1. Acceptance of Terms
By accessing our websites, requesting a demo, logging into a system, using a trial, subscribing to any module, clicking to accept in-product, or allowing users to access our services, you agree to this User Agreement, our Privacy Policy and any quotation, order form, service scope, invoice, subscription plan, support arrangement or written agreement issued by BizCloud Asia Sdn Bhd (Registration No. 201301027403 (1057232-T)) ("BizCloud", "we", "us").
If you act for a company, employer, association or organisation, you confirm that you are authorised to bind that organisation. If you do not agree, you must not use the website or services.
1.1 Electronic Acceptance and Record of Acceptance
Acceptance may be given electronically, including by clicking "I Agree", ticking an acceptance box, signing electronically, or by continued use of the services after notice of updated terms. You agree that electronic acceptance has the same legal effect as a signed document under the Electronic Commerce Act 2006 and the Digital Signature Act 1997.
We maintain an acceptance log recording the accepting user account, company account, document version, date, time, IP address and device information. You agree that these records, and computer-generated records of your use of the services, may be produced as evidence of acceptance and of the terms in force at the relevant time, including under section 90A of the Evidence Act 1950.
1.2 Re-Acceptance on Material Change
Where we materially update this Agreement or the Privacy Policy, we may require authorised users to accept the updated version before continuing to use the services. Refusal to accept may result in restricted access to affected features.
1A. Order of Precedence
If there is a conflict between documents, the following order applies, from highest to lowest priority, unless a document expressly states that it overrides this clause:
- A separately signed written agreement between you and BizCloud.
- The accepted quotation, order form, proposal or service scope.
- Module-specific terms in Section 6B of this Agreement.
- This User Agreement.
- The Privacy Policy.
- Any other documentation, marketing material, brochure, feature list, demonstration or verbal representation.
Marketing material, screenshots, demonstrations, roadmaps and verbal statements are not contractual commitments and do not form part of the agreed scope unless expressly written into a quotation or signed agreement.
2. Services and Scope
BizCloud Asia Sdn Bhd may provide cloud business software and related services including BMO HRM, payroll, e-Leave, e-Claim, e-Attendance, POS, CRM, iCRM, inventory, membership, accounting/e-Invoice preparation, Queue System, WhatsApp Business API chatbot, AI and automation features, implementation, training, support, hosting and related modules.
The exact functions, limits, support level, implementation scope, customisation, integrations, users, storage, message volume, AI usage allowance and commercial terms are determined by the subscribed package, quotation, invoice, written agreement or accepted service scope.
2A. Cloud, Client-Hosted and On-Premise Services
Services may be provided as cloud-hosted services managed by BizCloud Asia Sdn Bhd or as client-hosted, PC-hosted, local server, NAS, virtual machine, third-party hosting or on-premise installations, depending on the agreed scope.
For cloud services, we are responsible only for the application, database and infrastructure elements that are within our control and service scope. For client-hosted or on-premise installations, our responsibility is limited to the BMO software under active maintenance or support. The customer remains responsible for hardware, operating system, network, internet connectivity, antivirus, firewall, power protection, backup, restore testing, access control, physical security, third-party hosting and local environment maintenance.
We are not liable for data loss, corruption, downtime, ransomware, malware, disk failure, operating system failure, user deletion, misconfiguration, expired licences or unavailable backups caused by customer-controlled environments. Recovery, repair or reconfiguration work outside the subscribed support scope may be chargeable.
3. Accounts, Access and Security
Customers are responsible for all activities under their accounts and user credentials. You must ensure authorised users keep passwords confidential, use appropriate access permissions, remove users who no longer require access and notify us promptly of suspected unauthorised access.
We are not responsible for losses caused by weak passwords, shared accounts, unauthorised internal users, compromised devices, inaccurate data entry, customer-side approval failures or misuse of administrator permissions.
You are responsible for reviewing and maintaining role permissions, approval workflows and segregation of duties inside your account, particularly for payroll approval, claim approval, leave approval, discount authority, void transactions, price overrides, stock adjustment, credit note issuance and data export rights.
