Privacy Policy
Last updated: July 12, 2026
This Privacy Policy explains how com1 coding Sdn. Bhd., [REGISTERED ADDRESS], Malaysia ("InstantBlast", "we") processes personal data when you use the InstantBlast service. Questions and requests: [CONTACT E-MAIL].
1. Two roles: controller and processor
- For account, team, billing, and usage data of the people who sign up and work in InstantBlast, we are the controller.
- For the Contacts and WhatsApp conversations that a Team brings into the Service (their customers' names, phone numbers, attributes, messages, media), we act as a processor on the Team's documented instructions. The Team is the controller of that data. If you are a Contact of one of our customers, please direct privacy requests to that business first — we support them in fulfilling your rights.
2. Data we process
As controller
- Account data — name, e-mail, password hash, optional passkeys and two-factor secrets, team memberships and roles.
- Billing data — subscription status, credit balance and ledger, and Paddle transaction references. We never receive or store card numbers; payment details go directly to Paddle, our merchant of record.
- Usage and log data — application logs, IP addresses, and security events, kept for operations and abuse prevention.
As processor (Team content)
- Contacts — phone number, name, e-mail, birthday, address fields, tags, and custom attributes the Team records.
- Conversations — inbound and outbound WhatsApp messages, including media (stored in private object storage), reactions, delivery/read events, and WhatsApp profile names.
- Templates and bot flows the Team creates.
3. Purposes and legal bases
- Providing the Service (contract performance) — operating broadcasts, the inbox, bots, and billing.
- Security and abuse prevention (legitimate interests) — webhook signature verification, rate limiting, logs.
- Communications — transactional e-mail about your account (contract); product news only with consent.
- Legal compliance — accounting and tax retention duties.
4. Subprocessors and recipients
| Provider | Purpose | Data involved |
|---|---|---|
| Amazon Web Services | Hosting, database, private media storage | All service data |
| Meta Platforms (WhatsApp Business Platform) | Message delivery to and from WhatsApp | Message content, phone numbers, delivery metadata — under your own WABA |
| Paddle (merchant of record) | Payments, tax, invoicing | Buyer name, e-mail, payment details (held by Paddle, not us) |
| Anthropic | Optional AI template rework | Template text only — never Contact data or conversations |
Real-time inbox updates run on infrastructure we operate (Laravel Reverb) — no third-party websocket service is involved. We do not sell personal data and do not share it with advertisers.
5. International transfers
We are a Malaysian company and use infrastructure providers that may process data outside your country (hosting region configurable per deployment). Where GDPR applies, transfers rely on adequacy decisions or Standard Contractual Clauses with the providers above.
6. Retention
- Raw WhatsApp webhook payloads — deleted after 30 days.
- Contacts, conversations, media, templates, flows — kept until the Team deletes them or closes the account; then deleted within a reasonable period.
- Billing and credit-ledger records — kept for statutory accounting periods.
- Logs — short rotation windows appropriate to security needs.
7. Cookies
We use only strictly necessary cookies: a session cookie and a CSRF token. There are no advertising, analytics, or cross-site tracking cookies, which is why you see no cookie banner.
8. Security
Measures include TLS in transit, encryption at rest for access tokens and other sensitive columns, strict team-level data isolation enforced in the application, signature-verified webhooks, role-based access within Teams, and support for passkeys and two-factor authentication on user accounts.
9. Your rights
Malaysia (PDPA 2010)
You may request access to and correction of your personal data, withdraw consent, and limit processing for direct marketing. Contact [CONTACT E-MAIL]; we respond within the timelines set by the Personal Data Protection Act 2010.
EEA / UK (GDPR)
If you are in the EEA or UK you additionally have the rights of access, rectification, erasure, restriction, portability, and objection, and the right to lodge a complaint with your supervisory authority. Where we act as processor, we will refer your request to the responsible Team and assist them in answering it.
10. Children
The Service is for businesses and is not directed at children under 16.
11. Changes
We may update this policy; material changes are announced by e-mail or in-app at least 14 days before taking effect. The "Last updated" date above always reflects the current version.