Skip to main content

Privacy Policy

DERYK YEO & CO (Business Registration No. 002945678-K) — the registered business operating the AIGC brand
Effective date: 1 November 2024 · Last updated: 7 August 2026

1. Introduction

This Privacy Policy describes how DERYK YEO & CO (Business Registration No. 002945678-K · Firm No. AF002288), the registered business under which the AIGC services are operated, together with its affiliated companies AIGC Sdn. Bhd. (Company Registration No. 202401046806, Malaysia) and AIGC (S) PTE. LTD. (202607120E, Singapore) (collectively, "AIGC", "we", "us" or "our"), collects, uses, discloses, stores, transfers and deletes personal data when you:

  • visit our websites at aigc.com.my and aigcmalaysia.com (the "Sites");
  • use our AI content-generation platform, including AI avatar, voice cloning, video generation and related services (the "Platform");
  • register for or attend our training courses, workshops and events;
  • interact with us or with our business clients through messaging and social channels that we integrate, operate or automate — including products offered by Meta Platforms, Inc. such as the WhatsApp Business Platform, Messenger, Instagram and Facebook (see Section 5).

We are committed to processing personal data in accordance with the Malaysian Personal Data Protection Act 2010 ("PDPA") and, where applicable to individuals in other jurisdictions, other applicable data protection laws, including the EU/UK General Data Protection Regulation ("GDPR") and the Singapore Personal Data Protection Act 2012.

By using our Sites or services, you acknowledge that you have read and understood this Privacy Policy. If you do not agree with it, please do not use our services.

2. Who is responsible for your data

For data we collect for our own purposes (website visitors, students, Platform users, customers), DERYK YEO & CO (002945678-K) is the data controller / data user.

Where we provide technology services to business clients — for example building, hosting or operating messaging automations, chatbots, customer-relationship tooling or advertising integrations on their behalf — the business client is the data controller and AIGC acts as a data processor / service provider, processing personal data solely on the client's documented instructions. In those cases, the client's own privacy policy governs how your data is used, and this Policy explains our role as their technology provider.

3. Personal data we collect

3.1 Data you provide directly

  • Identity & contact data — name, email address, phone number, company name, job title;
  • Registration data — course/event sign-up details, industry, experience level, learning goals, names of additional participants registered by a company;
  • Payment data — billing details and transaction records. Card payments are processed by Stripe; we never receive or store your full card number;
  • Content you upload to the Platform — photos, videos, voice recordings and scripts used to create AI avatars, voice clones and generated videos;
  • Communications — messages you send us via forms, email, WhatsApp or social channels.

3.2 Data collected automatically

  • Usage & device data — IP address, browser type, device information, pages visited, referring URLs and interaction events, collected via cookies and similar technologies (see Section 12);
  • Platform logs — feature usage, generation jobs, credit consumption and security logs.

3.3 Data received from third parties

  • Meta Platform Data — data received through Meta's APIs and business tools when you or a business you interact with uses our Meta-integrated services (detailed in Section 5);
  • Payment confirmations from Stripe and banks (e.g. FPX);
  • Analytics data from providers such as Google Analytics.

4. How and why we use personal data

We use personal data only for the following purposes and on the following legal bases:

  • To deliver our services — creating your account, generating AI content you request, delivering courses, issuing certificates, invoices and official receipts (performance of a contract);
  • To operate messaging & automation services for business clients — routing, storing and responding to messages, running chatbots and workflows on the client's instructions (performance of a contract / client's instructions as controller);
  • To process payments and maintain accounting records (legal obligation and contract);
  • To provide customer support and respond to enquiries (legitimate interest / contract);
  • To send service notifications — enrolment confirmations, class reminders, receipts (contract);
  • To send marketing communications about our courses and products, where permitted — you may opt out at any time (consent / legitimate interest with opt-out);
  • To improve and secure our Sites and Platform — analytics, debugging, fraud and abuse prevention (legitimate interest);
  • To comply with law — tax, accounting, regulatory and law-enforcement obligations (legal obligation).

We do not sell personal data. We do not use AI-generated likenesses or voice clones of any person except as directed by the account holder who uploaded them.

5. Data from Meta platforms (Platform Data)

AIGC provides technology services that integrate with products offered by Meta Platforms, Inc. and its affiliates, including the WhatsApp Business Platform (Cloud API), Messenger Platform, Instagram APIs, Facebook Pages, Facebook Login and the Meta Marketing API. In this role we may act as a technology provider ("Tech Provider") processing Platform Data on behalf of our business clients.

5.1 What Platform Data we process

  • Message content and metadata sent to or from a business's WhatsApp, Messenger or Instagram account that we service (e.g. text, media, timestamps, sender phone number or handle);
  • Contact and profile information made available through the relevant Meta API (e.g. display name, WhatsApp phone number);
  • Page, ad-account and campaign data of our clients where they authorise us to manage advertising;
  • Basic profile information (name, email) if you choose to log in with Facebook.

