PDPA Compliance

How Boka meets the Personal Data Protection Act 2010, as amended in 2024. Written to be forwarded to whoever reviews this for you.

1. Why this page exists

No business can adopt a tool that records its customers’ calls without someone checking it first, and in a clinic or a salon that check is a formal one. This page is that check, in one place, so you are not reverse-engineering our position from a privacy policy written for the general public.

If your reviewer needs something not covered here, email privacy@boka.my and we will answer in writing rather than on a call.

2. Which of us is responsible for what

This is the first question a reviewer asks, and getting it wrong is how businesses end up with a gap neither party thought they owned.

In practice this means obligations that attach to the data user attach to you: having a lawful basis for recording your callers, answering their access requests, and publishing your own privacy notice. We build the tooling that makes those straightforward, and section 4 covers what we hand you.

3. The seven principles

4. Call recording and consent

The PDPA requires consent for recording, and requires that it be informed. Our approach is that the notice cannot be left to chance:

5. Where data is stored

Call recordings, transcripts and customer records are stored in Malaysia or Singapore, encrypted at rest and in transit. Some of our processors operate infrastructure outside Malaysia; where personal data is transferred abroad we rely on contractual protections requiring a standard of care no lower than the PDPA.

6. Retention and deletion

Deletion runs as a scheduled job. It is not a manual clean-up that depends on someone remembering, which is the usual reason retention policies quietly stop being true.

7. Security

8. Breach notification

The 2024 amendments introduced a 72-hour notification requirement. If we become aware of a personal data breach that poses a significant risk, we will notify the Commissioner and affected customers within 72 hours, with what we know at the time rather than waiting for a complete picture. You will hear it from us, not from a news article.

9. Data Protection Officer

The 2024 amendments require a Data Protection Officer. Ours is contactable at privacy@boka.my; we will name the individual here on request and in our data processing agreement.

10. Processors we use

We use third parties for cloud hosting, telephony, speech recognition, speech synthesis, AI inference and payment processing. Each is bound to process data only on our instructions. We will provide the current named list, with locations, under NDA or as part of a data processing agreement — ask at privacy@boka.my.

11. What we ask of you

12. What we have not done yet

Stated plainly, because a compliance page that admits nothing is not worth reading:

13. Contact

privacy@boka.my for anything on this page, including data processing agreements and security questionnaires. See also our Privacy Policy and Terms of Service.


Questions about this document: privacy@boka.my.