Master Subscription & Terms of Use for BMO System – provided by BizCloud Asia Sdn Bhd and its affiliate, Mobiweb Sdn Bhd.
THIS AGREEMENT GOVERNS YOUR ACQUISITION AND USE OF BMO SERVICES AND SOFTWARE.
BY CLICKING “I ACCEPT”, SIGNING A QUOTATION / ORDER FORM THAT REFERENCES THESE TERMS, OR ACCESSING OR USING THE BMO SYSTEM, YOU AGREE TO BE BOUND BY THIS TERMS OF SERVICE (“Agreement”).
IF YOU ARE ACCEPTING THIS AGREEMENT ON BEHALF OF A COMPANY OR OTHER LEGAL ENTITY, YOU REPRESENT THAT YOU HAVE THE AUTHORITY TO BIND THAT ENTITY. IN THAT CASE, “YOU” AND “YOUR” REFER TO THAT ENTITY AND ITS AFFILIATES.
IF YOU DO NOT HAVE SUCH AUTHORITY OR DO NOT AGREE TO THESE TERMS, YOU MUST NOT USE THE SERVICES.
You may not access the Services or Software if you are a direct competitor of BizCloud Asia Sdn Bhd or Mobiweb Sdn Bhd, except with our prior written consent. You also may not access the Services for the purpose of benchmarking, competitive analysis, or monitoring availability or performance.
This Terms of Service is intended to be read together with our Master Subscription & Service Level Agreement (SLA) and Privacy Notice. In case of any conflict, the Order Form and Master Subscription Agreement will prevail.
“BizCloud”, “we”, “us”, “our” means BIZCLOUD ASIA SDN. BHD. (Registration No. 201301027403 (1057232-T)), a company incorporated in Malaysia, and where the context requires its affiliate Mobiweb Sdn Bhd, and its authorised personnel, representatives and subcontractors.
In this Agreement:
If you register for a free trial, we will make one or more Services available to you on a trial basis free of charge until the earlier of:
ANY DATA YOU ENTER DURING THE FREE TRIAL AND ANY CONFIGURATION OR CUSTOMISATION YOU PERFORM MAY BE PERMANENTLY LOST UNLESS YOU PURCHASE A SUBSCRIPTION TO THE SAME SERVICE OR EXPORT YOUR DATA BEFORE THE TRIAL ENDS.
DURING THE FREE TRIAL, THE SERVICES ARE PROVIDED “AS IS” WITHOUT WARRANTY OF ANY KIND.
Subject to this Agreement and the applicable Order Form, we will:
We will maintain administrative, physical and technical safeguards designed to protect the security, confidentiality and integrity of Your Data while it is hosted in our cloud infrastructure, as described in our Documentation and Privacy Notice.
For client-hosted / on-premise / PC-hosted installations, you are responsible for your own hardware, operating system, network, firewall, security, antivirus, backup and restore.
We are responsible for the performance of our employees and contractors and their compliance with this Agreement, within the scope of services we provide.
From time to time we may provide Beta Services at no charge. Beta Services are for evaluation only, may be changed or discontinued at any time, and are provided “AS IS” without warranty.
Unless stated otherwise in an Order Form, Services and Software are provided as subscriptions for the term specified in the Order Form.
Your use of the Services may be subject to usage limits (e.g. number of users, branches, devices, messages, storage, transactions) as stated in the Order Form or Documentation. You agree not to exceed these limits. If you exceed them, we may:
You agree to:
4.3.1 Verification Duty. The Services generate figures, documents, files, messages and reports from data that you supply and settings that you configure. Output is only as accurate as that input and configuration. Before any payment, disbursement, statutory submission, tax filing, e-Invoice submission, bank file upload, customer communication, published document or business decision, an authorised and competent person in your organisation must independently check and approve the relevant output. This applies to every module, including:
BizCloud does not review, audit, certify or approve Your Data or output, and does not provide accounting, tax, audit, payroll, legal or HR advice. We are not a licensed tax agent under Section 153 of the Income Tax Act 1967, a registered company secretary, an audit firm, or a firm registered under the Accountants Act 1967. Failure to perform this verification is a customer failure, and we are not liable for any loss, penalty, fine, back-payment, interest, surcharge or third-party claim caused wholly or partly by output that you did not verify before use.
