Legal
Privacy Policy
How we handle personal data worldwide, on this site and in our work.
Who we are
This policy is published by Axtraction AI Sdn Bhd (no. 202301042335), a company registered in Malaysia with its office at Level 27 Penthouse, Centrepoint North, Mid Valley City, Lingkaran Syed Putra, 59200 Kuala Lumpur. Our group also includes Axtraction AI Limited (no. 79826532), registered in Hong Kong SAR at Unit 2A, 17/F, Glenealy Tower, 1 Glenealy, Central.
Axtraction AI Sdn Bhd decides how the personal data described here is handled, except where your agreement is with Axtraction AI Limited. In that case the Hong Kong company decides, and the same standards apply.
Our responsible privacy officer can be reached at privacy@axtraction.ai. We will give you their current contact particulars on request.
What this policy covers
This English policy is our global privacy notice. It applies wherever we do business, subject to any mandatory rights and duties under the law that applies to you. Our Bahasa Malaysia notice explains the position for Malaysia.
This policy covers personal data we control about people who visit axtraction.ai and people who contact us or work with us in a business capacity.
It also explains our role when personal data is held inside a customer's deployment. The customer controls that data; we handle it only on their instructions.
The website
axtraction.ai is a static site. It sets no cookies. It runs no analytics, no tracking pixels, and no third-party scripts. There is nothing to sign up for and no page asks you to submit anything. Even our typeface is served from our own domain, so opening a page sends no request to any domain other than ours.
The site is hosted on Google Cloud and served through its content delivery network. As with any website, the hosting provider processes standard technical request data such as your IP address, the page requested, and your browser's user agent. That is what makes it possible to deliver the page and to keep the site available and secure. We do not use it to profile you and we do not combine it with anything else.
When you email us
Email is the only contact channel on this site. If you write to us, we receive whatever you choose to send: usually your name, your email address, the organisation you work for, and the content of your message.
Providing personal data to us is voluntary, and you choose what to include. If what you provide is not enough for us to identify or answer your request, we may be unable to respond or take the step you ask for. If information is mandatory for a contract or legal requirement, we will tell you when we collect it and explain what happens if you do not provide it.
We use this information to answer you and keep a record of our dealings with you if a working relationship follows. Under Malaysian law we rely on your consent, given by choosing to write to us, and on the need to take steps at your request before entering into an agreement. Where the GDPR applies to a particular case, we rely on our legitimate interest in answering enquiries and in managing business relationships.
Sometimes your details reach us another way: you hand over a card at an event, a colleague introduces you, or a customer or partner passes on a contact. We record the same kind of business details and the source available to us in that case. We will tell you that source where the law requires it or if you ask us.
No automated system makes decisions about you based on what you send. A person reads your message.
Please do not send sensitive material by email. It is not a secure channel. Tell us what you need to share and we can arrange a safer route.
Email we send you
If you are a business contact, we may write to you about our products and what we are building. To do that we use your name, work email address, job title, the organisation you work for, and our record of earlier conversations. We write only about Axtraction AI's own products and services, never on behalf of anyone else, and we do not pass your details to another company so that it can market to you.
You can ask us to stop at any time, at no cost. Reply to any message and say so, or write to privacy@axtraction.ai. We act on your request and we do not ask you to give a reason.
Who else handles your data
We keep the number of companies that touch your data small, and each is bound by contract terms that limit what they may do with it.
- Google Cloud hosts this website and its content delivery network.
- Microsoft provides our company email, so a message you send us is stored in a Microsoft 365 mailbox.
- Our customer relationship management provider holds business contact details and a record of our correspondence, so the team can pick up a conversation without asking you to repeat yourself.
These providers run infrastructure in more than one country, so your data may be handled outside Malaysia. Each is engaged on data protection terms that require them to handle it only on our instructions and to protect it wherever it sits. Where the Malaysian PDPA applies, we make a cross-border transfer only on a basis permitted by section 129 and keep a record of the basis used. We do not sell personal data.
How long we keep your contact details
Business contact details and correspondence stay with us while we have, or reasonably expect to have, a working relationship with you or the organisation you represent, and for up to seven years after we last hear from you. Government and enterprise relationships go quiet for long stretches and then pick up again, so a short clock would mean asking you to repeat a conversation we already had.
Seven years is not an arbitrary figure. It matches the period we are required to keep business records under Malaysian and Hong Kong tax and company law, and it outlasts the six-year window for bringing a contract claim in either place. Running contact records on the same clock gives us one retention rule to follow instead of several.
Technical request data handled by our hosting provider is short-lived, and we do not retain it for analysis. You can ask us to delete what we hold about you sooner than seven years. We will do that unless we are required to keep it, and we will say so if that is the case.
