EzFlow

Privacy Policy

Version: 1.1.0

Effective Date: July 21, 2026

Last Updated: July 21, 2026

Changes: Updated infrastructure and sub-processors (self-hosted database and object storage on Vultr Singapore; Anthropic Claude for document text extraction; Billplz split collections); added Sensitive Personal Data, AI and model-improvement, cross-border transfer, data-portability and data-breach provisions to reflect the Personal Data Protection (Amendment) Act 2024.

EZ FLOW LABZ SDN. BHD. (Company No. 202201026529 (1472226-H)) ("we", "us", or "EzFlow") is committed to protecting your privacy and personal data in full compliance with the Personal Data Protection Act 2010 of Malaysia, as amended by the Personal Data Protection (Amendment) Act 2024 (together, the "PDPA"). This Privacy Policy explains how we collect, use, disclose, store, and protect your personal information when you use ezflow.my.

A Bahasa Malaysia version of this Privacy Policy is available on request at privacy@ezflowlabz.com. Where there is any inconsistency, the English version prevails to the extent permitted by law.

1. PDPA Compliance Statement

We are fully committed to compliance with the Personal Data Protection Act 2010 and all seven PDPA principles. This Privacy Policy is designed to meet the requirements of the PDPA and provide you with transparent information about our data processing practices.

In line with the Personal Data Protection (Amendment) Act 2024, we have appointed a Data Protection Officer who is responsible for overseeing our PDPA compliance, and whose appointment is notified to the Personal Data Protection Commissioner as required.

Data Protection Officer:

Email: privacy@ezflowlabz.com

2. Personal Data We Collect

2.1 Account Registration Data

When you create an EzFlow account:

  • Full name of the authorized representative
  • Business name and SSM registration number (if applicable)
  • Email address
  • Malaysian mobile phone number
  • Password (encrypted — never stored in plain text)

2.2 Business and Operational Data

When you use EzFlow to run your business:

  • Appointment bookings and scheduling records
  • Staff profiles, work schedules, and attendance records
  • Customer names, contact numbers, and email addresses
  • Invoice records and transaction history
  • WhatsApp communication logs
  • Google review data linked to your business

2.3 Payment and Billing Data

When you subscribe to a paid plan (subscription billing) or use EzFlow to collect payments from your own customers (collections):

  • Billing name and email address
  • Subscription plan and payment history
  • For collections you enable: your business's payout bank account details, and the amount, reference, and payer contact details of each transaction your customers pay you
  • Note (subscriptions): All subscription card and payment details are processed directly by Stripe. EzFlow never stores, processes, or has access to your payment card information.
  • Note (collections): When you use EzFlow to collect payments from your customers, payments are processed through Billplz using a split-payment arrangement that settles funds directly to your own bank account. EzFlow is not a custodian of, and does not hold, the funds your customers pay you. EzFlow charges a platform fee per transaction, which is deducted or invoiced as disclosed at the time of the transaction.

2.4 Technical Data

Automatically collected when you use the Platform:

  • IP address
  • Browser type and version
  • Device information and operating system
  • Access times and pages visited
  • Platform usage patterns and feature usage statistics

2.5 Uploaded Documents and Extracted Data

Certain features allow you to upload documents and images (for example receipts, invoices, and business records) so that EzFlow can automatically read and extract information from them (optical character recognition, or "OCR"). When you use these features:

  • We store the document or image you upload and the text and data fields extracted from it
  • To perform the extraction, the document or image is processed by our AI sub-processor, Anthropic (Claude), via its enterprise API
  • Anthropic processes the content solely to return the extraction result to EzFlow and, under its commercial API terms, does not use your inputs or outputs to train its models

You are responsible for the documents you choose to upload. Please do not upload documents containing sensitive personal data (see 2.6) unless it is necessary for the feature you are using and you have the right to do so.

2.6 Sensitive Personal Data

Under the PDPA, "sensitive personal data" includes data concerning health, political opinions, religious beliefs, the commission of an offence, and — following the Personal Data Protection (Amendment) Act 2024 — biometric data. A document you upload (such as an identity document or a record bearing a Malaysian identity card / NRIC number, photograph, or signature) may contain sensitive personal data.

We do not require sensitive personal data to provide our core Services and ask that you avoid submitting it where it is not needed. Where a feature does involve sensitive personal data, we will process it only with your explicit consent and will apply heightened security measures. We do not use sensitive personal data to train or improve AI models (see Section 4.5).

