aiBalas

Privacy Policy

Last updated 15 August 2026.

Who this covers

This policy covers two groups of people. The first is you — the person who holds or works on an aiBalas account. The second is your customers: the people who message a channel you have connected to aiBalas — your WhatsApp number, your Telegram account, or the chat widget on your website. They never signed up for aiBalas and most of them will never have heard of it, but their messages pass through it, so this policy describes what happens to them too.

aiBalas is operated by AIBALAS TECHNOLOGY. For your own account data we are the data controller. For your customers’ data you are the controller and we are your processor — we handle it to run the service for you. That split matters for the cross-border section below.

What we collect

Account details. The name and email address of each person on the account, a hashed password (never the password itself), the business name and time zone, and the billing contact details used to issue bills.

Message content. The full text of messages sent to and from your connected channels, stored so you can read the conversation in the console and so the assistant has context to reply with. Voice notes are stored as their transcript and pictures as a written description of them.

Contact records. How each person who messages you is identified on the channel they used — a phone number and WhatsApp profile name, a Telegram chat id with whatever name or username that account shows, or, for a website visitor, a random identifier we generate that is tied to nothing else about them — plus anything you or your team add about them: a display name, email, company, address, tags, notes, lead status, and who on your team is handling them.

What the assistant works out for itself. So that it is useful to someone who comes back weeks later, the assistant keeps a short summary of what it has learned about each contact from the conversation, and it may fill in that contact’s email, company, or address when they give it. It cannot invent any other field, and it never reads or writes your team’s private notes.

Business content you enter. Your knowledge base, business facts such as opening hours and address, products and their images, promotions, and — where you use them — your bookable services and the bookings made against them.

Usage and billing records. How much of your RM usage balance each reply spent, the number of tokens each model call used, your usage balance and any top-ups you buy, bills and their payment status, and server logs kept for security and debugging. The current plans include a monthly RM allowance — RM5.00 on the Free plan — and these records are what that allowance is metered against. Older plans meter a number of replies instead, against the same records.

Why we collect it

To run the service you asked for: to generate replies from your business information, to show you your conversations and contacts, to meter your plan’s usage allowance and bill you correctly, to sign you in and let you reset your password, to keep the platform secure and diagnose failures, and to send email — service email such as verification, password resets, and billing notices, and, if you turn them on, alerts telling your team that a conversation needs a person.

We do not sell personal data, we do not share it with advertisers, and we do not use your conversations or your customers’ data to market anything to anyone.

Cross-border processing

To generate replies, the content of messages sent to your connected channels is transmitted to an AI provider operating outside Malaysia. We use a mix of Google (Gemini) and OpenAI, and which one handles any particular reply is an operational choice of ours. Voice notes, pictures, and spoken replies always go to OpenAI. This applies to messages from your customers, who are not aiBalas users. If you use aiBalas, you are responsible as the data controller for informing your own customers of this processing.

In practice this means: when someone messages you, what they wrote is sent to one of those providers so a reply can be written. If they send a voice note or a picture, the audio or the image itself is sent to OpenAI to be transcribed or described, and the resulting text then goes to the reply provider with the rest of the conversation. When the assistant answers with a voice note, the text of that reply is also sent to OpenAI to be spoken. These transfers happen for every message the assistant handles, including messages that contain whatever personal information your customer chose to put in them.

The channel itself carries the message before we ever see it. A message to your WhatsApp number passes through WhatsApp, and a message to your Telegram account passes through Telegram — both operated outside Malaysia. The website widget talks to our own servers directly, with no third party in between.

On paid plans you may point aiBalas at your own AI provider instead of ours. If you do, message content goes to that provider on your instructions rather than to the ones named above, and what they do with it is a matter between you and them.

Under the Personal Data Protection Act 2010 these are transfers of personal data outside Malaysia. Because your customers are your data subjects and not ours, we cannot obtain their consent for you — telling them, and having a lawful basis for it, is your obligation as the controller.

Alongside these, we use Amazon Web Services for hosting our offsite database backups and for sending email — both service email to you and, where you switch them on, alerts to your team that carry a customer’s name and how to reach them on the channel they messaged from. We use a payment gateway to issue and collect bills; it receives only the billing contact details and the amount due, never your conversations.

Google Calendar and Sheets

If you choose to connect a Google account, aiBalas asks Google for two narrow permissions: to create a calendar and a spreadsheet in that account, and to manage only what it created. It cannot see your other calendars, your events, or any other file in your Google Drive — Google’s own permission system makes that impossible, not just something we promise.

What flows through that connection is your own booking and lead records — the same data described above — written into your calendar and your spreadsheet so your team can work from the tools they already use. The flow is one way, from aiBalas to your Google account: nothing is read back, and nothing from your Google account reaches the AI providers named above. Calendar events are never sent to your customers — no invitations, no emails from Google on your behalf.

