← Back to site

Privacy Policy

How JomChats collects, uses, stores and protects personal data — written to meet Malaysia's Personal Data Protection Act 2010, as amended by the Personal Data Protection (Amendment) Act 2024.

Effective 7 August 2026 · Version 1.0

JomChats provides an AI assistant that answers customer messages on WhatsApp for businesses. That means we handle other people's conversations. This page explains exactly what we do with them, in plain language.

1. Who we are

JomChats ("JomChats", "we", "us", "our") is a WhatsApp AI concierge service operated by MyTaxMate Solutions, a business registered in Malaysia under the Registration of Businesses Act 1956.

Registered nameMyTaxMate Solutions
Registration no.202603104965 (JM1043208-T)
Registered address2-5-13 Desa Green Serviced Apartment, Jalan Desa Bakti, 58100 Kuala Lumpur, Wilayah Persekutuan, Malaysia
Privacy contactprivacy@jomchats.com
Websitejomchats.com

References in this Policy to JomChats are references to MyTaxMate Solutions trading as JomChats. We are the party responsible to you for the matters described here.

This Policy applies to:

  • visitors to jomchats.com;
  • businesses that engage us to operate a WhatsApp assistant (our Clients); and
  • individuals who send messages to a WhatsApp number operated using JomChats (End Customers).

2. When we are a data controller, and when we are a data processor

This distinction matters, and it changes who you should contact about your data.

SituationData controllerData processor
You visit jomchats.com, book a demo, or email us JomChats
You message a business's WhatsApp number that runs on JomChats That business (our Client) JomChats

In the second case, the business decides why and how your personal data is used. We process it on their written instructions in order to provide the service. Under the Personal Data Protection Act 2010 as amended, we also carry direct obligations as a data processor, including security and breach-reporting duties, and we comply with those independently.

If you messaged a business and want your data deleted, you can ask us and we will act, but the business is the controller. See our Data Deletion page — it explains both routes and we will help either way.

3. What personal data we collect

3.1 From End Customers (people who message a JomChats-powered number)

  • Your WhatsApp phone number and WhatsApp profile name, as supplied by Meta.
  • The content of your messages — text, and any images, documents, voice notes or location you choose to send.
  • Details you volunteer in conversation, which may include your name, budget, preferred area, purpose of purchase, appointment date and time, or similar enquiry details.
  • Conversation metadata — timestamps, message delivery status, language detected, and which staff member the conversation was passed to.

3.2 From Clients and prospective Clients

  • Business name, contact person's name, work email address, phone number.
  • Account credentials for the JomChats portal.
  • Business content you provide for the assistant to learn from — brochures, price lists, FAQs, floor plans.
  • Meta credentials you supply so we can operate your WhatsApp number on your behalf, which we store encrypted (see section 9).
  • Billing and payment records.

3.3 From website visitors

  • Anything you type into a demo or contact form.
  • Basic technical data your browser sends — IP address, browser type, pages viewed — used for security and aggregate traffic measurement.

We do not use advertising cookies or third-party tracking pixels on jomchats.com.

3.4 Sensitive personal data

We do not ask for sensitive personal data (such as health, religious or political information, or financial account numbers) and our assistants are not designed to collect it. If you send it to us unprompted, it will sit inside the conversation record and be handled with the same protections as everything else. Please do not send bank card numbers, passwords or identity document numbers over WhatsApp.

4. Why we process personal data, and on what basis

PurposeBasis under the PDPA
Replying to customer enquiries on a Client's WhatsApp numberConsent — you chose to start the conversation — and performance of the Client's contract with you
Passing an enquiry to the Client's staff so a human can follow upConsent and legitimate interests of the Client
Booking, confirming and reminding you of appointmentsPerformance of a contract, and consent
Providing, maintaining, securing and improving the JomChats servicePerformance of our contract with the Client; our legitimate interests
Billing, accounting and tax recordsCompliance with legal obligations
Sending marketing or promotional WhatsApp messagesConsent, which you may withdraw at any time

We do not sell personal data. We do not share it with advertisers. We do not use one Client's data to serve another Client.

5. How artificial intelligence is used

Messages sent to a JomChats-powered number are processed by large language models in order to understand the question and compose a reply. You should know four things about this:

  • The AI answers only from information the Client has given it. It is built to say it does not know, and to pass the question to a human, rather than to invent an answer.
  • Message content is sent to our AI model providers purely to generate the reply. We use providers on terms that prohibit them from training their models on our data.
  • A human at the Client's business can read the conversation, and in some configurations approves replies before they are sent.
  • Automated processing here does not produce legal or similarly significant decisions about you. A person always makes the actual commercial decision.

