Legal
Privacy Notice
1. Who is responsible for your data
Skill Pilot Advisory Sdn. Bhd. ("SkillPilot", "we") is responsible for the personal data described here. We are a company incorporated in Malaysia (company registration number 202601022948 (1685045-M)), with our registered address at Level 7, Mercu 3, No. 3, Jalan Bangsar, KL Eco City, 59200 Kuala Lumpur, W.P. Kuala Lumpur, Malaysia.
For privacy inquiries, contact our designated privacy team at info@skillpilotadvisory.ai with the subject line "Privacy request". You can also use the privacy route on the Support page.
2. What we collect and why
The following table lists each activity, the data involved, its purpose, and the legal basis we rely on where the EU General Data Protection Regulation (GDPR) applies:
| Activity | Data | Purpose | GDPR basis |
|---|---|---|---|
| Browsing | IP address, browser type, pages requested, and time, in standard hosting logs | Deliver the site, keep it secure, and diagnose faults | Legitimate interests |
| Analytics, only if you allow it | Page path, referrer domain, country, device type, and product-interest events. No cookies and no personal identifiers | Understand which pages and products visitors use | Consent |
| Checkout | Name, email, billing country, payment method details, and your acceptance of the Terms, collected by Stripe | Take payment, prevent fraud, and record the contract | Contract and legal obligation |
| Purchase record | Purchase email, product code, Stripe checkout and payment references, Terms version, Terms acceptance status, and timestamps | Grant access only to the products you paid for, handle refunds, and prove acceptance | Contract and legal obligation |
| Sign-in | Email address, one-time code requests, and session data | Let you sign in without a password and protect your account | Contract and legitimate interests |
| Product use | Information you enter or upload in a workspace, saved reports, and approval status | Provide the product and save your work privately under your login | Contract |
| PDF generation | The saved report you choose to export | Create the PDF in your browser. The PDF is not sent to us | Contract |
| Support and grievances | Name, email, category, product, and your description of the problem | Answer questions, resolve complaints, and handle rights requests | Legitimate interests and legal obligation |
| Contact enquiries | Name, company, title, email, and message | Reply to advisory enquiries | Legitimate interests |
| Benchmark contribution, only if you allow it and not active in every product yet | Your sector, company size band, and market, plus bucketed numbers and scores drawn from your workspace inputs. No free text, company name, or other personal identifier | Build anonymised benchmarks that other customers can compare against | Consent |
| AI-assisted drafting, only if you allow it and not active yet | The specific fields a task needs from your workspace inputs, with emails, phone numbers, and links removed first | Draft text or suggest a score for your own review | Consent |
AI-assisted drafting is not active in any product yet. This notice describes it now so it is in place before that changes. When AI-assisted drafting becomes available, the product page and the AI-help consent prompt will say so before you can turn it on, and section 6 below names the AI vendors that would process your data.
3. What we ask you not to send us
Please do not enter or upload the following into a product workspace, support form, or email, unless you have authority and a lawful basis to share it:
- personal data about customers, employees, or other individuals
- health, biometric, religious, political, or criminal record information
- financial account numbers, card details, passwords, or identity document numbers
- confidential client information or regulated data
- the contents of a confidential report in a general support message
Our products work with aggregated business figures and descriptions. They do not need the information listed above.
4. Required and optional information
An email address is required to buy a product and to sign in, because access is linked to your purchase email. Payment details are required by Stripe to complete a purchase. Workspace fields marked as required are needed to produce an output. All other fields are optional. Analytics is optional and off unless you allow it.
5. Cookies and similar technologies
We use the following storage in your browser:
| Name | Type | Category | Purpose | Duration |
|---|---|---|---|---|
| sb-...-auth-token | Local storage | Strictly necessary | Keeps you signed in to purchased products | Until you sign out or the session expires |
| sp_consent | Local storage | Strictly necessary | Remembers your cookie choice, the policy version, and the date. No identifier | Until you change it or clear your browser storage |
| Plausible Analytics | Script, no cookies | Analytics | Counts visits and product-interest events without identifying you | Loads only after you allow analytics |
We do not use marketing or advertising cookies. The Inter typeface is served from this website, so no font request goes to a third party.
Your current choice: Loading your choice.
6. Who processes data for us
We share personal data only with providers who help us run the service. The main categories are:
- Payments: Stripe processes checkout, payment, receipts, refunds, and disputes.
- Sign-in and data storage: Supabase stores purchase records, accounts, and saved workspace data.
- Hosting: Netlify hosts the website and serves pages.
- Email delivery: Amazon SES, in its Malaysia region, sends one-time sign-in codes, and our mailbox provider receives support email.
- Forms: Formspree receives contact and support form submissions.
- Analytics, only with consent: Plausible Analytics.
- AI drafting, only once available and only with your AI-help consent: Google and Anthropic process the specific fields a task needs. We use paid business accounts, not a free consumer service.
