BMO Privacy Notice

How BizCloud Asia Sdn Bhd collects, uses and protects personal data in the BMO System.

BIZCLOUD ASIA SDN. BHD. (Registration No. 201301027403 (1057232-T))  |  Last updated: 28 July 2026

1. Introduction

This Privacy Notice explains how BIZCLOUD ASIA SDN. BHD. (Registration No. 201301027403 (1057232-T)) (“BizCloud”, “we”, “us”, “our”) collects, uses and protects personal data when you use the BMO System and our related websites, modules and services.

This Privacy Notice should be read together with our Master Subscription & Service Level Agreement (SLA) and Terms of Service. If there is any conflict, the SLA and Terms of Service will prevail.

This Privacy Notice is issued under the Personal Data Protection Act 2010 as amended by the Personal Data Protection (Amendment) Act 2024, and reflects the obligations that came into force in stages during 2025, including mandatory data breach notification, mandatory appointment of a Data Protection Officer, the right to data portability, and the classification of biometric data as sensitive personal data.

2. Who this applies to

This Privacy Notice applies to:

  • Companies and organisations that subscribe to BMO;
  • Users who log in to BMO (e.g. HR, payroll, finance, admin, manager, staff);
  • Visitors who browse our websites, submit forms, or contact us.

If you are an employee, customer or supplier of our client, your data is usually entered and controlled by that client. In that case, BizCloud only acts as a service provider / data processor. You should also refer to your employer’s or service provider’s own privacy policy.

2.1 Data Controller and Data Processor. For all personal data that a subscriber or its Users enter, upload, import or generate inside their own BMO account, the subscriber is the Data Controller and BizCloud acts only as Data Processor. The subscriber decides the purpose of processing, the retention period and who may access the data.

As Data Controller, the subscriber is responsible for issuing its own Personal Data Protection Notice to its employees and contacts (which under Section 7 of the PDPA must be in both Bahasa Malaysia and English), for obtaining consent, for appointing its own Data Protection Officer where required, for responding to data subject requests, and for notifying the Commissioner of a personal data breach.

BizCloud acts as Data Controller only for our own business records, such as subscriber billing accounts, our sales and support communications, website visitor data, and platform telemetry and security logs.

3. What personal data we collect

3.1 Information you or your company provide to us

We only collect information that is reasonably necessary to provide our services and support, for example:

  • Company details: name, registration number, billing address, contact details;
  • Contact persons: name, job title, email, phone number, department;
  • Login details: username, password (stored in protected form, not plain text);
  • Subscription and billing information: package subscribed, payment records, invoices, support history;
  • Support communications: emails, phone/WhatsApp messages, tickets, remote-session logs.

3.2 Information entered into the BMO System (“Your Data”)

Your company and users may store a wide range of business data in BMO, for example:

  • HR & employee data (HRM, e-Leave, e-Claim, attendance, payroll);
  • Accounting and e-Invoice data (customers, suppliers, transactions, SST/tax codes);
  • CRM, sales, inventory, POS and other business records;
  • Files and documents uploaded to file management modules.

This data is controlled by you. We do not create or change this content on our own and we do not use Your Data for our own marketing or resale.

3.3 Website & usage information

When you visit our websites or cloud systems, we may collect:

  • Technical information: IP address, browser type, device type, approximate location;
  • Log information: login time, pages accessed, error logs, basic usage patterns;
  • Cookies or similar technologies used mainly for session management and user experience.

You can adjust your browser settings to limit cookies, but some features may not work properly if cookies are disabled.

3.4 Sensitive personal data and biometric data

Certain categories are treated as sensitive personal data under the PDPA and require explicit consent unless an exemption applies. Following the 2024 amendments, biometric data is expressly included in that category.

Depending on the modules a subscriber uses and configures, the BMO System may hold:

  • Biometric templates or references used for fingerprint, facial or palm recognition clocking, kiosk access, door access or POS login;
  • Health and medical certificate information submitted with leave or claim applications;
  • Disability status, and religious information used for leave, dietary or scheduling settings;
  • Records of offences, warnings or disciplinary action.

