← Back to Home

Privacy Policy

Last updated: April 2026

📌 Versi Bahasa Malaysia boleh dimuat turun di bawah. | BM version available below.

1. Information We Collect

CikguAI collects the following information when you use our service: your name, email address, school name, and the content you generate using our AI tools. We also collect usage data such as feature usage frequency and generation counts for service improvement.

2. How We Use Your Information

Your information is used to: provide and improve our AI teaching tools, manage your account and subscription, communicate important service updates, and ensure platform security. We do not sell your personal data to third parties.

3. Data Storage & Security

All data is stored securely on cloud infrastructure with encryption at rest and in transit. Each school/organization has isolated data that cannot be accessed by other tenants. We use industry-standard security practices including JWT authentication, rate limiting, and input validation.

4. AI-Generated Content

Content generated by CikguAI belongs to you. We do not use your generated content to train AI models. Uploaded files (PDF, DOCX, PPTX) are processed for content extraction only and are not stored permanently after processing.

5. Student Data

We collect minimal student data (names only, for comment and assessment generation). We do not collect student personal identification numbers, addresses, or sensitive information. Schools are responsible for obtaining appropriate consent for student data used in the platform.

6. Your Rights

You may request access to, correction of, or deletion of your personal data at any time by contacting us at max@aigcmy.com. You may also delete your account and all associated data through the Settings page.

7. Contact

For privacy-related inquiries, contact: AIGC SDN BHD, email: max@aigcmy.com, website: aigc.com.my

PDPA 2010 (Amendment 2024) Compliance

8. Data Protection Officer (DPO)

In accordance with the PDPA Amendment Act 2024, CikguAI has appointed a Data Protection Officer. For any data protection inquiries, requests, or complaints, please contact our DPO:

  • DPO Email: dpo@aigcmy.com
  • Organization: AIGC SDN BHD
  • Response time: Within 14 working days

9. Data Breach Notification

In the event of a personal data breach, CikguAI commits to notifying the Personal Data Protection Commissioner and affected data subjects within 72 hours of becoming aware of the breach, as required by the PDPA Amendment Act 2024. Notification will include the nature of the breach, data affected, remedial measures taken, and recommended actions for affected individuals.

10. Data Portability (Section 43A)

Under Section 43A of the PDPA Amendment Act 2024, you have the right to receive your personal data in a structured, commonly used, and machine-readable format (JSON). You can exercise this right through the Settings page by clicking "Export Data", or by contacting our DPO. We will fulfill data portability requests within 14 working days.

11. Right to Deletion (Right to be Forgotten)

You have the right to request the deletion of your personal data. Upon receiving a valid deletion request, we will: soft-delete your data immediately, permanently erase all data within 30 days, and provide confirmation of deletion. Deletion requests can be made through the Settings page or by contacting our DPO. Note: some data may be retained as required by law (e.g., audit logs for compliance purposes).

12. Cross-Border Data Transfer

CikguAI may process data using cloud services located outside Malaysia. In such cases, we ensure that adequate safeguards are in place as required by the PDPA, including contractual obligations with our service providers to maintain equivalent data protection standards.

Dasar Privasi (Versi Bahasa Malaysia)

CikguAI komited untuk melindungi data peribadi anda selaras dengan Akta Perlindungan Data Peribadi 2010 (Pindaan 2024). Untuk versi penuh Bahasa Malaysia, sila hubungi Pegawai Perlindungan Data kami di dpo@aigcmy.com.

  • Hak untuk mengakses dan membetulkan data peribadi anda
  • Hak untuk pemindahan data (Seksyen 43A)
  • Hak untuk memadamkan data (Hak untuk Dilupakan)
  • Pemberitahuan pelanggaran data dalam masa 72 jam
  • Pegawai Perlindungan Data (DPO) dilantik