Privacy Policy
Last updated: 22 July 2026
1. Who We Are
ErzyCall is operated by Erzy Sdn Bhd, a company incorporated in Malaysia and a Malaysia Digital (MDEC) status company (“ErzyCall,” “we,” “our,” or “us”), with its registered office at Level 24 & 25, Menara Worldwide, 198 Jalan Bukit Bintang, 55100 Kuala Lumpur, Malaysia.
This Privacy Policy explains how we collect, use, disclose, store, and protect personal data when you use our AI-powered call answering, voice automation, and reminder services (the “Services”), in accordance with the Malaysian Personal Data Protection Act 2010 (“PDPA”), as amended, and its subsidiary regulations and guidelines.
For the purposes of the PDPA:
- We act as a data controller in respect of the personal data of our account holders and their authorised users (our business customers).
- We act as a data processor on behalf of our business customers in respect of the personal data of the individuals they call, message, or schedule through the Services (“Call Recipients”). Our customers are the data controllers of that data and are responsible for having a lawful basis to process it. See Section 10.
2. Personal Data We Collect
From our business customers and their users:
- Account & contact data: name, business name, email address, phone number, job role, and login credentials.
- Billing data: billing address, payment method details, and transaction records (card details are handled by our payment provider, not stored by us).
- Usage data: log data, device and browser information, IP address, and analytics on how you use the Services.
Processed on behalf of our customers (Call Recipient data):
- Call data: phone numbers, audio recordings, transcriptions, call metadata (time, duration, outcome), and any information a Call Recipient provides during a call.
- Connected Calendar data: if you connect Google Calendar or Microsoft Outlook Calendar, event details from the calendars you authorise. See Section 4.
Sensitive personal data: Voice recordings may constitute biometric or sensitive personal data, and Call Recipients may volunteer sensitive information. We only process sensitive personal data where explicit consent has been obtained by our customer, or where otherwise permitted under Section 40 of the PDPA. See Section 10.
3. Purposes for Which We Process Personal Data
We process personal data only for lawful purposes directly related to our activities, and in a manner that is adequate, relevant, and not excessive. Specifically, to:
- Provide, operate, and maintain the Services, including answering, routing, recording, and transcribing calls and delivering reminders;
- Create, reschedule, or cancel bookings and calendar events at your direction;
- Process subscriptions, payments, and renewals;
- Send technical notices, updates, security alerts, and support messages;
- Respond to enquiries, requests, and complaints;
- Improve and secure the Services and prevent fraud or misuse;
- Comply with legal and regulatory obligations in Malaysia.
We do not sell personal data. We do not use Call Recipient data or Google user data to train generalised AI/ML models. Any AI processing (for example, generating the spoken content of a call or reminder) is limited to delivering the specific feature you have enabled.
4. Google Calendar Integration & Google User Data
If you connect a Google Calendar account, we access Google user data through the Google Calendar API. This access is governed by the Google API Services User Data Policy, including its Limited Use requirements.
Data we access: event titles, start/end times, locations, recurrence information, and the names, email addresses, and RSVP status of organisers and attendees, for events on the calendars you authorise.
How we use it: solely to power features you have enabled — generating AI voice-call, SMS, and email reminders to attendees; creating events when a booking is made through ErzyCall; rescheduling or cancelling events at your request; and detecting when a meeting is cancelled or moved so we can update the associated reminder. We do not use Google user data for advertising, and any AI processing of it is limited to producing that specific reminder — it is not used to train generalised AI/ML models.
Data sharing: we share Google Calendar data only with the service providers that power these features, under agreements limiting their use to providing the service to us — Composio (calendar integration middleware) and Vapi (voice AI). We do not sell Google user data or transfer it for any unrelated purpose.
Protection, retention & deletion: Google Calendar data is encrypted in transit (TLS) and at rest, and access is segregated by organisation. We retain synced event data only as long as needed to deliver reminders for that event — generally until the meeting passes or you disconnect your calendar. Disconnecting Google Calendar in your ErzyCall settings, or deleting your account, revokes our access token and removes the associated stored calendar data.
Limited Use disclosure: ErzyCall's use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
5. Disclosure of Personal Data
We disclose personal data only:
- To service providers who process data on our behalf under contracts that restrict their use of it. Current categories include: voice AI (Vapi), calendar/integration middleware (Composio), cloud hosting and infrastructure, payment processing, communications/telephony carriers, and analytics.
