Privacy Notice

Effective date: 1 July 2025  ·  Last updated: 6 July 2026

This Privacy Notice is issued by Mesh App Solutions PLT (“we”, “us”, “our”) in compliance with the Personal Data Protection Act 2010 (Act 709) of Malaysia. It explains how we collect, use, store, process, and protect personal data when you use PropOS, our AI-powered property management platform.

1. Our Capacity under the PDPA

Depending on your relationship with PropOS, our legal obligations differ under Act 709:

  • As a Data User: We act as a Data User for the personal data of our direct Customers (account holders, company representatives, and invited team members).
  • As a Data Processor: We act strictly as a Data Processor regarding personal data uploaded by our Customers about third parties (such as property unit owners, tenants, and residents). If you are a resident or unit owner, any requests regarding your personal data rights must be directed to your property management company/JMB/MC.

2. Personal Data We Collect

We collect and process the following categories of data for distinct business purposes:

Data CategoryWhat It IncludesPurpose of Processing
Account DataFull name, work email address, phone numberAccount creation, authentication, and secure login
Company DataCompany name, SSM registration number, office address, corporate contact detailsSetting up your organization profiles in PropOS
Team Member DataFull name, email, phone number, job role of invited staffFacilitating platform collaboration features
Property DataProperty name, physical address, strata title number, unit details, developer infoCore property management platform operations
Resident / Unit DataUnit owner/tenant name, contact details imported via onboarding templatesProcessing WhatsApp routing, correspondence drafting, and compliance logs on your instructions
Usage Data & LogsPages visited, features used, timestamps, API errors, anonymized IP addresses (last octet removed)Product optimization, system diagnostic monitoring, and security auditing
Communication LogsInbound and outbound WhatsApp message metadata, sender numbers, and prompt historiesOperating the PropOS AI features and WhatsApp Hub routing logs
Payment DataBilling plan selected, corporate payment statusHandled securely via our third-party payment gateways (Billplz / Stripe). We do not store raw card numbers.

3. Legal Basis for Processing

We process personal data based on one or more of the following lawful grounds under the PDPA:

  • Consent: Your explicit agreement to this notice upon account registration.
  • Contractual Necessity: Processing required to fulfill our software subscription agreement with your organization.
  • Legitimate Interests: Operations necessary for system security monitoring, fraud prevention, platform optimization, and error diagnostics.
  • Statutory Compliance: Meeting legal and regulatory obligations under Malaysian law, including the Strata Management Act 2013 (Act 757).

4. Cross-Border Data Transfers and Third-Party Processors

To provide a globally resilient, AI-driven SaaS platform, we utilize specialized third-party infrastructure. Some of these cloud platforms host data outside of Malaysia. By using the platform, you acknowledge and explicitly consent to the transfer and processing of data to the following locations:

Service ProviderFunction within PropOSData LocationCompliance Standard
Supabase (PostgreSQL)Primary database and authenticationSingapore (AWS ap-southeast-1, ASEAN)SOC 2 Type II, ISO 27001
VercelFrontend web application hostingGlobal CDN / USASOC 2 Type II
RailwayBackend API infrastructure engineUSASOC 2 Type II
Anthropic (Claude API)Gen-AI compliance & drafting processingUSAData Processing Addendum (Enterprise)
Meta Platforms (WhatsApp Cloud API)WhatsApp Business messagingUSA / GlobalMeta Data Processing Terms, GDPR Compliant
BillplzLocal ringgit payment clearingMalaysiaBank Negara Malaysia Compliant
StripeInternational payment processingUSAPCI-DSS Level 1

All external processors are bound by strict data processing agreements matching the standards established under the PDPA (Amendment) Act 2024.

5. Data Retention

We retain data only as long as necessary to fulfill corporate service needs or legal duties:

  • Account, Company & Team Data: Maintained for the duration of your active subscription + 30 calendar days following account deletion.
  • System Error Logs: Automatically purged on a rolling 90-day cycle.
  • WhatsApp Transmission Logs: Retained for 12 months from the message metadata date.
  • AI Compliance Query History: Kept for the duration of the active business subscription.
  • Financial & Payment Records: Retained for 7 years to comply with Malaysian statutory tax and accounting regulations.

6. Your Rights Under the PDPA 2010

Where we act as a Data User, you possess the following statutory rights under Act 709:

  • Right of Access: Request a copy of the direct account personal data we hold about you.
  • Right of Correction: Request correction of inaccurate, misleading, or outdated personal data.
  • Right to Withdraw Consent: Terminate our ongoing processing of your data (noting this will require account termination as our platform cannot function without base operational data).
  • Right to Prevent Processing: Restrict processing likely to cause unwarranted distress or object to direct marketing.

To exercise these rights, email our team at hello@propos.my. We will verify your identity and respond within 21 days as mandated by law. You may also delete your account directly from Settings → My Account → Delete Account.

7. Enforced Security Protocols

  • Data Encryption: All system data is encrypted in transit using TLS 1.2+ protocols and protected at rest via AES-256 standard encryption.
  • Access Control Isolation: Enforced Row-Level Security (RLS) at the database layer ensures tenancy separation—staff can only view data tied to their validated organization.
  • Anonymization & Redaction: IP addresses are truncated (last octet removed) prior to log entry, and PII identifiers are automatically filtered out from technical error logs.
  • Credential Enforcement: Implementation of a strict minimum 12-character password policy with optional multi-factor authentication (MFA).

8. Cookies

PropOS utilizes purely technical, first-party functional session cookies (via @supabase/ssr) required to manage secure user authentication states. We do not run marketing, behavioral tracking, or third-party analytics pixels.

9. Policy Modifications

We reserve the right to amend this Privacy Notice to match changing legal standards or platform updates. Users will be alerted via email or an in-app dashboard notification at least 14 days before any material changes go into effect. Emergency regulatory updates may be applied immediately upon notification.

10. Contact and Compliance Authority

For all data protection inquiries, security notifications, or data policy clarifications, contact our designated Data Protection Officer:

If you believe your personal data has been handled in breach of Act 709, you reserve the right to file an official complaint with the Personal Data Protection Commissioner (PDPC) of Malaysia via the official portal at www.pdp.gov.my.