You must NOT use the Services, website or software to send, store or publish any content that is: unlawful, harassing, fraudulent, defamatory, abusive, threatening, harmful, vulgar, obscene, sexually explicit, racist, hateful, misleading, scam-related, or otherwise in violation of any law or third-party rights.
We may suspend or terminate your account immediately if we reasonably believe you are using the Services for illegal, abusive, spam or prohibited activities. In such cases, fees paid are not refundable.
You agree that you will not:
The following apply in addition to Section 4.3 where the relevant module is subscribed.
4.5.1 Payroll. BMO Payroll is a calculation and record-keeping tool, not a payroll bureau, tax agent or statutory filing agent. The employer remains legally responsible for correct remuneration, deductions, contributions, submissions and record retention. Statutory rates, tables, ceilings, categories and file formats change from time to time. We will use commercially reasonable efforts to update the software within a reasonable period after an authority publishes a change and its technical specification, but we do not warrant that an update will be available before any particular payroll run or submission deadline.
4.5.2 Biometric and Sensitive Data. Biometric data is sensitive personal data under the amended PDPA and requires explicit consent. If you use fingerprint, facial, palm or iris recognition for attendance clocking, kiosk access, door access or POS login, you are solely responsible for obtaining and retaining written consent from each affected individual, for providing a reasonable non-biometric alternative where consent is refused or required by law, and for lawful retention and deletion of biometric templates. The same applies to health, medical certificate, disability, religious and disciplinary records. We do not verify that consent has been obtained and are not liable for any resulting regulatory action or employee claim.
4.5.3 Attendance and Time Records. Attendance capture may rely on mobile devices, GPS, network location, Wi-Fi, QR codes, biometric or card devices and third-party hardware. Location accuracy, device clock accuracy, permissions, connectivity, battery state and hardware condition are outside our control. GPS and geofence readings are indicative only and must not be treated as conclusive proof of location. You are responsible for shift, rest day, public holiday, overtime and rounding configuration, and for reconciling records before using them for payroll, discipline, dismissal or any Employment Act 1955 or Industrial Relations Act 1967 process.
4.5.4 e-Leave and e-Claim. Entitlement tables, accrual rules, carry-forward, approval routing, claim categories, limits and mileage rates are configured by you. The system applies your configuration and does not determine or guarantee statutory minimum entitlements. You are responsible for compliance with the Employment Act 1955, any collective agreement, and your own contracts and handbook.
4.5.5 POS, Inventory and Membership. You are responsible for pricing, discount authority, tax and SST configuration, cash handling, till reconciliation, void and refund controls, stock counts and costing method. Where offline or local caching mode is used, transactions held on a local device before synchronisation may be lost if the device fails, is reset, is stolen or is not synchronised. Payment terminals and gateways are third-party services; we do not store full payment card numbers and are not a payment processor.
4.5.6 CRM, Queue and Messaging. You are responsible for the lawful basis of every contact record, message content, opt-in and opt-out handling, honouring direct marketing cessation notices under Section 43 of the PDPA, and the accuracy of any campaign, follow-up sequence or chatbot flow you configure or approve. Where an automated or AI agent replies to your end users, you are responsible for disclosing that the interaction is automated and for providing a route to a human where appropriate. A message sent from your account is your message and may bind you.
4.5.7 Accounting and e-Invoice. Unless expressly agreed in writing, we are not appointed as your e-Invoice intermediary or tax agent and do not submit on your behalf. You are responsible for TIN, registration details, classification codes, tax types, exemption status, buyer details, submission timing, and for monitoring validation, rejection and cancellation windows in the LHDN MyInvois system.
