How BizCloud Asia Sdn Bhd collects, uses and protects personal data in the BMO System.
This Privacy Notice explains how BIZCLOUD ASIA SDN. BHD. (Registration No. 201301027403 (1057232-T)) (“BizCloud”, “we”, “us”, “our”) collects, uses and protects personal data when you use the BMO System and our related websites, modules and services.
This Privacy Notice should be read together with our Master Subscription & Service Level Agreement (SLA) and Terms of Service. If there is any conflict, the SLA and Terms of Service will prevail.
This Privacy Notice is issued under the Personal Data Protection Act 2010 as amended by the Personal Data Protection (Amendment) Act 2024, and reflects the obligations that came into force in stages during 2025, including mandatory data breach notification, mandatory appointment of a Data Protection Officer, the right to data portability, and the classification of biometric data as sensitive personal data.
This Privacy Notice applies to:
If you are an employee, customer or supplier of our client, your data is usually entered and controlled by that client. In that case, BizCloud only acts as a service provider / data processor. You should also refer to your employer’s or service provider’s own privacy policy.
2.1 Data Controller and Data Processor. For all personal data that a subscriber or its Users enter, upload, import or generate inside their own BMO account, the subscriber is the Data Controller and BizCloud acts only as Data Processor. The subscriber decides the purpose of processing, the retention period and who may access the data.
As Data Controller, the subscriber is responsible for issuing its own Personal Data Protection Notice to its employees and contacts (which under Section 7 of the PDPA must be in both Bahasa Malaysia and English), for obtaining consent, for appointing its own Data Protection Officer where required, for responding to data subject requests, and for notifying the Commissioner of a personal data breach.
BizCloud acts as Data Controller only for our own business records, such as subscriber billing accounts, our sales and support communications, website visitor data, and platform telemetry and security logs.
We only collect information that is reasonably necessary to provide our services and support, for example:
Your company and users may store a wide range of business data in BMO, for example:
This data is controlled by you. We do not create or change this content on our own and we do not use Your Data for our own marketing or resale.
When you visit our websites or cloud systems, we may collect:
You can adjust your browser settings to limit cookies, but some features may not work properly if cookies are disabled.
Certain categories are treated as sensitive personal data under the PDPA and require explicit consent unless an exemption applies. Following the 2024 amendments, biometric data is expressly included in that category.
Depending on the modules a subscriber uses and configures, the BMO System may hold:
Where this data sits inside a subscriber's account, the subscriber is the Data Controller and is responsible for obtaining explicit consent, for offering an alternative to biometric capture where consent is refused or required by law, and for lawful retention and deletion of biometric templates. We do not verify that such consent has been obtained. Where biometric matching is performed on a third-party device, that vendor's own privacy terms also apply.
We use your personal data for the following purposes:
We do not sell your personal data to third parties.
We may share personal data within BizCloud and with appointed contractors who help us provide hosting, support, development or customer service. Access is on a need-to-know basis and subject to confidentiality obligations.
Depending on your setup and modules, we may use third-party providers for data centre/cloud hosting, backup, email gateways, SMS/WhatsApp providers, payment gateways, government e-Invoice platforms and other APIs.
We may disclose personal data if required by law, court order or regulatory authority, or if we reasonably believe disclosure is necessary to comply with legal obligations, protect our rights or respond to fraud, security or abuse cases.
We do not provide your personal data to unrelated third parties for their own marketing.
Where a subscriber enables AI or automation features, prompts, inputs, documents or records reasonably necessary for the feature may be transmitted to third-party AI model providers for processing. Categories of provider include large-language-model and machine-learning services, which may operate outside Malaysia.
Where we control the integration, we use commercially reasonable efforts to limit the data shared to what is reasonably necessary, and to select provider settings that do not permit customer data to be used to train the provider's general-purpose models. We do not control every aspect of a provider's processing, retention, model behaviour or later changes to their terms. See Section 8A.
Some service providers, cloud infrastructure, messaging providers, push notification services, email and SMS gateways, AI providers and support tools process data outside Malaysia. Following the 2024 amendments, transfers outside Malaysia are permitted where the receiving jurisdiction has a law substantially similar to the PDPA or ensures an at least equivalent level of protection, or where another statutory ground applies, including the consent of the data subject and transfers necessary for the performance of a contract.
