Last updated: 24 July 2026
Status: Early access product note. Not a signed DPA and not legal advice.
Operator: Lazuar · Contact: [email protected]
This page explains who does what with data in BalasAuto. Use it with our Privacy Policy and Subprocessors. Enterprise customers may later require a formal Data Processing Agreement (DPA); this page is the product-facing summary.
1. The parties
| Party | Who |
|---|---|
| You / Shop / Workspace owner | The business using BalasAuto |
| Lazuar | Operator of BalasAuto (lazuar.com) |
| Your customers | People who message your WhatsApp business number |
| Meta | WhatsApp Cloud API platform |
| Optional AI vendor | LLM API when you enable a non-mock provider |
2. Controller vs processor (typical)
| Data | Typical role of the shop | Typical role of Lazuar (BalasAuto) |
|---|---|---|
| Your customers’ WhatsApp chats & profiles in the inbox | Controller (you decide why you message them) | Processor (we host/process to provide the product on your instructions) |
| Knowledge base content you upload | Controller | Processor |
| Your staff account (email, name, login) | — | Controller (we manage accounts for the service) |
| Billing / trial usage meters | — | Controller |
| Channel tokens (encrypted) | You supply credentials you control | We store/process as needed to connect Cloud API (processor of secret material for the service; high sensitivity) |
| Product security logs | — | Controller (operate and secure the platform) |
In plain language:
Your customer conversations are your business’s relationship. BalasAuto is the tool. Lazuar processes that content so auto-reply, inbox, and takeover work — not to build unrelated profiles of your customers.
3. Instructions and product features
By using BalasAuto you instruct Lazuar to process customer and knowledge data to:
- receive and send WhatsApp messages via Cloud API,
- store and display threads in the inbox,
- run rules and optional AI replies,
- escalate / pause AI for human takeover,
- enforce trial and plan limits,
- provide export/delete tools where implemented.
You must not instruct us (via configuration or content) to process data unlawfully or in breach of Meta policies. See Acceptable Use.
4. Meta / WhatsApp
Message transport on WhatsApp is handled under Meta’s terms and infrastructure. Meta is generally an independent controller/processor of platform traffic under its own policies — not “Lazuar acting as Meta.”
You remain responsible for WhatsApp Business acceptance, templates, and conversation fees.
5. Subprocessors
Lazuar may use infrastructure and optional AI vendors as described in Subprocessors. Those parties process data only as needed for the listed purposes.
6. International processing
Depending on configuration, hosting or AI APIs may process data outside Malaysia. See Privacy Policy § international transfers. Confirm regions for production deployments with Lazuar if required for your compliance program.
7. Security measures (summary)
- Password hashing
- Encryption of channel tokens at rest
- Authenticated, workspace-scoped access
- Signed webhooks on the WhatsApp path
- Operational logging for reliability and security
Details evolve with the product; this is not a SOC 2 report.
8. Retention, export, deletion
- Active workspace: data retained to provide the service
- Owners: export / delete pathways in product where available
- After delete: application cascade; backups may retain residual data for a limited operational window
See Privacy Policy for more detail.
9. Your customers’ rights
People who message you typically exercise privacy rights with your business first (you are closest to the customer relationship). Lazuar assists via product tools and support ([email protected]) as processor of workspace data.
10. Formal DPA
This page is not a signed DPA. If you need contractual processor terms (liability, audit, breach notice timelines), contact [email protected] for early-access / pilot arrangements.