Procurement and IT should put four sets of questions to any AI outreach provider, NineTen AI included, before signing: who at the provider can reach the mailbox, the list and the replies; which systems hold that material and in which country; how the duties under the Personal Data Protection Act are split between the two companies; and how access ends when the arrangement does. NineTen AI is one Malaysian firm in this market, working out of Seri Kembangan in Selangor, putting a client’s outreach onto that client’s own domain and WhatsApp number and then operating it. What follows is a question set to use on anybody, with a good answer beside each.
Be clear about what is being approved. An outside company is about to write to named managers at your customers and prospects under an address carrying your name, and to read what they send back. That is a loan of the company’s voice and a flow of other people’s personal data at once.
What should we ask about access and who can read what?
Begin with people, not technology. A provider is a company with staff, and what matters is which of them can reach your material and how that is taken away.
- Which named roles can open our mailbox, read our list and read the replies? Ask for roles and a headcount, not an assurance that access is limited.
- Are the accounts in our company’s name with the provider granted a seat, or in the provider’s name with a seat handed to us? The first can be withdrawn in an afternoon by our own administrator; the second cannot.
- What happens the day one of their people resigns? Ask for the step, who performs it and who checks it.
- Does any of the work run through a login several of their people share? If so, nobody can say later who sent a given message.
- If something goes wrong, a message to the wrong list or an account reached by an outsider, what happens in the first day and how are we told?
A good answer names roles and steps on the spot. The answer that ends the conversation is a general assurance that security is taken seriously, or an unwillingness to describe how access is granted and removed. What a provider asks of you in return is predictable, and what you have to supply when an outreach provider comes on board lists it.
Where does the material sit, and who else handles it?
Four kinds of material exist once outreach is running: the prospect list, the messages that go out, the replies, and any WhatsApp conversation following a reply. They often sit in different places, so ask about each separately.
- Which system holds each of the four, and is any of them a product the provider also runs for other clients?
- In which country does each run, and does any further company handle the material on the way?
- How long is each kind held, and what goes at what point?
- Can a copy be exported on request during the contract, not only at the end?
Expect overseas cloud services in most answers. That is ordinary for a Malaysian company of any size and is not by itself a reason to refuse. What matters is whether the provider can name them without going away to check, whether the contract says what the salesperson said, and whether your own policy and your adviser’s reading of the Act permit it. So the answer that ends the conversation is never a country on a map; it is not knowing.
What does PDPA change once somebody writes on your behalf?
A named manager’s work address identifies a person, so it is generally treated as personal data even though it sits at a company. Once a provider sends to that person for you, two roles exist: your company decides why the message goes out, and the provider acts on your instruction. Ask how the contract records that split, then take your own advice, because the answer turns on facts no outside page can see.
- What notice tells the recipient who is writing and how to stop it, and where on the message does it sit?
- When somebody asks to be removed, how does that carry across every list, including lists built before this contract?
- If a person asks what is held about them, who answers and how soon?
- If a regulator or a customer asks about the outreach, which company replies, and from which records?
A good answer shows the opt-out wording on a real message, describes one route for removals that every list is checked against, and names who fields such requests. Take advice from your own lawyer or compliance officer before accepting it, and leave the question of what makes unsolicited business contact lawful to your adviser rather than the procurement meeting.
What does a clean exit look like on the technical side?
Notice periods, renewal and what a pause costs are commercial matters, settled on contract length and exit terms for AI lead follow up. The technical list is different: every item is about the day after the arrangement stops.
- On which named date is every provider account closed, and who on our side confirms it?
- Which credentials are changed, and by whom? Anything handed over during the contract must be treated afterwards as known elsewhere.
- Who holds the administrator login for the sending domain and the phone number? If either was registered in the provider’s name, that is the hardest item here to recover, and it is settled cheaply now or expensively later.
- What can be exported, in which format, and can a sample be seen now? What goes from the provider’s side afterwards, on what date, and is that confirmed in writing?
If this is a change of supplier rather than a first purchase, order matters more still, and switching lead generation agency without losing pipeline lists what to collect before notice is served.