4.5.8 Permissions and Segregation of Duties. You are responsible for role permissions, approval workflows and segregation of duties inside your account, particularly for payroll, claim and leave approval, discount authority, void transactions, price overrides, stock adjustment, credit note issuance and data export rights.
The Services may interoperate with or rely on third-party applications or services (such as payment gateway, SMS / WhatsApp providers, government e-Invoice platforms, or client-hosted systems). Any contract with these providers is between you and the provider. We are not responsible for the acts, omissions, performance or security of third-party providers.
If you enable a third-party integration, you authorise us to exchange Your Data with that provider to enable the integration. We are not responsible for any modification, deletion or misuse of Your Data by such third-party providers.
You agree to pay all fees specified in Order Forms. Unless otherwise stated:
Invoices are payable within the period specified in the Order Form (typically 30 days). Late payments may incur interest and may result in suspension of Services until full payment is received.
Fees are exclusive of taxes (e.g. SST). You are responsible for all applicable taxes, except those based on our own income.
The Services, Software and Content are owned by us and/or our licensors and are protected by intellectual property laws. No rights are granted to you other than those expressly stated in this Agreement.
You grant us a limited licence to host, process and display Your Data solely for the purpose of providing the Services and related support.
You grant us a royalty-free licence to use suggestions or feedback you provide to improve our products and services.
Each party agrees to protect the other party’s confidential information with at least the same care it uses to protect its own similar information (and not less than reasonable care).
Confidential information may be disclosed where required by law, subject to reasonable prior notice (where legally permitted).
For all personal data that you or your Users enter, upload, import or generate inside your own account, you are the Data Controller and BizCloud acts only as Data Processor under the Personal Data Protection Act 2010 as amended by the Personal Data Protection (Amendment) Act 2024. This includes employee, payroll, attendance, biometric, leave, claim, member, customer, contact and messaging records.
As Data Controller you are solely responsible to:
As Data Processor we will process personal data in accordance with your documented instructions and the subscribed service scope, apply reasonable security measures consistent with the Security Principle, and impose confidentiality obligations on personnel with access. You warrant that your instructions to us are lawful, and you indemnify us in respect of instructions that are not.
8A.1 Breach Notification. A Data Controller must notify the Commissioner of a personal data breach within the statutory timeline, and must notify affected individuals without undue delay where the breach is likely to cause significant harm. Because you are the Data Controller for the data in your account, that obligation rests with you, not with us. Where we become aware of a security incident affecting your data in systems under our control, we will notify you without undue delay and provide reasonable information to help you assess and report it, but we do not report on your behalf unless expressly agreed in writing. You must maintain your own breach response procedure, escalation contact and breach record register, and must notify us promptly of any breach originating in your own environment, credentials or devices.
8A.2 Cross-Border Processing. Some processing takes place outside Malaysia, including cloud hosting, messaging providers, push notification services, email and SMS gateways and AI providers. Where we transfer data on your instruction, you as Data Controller remain responsible for the lawfulness of that transfer and for any transfer impact assessment required of you. We will provide reasonable information about processing locations and a current sub-processor list on written request.
Each party represents that it has the legal power to enter into this Agreement.
EXCEPT AS EXPRESSLY STATED IN THIS AGREEMENT, THE SERVICES, SOFTWARE, CONTENT AND BETA SERVICES ARE PROVIDED “AS IS” AND “AS AVAILABLE” WITHOUT ANY WARRANTY OF ANY KIND, WHETHER EXPRESS, IMPLIED OR STATUTORY, INCLUDING WARRANTIES OF MERCHANTABILITY, FITNESS FOR A PARTICULAR PURPOSE, AND NON-INFRINGEMENT.
