Responsible data handling for enterprise AI

Privacy Policy Overview

VisionTopAI operates VisionTopAI.digital to deliver AI business solutions tailored to Malaysian organizations. This Privacy Policy explains what data we collect, how we use it, retention practices and the rights available to data subjects. Our office: 42675, Jalan Rawang Mutiara 3, Taman Rawang Perdana, 48000 Rawang, Selangor, Malaysia. Business ID: 127399740192. Contact phone: +60128266197. Policy effective date: 21-04-2026. The policy applies to clients, prospective clients and visitors interacting with our services and website and reflects our professional approach to data stewardship and compliance with applicable laws.

21-04-2026 VisionTopAI 42675, Jalan Rawang Mutiara 3, Taman Rawang Perdana, 48000 Rawang, Selangor, Malaysia [email protected]
01

Definitions

For clarity, key terms used in this policy are defined below to help you understand how we process information in the context of providing AI solutions.

Personal data means any information that can identify an individual, directly or indirectly, such as name, contact details, identification numbers or other identifiers used in our client onboarding and service delivery. Processing refers to any operation performed on personal data, including collection, storage, use, disclosure, analysis, transfer and deletion, carried out in support of our services and internal operations. User refers to any person who engages with VisionTopAI.digital, including clients, their authorized representatives, website visitors and individuals whose data is provided as part of service delivery or evaluation. Service denotes the suite of AI consulting, model development, integration, monitoring and support offerings provided by VisionTopAI to business clients. Cookies are small text files placed on a device to store preferences and usage information; similar technologies include web beacons and local storage used to support site functionality and analytics.
02

Data We Collect

We collect data necessary to provide services, manage accounts, secure systems and improve solutions. Data collection occurs through direct input, automated technical processes and from trusted third-party sources.

Data You Provide

Information you provide when engaging our services or communicating with us enables onboarding, configuration and delivery of tailored AI solutions.

  • Contact details: name, professional email, phone number, job title and company name provided during inquiries and account setup.
  • Company data: business registration details, company size and operational context supplied to scope AI projects and integrations.
  • Project inputs: documents, datasets, system access credentials (transmitted securely) and technical specifications required for model development and integration.
  • Billing and contractual information: invoicing address, payment details and contract contacts needed for account administration and business processing.
  • Communications: messages, support tickets and feedback platform with our team to manage delivery and continuous improvement.
  • Consents and preferences: explicit preferences you set for communications, data processing and feature use related to our services.

Data Collected Automatically

When you use our website or services, certain technical data is collected automatically to operate and secure systems, and to measure service performance.

  • Usage data: pages visited, features used, timestamps and interaction patterns captured for operational analytics.
  • Device and browser information: device type, operating system, browser version and language settings used for compatibility and security.
  • IP address and connection data: logged for security, geolocation approximation and access control.
  • System logs: error reports, diagnostic traces and performance metrics used to detect incidents and improve reliability.
  • Cookies and identifiers: persistent and session identifiers that support authentication, preferences and analytics.
  • Aggregated and anonymized telemetry: non-identifiable aggregates used to refine models and product features.

Third-Party Sources

We may receive data from trusted third parties to enhance services, verify information, or support integrations under contractual safeguards.

  • Service providers such as cloud infrastructure and analytics vendors who process data on our behalf under data processing agreements.
  • Payment processors and business services used for billing and transaction verification.
  • Business partners and integrators who collaborate on client solutions or supply relevant technical data.
03

How We Use Data

We process personal data to fulfill contractual obligations, operate and improve our services, protect systems and meet legal requirements. Processing purposes are limited to what is necessary for those objectives.

  • Provision and operation of AI solutions, including model training, deployment and integration with client systems.
  • Account management, billing and business administration related to service contracts.
  • Service improvement and product development based on anonymized usage data and performance metrics.
  • Security, fraud detection and incident response to protect client data and infrastructure.
  • Customer support, troubleshooting and technical assistance during onboarding and ongoing operations.
  • Legal and regulatory compliance, including responses to lawful requests and recordkeeping obligations.
  • Limited marketing communications where consent has been provided, focusing on relevant product updates and events.
  • Research and internal analytics using aggregated or pseudonymized datasets to inform engineering and business decisions.

Legal Bases for Processing

We rely on appropriate legal bases to process personal data, depending on the context and applicable law. These bases are documented and assessed for each processing activity.

  • Performance of a contract: processing necessary to provide services under an agreement with a client.
  • Consent: where we ask for and obtain explicit consent for specific processing activities, such as marketing communications.
  • Legitimate interests: processing required for security, fraud prevention and business operations, balanced against individual rights.
  • Legal obligation: processing necessary to comply with statutory or regulatory duties.

Data Protection Rights

Subject to applicable data protection laws, individuals may exercise specific rights regarding personal data we hold. We respond to requests in line with legal timeframes and verification requirements.

  • Right of access — you can request confirmation of whether we process your personal data and access to a copy.
  • Right to rectification — you may request correction of inaccurate or incomplete personal data.
  • Right to erasure — where applicable, you can request deletion of personal data when retention is no longer necessary.
  • Right to restriction of processing — you can request limitation of processing in certain circumstances.
  • Right to data portability — where technically feasible, you may request your data in a structured, commonly used format.
  • Right to object — you can object to processing based on legitimate interests or direct marketing where applicable.
04

Cookies and Similar Technologies

Our website uses cookies and similar technologies to enable essential functionality, analyze usage and improve user experience. You can manage preferences through your browser and provided controls.

Common types include session cookies that expire at the end of a visit, persistent cookies that remain for a defined period, and third-party cookies set by external services such as analytics providers.

