1. Scope and Application
For this Privacy Policy, "BizCloud", "we", "us" or "our" means BizCloud Asia Sdn Bhd (Registration No. 201301027403 (1057232-T)) and its authorised personnel, representatives, service providers and business units operating BMO.my, BizCloud services, HRM, Payroll, e-Leave, e-Claim, e-Attendance, POS, iCRM, Queue System, WhatsApp Business API solutions, AI features and related software or support services.
This Policy applies to website visitors, prospects, customers, administrators, employees of customers, end users, event participants, queue users, CRM contacts, WhatsApp users and other individuals whose personal data is processed through our websites, software, forms, support channels or business communications.
This Policy is issued under the Personal Data Protection Act 2010 as amended by the Personal Data Protection (Amendment) Act 2024, and reflects the obligations that came into force in stages during 2025, including mandatory data breach notification, mandatory appointment of a data protection officer, and the right to data portability.
2. Our Role: Data Controller or Data Processor
Our role depends on whose data is being processed and who decides how it is used. This distinction matters, because it determines who is legally responsible for notices, consent and regulator notification.
We act as data controller for our own business records, including enquiry and demo requests, website visitor and analytics data, sales and support communications, billing and subscription records, and platform telemetry and security logs.
We act as data processor for personal data that our customers enter, upload, import or generate inside their own BMO or BizCloud account in the course of running their own business. This includes employee, payroll, attendance, biometric, leave, claim, member, customer, contact and messaging records. For that data, the customer is the data controller and decides the purpose, the retention period, and who may access it.
If your personal data is held inside a customer's account, for example because you are an employee of a company that uses BMO Payroll, or a contact in a company's CRM, that company is the data controller. Please direct access, correction, withdrawal, portability and deletion requests to that company first. Where such a request is sent to us, we will refer it to the relevant customer administrator rather than act on it directly, unless the customer has instructed us otherwise in writing or the law requires otherwise.
3. Data Protection Officer
We have appointed a Data Protection Officer to oversee compliance with the PDPA, respond to data protection enquiries, and coordinate personal data breach handling.
Data Protection Officer: Data Protection Officer, BizCloud Asia Sdn Bhd
Email: sales@bizcloud.asia
Address: BizCloud Asia Sdn Bhd, Malaysia
Customers who are themselves data controllers may also be required to appoint their own data protection officer and to notify the Personal Data Protection Commissioner of that appointment. Our appointment does not satisfy that obligation for you.
4. Personal Data We May Collect
- Identity and contact details such as name, company, job title, phone number, email address and business address.
- Account and login information such as username, role, access permissions, login records, device tokens and system activity logs.
- HR and workforce data entered by customers into BMO HRM, payroll, attendance, e-Leave or e-Claim modules, including identification numbers, EPF, SOCSO, EIS and tax reference numbers, bank account details for salary crediting, salary, deductions, dependants and next-of-kin details.
- Attendance and time records, including clock-in and clock-out records, shift data, device identifiers and, where enabled by the customer, location or geofence readings.
- Customer, member, CRM, queue, service case, quotation, sales, POS, inventory or e-Invoice related data entered into subscribed modules.
- WhatsApp, SMS, email, chatbot and support conversation content, including attachments where submitted by users.
- Prompts, inputs and outputs associated with AI features, where those features are enabled by the customer.
- Technical data such as IP address, browser type, device information, cookies, usage logs, diagnostic data and security logs.
- Billing, subscription, payment reference and commercial records necessary for service administration.
5. Sensitive Personal Data and Biometric Data
Certain categories are treated as sensitive personal data under the PDPA and require explicit consent unless an exemption applies. Following the 2024 amendments, biometric data is expressly included in that category.
Depending on the modules a customer subscribes to and configures, the platform may hold: biometric templates or references used for fingerprint, facial or palm recognition clocking, kiosk access or POS login; health and medical certificate information submitted with leave or claim applications; disability status; religious information used for leave, dietary or scheduling settings; and records of offences or disciplinary action.
Where this data sits inside a customer account, the customer is the data controller and is responsible for obtaining explicit consent, for offering an alternative to biometric capture where consent is refused or required by law, and for lawful retention and deletion of biometric templates. We do not verify that such consent has been obtained.
Where biometric matching is performed on a third-party device or by a device vendor, that vendor's own privacy terms also apply.
6. Purposes of Processing
- To provide, configure, maintain and support subscribed software modules and cloud services.
