Legal & Compliance
Privacy Policy
How MumuWorks collects, uses, shares, retains, and protects personal data across its AI, automation, and WhatsApp workflows.
Our privacy commitment
Your business data is yours.
Your customer conversations, documents and business knowledge deserve protection. Privacy is a core commitment behind how we build MumuWorks.
A private workspace
Your business has its own workspace. Access controls separate your customer records and documents from other businesses and help protect them from public access.
No AI training use
Your data is for running your assistant. Our policy prohibits using it, or sharing it with AI providers, to train general-purpose AI models.
You control team access
Choose who can work in your workspace and what they can access. Permissions help keep customer conversations and business information in the right hands.
Clear about AI processing
AI features send relevant content to service providers to carry out your requests. That processing is subject to provider security and retention terms. Our no-training commitment does not mean zero data retention.
Google Calendar data
Google Calendar is an optional integration. MumuWorks accesses Google Calendar data only after an authorized workspace user chooses to connect an account and grants permission through Google.
- Data accessed: calendar names, identifiers, and access roles so the user can choose calendars; and limited event information such as event identifiers, status, availability times, transparency, and synchronization metadata. MumuWorks does not request or display the titles or descriptions of external events.
- How data is used: to check availability, prevent double-booking, detect scheduling conflicts, and create, update, or remove MumuWorks appointment and travel events in the writable calendar selected by the user.
- Storage and protection: access and refresh tokens and notification tokens are encrypted at rest. MumuWorks stores selected calendar identifiers and labels, MumuWorks-generated event identifiers, and synchronization metadata only as needed to operate and secure the integration. Access is isolated to the authorizing workspace.
- Sharing and training: Google Calendar data is not sold, used for advertising, or used to train general-purpose AI models. It is disclosed only to service providers acting on our behalf when necessary to operate, secure, and support the integration, or when disclosure is legally required.
- Retention and user control: integration records are retained while needed to provide the connected service, protect its integrity, meet legal obligations, or resolve disputes. Users can stop future access by disconnecting calendars in Booking settings or revoke MumuWorks access from their Google Account. They may request deletion of retained account or integration data through Contact & Data Requests, subject to the retention terms in this policy.
MumuWorks’ use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
1. Scope and role
This Privacy Policy explains how MumuWorks collects, uses, discloses, stores, and protects personal data when you visit mumuworks.com, create an account, connect a messaging channel, upload business materials, submit customer information, or use any MumuWorks AI, automation, knowledge base, WhatsApp, workflow, or support feature.
In many cases, MumuWorks acts as a service provider or processor on behalf of customers that use the platform to manage their own business contacts, leads, customers, conversations, and documents. Those customers control the business purposes for that data and remain responsible for having a lawful basis to collect and use it.
2. Data we collect
Account and business data
- User account information such as name, email address, login credentials, role, and preferred language.
- Business information such as company name, billing details, subscription metadata, support history, and onboarding records.
- Customer information entered by users, including contact details, notes, lead data, quotations, or workflow inputs.
Operational and content data
- WhatsApp conversation data, message metadata, webhook events, phone-number identifiers, and handover status.
- Uploaded documents, knowledge base files, prompts, generated drafts, workflow instructions, and other content submitted for processing.
- Usage analytics, device information, cookies, browser attributes, IP addresses, and application log data.
3. How we use data
MumuWorks may use personal data to operate and improve the service, provision tenant accounts, authenticate users, process AI and automation requests, support customers, monitor security, calculate billing, prevent abuse, investigate incidents, enforce our terms, and comply with legal obligations.
- Service operation, tenant setup, product delivery, feature configuration, and workflow execution.
- AI processing, retrieval, summarization, drafting, and other customer-requested automation tasks.
- Customer support, rollout guidance, incident response, quality assurance, and product improvements.
- Security monitoring, fraud prevention, logging, backup management, and legal compliance.
