Bersedia
Home

Privacy Policy

Last updated: 2 September 2026

This policy explains what information Bersedia collects, why we collect it, and what you can ask us to do with it. Bersedia is operated by Art Byte Creative Agency (SSM 202503150630, Certificate CT0151075-H), 52-1-C, Jalan Pusat Perniagaan Raja Uda 1, Raja Uda Industrial Estate, 12300 Butterworth, Pulau Pinang, Malaysia.

1. Two kinds of data, two different roles

Bersedia is a business-to-business tool that many companies use to serve their own customers. That creates two clearly different situations, and it matters which one applies:

  • Data we control. Information about the company that subscribes to Bersedia and its staff accounts — company name, admin and agent names, email addresses, language preference, roles, plan and billing records. For this data we are the data controller and this policy governs it directly.
  • Data we only process. Everything your company puts into tickets, including personal data belonging to your end customers submitted through your external portal — names, contact details, order or account references, complaint details, attachments and message content. For this data your company is the data user (controller) and Bersedia acts purely as a data processor on your instructions. We do not decide what is collected, we do not use it for our own purposes, and we do not mine it for marketing or product analytics.

Because of this B2B2C arrangement, your company remains responsible for having a lawful basis and its own privacy notice for the customer data it brings into Bersedia, for telling its customers that a third-party ticketing system is used, and for handling requests those customers make about their data. We will assist you with any such request in good faith, but we cannot answer them on your behalf.

2. What we collect

  • Company information: company name, portal settings, departments, plan tier, billing interval, subscription status and renewal dates.
  • Staff and user accounts: name, email address, password credentials handled by our authentication provider (we never see plain passwords), role assignments per department, invitation records and language preference.
  • Ticket content: ticket titles, descriptions, priority, status, department, assignment history, public replies and internal notes, plus the timestamps around them.
  • Customer requester data via the external portal: whatever the requester or your staff enters — typically a name, email address and the details of the request.
  • Payment data: handled by our payment gateway, CHIP (Malaysia). We store only a purchase reference, amount, plan and payment status. We never receive or store full card numbers.
  • Technical logs: limited server and error logs (such as IP address, timestamp and error details) used to keep the service running securely.

3. How we use it

  • To provide the service: creating, routing, displaying and updating tickets.
  • To authenticate users and enforce role-based access and plan limits.
  • To process subscription payments and issue receipts.
  • To provide support when a company admin contacts us, and to investigate faults, abuse or security incidents.
  • To send necessary service messages (billing, security, material changes to the service).

We do not use ticket content to train machine-learning models, and we do not use it to contact your customers.

4. We do not sell your data

Bersedia does not sell, rent or trade personal data to third parties, ever. We share data only with the service providers needed to run the product, and only to the extent required:

  • Supabase — database, authentication and file storage (our hosting and infrastructure provider).
  • CHIP — payment processing for subscription upgrades.
  • Email delivery provider — sending account, invitation and billing emails.

These providers act as our sub-processors under confidentiality obligations. We may also disclose data where required by Malaysian law or a valid legal order.

5. Where data is stored

Application data is stored in managed Supabase infrastructure on cloud servers that may be located outside Malaysia, including in Singapore and other regions operated by Supabase and its underlying cloud providers. Data is encrypted in transit and at rest. Access within Bersedia is limited to the personnel who need it to operate and support the service, and every company's data is isolated from every other company's by row-level access rules tied to the signed-in user's company.

6. Retention

  • Ticket and account data is kept for as long as your company keeps an active Bersedia account, because closed tickets are your operational history.
  • After an account is cancelled or closed, data is retained for up to 60 days so it can be restored or exported, then deleted or irreversibly anonymised.
  • Billing and transaction records are kept for up to 7 years where Malaysian tax and accounting rules require it.
  • Backups roll off on their own schedule and are fully purged within 90 days of deletion.

7. Your rights: access, correction, export, deletion

Staff and admins can view and correct their own profile details in the app at any time. Company admins can manage departments, people and portal settings directly. In addition, you may ask us to:

  • Export your company's tickets, messages and account records in a machine-readable format (CSV or JSON).
  • Correct inaccurate account information.
  • Delete your company account and its data. Deletion is permanent and cannot be undone once the 60-day window has passed.
  • Restrict or withdraw consent for non-essential processing, understanding that some processing is required to provide the service at all.

Email support@bersedia.com and we will respond within 21 days. If you are an end customer of a company that uses Bersedia, please contact that company first — they control your data and we will refer your request to them.

8. Security and breach notification

We use encrypted connections, hashed credentials, per-company access rules and least privilege access internally. No system is perfectly secure, so if a breach affects your data we will notify affected company admins without undue delay, describe what happened and what we are doing about it.

9. Children

Bersedia is a workplace tool and is not intended for anyone under 18. We do not knowingly collect data from children.

10. Changes to this policy

We may update this policy as the product changes. Material changes will be announced in the app or by email to company admins at least 14 days before they take effect. The date at the top of this page always reflects the current version.

11. Contact us

Art Byte Creative Agency (SSM 202503150630, Certificate CT0151075-H)
52-1-C, Jalan Pusat Perniagaan Raja Uda 1, Raja Uda Industrial Estate, 12300 Butterworth, Pulau Pinang, Malaysia
support@bersedia.com

Note for the Bersedia team: support@bersedia.com is a placeholder. Confirm that this inbox exists and is monitored, or replace it everywhere on this page, before going live — a privacy contact address that bounces is a compliance problem.

This policy is governed by the laws of Malaysia, including the Personal Data Protection Act 2010.