SkillTrainer AI
Home About Pricing Contact
Sign In
Home About Pricing Contact Sign In

Privacy Policy

SkillTrainer AI Platform — PDPA-Compliant (Malaysia)

PDPA COMPLIANCE STATEMENT

This Privacy Policy is issued in compliance with the Personal Data Protection Act 2010 of Malaysia (“PDPA”). It governs how SkillTrainer AI Sdn Bhd collects, uses, stores, discloses, and protects your Personal Data.

Last Updated: 13 April 2026  |  Version: 1.0

1. Data Controller

SkillTrainer AI Sdn Bhd (“Company”, “we”, “us”, “our”) is the data controller for Personal Data collected through the Platform. We are registered under the laws of Malaysia and are responsible for ensuring compliance with the PDPA.

Company NameSkillTrainer AI Sdn Bhd
Registration No.202601008220 (1670318-M)
Registered AddressNo. 17A Jalan Daya 6, Taman Daya, 52100 Kepong, W.P. Kuala Lumpur
Data Protection Contacthello@skilltrainer.ai
Telephone012-652 2189

2. Personal Data We Collect

2.1 Data You Provide Directly

  • Identity data: full name, username, and profile information;
  • Contact data: email address, telephone number, and mailing address;
  • Account data: login credentials, security questions, and account preferences;
  • Payment data: billing details (processed via authorised payment processors; we do not store card numbers);
  • User inputs: prompts, queries, documents, and other content submitted through the Platform.

2.2 Data Collected Automatically

  • Device and browser data: IP address, browser type and version, operating system, and device identifiers;
  • Usage data: pages visited, features accessed, session duration, click patterns, and interaction logs;
  • Cookie and tracking data: in accordance with our Cookie Policy (see clause 11).

2.3 Data from Third Parties

Where you register or sign in using a third-party account (e.g., Google, Microsoft), we may receive basic profile information from that provider in accordance with your privacy settings on that platform.

3. Purposes and Legal Basis for Processing

Under the PDPA, we are required to process your Personal Data only for purposes for which consent has been obtained or which are otherwise permitted by law. We process your Personal Data for the following purposes:

PurposeDescriptionRetention Period
Service deliveryOperating and maintaining your account and the PlatformDuration of account + 2 years
CommunicationsSending service updates, security alerts, and support messagesDuration of account + 2 years
AI improvementImproving AI models using anonymised, aggregated data onlyAnonymised — indefinite
Legal complianceMeeting legal, regulatory, audit, and enforcement obligationsAs required by law (typically 7 years)
Analytics and improvementAnalysing usage patterns to improve the Platform (anonymised)24 months (rolling)
Marketing (with consent)Sending promotional content where you have opted inUntil opt-out + 6 months

4. Consent

Where we rely on consent as the basis for processing, we obtain this through an explicit, affirmative action — such as ticking a consent checkbox or completing a registration form — prior to processing. Continued use of the Platform alone does not constitute consent to processing that requires affirmative opt-in.

You have the right to withdraw consent at any time by contacting us at hello@skilltrainer.ai. Withdrawal of consent does not affect the lawfulness of processing carried out prior to withdrawal, and may affect your ability to use certain features of the Platform.

5. AI Training and Data Usage

User inputs may be used to improve AI model performance and Platform functionality. We ensure that:

  • only anonymised and aggregated data is used for AI training purposes — your identifiable Personal Data is not used to train AI models without your separate, express consent;
  • raw user inputs are pseudonymised or anonymised before any use in model improvement pipelines;
  • you may opt out of having your data used for AI training at any time by emailing hello@skilltrainer.ai, without affecting your access to the Platform.

6. Disclosure of Personal Data

6.1 Third-Party Service Providers

We may share Personal Data with trusted third-party service providers who assist us in operating the Platform, including:

  • cloud infrastructure and hosting providers (e.g., Amazon Web Services, Microsoft Azure);
  • analytics service providers;
  • customer support platforms;
  • payment processors (subject to their own PCI-DSS compliant policies).

All third-party processors are contractually required to: (a) process data only on our instructions; (b) implement appropriate technical and organisational security measures; and (c) comply with applicable data protection laws.

6.2 Legal Disclosure

We may disclose Personal Data to government authorities, regulators, courts, or law enforcement agencies where required or permitted by Malaysian law, including the PDPA, the Communications and Multimedia Act 1998, or any applicable court order.

6.3 Business Transfers

In the event of a merger, acquisition, restructuring, or sale of assets, Personal Data may be transferred to the successor entity, provided that the acquirer agrees to be bound by obligations equivalent to those in this Privacy Policy.

6.4 No Sale of Data

We do not sell, rent, or trade your Personal Data to any third party for their independent marketing or commercial purposes.

7. Cross-Border Data Transfers

Some of our service providers and infrastructure partners are located outside Malaysia. In accordance with Section 129 of the PDPA, we only transfer Personal Data to countries or territories outside Malaysia where:

  • the destination country provides a level of protection substantially similar to that afforded under the PDPA, as determined by the Minister of Digital (or equivalent authority);
  • the recipient has agreed to contractual safeguards that are equivalent to the protections under the PDPA (including data processing agreements or standard contractual clauses);
  • you have consented to the transfer after being informed of the risks associated with transfer to a country without equivalent protection; or
  • the transfer is necessary for the performance of a contract between you and the Company, or for the implementation of pre-contractual measures taken at your request.

