Privacy Policy · 隐私政策
Last updated / 最后更新:2026-10-07
This Privacy Policy is provided in English and Chinese. If there is any inconsistency, the English version prevails. 本隐私政策提供英文和中文版本,如有不一致,以英文版为准。
1. Who we are / 我们是谁
This service is operated by KOVA AI SOLUTIONS ("we"). This policy explains how we handle personal data under Malaysia's Personal Data Protection Act 2010 (PDPA), as amended.
本服务由 KOVA AI SOLUTIONS("我们")运营。本政策说明我们如何依照马来西亚《2010年个人数据保护法》(PDPA)及其修订处理个人数据。
2. Data we collect / 我们收集哪些数据
Merchant account data: business name, industry, email address, login credentials (passwords are stored hashed by our authentication provider), language preference and subscription/billing records.
Customer conversation data processed on behalf of merchants: names, phone numbers or platform user IDs, message contents, order and tracking numbers received from connected platforms (WhatsApp, Facebook, Instagram, Shopee, Lazada, TikTok Shop).
Platform authorisation tokens that merchants grant us to send and receive messages. These are stored encrypted.
商家账户数据:店铺名称、行业、邮箱、登录凭证(密码由认证服务商加密散列保存)、语言偏好、订阅和付款记录。
代商家处理的顾客对话数据:已连接平台(WhatsApp、Facebook、Instagram、Shopee、Lazada、TikTok Shop)传来的顾客姓名、电话或平台用户ID、消息内容、订单号和物流单号。
商家授权我们收发消息所用的平台授权密钥,加密保存。
3. How we use it / 用途
To provide the service: receive customer messages, generate and send AI replies in the merchant's brand voice, escalate conversations to the merchant's staff, show analytics, and process subscription payments.
We do not sell personal data and do not use customer conversations to advertise to them.
用于提供服务:接收顾客消息、按商家话术风格生成并发送AI回复、转交商家客服处理、显示数据统计、处理订阅付款。我们不出售个人数据,也不会用顾客对话向顾客投放广告。
4. Roles / 各方角色
For customer conversation data, the merchant is the data user (controller) and we process it on the merchant's instructions. Merchants are responsible for informing their customers that an automated assistant may reply on their behalf.
对于顾客对话数据,商家是数据使用者(控制者),我们按商家的指示处理。商家有责任告知其顾客:可能由自动化助手代为回复。
5. Service providers and overseas transfer / 服务商与境外传输
We use the following processors, some of which store or process data outside Malaysia: Supabase (database and authentication), Vercel (hosting), Anthropic (AI reply generation), OpenAI (text embeddings for brand-voice matching), Razorpay/Curlec (payments), and the messaging platforms the merchant connects. Each is bound by its own data protection terms.
我们使用以下数据处理方,其中部分会在马来西亚境外存储或处理数据:Supabase(数据库和认证)、Vercel(网站托管)、Anthropic(生成AI回复)、OpenAI(话术语义匹配)、Razorpay/Curlec(付款),以及商家自行连接的消息平台。各方均受其自身的数据保护条款约束。
6. Retention / 保存期限
We keep data for as long as the merchant's account is active. When a merchant closes their account, we delete account data and conversation data within 30 days, except billing records we must keep under Malaysian tax law.
账户有效期间我们会保存数据。商家注销账户后,我们会在30天内删除账户和对话数据;依照马来西亚税务法规须保留的账单记录除外。
7. Security / 安全措施
Data is encrypted in transit (HTTPS). Platform tokens are encrypted at rest. Each merchant's data is isolated at the database level, and incoming platform messages are verified by signature before processing.
数据传输全程加密(HTTPS),平台授权密钥加密存储;每个商家的数据在数据库层面相互隔离;平台推送的消息先验证签名再处理。
8. Your rights / 您的权利
You may request access to, correction of, or deletion of your personal data, or withdraw consent, by emailing support@kovaai.my. We respond within 21 days. Customers of a merchant should first contact that merchant; we will assist the merchant in fulfilling the request.
您可以发邮件至 support@kovaai.my 要求查阅、更正或删除个人数据,或撤回同意,我们会在21天内回复。商家的顾客请先联系该商家,我们会协助商家处理。
9. Changes / 政策变更
We will notify merchants by email or in the dashboard before material changes take effect.
重大变更生效前,我们会通过邮件或后台通知商家。
Contact / 联系我们:KOVA AI SOLUTIONS · support@kovaai.my