The Services may include artificial intelligence, machine learning, large language model, generative AI, automation, agentic workflow or robotic process automation features (collectively "AI Features"). These may be built into our software or supplied by third-party AI providers whose models we do not build, own, train or control.
AI output is generated by a statistical model. It is not authored, drafted, written, reviewed, verified, endorsed or approved by BizCloud. We do not adopt AI output as our own statement, advice, representation, opinion, certification or recommendation. Where AI output appears inside the Services it appears as machine-generated content presented to you for your review, in the same way that an imported file or a search result is not our statement. AI Features are assistance tools only and do not replace human review, professional advice or management judgment.
You must assume AI output may contain errors. Known and expected limitations include:
Before any AI output is relied on, sent to a third party, published, paid, filed, submitted to an authority, or used as the basis of a business decision, an authorised and competent person in your organisation must read it, verify it against the underlying source data, correct it as needed, and approve it. You should decide internally who may use AI Features, for what, and who signs off. We recommend recording that sign-off.
AI Features must not be the sole basis for any decision producing a legal or similarly significant effect on an individual, including hiring, dismissal, non-confirmation, promotion, demotion, disciplinary action, performance rating, payroll adjustment, rejection of a leave or claim application, credit assessment, or customer blacklisting. Meaningful human review by a person with authority to change the outcome is required in every such case, and you are responsible for keeping a record of it.
Where AI Features are enabled, prompts, inputs, documents or records reasonably necessary for the feature may be transmitted to third-party AI providers and processed outside Malaysia. Where we control the integration we will use commercially reasonable efforts to limit the data shared to what is reasonably necessary and to select provider settings that do not permit customer data to be used to train the provider's general-purpose models. We do not control every aspect of a third-party AI provider's processing, retention, model behaviour or later changes to their terms. You decide whether to enable AI Features and which Users may access them, and you are responsible for lawful basis, PDPA compliance and internal approval for data submitted to them.
Where you deploy AI or automated agents to communicate with your employees, customers or the public, you are responsible for disclosing that the interaction is automated, for providing a route to a human where appropriate, and for compliance with any applicable AI governance guideline, code or legislation now or later in force in Malaysia.
We may suspend or restrict AI access where we reasonably believe there is a security, legal, platform-compliance, cost-abuse or misuse risk.
As between the parties, and to the extent permitted by law, AI output generated from your inputs is treated as Your Data. We make no warranty that AI output is original, protectable by copyright, or free from similarity to output generated for other users, and no warranty that its use will not infringe third-party rights. You are responsible for checking AI output for third-party rights before publication or commercial use. Our prompts, model configurations, tuning and orchestration logic remain our intellectual property.
AI Features may be metered, capped, throttled, priced separately, changed or withdrawn. We may change, replace, retrain or reconfigure models at any time, including where a provider changes its terms, pricing or availability. Resulting changes in behaviour or output quality are not defects. AI Features are excluded from any service level target unless a signed agreement states otherwise.
In addition to Section 9, AI Features are provided strictly "as-is" and "as-available" with no warranty that they will be accurate, reliable, complete, fit for any particular purpose, free from bias or free from error. You assume all risk associated with the use of AI Features.
To the maximum extent permitted by law and without limiting Section 11, we shall have no liability for any loss, damage, penalty, fine, claim, cost or expense arising from your use of or reliance on AI output, any inaccuracy, error, hallucination, bias or omission in AI output, decisions made by you or your Users based on AI output, any third-party claim (including intellectual property claims) arising from AI-generated content, any regulatory action resulting from the use of AI output in statutory submissions, loss or misuse of data processed by third-party AI providers, or the suspension, modification or discontinuation of any AI Feature.
You will indemnify and hold us harmless against claims, losses, penalties, liabilities, costs and expenses arising from AI output that you use, publish, submit or rely on, and from your failure to review AI output in accordance with Sections 4.3.1 and 9A.3.
