Privacy policy.
How we handle personal data under the Personal Data Protection Act 2010, as amended by the Personal Data Protection (Amendment) Act 2024.
This Privacy Policy explains how Sitehandy Solutions (Business Registration No. NS0159990-H) ("Company", "we", "us", "our") collects, uses, stores, discloses and protects personal data in connection with the SMSHandy platform, website, dashboard, API and related services (collectively, the "Service").
We process personal data in accordance with the Personal Data Protection Act 2010 ("PDPA"), as amended by the Personal Data Protection (Amendment) Act 2024, together with the guidelines and standards issued by the Personal Data Protection Commissioner. This Privacy Policy forms part of, and is incorporated into, our Terms of Service, and is read together with our Disclaimer.
By registering for or using the Service, you confirm that you have read and understood this Privacy Policy.
1. Our Role: Controller and Processor
The PDPA distinguishes between a data controller (who determines the purposes and means of processing) and a data processor (who processes data on a controller's behalf). Our role depends on the data concerned:
- We are the data controller for the personal data of our own customers and website visitors — your account details, KYC documents, billing records, support communications and usage logs. Sections 2 to 15 describe how we handle that data.
- We are the data processor for the personal data of your message recipients — the telephone numbers, names, personalisation fields and message content you upload or submit through the Platform ("Recipient Data"). You are the data controller of Recipient Data. We process it only on your instructions, to deliver your messages and to comply with the law. Your obligations as controller are set out in Section 8.
2. Personal Data We Collect
2.1 Account Information
- Full name
- Email address
- Mobile or WhatsApp number
- Company or business name, where applicable
- Business registration number, where applicable
- Account credentials (passwords are stored only as salted hashes, never in plain text)
2.2 Verification (KYC) Information
Where we are required to verify your identity under Section 3.3 of the Terms of Service, we may collect identity documents (MyKad or passport), SSM business registration documents, proof of address, details of beneficial owners, and evidence of your lawful basis for messaging (such as consent records and the source of your contact lists).
2.3 Payment Information
- Transaction details (amount, date, reference number, plan purchased)
- Bank or payment account details used for FPX or bank transfer
- Billing name and address, and tax identification details where required
We do not store full credit or debit card numbers. Card processing, where offered, is handled by our payment providers on their own systems.
2.4 Messaging Data
- Recipient telephone numbers and contact list content
- Message content and templates
- Sender IDs used
- Delivery status, timestamps, error codes and message part counts
- Campaign metadata (scheduling, list size, throughput)
2.5 Usage and Technical Data
- IP address and approximate location derived from it
- Browser type and version, device and operating system information
- Pages visited, actions taken and features used within the Platform
- API usage logs (endpoints called, timestamps, response codes, request volumes)
- Login timestamps, session data and security events
2.6 Support and Correspondence
When you contact us, we collect the content of your communications, including emails, WhatsApp messages, contact-form submissions and attachments, together with our responses.
2.7 Sensitive Personal Data
We do not seek sensitive personal data (such as data relating to health, religious beliefs, political opinions or the commission of offences) and you must not upload it through the Platform unless we have agreed in writing. If sensitive personal data is provided to us without agreement, you remain responsible for having obtained the explicit consent required under the PDPA.
3. How We Use Personal Data
- Providing the Service: processing and transmitting your messages, managing your account, contacts, templates and Sender IDs, and providing delivery reporting and analytics.
- Billing: processing credit purchases, verifying payments, issuing receipts and maintaining accounting records.
- Account security: authenticating you, detecting unauthorised access, and protecting accounts and infrastructure.
- Service communications: sending operational notices, security alerts, maintenance notices, billing notifications and support responses. These are not marketing messages and you cannot opt out of them while you hold an account.
- Compliance, fraud prevention and enforcement: verifying identity, screening and investigating content and traffic under Section 12 of the Terms of Service, preventing scams, spam and abuse, enforcing our Terms, and complying with legal and regulatory obligations, including MCMC requirements and operator rules.
- Service improvement: analysing usage patterns, diagnosing faults, and improving reliability, features and performance.
- Marketing: where you have consented or where you are an existing customer and the message concerns similar services, sending information about features, offers and updates. You may opt out at any time (Section 12).
4. Legal Basis for Processing
- Consent: given when you register, when you submit a form, and where you opt in to marketing.
- Performance of a contract: processing necessary to provide the Service under the Terms of Service.
- Legal obligation: processing required by law, by a court, or by a regulator such as MCMC, the Royal Malaysia Police, Bank Negara Malaysia or the Personal Data Protection Commissioner, and record-keeping required by tax and accounting law.
- Legitimate interests: preventing fraud and abuse, protecting network and platform security, defending legal claims, and improving the Service — balanced against your rights and interests.
5. Message Content and Recipient Data
Because of the nature of the Service, we set out separately how messaging data is treated:
- Purpose limitation: Recipient Data is processed solely to deliver your messages, to provide you with delivery reporting and history, to secure and maintain the Platform, and to meet legal, regulatory and abuse-prevention obligations.