2.7 eKYC and Identity/Business Verification Data

Where you enable features that require identity or business verification ("eKYC") — including LHDN MyInvois e-invoicing, for which you appoint EzFlow as your authorised intermediary — we (and our verification providers) may collect and verify:

  • Identity information, which may include an identity document, NRIC number, photograph, and date of birth
  • Business registration information (e.g. SSM details) and taxpayer identification
  • Authorisation and consent records evidencing your appointment of EzFlow as intermediary

We use this data for onboarding, identity and business verification, intermediary appointment, fraud prevention, and compliance with applicable law (including LHDN e-invoicing requirements and anti-money-laundering obligations). Where any of this data is sensitive personal data, we process it on the basis of your explicit consent.

3. Legal Basis for Processing

We process your personal data based on:

  • Consent: Provided when you create an account and agree to these policies
  • Contractual Necessity: Required to deliver the Services you have subscribed to
  • Legitimate Interests: For fraud prevention, platform security, and service improvement
  • Legal Obligation: To comply with Malaysian law, including LHDN e-invoicing and tax record-keeping requirements and anti-money-laundering obligations under the AMLA 2001 where applicable
  • Explicit Consent: For any processing of sensitive personal data (including biometric or NRIC data) and for eKYC/intermediary appointment

4. How We Use Your Personal Data

4.1 Service Provision

  • Creating and managing your account
  • Delivering all subscribed features including bookings, invoicing, scheduling, document extraction (OCR), and automations
  • Processing subscription payments via Stripe and, where you enable collections, facilitating payments from your customers via Billplz
  • Sending transactional notifications (booking confirmations, invoice receipts, OTP)

4.2 Platform Improvement

  • Analyzing usage patterns to improve user experience
  • Identifying and resolving technical issues
  • Developing new features based on user needs and feedback

4.3 Communication

  • Transactional emails (subscription confirmations, payment receipts, security alerts)
  • Product updates and feature announcements
  • Marketing communications — only with your explicit opt-in consent

4.4 What We Will NEVER Do

  • Sell your personal data or your customers' data to any third party
  • Share your business data with competitors
  • Use your data for purposes beyond those stated in this Policy without fresh consent
  • Access your customers' WhatsApp messages beyond what is necessary to deliver automation features
  • Use sensitive personal data (including biometric data or NRIC data) to train or improve AI or machine-learning models

4.5 AI, Analytics, and Service Improvement

By registering an account, you consent to EzFlow using personal data relating to your account and your use of the Platform to operate, secure, analyse, maintain, and improve the Services, including to develop, train, and improve EzFlow's own features and AI/machine-learning models for internal purposes. In doing so:

  • We prioritise the use of aggregated or de-identified data (data that does not identify you or any individual) for model development and analytics, and we retain the right to use such aggregated or de-identified data without time limit
  • We do not use sensitive personal data (including biometric data or NRIC data) for model training or improvement
  • Personal data of your own customers that we hold as a data processor on your behalf (see Section 5) is not used to train EzFlow's models except in aggregated or de-identified form, and only to the extent permitted by your instructions and applicable law
  • We do not sell your personal data or your customers' personal data (see Section 6)

You may object to or opt out of the use of your identifiable personal data for AI model training by contacting privacy@ezflowlabz.com. Opting out does not affect our use of aggregated or de-identified data or processing necessary to deliver the Services.

5. Your Customer Data

5.1 Your Responsibility

When you use EzFlow to manage your customer data (bookings, contacts, invoices), you are the data controller for that customer data. You are responsible for obtaining appropriate consent from your customers, complying with PDPA obligations, responding to your customers' data rights requests, and providing your customers with a privacy notice.

5.2 Our Role

EzFlow acts as a data processor for your customer data. We process it solely on your instructions to deliver the Services and will not use it for our own purposes.

6. Third-Party Data Sharing and Processors

We share your data only with trusted service providers who are contractually bound to protect it.

Vultr

Purpose: Cloud infrastructure hosting for EzFlow's self-managed servers (database, application, and self-hosted object storage via MinIO)

Data: Account data, business data, customer records

Location: Singapore

Stripe

Purpose: Payment processing for subscriptions

Data: Billing name, email, payment amount

Location: United States / Ireland

Note: Stripe handles all card data directly. EzFlow never receives or stores payment card details.

Billplz

Purpose: Split-payment collections (FPX / online banking) — enabling you to collect payments from your own customers, with funds settled directly to your bank account and EzFlow's platform fee applied per transaction

Data: Payer name and contact, payment amount and reference, your business payout bank details

Location: Malaysia

Anthropic (Claude)

Purpose: AI-powered text and data extraction (OCR) from documents and images you upload

Data: The document or image content you submit for extraction

Location: United States

Note: Anthropic processes content via its enterprise API solely to return the extraction result and, under its commercial API terms, does not use your inputs or outputs to train its models.

