Waagen
Draft — not yet in force. This document is published for review and does not bind anyone yet. Missing configuration: LEGAL_ENTITY_NAME, LEGAL_REGISTRATION_NO, LEGAL_ADDRESS, LEGAL_PRIVACY_EMAIL, LEGAL_DB_REGION, LEGAL_BACKUP_REGION.

Privacy Policy

Last updated 26 July 2026.

Who this covers

This policy covers two groups of people. The first is you — the person who holds or works on a Waagen account. The second is your customers: the people who send WhatsApp messages to a number you have connected to Waagen. They never signed up for Waagen and most of them will never have heard of it, but their messages pass through it, so this policy describes what happens to them too.

Waagen is operated by ACME SDN BHD. For your own account data we are the data controller. For your customers’ data you are the controller and we are your processor — we handle it to run the service for you. That split matters for the cross-border section below.

What we collect

Account details. The name and email address of each person on the account, a hashed password (never the password itself), the business name and time zone, and the billing contact details used to issue bills.

WhatsApp message content. The full text of messages sent to and from your connected number, stored so you can read the conversation in the console and so the assistant has context to reply with. Voice notes are stored as their transcript and pictures as a written description of them.

Contact records. The phone number and WhatsApp profile name of each person who messages you, plus anything you or your team add about them — a display name, email, company, address, tags, notes, lead status, and who on your team is handling them.

Business content you enter. Your knowledge base, business facts such as opening hours and address, products and their images, and promotions.

Usage and billing records. How many AI credits each reply consumed, the number of tokens each model call used, bills and their payment status, and server logs kept for security and debugging.

Why we collect it

To run the service you asked for: to generate replies from your business information, to show you your conversations and contacts, to meter your plan’s credit allowance and bill you correctly, to sign you in and let you reset your password, to keep the platform secure and diagnose failures, and to send you service email such as verification, password resets, and billing notices.

We do not sell personal data, we do not share it with advertisers, and we do not use your conversations or your customers’ data to market anything to anyone.

Cross-border processing

To generate replies, the content of messages sent to your WhatsApp number is transmitted to DeepSeek, operated outside Malaysia. Voice notes and images are transmitted to OpenAI, operated outside Malaysia. This applies to messages from your customers, who are not Waagen users. If you use Waagen, you are responsible as the data controller for informing your own customers of this processing.

In practice this means: when someone messages your number, what they wrote is sent to DeepSeek so a reply can be written. If they send a voice note or a picture, the audio or the image itself is sent to OpenAI to be transcribed or described, and the resulting text then goes to DeepSeek with the rest of the conversation. Both transfers happen for every message the assistant handles, including messages that contain whatever personal information your customer chose to put in them. When the assistant answers with a voice note, the text of that reply is also sent to OpenAI to be spoken.

Under the Personal Data Protection Act 2010 these are transfers of personal data outside Malaysia. Because your customers are your data subjects and not ours, we cannot obtain their consent for you — telling them, and having a lawful basis for it, is your obligation as the controller.

Alongside these, we use Amazon Web Services for hosting our offsite database backups and for sending service email, and a payment gateway to issue and collect bills. The payment gateway receives only the billing contact details and the amount due, never your conversations.

Where data is stored

The live database and the uploaded product images sit on our own servers in (database region not yet configured). A nightly backup of the database is copied offsite to Amazon S3 in (backup region not yet configured).

Two things are deliberately left out of that offsite backup. The live WhatsApp session credentials for QR-linked numbers are excluded, because holding those outside our own infrastructure would mean holding the means to impersonate your WhatsApp session. Product images are also not in the backup — if they were ever lost you would need to upload them again, which is why we accept that gap. Everything else in the database is included.

How long we keep it

We keep your account data, conversations, and contact records for as long as your account is open, because the assistant and your team both need the history to work from. There is no automatic deletion after a fixed period, and we would rather say that plainly than publish a retention schedule we do not actually run.

If you close your account, or ask us to delete a conversation or a contact, we delete it from the live system. Deletion is handled by us on request rather than by a button in the console. Backup copies age out on their own rotation, so a deleted record can survive in a backup for a period afterwards before that backup is replaced. Billing records are kept longer where we have to keep them for tax and accounting purposes.

Separation between businesses

Every business on Waagen is a separate tenant, and every query the platform runs is scoped to a single tenant. One business’s conversations, contacts, knowledge, products, and bills are never returned to another. Staff you invite see only the numbers you invited them to, so an agency running several clients does not expose one client to another.

The exception is our own support staff: an administrator can open a tenant to help with a problem, and when they do, the console shows a banner saying it is being viewed by an administrator.

Your rights under the PDPA

Under Malaysia’s Personal Data Protection Act 2010 you can ask us for a copy of the personal data we hold about you, ask us to correct it if it is wrong, ask us to limit how it is processed, and withdraw a consent you previously gave. Email us at the address below and we will respond within a reasonable time; we may need to confirm who you are first.

Withdrawing consent may mean we can no longer run the service for you — for example, the assistant cannot generate replies without sending message content to the providers named above, so refusing that means the assistant cannot be used.

If you are someone who messaged a business using Waagen and you want your data seen to, contact that business first: they are the controller of it, and a request to access, correct, or delete it is theirs to decide. If you cannot reach them, write to us and we will help you get to the right party.

Changes to this policy

We will update this page when the service changes, and we will tell account owners by email before a change that materially affects how personal data is handled.

Contact

For anything in this policy, email [email protected] or write to ACME SDN BHD, (registered address not yet configured).

Back to sign in