1. Who we are and what this covers
This policy explains how Advorum ("we", "us") processes personal data in connection with the Advorum website and service, in line with Malaysia's Personal Data Protection Act 2010, as amended (the "PDPA").
We decide how account, billing, enquiry and website data is used. Personal data contained in the business records you connect or upload is processed on your behalf and on your instructions.
2. Personal data we collect
- Account data: name, email address, password (stored only as a salted hash), and language and theme preferences.
- Workspace data: workspace names, members' roles, invitations and settings.
- Business records you connect or upload, which may include names and contact details of your customers, suppliers or staff.
- Enquiry data: what you send through our contact form, such as your name, email, company, phone number and message.
- Technical data: IP address, browser user agent, session records, and an activity log of sign-ins and sensitive actions.
- Billing data: invoicing contacts and payment records for paid plans.
3. Why we process it
We process personal data to:
- create and secure accounts and workspaces;
- provide the service, including syncing connectors, calculating the Resilience Index and running consultations;
- respond to enquiries and provide support;
- send service messages such as invitations, security notices and plan reminders;
- bill for paid plans and keep financial records;
- detect abuse, enforce rate limits and investigate security incidents;
- comply with our legal obligations.
We do not sell personal data and do not use Customer Data to train AI models. We ask for consent before sending marketing messages, and you can withdraw it at any time.
4. AI providers
When advisors run, the relevant parts of your data and brief are sent to the AI provider selected for each advisor, such as Anthropic, OpenAI or Google. On plans where you supply your own API keys, that processing takes place under your agreement with the provider. During the Starter trial, it takes place under ours.
AI providers process this data to return a response, under their own retention and data-use terms. We choose providers and settings that do not use API data for model training by default, but you should review the terms of any provider you connect.
5. Who we share it with
We share personal data only with:
- service providers that host, store, email or support the service for us, under contracts that require them to protect it;
- AI providers, as described above;
- professional advisers, auditors and insurers, under a duty of confidentiality;
- authorities, where the law requires it or where needed to protect rights, safety and security;
- a successor business if the service is sold or restructured, subject to this policy.
6. Transfers outside Malaysia
Our hosting, email and AI providers may store or process data outside Malaysia, including in Singapore, the United States and the European Union. When personal data is transferred abroad, we take the steps the PDPA requires so that it receives a comparable level of protection, such as contractual safeguards.
7. How long we keep it
We keep account and workspace data while your account is active. After a workspace is closed, Customer Data is deleted within 90 days, apart from backups, which expire on their normal cycle. Enquiry data is kept for up to 24 months.
Billing records and the activity log are kept for as long as tax, accounting or other legal obligations require, which for financial records in Malaysia is generally seven years.
8. How we protect it
We protect personal data with technical and organisational measures suited to the risk, including encryption in transit, AES-256-GCM encryption of stored connector and AI credentials, hashed passwords, strict separation between workspaces, rate limiting and logging of sensitive actions.
No system is perfectly secure. If a personal data breach occurs, we will notify affected users and the authorities as the law requires.
9. Your rights under the PDPA
Subject to the PDPA, you may:
- ask whether we hold your personal data and request a copy of it;
- ask us to correct personal data that is inaccurate, incomplete, misleading or out of date;
- withdraw consent, or ask us to limit processing, where processing relies on consent;
- ask us to stop processing that is causing, or is likely to cause, substantial damage or distress;
- ask us not to use your personal data for direct marketing;
- ask for your personal data to be transmitted to another data controller where the law provides for it.
To make a request, contact us as described below. We may need to verify your identity and, where the law allows, may charge a prescribed fee for access requests. We respond within the time the PDPA requires, normally 21 days. Requests about personal data in business records uploaded by one of our customers will be referred to that customer.
Providing account data is necessary to use the service. Without it, we cannot create an account for you.
10. Cookies
We use a small number of first-party cookies that are needed for the site to work: a session cookie that keeps you signed in, one that remembers the selected workspace, and ones that remember your language and theme. We do not use advertising or third-party tracking cookies.
11. Changes to this policy
We may update this policy from time to time. We will publish the new version here with a new effective date and, for material changes, notify account holders by email or in the service.
12. Contact
Questions and requests about personal data can be sent through the contact form at https://advorum.nexsim.co/contact. Please start your message with "Personal data request".