Legal & Compliance
Trust Center
A central overview of MumuWorks security, privacy, AI governance, infrastructure practices, compliance posture, and incident handling approach.
Our privacy commitment
Your business data is yours.
Your customer conversations, documents and business knowledge deserve protection. Privacy is a core commitment behind how we build MumuWorks.
A private workspace
Your business has its own workspace. Access controls separate your customer records and documents from other businesses and help protect them from public access.
No AI training use
Your data is for running your assistant. Our policy prohibits using it, or sharing it with AI providers, to train general-purpose AI models.
You control team access
Choose who can work in your workspace and what they can access. Permissions help keep customer conversations and business information in the right hands.
Clear about AI processing
AI features send relevant content to service providers to carry out your requests. That processing is subject to provider security and retention terms. Our no-training commitment does not mean zero data retention.
1. Security overview
MumuWorks maintains reasonable technical and organizational safeguards designed to support the confidentiality, integrity, and availability of customer data. Security controls may include encryption in transit, encryption at rest where supported by the environment or provider, secure authentication flows, access controls, and audit logging aligned to operational needs.
2. Privacy overview
MumuWorks documents its data handling approach through customer-facing privacy and compliance notices, including the Privacy Policy, GDPR Notice, and Malaysia PDPA Notice. These materials describe how data is collected, used, disclosed, retained, and protected across the platform.
3. AI governance
MumuWorks is designed to support responsible AI usage through customer-configured prompts, workflow boundaries, channel controls, and human oversight. AI-generated outputs may be reviewed, edited, escalated, or rejected by users before business reliance. Customer-submitted content remains customer-owned, and prompt or output handling is limited to the operational purposes described in applicable customer-facing policies and agreements.
4. Infrastructure
MumuWorks operates as a cloud-hosted SaaS platform with tenant-aware application boundaries, storage services, background job processing, operational monitoring, backups, and disaster-recovery planning appropriate to the service stage and deployment context. Backup and recovery practices are maintained to support restoration after service disruption or data-loss events.
5. Compliance
MumuWorks aligns its public documentation and platform practices with GDPR readiness, Malaysia PDPA compliance, Meta Platform compliance, and WhatsApp Business compliance as relevant to the service features customers enable. MumuWorks does not claim ISO 27001, SOC 2, PCI-DSS, or other certifications unless those certifications are explicitly stated by MumuWorks in writing.
6. Incident response
MumuWorks monitors production systems, investigates suspicious activity, mitigates confirmed issues, and coordinates customer notification where an incident materially affects customer data or service integrity and notification is legally or contractually required. Response activities may include triage, containment, remediation, recovery, and post-incident improvement work.
7. Contact
- Security: [email protected]
- Privacy: [email protected]
- Support: [email protected]