Privacy Policy
G6 Labs Asia Sdn. Bhd. (Company No. 1667152-K) · GSendr platform · Last updated 27 August 2026
This policy explains how G6 Labs Asia Sdn. Bhd. (“G6 Labs”, “we”) handles personal data in connection with the GSendr platform and the gsendr.com website. It forms part of the Terms & Conditions under clause 13.8, and clause 13 of those Terms prevails if the two ever conflict.
1. Our role: controller and processor
Two different relationships sit side by side, and the distinction matters.
- We are the controller of your own account data: the details of the organisation and the people who use GSendr, billing records, support correspondence, and website usage data.
- We are the processor of the recipient personal data you upload and send through the platform. For that data you are the controller. We process it only on your documented instructions and only to provide the Service.
2. Information we collect
- Account information you provide when you register or apply, such as your name, business name, business registration details, email address and phone number.
- Billing information. Card payments are processed by our payment gateway using a tokenised payment method. We do not receive or store full card numbers. We keep invoices, transaction references and payment status.
- Campaign content you upload or create: recipient lists, WhatsApp and email templates, HTML-to-PDF templates, images, attachments, merge data and scheduling details.
- Recipient personal data contained in the lists you upload, and the WhatsApp conversations and email correspondence that follow.
- Usage and technical data, such as log files, IP address, device and browser information, and how you interact with the platform.
- Website data collected on gsendr.com, described in section 5.
3. How we use information
- To provide, operate and maintain the Service, including sending your campaigns through the official Meta WhatsApp Cloud API and through email.
- To process replies to your WhatsApp campaigns and present them in your shared inbox. Email replies are not collected in that inbox.
- To take payment, issue invoices, apply credits to your balance, and settle message charges with Meta where you have asked us to do so.
- To communicate with you about your account, support requests, security notices and product changes.
- To improve, secure and troubleshoot the Service, investigate abuse or a complaint, and comply with legal obligations.
We do not sell personal data, and we do not use the recipient data you upload for our own marketing or to build our own contact lists.
4. Recipient data and your responsibilities
You are responsible for the recipient data you upload and for having valid opt-in consent to message every person on your list, in compliance with the Personal Data Protection Act 2010 and Meta’s policies. Clause 12 of the Terms sets this out in full.
We do not source, supply, verify or vet recipient data. Purchased, rented, scraped or harvested lists must not be uploaded. You must honour opt-out requests promptly and keep records evidencing consent, and produce them within five business days where Meta, the Personal Data Protection Commissioner or another regulator requires them.
Conversations and email correspondence are logged. We do not routinely monitor their content, but may access it where necessary to provide support, investigate abuse or a complaint, protect the platform, or comply with a legal obligation.
5. Cookies and website analytics
gsendr.com sets the following categories of cookie and similar technology:
- Strictly necessary — session, cart, checkout and login cookies set by WordPress and WooCommerce so the shop and your account work. These cannot be switched off without breaking the site.
- Analytics — we use Google Analytics 4, added through the Google Site Kit plugin, to understand how the site is used. It records pages viewed, approximate location derived from IP address, device and browser, and events such as a form submission or a checkout step. Google acts as our analytics provider and processes this data on servers outside Malaysia.
- Form submissions — the contact form records what you type into it, together with your IP address and timestamp, so we can reply and detect abuse.
You can block or delete cookies through your browser settings, and you can opt out of Google Analytics using Google’s browser add-on. Blocking strictly necessary cookies will prevent the shop and account areas from working.
6. Sharing and sub-processors
We share data only as needed to run the Service:
- Meta Platforms — WhatsApp messages, templates and the phone numbers you send to are transmitted to Meta through the official WhatsApp Cloud API. Meta processes them under its own terms and policies, which we do not control.
- Sub-processors for hosting, email delivery, AI processing and payment handling. A current list is available on request. We remain responsible for their performance of the processing entrusted to them.
- Professional advisers, regulators and law enforcement, where we are legally required to disclose or where disclosure is necessary to establish or defend a legal claim.
- A successor in the event of a merger, acquisition or sale of assets, subject to this policy.
Where you fund WhatsApp credits by manual top-up or automatic card deduction, we settle the corresponding message charges with Meta on your behalf. Where you register your own payment method with Meta, Meta bills you directly and that relationship is between you and Meta.
7. International transfers
Some processing takes place outside Malaysia, including by Meta, our analytics provider and certain sub-processors. Where personal data is transferred out of Malaysia we apply the safeguards required by the cross-border transfer requirements of the PDPA.
8. Retention
We retain account and campaign data for as long as your account is active or as needed to provide the Service.
On termination, your data is retained for 30 days and then deleted, except where we are required by law to keep it longer. You can request an export within that window.
Where an account is suspended for non-payment, account data is retained for 30 days after suspension and may then be deleted. Invoices, transaction records and other accounting documents are kept for the periods required by Malaysian tax and company law.
9. Security
We comply with the Security Principle under section 9 of the PDPA and with the direct obligations imposed on data processors by the Personal Data Protection (Amendment) Act 2024. We use administrative, technical and organisational measures designed to protect personal data, including tokenised payment handling, access controls and encrypted transport.
No method of transmission or storage is completely secure, and we cannot guarantee absolute security.
10. Data breach notification
On becoming aware of a personal data breach affecting your data, we will notify you without undue delay and give reasonable assistance with your own notification obligations — to the Personal Data Protection Commissioner within 72 hours, and to affected data subjects within seven days, where the breach causes or is likely to cause significant harm.
11. Data protection officer
The PDPA requires a data protection officer to be appointed where the Act so provides. Where that requirement applies to us we will appoint one and notify the Commissioner. The same requirement may apply to you in respect of the recipient data you control, and meeting it is your responsibility. Data protection questions can be sent to the contact address below.
12. Your rights
Subject to the PDPA, you may request access to the personal data we hold about you, ask us to correct it if it is inaccurate, withdraw consent, or ask us to limit how we process it. Write to the address below and we will respond within the period the Act allows. We may need to verify your identity first.
If you are a recipient of a message sent through GSendr and want your data accessed, corrected or removed, contact the business that messaged you. They are the controller of that data. If you contact us instead, we will pass your request on to them.
You may also complain to the Personal Data Protection Commissioner, Malaysia.
13. Children
GSendr is a business tool and is not directed at children. We do not knowingly collect personal data from anyone under 18. If you believe a child’s data has reached us, contact us and we will delete it.
14. Changes to this policy
We may update this policy from time to time. Material changes will be posted here with an updated date, and where the Terms require it we will give notice before the change takes effect.
Contact us
For any privacy or data protection question, including a request to exercise your rights or a copy of our current sub-processor list, email sales@g6labs.asia. For billing records, email accounts@g6labs.asia. Or write to G6 Labs Asia Sdn. Bhd., E-05-02, Second Floor, Garden Shoppe @ One City, Jalan USJ 25/1C, 47650 Subang Jaya, Selangor, Malaysia.