Who we are
NexFlows is a brand of Dialify Technologies, a company registered in Malaysia (SSM 202503197904 (003754718-A)). Our address is VO1-12-16 Office Tower, Sunway Velocity, Jalan Peel, Maluri, 55100 Kuala Lumpur. We build custom CRMs, apps, websites and WhatsApp setups for businesses, and we sell a ready-made Loan Advisory CRM.
Our customers are loan advisory firms, collections agencies and other small and medium businesses. They use NexFlows to keep records of their own customers and to contact them by phone and WhatsApp. This page explains how personal data is handled in that work, and on this website.
The person responsible for data protection at NexFlows is Jayden, founder of NexFlows. You can write to him at [email protected].
Whose data we hold
We hold two kinds of personal data.
- People who work at our customers. The staff who sign in to NexFlows: their name, work email, phone number, and what they do in the system.
- Our customers' own customers and contacts. The records a customer keeps: names, identification numbers, phone numbers, addresses, account balances, and notes of calls and messages. This can include documents and credit reports that the customer's staff upload to a person's file. Where a customer uses the multi-line dialer, calls are recorded so that its staff can play them back.
For the second kind, our customer decides what is collected and why. That makes the customer the data controller, and NexFlows the processor: we handle those records on the customer's instructions.
This website
Browsing. The pages of nexflows.ai use no analytics, no advertising tools and no tracking scripts, and they load no scripts or fonts from other companies. Like any website, our server, and Cloudflare in front of it, can see your internet address and the page you asked for, so that the page can be delivered.
Cookies. The public pages set no cookies. Cookies appear only when someone signs in to the NexFlows app: one that keeps them signed in, which lasts up to 14 days or until they sign out, and short ones, lasting 10 minutes, used while a signed-in person connects a Google or Facebook account. All of these are strictly necessary for the app to work. We do not use cookies for tracking or advertising.
The contact form. If you use the form, we ask for your name and phone number and, if you wish, your company, your email and a message. We use these only to reply to you. The form sends them to us as an email, through our email provider, Resend, and the email sits in our inbox like any other message.
WhatsApp and email. If you message us on WhatsApp, WhatsApp (Meta) handles the message under its own policy, and we see your number and what you write. If you email us, we see your email address and your message.
The credit report analyzer. The analyzer on our homepage reads a credit report inside your own browser. The file is not uploaded to us or to anyone else, and you can check this yourself. That applies to the public website only. Inside the Loan Advisory CRM, when a customer's staff upload a credit report for a person, it is read on our servers and kept in that customer's account.
WhatsApp messaging
Some customers send and receive WhatsApp messages through NexFlows, usually using the WhatsApp Business Platform provided by Meta. When you message such a business, or it messages you, the message content, your WhatsApp phone number and the delivery status are stored in that customer's NexFlows account, so that its staff can reply and keep a record.
Messages to you outside a 24-hour reply window use templates approved by Meta. You can ask the business to stop messaging you at any time by replying to say so, and the business must then stop. Where the business has marked you as do-not-message in NexFlows, the system blocks reminder and campaign messages to you. It is the business that decides what to send, so requests about its messages are best sent to the business.
How the data is used
Only to provide the service: showing records to authorised staff, sending the messages they write, keeping an audit record of who did what, and producing the reports and printouts the business needs.
We do not sell personal data. We do not use it for advertising. We do not use customers' records to train AI models. We share it only with the providers listed below.
AI features
Some features can use an AI model, for example to suggest or write a reply in a WhatsApp conversation. Where a customer switches one on, the text that feature needs, such as the conversation and the details of the lead, is sent to an AI model provider, and the answer is sent back. The provider our software is built to use is Anthropic, with OpenAI as an optional backup.
Who else handles the data
These providers handle data for us. Each one does only its part of the service.
- Hostinger hosts our web servers, our databases and the servers that run WhatsApp and calling. The servers are in Kuala Lumpur, Malaysia.
- Cloudflare looks after our domain name and passes web traffic to our servers.
- Meta delivers WhatsApp messages for customers who use the WhatsApp Business Platform.
- Amazon Web Services stores the documents and credit reports that customers upload, in a private storage bucket.
- Resend sends emails for us, such as sign-in invitations and password resets, and delivers contact form messages to us.
- Anthropic answers AI requests, as described above. OpenAI is an optional backup.
- Google holds an encrypted copy of our database backups.
If a staff member turns on browser notifications, those notifications travel through the push service of their browser. Some of the providers above work outside Malaysia, so personal data can be processed in other countries. We use these providers only for the purposes in this policy, and we do not sell personal data to any of them.
How long we keep it
We keep a customer's records for as long as it keeps its NexFlows account. After it ends its agreement, we delete its records when it asks us to. Backup copies are replaced on a rolling cycle of about 14 days, so a deleted record can stay in a backup for up to that long.
Messages sent to us through the contact form are kept as email for as long as we need them to deal with your enquiry.
How we protect it
How your data is handled explains each of these in more detail.
- Connections to the site and the app use HTTPS.
- Passwords are stored as one-way hashes, so nobody at NexFlows can read them.
- Staff see only the records their role allows, and a customer's records are kept apart from every other customer's.
- Access tokens for connected services, such as a WhatsApp number, are stored encrypted.
- An audit record keeps track of important actions, and the account owner can remove the access of a person who leaves.
- Uploaded documents sit in a private store and open through links that expire.
No system is perfectly safe. If you think you have found a weakness, email [email protected] with the subject "Security".
If something goes wrong
If personal data we hold is lost, stolen or reached by someone who should not have it, we move to contain it straight away and find out what was affected.
For records we hold for a customer, we tell that customer without delay. The customer is the data controller, so it decides who else to tell and carries the legal duty to do so.
Under Malaysian law (section 12B of the Personal Data Protection Act 2010, added in 2024, and the Commissioner's guideline on breach notification), a data controller tells the Personal Data Protection Commissioner as soon as practicable, and no later than 72 hours, when a breach causes or is likely to cause significant harm. It also tells the people affected, without unnecessary delay. For personal data that NexFlows itself controls, such as staff accounts and website enquiries, we make these notifications where the law requires them.
Your rights and how to ask
Under Malaysia's Personal Data Protection Act 2010 you may ask what personal data is held about you, ask for it to be corrected, and withdraw your consent to its use by notice in writing. Since the 2024 amendments you may also ask a data controller to send your personal data to another controller of your choice, where that is technically possible.
Requests about a business's records of you should go to that business, because it controls those records. That includes a request to delete the records it holds about you. If such a request reaches us instead, we pass it to the business and help it answer. Requests about NexFlows itself, such as website enquiries or staff accounts, can be sent to [email protected] with the subject "Personal data request".
The Act gives 21 days to answer a request for access to data or for correction of data, and we answer within 21 days. If we cannot give a full answer in that time, we tell you why in writing before the 21 days end.
Changes to this policy
If this policy changes, the date at the top is updated and the new version is published at this address.
The law behind this page
- Personal Data Protection Act 2010 (Act 709), reprint of 14 June 2016: sections 31 and 35 on the 21 days, and section 38 on withdrawing consent.
- Personal Data Protection (Amendment) Act 2024 (Act A1727): breach notification (section 12B), data portability (section 43A) and the duties of data processors.
- Personal Data Protection Commissioner, Guideline on Data Breach Notification, version 1.0, 25 February 2025: the 72 hour and 7 day timings, and what counts as significant harm.
Questions about this page? Email [email protected].