Sator AI Technology Sdn. Bhd. T/A Sator.ai (Malaysia co.no 202401045398) (“we”, “us” or “our”) is committed to safeguarding the privacy of our users and protecting their personal information. This Privacy Policy outlines how we collect, use, disclose, and safeguard the personal information provided to us or collected by us during our interactions with you.
This Privacy Policy is formulated in accordance with the laws and regulations of Malaysia governing data protection and privacy, including but not limited to the Personal Data Protection Act 2010 and its Amendment Act 2024, effective in phases starting January through June 2025 – including mandatory DPO appointment, breach notification, data portability and cross-border transfer provisions.
Personal information refers to any information or opinion, whether true or not, and whether recorded in a material form or not, that pertains to an identifiable individual. The types of personal information we may collect about you include:
Sensitive information is a subset of personal information that requires a higher level of protection. We do not actively solicit sensitive information. However, if we need to collect sensitive information such as your health information, religious beliefs, or political opinions for a specific and legitimate purpose permitted by law, we will first obtain your explicit consent and ensure its proper handling and protection.
We use and disclose your personal information for the following purposes:
| Purpose of Use/Disclosure | Type of Personal Information |
|---|---|
| To provide and manage access to our Sator.ai services, including account creation and authentication. | Identity Data, Account Data |
| To communicate with you about our services, respond to your inquiries, and provide customer support. | Identity Data, Contact Data, Profile Data |
| For internal administrative and operational purposes, such as record keeping, invoicing, and accounting. | Identity Data, Contact Data, Transaction Data |
| To personalize your experience on our platform, offer tailored content and recommendations. | Profile Data, Technical and Usage Data |
| To conduct analytics and research to improve our services, understand user behavior, and develop new features. | Technical and Usage Data, Profile Data |
| For marketing and promotional activities, including sending you information about our events, offers, and new products or services, subject to your marketing preferences. | Identity Data, Contact Data, Profile Data, Marketing and Communications Data |
| To enable your participation in interactive features, contests, and surveys. | Interaction Data |
| To comply with legal obligations, such as responding to legal requests, court orders, or regulatory requirements. | Any relevant Personal Information |
We will only disclose your personal information to third parties in the following circumstances:
We take the security of your personal information seriously. We have implemented appropriate physical, technical, and administrative measures to protect your information from unauthorized access, disclosure, alteration, or destruction. These measures include but are not limited to:
However, please note that no method of data transmission or storage is completely secure, and we cannot guarantee absolute security of your information.
We retain personal data only as long as necessary to fulfil the purposes described in this Policy, or as required by law. Unless legally required otherwise, personal information will be deleted or anonymized no later than three years after the relevant service concludes.
We use cookies and similar technologies on our website and application to enhance your user experience, personalize content, and analyze user behavior. You can control the use of cookies through your browser settings. By using our platform, you consent to the use of cookies in accordance with this Privacy Policy.
Our website may contain links to third-party websites. We are not responsible for the privacy practices or content of these third-party websites. When you click on a link to a third-party website, we encourage you to review their privacy policies before providing any personal information.
We have appointed an internal Data Protection Officer, contactable at [email protected]. The DPO is responsible for overseeing our data protection compliance as required under PDPA 2024.
In accordance with PDPA Amendment Act effective 1 June 2025, we will notify the Malaysian Personal Data Protection Commissioner “as soon as practicable” and affected individuals “without unnecessary delay” if a personal data breach occurs that may cause significant harm. We will also maintain a data breach register for at least two years and, if required, provide remediation steps.
We may transfer personal data outside Malaysia to jurisdictions with laws substantially similar to the PDPA, or upon obtaining your explicit consent, or where required to perform a contract. We will conduct a Transfer Impact Assessment every three years to evaluate the destination country’s safeguards, and will rely on Standard Contractual Clauses or Binding Corporate Rules where applicable.
This Privacy Policy may be updated to reflect the latest “Guidelines” issued by the Commissioner (e.g., Data portability, Data protection by design, Automated decision-making) or changes in law. We will post a notice on our website or notify users through other appropriate channels. Continued use after the new effective date indicates acceptance.
If you have any questions, concerns, or requests regarding this Privacy Policy or our handling of your personal information, please contact: