Effective date: 29 July 2026. This Security Policy describes how ChatOwl protects your business data and your customers’ data. It forms part of our Terms of Service and works alongside our Privacy Policy and Data Processing Agreement.
1. Payment security
Card and online-banking payments are handled by our PCI-DSS-compliant payment gateway. ChatOwl does not store your full card details on our servers.
2. Encryption in transit
All traffic to and from ChatOwl is encrypted using TLS 1.3 (HTTPS) end-to-end.
3. Hosting and data at rest
ChatOwl runs on reputable cloud infrastructure hosted in the Singapore region, with provider-side disk encryption. We keep regular off-site backups, transferred over encrypted connections.
4. Access control and tenant isolation
Each client’s data is logically isolated from every other client. Access uses individually revocable, per-client keys and short-lived signed tokens, and is limited to authorized personnel on a need-to-know basis. Secrets and credentials are kept out of our source code.
5. Application safeguards
Our platform applies origin allow-listing, rate limiting, per-client spend caps and circuit breakers, and prompt-injection guardrails to protect the service and your account.
6. Data minimisation and PDPA
We collect only the data needed to run your assistant, apply consent and data-retention / purge controls, and support data export and deletion (right to erasure) on request. For your customers’ personal data we act as your data processor under the Malaysian PDPA 2010, processing it only on your instructions under our Data Processing Agreement.
7. Monitoring
We run automated health monitoring with real-time alerts so issues are detected and addressed quickly.
8. Ongoing improvement
Security is continuous. We architect our controls against recognised frameworks such as the NIST Cybersecurity Framework and OWASP guidelines, and keep strengthening our posture as we grow.
9. Reporting a security issue
If you believe you have found a security vulnerability, please email hello@chatowl.my. We investigate reports promptly and, in the event of a personal-data breach, follow our internal breach-response procedure and PDPA obligations, including notifying affected clients where required.
10. Your responsibilities
Please keep your ChatOwl access link and credentials secure and limit them to people you trust. Notify us immediately if you suspect any unauthorised access.
11. Contact
hello@chatowl.my · 011-1205 2265 · C2-37-02, Arte Cheras, Taman Midah, Cheras, 56000 Kuala Lumpur, Wilayah Persekutuan. Data-protection contact: Lee Hao Ying (owner).