// 1. summary
Quick summary
Webiti (webiti.id) is a website-building studio based in Madiun, Indonesia. We collect the minimum data needed to: (a) run the site correctly, (b) respond to contact messages from prospective clients, and (c) measure content performance through anonymous analytics. We do not sell your data to third parties. You have the right to request deletion of your data at any time by emailing sales@webiti.id.
// 2. data we collect
Data we collect
a. When you fill out the contact / newsletter form
- Name (contact form)
- Email address
- WhatsApp number (optional, contact form)
- Type of website you're interested in (contact form)
- Message / short brief (contact form)
- IP address (for rate-limiting & anti-spam)
Legal basis: consent (you voluntarily submit that form) — PDP Law Article 20 paragraph (1) letter a.
b. When you browse the site (automatic)
- Google Analytics 4: anonymous pageviews, visit duration, device & browser, traffic source, approximate location (city — not precise). IP is anonymized via
anonymize_ip. Cookies_ga,_ga_*. 14-month retention. - Microsoft Clarity: activity heatmaps (clicks, scrolls), approximate navigation paths. All form input is automatically masked via
clarity('set','mask','*')— we do not record the contents of email/WhatsApp/brief fields. 90-day retention. - Google Ads conversion tag (when a campaign is active): measures whether an ad click becomes a contact lead. Stores no personal data beyond the Google ID.
- Server log: IP & user-agent for rate-limiting. Not merged with personal identity. 7-day retention.
Legal basis for analytics: legitimate interest — measuring traffic to improve the site (PDP Law Article 20 paragraph (1) letter f). You can opt out using tracker-blocking extensions (uBlock Origin, Privacy Badger) or private/incognito mode — both block the analytics scripts (GA4, Clarity) before they load. This is more effective and portable than a per-site banner.
// 3. purpose
How we use your data
- Communication: Responding to your questions via email or WhatsApp.
- Operations: Sending quotes, invoices, and project documentation if you become a client.
- Analytics: Understanding which content helps and what devices visitors use — improving UX and SEO. Aggregate data, never viewed per individual.
- Security: Detecting form abuse (spam, bots), protecting server infrastructure.
We do not use your data for automated profiling, personally targeted ads, or selling to data brokers.
// 4. third parties
Third parties that receive data
We share minimal data with the following processors. They may not use the data for their own purposes.
- Vercel Inc. (United States) — site hosting & content delivery. Subject to Vercel's DPA.
- Google LLC (United States) — Google Analytics 4, Google Ads, Google Fonts. See Google's Privacy Policy (opens in new tab).
- Microsoft Corporation (United States) — Clarity heatmaps. See Microsoft's Privacy Statement (opens in new tab).
- Resend Inc. (United States) — transactional email delivery (contact, newsletter). The email recipient is only our internal address sales@webiti.id.
Data may cross national borders (cross-border transfer) because of the processors above. Per PDP Law Article 56, we ensure the destination country provides an equivalent level of protection or the processor is bound by standard contractual clauses.
// 5. your rights
Your rights (PDP Law Articles 5–12)
As a data subject, you have the right to:
- Know what we store about you
- Request correction of inaccurate data
- Request deletion of data (right to be forgotten)
- Opt out of analytics via incognito mode or tracker-blocking extensions
- Obtain a copy of your data (portability)
- File a complaint with the Personal Data Protection Commission (Komdigi — Ministry of Communication and Digital Affairs of Indonesia)
To exercise the rights above, email sales@webiti.id with the subject [PDP]. We respond within 3×24 business hours and resolve requests within 30 calendar days, in accordance with PDP Law Article 16 paragraph (3).
// 6. analytics opt-out
How to opt out of analytics
We don't use a cookie banner. Instead, opt-out is available at the browser / device level:
- Enable Do Not Track (DNT) (opens in new tab) in your browser to signal your privacy preference. To actually stop analytics, use one of the options below
- Install a privacy extension such as uBlock Origin (opens in new tab) or Privacy Badger (opens in new tab)
- Use private / incognito mode
- Install the Google Analytics Opt-out Browser Add-on (opens in new tab)
// 7. security
How we protect your data
- HTTPS with HSTS preload (2 years) — the connection is always encrypted
- Form rate-limiting (5 submissions per 10 minutes per IP) — prevents spam
- Anti-bot honeypot + server-side validation for all input
- Clarity form masking (
mask='*') — field contents are never recorded in session replay - GA4 with
anonymize_ip— the last IP octet is truncated before reaching Google - No password storage (we have no user-account system)
- Transactional email uses DKIM + SPF — prevents spoofing
// 8. children
Children under age
This site is intended for adult business owners (age ≥ 17). We do not knowingly collect data from children. If you believe your child has provided data to us, contact sales@webiti.id for immediate deletion.
// 9. changes
Policy changes
If this policy changes, we update the “Last updated” date above and, for material changes, notify you via an on-page banner or email (if you're subscribed to the newsletter). Previous versions can be requested via sales@webiti.id.
// 10. contact
Contact us
Privacy questions or requests:
- Email: sales@webiti.id (subject
[PDP]for fast-track) - WhatsApp: +62 823-1333-3614
- Studio: Studio Webiti, Madiun, Jawa Timur, Indonesia
For independent complaints about data processing, contact the Ministry of Communication and Digital Affairs of Indonesia (Komdigi) as Indonesia's data protection authority.