Where we transfer data as Data Processor on a subscriber's instruction, the subscriber as Data Controller remains responsible for the lawfulness of the transfer and for conducting any transfer impact assessment required of it. We will provide reasonable information about relevant processing locations, and a current list of named sub-processors, to subscribers on written request.
We take reasonable technical and organisational measures to protect data under our control, for example:
However, no system or internet transmission can be guaranteed to be 100% secure, and we cannot guarantee absolute protection against all attacks, malware, or human error.
We cannot be responsible for data loss or breaches caused by your own devices, networks, misconfiguration, ransomware, or failure to implement proper backup.
Under the amended PDPA, a Data Controller must notify the Personal Data Protection Commissioner of a personal data breach within the statutory timeline, and must notify affected individuals without undue delay where the breach is likely to cause significant harm.
Where we become aware of a personal data breach affecting data for which we are the Data Controller, we will make that notification ourselves.
Where we become aware of a security incident affecting subscriber account data for which we act as Data Processor, we will notify the affected subscriber without undue delay and provide reasonable information to help them assess and report the incident. The obligation to notify the Commissioner and the affected individuals rests with the subscriber as Data Controller, not with us, unless expressly agreed otherwise in writing. Subscribers should maintain their own breach response procedure, escalation contact and breach record register.
To report a suspected security issue or data breach, contact our Data Protection Officer using the details in Section 11 without delay. Please do not include passwords, access tokens or full copies of affected records in the initial report.
You are responsible to ensure that all information entered into BMO (including HR, payroll, accounting and e-Invoice data) is accurate, complete and up to date.
We do not review or audit Your Data for correctness, and we do not provide tax, accounting or legal advice. You should regularly:
We retain personal data for as long as reasonably required to deliver the services, fulfil our contract with you, comply with legal requirements, and handle disputes or audits. When data is no longer needed, we will take reasonable steps to delete or anonymise it, subject to any legal or regulatory retention duties.
For cloud systems, after your subscription ends, we may provide a limited window for data export upon written request (as described in the SLA). After that period, data may be deleted or archived.
For subscriber account data where we act as Data Processor, the subscriber determines the retention period. Malaysian law imposes minimum retention periods on employers and businesses, including for employment registers, payroll records and tax records, and subscribers should configure retention accordingly. We do not delete subscriber account records without an authorised instruction, except as permitted by our own retention practices after termination. Backup copies may persist for a limited period after deletion from active systems due to backup and disaster recovery cycles.
Subject to applicable law (including the Malaysian Personal Data Protection Act, PDPA), you may have the right to:
If your data is managed by your employer or another organisation using BMO, we may refer you back to that organisation, as they are the primary data controller.
To exercise these rights, contact our Data Protection Officer using the details in Section 11. We may need to verify your identity, a prescribed fee may apply to a data access request where permitted by law, and we will respond within the period required by law. We may decline a request where permitted by law, where the data belongs to a subscriber-controlled account, or where disclosure would affect another person, security, legal privilege, an investigation or a contractual obligation.
Some BMO features use artificial intelligence, machine learning or large language models, supplied either by us or by third-party AI providers. Where a subscriber enables such a feature, relevant inputs may be transmitted to an AI provider, and that processing may take place outside Malaysia (see Sections 5.4 and 5.5).
Content produced by these features is generated by a statistical model. It is not authored, written, reviewed, verified or approved by BizCloud Asia Sdn Bhd. We do not adopt AI output as our own statement, advice or recommendation. AI output may be inaccurate, incomplete, outdated or fabricated, and must be reviewed and approved by the subscriber before it is used, sent, published, paid or submitted to any authority.
Subscribers control whether AI features are enabled and which of their users may access them. If your personal data is held inside a subscriber's account, please direct questions about how that subscriber uses AI to the subscriber. Full AI terms are set out in the Terms of Service and the Master Subscription, Service Level & AI Usage Agreement.
The BMO System may produce automated scores, classifications, reminders, anomaly flags, follow-up suggestions or draft replies, for example in CRM lead handling, attendance exception flagging or chatbot responses.
