BalasAuto
How it worksWhy usFeaturesPricingBlogFAQ
Sign inStart free setup
How it worksWhy usFeaturesPricingBlogFAQ
Sign inStart free setup
Home/Legal/Privacy Policy

Trust & policies

Privacy Policy

How BalasAuto handles personal data for Malaysian SMEs — account and workspace data, WhatsApp conversations, knowledge base content, AI processing, retention, export/delete, and PDPA-oriented rights.

Early access · product of Lazuar

PrivacyTermsAcceptable useSubprocessorsData roles

Last updated: 24 July 2026
Status: Early access / MVP product documentation. This is not legal advice. Replace with counsel-reviewed copy before mass marketing or paid self-serve scale.

BalasAuto (“we”, “us”) is a product of Lazuar (lazuar.com). It provides AI-assisted auto-reply and inbox tools for small businesses, starting with WhatsApp via the official Meta WhatsApp Cloud API.

Contact: [email protected]
Website: https://lazuar.com


1a. Cookies and local storage (Phase 15–16)

Mechanism Purpose Essential?
Session cookie (balasauto_session, httpOnly, Secure in production, SameSite=Lax) Keep you signed in after login Yes — authentication
localStorage Optional dual-read bearer token during migration; active workspace id; UI prefs Functional
Marketing “OK” flags Dismiss cookie notice / early-access banner Preference

We do not use third-party advertising cookies on the product app. See the cookie notice on the marketing site.


1. Scope

This policy describes how we process personal data when you:

  • visit our marketing site,
  • create an account and workspace,
  • connect a messaging channel,
  • store knowledge content, or
  • use inbox, rules, and AI auto-reply features.

It applies to the BalasAuto software service operated by Lazuar for early access.


2. Who is who (roles)

Party Typical role Examples
Shop / workspace owner Controller of customer chats and knowledge content you put in BalasAuto Your customers’ WhatsApp messages, FAQ files, prices
BalasAuto Controller of account, billing/trial meters, and product operations data; processor of customer conversation and knowledge content on your behalf Email/password, AI run counters, encrypted channel tokens, job logs
Meta / WhatsApp Independent processing under Meta’s terms for Cloud API Message delivery on WhatsApp’s network
Optional AI provider Subprocessor when you enable a non-mock model Prompt text + retrieved knowledge snippets sent to generate a reply

In plain language: your customers’ messages belong to your business relationship. You decide what to put in the knowledge base and how AI is used. We run the software so you can receive, store, reply, and take over conversations.


3. Data we process

3.1 Account and workspace (shop side)

  • Name, email, password (hashed, not stored in plaintext)
  • Workspace name and membership
  • Product settings (e.g. AI on/off, rules)
  • Trial / plan and usage meters (e.g. AI runs)

3.2 Channel configuration (high sensitivity)

  • WhatsApp phone number ID and related Cloud API identifiers
  • Access tokens and webhook-related secrets — encrypted at rest with an application encryption key
  • Webhook verification configuration

3.3 Customer conversations (your customers)

  • WhatsApp identifiers and display metadata needed for the inbox
  • Inbound and outbound message text and timestamps
  • Whether a message was sent by AI, a human, or the system (e.g. escalation)
  • Escalation / needs-human flags and related state

3.4 Knowledge base

  • Titles and text you paste or upload (FAQ, policies, menus, PDFs/files as supported)
  • Derived chunks used for retrieval so AI answers stay grounded

3.5 AI processing

When AI auto-reply runs (and the provider is not a local “mock”):

  • Customer message text (or a relevant portion)
  • Retrieved knowledge snippets
  • Model configuration (provider/model id as configured)
  • Usage counts for limits and billing

3.6 Operations and security

  • Request IDs, error and job failure logs
  • Rate-limit and reliability signals
    We aim to avoid retaining full message bodies in logs longer than needed for debugging and security.

3.7 Support and sales

  • Messages you send to support or sales channels (email / WhatsApp), kept as needed to help you

3.8 Demo content

Sample or seeded FAQ packs are illustrative only and are not real customer data.


4. Why we process data (purposes)

Purpose Examples
Provide the service Sign-in, workspace, connect Cloud API, inbox, rules, AI reply, takeover
Security Authentication, encryption of tokens, abuse prevention, audit of failures
Limits and commercial terms Trial windows, AI run caps, plan activation
Support Diagnose stuck jobs, connection issues, billing questions
Improve reliability Aggregated operational metrics (not training public foundation models on your chats)

We process shop customer conversation and knowledge content to deliver the features you enable, on your instructions as controller of that content.