Where this data sits inside a subscriber's account, the subscriber is the Data Controller and is responsible for obtaining explicit consent, for offering an alternative to biometric capture where consent is refused or required by law, and for lawful retention and deletion of biometric templates. We do not verify that such consent has been obtained. Where biometric matching is performed on a third-party device, that vendor's own privacy terms also apply.

4. How we use your personal data

We use your personal data for the following purposes:

  • To provide and operate the BMO System – create and manage user accounts, provide access to subscribed modules, and generate system reports based on Your Data and settings.
  • To provide support and maintenance – respond to support tickets, diagnose issues, perform configuration, updates and improvements.
  • To manage our relationship with you – handle billing, renewals, system notices, training and implementation.
  • To improve our products and services – analyse anonymised or aggregated usage trends to enhance performance, stability and security.
  • Marketing and communication (optional) – send information on new features, modules, promotions or events. You can opt-out from marketing emails at any time.

We do not sell your personal data to third parties.

5. Who we share your data with

5.1 Within BizCloud and trusted contractors

We may share personal data within BizCloud and with appointed contractors who help us provide hosting, support, development or customer service. Access is on a need-to-know basis and subject to confidentiality obligations.

5.2 Third-party service providers & integrations

Depending on your setup and modules, we may use third-party providers for data centre/cloud hosting, backup, email gateways, SMS/WhatsApp providers, payment gateways, government e-Invoice platforms and other APIs.

  • Any contract or fee for these services is between you and the provider (where applicable);
  • When you enable an integration, you authorise us to exchange data with that provider as needed to make the integration work;
  • These providers handle data according to their own privacy policies and contracts. We do not control their internal systems or policies.

5.3 Legal and regulatory requirements

We may disclose personal data if required by law, court order or regulatory authority, or if we reasonably believe disclosure is necessary to comply with legal obligations, protect our rights or respond to fraud, security or abuse cases.

We do not provide your personal data to unrelated third parties for their own marketing.

5.4 Artificial intelligence providers

Where a subscriber enables AI or automation features, prompts, inputs, documents or records reasonably necessary for the feature may be transmitted to third-party AI model providers for processing. Categories of provider include large-language-model and machine-learning services, which may operate outside Malaysia.

Where we control the integration, we use commercially reasonable efforts to limit the data shared to what is reasonably necessary, and to select provider settings that do not permit customer data to be used to train the provider's general-purpose models. We do not control every aspect of a provider's processing, retention, model behaviour or later changes to their terms. See Section 8A.

5.5 Cross-border processing

Some service providers, cloud infrastructure, messaging providers, push notification services, email and SMS gateways, AI providers and support tools process data outside Malaysia. Following the 2024 amendments, transfers outside Malaysia are permitted where the receiving jurisdiction has a law substantially similar to the PDPA or ensures an at least equivalent level of protection, or where another statutory ground applies, including the consent of the data subject and transfers necessary for the performance of a contract.

Where we transfer data as Data Processor on a subscriber's instruction, the subscriber as Data Controller remains responsible for the lawfulness of the transfer and for conducting any transfer impact assessment required of it. We will provide reasonable information about relevant processing locations, and a current list of named sub-processors, to subscribers on written request.

6. Security and where data is stored

We take reasonable technical and organisational measures to protect data under our control, for example:

  • Using HTTPS (TLS) for access to our cloud systems and admin portals;
  • Role-based access controls and passwords for our staff;
  • Separation of production and test environments where applicable;
  • Regular backups for cloud-hosted data with restricted access.

However, no system or internet transmission can be guaranteed to be 100% secure, and we cannot guarantee absolute protection against all attacks, malware, or human error.

6.1 Cloud vs client-hosted / on-premise (important)

  • Cloud BMO: when hosted on our servers or our cloud partner, we are responsible for the infrastructure level (server OS, database, basic backup and security within our environment).
  • Client-hosted / PC-hosted / on-premise: when BMO is installed on your own PC, server, VM, NAS or third-party hosting, you are fully responsible for hardware, OS, network, antivirus, firewall, access control and backup/restore of your database and files.

We cannot be responsible for data loss or breaches caused by your own devices, networks, misconfiguration, ransomware, or failure to implement proper backup.

6.2 Personal data breach notification

Under the amended PDPA, a Data Controller must notify the Personal Data Protection Commissioner of a personal data breach within the statutory timeline, and must notify affected individuals without undue delay where the breach is likely to cause significant harm.

