Privacy Policy
Last updated: February 2026
SŌMA Aesthetics & Longevity Club ("SŌMA," "we," "our," or "us") is committed to protecting your privacy and personal data. This Privacy Policy explains how we collect, use, store, and protect information when you visit our website (www.somalongevityclub.com), use our services, or communicate with us.
We operate in compliance with applicable Indonesian data protection laws, including Law No. 27 of 2022 on Personal Data Protection (UU PDP).
By using our website or services, you acknowledge that you have read and understood this Privacy Policy.
1. Information We Collect
Personal Information You Provide
When you book an appointment, enquire about services, or visit our clinic, we may collect:
-
Full name, date of birth, gender, and nationality
-
Contact details including email address, phone number, and WhatsApp number
-
Postal address or accommodation address in Bali
-
Emergency contact information
-
Payment and billing information
Medical and Health Information
As a medical aesthetics and longevity clinic, we collect health-related data necessary to provide safe and effective treatment, including:
-
Medical history, allergies, and current medications
-
Treatment records and clinical notes
-
Blood test results and diagnostic reports
-
Photographs taken for treatment planning and progress documentation
-
Consent forms and treatment agreements
Information Collected Automatically
When you visit our website, we may automatically collect:
-
IP address and approximate geographic location
-
Browser type, device type, and operating system
-
Pages visited, time spent on pages, and referring website
-
Cookies and similar tracking technologies (see Section 6 below)
2. How We Use Your Information
We use the information we collect for the following purposes:
-
To provide, personalise, and improve our medical and aesthetic treatments
-
To communicate with you about appointments, treatment plans, results, and follow-up care
-
To process payments and maintain financial records
-
To comply with medical record-keeping obligations under Indonesian law
-
To send you information about our services, promotions, or health-related content (only with your consent)
-
To improve our website, services, and patient experience
-
To comply with legal and regulatory requirements
We will never sell your personal information to third parties.
3. How We Share Your Information
We may share your information with the following parties, only as necessary:
-
Medical and laboratory partners: Accredited Indonesian laboratories that process blood tests and diagnostic samples on our behalf. Only the minimum data required for testing is shared.
-
Payment processors: Secure third-party payment services (credit card processors, QRIS, WISE, PayPal) to process your transactions. We do not store full credit card details.
-
Technology providers: Our website is hosted by Wix.com Ltd. and may use analytics services such as Google Analytics. These providers process data in accordance with their own privacy policies.
-
Legal and regulatory authorities: Where required by Indonesian law, court order, or regulatory request.
-
Professional advisors: Accountants, auditors, or legal advisors bound by professional confidentiality obligations.
We do not share your medical records with any third party without your explicit written consent, except where required by law.
4. Data Storage and Security
We take reasonable technical and organisational measures to protect your personal and medical data, including:
-
Secure storage of digital records with access limited to authorised medical and administrative staff
-
Encryption of sensitive data transmitted via our website
-
Physical security measures at our clinic for paper-based records
-
Regular review of our data handling practices
Medical records are retained for the minimum period required by Indonesian medical regulations. Upon expiry of the retention period, records are securely destroyed.
Your data may be processed or stored on servers located outside Indonesia through our technology providers (such as Wix and Google). Where this occurs, we take reasonable steps to ensure adequate data protection standards are maintained.
5. Your Rights
Under Indonesian data protection law, you have the right to:
-
Access your personal data that we hold
-
Correct inaccurate or incomplete data
-
Request deletion of your personal data, subject to legal retention requirements
-
Withdraw consent for marketing communications at any time
-
Request a copy of your personal data in a portable format
-
Object to certain processing of your data
To exercise any of these rights, please contact us using the details provided in Section 9 below. We will respond to your request within 30 days.
6. Cookies and Tracking
Our website uses cookies and similar technologies to improve your browsing experience. These include:
-
Essential cookies: Required for basic website functionality, such as navigation and page loading.
-
Analytics cookies: Used to understand how visitors interact with our website (e.g., Google Analytics). These collect anonymised, aggregated data.
-
Third-party cookies: Our website may contain embedded content from third parties (such as Instagram or Google Maps) that may set their own cookies.
You can manage your cookie preferences through your browser settings. Disabling cookies may affect certain website functionality.
Our website is built on the Wix platform, which uses its own cookies. You can review Wix's cookie policy at wix.com/about/privacy.
7. Communication via WhatsApp
We use WhatsApp Business as a primary communication channel for appointment booking, enquiries, and sharing treatment information. By initiating or responding to WhatsApp communication with us, you consent to receiving messages via this channel.
WhatsApp messages are encrypted end-to-end by WhatsApp (operated by Meta Platforms, Inc.). We do not control WhatsApp's data practices. Please review WhatsApp's privacy policy for information about how they handle your data.
We will never share sensitive medical results via WhatsApp unless you explicitly request this and provide consent.
8. Marketing Communications
We may send you information about our services, promotions, or health-related content via email or WhatsApp. We will only do so with your prior consent.
You may withdraw your consent and opt out of marketing communications at any time by:
-
Replying "STOP" to any WhatsApp marketing message
-
Clicking the unsubscribe link in any marketing email
-
Contacting us directly using the details below
Opting out of marketing will not affect communications related to your booked appointments or treatment care.
9. Children's Privacy
Our services are intended for individuals aged 18 and over. We do not knowingly collect personal data from children under 18. Certain treatments may be provided to individuals aged 16-17 with written parental or guardian consent, in which case we collect only the data necessary for treatment.
10. Changes to This Policy
We may update this Privacy Policy from time to time to reflect changes in our practices, technology, or legal requirements. The updated policy will be posted on this page with a revised "Last updated" date. We encourage you to review this page periodically.
11. Contact Us
If you have questions, concerns, or requests regarding this Privacy Policy or your personal data, please contact us:
SŌMA Aesthetics & Longevity Club Jl. Pantai Padang-Padang, Jl. Pantai Suluban, Pecatu, Kec. Kuta Sel., Kabupaten Badung, Bali 80361
-
WhatsApp: +62 811 2522 8000
-
Phone: +62 811 2522 8000
-
We aim to respond to all privacy-related enquiries within 7 business days.
