Legal
Privacy Policy
How Bridzia collects, uses, discloses, retains, and protects personal data through the Bridzia messaging platform.
Effective Date: 1 June 2026 | Last Updated: 1 June 2026
1. Introduction
Bridzia Sdn Bhd (Company No. 201201018441) (“Bridzia”, “we”, “our”, or “us”) operates the Bridzia messaging platform (the “Service”), which enables businesses to engage with their customers through the WhatsApp Business Platform and other messaging channels.
This Privacy Policy describes how Bridzia collects, uses, discloses, retains, and protects personal data when our customers (“Business Customers”) use the Service to communicate with their own end-users (“End Users”), and when individuals visit our website or interact with us directly.
We are committed to compliance with the Malaysian Personal Data Protection Act 2010 (“PDPA”), Meta Platform policies, the WhatsApp Business Messaging Policy, and where applicable, the EU General Data Protection Regulation (“GDPR”) and equivalent international standards.
2. About Us
Bridzia Sdn Bhd is a Malaysian-incorporated company that provides a software-as-a-service platform integrating with the Meta WhatsApp Business Platform under Meta’s Tech Provider Program.
Registered Office: VO-579, Levels 15-19, Boutique Office 1 (B01-C), Menara 2, No. 3 Jalan Bangsar, KL Eco City, 59200 Kuala Lumpur, Malaysia
Data Protection Officer / Privacy Contact: privacy@bridzia.com.my
General Contact: enquiry@bridzia.com.my | +603-2774 5234
3. Information We Collect
3.1 Information You Provide Directly
When you register for or use the Service as a Business Customer, we collect:
- Identification data: full name, job title, company name, business registration number, business address.
- Contact data: email address, phone number, WhatsApp Business Account identifier.
- Account credentials: username, password (stored as a cryptographic hash).
- Billing information: billing address, payment method tokens (processed by our payment processor; we do not store full card numbers).
- Marketing preferences and communications you send us.
3.2 Information Collected Automatically
When you use our Service or website, we automatically collect:
- Device and connection data: IP address, browser type, operating system, device identifiers.
- Usage data: pages visited, features used, timestamps, referring URLs, session duration.
- Cookies and similar technologies (see Section 12).
- Log data: error reports, performance metrics, security event logs.
3.3 Information from the WhatsApp Business Platform
When our Business Customers use the Service to communicate with their End Users via WhatsApp, we process the following on their behalf as a data processor:
- End User phone numbers (in international E.164 format).
- End User WhatsApp display names and profile pictures (where shared by Meta).
- Message content sent between Business Customers and End Users, including text, images, documents, audio, video, locations, contacts, interactive buttons, and template messages.
- Message metadata: timestamps, delivery and read receipts, conversation identifiers, template identifiers, message status codes.
- Opt-in records: timestamp, method, and source of End User consent to receive messages.
- WhatsApp Business Account identifiers, phone number identifiers, and template approval status.
3.4 Information from Third Parties
We may receive information about you from:
- Meta Platforms, Inc., relating to your WhatsApp Business Account.
- Payment processors and billing partners.
- Identity verification providers (for business verification).
- Public business registries (SSM, LHDN) where required for verification.
4. How We Use Information
We use the information collected to:
- Provide, maintain, and improve the Service.
- Process WhatsApp messages between Business Customers and their End Users.
- Authenticate users, process payments, and manage subscriptions.
- Send service-related communications (account notices, security alerts, policy updates).
- Monitor compliance with our Terms of Service, the WhatsApp Business Messaging Policy, and applicable law.
- Detect, prevent, and respond to fraud, abuse, security incidents, and violations.
- Comply with legal obligations, court orders, and law enforcement requests.
- Conduct analytics, research, and product development (using aggregated and anonymised data where possible).
5. Legal Bases for Processing
Our lawful bases for processing personal data include:
- Performance of a contract with you (PDPA §6; GDPR Art. 6(1)(b)).
- Compliance with legal obligations (PDPA §6; GDPR Art. 6(1)(c)).
- Our legitimate interests in operating, securing, and improving the Service, where not overridden by your rights (GDPR Art. 6(1)(f)).
- Your consent, where we rely on it (which you may withdraw at any time).
6. How We Share Information
6.1 With Meta Platforms, Inc.
To deliver messages via the WhatsApp Business Platform, we transmit relevant data (phone numbers, message content, metadata, opt-in records) to Meta. Meta processes this data according to its own privacy policy (https://www.whatsapp.com/legal/privacy-policy) and its agreements with Business Customers.
6.2 With Our Business Customers
Information about End Users is shared with the Business Customer who initiated the conversation. Bridzia acts as a data processor on behalf of the Business Customer in respect of End User data; the Business Customer is the data controller.
6.3 With Service Providers
We engage trusted third-party providers for hosting (cloud infrastructure), payment processing, customer support tooling, analytics, and security monitoring. These providers are contractually bound to process personal data only on our instructions and to implement appropriate security measures.
6.4 For Legal and Safety Reasons
We may disclose information when required by law, court order, or government request, or where necessary to protect the rights, property, or safety of Bridzia, our customers, or others, or to investigate fraud, abuse, or violations of our Terms.