4. Customer Data and Customer Responsibilities
Customers retain responsibility for data entered, uploaded, imported, transmitted or generated through the services, including employee, payroll, tax, attendance, biometric, claim, leave, customer, member, queue, CRM, WhatsApp, POS, inventory and accounting data.
You represent that you have obtained all consents, notices, permissions and legal bases needed to collect, process and submit customer data through our systems. You grant us a limited, non-exclusive licence to host, process, transmit, back up and display customer data solely to provide, support, secure and maintain the services.
If the services include file management or document storage, customer files may be stored in the cloud or in customer-controlled storage depending on setup. Where files are stored on customer devices, mapped drives, local servers or third-party storage, the customer is solely responsible for backup, redundancy, antivirus, encryption, access control and physical security.
4A. Customer Verification Duty
This is a fundamental obligation of the customer and a condition of use of the services. The services generate figures, documents, files, messages and reports from data that the customer supplies and settings that the customer configures. Output is only as accurate as that input and configuration.
Before any payment, disbursement, statutory submission, tax filing, e-Invoice submission, bank file upload, customer communication, WhatsApp broadcast, published document or business decision, the customer must have an authorised and competent person independently check and approve the relevant output. This applies to every service and module, including but not limited to:
- Salary, wages, overtime, allowances, deductions, unpaid leave, prorated pay, bonus, commission and final settlement figures.
- PCB/MTD, EPF/KWSP, SOCSO/PERKESO, EIS/SIP, HRDF/HRD Corp, EA forms, CP8D, CP21/CP22/CP22A and any statutory rate, ceiling, category or exemption setting.
- Leave balances, carry-forward, entitlement tables, prorated entitlement, replacement leave, and statutory minimum entitlements under the Employment Act 1955 and its amendments.
- Claim amounts, claim limits, approval routing, mileage rates and reimbursement categories.
- Attendance, clock-in/out records, shift assignment, overtime eligibility, rest day and public holiday treatment.
- Accounting entries, tax codes, SST settings, chart of accounts mapping, opening balances, e-Invoice profiles, TIN, MSIC and classification codes.
- Customer and supplier master data, pricing, discounts, stock counts, costing and inventory valuation.
- Any AI-generated or automation-generated text, summary, reply, classification, score, recommendation or draft document.
BizCloud Asia Sdn Bhd does not review, audit, certify or approve customer data or output. We do not provide accounting, tax, audit, payroll, legal, HR or statutory advice, and we are not a licensed tax agent under section 153 of the Income Tax Act 1967, a registered company secretary, an audit firm or a firm registered under the Accountants Act 1967. Where such advice is required, you must engage an independent qualified professional.
Failure to perform this verification is a customer failure. We are not liable for any loss, penalty, fine, back-payment, interest, surcharge, dispute, reputational harm or third-party claim caused wholly or partly by output that the customer did not verify before use.
4B. Data Protection Roles under the PDPA
For data that you or your users enter into, generate in, or transmit through the services in the course of operating your own business, you are the data controller and BizCloud Asia Sdn Bhd acts as data processor under the Personal Data Protection Act 2010 as amended by the Personal Data Protection (Amendment) Act 2024. This includes employee, payroll, attendance, leave, claim, member, customer, patient, student, contact and messaging records held in your account.
BizCloud acts as data controller only in respect of our own business records, such as your billing account, our sales and support communications, website visitor data, and telemetry used to operate and secure the platform.
As data controller, you are responsible for:
- Issuing your own personal data protection notice to your employees, customers, members and other data subjects, in both Bahasa Malaysia and English as required by section 7 of the PDPA, and obtaining valid consent or establishing another lawful basis.
- Appointing a data protection officer where required, and notifying the Personal Data Protection Commissioner of that appointment.
- Responding to data subject access, correction, withdrawal, portability and direct-marketing cessation requests relating to your data. Where such a request reaches us, we will refer it to you rather than act on it directly, unless you have instructed us otherwise in writing.
- Notifying the Commissioner and, where required, affected individuals of a personal data breach within the statutory timelines. Where we become aware of a security incident affecting your data in systems under our control, we will notify you without undue delay and provide reasonable information to support your notification, but the notification obligation to the regulator and to data subjects remains yours as data controller.