In general, we will defend you against third-party claims alleging that the core BMO Service infringes intellectual property rights, and you will defend us against third-party claims arising from Your Data, illegal use, or breach of this Agreement. Any such obligations will be subject to prompt notification, control of defence, and reasonable cooperation.
TO THE MAXIMUM EXTENT PERMITTED BY LAW, EACH PARTY’S TOTAL AGGREGATE LIABILITY ARISING OUT OF OR RELATED TO THIS AGREEMENT WILL NOT EXCEED THE TOTAL AMOUNT PAID BY YOU FOR THE SERVICES GIVING RISE TO THE CLAIM DURING THE TWELVE (12) MONTHS IMMEDIATELY PRECEDING THE FIRST INCIDENT.
NEITHER PARTY WILL BE LIABLE FOR ANY INDIRECT, INCIDENTAL, SPECIAL, CONSEQUENTIAL OR PUNITIVE DAMAGES (INCLUDING LOSS OF PROFITS, REVENUE, DATA OR BUSINESS INTERRUPTION), EVEN IF ADVISED OF THE POSSIBILITY OF SUCH DAMAGES.
In particular, we are not liable for penalties, interest or losses arising from wrong or incomplete data entered by your Users, incorrect configuration of payroll, statutory, accounting or e-Invoice settings, your failure to review and verify output before payment or submission as required by Sections 4.3.1 and 9A.3, biometric consent failures, or unauthorised access resulting from weak passwords, shared credentials, phishing or failure to follow good security practice within your organisation.
Exceptions. Nothing in this Agreement excludes or limits liability for death or personal injury caused by negligence, for fraud or fraudulent misrepresentation, or for any other liability that cannot lawfully be excluded or limited under Malaysian law. Your obligations to pay fees and your indemnity obligations under Sections 10 and 9A.10 are not subject to the cap above. Each limitation and exclusion operates separately, and if any part is held unenforceable the remaining parts continue to apply to the fullest extent permitted by law.
This Agreement starts on the date you first accept it and continues until all subscriptions have expired or been terminated.
Each subscription term is specified in the Order Form and will renew as stated there, unless either party gives timely written notice of non-renewal.
Either party may terminate this Agreement for material breach if the breach is not remedied within a reasonable cure period after written notice, or if the other party becomes insolvent or subject to similar proceedings.
Upon written request made within thirty (30) days after termination or expiry, we will provide you with access to export Your Data as described in the Documentation (for cloud-hosted Services). After that period, we may delete or anonymise Your Data, except where retention is required by law.
This Agreement is governed by the laws of Malaysia. Any dispute that cannot be resolved amicably shall be submitted to the exclusive jurisdiction of the courts of Malaysia.
The parties are independent contractors. Nothing in this Agreement creates a partnership, joint venture or employment relationship.
If any provision of this Agreement is held invalid, the remaining provisions will remain in full force and effect.
This Agreement, together with the applicable Order Forms, Privacy Notice and SLA, constitutes the entire agreement between the parties regarding the Services and supersedes all prior proposals or agreements, whether written or oral, relating to the same subject matter.
Electronic acceptance. Acceptance may be given electronically, including by clicking to accept, ticking an acceptance box, or continued use of the Services after notice of updated terms. You agree that electronic acceptance has the same legal effect as a signed document under the Electronic Commerce Act 2006 and the Digital Signature Act 1997, and that our acceptance records and computer-generated records of your use of the Services may be produced as evidence, including under Section 90A of the Evidence Act 1950.
Survival. Sections 4.3 (Your Responsibilities), 4.5 (Module-Specific Responsibilities), 7 (Proprietary Rights), 8 (Confidentiality), 8A (Data Protection Roles and Breach Notification), 9 (Warranties and Disclaimers), 9A (Artificial Intelligence and Automated Features), 10 (Indemnification), 11 (Limitation of Liability), 13 (Data Portability on Termination) and any provision that by its nature should survive will survive termination or expiry of this Agreement.