Where we become aware of a personal data breach affecting data for which we are the Data Controller, we will make that notification ourselves.

Where we become aware of a security incident affecting subscriber account data for which we act as Data Processor, we will notify the affected subscriber without undue delay and provide reasonable information to help them assess and report the incident. The obligation to notify the Commissioner and the affected individuals rests with the subscriber as Data Controller, not with us, unless expressly agreed otherwise in writing. Subscribers should maintain their own breach response procedure, escalation contact and breach record register.

To report a suspected security issue or data breach, contact our Data Protection Officer using the details in Section 11 without delay. Please do not include passwords, access tokens or full copies of affected records in the initial report.

7. Data accuracy, retention and your responsibilities

You are responsible to ensure that all information entered into BMO (including HR, payroll, accounting and e-Invoice data) is accurate, complete and up to date.

We do not review or audit Your Data for correctness, and we do not provide tax, accounting or legal advice. You should regularly:

  • Review system reports and ledgers before using them for payment or submission;
  • Perform and test backup and restore procedures, especially for client-hosted installations.

We retain personal data for as long as reasonably required to deliver the services, fulfil our contract with you, comply with legal requirements, and handle disputes or audits. When data is no longer needed, we will take reasonable steps to delete or anonymise it, subject to any legal or regulatory retention duties.

For cloud systems, after your subscription ends, we may provide a limited window for data export upon written request (as described in the SLA). After that period, data may be deleted or archived.

For subscriber account data where we act as Data Processor, the subscriber determines the retention period. Malaysian law imposes minimum retention periods on employers and businesses, including for employment registers, payroll records and tax records, and subscribers should configure retention accordingly. We do not delete subscriber account records without an authorised instruction, except as permitted by our own retention practices after termination. Backup copies may persist for a limited period after deletion from active systems due to backup and disaster recovery cycles.

8. Your rights

Subject to applicable law (including the Malaysian Personal Data Protection Act, PDPA), you may have the right to:

  • Request access to personal data we hold about you;
  • Request correction of inaccurate or incomplete data;
  • Request deletion, blocking or restriction of processing in certain circumstances;
  • Withdraw consent to marketing communications;
  • Require us to cease processing your personal data for direct marketing purposes (Section 43 of the PDPA); and
  • Data portability - request that your personal data be transmitted directly to another data controller, where the request is technically feasible and the data formats are compatible (Section 43A of the PDPA, introduced by the 2024 amendments).

If your data is managed by your employer or another organisation using BMO, we may refer you back to that organisation, as they are the primary data controller.

To exercise these rights, contact our Data Protection Officer using the details in Section 11. We may need to verify your identity, a prescribed fee may apply to a data access request where permitted by law, and we will respond within the period required by law. We may decline a request where permitted by law, where the data belongs to a subscriber-controlled account, or where disclosure would affect another person, security, legal privilege, an investigation or a contractual obligation.

8A. Artificial intelligence and how we use it

Some BMO features use artificial intelligence, machine learning or large language models, supplied either by us or by third-party AI providers. Where a subscriber enables such a feature, relevant inputs may be transmitted to an AI provider, and that processing may take place outside Malaysia (see Sections 5.4 and 5.5).

Content produced by these features is generated by a statistical model. It is not authored, written, reviewed, verified or approved by BizCloud Asia Sdn Bhd. We do not adopt AI output as our own statement, advice or recommendation. AI output may be inaccurate, incomplete, outdated or fabricated, and must be reviewed and approved by the subscriber before it is used, sent, published, paid or submitted to any authority.

Subscribers control whether AI features are enabled and which of their users may access them. If your personal data is held inside a subscriber's account, please direct questions about how that subscriber uses AI to the subscriber. Full AI terms are set out in the Terms of Service and the Master Subscription, Service Level & AI Usage Agreement.

8B. Automated decision-making and profiling

The BMO System may produce automated scores, classifications, reminders, anomaly flags, follow-up suggestions or draft replies, for example in CRM lead handling, attendance exception flagging or chatbot responses.