- Determining retention periods and instructing deletion. We are not obliged to delete records in the absence of an authorised instruction, and may retain records where required by law, or for security, audit, billing, dispute and backup purposes.
As data processor, we will process personal data in accordance with your documented instructions and the subscribed service scope, apply reasonable security measures consistent with the Security Principle, and impose confidentiality obligations on personnel with access. You warrant that your instructions are lawful, and you indemnify us in respect of instructions that are not.
Some processing occurs outside Malaysia, including cloud hosting, messaging providers, push notification services, email and SMS gateways and AI providers. Current categories of sub-processors are described in our Privacy Policy. Where required by law, you are responsible for carrying out your own transfer impact assessment for your data, using the information we make available.
4C. Sensitive and Biometric Data
Biometric data is classified as sensitive personal data under the amended PDPA and requires the explicit consent of the individual, unless a statutory exemption applies.
If you use fingerprint, facial recognition, palm, iris or other biometric clocking, or biometric-linked e-Attendance, kiosk, door access or POS login features, whether through BMO or through connected devices, you are solely responsible for obtaining and recording explicit written consent from each affected employee or individual, for providing an alternative non-biometric method where consent is refused or where required by law, and for the lawful configuration, retention and deletion of biometric templates.
The same applies to other sensitive categories that may be entered into HRM, payroll or CRM modules, including health and medical certificate information, disability records, religious information used for leave or dietary settings, and records of offences or disciplinary action.
We do not verify that consent has been obtained. We are not liable for any regulatory action, employee claim, industrial court claim or penalty arising from your collection or use of biometric or other sensitive personal data.
5. WhatsApp, Messaging and Third-Party Platforms
Where services connect to WhatsApp Business API, Meta platforms, SMS, email, payment gateways, government portals such as MyInvois, cloud providers, social platforms, PBX or telephony providers, AI providers or other third-party services, your use is also subject to the terms, policies, fees, approval processes and technical limits of those third parties.
We do not control third-party approval, account suspension, delivery rates, template approval, message delays, platform outages, API deprecation, pricing changes, model changes or policy enforcement. Customers are responsible for lawful message content, opt-in and consent, opt-out handling, and compliance with applicable anti-spam, privacy and communication rules, including section 43 of the PDPA regarding direct marketing cessation notices.
Third-party charges, including per-message conversation charges, template charges, telco charges and AI usage charges, are payable by the customer and may change without notice from the provider. We may pass through such changes.
6. Fees, Payment and Suspension
Fees, subscriptions, setup charges, renewal periods, usage charges and payment terms are as stated in the relevant quotation, invoice, proposal, order form or written agreement. Unless expressly stated otherwise, fees paid are non-refundable.
We may suspend or restrict access for overdue payment, chargeback, suspected fraud, security risk, misuse, legal risk, breach of terms, end of subscription, or failure to provide information required for service delivery.
Unless stated otherwise, subscriptions are billed in advance, fees are exclusive of SST and other applicable taxes, and customers are not entitled to set off, withhold or deduct amounts from our invoices except where required by law. Overdue amounts may attract late payment charges and recovery costs, including legal and collection costs on a full indemnity basis.
6A. Support, Maintenance and Service Levels
Standard support is provided during Malaysian business hours through remote or online channels such as helpdesk, email, remote access, phone or WhatsApp, unless a separate signed service level agreement states otherwise. After-hours support is best-effort and may be chargeable.
Any response or uptime targets are operational targets, not absolute guarantees. Resolution time depends on issue complexity, customer cooperation, access to logs, sample data, third-party providers and whether the issue is caused by our system or by customer hardware, network, browser, device, local installation, customisation, third-party service or misconfiguration.
Service level targets do not apply to free trials, demo accounts, beta features, AI features, test environments, non-production systems, client-hosted or PC-hosted installations, or issues caused by customer-controlled environments or third-party systems unless expressly agreed in writing.
6B. Module-Specific Terms
The following terms apply in addition to the rest of this Agreement where the relevant module is subscribed. They do not limit Section 4A, which applies to every module.
6B.1 Payroll
BMO Payroll is a calculation and record-keeping tool. It is not a payroll bureau, tax agent or statutory filing agent. The employer remains the party legally responsible for correct remuneration, deductions, contributions, submissions and record retention.
