Privacy Policy
Last updated: 2026-05-09 — Drafted with reference to Malaysia PDPA 2010
1. Information We Collect
We collect the following categories of personal data when you use Alpha Connex:
- Account data: Full name, email address, and hashed password provided during registration.
- Company data: Company name used to create your workspace.
- Phone numbers: WhatsApp phone numbers you import for campaigns or customer contacts.
- Message content: Text messages you compose and send via blast campaigns or recurring rules; replies received from recipients.
- Usage data: Log data including IP address, browser type, pages visited, and feature usage for security and analytics.
- Technical data: Evolution API instance identifiers, webhook endpoint URLs, and delivery logs.
2. How We Use Your Data
- To operate and provide the Alpha Connex platform services.
- To authenticate your identity and secure your account.
- To deliver WhatsApp messages on your behalf via the Evolution API integration.
- To run AI sentiment classification on received message replies.
- To send transactional emails (e.g., account setup, security alerts).
- To monitor platform health and performance.
We do not sell, rent, or share your personal data or your customers' data with any third party for marketing purposes.
3. Data Retention
- Webhook delivery logs: Retained for 30 days, then automatically purged.
- Health check logs: Retained for 90 days, then automatically purged.
- Campaign and message data: Retained for the duration of your active account.
- Account data: Retained until you request deletion or your account is terminated.
4. Data Security
We implement industry-standard security measures including encrypted connections (TLS), hashed passwords, and JWT-based authentication with short-lived tokens. Sensitive credentials are stored encrypted and never logged.
5. Your Rights (Malaysia PDPA 2010)
Under the Personal Data Protection Act 2010 (Malaysia), you have the right to:
- Access the personal data we hold about you.
- Correct inaccurate or incomplete personal data.
- Request deletion of your personal data (subject to legal obligations).
- Withdraw consent for data processing where consent is the legal basis.
6. Sub-processors
We use a small number of trusted infrastructure providers to operate the Service. Each processes only the data needed for its specific function.
| Provider | Region | Data processed | Privacy policy |
|---|---|---|---|
| Anthropic, PBC | United States | Inbound message text submitted to Claude for sentiment classification and optional AI replies. | anthropic.com/legal/privacy |
| Stripe, Inc. | United States / Ireland | Billing email, subscription and payment-card metadata. We never see your full card number. | stripe.com/privacy |
| Cloudflare, Inc. | United States (global edge) | DNS, CDN, and the access tunnel that fronts the dashboard. Sees IP and request metadata; does not see message content. | cloudflare.com/privacypolicy |
| Oracle Cloud Infrastructure | Singapore region | Hosts our application servers and database. All workspace data, including messages and contact lists, is stored here. | oracle.com/legal/privacy |
| Resend, Inc. | United States | Transactional email delivery (welcome email, password reset, billing notifications). Sees recipient email and message body. | resend.com/legal/privacy-policy |
7. International transfers
Operating the Service involves transferring personal data outside Malaysia to the sub-processors listed above (United States, Ireland, Singapore, and the global Cloudflare edge). We rely on the "appropriate safeguards" limb of section 129 of the PDPA, supported by each provider's contractual data-processing terms and, where applicable, EU Standard Contractual Clauses.
8. Data retention
| Category | Retention |
|---|---|
| Message content (inbound & outbound) | Up to 5 years for tax/record-keeping compliance, or shorter if the customer configures a workspace-level retention setting. |
| Audit logs (admin actions, access) | 12 months. |
| Webhook delivery logs | 30 days. |
| Health-check logs | 90 days. |
| Off-server backups | 14-day rolling snapshots, plus longer-term archive of up to 12 months. |
| User-consent log (signup record) | Lifetime of the workspace + 6 years. |
9. Cookies
We use the minimum cookies needed to operate the Service:
- NextAuth session cookie — keeps you logged in. Strictly necessary; cannot be disabled while using the dashboard.
- Cloudflare
__cf_bm— bot-management cookie set by Cloudflare in front of the application. Used to distinguish humans from automated traffic. - Locale preference — remembers whether you chose English or Bahasa Melayu.
We do not use advertising or cross-site tracking cookies.
10. Contact us
For data access requests, deletion requests, or any privacy concerns:
We aim to respond to all requests within 21 days as contemplated by the PDPA.