6.5 In Connection with Business Transactions
In the event of a merger, acquisition, restructuring, or sale of assets, personal data may be transferred to the relevant counterparty, subject to confidentiality obligations and applicable law.
6.6 We Do Not Sell Personal Data
We do not sell, rent, or trade personal data to third parties for monetary consideration.
7. WhatsApp Business Platform — Specific Data Handling
This Section sets out our specific commitments in respect of data processed through the WhatsApp Business Platform, in accordance with Meta’s Tech Provider obligations:
- Message content is encrypted in transit between Bridzia and Meta, and between Bridzia and Business Customers.
- We process End User personal data only on the documented instructions of the Business Customer (as data processor).
- We retain message content for the period configured by the Business Customer, subject to our maximum retention period (see Section 8).
- Opt-in records are stored for the duration of the End User’s relationship with the Business Customer plus six (6) years.
- Template content is stored for the duration of the template’s approval status with Meta.
- We do not use End User personal data to train any artificial intelligence model or machine learning system, except to provide service-specific functionality requested by the Business Customer (e.g., conversation routing) and only on anonymised or aggregated data.
- We require Business Customers to obtain valid opt-in consent from End Users before sending marketing or utility template messages, and we provide tools to record and audit such consent.
8. Data Retention
We retain personal data only for as long as necessary to fulfil the purposes for which it was collected, including any legal, accounting, or reporting requirements.
- Account and billing records: retained for the duration of the customer relationship plus seven (7) years for tax compliance.
- WhatsApp message content: retained per the Business Customer’s configuration, subject to a maximum default of thirty-six (36) months.
- WhatsApp metadata (delivery, read, status): retained for twenty-four (24) months.
- Opt-in records: retained for the duration of the End User’s relationship with the Business Customer plus six (6) years.
- Website and analytics logs: retained for twelve (12) months.
- Support and incident records: retained for thirty-six (36) months.
Upon expiry of these periods, or upon a valid deletion request, we securely delete or irreversibly anonymise the data, subject to legal retention requirements.
9. Your Rights
Subject to PDPA, GDPR, and other applicable law, you have the right to:
- Access the personal data we hold about you.
- Request correction of inaccurate or incomplete data.
- Request erasure of your personal data (“right to be forgotten”).
- Restrict or object to certain processing.
- Receive your data in a portable format.
- Withdraw consent at any time (where processing is based on consent).
- Lodge a complaint with the Department of Personal Data Protection Malaysia (https://www.pdp.gov.my) or, where applicable, an EU supervisory authority.
To exercise these rights, email privacy@bridzia.com.my. We respond within thirty (30) days. We may request additional information to verify your identity before processing your request.
End Users seeking to exercise rights over data collected via the WhatsApp Business Platform should contact the Business Customer who initiated the conversation, as the Business Customer is the data controller. Bridzia will assist Business Customers in responding to such requests.
10. Data Security
We implement appropriate technical and organisational measures to protect personal data, including:
- Encryption in transit (TLS 1.2 or higher) and at rest (AES-256).
- Strict access controls and least-privilege principles for our personnel.
- Regular security audits, vulnerability assessments, and penetration testing.
- Multi-factor authentication for administrative access.
- Logging, monitoring, and intrusion detection.
- Employee training on data protection and information security.
- Incident response procedures, including breach notification within seventy-two (72) hours where required by law.
Despite our efforts, no system is completely secure. We cannot guarantee absolute security and you transmit information at your own risk.
11. International Data Transfers
Bridzia is based in Malaysia. Personal data may be processed in Malaysia and other jurisdictions where our service providers operate, including the European Union, the United States, Singapore, and other countries used by Meta’s WhatsApp infrastructure.
Where personal data is transferred outside Malaysia, we ensure an adequate level of protection through Standard Contractual Clauses, the recipient’s certification under recognised frameworks, or your explicit consent.
12. Cookies and Tracking Technologies
Our website and Service use cookies and similar technologies for authentication, preference storage, analytics, and security. You can manage cookie preferences through your browser settings or our cookie banner. Essential cookies (necessary for the Service to function) cannot be disabled.
13. Children’s Privacy
Our Service is intended for businesses and individuals aged eighteen (18) or older. We do not knowingly collect personal data from children under eighteen (18). If you believe we have inadvertently collected data from a minor, please contact us at privacy@bridzia.com.my and we will delete it.
14. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify Business Customers of material changes via email or in-app notice at least thirty (30) days before the changes take effect. The “Last Updated” date at the top of this Policy will always reflect the most recent revision.
15. Contact Us
If you have any questions, concerns, or complaints about this Privacy Policy or our handling of your personal data, please contact:
Bridzia Sdn Bhd
Attn: Data Protection Officer
VO-579, Levels 15-19, Boutique Office 1 (B01-C), Menara 2, No. 3 Jalan Bangsar, KL Eco City, 59200 Kuala Lumpur, Malaysia
Email: privacy@bridzia.com.my
Phone: +603-2774 5234
16. Governing Law
This Privacy Policy is governed by the laws of Malaysia. Any disputes arising under or in connection with this Policy shall be subject to the exclusive jurisdiction of the courts of Malaysia.
— End of Privacy Policy —