Statutory rates, tables, ceilings, categories and file formats issued by LHDN, KWSP, PERKESO, HRD Corp and other authorities change from time to time. We will use commercially reasonable efforts to update the software within a reasonable period after an authority publishes a change and its technical specification, but we do not warrant that an update will be available before any particular payroll run or submission deadline. The customer is responsible for confirming, before each run, that the configured rates, categories, exemptions and employee setup are correct and current.
The customer is responsible for verifying every payroll run before payment or submission, for retaining its own statutory records for the periods required under the Employment Act 1955, the Income Tax Act 1967 and related legislation, and for any correction, resubmission, amended return, penalty, interest or back-payment arising from incorrect setup, incorrect employee data, late detection or regulatory change.
6B.2 e-Attendance and Time Records
Attendance capture may rely on mobile devices, GPS, network location, Wi-Fi, QR codes, biometric or card devices, and third-party hardware. Location accuracy, device clock accuracy, device permissions, connectivity, battery state, operating system restrictions and hardware condition are outside our control. Geofence and GPS readings are indicative and must not be treated as conclusive proof of an employee's location.
The customer is responsible for shift configuration, rest day and public holiday setup, overtime rules, rounding rules, and for reconciling attendance records against its own records before using them for payroll, discipline, dismissal or any Industrial Relations Act 1967 or Employment Act 1955 process. Section 4C applies where biometric capture is used.
6B.3 e-Leave and e-Claim
Entitlement tables, accrual rules, carry-forward rules, approval routing, claim categories, claim limits and mileage rates are configured by the customer. The system applies the configuration given to it and does not determine or guarantee statutory minimum entitlements. The customer is responsible for ensuring configuration complies with the Employment Act 1955 and its amendments, applicable collective agreements and its own employment contracts and handbook, and for verifying balances before approval, payment or final settlement.
6B.4 POS, Inventory and Membership
The customer is responsible for pricing, discount authority, tax and SST configuration, cash handling, till reconciliation, void and refund controls, stock counts and costing method. Where offline or local caching mode is used, transactions held on a local device before synchronisation may be lost if the device fails, is reset, is stolen or is not synchronised, and the customer is responsible for daily reconciliation and end-of-day closing procedures.
Payment terminals, card readers, e-wallets and payment gateways are third-party services governed by their own agreements. We do not store full payment card numbers and are not a payment processor. Card data handling and PCI DSS obligations rest with the customer and its payment provider.
6B.5 CRM, iCRM, Queue and Messaging
The customer is responsible for the lawful basis of every contact record, for message content, for opt-in and opt-out handling, for honouring direct-marketing cessation notices, and for the accuracy of any automated or scheduled campaign, follow-up sequence or chatbot flow it configures or approves. Where an AI or automated agent replies to end users, Section 9A applies and the customer is responsible for appropriate disclosure to those end users.
6B.6 Accounting and e-Invoice
Unless expressly agreed in writing, BizCloud is not appointed as your e-Invoice intermediary, peppol service provider or tax agent, and does not submit on your behalf. The customer is responsible for TIN, business registration details, classification codes, tax types, exemption status, buyer details, submission timing, and for monitoring validation, rejection and cancellation windows in the LHDN MyInvois system. We are not liable for rejected, late, duplicated or incorrect submissions, or for any resulting penalty or audit exposure.
6B.7 AI Features
See Section 9A, which applies in full to every AI feature in every module. AI features may be metered, capped, throttled, priced separately, changed or withdrawn.
7. Acceptable Use and Restrictions
- Do not use the services for unlawful, fraudulent, harmful, abusive, defamatory, misleading or unauthorised purposes.
- Do not bypass security, access another customer account, reverse engineer, copy, scrape, overload, disrupt or damage our systems.
- Do not upload malicious code, infringing content, unlawful personal data, spam, phishing content or materials that violate third-party rights.
- Do not use the services to send messages without proper consent, opt-in or lawful basis.
- Do not use AI features to generate unlawful, deceptive, discriminatory, defamatory or infringing content, to impersonate a person without disclosure, or to make final decisions about an individual without human review.
- Do not use output of the services, including AI output, to train, fine-tune, benchmark or develop a competing product or model.
