Privacy Policy

Last updated: 30 August 2026

In plain language

We are EezieLead, operated by Alchemistic Cloud. We help your business answer WhatsApp customers with AI. We collect the information you give us (your account, your business, your knowledge base), your WhatsApp Business connection, and the conversations, contacts, and orders that flow through your WhatsApp number — including the messages your customers send you. We use Google's AI to draft replies, Stripe to bill paid plans, and a few other providers to run the service. If you connect an accounting provider, we exchange your customer and product data with it on your instruction. We do not sell your data. The people who message your business are your customers: you decide how their data is used, and you are responsible for telling them. You can ask us to delete your data at any time — just email [email protected].

1. Who we are

EezieLead is operated by Alchemistic Cloud (Malaysian sole proprietorship, SSM No. 202403173449) ("we", "us", "our"). For any privacy question, or to exercise your rights under the Malaysian Personal Data Protection Act 2010 ("PDPA"), contact [email protected].

2. Two roles: your data vs. your customers' data

EezieLead handles two different kinds of personal data, and our responsibility is different for each:

  • Your data — we are the controller. For the account, business, and billing information you give us to run your EezieLead account, we decide how it is used and we are responsible for it under the PDPA.
  • Your customers' data — we are the processor. For the WhatsApp conversations, phone numbers, names, and media your customers send to your business, you are the controller and we process that data on your behalf, on your instructions, to provide the service. You are responsible for having a lawful basis to collect it and for giving your customers their own privacy notice.

3. Personal data we collect

  • Account data: name, email address, language preference, and how you sign in — a magic link sent to your email, or your Meta / Facebook login when you connect WhatsApp through the embedded signup.
  • Business data: your business name and profile, your connected WhatsApp Business Account (WABA) details and phone number ID, and the FAQ, product, and knowledge-base content you provide to ground the AI.
  • Customer conversation data (you are the controller): the WhatsApp phone numbers, display names, message content, and media of the customers who message your business, plus the lead and contact records we build automatically from those conversations. You are responsible for having a lawful basis to share this data with us.
  • Messages you send from the WhatsApp Business app: if your number is connected to EezieLead while you also use it in the WhatsApp Business app, Meta forwards us a copy of the replies you type there. We store their text and any media alongside the conversation so your inbox stays complete and the AI knows you have already answered.
  • Order and inventory data (you are the controller): the customer phone number an order is filed under, the items, quantities, prices and totals, the payment and fulfilment status, and any notes or tracking notes you or your AI agent record. Stock levels are held against your own product list.
  • Your notification phone number, if you turn on WhatsApp alerts for handovers. These alerts are sent from EezieLead's own WhatsApp number to yours, and include the customer's name and the message that triggered the handover.
  • AI processing: to draft a reply, the relevant message content and your knowledge base are sent to Google's Gemini API, along with the products and any recent orders relevant to that customer. The same content is used to build search embeddings so the AI can retrieve the right answer, and to extract order details from what your customer writes.
  • Billing data: handled directly by Stripe. We do not store full card numbers — only the last 4 digits, card brand, and your subscription and usage status.
  • Usage data: pages viewed, features used, device type, IP address, approximate location, and error logs.
  • Signup attempts: when you try to connect WhatsApp, we record the attempt so we can see when signup breaks and fix it. That record holds the email address you entered, the WhatsApp account and phone number ID involved, which step failed, and the page on our website you followed the link from. This is kept whether the signup succeeds or fails, because a signup that fails silently is the one we most need to see.

4. Why we use it (purposes & legal basis)

Purpose Legal basis (PDPA s.6)
Run the platform (inbox, AI conversations, leads, knowledge base) Performance of a contract with you
Generate AI replies via Google Gemini Performance of a contract
Send and receive WhatsApp messages via Meta on your behalf Performance of a contract
Notify you (email or WhatsApp) of handovers, billing, and account events Performance of a contract
Process payments and meter your usage for paid plans Performance of a contract
Sync products and push orders to an accounting provider you have connected Performance of a contract / your instruction
Measure marketing traffic, sign-ups, and plan changes (upgrades and downgrades) Your consent, given in our cookie banner, on our public pages. Inside the app, performance of a contract
Improve the product, fix bugs, and prevent abuse Performance of a contract (keeping the service working and secure)

5. Who we share data with (sub-processors)

We share the minimum necessary data with the following service providers, each bound by their own terms and security obligations:

  • Supabase (database, authentication, file storage, realtime) — hosted in the AWS Singapore (ap-southeast-1) region.
  • Google Gemini API (AI replies and search embeddings) — operated by Google LLC; data is sent on a per-request basis and is not used to train Google's models under their API terms.
  • Meta Platforms (WhatsApp Business Platform) — Meta plays two roles: it routes the WhatsApp messages between your business and your customers, and its embedded signup / Facebook Login for Business is how you connect your WhatsApp Business Account and create your EezieLead account. Messages you send and receive are also governed by WhatsApp's own terms between you, your customers, and Meta.
  • Stripe (payment processing) — global infrastructure; you are also subject to Stripe's privacy policy when you pay.
  • Resend (transactional email) — for magic-link sign-in, handover alerts, and account notifications.
  • Hostinger (server hosting) — the EezieLead app and this website run as containers on a Hostinger virtual server in Kuala Lumpur, Malaysia.
  • Cloudflare (network proxy and content delivery) — every request to us passes through Cloudflare, which caches static files and protects the app against abuse.
  • BetterStack (error and uptime monitoring) — when something breaks, we send the error message, the technical stack trace, and internal identifiers such as your tenant, conversation, and message ids so we can find the fault. We do not send message content to it.
  • PostHog and the Meta Pixel (product and marketing analytics) — used on our public marketing pages and inside the app to measure a small set of conversion events: page views, sign-ups, and plan changes (upgrades and downgrades). When we record a purchase, we also send Meta an irreversibly hashed copy of your account id and email so it can match the conversion to its own records. We do not send your customer conversations, contact lists, or business data to them.