- To respond to enquiries, demo requests, support tickets, WhatsApp messages, calls and sales communications.
- To manage user accounts, authentication, permissions, audit trails, service records and operational logs.
- To perform implementation, onboarding, training, troubleshooting, backup, security monitoring and service improvement.
- To operate AI and automation features that a customer has enabled, as described in Section 7.
- To issue invoices, manage subscriptions, collect payment, enforce contract terms and administer accounts.
- To send service notices, maintenance updates, renewal reminders, product information and lawful marketing communications.
- To detect, investigate and prevent fraud, abuse, unauthorised access and security incidents.
- To comply with legal, regulatory, tax, accounting, security, audit, dispute resolution and enforcement requirements.
Supplying personal data for account administration, service delivery, billing and statutory purposes is obligatory. If it is not supplied, we may be unable to provide the services or maintain the account.
7. Artificial Intelligence Processing
Some features use artificial intelligence, machine learning or large language models, supplied either by us or by third-party AI providers. Where a customer enables such a feature, prompts, inputs, documents or records reasonably necessary for that feature may be transmitted to an AI provider for processing, and that processing may take place outside Malaysia.
Content produced by these features is generated by a model, not written or verified by BizCloud Asia Sdn Bhd. It may be inaccurate or incomplete and must be reviewed by the customer before use. Section 9A of our User Agreement sets out the customer's review obligations in full.
Where we control the integration, we use commercially reasonable efforts to limit the data shared to what is reasonably necessary and to select provider settings that do not permit customer data to be used to train the provider's general-purpose models. We do not control every aspect of a third-party AI provider's processing, retention or subsequent policy changes.
Customers control whether AI features are enabled and which users may access them. Individuals whose data is held in a customer account should direct questions about AI use to that customer.
8. Automated Decision-Making and Profiling
Our systems may produce automated scores, classifications, reminders, anomaly flags, follow-up suggestions or draft replies, for example in CRM lead handling, attendance exception flagging or chatbot responses.
We do not use these to make final decisions that produce legal or similarly significant effects on individuals. Where a customer configures such features in its own account, the customer is responsible for ensuring meaningful human review before any decision affecting an individual, including decisions about hiring, dismissal, discipline, promotion, payroll adjustment, or rejection of a leave or claim application, and for recording that review.
9. Disclosure and Sharing
We do not sell personal data. We may disclose personal data only where reasonably necessary, including to the classes of parties below:
- Authorised personnel, contractors and implementation partners of BizCloud.
- Hosting, cloud infrastructure, storage, backup and content delivery providers.
- Messaging and communication providers, including WhatsApp Business API providers, SMS gateways, email delivery services and push notification services.
- Artificial intelligence and machine learning service providers, where AI features are enabled.
- Payment, banking and billing providers.
- Telephony, PBX and call-handling providers, where those integrations are enabled.
- Professional advisers, auditors and insurers.
- Government authorities, regulators, law enforcement and courts, where required or permitted by law.
- An acquirer or successor in connection with a reorganisation, merger or sale of business.
- Any other party to whom the customer or the individual has directed or consented to disclosure.
10. Categories of Sub-Processors
Where we act as data processor for customer account data, we engage sub-processors within the categories listed in Section 9. Current categories include cloud hosting and virtual private server providers, Google services used for push notification and file storage integrations, Meta WhatsApp Business Platform providers, SMS and email gateway providers, telephony providers, and AI model providers.
A current list of named sub-processors, and the countries in which they process data, is available to customers on written request to our Data Protection Officer. We may add or replace sub-processors as the services develop, and will use reasonable efforts to make updated information available to customers who have requested it.
11. Cross-Border Processing
Some service providers, cloud infrastructure, messaging providers, AI providers or support tools process data outside Malaysia. Following the 2024 amendments, transfers outside Malaysia are permitted where the receiving jurisdiction has a law substantially similar to the PDPA or ensures a level of protection at least equivalent to it, or where another statutory ground applies, including the consent of the data subject and transfers necessary for the performance of a contract.
Where we transfer data as data controller, we assess the destination and apply contractual safeguards where appropriate. Where we transfer data as data processor on a customer's instruction, the customer as data controller remains responsible for the lawfulness of the transfer and for conducting any transfer impact assessment required of it. We will provide reasonable information about relevant processing locations to support that assessment.