- Do not resell, sublicense or commercially exploit the services except as expressly agreed in writing.
We may investigate suspected breaches, and may suspend accounts, features, messaging or AI access where we reasonably believe there is a security, legal, platform-compliance or abuse risk.
7A. Confidentiality
Each party may receive confidential information of the other, including pricing, quotations, system design, source code, configuration, security information, business data and customer data. The receiving party will keep it confidential, use it only for the purposes of this Agreement, and disclose it only to personnel, contractors and advisers who need it and are under equivalent obligations.
These obligations do not apply to information that is public through no breach, was already lawfully known, is independently developed, or is required to be disclosed by law, regulator or court, provided reasonable notice is given where lawful. Confidentiality obligations continue for three years after termination, and indefinitely for source code, security information and personal data.
8. Intellectual Property
All software, website design, source code, databases, templates, workflows, documentation, graphics, trade names, logos, product names, know-how, prompts, model configurations and materials provided by BizCloud Asia Sdn Bhd remain owned by us or our licensors. No rights are transferred except the limited right to use the subscribed services during the active subscription period.
You retain ownership of your customer data. Where you provide suggestions, feature requests, feedback or improvement ideas, you grant us a perpetual, irrevocable, royalty-free right to use them without obligation or attribution.
You must not access or use the services as a direct competitor, for benchmarking, feature copying, reverse engineering, competitive analysis or development of competing products without our prior written consent.
9. Disclaimers
The services are provided on an "as is" and "as available" basis to the fullest extent permitted by law. We do not guarantee that the services will be uninterrupted, error-free, immune from cyber incidents, compatible with every device, suitable for every legal, tax, payroll or employment scenario, or capable of replacing professional advice.
Any payroll, accounting, tax, e-Invoice, HR, attendance, leave, claim, statutory, queue analytics, CRM, chatbot, AI or reporting output must be reviewed by authorised and qualified personnel before reliance, filing, payment, submission or business action, in accordance with Section 4A.
Complex software may contain bugs, defects, vulnerabilities or compatibility issues. If a defect is confirmed, our sole obligation is to use reasonable efforts to provide a fix, workaround or assistance to regenerate affected reports where practical. We are not responsible for historical corrections, resubmissions, penalties or losses caused by late detection, wrong setup, customer data errors or regulatory changes.
9A. Artificial Intelligence, Automation and Beta Features
9A.0 Summary in Plain Language
- AI features are assistants. They draft, summarise, classify and suggest. They do not decide.
- AI output is produced by a computer model. It is not written, checked or approved by BizCloud Asia Sdn Bhd.
- AI can be confidently wrong. It can invent facts, figures, names, dates and references that look correct.
- A competent person on your side must check every AI output before it is sent, published, paid, filed or acted on.
- If that check is skipped and something goes wrong, that is the customer's responsibility, not ours.
9A.1 Nature of AI Features
The services may include artificial intelligence, machine learning, large language model, generative AI, automation, agentic workflow or robotic process automation features. These may be provided by us, embedded in our software, or supplied by third-party AI providers whose models we do not build, own, train or control.
AI output is generated by a statistical model, not authored, reviewed, verified or approved by BizCloud Asia Sdn Bhd. We do not adopt AI output as our own statement, advice, representation or recommendation. AI and automation features are assistance tools only and do not replace human review, professional advice or management judgment.
9A.2 AI Output May Be Wrong
The customer must assume that AI output may contain errors. Known and expected limitations include:
- Fabrication. AI may invent facts, figures, names, dates, legal provisions, statutory rates, citations, product details or references that do not exist, and may present them fluently and confidently.
- Arithmetic and calculation errors. AI is not a calculator and must never be used to compute or confirm salary, statutory contributions, tax, discounts, stock values or any other figure that has financial or statutory consequence.
- Outdated information. Models are trained on historical data and may not reflect current Malaysian statutory rates, thresholds, forms, deadlines, formats or regulatory positions.
- Misclassification. Categories, sentiment, priority, intent and entity extraction may be wrong, especially with mixed-language, colloquial, abbreviated or handwritten input.
- Non-determinism. The same input may produce different output on different occasions. Output is not reproducible and must not be treated as an audit trail.
