communications, and workspace operating policies. In this context, the provider generally acts as controller of patient data and Aibiz as processor or service provider acting on lawful instructions.

Aibiz may act as controller for account, prospect, contract, payment, security, audit, support, website analytics, and direct Aibiz communication data. Specific roles may be further defined in a proposal, service agreement, NDA, DPA, SLA, or implementation document.

  • Healthcare providers are responsible for privacy notices and for obtaining consent or another required legal basis.
  • Users must access data only within their role, authority, care purpose, and organizational policy.
  • Patients may submit clinical-data requests to their healthcare provider; Aibiz supports the provider under the agreed procedure.

3. Categories of data we may process

Identity and account data

Name, email, phone number, organization, position, role, encrypted credentials, professional identity, licenses or permits, preferences, and access history.

Patient and health data

Patient identity, demographics, complaints, history, examinations, diagnoses, procedures, prescriptions, allergies, lab results, imaging, documents, referrals, summaries, consent, and other care data.

Communication data

Message content, attachments, audio, transcripts, delivery status, timing, channel identifiers, conversation notes, agent assignments, and human-handoff history.

Operational and transaction data

Bookings, schedules, queues, inventory, pharmacy, billing, invoices, payments, transaction status, reports, CRM activities, reminders, follow-up, and lawful campaigns.

Imaging, lab, and device data

DICOM, accession numbers, worklists, radiology images and reports, laboratory orders and results, device identifiers, device messages, and local-server metadata.

Technical and security data

IP address, device and browser type, access time, cookies, session tokens, application logs, audit trails, API logs, telemetry, errors, backups, and anti-abuse signals.

4. Sources of data

Data may come directly from users; healthcare providers or professionals; patients, representatives, or consumers; medical devices and local servers; enabled integrations; Meta or communications providers; official government sources; and lawful public sources used for directories or professional verification.

  • Data entered, uploaded, recorded, scanned, or sent by an authorized user.
  • Data generated as the service operates booking, EMR, billing, integrations, security, and support.
  • Data received through webhooks, APIs, medical devices, SATUSEHAT, WhatsApp, Instagram, email, calendars, or user-selected third parties.

5. Purposes and legal bases

The legal basis may include performance of a contract, legal obligations, consent, protection of vital interests, performance of lawful functions, and permitted legitimate interests. The applicable basis depends on the context, data, and relationship between the parties.

Service delivery

Creating accounts and workspaces and operating EMR, booking, queues, documentation, prescriptions, billing, CRM, communications, imaging, labs, integrations, reporting, and support.

Security and reliability

Authenticating users, enforcing permissions, preventing abuse, diagnosing incidents, retaining audit trails, recovering data, and maintaining continuity.

Compliance

Meeting contractual, medical-record, privacy, electronic-system, tax, rights-enforcement, lawful government-request, and audit requirements.

Controlled improvement

Measuring performance, fixing features, testing quality, and developing services using minimized, aggregated, anonymized, or otherwise properly authorized data.

6. Electronic medical records and health data

Health data is personal data requiring heightened protection. Aibiz Medical provides the technical means to record and exchange data; healthcare professionals and providers remain responsible for content, accuracy, completeness, authorization, access, correction, disclosure, and clinical use of medical records.

Access is restricted by role and workspace. Users may not view, copy, export, or share patient data without authority and a lawful purpose. Medical-record corrections must preserve traceability under provider policy and applicable rules.

7. AI, Aibiz Scribe, and automation

Aibiz Scribe may convert audio or conversations into structured transcripts and clinical-documentation drafts. The output may be normalized for the EMR context but must be reviewed and approved by an authorized user before becoming a final record.

Aibiz Wagen may classify messages, answer questions, support booking, reminders, follow-up, task assignment, and operational insights. Human handoff is supported. AI output is assistive and does not replace diagnosis, professional judgment, clinical consent, or emergency care.

Health data is not sold. Customer data is used to train a general-purpose model outside service delivery only where the required legal basis, authority, and written arrangement are in place.

8. WhatsApp, Instagram, Facebook, and Meta services

When a provider or business connects a Meta account, Aibiz may process business-account identity, phone number, account identifiers, available public profile data, messages, media, templates, webhooks, sent or read status, authorized comments or interactions, and API-provided metrics.

WhatsApp, Instagram, Facebook, and Meta also process data under their own terms and privacy policies. Some processing may occur on Meta's global infrastructure. Aibiz requests only the permissions and data required for enabled features.

  • Providers or businesses must have the rights, notices, and consent required before contacting a person through WhatsApp or another Meta channel.
  • Users must honor opt-outs, blocking, withdrawn consent, template categories, conversation windows, and Meta quality policies.
  • Sensitive health messages should be minimized and aligned with patient instructions and provider policy.
  • WhatsApp and social channels are not emergency services. Emergencies must be directed to an appropriate emergency channel.