We do not use these to make final decisions that produce legal or similarly significant effects on individuals. Where a subscriber configures such features in its own account, the subscriber is responsible for ensuring meaningful human review before any decision affecting an individual, including decisions about hiring, dismissal, discipline, promotion, performance rating, payroll adjustment, or rejection of a leave or claim application, and for keeping a record of that review.

9. Third-party websites

Our websites and portals may contain links to third-party sites or services. We are not responsible for the privacy practices, content or security of those external websites. You should review the privacy notices of any third-party site you visit.

10. Online threats and logging

Access to BMO and related admin systems requires a valid username and password, and in some cases additional security measures. Certain activities (such as login attempts, configuration changes, and support actions) may be logged for security and audit purposes.

While we follow secure development practices and take reasonable precautions, no software can be guaranteed free from vulnerabilities. Our goal is to make unauthorised access difficult and detectable, and to respond in a timely manner when issues are reported.

10A. Personal Data Protection Notice / Notis Perlindungan Data Peribadi

English. BizCloud Asia Sdn Bhd processes personal data in accordance with the Personal Data Protection Act 2010 as amended. For data entered into a subscriber's own account, the subscriber is the Data Controller and BizCloud acts as Data Processor. Subscribers are responsible for issuing their own PDPA notice to their employees and contacts in both Bahasa Malaysia and English, for obtaining consent (including explicit consent for sensitive personal data such as biometric, health and religious data), and for notifying the Commissioner of any personal data breach. Where we become aware of a security incident affecting subscriber account data, we will notify the subscriber without undue delay. You may contact our Data Protection Officer for access, correction, withdrawal or data portability requests relating to data for which we are the Data Controller.

Bahasa Malaysia. BizCloud Asia Sdn Bhd memproses data peribadi selaras dengan Akta Perlindungan Data Peribadi 2010 sebagaimana yang dipinda. Bagi data yang dimasukkan ke dalam akaun pelanggan sendiri, pelanggan ialah Pengawal Data dan BizCloud bertindak sebagai Pemproses Data. Pelanggan bertanggungjawab untuk mengeluarkan notis PDPA mereka sendiri kepada pekerja dan kenalan mereka dalam Bahasa Malaysia dan Bahasa Inggeris, mendapatkan persetujuan (termasuk persetujuan nyata bagi data peribadi sensitif seperti data biometrik, kesihatan dan keagamaan), serta memberitahu Pesuruhjaya mengenai sebarang pelanggaran data peribadi. Sekiranya kami mengetahui tentang insiden keselamatan yang menjejaskan data akaun pelanggan, kami akan memberitahu pelanggan tanpa kelewatan yang tidak wajar. Anda boleh menghubungi Pegawai Perlindungan Data kami untuk permohonan akses, pembetulan, penarikan balik atau kemudahalihan data bagi data yang kami menjadi Pengawal Data.

11. How to contact us

If you have any questions, concerns or requests related to this Privacy Notice or your personal data, please contact us:

Data Protection Officer
Data Protection Officer, BizCloud Asia Sdn Bhd
Email: sales@bizcloud.asia

Email (general)
sales@bizcloud.asia

If you are not satisfied with our response, you may lodge a complaint with the Personal Data Protection Department (Jabatan Perlindungan Data Peribadi), Malaysia.

Kuala Lumpur Office
No.B-2-7, Block B, Kuchai Exchange,
Jalan Kuchai Maju 13, Kuchai Lama 58200,
Kuala Lumpur, Malaysia.
Phone: +603 2780 3880
Email: sales@bizcloud.asia
Waze: View in Waze
Google Maps: View in Google Maps

Penang Offices

Unit 1-3-31, i-Avenue, No. 1, Jalan Tun Dr Awang,
11900 Bayan Lepas, Penang, Malaysia.

5-5-37, The Promenade,
Persiaran Mahsuri,
Bandar Bayan Lepas,
11900 Bayan Lepas,
Penang, Malaysia.
Phone: +604 2024 033
Email: sales@bizcloud.asia
Waze: View in Waze
Google Maps: View in Google Maps

Johor Office
01-35, Jalan Austin Perdana 2/22,
Taman Austin Perdana,
81100 Johor Bahru,
Johor, Malaysia.
Phone: +607 4890 353
Email: sales@bizcloud.asia
Waze: View in Waze
Google Maps: View in Google Maps