You may request further information about applicable transfer mechanisms by contacting hello@skilltrainer.ai.

8. Data Security

We implement reasonable and appropriate technical and organisational measures to protect Personal Data against unauthorised access, disclosure, alteration, loss, or destruction. These measures include:

  • encryption of data in transit using TLS/SSL and at rest using AES-256 or equivalent standards;
  • access controls and role-based permissions restricting data access to authorised personnel only;
  • regular security assessments, penetration testing, and vulnerability management;
  • incident response procedures and business continuity planning.

Notwithstanding the foregoing, no system is completely secure. In the event of a data security incident affecting your Personal Data, we will notify you and relevant regulatory authorities as required under applicable law and as soon as reasonably practicable.

9. Data Retention

We retain Personal Data only for as long as necessary for the purposes set out in clause 3, or as required by applicable law. Upon expiry of the applicable retention period, we will securely delete or irreversibly anonymise your Personal Data.

Specific retention periods by data category are set out in the table in clause 3. Where we are required by law to retain data for longer periods (e.g., for tax or financial records, typically 7 years under Malaysian law), we will retain data for the legally required period and delete it thereafter.

10. Your Rights Under the PDPA

Under the PDPA and applicable Malaysian law, you have the following rights in relation to your Personal Data:

Right of AccessYou may request a copy of the Personal Data we hold about you, subject to any applicable statutory exemptions (s.30 PDPA).
Right of CorrectionYou may request that we correct any inaccurate or incomplete Personal Data we hold about you (s.34 PDPA).
Right to Withdraw ConsentYou may withdraw consent to processing at any time, subject to limitations where processing is required by law or for performance of a contract.
Right to Limit ProcessingYou may request that we cease or restrict processing of your data for direct marketing purposes (s.43 PDPA).
Right to ComplainYou have the right to lodge a complaint with the Department of Personal Data Protection (JPDP) of Malaysia if you believe your rights have been violated.

To exercise any of these rights, please submit a written request to hello@skilltrainer.ai. We will respond within twenty-one (21) days of receiving a valid request. We may require proof of identity before processing your request. Certain requests may be subject to a processing fee as permitted by the PDPA.

11. Cookies and Tracking Technologies

The Platform uses cookies and similar tracking technologies to operate core functionality, analyse usage, and improve user experience. The categories of cookies we use are:

  • Strictly necessary cookies: essential for Platform operation and cannot be disabled;
  • Functional cookies: enable personalisation and user preferences;
  • Analytics cookies: help us understand how users interact with the Platform (anonymised);
  • Marketing cookies: used only where you have given consent, to deliver relevant communications.

You may configure your browser to refuse or delete cookies. However, disabling strictly necessary cookies may impair your ability to use the Platform.

12. Children’s Privacy

The Platform is not directed at children under the age of 13. We do not knowingly collect Personal Data from children under 13. If we become aware that a child under 13 has provided Personal Data without verified parental consent, we will delete that data without notice. Parents or guardians may contact us at hello@skilltrainer.ai to request review and deletion of a minor’s data.

13. Data Breach Notification

In the event of a Personal Data breach that is likely to result in a risk to the rights and freedoms of individuals, we will:

  • notify the relevant regulatory authority (Department of Personal Data Protection, Malaysia) without undue delay, and in any event within seventy-two (72) hours of becoming aware of the breach where feasible;
  • notify affected individuals directly where the breach is likely to result in a high risk to their rights, without undue delay;
  • document all breaches, including those not reported to authorities, and maintain an internal breach register.

14. Updates to This Privacy Policy

We may update this Privacy Policy from time to time to reflect changes in our practices, legal requirements, or the Platform. Where changes are material, we will provide notice by email or a prominent notice on the Platform at least fourteen (14) days before the updated Policy takes effect. The “Last Updated” date at the top of this Policy will be revised accordingly. Continued use of the Platform after the effective date constitutes acceptance of the updated Policy.

15. Contact Us

For all data protection enquiries, access requests, complaints, or questions regarding this Privacy Policy, please contact:

SkillTrainer AI Sdn Bhd

No. 17A Jalan Daya 6, Taman Daya, 52100 Kepong, W.P. Kuala Lumpur

Email: hello@skilltrainer.ai

Tel: 012-652 2189

Response time: We aim to respond to all requests within 21 working days.

If you are unsatisfied with our response, you have the right to escalate your complaint to the Department of Personal Data Protection (JPDP) Malaysia at www.pdp.gov.my.

SkillTrainer AI

Your intelligence, amplified.

No. 17A Jalan Daya 6, Taman Daya, 52100 Kepong, W.P. Kuala Lumpur.

Business Registration: 202601008220 (1670318-M)

Product

  • Home
  • About
  • Pricing
  • Sign In

Company

  • Our story
  • Contact
  • hello@skilltrainer.ai

Legal

  • Privacy Policy
  • Terms of Service
  • PDPA Notice

© 2026 SkillTrainer AI. Made in Malaysia.