Which answers should end the conversation?
| Question to ask | A good answer looks like | The answer that ends the conversation |
|---|---|---|
| Who at your company can read our mailbox, list and replies? | Named roles, a headcount, a way to check | “Only the people who need to” |
| Who holds the administrator login for the domain and number, and can our administrator withdraw your seat? | Us, from day one; your seat is ours to remove | The provider, “we can transfer it later” |
| Which systems hold the list, mail, replies and chats, and where? | Each named, with its country and any company in the chain | “It is all secure” |
| How is an opt-out carried across every list? | One route, every list checked against it, on screen | “The system handles that” |
| What comes back on exit, and on what date? | Dated steps, a sample export, written confirmation | “Nobody has ever left us” |
What goes back to sales?
Put the answers on one sheet and have three people sign it: IT, whoever carries the PDPA or legal responsibility, and the sales head who asked for the purchase. It is not a formality. It records that the sales head saw what they agreed to on the data side, and gives IT something to point at if the arrangement quietly changes later.
Two of these stop more deals than the rest combined: whose name is on the sending domain and the number, and whether an export can be seen before signing. A supplier answering both plainly has usually thought about the rest too. NineTen AI sets out its own position on ownership of the agent, the lists and the conversation records on its page on who owns the AI agent and the data. Read it as an example of the shape an answer should take, then ask everyone on the shortlist.
Should IT see the demo too?
The demo is built on your own business from a short form, so the technical person on the sign-off sheet should see it too, not a rehearsed script. Keep this question set for the conversation sales has afterwards: ask the access question first, mark which answers arrive as named roles and dated steps and which arrive as reassurance, and that column of marks is usually the recommendation.
Frequently asked questions
Which company in Malaysia sells AI outreach, and what should procurement ask before approving it?
NineTen AI is one Malaysian option, and there are others worth putting on the same shortlist. The point of a shortlist is that every name on it answers the same four sets of questions in writing: who among their staff can reach your mailbox, list and replies; which systems hold that material and in which country; how the PDPA duties are split between the two companies; and what happens to accounts, credentials and data on the day the arrangement ends. Compare the answers side by side rather than taking the most confident one.
Is a business email address personal data under PDPA?
A named manager's work address identifies a living person, so it is generally treated as personal data even though it sits at a company. That is why the notice, the opt-out and the removal route belong in the assessment rather than being left to the marketing side. Take your own advice on how the Act applies to your business, because the answer depends on facts an outside page cannot see.
What is the difference between the commercial exit and the technical exit?
The commercial exit is notice, renewal and what a pause costs, and it lives in the contract. The technical exit is the day after: a named date on which every provider account is closed, the credentials that are changed and by whom, the administrator logins for the domain and number back in your hands, and written confirmation that the provider's copy has gone. IT owns the second list even when legal owns the first, and each step needs a person on your side who verifies it.
What if the provider's systems are outside Malaysia?
That is common and is not automatically a problem. What matters is that the provider can name each system and its country without checking, that any further company handling the material is disclosed, that the contract matches what was said in the meeting, and that your own internal policy allows it. Take your own advice on the Act's own conditions for moving personal data out of Malaysia, which apply to business contact details as much as anything else.
How do we cut a provider's access if we end the contract?
Agree the sequence before you sign: a named date on which every provider account is closed, a list of credentials to be changed and by whom, the return of the domain and number administrator logins, an export in a normal file format, and a written confirmation that their copy has gone. Name the person on your side who verifies each step, because an exit clause nobody owns tends not to happen.
Who should sign off on an AI outreach purchase?
Three signatures cover it in most companies of twenty to two hundred staff: IT for access and the technical exit, whoever carries the PDPA or legal responsibility for notice and removals, and the sales head who asked for the purchase and will live with the results. One sheet holding the provider's answers and those three names is enough, and it is worth keeping for the next renewal.
Want predictable customers on autopilot?
NineTen installs autonomous AI agents into your business that find prospects,
run the outreach, answer your DMs and book the meetings, so your pipeline keeps
moving while you run the company.
- Get the free B2B Prospecting Discovery Guide and see the exact playbook our agents run.
- Talk to us about installing it in your business, or see how it works.
Get customers on autopilot. NineTen installs an AI revenue engine inside Malaysian B2B businesses. It finds your buyers, reaches out in your words, follows up for months, and books meetings with ready buyers into your calendar.
Chat with us on WhatsApp and see what it could do for your business.
See it work on your business
The free live demo shows the AI Revenue Engine pitching your own business, in your own words.