We do not use these to make final decisions that produce legal or similarly significant effects on individuals. Where a subscriber configures such features in its own account, the subscriber is responsible for ensuring meaningful human review before any decision affecting an individual, including decisions about hiring, dismissal, discipline, promotion, performance rating, payroll adjustment, or rejection of a leave or claim application, and for keeping a record of that review.
Our websites and portals may contain links to third-party sites or services. We are not responsible for the privacy practices, content or security of those external websites. You should review the privacy notices of any third-party site you visit.
Access to BMO and related admin systems requires a valid username and password, and in some cases additional security measures. Certain activities (such as login attempts, configuration changes, and support actions) may be logged for security and audit purposes.
While we follow secure development practices and take reasonable precautions, no software can be guaranteed free from vulnerabilities. Our goal is to make unauthorised access difficult and detectable, and to respond in a timely manner when issues are reported.
English. BizCloud Asia Sdn Bhd processes personal data in accordance with the Personal Data Protection Act 2010 as amended. For data entered into a subscriber's own account, the subscriber is the Data Controller and BizCloud acts as Data Processor. Subscribers are responsible for issuing their own PDPA notice to their employees and contacts in both Bahasa Malaysia and English, for obtaining consent (including explicit consent for sensitive personal data such as biometric, health and religious data), and for notifying the Commissioner of any personal data breach. Where we become aware of a security incident affecting subscriber account data, we will notify the subscriber without undue delay. You may contact our Data Protection Officer for access, correction, withdrawal or data portability requests relating to data for which we are the Data Controller.
Bahasa Malaysia. BizCloud Asia Sdn Bhd memproses data peribadi selaras dengan Akta Perlindungan Data Peribadi 2010 sebagaimana yang dipinda. Bagi data yang dimasukkan ke dalam akaun pelanggan sendiri, pelanggan ialah Pengawal Data dan BizCloud bertindak sebagai Pemproses Data. Pelanggan bertanggungjawab untuk mengeluarkan notis PDPA mereka sendiri kepada pekerja dan kenalan mereka dalam Bahasa Malaysia dan Bahasa Inggeris, mendapatkan persetujuan (termasuk persetujuan nyata bagi data peribadi sensitif seperti data biometrik, kesihatan dan keagamaan), serta memberitahu Pesuruhjaya mengenai sebarang pelanggaran data peribadi. Sekiranya kami mengetahui tentang insiden keselamatan yang menjejaskan data akaun pelanggan, kami akan memberitahu pelanggan tanpa kelewatan yang tidak wajar. Anda boleh menghubungi Pegawai Perlindungan Data kami untuk permohonan akses, pembetulan, penarikan balik atau kemudahalihan data bagi data yang kami menjadi Pengawal Data.
If you have any questions, concerns or requests related to this Privacy Notice or your personal data, please contact us:
Data Protection Officer
Data Protection Officer, BizCloud Asia Sdn Bhd
Email: sales@bizcloud.asia
Email (general)
sales@bizcloud.asia
If you are not satisfied with our response, you may lodge a complaint with the Personal Data Protection Department (Jabatan Perlindungan Data Peribadi), Malaysia.
Kuala Lumpur Office
No.B-2-7, Block B, Kuchai Exchange,
Jalan Kuchai Maju 13, Kuchai Lama 58200,
Kuala Lumpur, Malaysia.
Phone: +603 2780 3880
Email: sales@bizcloud.asia
Waze: View in Waze
Google Maps: View in Google Maps
Penang Offices
Unit 1-3-31, i-Avenue, No. 1, Jalan Tun Dr Awang,
11900 Bayan Lepas, Penang, Malaysia.
5-5-37, The Promenade,
Persiaran Mahsuri,
Bandar Bayan Lepas,
11900 Bayan Lepas,
Penang, Malaysia.
Phone: +604 2024 033
Email: sales@bizcloud.asia
Waze: View in Waze
Google Maps: View in Google Maps
Johor Office
01-35, Jalan Austin Perdana 2/22,
Taman Austin Perdana,
81100 Johor Bahru,
Johor, Malaysia.
Phone: +607 4890 353
Email: sales@bizcloud.asia
Waze: View in Waze
Google Maps: View in Google Maps