9. Integrations and recipients

Depending on enabled features, data may be processed by or exchanged with infrastructure and cloud providers, Meta and communications channels, the Ministry of Health SATUSEHAT platform, hospital or clinic systems, LIS, RIS, PACS, Orthanc, medical devices, local servers, email, calendars, payments, notifications, analytics, security, and support services.

  • Integrations operate under the configuration and instructions of an authorized user.
  • Service providers receive limited access for their function and are subject to relevant confidentiality, security, or data-processing terms.
  • Independent third parties may have their own policies and terms, which users should review before enabling an integration.

10. Storage location and international transfers

Aibiz's primary infrastructure operates on servers in the Jakarta region, Indonesia. Some data may remain on a provider's local device or server for medical-device integration and operational continuity.

Third parties, including Meta, may process data outside Indonesia as part of their global operations. For cross-border processing, Aibiz and customers apply applicable legal and contractual requirements, protection assessments, and safeguards according to their roles.

11. Security and access restrictions

Aibiz applies technical and organizational measures appropriate to risk, including encrypted connections, authentication, role-based access, workspace isolation, audit trails, activity logging, backups, recovery procedures, credential controls, monitoring, testing, and incident management.

  • Users must secure passwords, devices, sessions, tokens, and connected third-party accounts.
  • Shared access, transferred credentials, or use outside an assigned role is prohibited.
  • No system is entirely risk-free. An incident affecting data will be handled and notified according to legal duties and the parties' respective roles.

12. Retention, deletion, and destruction

Data is retained as needed for care, contracts, security, audits, disputes, tax obligations, and medical-record retention. Clinical-data retention follows health regulations and the provider's policy as data controller.

After the purpose and retention period end, data may be deleted, destroyed, or anonymized through reasonable procedures. Backup copies may remain until the backup cycle expires and are not used for ordinary operations unless required for recovery, security, legal defense, or a lawful obligation.

13. Data-subject rights and requests

Subject to law and context, individuals may request information, access, a copy, correction, updating, restriction, cessation, deletion, withdrawal of consent, objection, portability, or review of automated decisions. A right may be limited by medical-record retention, evidence, security, other persons' rights, and applicable law.

  • For care or medical-record data, submit the request to the healthcare provider that delivered the service.
  • For Aibiz accounts, websites, business communications, or where a provider cannot be reached, contact support@aibiz.id.
  • Aibiz or the provider may verify identity, authority, relationship to the patient, and request details to prevent unauthorized disclosure.

14. Children, represented patients, and special circumstances

Data relating to children, patients who cannot act for themselves, or represented patients is processed in a lawful care context through the healthcare provider and an authorized parent, guardian, companion, or representative. The provider is responsible for verifying authority and applying safeguards appropriate to the patient's interests.

15. Websites, cookies, Insights, and directories

Aibiz websites may use cookies or local storage for sessions, security, language selection, preferences, technical measurement, and user experience. Browser settings may restrict cookies, although some functions may not operate correctly.

Aibiz Insights provides educational material. Directories may include professional or facility information obtained from profile owners, public sources, and official sources. Data owners may request correction or updating with appropriate proof of authority.

16. Policy changes and contact

This policy may be updated to reflect changes in services, integrations, technology, agreements, or law. The revision date appears at the top. Material changes may be communicated through the application, email, messaging, or another appropriate channel.

Official references

These links help users inspect the regulatory basis and external platform terms referenced in this policy.

Law No. 27 of 2022 on Personal Data ProtectionThe Indonesian basis for data-subject rights and controller and processor obligations.https://peraturan.bpk.go.id/Details/229798/uu-no-27-tahun-2022.12UUDGovernment Regulation No. 71 of 2019 on Electronic Systems and TransactionsRules governing electronic systems and transactions in Indonesia.https://peraturan.bpk.go.id/Details/122030/pp-no-71-tahun-2019?id=fnbMinistry of Health Regulation No. 24 of 2022 on Medical RecordsRules for electronic medical records, retention, confidentiality, and record administration.https://jdih.kemkes.go.id/documents/peraturan-menteri-kesehatan-nomor-24-tahun-2022WhatsApp Business Terms of ServiceOfficial terms for WhatsApp applications, services, and APIs used by businesses.https://www.whatsapp.com/legal/business-terms/WhatsApp Business Messaging PolicyOfficial requirements for consent, message categories, quality, and business communication.https://business.whatsapp.com/policyMeta Privacy PolicyMeta's explanation of data processing across Meta products, including Facebook and Instagram.https://www.facebook.com/privacy/policy/Meta Platform TermsOfficial terms governing third-party use of Meta APIs and technologies.https://developers.facebook.com/terms/

Privacy and data-protection contact

PT Aplikasi Alday Indonesia · AIBIZ.ID · Indonesia. Privacy requests, security questions, or incident notifications may be sent to support@aibiz.id with a subject identifying the relevant provider, account, and request type.