- Bias and unsuitability. Output may be biased, culturally inappropriate, wrongly toned, or unsuitable for the recipient or context.
- Third-party rights. Output may resemble existing material and may raise copyright, trademark, confidentiality or publicity issues.
- Prompt injection and untrusted content. Where AI reads incoming messages, uploaded files or web content, that content may contain instructions designed to manipulate the AI. AI output derived from untrusted input must be treated with particular caution.
AI output is not a certification, audit, legal opinion, tax position or professional advice of any kind.
9A.3 Customer Obligation to Review
The customer must review, verify, correct and approve all AI-generated content, calculations, classifications, scores, summaries, recommendations, correspondence, drafts, reports and decisions before relying on them, acting on them, sending them to any third party, publishing them, or submitting them to any authority. A human with appropriate authority and competence must remain in control of the final decision.
AI features must not be used as the sole basis for any decision that has a legal, financial, disciplinary, employment or similarly significant effect on an individual, including hiring, dismissal, promotion, disciplinary action, payroll adjustment, claim rejection, leave rejection, credit assessment or customer blacklisting. Meaningful human review is required in every such case, and the customer is responsible for maintaining a record of that review.
9A.4 Data Sent to AI Providers
Where AI features are enabled, prompts, inputs, documents, records or customer data reasonably necessary for the feature may be transmitted to third-party AI providers, which may process the data outside Malaysia. Categories of AI providers are described in our Privacy Policy.
The customer is responsible for deciding whether to enable AI features, for restricting which users may use them, for ensuring lawful basis and PDPA compliance for data submitted to them, for internal policy approval, and for not submitting sensitive personal data, credentials, confidential third-party information or regulated data to AI features where that would be unlawful or inappropriate. Where we control the integration, we will use commercially reasonable efforts to limit the data shared to what is reasonably necessary and to use provider settings that do not permit customer data to be used to train the provider's general models. We do not control all third-party AI provider processing, retention, model behaviour or subsequent changes to their terms.
9A.5 Transparency to End Users
Where the customer deploys AI or automated agents to communicate with its own employees, customers or the public, including WhatsApp and chatbot replies, the customer is responsible for making appropriate disclosure that the interaction is automated, for providing a route to a human where appropriate, and for compliance with any applicable AI governance guideline, code or legislation now or later in force in Malaysia.
9A.6 Ownership and Rights in AI Output
As between the parties, and to the extent permitted by law, AI output generated from your inputs is treated as your customer data. We make no warranty that AI output is original, non-infringing, protectable by copyright, or free from similarity to output generated for other users. You are responsible for checking AI output for third-party rights before publication or commercial use.
9A.7 Beta and Experimental Features
Beta, experimental, preview, pilot or early-access features are provided as-is, without warranty, SLA, support commitment or liability. They may be unstable, incomplete, modified, withdrawn or produce incorrect results, and must not be used for production, payroll, statutory or compliance-critical workflows without customer testing and validation.
9A.8 Changes to AI Features
We may change, replace, retrain, reconfigure, throttle, meter, price, restrict or withdraw AI models and AI features at any time, including where a provider changes its terms, pricing or availability. AI feature behaviour and quality may change as a result, and such change is not a defect.
9A.9 Module-Specific AI Risk Notes
Payroll and HRM. AI must never be used to determine, confirm or explain PCB/MTD, EPF, SOCSO, EIS or HRD Corp rates, ceilings, categories or exemptions. Statutory figures must come from the configured payroll engine and be checked against the current official tables published by the relevant authority.
e-Leave and e-Claim. AI summaries or suggested approvals do not determine statutory entitlement under the Employment Act 1955. Entitlement, accrual and carry-forward must be verified against the customer's configuration and its employment contracts.
e-Attendance. AI anomaly flags, absence patterns and exception summaries are indicative only. They must not be used as evidence in disciplinary, dismissal or Industrial Court matters without independent verification of the underlying records.
POS and Inventory. AI-generated product descriptions, categories, reorder suggestions and demand forecasts are estimates. Pricing, tax codes, costing and stock figures must be verified before they affect a transaction or a valuation.
