Effective date: 11 October 2026

Privacy Policy

This policy explains what data Replyero collects, why, how the AI processes messages, who we share it with, and the rights you have.

1. Who we are

Replyero is a product name. Depending on where you are a customer, your data is controlled by: Huali Global Sdn. Bhd. (SSM company no. 201401026957 (1103047-K), Malaysia) for customers in Malaysia; or Kai Ao Pty Ltd (ABN 16 649 778 290, Australia) for customers elsewhere (together, "Replyero", "we", "us").

Kai Ao Pty Ltd handles personal information in accordance with the Australian Privacy Act 1988 and the Australian Privacy Principles, and applies them voluntarily even where a small-business exemption might be available, because the Service processes business-customer data. Huali Global Sdn. Bhd. complies with the Malaysian Personal Data Protection Act 2010 as amended, including the Personal Data Protection (Amendment) Act 2024. Both companies maintain the standards described in this policy.

This Privacy Policy explains what personal data we collect, why, how we use and protect it, and the choices you have. It applies to the replyero.com website and Service, and should be read together with our Terms of Service.

Privacy questions and requests: [email protected].

2. Data we collect

  • Account data: your name, business name, email address, password (stored only as a cryptographic hash) and market/billing region.
  • Business content: the knowledge, instructions and settings you configure, and the conversations, messages, contact details and media processed through connected channels.
  • End-customer data: your customers’ names, phone numbers, email addresses and message content, received via the channels you connect, processed on your behalf.
  • Usage data: feature usage, AI resolution counts, token consumption for billing, and basic technical logs (IP address, timestamps, user agent).
  • Payment data: handled by our payment processor (Stripe); we do not store your card details.

3. How the AI processes messages

To generate replies, the Service sends the relevant conversation context and your configured business knowledge to a third-party large-language-model ("LLM") provider over an encrypted connection. The provider processes this content solely to generate the response for your conversation.

We select reputable providers and configure them to process data for the sole purpose of providing the Service, without using your content to train their public models where that option is available on the plan we purchase.

If you are uncomfortable with any provider, contact us — the LLM layer supports multiple providers and can be reconfigured.

4. Why we process (purposes and legal bases)

  • To provide the Service you signed up for (necessary for the performance of your contract with us).
  • To bill subscriptions and usage, prevent fraud, and meet tax and accounting obligations (contract; legal obligation).
  • To communicate service, security and account notices (necessary for the contract or required by law).
  • To improve the Service using aggregated, de-identified analytics that no longer identify you or your customers.
  • Marketing email only with your consent. You may withdraw consent at any time — via the unsubscribe link in any message or by emailing [email protected] — including your right to withdraw direct-marketing consent under Malaysia’s PDPA and Australia’s Privacy Act 1988.

5. Who we share data with (processors)

We share data only with processors that operate parts of the Service, bound by contractual confidentiality and security commitments:

  • Application hosting: Fly.io (Singapore region).
  • Database hosting: Neon (Postgres) and cache/queue hosting: Upstash (Redis), with primary storage in the Singapore region.
  • LLM providers for AI reply generation (see Section 3).
  • Payment processing: Stripe.
  • Messaging platforms you connect (e.g. WhatsApp/Meta, Instagram, email providers) — as needed to send and receive your messages.
  • We never sell your personal data or your end-customer data.

6. International data transfers

Primary storage and processing occur in the Singapore region. Some processors (for example LLM providers, Stripe or email infrastructure) may process data in other countries, which may include the United States, Australia and Malaysia.

Before transferring personal data overseas we satisfy ourselves — through contractual commitments and, where available, regional configuration — that the recipient is bound to provide a standard of personal data protection comparable to ours (the accountability-based approach under both the amended PDPA and Australian Privacy Principle 8).

7. Retention

  • Account and business content: retained while your account is active; deleted within 90 days of account closure unless legally required otherwise.
  • Conversations and messages: retained for the life of the workspace; deleted with the workspace.
  • Billing records: retained as required by tax law (typically 7 years).
  • Logs: retained for a limited operational window.

8. Your rights (and your end-customers’ rights)

Depending on your jurisdiction (including Malaysia’s Personal Data Protection Act 2010 as amended, Australia’s Privacy Act 1988 and Australian Privacy Principles 11–13, and, where applicable, the GDPR), you may have rights to: access and correct your personal data; obtain a copy in a portable format (data portability); withdraw consent to processing including direct marketing; and request that we stop or not begin processing likely to cause damage or distress to you.

Because conversation data belongs to the business operating the workspace, your end-customers should direct requests to that business, which can action them from the inbox; we will assist the business where needed.

To exercise a right, email [email protected] from your account address. We respond within 21 days or as otherwise required by applicable law.

9. Security and data breach response

We protect data with encryption in transit (TLS), access-controlled infrastructure, managed database hosting with encryption at rest, and least-privilege operational access. Each operator designates an internal data protection contact responsible for its obligations under the amended PDPA and the Privacy Act 1988; reach them at [email protected].

We maintain an internal breach response procedure. If a data breach occurs that is likely to result in significant harm to affected individuals, we will notify: affected account holders without undue delay; and the relevant regulator as soon as practicable — the Commissioner of Personal Data Protection (JPDP) for Malaysian customers, or the Office of the Australian Information Commissioner (OAIC) for Australian customers — as required by law.

No system is perfectly secure. If you believe a breach has occurred, contact [email protected] immediately.

10. Cookies

We use a single essential session cookie to keep you signed in. We do not use advertising cookies. Analytics, when enabled, is aggregated and does not build individual profiles.

11. Children

The Service is intended for business use and is not directed at children. We do not knowingly collect data from children under 16.

12. Changes to this Policy

We may update this Privacy Policy; material changes will be notified by email or in-product at least 14 days before taking effect. The effective date below shows the current version.

Operator details

Huali Global Sdn. Bhd. — No. 63A, Jalan SS25/2, Taman Bukit Emas, 47301 Petaling Jaya, Selangor, Malaysia · [email protected] (customers in Malaysia)

Kai Ao Pty Ltd — Suite 2 & 3, 321 Chapel Street, Prahran VIC 3181, Australia · [email protected] (customers elsewhere)

[email protected] · [email protected]