Resend

Purpose: Transactional email delivery (account and notification emails)

Data: Email address, email content

Location: United States (global operations)

Twilio

Purpose: WhatsApp/SMS message delivery and phone number verification

Data: Mobile number, message content

Location: United States

WhatsApp Business API (Meta)

Purpose: WhatsApp automation features

Data: Business phone number, message templates

Location: United States

We do not sell, rent, or trade your personal data or your customers' personal data to any third party under any circumstances.

7. Data Storage and Security

7.1 Storage Infrastructure

All data is stored on EzFlow's self-managed servers hosted in Singapore (Vultr), with object storage self-hosted via MinIO, with:

  • Encryption in transit (TLS/SSL) and at rest
  • Row-Level Security (RLS) ensuring Users can only access their own data
  • Regular security audits and vulnerability assessments
  • Access controls limiting data access to authorized personnel only

7.2 Password Security

Passwords are never stored in plain text. We use industry-standard cryptographic hashing via EzFlow's first-party authentication system.

7.3 Cross-Border Transfer

Your primary data is stored in Singapore (Vultr infrastructure), which maintains data protection standards comparable to Malaysia's PDPA. Limited data is also transferred to the United States where necessary for specific features — document/image content to Anthropic (Claude) for OCR extraction, and communications data to Twilio, Meta/WhatsApp, Resend, and Stripe. These providers operate under contractual data-processing terms and recognised cross-border transfer safeguards.

All transfers are encrypted and access-controlled and are made in reliance on one or more of the bases permitted under Section 129 of the PDPA (including your consent, contractual necessity, and the destination's adequate level of protection or contractual safeguards). Full details of each transfer are set out in our PDPA Compliance Statement.

8. Data Retention

8.1 Active Accounts

We retain your data for as long as your account is active to ensure continuity of service.

8.2 Post-Termination

After account termination, we retain your data for 30 days to allow data export. After this period, data is permanently deleted unless retention is required by Malaysian law.

8.3 Legal Retention Requirements

Certain records (e.g., invoices, transaction logs) may be retained for up to 7 years as required by Malaysian tax and accounting law, even after account termination.

9. Your Rights Under PDPA

You have the following rights under the Personal Data Protection Act 2010:

9.1 Right of Access

Request a copy of all personal data we hold about you. Contact privacy@ezflowlabz.com. We will respond within 21 days.

9.2 Right to Correction

Request correction of inaccurate or incomplete data through your account settings or by contacting privacy@ezflowlabz.com.

9.3 Right to Withdraw Consent

Withdraw consent for data processing at any time by contacting privacy@ezflowlabz.com. Note that withdrawal may affect your ability to use certain features.

9.4 Right to Data Portability

Request your data in a structured, commonly used, machine-readable format, and — where technically feasible and the data format is compatible — request that we transmit it directly to another data controller, by contacting privacy@ezflowlabz.com.

9.5 Right to Deletion

Request permanent deletion of your personal data. Requests are processed within 30 days except where legal retention obligations apply.

9.6 Right to Lodge a Complaint

If you believe we have not handled your data in accordance with the PDPA:

Personal Data Protection Department

Ministry of Communications and Digital

Level 4-7, Menara MCMC, Off Persiaran Multimedia, Cyberjaya, 63000, Selangor

Email: pdp@kkmm.gov.my

Tel: +603 8688 8333

10. Cookies and Tracking Technologies

We currently use only essential session cookies required for Platform functionality (authentication, session management). These cannot be disabled.

When analytics tools are activated, we will provide a cookie consent banner and allow you to manage preferences. No analytics cookies are set without your consent.

11. Children's Privacy

EzFlow is not intended for individuals under 18 years of age. We do not knowingly collect personal data from minors. If you believe a minor has registered, contact privacy@ezflowlabz.com immediately.

12. Data Breach Notification

In the event of a personal data breach, and in line with the Personal Data Protection (Amendment) Act 2024, we will:

  • Notify the Personal Data Protection Commissioner as soon as practicable after we have reason to believe a breach has occurred, as required by law
  • Where the breach is likely to cause significant harm, notify affected Users without unnecessary delay (and in any event promptly after becoming aware)
  • Provide details of the breach, the data affected, and the steps taken to address it and mitigate harm

13. Changes to This Privacy Policy

Material changes will be communicated via email at least 14 days before taking effect. Continued use of EzFlow constitutes acceptance of the updated Policy.

14. Contact Information

EZ FLOW LABZ SDN. BHD.

Company No.: 202201026529 (1472226-H)

Data Protection: privacy@ezflowlabz.com

General: hello@ezflow.my

Website: ezflow.my

By using EzFlow, you acknowledge that you have read, understood, and agree to the collection, use, and disclosure of your personal data as described in this Privacy Policy.