- No secondary use: We do not use your message content or your contact lists to build our own marketing lists, to profile Recipients, to train models for unrelated purposes, or for advertising.
- No sale of data: We do not sell, rent or trade personal data.
- Screening: Message content and traffic are screened by automated means and, where a risk is identified, by manual review, for the purpose of detecting prohibited content and abuse under our Terms of Service. Access to content by our staff is restricted, logged and permitted only where necessary for that purpose, for support you have requested, or for a lawful request from an authority.
- Delivery reports: Delivery status information is received from operators and aggregators and made available to you in the dashboard and API.
- Isolation: Each account's data is logically isolated from other accounts.
6. Disclosure of Personal Data
6.1 Service Providers and Sub-Processors
We disclose personal data to the following categories of provider, under contractual obligations of confidentiality and security:
- SMS gateway providers and aggregators — recipient numbers, Sender ID and message content, for transmission to the destination network. We use more than one provider for reliability and routing.
- Telecommunications operators — for delivery over their networks, and for abuse investigations affecting their networks.
- Payment processors and banks — for payment collection and reconciliation.
- Cloud hosting and infrastructure providers — for storage and processing of Platform data.
- Security and delivery-network providers — including Cloudflare, for DDoS protection, web application firewall and bot protection.
- Professional advisers — auditors, accountants and lawyers, where required.
6.2 Disclosure Required or Permitted by Law
We may disclose personal data, without further notice to you, where required or permitted by law, including in response to a court order, warrant, subpoena or lawful request from MCMC, the Royal Malaysia Police (including the Commercial Crime Investigation Department and the National Scam Response Centre), Bank Negara Malaysia, the Securities Commission Malaysia, the Personal Data Protection Commissioner, or any other competent authority. We may also disclose data where we reasonably consider it necessary to prevent, detect, investigate or report an offence, to enforce our Terms of Service, or to protect the rights, property or safety of the Company, our users, Recipients or the public. This is set out further in Section 12.3 of the Terms of Service.
6.3 Business Transfers
If the Company undergoes a merger, acquisition, restructuring or sale of all or part of its business or assets, personal data may be transferred to the acquiring or successor entity, subject to that entity being bound to handle the data in accordance with this Privacy Policy or a policy no less protective.
6.4 No Sale of Personal Data
We do not sell, rent or trade personal data to third parties for their own marketing purposes.
7. Cross-Border Transfers
We are based in Malaysia and store Platform data on infrastructure selected for reliability and performance. Some of our providers — for example cloud hosting, security and certain messaging routes — may process data outside Malaysia. Where personal data is transferred outside Malaysia, we take reasonable steps to ensure the transfer is permitted under the PDPA and that the recipient provides a level of protection comparable to that required in Malaysia, including by imposing contractual safeguards and confidentiality and security obligations. By using the Service, you consent to such transfers where consent is the applicable basis.
8. Your Obligations as Data Controller
Where you upload or submit Recipient Data, you are the data controller and you are responsible for compliance with the PDPA in respect of that data. You represent, warrant and undertake that:
- you have a lawful basis, and where required the valid consent of each Recipient, to process their personal data and to disclose it to us and our sub-processors for transmission;
- you have given each Recipient the notice required under the PDPA Notice and Choice Principle, including the purposes of processing and the classes of third parties to whom their data may be disclosed;
- you maintain records evidencing consent and will produce them to us within 3 business days on request;
- you did not obtain the contact data from a purchased, scraped, leaked or otherwise unlawful source;
- you will honour Recipient opt-out, access and correction requests promptly, and will maintain a suppression list; and
- you will not upload sensitive personal data without our prior written agreement.
If we receive a request or complaint from a Recipient relating to data you control, we will refer it to you and you must respond to it within the period required by law. You indemnify us in respect of claims, investigations and penalties arising from your breach of this Section, in accordance with Section 21 of the Terms of Service.
9. Security
We apply technical and organisational measures appropriate to the nature of the data and the harm that would result from a breach, including:
- Encryption in transit using TLS for the website, dashboard and API, and encryption at rest where applicable.
- Access control on a least-privilege basis, with access to production data restricted to authorised personnel and logged.
- Credential protection — passwords stored as salted hashes using industry-standard algorithms; API keys stored in protected form and revocable by you at any time.
- Account isolation so that each customer's data is logically separated.
- Perimeter protection including Cloudflare DDoS mitigation, web application firewall and bot protection.
- Monitoring and logging of authentication, administrative actions and security events.
- Confidentiality obligations binding our personnel and service providers.
No system is completely secure. While we take reasonable measures, we cannot guarantee absolute security, and you are responsible for protecting your own credentials and API keys.
10. Personal Data Breach Notification
Under the PDPA as amended, a data controller who has reason to believe that a personal data breach has occurred must notify the Personal Data Protection Commissioner, and — where the breach causes or is likely to cause significant harm to affected individuals — must notify those individuals.
- Where we are the controller: we will notify the Commissioner as soon as practicable and, in any event, within 72 hours of becoming aware of a notifiable breach, and will notify affected individuals without unnecessary delay where the breach is likely to cause them significant harm.