CRM, iCRM and Messaging. AI-drafted replies, follow-ups and campaign content are drafts. Factual claims, prices, commitments, delivery dates and warranty statements must be verified before sending. An AI-generated message sent from the customer's account is the customer's message and may bind the customer.
Accounting and e-Invoice. AI must not be relied on for TIN, classification codes, tax type, exemption status, buyer details or submission validity. These must be verified against the customer's records and the MyInvois requirements before submission.
9A.10 Prohibited AI Uses
- Generating unlawful, deceptive, discriminatory, harassing, defamatory or infringing content.
- Impersonating a real person or organisation without clear disclosure and authorisation.
- Producing content designed to mislead a regulator, auditor, court, employee or customer.
- Making automated decisions about individuals without human review, as set out in Section 9A.3.
- Submitting other people's confidential or regulated data to AI features without a lawful basis.
- Attempting to extract, reverse engineer or circumvent model safeguards, system prompts or usage limits.
- Using AI output to train, fine-tune, benchmark or build a competing product or model.
- Bulk or automated generation of unsolicited messaging in breach of consent or anti-spam requirements.
We may suspend or restrict AI access where we reasonably believe there is a security, legal, platform-compliance, cost-abuse or misuse risk.
10. Limitation of Liability
To the fullest extent permitted by Malaysian law, BizCloud Asia Sdn Bhd, its directors, employees, contractors, suppliers and affiliates will not be liable for indirect, incidental, special, consequential, punitive or exemplary damages, loss of profit, loss of revenue, loss of goodwill, loss of anticipated savings, loss of business opportunity, business interruption, loss or corruption of data, inaccurate customer input, third-party platform failure, messaging failure, unauthorised customer-side access, AI output, or statutory submission errors.
Subject to the paragraph headed "Exceptions" below, our total aggregate liability for all claims arising from or related to the services, whether in contract, tort, negligence, statute or otherwise, is limited to:
- for a paid service, the total fees actually paid by the customer to BizCloud Asia Sdn Bhd for the affected service during the twelve (12) months immediately before the first event giving rise to the claim; and
- for any free trial, demonstration account, beta feature, unpaid feature or service provided at no charge, RM500.
Where a separate signed written agreement specifies a different limit, that limit applies instead.
Without limiting the above, we are not liable for losses, penalties, fines, claims, data leakage, regulatory action or third-party claims arising from reliance on AI output, customer failure to review AI or system output under Section 4A or Section 9A.3, third-party AI provider processing, cybersecurity incidents outside our reasonable control, customer-side malware, phishing, shared credentials, weak passwords, customer devices, biometric consent failures, enabled third-party integrations, or events beyond our reasonable control.
Exceptions. Nothing in this Agreement excludes or limits liability for death or personal injury caused by negligence, for fraud or fraudulent misrepresentation, or for any other liability that cannot lawfully be excluded or limited under Malaysian law. The customer's obligations to pay fees and its indemnity obligations under Section 11 are not subject to the limit above.
Each limitation and exclusion in this Section operates separately. If any part is held unenforceable, the remaining parts continue to apply to the fullest extent permitted by law.
11. Indemnity
You agree to indemnify and hold harmless BizCloud Asia Sdn Bhd, its directors, employees, contractors and service providers from claims, losses, penalties, liabilities, costs and expenses, including legal costs on a full indemnity basis, arising from your data, your users, breach of this Agreement, unlawful use, third-party platform breach, messaging content, failure to obtain consent, inaccurate submissions or misuse of the services.
This indemnity includes claims arising from AI output that you use, publish, submit or rely on, your failure to validate AI or system output, your breach of data protection laws, your collection or use of biometric or other sensitive personal data, unlawful messaging, uploaded files, employee or industrial relations claims relating to payroll, attendance, leave or claim records, customer-controlled environments and third-party integrations enabled by you.
12. Termination
We may terminate or suspend access if you breach these terms, fail to pay, create security or legal risk, misuse the services, or if continuing the service becomes commercially, technically or legally impractical. Upon termination, access may be disabled and data may be retained or deleted according to our retention practices, agreement terms and legal obligations.
For cloud services, where practical and subject to payment of all outstanding fees, we may provide a reasonable method to export customer data upon written request made within thirty days after termination or expiry. Export outside standard formats may be chargeable. After that period, we may delete, anonymise or archive data according to our retention policy, backup cycles and legal obligations.
