Skip to content
SkillPilot AdvisoryStart. Think. Work. Grow. with AI.
ProductsAdvisoryAboutNewsContact
ProductsAdvisoryAboutNewsContact

Legal

Privacy Notice

Version 1.0Effective date: 29 September 2026

  1. Who is responsible
  2. What we collect and why
  3. What not to send us
  4. Required and optional information
  5. Cookies and similar technologies
  6. Who processes data for us
  7. Transfers and storage locations
  8. How long we keep data
  9. Security
  10. Your rights
  11. Automated processing
  12. Data breaches
  13. Children
  14. Marketing choices
  15. Complaints and regulators
  16. Changes to this notice

1. Who is responsible for your data

Skill Pilot Advisory Sdn. Bhd. ("SkillPilot", "we") is responsible for the personal data described here. We are a company incorporated in Malaysia (company registration number 202601022948 (1685045-M)), with our registered address at Level 7, Mercu 3, No. 3, Jalan Bangsar, KL Eco City, 59200 Kuala Lumpur, W.P. Kuala Lumpur, Malaysia.

For privacy inquiries, contact our designated privacy team at info@skillpilotadvisory.ai with the subject line "Privacy request". You can also use the privacy route on the Support page.

2. What we collect and why

The following table lists each activity, the data involved, its purpose, and the legal basis we rely on where the EU General Data Protection Regulation (GDPR) applies:

ActivityDataPurposeGDPR basis
BrowsingIP address, browser type, pages requested, and time, in standard hosting logsDeliver the site, keep it secure, and diagnose faultsLegitimate interests
Analytics, only if you allow itPage path, referrer domain, country, device type, and product-interest events. No cookies and no personal identifiersUnderstand which pages and products visitors useConsent
CheckoutName, email, billing country, payment method details, and your acceptance of the Terms, collected by StripeTake payment, prevent fraud, and record the contractContract and legal obligation
Purchase recordPurchase email, product code, Stripe checkout and payment references, Terms version, Terms acceptance status, and timestampsGrant access only to the products you paid for, handle refunds, and prove acceptanceContract and legal obligation
Sign-inEmail address, one-time code requests, and session dataLet you sign in without a password and protect your accountContract and legitimate interests
Product useInformation you enter or upload in a workspace, saved reports, and approval statusProvide the product and save your work privately under your loginContract
PDF generationThe saved report you choose to exportCreate the PDF in your browser. The PDF is not sent to usContract
Support and grievancesName, email, category, product, and your description of the problemAnswer questions, resolve complaints, and handle rights requestsLegitimate interests and legal obligation
Contact enquiriesName, company, title, email, and messageReply to advisory enquiriesLegitimate interests
Benchmark contribution, only if you allow it and not active in every product yetYour sector, company size band, and market, plus bucketed numbers and scores drawn from your workspace inputs. No free text, company name, or other personal identifierBuild anonymised benchmarks that other customers can compare againstConsent
AI-assisted drafting, only if you allow it and not active yetThe specific fields a task needs from your workspace inputs, with emails, phone numbers, and links removed firstDraft text or suggest a score for your own reviewConsent

AI-assisted drafting is not active in any product yet. This notice describes it now so it is in place before that changes. When AI-assisted drafting becomes available, the product page and the AI-help consent prompt will say so before you can turn it on, and section 6 below names the AI vendors that would process your data.

3. What we ask you not to send us

Please do not enter or upload the following into a product workspace, support form, or email, unless you have authority and a lawful basis to share it:

  • personal data about customers, employees, or other individuals
  • health, biometric, religious, political, or criminal record information
  • financial account numbers, card details, passwords, or identity document numbers
  • confidential client information or regulated data
  • the contents of a confidential report in a general support message

Our products work with aggregated business figures and descriptions. They do not need the information listed above.

4. Required and optional information

An email address is required to buy a product and to sign in, because access is linked to your purchase email. Payment details are required by Stripe to complete a purchase. Workspace fields marked as required are needed to produce an output. All other fields are optional. Analytics is optional and off unless you allow it.

5. Cookies and similar technologies

We use the following storage in your browser:

NameTypeCategoryPurposeDuration
sb-...-auth-tokenLocal storageStrictly necessaryKeeps you signed in to purchased productsUntil you sign out or the session expires
sp_consentLocal storageStrictly necessaryRemembers your cookie choice, the policy version, and the date. No identifierUntil you change it or clear your browser storage
Plausible AnalyticsScript, no cookiesAnalyticsCounts visits and product-interest events without identifying youLoads only after you allow analytics

We do not use marketing or advertising cookies. The Inter typeface is served from this website, so no font request goes to a third party.

Your current choice: Loading your choice.

6. Who processes data for us

We share personal data only with providers who help us run the service. The main categories are:

  • Payments: Stripe processes checkout, payment, receipts, refunds, and disputes.
  • Sign-in and data storage: Supabase stores purchase records, accounts, and saved workspace data.
  • Hosting: Netlify hosts the website and serves pages.
  • Email delivery: Amazon SES, in its Malaysia region, sends one-time sign-in codes, and our mailbox provider receives support email.
  • Forms: Formspree receives contact and support form submissions.
  • Analytics, only with consent: Plausible Analytics.
  • AI drafting, only once available and only with your AI-help consent: Google and Anthropic process the specific fields a task needs. We use paid business accounts, not a free consumer service.