12. Security and Customer Responsibilities
We apply reasonable technical and organisational measures designed to protect personal data against accidental loss, misuse, unauthorised access, disclosure, alteration and destruction. Measures may include HTTPS/TLS transport encryption, access controls, role permissions, tenant separation, backup procedures, audit logging, administrative safeguards and restricted internal access.
Following the 2024 amendments, data processors are directly subject to the Security Principle. We maintain measures appropriate to the processing we perform on customers' behalf.
No website, cloud service, internet transmission, WhatsApp communication, email or storage system can be guaranteed completely secure. Customers are responsible for managing authorised users, passwords, multi-factor settings where available, internal access approvals, device security, data accuracy, employee consent, payroll review, statutory review and lawful use of the subscribed modules.
13. Personal Data Breach Notification
Where we become aware of a personal data breach affecting data for which we are the data controller, we will notify the Personal Data Protection Commissioner in accordance with the statutory timeline, and will notify affected individuals without undue delay where the breach is likely to cause significant harm.
Where we become aware of a security incident affecting customer account data for which we act as data processor, we will notify the affected customer without undue delay and provide reasonable information to help that customer assess the incident. The obligation to notify the Commissioner and affected individuals rests with the customer as data controller. Customers should ensure their own breach response procedure, internal escalation contact and record-keeping register are in place.
To report a suspected security issue or data breach involving our services, contact our Data Protection Officer at sales@bizcloud.asia without delay. Please do not include passwords, access tokens or full copies of affected records in the initial report.
14. Retention
We retain personal data for as long as reasonably necessary to provide services, support customer accounts, meet legal and accounting obligations, resolve disputes, enforce agreements, maintain backups and protect legitimate business interests.
For customer account data where we act as data processor, the customer determines the retention period. Customers should note that Malaysian law imposes minimum retention periods on employers and businesses, including for employment registers, payroll records and tax records, and should set retention accordingly. We do not delete customer account records without an authorised instruction, except as permitted by our own retention practices after termination.
Backup data may remain for a limited period after deletion from active systems due to technical backup cycles and disaster recovery practices. We maintain a record of personal data breaches for the period required by law.
15. Access, Correction, Portability and Choices
Subject to applicable law, you may request access to, correction of, or information about your personal data processed by us. You may also withdraw consent, limit processing, request that we cease processing for direct marketing purposes, and, where the amended PDPA applies and the request is technically feasible and format-compatible, request that your personal data be transmitted directly to another data controller.
To exercise these rights, contact our Data Protection Officer using the details in Section 3. We may need to verify your identity, and a prescribed fee may apply to a data access request where permitted by law. We will respond within the period required by law.
We may decline requests where permitted by law, where data belongs to a customer-controlled account, or where disclosure would affect another person, security, legal privilege, investigations or contractual obligations.
If your data is controlled by your employer or another customer using our software, please contact that organisation first. We may redirect your request to the relevant customer administrator.
16. Cookies and Website Technologies
Our websites may use cookies, logs and similar technologies to operate the website, remember preferences, improve performance, analyse traffic, secure sessions and support marketing or enquiry workflows. You may adjust browser settings to reject cookies, but some functions may not work properly. Where a cookie consent tool is presented, your choices are recorded and can be changed at any time.
17. Third-Party Links and Platforms
Our websites and services may link to third-party websites, WhatsApp, email providers, payment providers, government portals or external services. We are not responsible for the privacy practices, security or content of third-party platforms. Deletion of data held by Meta platforms is addressed in our Meta Data Deletion Instructions.
18. Children
Our services are business tools and are not directed to children. Where a customer processes data relating to individuals under 18, for example students, dependants or young workers, the customer as data controller is responsible for obtaining consent from a parent or guardian where required by law.
19. Updates to This Policy
We may update this Privacy Policy from time to time to reflect changes in our services, legal obligations or operational practices. The version and date are shown at the top of this page. Continued use of our website or services after changes are posted means you acknowledge the updated Policy. Where a change is material, we may require account administrators to accept the updated Policy in-product.
20. Contact Us
BIZCLOUD ASIA SDN. BHD. (Registration No. 201301027403 (1057232-T))
General: sales@bizcloud.asia
Data Protection Officer: sales@bizcloud.asia
WhatsApp / Phone: +6016 450 2380
If you are not satisfied with our response, you may lodge a complaint with the Personal Data Protection Department (Jabatan Perlindungan Data Peribadi), Malaysia.