Privacy Notice
Effective date: 4 October 2026
This Privacy Notice explains how CoreGen AI Sdn. Bhd. ("CoreGen AI", "we", "us" or "our") collects, uses, discloses, stores and otherwise processes personal data when you use our websites, applications, AI Search, AI Audit and related services. CoreGen AI is committed to handling personal data in accordance with applicable Malaysian data-protection law, including the Personal Data Protection Act 2010 and applicable amendments, regulations and guidelines.
1. Personal data we may collect
- Account and identity data, such as your name, email address, organisation, role, authentication identifiers and account status.
- Contact and support data, such as messages, enquiries, approval requests and communications with CoreGen AI.
- Billing and transaction data, such as plan, invoice, payment status, bank-transfer reference or receipt information. Where a third-party payment provider processes card payments, CoreGen AI does not need to receive or store your complete payment-card details unless expressly stated.
- Usage data, such as selected AI engines, questions, prompts, websites, URLs, run history, credit usage, generated reports, feature interactions and timestamps.
- AI Audit engagement data, such as organisation name, website/domain, agreed competitors, priority questions, public digital-surface data, audit findings and engagement communications.
- Technical and security data, such as IP address, device/browser information, authentication events, diagnostic logs, security events, rate-limit information and service telemetry.
- Cookie and similar technology data where used for essential session, authentication, preference, analytics or security purposes.
- Personal data contained in prompts, public web pages, source material or reports. Users should avoid submitting unnecessary sensitive personal data.
2. How we obtain personal data
- Directly from you when you register, sign in, request access, contact us, purchase a Service, submit a question, provide a website/domain or otherwise interact with CoreGen AI.
- From identity providers used for authentication, such as Microsoft Entra External ID or a supported social identity provider.
- From payment, email, cloud, security and other service providers supporting the Services.
- From publicly available online sources when performing AI Search, AI Audit, citation analysis, source analysis or related research at your request.
- Automatically through logs, telemetry, cookies and similar technologies when you use the Services.
3. Purposes of processing
- To create and administer accounts and authenticate users.
- To review and approve access requests and allocate trial or paid credits.
- To provide AI Search, AI Audit, reports, dashboards, history and related product functionality.
- To process payments, invoices, receipts and account balances.
- To send transactional and service communications, including approval, account, security and operational messages.
- To provide customer support and respond to enquiries.
- To protect the Services, prevent abuse, investigate security issues and enforce our Terms.
- To diagnose errors, maintain availability and improve reliability, usability and performance.
- To analyse usage in aggregated or de-identified form and improve the Services.
- To comply with legal, regulatory, tax, accounting, audit and law-enforcement obligations.
- To establish, exercise or defend legal claims and protect the rights, safety and property of CoreGen AI, users and third parties.
4. AI processing and selected AI providers
When you run AI Search or another AI-enabled feature, your question, selected context and limited related information may be transmitted to the AI, search or model provider required to perform that run.
Depending on the selected engine and feature, these providers may include Microsoft, OpenAI, Anthropic, Google, Perplexity or other providers used by CoreGen AI from time to time.
CoreGen AI seeks to limit information sent to external providers to what is reasonably necessary for the requested service. You should not include sensitive or confidential personal information in prompts unless it is necessary and you are authorised to do so.
External AI providers process information under their own technical and contractual arrangements. Their models, results and retention practices may differ.
5. Public web and third-party source data
AI Search and AI Audit may retrieve, analyse, classify, cite or link to information available on public websites and third-party services.
Public information may include personal data about identifiable individuals where relevant to the user’s requested research. CoreGen AI processes such information only as reasonably necessary to provide the requested service and subject to applicable law.
CoreGen AI does not control the accuracy, availability or future modification of third-party source material.
6. Disclosure of personal data
- We may disclose personal data to cloud hosting, identity, AI/model, email, payment, security, analytics, customer-support and professional service providers that support the Services.
- We may disclose information to professional advisers, auditors, insurers, banks or prospective transaction advisers where reasonably necessary and subject to appropriate confidentiality obligations.
- We may disclose information where required by law, court order, regulatory request or valid legal process, or where reasonably necessary to protect rights, safety, security or the integrity of the Services.
- If CoreGen AI undergoes a merger, acquisition, financing, restructuring or sale of assets, personal data may be transferred as part of that transaction subject to applicable law.
- CoreGen AI does not sell personal data to advertisers.
7. International and cross-border processing
CoreGen AI is established in Malaysia, but some service providers, cloud systems, AI providers and technical infrastructure may process data in other countries.
Where personal data is transferred across borders, CoreGen AI will take reasonable steps to use lawful transfer mechanisms, contractual protections and security measures appropriate to the circumstances and applicable law.
8. Data retention
CoreGen AI retains personal data for as long as reasonably necessary for the purposes described in this Notice, including to provide the Services, maintain account history, resolve disputes, enforce agreements, meet legal/accounting obligations and protect security.
Retention periods vary by data type and purpose. Account, billing and contractual records may be retained for longer periods where required for legal, tax, audit or dispute purposes. Security and operational logs may be retained for shorter or longer periods according to risk and technical requirements.
When personal data is no longer reasonably required, CoreGen AI may delete, anonymise or securely archive it, subject to lawful retention obligations and technical backup cycles.
9. Security
CoreGen AI uses reasonable administrative, technical and organisational safeguards designed to protect personal data against unauthorised access, disclosure, alteration, loss or misuse.
No internet, cloud or AI service can be guaranteed to be completely secure. You are responsible for protecting your own devices, email accounts, authentication methods and credentials.
Where a personal-data breach occurs, CoreGen AI will assess and respond to it in accordance with applicable legal and regulatory requirements.
10. Your rights and choices
Subject to applicable law, you may request access to personal data CoreGen AI holds about you and request correction of inaccurate or incomplete personal data.
Where processing is based on consent, you may withdraw consent, subject to legal and contractual consequences and to processing that is otherwise permitted or required by law.
Where applicable under law, you may request data portability or exercise other statutory data-protection rights.
You may opt out of non-essential marketing communications where offered. Transactional, security and account communications may still be sent where necessary to provide the Services.
You may contact CoreGen AI using the details below to exercise applicable rights or raise a privacy concern. CoreGen AI may need to verify your identity before completing a request.
11. Cookies and similar technologies
CoreGen AI may use essential cookies or similar technologies for authentication, session management, security, preferences and core functionality.
Where analytics or other non-essential technologies are used, CoreGen AI will provide appropriate notice and choices where required by applicable law.
Blocking essential cookies may prevent parts of the Services from functioning correctly.
12. Children
The Services are intended for adults and business/professional use and are not directed to children under 18. CoreGen AI does not knowingly invite children under 18 to create accounts for the Services.
13. Automated analysis and profiling
The Services use automated analysis to classify sources, identify patterns, generate summaries, compare AI outputs, detect gaps and produce other intelligence.
These automated outputs are informational and may be wrong. CoreGen AI expects users to apply human review before making material decisions.
CoreGen AI does not intend the Services to make solely automated legal or similarly significant decisions about individuals without appropriate human involvement.
14. Changes to this Privacy Notice
CoreGen AI may update this Privacy Notice from time to time to reflect product, legal, regulatory or operational changes. The updated Notice will state a new effective date and material changes will be communicated by a reasonable method where required.
15. Contact
For privacy questions, access/correction requests or complaints, contact:
CoreGen AI Sdn. Bhd.
Kuala Lumpur, Malaysia
Email: support@coregenai.com
Website: coregenai.com