You remain responsible for retaining your own statutory records. Termination does not transfer your record-keeping obligations to us.
13. Governing Law and Disputes
This User Agreement is governed by the laws of Malaysia. The parties agree to submit to the exclusive jurisdiction of the courts of Malaysia, unless a separate signed agreement specifies another dispute resolution process.
You must notify us in writing of any claim or potential claim relating to the services as soon as reasonably practicable and, in any event, within thirty days after you first become aware of the issue. To the fullest extent permitted by law, any legal action arising from the services must be commenced within twelve months after the cause of action first arises, failing which it will be permanently time-barred.
The parties will first attempt in good faith to resolve any dispute through discussion between senior representatives within thirty days before commencing proceedings, except where urgent injunctive relief is required.
13A. Force Majeure
We are not liable for delay or failure to perform caused by events beyond our reasonable control, including natural disasters, acts of God, war, riot, labour dispute, government action, pandemic, epidemic, utility failure, telecommunications failure, data centre outage, cloud provider failure, AI provider outage or withdrawal, third-party system failure, cyberattack or other events outside our reasonable control. Our obligations are suspended for the duration of such event, and we will use reasonable efforts to mitigate its impact where practical.
13B. Usage Monitoring, Security and Product Improvement
We may collect system telemetry, audit logs, error logs, performance metrics, anonymised usage data and aggregated analytics to operate, secure, troubleshoot, improve and monitor the services, prevent abuse and develop product improvements. We will not sell identifiable customer data to third parties for their marketing purposes, and we will not use identifiable customer data to train general-purpose AI models for third parties.
13C. Non-Solicitation of Personnel
During the subscription term and for twelve months afterwards, you will not directly or indirectly solicit for employment or engagement any BizCloud employee or contractor who was materially involved in providing services to you, without our prior written consent. This does not restrict general public advertising not targeted at such personnel.
13D. Reference and Publicity
Unless you notify us in writing that you object, we may identify you as a customer and use your business name and logo in customer lists, our website and proposals. We will not disclose your confidential information or customer data in doing so.
14. Changes to Terms
Technology, business and regulatory requirements change continuously. We may add, modify, deprecate, replace or remove features, modules, interfaces, workflows, hosting providers, AI models, integrations or system behaviour. Where a change materially reduces functionality actively used by customers, we will use reasonable efforts to provide notice where practical. Continued use of the website or services after posting means you accept the updated terms.
14A. Survival
Sections relating to customer data, verification duty, data protection roles, confidentiality, intellectual property, disclaimers, limitation of liability, indemnity, payment obligations, claim time limits, AI and automation, cybersecurity, non-solicitation, data export and deletion, governing law and any provision that by its nature should survive will survive termination or expiry of this Agreement.
14B. General
Assignment. You may not assign or transfer this Agreement without our written consent. We may assign or novate to an affiliate or to a successor in connection with a reorganisation, merger or sale of business, and may use subcontractors and sub-processors, remaining responsible for their performance within our service scope.
Entire agreement. This Agreement, together with the documents listed in Section 1A, is the entire agreement between the parties on its subject matter and supersedes prior discussions, proposals and representations, other than fraudulent misrepresentation.
Severability. If any provision is held invalid or unenforceable, it is modified to the minimum extent necessary or severed, and the remainder continues in full force.
No waiver. A failure or delay in exercising a right is not a waiver of it.
Notices. Notices to us must be sent to the contact details below. Notices to you may be given by email to your registered account address, by in-product notice, or by posting to our website.
No third-party rights. No person who is not a party to this Agreement has any right to enforce it.
Relationship. Nothing creates a partnership, joint venture, agency or employment relationship between the parties.
Language. This Agreement is issued in English. Where a translation is provided for convenience, the English version prevails in the event of inconsistency, except where Malaysian law requires otherwise.
15. Contact
BIZCLOUD ASIA SDN. BHD. (Registration No. 201301027403 (1057232-T))
General: sales@bizcloud.asia
Data Protection Officer: sales@bizcloud.asia
WhatsApp / Phone: +6016 450 2380