white antlysis logo






Privacy Policy – Platform | Antlysis Design Sdn. Bhd.


Platform Privacy Policy

Last Updated: February 2026

1. Introduction & Scope

This Privacy Policy governs the collection, processing, storage, and transfer of data by Antlysis Design Sdn. Bhd. (“Company”, “We”, “Us”, or “Our”) in connection with the Laundro self-service laundry management software, mobile applications, cloud platform, and IoT hardware controllers (collectively, the “System” or “Service”).

This policy complies with the Malaysian Personal Data Protection Act 2010 (PDPA) and acknowledges regional data protection standards where the Service operates.

Regulatory Classification & Roles:

Data Controller: The Company acts as a Data Controller regarding business account information, billing records, and operational access credentials collected directly from commercial subscribers, dealers, and laundry operators.

Data Processor / Data Intermediary: When end-consumers initiate laundry cycles or interact with cashless kiosks, the commercial operator functions as the Data Controller, and the Company acts as a Data Processor carrying out technical activations on the operator’s instructions.

2. Categories of Information We Collect

2.1. Subscriber & Commercial Operator Data

When an operator or business entity subscribes to Laundro, we collect:

  • – Business registration details, registered outlet addresses, and corporate tax information;
  • – Account credentials: administrative names, corporate email addresses, phone numbers, and encrypted passwords;
  • – Financial and payment records: bank payout identifiers, billing contacts, and subscription invoice history.

2.2. IoT Hardware, Diagnostics & Telemetry Data

To ensure system uptime and deliver automated machine activation, our cloud servers process technical signals generated by Laundro IoT controllers:

  • – Hardware identifiers: MAC addresses, IMEI, firmware version, signal strength (RSSI), and IP addresses;
  • – Machine status logs: pulse triggers, cycle run-times, power relay confirmations, error codes, and offline event queues;
  • – Network telemetry: packet latency, connection timestamps, and SIM card telemetry data.

2.3. End-Consumer & Transactional Metadata

When consumers utilize machines connected to the Laundro network, we capture minimal transactional metadata necessary to execute the service:

  • – Digital transaction IDs generated by payment gateways and e-wallets (we do not store raw credit card numbers);
  • – Mobile numbers, if supplied by the consumer for OTP verification, digital receipt generation, or loyalty redemption;
  • – Machine activation timestamps, target machine number, outlet location, and pricing cycle parameters.

3. Purposes of Data Processing

The Company processes collected information for the following legitimate business purposes:

  • Service Fulfillment: Managing subscription access, provisioning IoT controller instances, verifying payments, and executing remote machine triggers;
  • Platform Reliability: Detecting firmware anomalies, resolving machine communication drops, monitoring network congestion, and pushing Over-the-Air (OTA) firmware updates;
  • Security & Fraud Mitigation: Auditing payment gateway callbacks, preventing fraudulent pulse injection, and validating transaction authenticity;
  • Customer Support: Providing second-line and third-line technical assistance to commercial subscribers and authorized field technicians.

4. Operator Responsibilities Regarding End-Consumers

Commercial Operators utilizing the Laundro platform are solely responsible for:

  • – Displaying adequate privacy notices at their retail outlets informing end-consumers of cashless transaction recording, security cameras, or mobile number collection;
  • – Ensuring lawful consent is obtained prior to utilizing end-consumer contact data for marketing or promotional SMS campaigns;
  • – Handling end-consumer inquiries, personal data access requests, or dispute resolutions related to retail laundry services.

5. Third-Party Service Providers & Disclosure

The Company does not sell or lease personal data. Information is disclosed solely to authorized third parties under strict confidentiality terms:

  • Cloud Infrastructure: Managed cloud database, hosting, and container infrastructure providers (e.g., AWS, Cloudflare) responsible for hosting Laundro servers;
  • Payment Processors & Gateway Integrations: Licensed acquiring banks and digital payment providers executing cashless processing;
  • Telecommunications Providers: Cellular IoT network carriers providing cellular data links to Laundro hardware;
  • Regulatory Bodies: Law enforcement or judicial authorities when formally required under Malaysian law or court order.

6. Aggregated Telemetry & Analytics

The Company automatically extracts, cleanses, and anonymizes operational metrics to create non-identifiable “Aggregated Data.” This data includes machine cycle counts, wash-to-dry ratios, peak utilization hours, and hardware error frequencies.

All personally identifiable markers are permanently scrubbed. The Company retains full proprietary rights to Aggregated Data for benchmarking, algorithmic machine learning models, reliability engineering, and industry analysis.

7. Data Security & Storage

We maintain comprehensive technical, physical, and administrative measures to secure platform data:

  • – Communication between IoT controllers, mobile devices, and our cloud API is protected using modern TLS encryption protocols;
  • – Critical database records, including authentication keys and passwords, are encrypted at rest using salted cryptographic algorithms;
  • – Access to production environments is strictly restricted to authorized engineering personnel using multi-factor authentication (MFA).

8. Data Retention

We retain Subscriber and transaction records for the active duration of the platform subscription agreement, and subsequently for a period required to satisfy statutory corporate, tax, and accounting compliance obligations under Malaysian law (typically seven (7) years for transaction logs). Routine machine ping data and raw MQTT logs may be purged on rolling cycles.

9. Cross-Border Transfers

Laundro cloud infrastructure is primarily centralized within data centers in Malaysia and regional secure cloud facilities. When serving international subscribers or processing data across regional nodes (such as Thailand, Taiwan, Brunei, or Brazil), the Company ensures cross-border data protection standards comparable to the PDPA are maintained.

10. Your Rights (PDPA Compliance)

Under the Malaysian Personal Data Protection Act 2010, authorized representatives of our commercial subscribers hold the right to:

  • – Request access to their personal profile data held within the Laundro system;
  • – Request the correction or updating of outdated or inaccurate personal records;
  • – Withdraw consent for optional operational communications (subject to contractual subscription requirements).

To exercise these rights, submit a written inquiry to our compliance team at the contact address below.

11. Amendments & Notifications

The Company reserves the right to revise this Privacy Policy periodically to reflect technological advancements, platform expansions, or regulatory changes. Updated versions will be posted on the management dashboard or notified via email. Continued access to the platform constitutes acceptance of the amended terms.

12. Contact Information

For inquiries, concerns, or data protection matters related to the Laundro platform, please contact:

Antlysis Design Sdn. Bhd.
Attn: Data Protection Officer
Email: [email protected]
Website: https://antlysis.com