We classify cookies as strictly necessary (required for site operation), analytics (used for performance measurement), functional (to remember preferences) and marketing (to support promotional activities).

Manage cookies through browser settings or use the cookie controls on our website to adjust preferences. Blocking certain cookies may limit functionality or analytics accuracy.

Cookie Policy

Sharing Your Data

We do not sell personal data. We share data only as required to deliver services, comply with legal obligations, or when you have provided consent, under contractual safeguards and need-to-know principles.

  • Service providers and subprocessors engaged to host, operate or maintain services and infrastructure under data processing agreements.
  • Professional advisors, such as lawyers and auditors, when necessary for legal compliance or governance.
  • Affiliates and partners involved in delivery of combined solutions with contractual confidentiality protections.
  • Legal authorities when disclosure is required by law, regulation or to defend legal rights.
  • Potential buyers or counterparties in the event of a business transaction, subject to appropriate confidentiality and data protection measures.
  • Analytics and research partners using aggregated or pseudonymized datasets to improve model performance and product capabilities.

International Transfers

Because we operate with global cloud services and partners, personal data may be transferred to jurisdictions outside Malaysia. Transfers are limited to the extent necessary for service provision.

When transfers occur, we adopt safeguards such as contractual data protection terms, standard contractual clauses, technical controls and strict access restrictions to maintain appropriate protection levels.

Data Retention

We retain personal data only as long as necessary for the purposes described in this policy, including legal, regulatory and contractual obligations, and then delete or anonymize it in a secure manner.

Account and contract-related data is retained for the duration of the service relationship and for a defined period thereafter to meet accounting and legal recordkeeping requirements.

Communications and support records are retained as necessary to provide support, resolve disputes and maintain a history of service interactions.

System logs and diagnostic data are retained for a limited period to support security contribute, forensic analysis and system health monitoring, then purged according to our retention schedule.

Upon termination of services and subject to contractual obligations, personal data is deleted or anonymized within a reasonable timeframe; clients can request deletion where applicable and permitted by law.

Security Measures

Security is integral to our service design. We apply a risk-based approach to protect data through administrative, technical and physical controls appropriate to the sensitivity of the information and the operational context.

  • Encryption in transit and at rest for sensitive data and credentials, using industry-recognized protocols.
  • Access controls, multi-factor authentication and least-privilege principles for internal systems and service accounts.
  • Regular security assessments, vulnerability scanning and third-party audits to maintain and improve defensive measures.
05

Your Rights

To exercise your rights or raise concerns about our data processing, we provide clear channels for requests and respond in a timely manner following verification of identity and applicable legal requirements.

  • To make requests regarding access, correction, deletion or other rights, contact our data protection representative at [email protected] or by postal mail to the address listed. Please include sufficient detail to identify the data and the requested action.
  • If you are not satisfied with our response, you may lodge a complaint with the relevant supervisory authority or pursue available legal remedies; we will cooperate with lawful contribute and provide required information.
  • Right to rectification: You may request correction of inaccurate or incomplete personal information we hold about you. We assess and implement verified changes in a timely manner, keeping a record of updates in our systems.
  • Right to erasure: Where retention is no longer necessary for the purposes for which data was collected, you can request deletion of your personal data. Deletion requests are evaluated against legal, regulatory and contractual requirements before action is taken.
  • Right to restrict processing: You can request restriction of processing where you contest accuracy, object to processing, or when processing is unlawful and you prefer restriction instead of erasure. Restricted records will be retained only for storage and limited use until resolved.
  • Right to data portability: Where applicable, you may request a copy of your personal data in a structured, commonly used and machine-readable format for transmission to another data controller. Transfers are handled securely and in compliance with applicable law.
  • Right to object to processing: You can object to processing based on legitimate interests or direct marketing. When an objection is valid, we will stop processing for those purposes unless we have compelling legitimate grounds or legal reasons to continue.
  • Right to withdraw consent: If processing is based on consent, you may withdraw that consent at any time. Withdrawal will not affect the lawfulness of processing carried out prior to withdrawal.

How to Exercise Your Privacy Rights

To submit a request to access, correct, restrict or delete your personal data, contact our Data Protection Officer at [email protected] or by mail to the address below. Please include a clear description of the request and proof of identity to help us verify your entitlement. VisionTopAI reviews requests with documented procedures to ensure security and legal compliance.

[email protected]

We aim to acknowledge receipt of privacy requests within 5 business days and to resolve eligible requests within 30 calendar days. Complex requests or those requiring verification may take up to 60 days; we will notify you if additional time is needed.

Marketing and Communications

VisionTopAI may use contact details to send service-related updates, industry insights, event invitations and product information tailored to business needs. Marketing communications are based on consent or a legitimate interest assessment where relevant. We apply segmentation and relevance criteria to minimize unnecessary messaging and protect user preferences.

You can manage marketing preferences or unsubscribe at any time via the unsubscribe link in email communications or by contacting [email protected]. Unsubscribe requests are processed promptly; transactional and service communications related to your account or purchased services may still be sent as permitted by law.

Children's Privacy

Our services are intended for business users and adults. VisionTopAI does not knowingly collect personal data from children under 16. If we become aware that we have collected personal data from a person under 16 without appropriate authorization, we will take steps to delete that information promptly.

Third-Party Links and Services

Our website and solutions may include links or integrations with third-party services, analytics providers and cloud platforms. These third parties have their own privacy practices and controls. VisionTopAI is not responsible for third-party privacy practices; please consult vendor privacy notices before sharing personal data with them.

Changes to This Privacy Policy

We periodically review and update our privacy practices. Material changes to this privacy policy will be published on VisionTopAI.digital with an updated effective date. We encourage users to review this policy regularly for any updates reflecting new services, regulatory developments or operational changes.