We do not sell your data, and we do not share your conversations, contact lists, or business data with advertisers.

Integrations you connect

Separately from the sub-processors above, paid plans let you connect your own account with an accounting provider (currently Bukku). This is optional and you start it. When connected, we send that provider — at your instruction, using credentials you supply — your customer's name, phone number, and order line items, so it can create your sales records; and we copy your product catalogue, prices, and stock levels back into EezieLead. That provider is not our sub-processor: it is your own account, governed by your agreement with them. Disconnecting it from your settings stops any further exchange, but does not delete what they already hold — you manage that with them directly.

6. International transfers

The server that runs EezieLead is in Kuala Lumpur, though Hostinger, the company that operates it, is based outside Malaysia. Our other sub-processors (Supabase, Google, Meta, Stripe, Resend, Cloudflare, BetterStack) do run servers outside Malaysia. Where that happens, we rely on the recipient's contractual safeguards and transfer only the data necessary for the relevant service.

7. How long we keep it

  • Active accounts: for as long as your account exists.
  • Conversation media: images, audio, and documents exchanged in conversations are deleted automatically after 90 days on a paid plan, or 30 days on the free plan. Storing them costs us money for as long as we hold them, and the shorter free-plan window is how the free plan stays free. The text of the conversation is kept while your account is active, so a chat you read later still reads in full; only the attachments go.
  • Deleted accounts: when you ask us to delete your account, we remove it from our production systems within 30 days. If you change your mind within that window, tell us and we can usually restore it.
  • Signup attempts: the email address and phone number ID on a signup attempt are erased after 90 days. What remains is the attempt itself, which step it reached, and the page you came from, with nothing in it that identifies you. We keep that indefinitely so we can tell how often signup fails.
  • Backups: we rely on Supabase's automated daily backups, which are retained for 7 days. Deleted data ages out of those backups within the same window.

Because EezieLead is not an accounting or tax record, we do not keep your data for any long statutory period — once it is deleted and has aged out of backups, it is gone.

8. Your rights under PDPA

You have the right to:

  • Access the personal data we hold about you.
  • Correct inaccurate personal data.
  • Withdraw consent for non-essential processing (note: this may prevent you from using affected features).
  • Request deletion of your account (see Data deletion below).

To exercise these rights, email [email protected] from the address on your account. We aim to respond within 21 days. If your request is about a customer's data that you process through EezieLead, that person should contact your business directly — you are the controller of that data, and we will help you respond as your processor.

9. Data deletion

If you want to delete your data, email us at [email protected] from the address on your account and ask us to delete your account and data. We will remove it from our production systems within 30 days, and it then ages out of our 7-day backups (see How long we keep it above). Tell us within that window if you change your mind. Deleting your EezieLead data does not delete anything Meta, WhatsApp, or an accounting provider you connected holds about you or your customers; you manage that with them directly.

10. Security

We use TLS for all data in transit, encrypted storage at rest (via Supabase), Row-Level Security to isolate each business's data, and standard access controls. Credentials for any accounting provider you connect are encrypted before they are stored. No system is perfectly secure; you are responsible for keeping your sign-in secure and your account access limited to people you trust.

If there is a breach

If personal data we hold is exposed, lost, or reached by someone who should not have it, we act on it and we tell people. Where the data is yours, we notify the Personal Data Protection Commissioner within the time the PDPA requires, and we tell you directly where the breach is likely to cause you significant harm. Where the data belongs to your customers, you are the controller and the duty to notify is yours. We will tell you without undue delay once we know, and give you what we have so you can notify the Commissioner and the people affected. Clause 5 of the Terms sets this out as a commitment.

11. Staff access

Our staff may access your account and the data in it where necessary to provide support, investigate faults, and prevent abuse. Access is limited to authorised personnel.

12. Cookies and tracking

We use first-party cookies for authentication and session management. We use PostHog and the Meta Pixel to measure traffic on our public marketing pages and a few key conversion events — sign-ups and plan changes (upgrades and downgrades). On our marketing pages PostHog runs in cookieless mode: it stores nothing on your device and counts visits with a privacy-preserving hash. The Meta Pixel loads a script from Meta and sets an _fbp cookie, which Meta uses to attribute advertising; it loads only if you accept it in our cookie banner, and we remember that choice in a single el_consent cookie. These trackers never see the content of your conversations, your contacts, or your business data. If your browser sends a "Do Not Track" signal, neither is loaded.

EezieLead works by sending the relevant conversation content, your knowledge base, and the products and recent orders relevant to that customer to Google's Gemini API — to generate replies, build search embeddings, and extract order details from what your customer writes. By using the service, you authorise this processing. It is core to how the product works; you cannot use the AI features without it.

14. Children

The service is intended for businesses and is not intended for users under 18. We do not knowingly collect data from minors.

15. Changes to this policy

When we make a material change, we will email account holders and show a notice in-app. Continued use after the effective date means you accept the updated policy.

16. Contact

Alchemistic Cloud (SSM 202403173449) — [email protected] or WhatsApp +60 17-476 8893.