PDPA Compliance
How Boka meets the Personal Data Protection Act 2010, as amended in 2024. Written to be forwarded to whoever reviews this for you.
1. Why this page exists
No business can adopt a tool that records its customers’ calls without someone checking it first, and in a clinic or a salon that check is a formal one. This page is that check, in one place, so you are not reverse-engineering our position from a privacy policy written for the general public.
If your reviewer needs something not covered here, email privacy@boka.my and we will answer in writing rather than on a call.
2. Which of us is responsible for what
This is the first question a reviewer asks, and getting it wrong is how businesses end up with a gap neither party thought they owned.
- You are the data user for your customers’ personal data. You decided to collect it, you decide what it is for, and the relationship with the caller is yours.
- We are the data processor for that data. We process it on your instructions, to provide the service, and for nothing else.
- We are the data user for your own account data — your staff logins, your billing records, your usage.
In practice this means obligations that attach to the data user attach to you: having a lawful basis for recording your callers, answering their access requests, and publishing your own privacy notice. We build the tooling that makes those straightforward, and section 4 covers what we hand you.
3. The seven principles
| Principle | How we meet it |
|---|---|
| General | We process personal data only to run the service our customer has asked for — answering their calls, booking their appointments, and taking their messages. We do not process it for our own purposes beyond that. |
| Notice and Choice | Callers are told at the start of every recorded call that the call is recorded, in the business's primary language, before the conversation begins. Our customer's own privacy notice covers the rest of their relationship with the caller. |
| Disclosure | Call data is disclosed to the business that received the call, and to the processors listed below. It is not sold, and it is not shared with anyone else without instruction or a legal obligation. |
| Security | Encryption in transit and at rest, per-tenant isolation enforced at the database level, and access limited to staff who need it. Detail below. |
| Retention | Recordings are deleted automatically on a per-customer schedule, 90 days by default. Nothing is kept indefinitely by accident — deletion is a scheduled job, not a manual clean-up someone has to remember. |
| Data Integrity | Callers confirm their name and appointment time back to the assistant before a booking is written, and our customer can correct any record from their dashboard. |
| Access | Data subjects can request access to or correction of their data. Where the record belongs to one of our customers, we route the request to them and confirm we have done so. |
4. Call recording and consent
The PDPA requires consent for recording, and requires that it be informed. Our approach is that the notice cannot be left to chance:
- The recording notice is configuration, not a prompt instruction. It is a fixed string spoken as the first thing on the call, before the AI is asked to do anything. A language model told to “mention recording” will eventually paraphrase it or drop it when a caller interrupts; this cannot.
- It is announced in your primary language, not always English. We ship notices for English, Bahasa Malaysia, Mandarin, Cantonese and Tamil.
- You can reword it to match your own privacy notice, or switch recording off entirely, in which case nothing is recorded and nothing is announced.
- Every call carries a per-call record of what happened — announced, not required, or failed. Evidence is per call, because “we announce recordings” is not the claim that matters if you are ever asked about one specific call.
- If a caller objects, the assistant does not argue or claim it can switch recording off mid-call. It apologises and either hands the call to one of your team, where you have transfers enabled, or takes a message.
5. Where data is stored
Call recordings, transcripts and customer records are stored in Malaysia or Singapore, encrypted at rest and in transit. Some of our processors operate infrastructure outside Malaysia; where personal data is transferred abroad we rely on contractual protections requiring a standard of care no lower than the PDPA.
6. Retention and deletion
- Recordings — deleted automatically, default 90 days, configurable per customer.
- Transcripts, summaries and bookings — kept for the life of your account.
- Billing and usage records — seven years, as tax law requires.
- After your account closes — deleted within 90 days, except where law requires otherwise.
Deletion runs as a scheduled job. It is not a manual clean-up that depends on someone remembering, which is the usual reason retention policies quietly stop being true.
7. Security
- Encryption in transit (TLS) and at rest.
- Per-tenant isolation enforced in the database itself, so one customer’s queries cannot return another customer’s rows even if application code is wrong.
- Access limited to staff who need it, and logged.
- Card details are held by our payment processor and never touch our systems.
- Your call recordings and transcripts are never used to train publicly available AI models.
8. Breach notification
The 2024 amendments introduced a 72-hour notification requirement. If we become aware of a personal data breach that poses a significant risk, we will notify the Commissioner and affected customers within 72 hours, with what we know at the time rather than waiting for a complete picture. You will hear it from us, not from a news article.
9. Data Protection Officer
The 2024 amendments require a Data Protection Officer. Ours is contactable at privacy@boka.my; we will name the individual here on request and in our data processing agreement.
10. Processors we use
We use third parties for cloud hosting, telephony, speech recognition, speech synthesis, AI inference and payment processing. Each is bound to process data only on our instructions. We will provide the current named list, with locations, under NDA or as part of a data processing agreement — ask at privacy@boka.my.
11. What we ask of you
- Publish a privacy notice covering your use of an AI receptionist.
- Keep the recording notice enabled, or turn recording off. Do not reword it into something that no longer discloses recording.
- Remove staff dashboard access when they leave.
- Pass us data subject requests that concern call data, and we will act on them.
- Do not use the service for unsolicited marketing, and enforce do-not-call at the point of dialling rather than in the assistant’s instructions.
12. What we have not done yet
Stated plainly, because a compliance page that admits nothing is not worth reading:
- We treat a caller continuing the conversation after the notice as consent. That is common practice, and we believe it is defensible, but it has not been tested in a Malaysian court and your own adviser may take a stricter view.
- There is no self-service path for a caller to decline recording and continue the call. Today the assistant takes a message instead. Automatically suppressing the recording is on the roadmap.
- We are not certified to ISO 27001 or SOC 2. If your procurement process requires it, tell us early — it is a question of timing, not willingness.
13. Contact
privacy@boka.my for anything on this page, including data processing agreements and security questionnaires. See also our Privacy Policy and Terms of Service.
Questions about this document: privacy@boka.my.