4. Data sharing and disclosures
We do not sell personal data. We share data only as needed to deliver the service, process customer instructions, protect the platform, collect payment, or meet legal requirements. Depending on the feature used, this may include OpenAI, Meta Platforms, cloud hosting and storage providers, payment providers such as HitPay, and analytics or monitoring providers that we enable for service operation.
We may also disclose data to professional advisers, auditors, or competent authorities when required by law, regulation, court order, or a good-faith belief that disclosure is necessary to protect rights, safety, property, or the integrity of the service.
5. WhatsApp and Meta Platform Data
MumuWorks accesses WhatsApp and Meta platform data only after a customer authorizes the relevant connection and configures the integration for its tenant. WhatsApp messages are processed solely to provide automation, inbox, handover, analytics, and AI features requested by that customer.
- MumuWorks does not sell WhatsApp data.
- Customers remain the owners of their WhatsApp conversation data and business content.
- Data handling is intended to comply with the Meta Platform Terms and WhatsApp Business Terms.
- Customers are responsible for giving notices, obtaining permissions, and configuring lawful use of their connected channels.
6. AI processing
User content may be sent to AI providers in order to generate responses, summaries, embeddings, suggestions, drafts, or workflow outputs. That content can include prompts, knowledge-base excerpts, uploaded materials, customer messages, and other data necessary to execute the requested feature.
- AI-generated responses may contain inaccuracies, omissions, or outdated information.
- Users must verify important information before acting on it.
- Customers remain responsible for final decisions, actions, notices, approvals, and communications.
- AI output should not be treated as legal, medical, financial, or other professional advice.
7. Data retention
Customer content that a workspace user deletes is normally placed in Trash for a 30-day recovery period. At the end of that period, it is permanently deleted from the live application and associated managed object storage. An authorized user may permanently delete it sooner. Active customer history is not deleted merely because it is old.
We retain account, billing, operational, audit, security, usage, and support information for as long as needed to provide and protect the service, maintain required records, resolve disputes, enforce agreements, or comply with legal obligations. Account closure and verified legal deletion requests may follow a separate process where required. Backup copies expire through the applicable backup-rotation schedule rather than being synchronously removed from every backup.
8. Security measures
We implement reasonable administrative, technical, and organizational safeguards designed to protect personal data against unauthorized access, loss, misuse, alteration, or disclosure. These safeguards include encryption in transit, access controls, audit logging, and backup processes appropriate to the service.
- Transport encryption for browser and API traffic.
- Role-based access controls and least-privilege administrative practices.
- Application logging and audit trails for operational visibility and investigation support.
- Backup strategies intended to support business continuity and recovery.
9. International transfers
MumuWorks may process or store data in Malaysia, Singapore, the United States, or other jurisdictions where we or our subprocessors operate. By using the service, customers acknowledge that data may be transferred internationally when necessary to deliver hosting, storage, AI, messaging, or support functions.
Where required, we use contractual, technical, or organizational safeguards that are reasonably designed to protect personal data during cross-border processing.
10. User rights and choices
Subject to applicable law and verification requirements, users may request access to personal data, correction of inaccurate records, export of eligible data, deletion of personal data, or closure of their account. Customers may also manage connected systems, cookies, and certain profile details through account controls.
Requests can be submitted through the Contact & Data Requests page or by emailing [email protected]. We may request additional information to confirm identity and authority before fulfilling a request.
11. Cookies, logs, and minors
We use cookies and similar technologies as described in our Cookie Policy. We also collect log and device information to secure the service, maintain sessions, diagnose errors, and understand feature usage. MumuWorks is intended for business use and is not directed to children.
12. Changes and contact information
We may update this Privacy Policy when our products, laws, or operational practices change. Material updates will be posted on this page with a revised effective date. Continued use of the service after changes take effect constitutes acceptance of the updated policy.
- Privacy Officer: [email protected]
- Support: [email protected]
- General: [email protected]