Who is responsible
Kipas is operated by OnlyKipas Sdn Bhd (business registration 1582122-V).
The business controls the customer and team records in its workspace, whether its team entered them or a customer submitted them through the business's public pages. Kipas processes those records to provide and protect the service.
What we collect
- Business application details, including the business and contact names, email address, WhatsApp number, area, team size, operating stage, optional notes, the application reference, and an optional SSM document sent by replying to the confirmation email. Kipas stores correspondence metadata in the application queue. The message and attachment are forwarded to the Kipas support inbox; the application queue does not store the message body or file.
- Business details, including SSM or BRN, TIN, SST registration, MSIC code, locations, branding, and service settings.
- Owner and staff account details, roles, branch access, schedules, and security audit activity.
- Attendance events, approved network evidence, device information, and selfie evidence captured during clock-in or clock-out.
- Customer details held by the business, including names, phone numbers, email addresses and email consent choices, optional e-invoice identifiers (TIN, NRIC or passport number), bookings, group session places, packages, memberships, vouchers, and service history.
- Details a customer submits through the business's public booking page or customer portal: name, phone number, an optional email address with its consent tick, notes, and requests to book, confirm, cancel, or reschedule.
- Sales and operational records, including receipts, tenders, refunds, voids, commissions, cash closings, and booking requests.
- Technical and security data such as IP addresses, browser details, timestamps, rate-limit events, and application logs. Public booking submissions record the sender's IP address so abuse limits work.
- If a business owner enables optional AI assistance after Kipas makes it available, the selected Guide passages, business-record excerpts, or private preview files needed for that request. Kipas records bounded usage, cost, route, safety, and deletion metadata. Its AI control tables do not store the prompt or answer.
Why we use it
- To review a business application, contact the applicant, and create a workspace only after a platform administrator approves the application.
- To run the business workspace: bookings, group sessions, jobs, checkout, attendance, customer care, reports, and closing. The workspace adapts to the business type the owner chose; the data handling rules are the same for every type.
- To send messages the business has switched on, such as appointment reminders, booking outcomes, receipts, and job-ready alerts, and, only with the customer's ticked consent, occasional birthday or offer emails. Every customer email carries an unsubscribe link, and unsubscribing stops all customer email to that address.
- To keep tenants separate, enforce roles, investigate fraud or misuse, and maintain an audit trail.
- To provide support, recover accounts, improve reliability, and communicate service changes.
- To provide optional read-only AI explanations, summaries, drafts, and previews after the business owner opts in. AI output is a suggestion for a person to review and cannot change a record, send a message, or take payment.
- To meet accounting, tax, employment, and other Malaysian legal obligations that apply to the business or Kipas.
Who helps us process it
We use a small number of service providers to operate Kipas:
- A managed database and authentication provider, for application data, sign-in, and private file storage.
- A cloud hosting provider, for running the application and its operational logs.
- WhatsApp / Meta when a business user chooses to open a prepared WhatsApp message, such as a booking reply, a job-ready alert, or a customer portal link. Kipas does not claim that a message was received or read.
- An email delivery provider, for application confirmations, account email (such as password recovery), and customer email the business has switched on: reminders, booking outcomes, receipts, purchase summaries, job-ready alerts, and consented birthday or offer emails. Sending is capped per workspace each month, and Kipas can pause a workspace's sending if something looks wrong.
- OpenRouter and the exact model provider selected for a request, only if optional AI assistance is made available and the business owner enables it. Kipas approves providers and exact endpoints separately, requires zero-data-retention and data-collection-denied routing, and does not allow a zero-cost model route to receive person-linked or restricted work.
These providers may process data outside Malaysia under their own safeguards. We do not sell customer or staff data.
Kipas sets one platform-wide policy for whether customer-facing emails, prepared WhatsApp messages, and receipt documents show a small "Powered by Kipas" line that links to our website. Where shown, it names the software behind the page; it does not add any sharing of the customer's data beyond running the service.
How long we keep it
- Business applications remain while they are new, under review, or being provisioned. We clear their IP address after 30 days, delete converted applications after 90 days, and delete rejected applications after 180 days. The platform review queue applies this cleanup and records an audit entry.
- Attendance selfie files are scheduled for deletion after 45 days; the attendance event and its audit record remain.
- Business, customer, sales, and accounting records remain while the workspace is active and for any period required for support, disputes, tax, or Malaysian law.
- Security logs, backups, rate-limit evidence, the IP addresses on public booking submissions, and expired portal or confirmation tokens are kept only for reasonable operational and recovery periods.
- The public demo workspaces hold fictional data and reset on a daily schedule. Anything typed into a demo is demo data and is cleared by that reset; do not enter real personal information there.
- AI prompts and answers are not stored in the AI control tables. Claimed AI preview files are scheduled for deletion after the attempt, with a retention job that retries failed deletion. AI run and access metadata is kept for 90 days, monthly aggregate usage for 12 months, and synthetic model-qualification evidence for 180 days.
When a business leaves, we will agree an export and deletion timetable, subject to records we must retain by law or to resolve a live dispute.
Your choices and requests
Business owners, team members, and customers can ask to access or correct their personal data, withdraw consent where consent is the basis, or request deletion where retention is not legally required. Customers should normally contact the business first because the business controls their record.
A customer can stop marketing-class email at any time using the unsubscribe link in any such message. A business can remove a customer's identity from its workspace using the built-in Anonymize customer tool, which clears contact, tax, booking, queue, portal, and service-profile identity data while keeping the underlying receipts and appointments as business records.
A customer portal link is private to the person who holds it. It shows that customer's own upcoming appointments, packages, memberships, and vouchers, and lets them ask the business to cancel or reschedule a one-to-one appointment. A shared group session appears read-only and never reveals who else is attending.
A business owner can keep optional AI assistance off, turn it off later, and control restricted-data assistance separately. Turning it off stops new provider requests and does not remove the business's ordinary records.
For a data request or privacy question, email hi@onlykipas.com. Include the business name and enough detail for us to verify the request without sending unnecessary personal data.
Security and changes
Kipas uses tenant isolation, role checks, encrypted transport, private storage, audit logs, and bounded public endpoints. No online system is risk-free. Businesses must protect their accounts and tell us promptly about suspicious access.
We will update this notice when the service or legal requirements materially change.