- To our business customer whose account the data relates to (for Call Recipient and calendar data processed on their behalf).
- Where required by law, court order, or a lawful request by a public authority in Malaysia.
- In connection with a corporate transaction (e.g. merger, acquisition, or asset sale), subject to this Policy.
We do not sell or rent personal data to third parties.
6. Cross-Border Data Transfers
Some of our service providers (including Vapi and Composio) process data on servers located outside Malaysia. Where we transfer personal data outside Malaysia, we do so in accordance with the PDPA and the Personal Data Protection Commissioner's Guidelines on Cross-Border Personal Data Transfer. We transfer data only where the destination provides protection substantially similar to the PDPA or an adequate level of protection, or where another lawful basis under the PDPA applies (for example, your consent, or where the transfer is necessary to perform our contract with you). We put contractual safeguards in place with recipients to protect transferred data.
7. Data Security
We implement appropriate technical and organisational measures to protect personal data against loss, misuse, and unauthorised access, alteration, or disclosure, consistent with the PDPA Security Principle. These include encryption of data in transit (TLS) and at rest, access controls and organisation-level data segregation, and restricting access to personnel who need it to operate the Services. No system is completely secure, but we work continuously to protect your data.
8. Data Retention
We retain personal data only for as long as necessary to fulfil the purposes in this Policy or as required by Malaysian law, consistent with the PDPA Retention Principle. Account data is retained for the life of your account and a reasonable period afterward to meet legal, tax, and audit obligations. Call recordings and transcriptions are retained according to your subscription plan settings and may be deleted earlier on request. Calendar event data is retained as described in Section 4. When personal data is no longer required, we securely delete or anonymise it.
9. Your Rights as a Data Subject
Under the PDPA you have the right to:
- Access the personal data we hold about you;
- Correct personal data that is inaccurate, incomplete, or out of date;
- Withdraw consent to processing (which may mean we can no longer provide certain Services);
- Limit or object to processing, including for direct marketing;
- Data portability — request that your personal data be transmitted directly to another data controller, where technically feasible and the data formats are compatible;
- Lodge a complaint with us or with the Personal Data Protection Commissioner.
To exercise any of these rights, contact us at info@erzy.net. We will respond within the timeframes required by the PDPA. If the personal data relates to calls made by one of our business customers, we may direct your request to that customer as the responsible data controller.
10. Our Business Customers' Responsibilities
Where we process Call Recipient data on behalf of a business customer, that customer is the data controller and is responsible under the PDPA for:
- Having a valid lawful basis and, where required, the consent of Call Recipients to be contacted, called, messaged, and recorded;
- Informing Call Recipients that calls may be handled by an automated/AI system and recorded, and the purpose of the recording, as required by the PDPA and the Communications and Multimedia Act 1998;
- Complying with laws on unsolicited commercial communications, including Section 233A of the Communications and Multimedia Act, and any applicable no-contact preferences;
- Issuing their own PDPA-compliant privacy notice to their Call Recipients.
Our customers agree to these obligations under our Terms of Service. If you are a Call Recipient and wish to stop receiving calls or exercise your rights, please contact the business that contacted you, or reach us at the details below and we will assist.
11. Data Breach Notification
If we become aware of a personal data breach affecting data we control, we will notify the Personal Data Protection Commissioner as soon as practicable, and — where the breach is likely to cause significant harm — notify affected data subjects without unnecessary delay, in accordance with the PDPA. Where we process data on behalf of a customer, we will notify that customer promptly so they can meet their own notification obligations.
12. Data Protection Officer & Contact
We have appointed a Data Protection Officer to oversee our PDPA compliance and handle data protection queries.
- Email: info@erzy.net
- Post: Data Protection Officer, Erzy Sdn Bhd, Level 24 & 25, Menara Worldwide, 198 Jalan Bukit Bintang, 55100 Kuala Lumpur, Malaysia
You may also contact the regulator: the Personal Data Protection Department (Jabatan Perlindungan Data Peribadi, JPDP), Ministry of Digital, Malaysia — www.pdp.gov.my.
13. Changes to This Policy
We may update this Policy from time to time. We will post the updated Policy on this page and revise the “Last updated” date. Material changes will be notified to account holders by email or in-product notice.
← Back to Home