Privacy Policy

Compliant with Malaysia's Personal Data Protection Act 2010 (PDPA).

Last updated: 19 June 2026

1. Introduction & Scope

This Privacy Policy explains how wush collects, uses, discloses, and protects personal data when you use our platform. It applies to account holders and to the data they process through the Service.

2. Data We Collect

  • Account data: name, email, phone number, business name.
  • Billing data: payment tokens held by our processors; we do not store full card numbers.
  • Service usage: messages sent and received through wush, AI prompts, flow executions, and contacts you manage.
  • Analytics: page views, feature usage, and error logs.
  • Cookies: session, theme preference, and authentication tokens.

3. How We Use Your Data

We use data to provide and maintain the Service, process billing, offer support, prevent abuse and fraud, and improve our product through aggregate analytics.

4. Legal Basis

We process personal data on the basis of your consent, the performance of our contract with you, and where necessary to operate and secure the Service, in accordance with the PDPA.

5. Data Retention

  • Account data: retained for the lifetime of your account plus 90 days after deletion.
  • Message content: retained for 1 year by default, configurable to a shorter period per workspace.
  • Logs: retained for 30 days.
  • Backups: rolling 90-day retention.

6. Third-Party Sharing

We share data only with service providers necessary to operate wush:

  • WhatsApp gateway: a messaging gateway operated by wush to send and receive your WhatsApp messages.
  • Payment processors: CHIP, Stripe, Billplz, Bayarcash, Atome, and GrabPay, each governed by its own privacy policy.
  • Email delivery: a transactional email provider for account and notification emails.
  • Hosting: OVH, in the Asia / Southeast Asia (Singapore) region.
  • AI providers: OpenAI, Anthropic, and DeepSeek may process message content to power AI agent features, according to each workspace’s configuration.

We do not sell your personal data.

7. Your Rights

Under the PDPA you may access, correct, or request deletion of your personal data, request a copy for portability, and withdraw consent. To exercise these rights, email hi@wush.my.

8. Cookies & Tracking

We use strictly functional cookies for session management, authentication, and theme preference. We do not use advertising or cross-site tracking cookies.

9. Data Security

We protect data with TLS encryption in transit, AES-256-GCM encryption for stored integration secrets, bcrypt password hashing, optional two-factor authentication, and audit logging. No system is perfectly secure, but we work continuously to safeguard your data.

10. International Transfers

Your primary data is stored in Singapore (Southeast Asia). Some processors listed in section 6 may operate outside the region; where data is transferred internationally, we apply safeguards consistent with the PDPA’s cross-border requirements.

11. Children

The Service is intended for users aged 16 and above and is not directed at children under 13. We do not knowingly collect data from children under 13.

12. Changes to This Policy

We may update this Policy from time to time. For material changes, we will provide at least 30 days’ notice by email or in-app notice.

13. Contact

For privacy questions or to reach our data protection contact, email hi@wush.my.

Questions? Email us at hi@wush.my.