Data inside a customer deployment
When we deploy a product for a customer, that customer decides what personal data goes into the system and what it is used for. They are the data controller. We act as a data processor on their instructions, under the agreement we hold with them.
The deployment model is recorded in the statement of work and is determined by who controls the operating environment: the customer's own cloud account, their own premises, or an environment we host for them. Unrelated customers are kept in separate environments, with logical separation between tenants. Where a customer's own group companies are named in the statement of work, they may share one environment. We do not use one customer's data for another customer.
Where a hosted deployment runs
For a deployment we host and run, the customer chooses Singapore or Frankfurt. The application infrastructure, network, storage, database and the application copy of customer content we retain all sit in that chosen region.
AI inference is different. It may use global endpoints, and it may be processed outside the chosen hosting region. Choosing a region does not mean every AI operation stays inside it. A customer with a mandatory location, provider or security requirement needs to tell us before deployment, so it can be written into the statement of work.
By default, inference runs through AI services we select and manage. These are paid enterprise services, and the supported providers are Google Cloud, including Vertex AI and Gemini; Amazon Web Services, including Bedrock; and Microsoft Azure, including Azure OpenAI and Microsoft Foundry. Not every provider is used for every customer. A customer can instead connect and pay for its own model under an agreed change to the statement of work.
We configure those services so that customer inputs and outputs are not used to train a provider's general models without permission. That is not a promise of zero retention on the provider's side. Limited caching, safety, abuse-monitoring, security and service-operation processing can still happen under the provider's own enterprise terms.
What a deployment keeps, and for how long
Our standard retention for application content is a rolling twelve months. Within that period we may keep the uploaded document or content, the submitted input, the extracted output and the generated response. That is what makes customer-visible history, support, billing verification, reliability work, accuracy investigation and prompt improvement possible.
Customer-visible history can include uploaded documents and the extracted or generated results, together with timestamps, user and system actions, source references, corrections, approvals, rejections, overrides and recorded outcomes. It does not expose our own prompt text, which remains our technology.
We may also keep operational and security records for up to twelve months: page counts, input and output token counts, request identifiers, provider and model version, errors and security events. Token counts are kept for billing and operational purposes even though usage is charged per processed page. Records may be kept longer where an active incident, dispute, legal claim or legal obligation requires it.
We do not reuse one customer's content for another customer, and we do not use it to train a general model. We improve our own prompt templates, orchestration and extraction accuracy from what we learn about performance, in a form that neither discloses nor reproduces customer content.
A customer can ask us to delete identified content before the standard period ends. Early deletion is not the default, and we explain the effect first: it can remove history and limit support, reprocessing, accuracy investigation and auditability.
The full terms are in the End User Data Processing Addendum, published so a customer can read it before being asked to sign anything.
Automated processing in a deployment
Our products carry out automated processing, including profiling. They assist qualified people and do not make the final decision. Where an output feeds a decision about a person, the customer decides how it is used and is responsible for any impact assessment the law requires. We give them the documentation about how the system works so they can complete one.
If you believe your personal data sits inside a system we run for a customer and you want to exercise a right over it, contact that organisation. They hold the relationship with you and they decide. If you come to us instead, we pass your request to them.
Your rights
You can ask us to:
- give you a copy of the personal data we hold about you;
- correct it where it is wrong or out of date;
- delete it, or stop using it, where the law allows;
- stop sending you anything you did not ask for.
Depending on where you are, you may also be able to ask for your data in a portable form, object to processing we base on legitimate interests, or withdraw consent you gave earlier.
Email privacy@axtraction.ai or write by post to the Privacy Officer, Axtraction AI Sdn Bhd, Level 27 Penthouse, Centrepoint North, Mid Valley City, Lingkaran Syed Putra, 59200 Kuala Lumpur. We may need to confirm who you are before we act. Requests are answered within the period set by applicable law, and sooner where we can.
If our answer does not satisfy you, you can complain to the data protection regulator where you live or work.
How we protect your data
Axtraction AI Sdn Bhd is certified to ISO 27001:2022 for information security management, within the scope stated in its current certificate. Traffic to this website is encrypted in transit. Access to our business systems is limited to the people who need it and is reviewed.
Children
Our products and this site are built for organisations, not for children. We do not knowingly collect personal data from children.
Changes to this policy
If we change this policy, the effective date at the top of this page changes with it. Where a change materially affects you, we will describe it here rather than quietly amend the text.
1 August 2026: We aligned the deployment, hosting, AI inference and content-retention descriptions with the End User Data Processing Addendum and End-User Licence Agreement.
Write to privacy@axtraction.ai.