5. AI and automated replies

  • Replies may be generated automatically from your knowledge base and rules.
  • Sensitive topics (e.g. refunds, money disputes) are designed to escalate to a human where product rules apply — AI can still be wrong; review knowledge content and use takeover when needed.
  • We do not use your customer chat data to train public foundation models.
  • Optional third-party LLM providers process prompts only to generate replies when AI is enabled and a provider is configured.

6. Sharing and third parties

We do not sell customer chat data.

We share data only as needed to run the product, for example:

  • Meta / WhatsApp — to send and receive messages on the official Cloud API path
  • Infrastructure you (or your host) use for the app: database, Redis/job queue, file storage
  • AI API provider — only when a non-mock provider is configured
  • Professional advisors or authorities — if required by law

A living list of commercial subprocessors should be published as your production stack stabilises (hosting, email, error tracking, LLM).


7. International transfers

Depending on configuration, AI providers or hosting may process data outside Malaysia. Where that happens, processing is for delivering the service you requested. Confirm regions with your operator for production deployments.


8. Security (high level)

  • Passwords hashed
  • Channel tokens encrypted at rest
  • Authenticated access to workspace data
  • Tenant-scoped data model (workspaces isolated in application logic)
  • Signed webhooks and operational logging for the WhatsApp path

No method of transmission or storage is 100% secure; report suspected issues to your support contact.


9. Retention

Data Typical retention
Account & workspace config While the account/workspace is active
Conversations & knowledge While the workspace is active, unless you delete content or the workspace
Usage meters As needed for trial/plan enforcement and history
Security / job logs Short operational window for debugging and security
After workspace delete Tenant data is removed via application delete/cascade; backups may retain residual copies for a limited operational period

Exact windows may vary by deployment; operators should document backup TTL in production runbooks.


10. Export, deletion, and your rights

In product (workspace owners):

  • Export workspace data where the product provides export
  • Delete workspace / account pathways in Settings / Billing (as implemented)
  • Control knowledge content and channel disconnect

PDPA-oriented rights (subject to applicable law): access, correction, and deletion of personal data we hold about you as a user. For your customers’ personal data in chats, the business (you) is typically the primary point of contact; we assist as processor via product tools and support.

To exercise rights, email [email protected] and describe your request.


11. Children

BalasAuto is aimed at businesses, not children. We do not knowingly offer the service for children to create accounts.


12. Cookies and similar technologies

Essential cookies or local storage may be used for session / auth and basic preferences (e.g. language). If we add analytics or advertising cookies later, we will update this policy and, where required, provide a clearer cookie notice.


13. Changes

We may update this policy as the product evolves. Material changes for early-access users should be communicated via the product site or email when practical. The last updated date at the top will change.


14. Bahasa Malaysia (ringkas)

Kami memproses data akaun, konfigurasi saluran WhatsApp (token disulitkan), perbualan pelanggan, dan kandungan pengetahuan untuk menjalankan perkhidmatan balas auto dan peti masuk.
Perniagaan anda lazimnya mengawal data pelanggan; BalasAuto mengendalikan perisian bagi pihak anda.
Kami tidak melatih model asas awam menggunakan sembang pelanggan anda.
Anda boleh eksport atau padam ruang kerja mengikut ciri produk. Hubungi sokongan untuk permintaan privasi.


15. Related policies

  • Terms of Service
  • Acceptable Use Policy
  • Subprocessors
  • Data Processing & Roles
  • All policies

16. Disclaimer

This document is an MVP / early-access description of product practices. It is not a substitute for legal advice. Obtain counsel review before public mass marketing, regulated claims, or enterprise contracts.

Also in this set

  • Terms of Service
  • Acceptable Use Policy
  • Subprocessors
  • Data Processing & Roles
  • All policies

Questions

These pages describe how BalasAuto works today. They are not legal advice — have counsel review before mass paid marketing.

[email protected]Start early access →

Ready when you are

WhatsApp auto-reply with human takeover

Official Cloud API. Knowledge-grounded AI. Clear early-access trial for Malaysian SMEs.

Start early accessSee how it works
BalasAuto

AI auto-reply for WhatsApp — built for Malaysian SMEs who need a fast first reply without losing human control.

A product of Lazuar

  • Malaysia-first
  • Official Cloud API
  • Early access

Product

  • How it works
  • Product
  • Pricing
  • FAQ
  • Blog

Account

  • Sign up
  • Sign in
  • Open app
  • Support

Legal

  • Privacy
  • Terms
  • Acceptable use
  • Subprocessors
  • Data roles
  • All policies
  • [email protected]

© 2026 Lazuar. BalasAuto is a product of Lazuar.

WhatsApp is a trademark of Meta. BalasAuto is not affiliated with Meta.