We do not sell personal data. We may disclose data where the law requires it or to protect our rights, customers, or the public.
7. International transfers and storage locations
Several providers process data outside Malaysia, including in the United States, the European Union, and Singapore. Purchase records, accounts, and saved workspace data are stored in Supabase's Singapore region. Stripe and Netlify process data in multiple countries.
When we transfer personal data out of Malaysia, we take the steps the Personal Data Protection Act 2010, as amended, requires, including data processing agreements with our processors. For data subject to the GDPR, we rely on adequacy decisions or standard contractual clauses offered by our providers. Once AI-assisted drafting is active, your AI-help consent is also the basis for sending the fields a task needs to an AI vendor outside Malaysia, subject to legal counsel's advice on the transfer basis for each vendor.
8. How long we keep data
We keep data only as long as needed for the purposes in section 2. The following periods apply:
| Data | Retention |
|---|---|
| Purchase, refund, and Terms acceptance records | 7 years after the purchase, to meet the record-keeping duties in the Companies Act 2016 and applicable tax law |
| Accounts and saved workspace data | While your access is active. Deleted within 30 days of a verified deletion request, or after 24 months without sign-in following an email notice |
| Support and grievance records | 2 years after the case closes |
| Contact enquiries | 2 years after the last exchange |
| Hosting and security logs | According to our providers' standard log retention, generally 30 days or less |
| Consent choice, including contribution and AI-help consent | Until you withdraw it or your account is deleted |
| Credit ledger, once credits are active | 7 years, the same period as purchase and refund records, to support billing and dispute records |
| Bucketed benchmark contributions | While used in a live benchmark. Withdrawing consent stops future contributions; a figure already shown or exported to someone else is not altered |
9. Security
We use encrypted connections (HTTPS) for the whole site, password-free one-time sign-in codes, database rules that let each account read only its own saved work, access that depends on a verified payment record, signed payment notifications, and restricted administrator access. Payment card details never reach our systems.
No system is completely secure. If you believe your account or data is at risk, report it through the security route on the Support page.
10. Your rights
Rights under Malaysian law
Under the Personal Data Protection Act 2010, as amended by the Personal Data Protection (Amendment) Act 2024, you may request access to and correction of your personal data, withdraw consent, limit processing likely to cause damage or distress, and object to direct marketing. Where the amended Act provides a data portability right, you may ask us to transmit your data to another controller once that right is in force. We respond to access and correction requests within 21 days.
Rights under the GDPR
Where GDPR Article 3(2) applies to your purchase as an EEA resident, we adhere to applicable GDPR standards. You have the rights to access, correction, deletion, restriction, objection, and data portability. Where we rely on consent, you may withdraw it at any time without affecting earlier processing. We respond within one month.
Singapore
If you are in Singapore, you may request access to and correction of your personal data and withdraw consent under the Personal Data Protection Act 2012. We follow the PDPA's access, correction, and retention obligations for those requests.
How to make a request
- Go to the Support page and choose "Privacy or data rights request", or email us with the subject "Privacy request".
- Tell us which right you want to exercise and which product, if any, it relates to.
- We verify the request by sending a code to the email address linked to your purchase. We do not ask for identity documents unless verification by email is not possible.
To delete saved reports or your account, make a deletion request through the privacy route. Some records, such as purchase and tax records, must be kept for the periods in section 8 even after a deletion request. We tell you when this applies.
11. Automated processing
Our products calculate figures and generate draft text from the information you enter. These drafts are for your own review. We do not make any decision about you by automated means that produces legal effects or similarly significant effects. Access to a product depends on an automatic check that a payment succeeded. If you think access was refused in error, contact support and a person will review it.
12. Data breaches
If a personal data breach occurs, we contain it, assess the risk, and notify the relevant authority and affected people where the law requires it, within the time the law sets. That includes the Personal Data Protection Commissioner in Malaysia and, where they apply, EU supervisory authorities and Singapore's Personal Data Protection Commission.
13. Children
Our services are restricted to business users aged 18 or over. By using the service, you warrant that you meet this age requirement. We do not knowingly collect personal data from children. If you believe a child has given us personal data, contact us and we will delete it.
14. Marketing choices
We send service emails that you need, such as sign-in codes, receipts, and important notices about a product you bought. We do not send marketing emails unless you have opted in. You can opt out at any time through the unsubscribe link or by contacting us.
15. Complaints and regulators
Please contact us first so we can try to resolve your concern. If you are not satisfied, you may complain to the relevant regulator:
- Malaysia: the Personal Data Protection Department.
- Singapore: the Personal Data Protection Commission.
- European Economic Area: the data protection supervisory authority where you live or work.
16. Changes to this notice
We update this notice when our processing changes. Each version has a version number and effective date at the top of the page. If a change materially affects how we use data you have already given us, we tell affected customers by email before the change applies.
Version 1.0. Effective date: 29 September 2026.