Legal
Privacy Policy
Last Updated: 15 May 2025 | Teratai AI | Kuala Lumpur, Malaysia
Teratai AI ("we", "us", "our") is committed to handling your personal data with care and transparency. This policy explains what we collect, why we collect it, how long we keep it, and what your rights are under Malaysia's Personal Data Protection Act 2010 (PDPA). If you have questions about anything here, please contact us at [email protected].
1. Who We Are
Teratai AI operates as an online AI development school based at Jalan Sungai Besi 117, 57100 Kuala Lumpur, Malaysia. We are the data controller for personal information collected through our website and during enrolment in our programmes.
2. What Data We Collect
We collect the following categories of personal data:
- Identity data: full name, as provided in our contact or enrolment forms
- Contact data: email address, phone number (if provided)
- Technical data: IP address, browser type, pages visited, session duration — collected via analytics tools
- Communications data: content of messages submitted through our contact form
- Programme data: enrolment details, project submissions, feedback records
We do not collect sensitive personal data (such as health, financial, or identity document information) and do not ask for it.
3. How We Collect Data
- Contact and enquiry forms on our website
- Enrolment and programme registration processes
- Cookies and analytics tools placed when you visit our website (see Section 7)
- Direct communication by email or phone
4. Legal Basis for Processing
Under the PDPA 2010, we process your data on the following bases:
- Consent: where you submit a form or accept cookies
- Contract performance: to manage your programme enrolment and deliver the service you've paid for
- Legitimate interests: to improve our website and communications based on how visitors use the site
- Legal compliance: where required by Malaysian law
5. How We Use Your Data
- To respond to enquiries and process enrolment applications
- To deliver programme content, send clinic reminders, and share feedback
- To communicate administrative information about your programme
- To improve our website and lesson content based on aggregate usage data
- To comply with legal or regulatory obligations
We do not use your data for automated decision-making or profiling.
6. Data Sharing
We do not sell personal data to any third party. We may share limited data with the following categories of service provider, who process data on our behalf under appropriate agreements:
- Website hosting and infrastructure providers (servers based in Southeast Asia)
- Analytics services (aggregated, anonymised data where possible)
- Email delivery services for programme communications
We will disclose data to law enforcement or regulatory authorities if required to do so by law.
7. Cookies
Our website uses cookies to support basic functionality and to understand how the site is used. A consent notice is shown on your first visit. You can manage your preferences through our Cookie Policy page. Declining non-essential cookies does not prevent you from using the site or enquiring about programmes.
8. Data Retention
- Enquiry data: retained for 12 months after last contact if no enrolment follows
- Programme data: retained for 3 years after programme completion for record-keeping purposes
- Analytics data: aggregated and anonymised; individual session data is not retained beyond 26 months
- Legal or financial records: retained for 7 years as required by Malaysian accounting standards
9. Data Protection Measures
We use the following measures to protect your data:
- HTTPS encryption for all data transmitted through our website
- Access to personal data restricted to team members who need it to perform their role
- Programme platforms require authentication before accessing learner content or submissions
- We review our data handling practices regularly
In the event of a data breach that is likely to affect your rights, we will notify you and the relevant authority within the timeframes required by applicable law.
10. Your Rights Under the PDPA
As a data subject under Malaysia's Personal Data Protection Act 2010, you have the right to:
- Access: request a copy of the personal data we hold about you
- Correction: request that inaccurate or incomplete data be corrected
- Withdrawal of consent: withdraw consent to processing at any time (this does not affect processing that took place before withdrawal)
- Object to processing: object to data being used for direct marketing purposes
- Erasure: request deletion of data we no longer have a legal basis to hold
To exercise any of these rights, contact us at [email protected]. We will respond within 21 days of receiving a verified request.
11. Third-Party Links
Our website may contain links to external sites. We are not responsible for the privacy practices of those sites and this policy does not cover them. We encourage you to read the privacy policy of any site you visit.
12. Children
Our programmes are intended for adults aged 18 and above. We do not knowingly collect personal data from persons under 18. If we become aware that data belonging to a minor has been submitted, we will delete it promptly.
13. Changes to This Policy
We may update this policy from time to time. Significant changes will be communicated by email to enrolled learners or by a notice on our website. Continued use of our website or services after an update constitutes acceptance of the revised policy. The "Last Updated" date at the top of this page reflects the most recent revision.
14. Contact
For privacy-related questions, corrections, or data subject requests:
- Email: [email protected]
- Phone: +60 3-2873 6194
- Address: Teratai AI, Jalan Sungai Besi 117, 57100 Kuala Lumpur, Malaysia