Privacy Policy

Last updated: [date]

Draft, not yet legal-reviewed. This follows the standard structure most SaaS privacy policies use, filled in with what's actually true about how DolveCRM works. Fields marked like this need real business details (company registration, address, DPO contact) before this is published or relied on. Have a lawyer check it against Malaysia's PDPA before it goes live.

This policy explains what personal data DolveCRM collects on behalf of the clinics, salons, spas, firms and studios that use it ("our clients"), and how that data is handled. If you're a patient, client or member messaging one of our clients on WhatsApp, this policy covers how your enquiry, booking and feedback data is processed.

1. Who this applies to

DolveCRM is a customer recovery system used by businesses (dental clinics, salons, spas, law and financial advisory firms, gyms and enrichment centres) to manage bookings, reminders, feedback and follow-up over WhatsApp. Our client is the business you're messaging; we process data on their behalf as their service provider.

2. Information we collect

We don't collect payment card details, government ID numbers, or health records beyond what you choose to type into a booking note.

3. How we use your information

We do not sell, rent, or trade your data, and we do not use it for advertising.

4. How we share your information

Messages are sent and received through the WhatsApp Business Platform, operated by Meta. Meta processes message content as part of delivering it, under its own terms. Beyond what's needed to operate WhatsApp messaging and hosting, we don't share your data with any other third party, and we don't sell it to anyone.

5. Where your data is stored

Data is stored on infrastructure located in Malaysia, in line with the Personal Data Protection Act 2010 (PDPA). It is not transferred outside Malaysia.

6. Data retention

We keep your data for as long as you remain a client of the business you're dealing with, plus a reasonable period afterward for record-keeping, or as required by law. A rejected or cancelled booking is kept temporarily (currently 7 days) before being permanently removed, so a mistaken rejection can still be reversed.

7. Security measures

Access to your data is restricted to authorised staff at the business you're dealing with, protected by encryption, access controls, and audit logging of who accessed what. If a security incident affects your data, we'll notify the affected business so they can inform you, in line with our obligations under the PDPA.

8. Your rights under PDPA

To exercise any of these, contact the business you're dealing with directly, or reach us at [email protected].

9. Changes to this policy

If this policy changes materially, we'll update the date at the top of this page.

10. Contact

[Company legal name]
[Registered address]
[email protected]