Privacy & Security

Health data, protected the way it should be.

How Livewell protects workforce health data — privacy, encryption, access control, and compliance with Indonesia's Personal Data Protection Law (PDP Law No. 27/2022).

Aggregate & anonymous by default

Company & broker dashboards show only aggregate data. Individual scores are never exposed to HR or brokers.

Encrypted in transit & at rest

Data is encrypted (TLS in transit, encryption at rest), with separation between identity and health data.

Consent & user rights

Employees give consent and can access, correct, and request deletion of their data under Indonesia's PDP Law.

Data minimization & purpose limits

Only data necessary for health & wellness is collected, and used solely for that purpose.

Audit-ready governance

Access is logged. Aligned with our Plebo partner facility standards (Medias by Plebo: ISO 9001/14001/45001, PJK3 Kemnaker).

Data protection contact

Privacy questions or data-rights requests can be sent to admin@livewellindo.com.

Effective: June 2026

1. Data controller

This service is operated by PT Livewell Indonesia Sehat (“Livewell”, “we”), in partnership with our healthcare facility partners (Plebo — OneLab & Medias — as well as OlabPro). For privacy questions: admin@livewellindo.com.

2. Data we collect

  • Profile data: name, email, department/company.
  • Activity & wellness data from the Livewell apps (steps, program participation, points).
  • Health data: MCU & screening results, only if you join a related program.
  • Technical data: device, logs, and essential cookies to run the service.

3. Legal basis for processing (PDP Law)

We process data based on your consent, performance of the service contract, compliance with legal obligations, and balanced legitimate interests — under Law No. 27/2022 on Personal Data Protection. Health data is treated as specific personal data with stricter protection.

4. How data is used

To provide wellness & MCU services, surface aggregate health insights to companies/brokers, recommend interventions, and improve the service. Companies & brokers never see individual health data — only aggregates per department/population.

5. Sharing & disclosure

We do not sell personal data. Data may be shared with: (a) our healthcare facility partners (Plebo — OneLab & Medias — as well as OlabPro) for clinical follow-up where you consent; (b) trusted processors (hosting, analytics) under data-processing agreements; (c) authorities where legally required. To companies/brokers, only aggregate & anonymized data.

6. Storage & retention

Data is stored on secure infrastructure and retained for as long as necessary for the purposes above or as required by law, then deleted or anonymized. Health data follows applicable medical-record retention standards.

7. Security

Encryption in transit (TLS) and at rest, separation of identity and health data, role-based access control, and access logging. Aligned with our Plebo partner facility standards (Medias by Plebo: ISO 9001/14001/45001, PJK3 Kemnaker RI).

8. Your rights

You may access, correct, restrict, and delete your personal data, obtain a copy, and withdraw consent at any time without affecting prior lawful processing. Send requests to admin@livewellindo.com; we respond within PDP-Law timelines.

9. Cookies

We use essential cookies for authentication & preferences (e.g. language, demo mode). No third-party advertising trackers are embedded.

10. Children

The service is intended for adult employees and is not directed to children under 18 without parental/guardian consent as applicable.

11. Changes & contact

This policy may be updated; material changes will be notified. The full privacy policy & data-processing agreement (DPA) are available to enterprise clients on request. Contact: admin@livewellindo.com.

This document is Livewell's standard policy and should be reviewed by your legal counsel before relying on it contractually.