We do not sell personal data. We may disclose data where the law requires it or to protect our rights, customers, or the public.

7. International transfers and storage locations

Several providers process data outside Malaysia, including in the United States, the European Union, and Singapore. Purchase records, accounts, and saved workspace data are stored in Supabase's Singapore region. Stripe and Netlify process data in multiple countries.

When we transfer personal data out of Malaysia, we take the steps the Personal Data Protection Act 2010, as amended, requires, including data processing agreements with our processors. For data subject to the GDPR, we rely on adequacy decisions or standard contractual clauses offered by our providers. Once AI-assisted drafting is active, your AI-help consent is also the basis for sending the fields a task needs to an AI vendor outside Malaysia, subject to legal counsel's advice on the transfer basis for each vendor.

8. How long we keep data

We keep data only as long as needed for the purposes in section 2. The following periods apply:

DataRetention
Purchase, refund, and Terms acceptance records7 years after the purchase, to meet the record-keeping duties in the Companies Act 2016 and applicable tax law
Accounts and saved workspace dataWhile your access is active. Deleted within 30 days of a verified deletion request, or after 24 months without sign-in following an email notice
Support and grievance records2 years after the case closes
Contact enquiries2 years after the last exchange
Hosting and security logsAccording to our providers' standard log retention, generally 30 days or less
Consent choice, including contribution and AI-help consentUntil you withdraw it or your account is deleted
Credit ledger, once credits are active7 years, the same period as purchase and refund records, to support billing and dispute records
Bucketed benchmark contributionsWhile used in a live benchmark. Withdrawing consent stops future contributions; a figure already shown or exported to someone else is not altered

9. Security

We use encrypted connections (HTTPS) for the whole site, password-free one-time sign-in codes, database rules that let each account read only its own saved work, access that depends on a verified payment record, signed payment notifications, and restricted administrator access. Payment card details never reach our systems.

No system is completely secure. If you believe your account or data is at risk, report it through the security route on the Support page.

10. Your rights

Rights under Malaysian law

Under the Personal Data Protection Act 2010, as amended by the Personal Data Protection (Amendment) Act 2024, you may request access to and correction of your personal data, withdraw consent, limit processing likely to cause damage or distress, and object to direct marketing. Where the amended Act provides a data portability right, you may ask us to transmit your data to another controller once that right is in force. We respond to access and correction requests within 21 days.

Rights under the GDPR

Where GDPR Article 3(2) applies to your purchase as an EEA resident, we adhere to applicable GDPR standards. You have the rights to access, correction, deletion, restriction, objection, and data portability. Where we rely on consent, you may withdraw it at any time without affecting earlier processing. We respond within one month.

Singapore

If you are in Singapore, you may request access to and correction of your personal data and withdraw consent under the Personal Data Protection Act 2012. We follow the PDPA's access, correction, and retention obligations for those requests.

How to make a request

  1. Go to the Support page and choose "Privacy or data rights request", or email us with the subject "Privacy request".
  2. Tell us which right you want to exercise and which product, if any, it relates to.
  3. We verify the request by sending a code to the email address linked to your purchase. We do not ask for identity documents unless verification by email is not possible.

To delete saved reports or your account, make a deletion request through the privacy route. Some records, such as purchase and tax records, must be kept for the periods in section 8 even after a deletion request. We tell you when this applies.

11. Automated processing

Our products calculate figures and generate draft text from the information you enter. These drafts are for your own review. We do not make any decision about you by automated means that produces legal effects or similarly significant effects. Access to a product depends on an automatic check that a payment succeeded. If you think access was refused in error, contact support and a person will review it.

12. Data breaches

If a personal data breach occurs, we contain it, assess the risk, and notify the relevant authority and affected people where the law requires it, within the time the law sets. That includes the Personal Data Protection Commissioner in Malaysia and, where they apply, EU supervisory authorities and Singapore's Personal Data Protection Commission.

13. Children

Our services are restricted to business users aged 18 or over. By using the service, you warrant that you meet this age requirement. We do not knowingly collect personal data from children. If you believe a child has given us personal data, contact us and we will delete it.

14. Marketing choices

We send service emails that you need, such as sign-in codes, receipts, and important notices about a product you bought. We do not send marketing emails unless you have opted in. You can opt out at any time through the unsubscribe link or by contacting us.

15. Complaints and regulators

Please contact us first so we can try to resolve your concern. If you are not satisfied, you may complain to the relevant regulator:

  • Malaysia: the Personal Data Protection Department.
  • Singapore: the Personal Data Protection Commission.
  • European Economic Area: the data protection supervisory authority where you live or work.

16. Changes to this notice

We update this notice when our processing changes. Each version has a version number and effective date at the top of the page. If a change materially affects how we use data you have already given us, we tell affected customers by email before the change applies.

Version 1.0. Effective date: 29 September 2026.

Sources consulted

  • Personal Data Protection Act 2010 (Malaysia)
  • Personal Data Protection (Amendment) Act 2024 (Malaysia)
  • Regulation (EU) 2016/679, the General Data Protection Regulation
  • European Commission guidance on GDPR principles
  • Singapore PDPA data protection obligations
© Skill Pilot Advisory Sdn. Bhd.
ProductsMy productsAdvisoryAboutContactSupportTermsPrivacyRefunds
Start. Think. Work. Grow. with AI.