- Where we are your processor: we will notify you without undue delay after becoming aware of a breach affecting Recipient Data, with the information reasonably available to us, so that you can meet your own notification obligations as controller.
Security concerns and suspected incidents may be reported to support@smshandy.com.
11. Data Retention
We retain personal data only for as long as necessary for the purposes for which it was collected, and thereafter as required for legal, regulatory, accounting or enforcement purposes:
- Account data: for the life of the account and for a reasonable period after closure, to handle disputes, claims and regulatory queries.
- KYC and verification records: for the life of the account and for a reasonable period after closure, for fraud prevention and legal compliance.
- Message logs and delivery reports: retained in your account for your reference while the account is active, and thereafter for the period necessary for billing disputes, abuse investigation and legal compliance.
- Payment and accounting records: at least seven (7) years, as required by Malaysian tax and accounting law.
- Support communications: for a reasonable period for continuity of support and quality assurance.
- Abuse, breach and enforcement records: records relating to a suspected or established breach of our Terms, and identifiers of terminated or blacklisted accounts, are retained for as long as necessary for enforcement, defence of claims, regulatory reporting and to prevent re-registration.
When data is no longer required, it is securely deleted or anonymised.
12. Your Rights Under the PDPA
Subject to the exceptions and conditions in the PDPA, you have the following rights in respect of personal data for which we are the controller:
- Right of access: to request a copy of the personal data we hold about you. We will respond within the period prescribed by the PDPA, currently twenty-one (21) days.
- Right of correction: to request correction of inaccurate, incomplete, misleading or out-of-date personal data.
- Right to withdraw consent: to withdraw consent to processing. Withdrawal may prevent us from continuing to provide the Service, and does not affect processing carried out before withdrawal or processing on another lawful basis.
- Right to limit processing: to require us to limit processing in certain circumstances.
- Right to prevent processing for direct marketing: to require us to stop using your personal data for marketing at any time.
- Right to data portability: to request, where technically feasible and subject to the conditions prescribed under the PDPA as amended, transmission of your personal data to another data controller.
To exercise a right, contact support@smshandy.com. We may require proof of identity before acting, and may charge a prescribed fee for access requests where permitted. We may decline a request where an exception under the PDPA applies, and will tell you why.
Marketing opt-out: you may unsubscribe from marketing at any time using the mechanism in the message or by emailing us. Operational and service messages will continue while you hold an account.
Complaints: if you are not satisfied with our response, you may lodge a complaint with the Personal Data Protection Department (Jabatan Perlindungan Data Peribadi, JPDP), Ministry of Digital, Malaysia. We ask that you raise the matter with us first so that we can try to resolve it.
13. Cookies and Similar Technologies
- Strictly necessary cookies: required for the Platform to function, including session management, authentication and security.
- Preference cookies: to remember settings such as language and light or dark theme.
- Security: Cloudflare Turnstile is used for bot protection on our forms and may set cookies for verification purposes.
We do not currently use third-party advertising or cross-site tracking cookies. If we introduce analytics or advertising technologies, we will update this Privacy Policy and, where required, obtain consent. Most browsers allow you to block or delete cookies; blocking strictly necessary cookies will prevent the Platform from working correctly.
14. Children
The Service is intended for business use by persons aged 18 and above. We do not knowingly collect personal data from children. If you believe a child has provided personal data to us, contact us and we will take steps to delete it.
15. Third-Party Services and Links
The Service relies on third parties including SMS gateway providers and aggregators, payment gateways and FPX providers, cloud hosting providers, Cloudflare, and Google Fonts. Our website and messages may also contain links to third-party sites. Each third party has its own privacy policy and practices. We are not responsible for the content or privacy practices of third-party services, and we encourage you to review their policies.
16. Future Messaging Channels
As we extend the Platform to additional channels such as WhatsApp, RCS or Telegram, delivery of your messages will involve sharing data with the operators of those platforms (for example Meta, in the case of WhatsApp), whose own terms and privacy policies will also apply to that traffic. We will update this Privacy Policy before or when such channels are made available and will notify you of material changes.
17. Changes to This Policy
We may update this Privacy Policy from time to time. Changes take effect on publication on this page with an updated "last updated" date. Where a change is material, we will make reasonable efforts to notify you by email or platform notice. Your continued use of the Service after the change takes effect constitutes acceptance of the updated Privacy Policy.
18. Contact Us
For questions about this Privacy Policy, to exercise your rights, or to raise a privacy concern:
- Company: Sitehandy Solutions (NS0159990-H)
- Data protection contact: support@smshandy.com
- Abuse and misuse reports: abuse@smshandy.com
- WhatsApp: +6011-3803 8022
- Address: F-7 Tingkat 1, Bangunan Arked MARA, 71000 Port Dickson, Negeri Sembilan, Malaysia.
This Privacy Policy is published in English and Bahasa Malaysia. The Bahasa Malaysia version is a translation provided for convenience; in the event of inconsistency, the English version prevails, save where Applicable Law requires otherwise.