Privacy Policy

Last Updated: August 20, 2025

This Privacy Policy explains how LazyReply ("LazyReply," "we," "us," or "our"), also doing business as "iCare Softwares," collects, uses, discloses, and safeguards personal information when you use our website and AI-powered WhatsApp automation Service.

By using the Service or providing personal information, you consent to this Privacy Policy. If you do not agree, please use the choices in 12. Your Choices or stop using the Service.

1. What Personal Information We Collect

1.1 Personal Information

  • Name and email address (account registration)
  • WhatsApp Business phone number
  • Billing details and payment information

1.2 WhatsApp Message Data

  • Messages sent/received in text format via your WhatsApp Business account
  • Your customers' contact information
  • Message metadata (timestamps, delivery status)

1.3 Usage Data

  • How you use the Service, login times, features accessed, settings
  • We do not collect the IP address and device information

2. Mandatory vs Optional Data

Some information is mandatory to provide the Service (e.g., WhatsApp Business number, billing details). If you do not provide mandatory data, we may be unable to provide the Service. Other information is optional and you may choose not to provide it.

3. What We Do With the Personal Information We Collect

Basis of Processing under PDPA. We process personal data with your consent, and where permitted under the PDPA (e.g., performance of a contract and legal obligations). You may withdraw consent at any time; upon receipt we will cease processing except where a PDPA exception applies.

  • Service Provision: Provide, maintain, and improve the Service
  • AI Processing: Use AI to generate and assist replies. We do not use your content to train third-party foundation models (e.g., OpenAI) unless you have explicitly opted in. We may use aggregated or de-identified analytics to improve features.
  • Customer Support: Respond to inquiries and provide technical support
  • Billing: Process payments and manage subscriptions via BillPlz integration
  • Communication: Send service updates and security alerts (and, where permitted, promotional materials)
  • Analytics: Analyze usage patterns using aggregated data to improve performance
  • Legal Compliance: Comply with applicable laws and regulations

Controller/Processor role. For your business account data, we act as data controller. For your customers' WhatsApp message data, we act as your data processor, processing only on your documented instructions and under a Data Processing Addendum (DPA). You are responsible for providing required privacy notices/consents to your customers.

4. When We Disclose Personal Information

We do not sell your personal information. We disclose it only:

  • Service Providers: Under contracts that require confidentiality and security
  • WhatsApp/Meta: As required for official WhatsApp Business API/Cloud API integrations
  • Legal: To comply with law, enforce terms, or protect rights
  • Business Transfers: With appropriate safeguards in a merger, acquisition, or sale of assets
  • With Consent: Where you explicitly agree

Important: We use official WhatsApp Business channels only and do not engage in unofficial automation or bulk messaging that violates WhatsApp policies.

5. Cookies and Similar Technologies

We use cookies and similar technologies to operate the site, enhance your experience, and analyze usage. Essential cookies are required for the Service to function. You can control non-essential cookies via your browser settings and, where available, our cookie settings banner.

6. Security

We protect data with TLS in transit, encryption at rest, strict access controls, audit logging, and regular vulnerability testing. We also maintain backups and disaster-recovery procedures.

7. Data Retention

  • Account Data: While your account is active, plus 30 days after deletion
  • Message Data: 90 days for service operation, then deleted unless anonymized for analytics
  • Billing Records: 7 years (Malaysian legal requirements)
  • Analytics Data: Anonymized/aggregated data may be retained to improve features

We keep data only as necessary for stated purposes under the PDPA Retention Principle.

8. Data Protection Officer (DPO)

We have appointed a DPO. Contact: admin@icaresoftwares.com. (DPO appointment is required from 1 June 2025.)

9. Personal Data Breach Notification

We maintain incident response procedures. Where required, we will notify the Commissioner within 72 hours of becoming aware of a personal data breach and notify affected individuals within 7 days after notifying the Commissioner where there is (or is likely) significant harm.

10. International Transfers

When transferring data outside Malaysia, we implement safeguards required by amended Section 129 PDPA and the Cross-Border Personal Data Transfer Guidelines (e.g., contractual protections, and where applicable, explicit consent). Some providers (e.g., cloud hosting and AI vendors) may be located outside Malaysia.

11. Links to Other Websites

Our Service may contain links to third-party sites. Their privacy practices are their own; review their policies before sharing personal information.

12. Your Choices

Update your account information; opt out of promotional communications; withdraw consent for optional processing; delete your account and request deletion.

13. Accessing and Correcting Your Personal Information

Under Malaysia's PDPA you may request access and correction of your personal data, withdraw consent, require us to cease processing likely to cause damage or distress, and opt out of direct marketing.

How to exercise your rights: email admin@icaresoftwares.com. We will respond within 21 days and may request information to verify your identity.

14. Children

The Service is not intended for children under 18. If you believe a child has provided personal information, contact us.

15. Changes to This Privacy Policy

We may update this notice. We will post updates here and revise the "Last Updated" date.

16. Contact Us

LazyReply (also doing business as iCare Softwares)

Email: admin@icaresoftwares.com

DPO: admin@icaresoftwares.com

Support: admin@icaresoftwares.com

Website: www.lazyreply.com

PDPA Compliance: Designed to comply with the Personal Data Protection Act 2010 (Malaysia) and the 2025 amendments/guidelines. We are committed to protecting personal data in accordance with Malaysian data protection laws and regulations.

© 2025. All rights reserved. • Developed & Maintained by iCare Softwares