The credential Google gives us for this is stored encrypted on our servers and is not shared with anyone. Disconnecting deletes it immediately; the calendar and the spreadsheet stay in your Google account, because they are yours. aiBalas’s use of information received from Google APIs adheres to the Google API Services User Data Policy, including its Limited Use requirements.

TikTok

If you choose to connect a TikTok account on the Marketing page, aiBalas asks TikTok for two narrow permissions: to read the account’s basic profile — its id, display name and profile photo, which we show so you can see which account is connected — and to send video to that account. In neither case can it read your messages, your followers, your analytics, or anyone else’s account.

There are two ways a video can be sent, and which one applies depends on the permission your account granted when you connected it. With the draftpermission, aiBalas cannot post on your behalf at all: every video lands in your TikTok drafts, and only you, inside the TikTok app, decide whether it is ever published. With the direct postingpermission, aiBalas does post on your behalf — the video is published to your account with the caption you wrote and the audience you chose on the Marketing page, at the time you chose. Before showing you those options we read your account’s current posting settings from TikTok — which audiences it allows, and whether it permits comments, Duet and Stitch — so the choices offered are ones your account actually permits. The Marketing page tells you which of the two applies to each connected account, and an existing connection keeps its draft-only permission until you reconnect it.

What flows through that connection is only what you put into it: the video file you upload, and — on the direct path — the caption and posting settings you chose. On the draft path the caption stays on our servers as your own record, because TikTok’s draft upload does not carry captions, so you re-enter the details in the TikTok app when you publish. Uploaded video files are kept for thirty days so a failed send can be retried, then deleted; the post history keeps only the caption and the outcome. Nothing from your TikTok account reaches the AI providers named above.

The credential TikTok gives us for this is stored encrypted on our servers and is not shared with anyone. Disconnecting on the Marketing page revokes it with TikTok and ends the connection; you can also withdraw access at any time from your own TikTok app’s security settings.

Where data is stored

The live database and the images you upload for products and promotions sit on our own servers in Singapore. A nightly backup of the database is copied offsite to Amazon S3 in Malaysia.

Two things are deliberately left out of that offsite backup. The live WhatsApp session credentials for QR-linked numbers are excluded, because holding those outside our own infrastructure would mean holding the means to impersonate your WhatsApp session. The images you upload are also not in the backup — if they were ever lost you would need to upload them again, which is why we accept that gap. Everything else in the database is included.

How long we keep it

We keep your account data, conversations, and contact records for as long as your account is open, because the assistant and your team both need the history to work from. The one exception is the activity log — the record of what happened on your account, such as a connection dropping or a setting changing — which we delete after 90 days. Otherwise there is no automatic deletion after a fixed period, and we would rather say that plainly than publish a retention schedule we do not actually run.

If you close your account, or ask us to delete a conversation or a contact, we delete it from the live system. Deletion is handled by us on request rather than by a button in the console. Backup copies age out on their own rotation, so a deleted record can survive in a backup for a period afterwards before that backup is replaced. Billing records are kept longer where we have to keep them for tax and accounting purposes.

Separation between businesses

Every business on aiBalas is a separate tenant, and every query the platform runs is scoped to a single tenant. One business’s conversations, contacts, knowledge, products, and bills are never returned to another. Staff you invite see only the agents you invited them to, so an agency running several clients does not expose one client to another.

Inside a single account it works the other way round, deliberately. If one person messages two of your agents, your team sees one contact record for them, with the profile details shared across the account; the conversations themselves stay with the agent that held them.

The exception is our own support staff: an administrator can open a tenant to help with a problem, and when they do, the console shows a banner saying it is being viewed by an administrator.

Your rights under the PDPA

Under Malaysia’s Personal Data Protection Act 2010 you can ask us for a copy of the personal data we hold about you, ask us to correct it if it is wrong, ask us to limit how it is processed, and withdraw a consent you previously gave. Email us at the address below and we will respond within a reasonable time; we may need to confirm who you are first.

Withdrawing consent may mean we can no longer run the service for you — for example, the assistant cannot generate replies without sending message content to the providers named above, so refusing that means the assistant cannot be used.

If you are someone who messaged a business using aiBalas and you want your data seen to, contact that business first: they are the controller of it, and a request to access, correct, or delete it is theirs to decide. If you cannot reach them, write to us and we will help you get to the right party.

Changes to this policy

We will update this page when the service changes, so check it from time to time. The providers named above are kept current; which of them serves a particular reply is a routine operational choice and is not separately announced.

Contact

For anything in this policy, email [email protected] or write to AIBALAS TECHNOLOGY, No 355, Jalan Timur 2/7C, Bandar Enstek, 71760 Bandar Enstek, Negeri Sembilan.

Back to sign in