Privacy Policy
Last updated: 16 May 2026 · Effective date: 16 May 2026
FlowCRM MY ("FlowCRM MY", "we", "our", or "us") is committed to protecting your personal data. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our platform and services, in accordance with the Personal Data Protection Act 2010 (Act 709) of Malaysia ("PDPA") and its subsidiary regulations.
By using FlowCRM MY, you acknowledge that you have read and understood this Privacy Policy and consent to the processing of your personal data as described herein. If you do not agree, please discontinue use of our services.
1. Data Controller
The data controller responsible for your personal data is:
Bandar Bestari Perdana
81700 Pasir Gudang, Johor, Malaysia
Email: privacy@flowcrm.my
2. Personal Data We Collect
We collect personal data that you provide directly and data generated through your use of our services. Categories include:
Account & Identity Data
Full name, email address, phone number, business name, business registration number (SSM), industry type, and profile photo (optional).
Financial & Billing Data
Subscription plan, billing address, payment records, and invoice history. We do not store full credit or debit card numbers — payments are processed by our third-party payment provider.
Business Operations Data
Customer contact lists, leads, sales records, invoices, expense records, and payroll information (including employee names, MyKad number, salary, EPF and SOCSO contribution data) that you input into the platform.
Usage & Technical Data
IP address, browser type, device identifiers, pages visited, session duration, clickstream data, and error logs collected automatically when you use our platform.
Communication Data
Support tickets, in-app messages, feedback forms, and any correspondence you send to us.
Affiliate & Referral Data
Referral code, referral link click and conversion events, referred user activity (sign-up and subscription status), commission records, payout history, and bank account or payment details provided by participants in the FlowCRM MY Affiliate Program.
3. Notice & Your Consent (PDPA Notice Principle)
In accordance with Section 7 of the PDPA, we inform you that your personal data is being processed. You provide consent when you:
- Register for a FlowCRM MY account;
- Accept this Privacy Policy and our Terms of Service;
- Opt in to marketing communications; or
- Continue to use our services after being notified of policy changes.
You may withdraw your consent at any time by contacting us at privacy@flowcrm.my. Withdrawal of consent does not affect the lawfulness of processing prior to withdrawal and may limit your ability to use certain features of the platform.
4. How We Use Your Personal Data (General Principle)
We process your personal data only for purposes disclosed to you and that are lawful, as required under Section 6 of the PDPA:
| Purpose | Legal Basis |
|---|---|
| Providing and operating the FlowCRM MY platform | Contractual necessity / Consent |
| Processing subscription payments and invoicing | Contractual necessity / Legal obligation |
| Generating payroll and compliance reports (EPF, SOCSO, PCB) | Legal obligation (Malaysian employment law) |
| Customer support and technical troubleshooting | Contractual necessity / Consent |
| Platform security, fraud prevention, and abuse detection | Legitimate interest |
| Product analytics and platform improvement | Legitimate interest |
| Sending service notifications and product updates | Consent / Contractual necessity |
| Marketing and promotional communications (opt-in only) | Consent |
| Tracking referral conversions and calculating affiliate commissions | Contractual necessity / Consent |
| Processing affiliate payouts and maintaining commission records | Contractual necessity / Legal obligation |
| Compliance with Malaysian laws and regulatory requirements | Legal obligation |
5. Disclosure of Personal Data (PDPA Disclosure Principle)
We do not sell or rent your personal data. We may share your data only in the following circumstances, as permitted under Section 8 of the PDPA:
- Service Providers:Trusted third-party vendors who assist in operating our platform (cloud hosting, payment processing, email delivery, analytics), bound by confidentiality obligations and PDPA-equivalent data protection terms.
- Regulatory Authorities:Government bodies such as LHDN (Inland Revenue Board), EPF (KWSP), SOCSO (PERKESO), SSM, or law enforcement when required by Malaysian law or a valid court order.
- Business Transfers:In the event of a merger, acquisition, or asset sale, your data may be transferred to the successor entity, subject to the same privacy protections.
- With Your Consent:Any other disclosure made only with your explicit consent.
6. Data Security (PDPA Security Principle)
We implement appropriate technical and organisational measures to protect your personal data against unauthorised access, loss, destruction, or alteration, as required under Section 9 of the PDPA. These measures include:
- TLS/SSL encryption for all data in transit
- AES-256 encryption for sensitive data at rest
- Role-based access control and least-privilege principles
- Regular security audits and vulnerability assessments
- Multi-factor authentication (MFA) for administrative access
- Automated backups and disaster recovery procedures
In the event of a data breach that affects your rights and freedoms, we will notify affected users and the relevant authorities in accordance with applicable Malaysian law.
7. Data Retention (PDPA Retention Principle)
We retain your personal data only for as long as necessary to fulfil the purposes for which it was collected, or as required by Malaysian law, as governed by Section 10 of the PDPA:
Upon expiry of the retention period, data is securely deleted or anonymised.
8. Data Accuracy (PDPA Data Integrity Principle)
We take reasonable steps to ensure that the personal data we hold is accurate, complete, and up to date, as required under Section 11 of the PDPA. You are responsible for ensuring that the information you provide to us is accurate and current. You may update your account details at any time through your FlowCRM MY dashboard settings.
9. Your Rights (PDPA Access Principle)
Under Section 12 and 13 of the PDPA, you have the following rights regarding your personal data:
Right to Access
Request a copy of the personal data we hold about you.
Right to Correction
Request that inaccurate or incomplete data be corrected.
Right to Withdraw Consent
Withdraw previously given consent for optional processing (e.g., marketing emails).
Right to Data Portability
Request an export of your business data in a commonly used machine-readable format.
Right to Deletion
Request deletion of your account and personal data, subject to records we are legally required to retain (e.g. payment records for statutory accounting periods).
Right to Restrict Processing
Request limitation of certain processing activities where permitted by law.
Right to Lodge a Complaint
File a complaint with the Personal Data Protection Department (JPDP) of Malaysia if you believe your rights have been violated.
To exercise any of the above rights, submit a written request to privacy@flowcrm.my. We will respond within 21 days of receipt. A fee may apply for access or correction requests as permitted under the PDPA regulations.
10. Cross-Border Data Transfers
Your data is primarily processed and stored on servers located in Malaysia or in countries approved under Section 129 of the PDPA as providing an adequate level of data protection (including Singapore and the European Economic Area). Where data is transferred outside Malaysia, we ensure appropriate contractual safeguards are in place to protect your personal data.
11. Cookies & Tracking Technologies
We use cookies and similar technologies to operate our platform, personalise your experience, and analyse platform usage. Categories of cookies we use:
You may manage cookie preferences through your browser settings. Disabling certain cookies may affect the functionality of the platform.
12. Children's Privacy
FlowCRM MY is designed for business use and is not directed at individuals under the age of 18. We do not knowingly collect personal data from minors. If you believe a minor has provided us with personal data, please contact us immediately and we will delete the information promptly.
13. Changes to This Privacy Policy
We may update this Privacy Policy from time to time to reflect changes in our practices or applicable law. We will notify you of material changes via email or a prominent in-platform notice at least 14 days before the changes take effect. The "Last updated" date at the top of this page will always reflect the most recent revision.
14. Contact & Complaints
For any privacy-related queries, requests, or complaints, please contact our Data Protection Officer:
HORIZON CENTRIX ENTERPRISE
Email: privacy@flowcrm.my
Response time: Within 21 working days
If you are dissatisfied with our response, you may lodge a complaint with the Personal Data Protection Department (Jabatan Perlindungan Data Peribadi — JPDP) at www.pdp.gov.my.