Last updated: 24 July 2026
Status: Early access / MVP product documentation. This is not legal advice. Replace with counsel-reviewed copy before mass marketing or paid self-serve scale.
BalasAuto (“we”, “us”) is a product of Lazuar (lazuar.com). It provides AI-assisted auto-reply and inbox tools for small businesses, starting with WhatsApp via the official Meta WhatsApp Cloud API.
Contact: [email protected]
Website: https://lazuar.com
1a. Cookies and local storage (Phase 15–16)
| Mechanism | Purpose | Essential? |
|---|---|---|
Session cookie (balasauto_session, httpOnly, Secure in production, SameSite=Lax) |
Keep you signed in after login | Yes — authentication |
| localStorage | Optional dual-read bearer token during migration; active workspace id; UI prefs | Functional |
| Marketing “OK” flags | Dismiss cookie notice / early-access banner | Preference |
We do not use third-party advertising cookies on the product app. See the cookie notice on the marketing site.
1. Scope
This policy describes how we process personal data when you:
- visit our marketing site,
- create an account and workspace,
- connect a messaging channel,
- store knowledge content, or
- use inbox, rules, and AI auto-reply features.
It applies to the BalasAuto software service operated by Lazuar for early access.
2. Who is who (roles)
| Party | Typical role | Examples |
|---|---|---|
| Shop / workspace owner | Controller of customer chats and knowledge content you put in BalasAuto | Your customers’ WhatsApp messages, FAQ files, prices |
| BalasAuto | Controller of account, billing/trial meters, and product operations data; processor of customer conversation and knowledge content on your behalf | Email/password, AI run counters, encrypted channel tokens, job logs |
| Meta / WhatsApp | Independent processing under Meta’s terms for Cloud API | Message delivery on WhatsApp’s network |
| Optional AI provider | Subprocessor when you enable a non-mock model | Prompt text + retrieved knowledge snippets sent to generate a reply |
In plain language: your customers’ messages belong to your business relationship. You decide what to put in the knowledge base and how AI is used. We run the software so you can receive, store, reply, and take over conversations.
3. Data we process
3.1 Account and workspace (shop side)
- Name, email, password (hashed, not stored in plaintext)
- Workspace name and membership
- Product settings (e.g. AI on/off, rules)
- Trial / plan and usage meters (e.g. AI runs)
3.2 Channel configuration (high sensitivity)
- WhatsApp phone number ID and related Cloud API identifiers
- Access tokens and webhook-related secrets — encrypted at rest with an application encryption key
- Webhook verification configuration
3.3 Customer conversations (your customers)
- WhatsApp identifiers and display metadata needed for the inbox
- Inbound and outbound message text and timestamps
- Whether a message was sent by AI, a human, or the system (e.g. escalation)
- Escalation / needs-human flags and related state
3.4 Knowledge base
- Titles and text you paste or upload (FAQ, policies, menus, PDFs/files as supported)
- Derived chunks used for retrieval so AI answers stay grounded
3.5 AI processing
When AI auto-reply runs (and the provider is not a local “mock”):
- Customer message text (or a relevant portion)
- Retrieved knowledge snippets
- Model configuration (provider/model id as configured)
- Usage counts for limits and billing
3.6 Operations and security
- Request IDs, error and job failure logs
- Rate-limit and reliability signals
We aim to avoid retaining full message bodies in logs longer than needed for debugging and security.
3.7 Support and sales
- Messages you send to support or sales channels (email / WhatsApp), kept as needed to help you
3.8 Demo content
Sample or seeded FAQ packs are illustrative only and are not real customer data.
4. Why we process data (purposes)
| Purpose | Examples |
|---|---|
| Provide the service | Sign-in, workspace, connect Cloud API, inbox, rules, AI reply, takeover |
| Security | Authentication, encryption of tokens, abuse prevention, audit of failures |
| Limits and commercial terms | Trial windows, AI run caps, plan activation |
| Support | Diagnose stuck jobs, connection issues, billing questions |
| Improve reliability | Aggregated operational metrics (not training public foundation models on your chats) |
We process shop customer conversation and knowledge content to deliver the features you enable, on your instructions as controller of that content.
5. AI and automated replies
- Replies may be generated automatically from your knowledge base and rules.
- Sensitive topics (e.g. refunds, money disputes) are designed to escalate to a human where product rules apply — AI can still be wrong; review knowledge content and use takeover when needed.
- We do not use your customer chat data to train public foundation models.
- Optional third-party LLM providers process prompts only to generate replies when AI is enabled and a provider is configured.
6. Sharing and third parties
We do not sell customer chat data.
We share data only as needed to run the product, for example:
- Meta / WhatsApp — to send and receive messages on the official Cloud API path
- Infrastructure you (or your host) use for the app: database, Redis/job queue, file storage
- AI API provider — only when a non-mock provider is configured
- Professional advisors or authorities — if required by law
A living list of commercial subprocessors should be published as your production stack stabilises (hosting, email, error tracking, LLM).
7. International transfers
Depending on configuration, AI providers or hosting may process data outside Malaysia. Where that happens, processing is for delivering the service you requested. Confirm regions with your operator for production deployments.
8. Security (high level)
- Passwords hashed
- Channel tokens encrypted at rest
- Authenticated access to workspace data
- Tenant-scoped data model (workspaces isolated in application logic)
- Signed webhooks and operational logging for the WhatsApp path
No method of transmission or storage is 100% secure; report suspected issues to your support contact.
9. Retention
| Data | Typical retention |
|---|---|
| Account & workspace config | While the account/workspace is active |
| Conversations & knowledge | While the workspace is active, unless you delete content or the workspace |
| Usage meters | As needed for trial/plan enforcement and history |
| Security / job logs | Short operational window for debugging and security |
| After workspace delete | Tenant data is removed via application delete/cascade; backups may retain residual copies for a limited operational period |
Exact windows may vary by deployment; operators should document backup TTL in production runbooks.
10. Export, deletion, and your rights
In product (workspace owners):
- Export workspace data where the product provides export
- Delete workspace / account pathways in Settings / Billing (as implemented)
- Control knowledge content and channel disconnect
PDPA-oriented rights (subject to applicable law): access, correction, and deletion of personal data we hold about you as a user. For your customers’ personal data in chats, the business (you) is typically the primary point of contact; we assist as processor via product tools and support.
To exercise rights, email [email protected] and describe your request.
11. Children
BalasAuto is aimed at businesses, not children. We do not knowingly offer the service for children to create accounts.
12. Cookies and similar technologies
Essential cookies or local storage may be used for session / auth and basic preferences (e.g. language). If we add analytics or advertising cookies later, we will update this policy and, where required, provide a clearer cookie notice.
13. Changes
We may update this policy as the product evolves. Material changes for early-access users should be communicated via the product site or email when practical. The last updated date at the top will change.
14. Bahasa Malaysia (ringkas)
Kami memproses data akaun, konfigurasi saluran WhatsApp (token disulitkan), perbualan pelanggan, dan kandungan pengetahuan untuk menjalankan perkhidmatan balas auto dan peti masuk.
Perniagaan anda lazimnya mengawal data pelanggan; BalasAuto mengendalikan perisian bagi pihak anda.
Kami tidak melatih model asas awam menggunakan sembang pelanggan anda.
Anda boleh eksport atau padam ruang kerja mengikut ciri produk. Hubungi sokongan untuk permintaan privasi.
15. Related policies
16. Disclaimer
This document is an MVP / early-access description of product practices. It is not a substitute for legal advice. Obtain counsel review before public mass marketing, regulated claims, or enterprise contracts.