6. Who we share personal data with

We disclose personal data only to the following categories of recipient, and only as far as needed:

RecipientWhy
The Client whose WhatsApp number you messagedThey are the data controller; the enquiry is for them
Meta Platforms (WhatsApp Business Platform)Message delivery. Meta's own terms and privacy policy also apply to WhatsApp
AI model providersGenerating replies, under no-training terms
Cloud hosting and database providersRunning and storing the service securely
Email and notification providersAlerting Client staff to new enquiries
Professional advisers, auditors, regulatorsWhere we are legally required, or to establish or defend legal claims

Every processor we appoint is bound by a written contract requiring confidentiality, appropriate security measures, and processing only on our instructions.

If our business is sold or reorganised, personal data may transfer to the acquirer, who will remain bound by this Policy or a policy at least as protective.

7. Transfers of data outside Malaysia

Our hosting, database and AI providers operate data centres outside Malaysia, principally in Singapore, the European Union and the United States. Personal data is therefore transferred out of Malaysia.

Where we transfer personal data outside Malaysia, we satisfy ourselves that the receiving jurisdiction or the receiving organisation provides protection substantially similar to that required by the PDPA, and we put contractual safeguards in place with each recipient. Where required, we rely on your consent to the transfer.

8. How long we keep personal data

DataRetention
Conversation records and enquiry detailsFor as long as the Client's account is active, unless the Client instructs deletion sooner
All Client data after the account endsDeleted within 60 days of termination, unless a longer period is required by law
Contact and enquiry data from jomchats.com24 months from last contact
Billing, invoicing and accounting records7 years, as required by Malaysian tax law
Security and audit logs12 months

When retention ends, data is deleted or irreversibly anonymised.

9. How we protect personal data

  • All data in transit is encrypted using TLS.
  • Data at rest is encrypted by our hosting providers.
  • Client Meta credentials — access tokens and app secrets — are separately encrypted with AES-256-GCM before they are written to our database, so a database copy alone does not expose them. They are never displayed back in any interface.
  • Every inbound message is cryptographically verified as genuinely from Meta before it is processed, and a Client's credentials can only ever act on that Client's own numbers.
  • Access to production data is limited to personnel who need it, and is logged.
  • Phone numbers are masked in staff-facing views except for the staff member the enquiry is assigned to.

No system is perfectly secure. We do not claim otherwise. What we do claim is that we treat a leak of a Client's conversations as the worst thing that could happen to us, and we build accordingly.

10. Your rights

Under the PDPA you have the right to:

  • Access the personal data we hold about you, and be told how it is being processed;
  • Correct data that is inaccurate, incomplete or out of date;
  • Withdraw consent to processing, at any time;
  • Limit processing, including telling us to stop using your data for direct marketing;
  • Data portability — ask that your data be transmitted to another service provider, where technically feasible;
  • Complain to the Personal Data Protection Commissioner of Malaysia.

To exercise any of these, email privacy@jomchats.com. We will respond within 21 days. We may ask you to verify your identity first — usually by messaging from the WhatsApp number in question. There is no charge for a reasonable request.

To stop marketing messages on WhatsApp immediately, reply STOP or BERHENTI to the message. That takes effect at once and permanently.

Where we act as processor for a Client, we will forward your request to that Client and support them in answering it.

11. Data breaches

If a personal data breach occurs that causes or is likely to cause significant harm, we will notify the Personal Data Protection Commissioner as soon as practicable and within 72 hours of becoming aware of it, and we will notify affected individuals without unnecessary delay and within 7 days of notifying the Commissioner, in line with the PDPA as amended.

Where we are a processor, we will notify the Client immediately so that they can meet their own obligations.

12. Children

Our services are sold to businesses and are not directed at children. We do not knowingly collect personal data from anyone under 18. If you believe a child's data has reached us, contact us and we will delete it.

13. Changes to this Policy

We may update this Policy. The effective date at the top always shows the current version. If a change materially affects how we handle personal data, we will notify Clients by email before it takes effect.

14. Contact us

Questions, requests or complaints about privacy:

If you are not satisfied with our response, you may complain to the Personal Data Protection Commissioner, Department of Personal Data Protection (JPDP), Malaysia.