5.2 How we use Platform Data

  • Solely to provide and improve the specific services requested by the business client — such as customer messaging, chatbot automation, appointment booking, order notifications, lead management and campaign reporting;
  • We process Platform Data in accordance with the Meta Platform Terms, the WhatsApp Business Terms and Meta's Developer Policies;
  • We do not sell, license or rent Platform Data to anyone;
  • We do not use Platform Data to build or augment user profiles for advertising, to train foundation models, or for any purpose unrelated to the service requested;
  • We do not combine Platform Data across different clients.

5.3 Sharing, retention and deletion of Platform Data

  • Platform Data is shared only with the business client on whose behalf it is processed and with the sub-processors listed in Section 6 that are necessary to host and deliver the service;
  • Platform Data is retained only for as long as needed to provide the service, and is deleted or irreversibly anonymised when the client relationship or the relevant integration ends, when the data is no longer required, or when Meta or the client requires its deletion — whichever comes first;
  • If you are an end user messaging one of our clients and want your data deleted, you may contact that business directly, or contact us (Section 14) and we will pass the request to the relevant client and delete data we hold as their processor within 30 days;
  • We will promptly report any unauthorised access to Platform Data to the affected client and, where required, to Meta and the relevant authorities.

6. How we share personal data

We share personal data only with:

  • Service providers (sub-processors) who help us run our business, bound by confidentiality and data-protection obligations:
    • Cloud hosting & storage — Amazon Web Services (Malaysia / Singapore regions) and Vercel;
    • Payments — Stripe;
    • Email delivery — Resend / Amazon SES;
    • Analytics — Google Analytics;
    • AI processing vendors used to fulfil generation jobs you request;
  • Meta Platforms, Inc. — messages and API calls necessarily pass through Meta's infrastructure when you use WhatsApp, Messenger or Instagram;
  • Our business clients — where we process data on their behalf as described in Sections 2 and 5;
  • Professional advisers and authorities — auditors, lawyers, tax authorities, regulators or law enforcement where required by law;
  • A successor entity in the event of a merger, acquisition or asset sale, subject to this Policy.

We never sell or rent personal data to third parties for their own marketing.

7. Data retention

  • Account & Platform data — kept while your account is active, deleted or anonymised within 90 days of verified account deletion;
  • Uploaded likeness / voice data — kept while the related avatar or voice model exists; deleted upon your deletion request;
  • Invoices, receipts & transaction records — kept for 7 years as required by Malaysian tax and companies legislation;
  • Marketing data — kept until you opt out or after 24 months of inactivity;
  • Meta Platform Data — see Section 5.3;
  • Server & security logs — up to 12 months.

8. Data security

  • All data in transit is encrypted with TLS; data at rest is stored on encrypted infrastructure (AWS);
  • Access to personal data is restricted to authorised personnel on a need-to-know basis, protected by authentication and role-based access controls;
  • Access credentials and API tokens are stored in managed secret stores, never in source code;
  • We maintain logging, monitoring and an incident-response process. If a data breach is likely to result in serious harm, we will notify affected individuals, affected clients and the relevant authorities without undue delay.

9. International data transfers

Our primary infrastructure is located in Malaysia (AWS ap-southeast-5, Kuala Lumpur) and Singapore. Some service providers (e.g. Stripe, Google, Meta, Vercel) may process data in other countries, including the United States. Where personal data is transferred outside Malaysia, we take reasonable steps to ensure it receives a level of protection consistent with the PDPA and, where GDPR applies, that appropriate safeguards such as Standard Contractual Clauses are in place.

10. Your rights

Subject to applicable law, you have the right to:

  • Access the personal data we hold about you;
  • Correct inaccurate or incomplete data;
  • Delete your data (see Section 11);
  • Withdraw consent to processing based on consent, including opting out of marketing at any time;
  • Limit or object to certain processing;
  • Data portability, where GDPR applies;
  • Complain to a supervisory authority — in Malaysia, the Personal Data Protection Department (JPDP).

To exercise any right, contact us using the details in Section 14. We will respond within 21 days for PDPA requests and within one month where GDPR applies. We may need to verify your identity before acting on a request.

11. Data deletion instructions

You may request deletion of your personal data at any time:

  • Email max@aigcmy.com with the subject "Data Deletion Request", from the email address associated with your data, stating what you would like deleted (e.g. account, avatar/voice data, messages); or
  • WhatsApp us at +6011-8888 1329.

We will confirm receipt, verify your identity, and complete deletion within 30 days, except for records we are legally required to retain (e.g. tax invoices). If your data is held by one of our business clients for whom we act as processor, we will forward your request to them and delete the copies we process on their behalf.

If you used Facebook Login to access any of our services, you can also remove the app from your Facebook settings (Settings & Privacy → Settings → Apps and Websites), then submit a deletion request as above and we will delete the associated data.

12. Cookies and analytics

Our Sites use a small number of cookies and similar technologies:

  • Essential cookies — required for security and core functionality (e.g. payment checkout sessions);
  • Analytics — Google Analytics (GA4), used in aggregate to understand site traffic and improve content. IP addresses are processed by Google as described in Google's privacy documentation;
  • Meta Pixel — where used on marketing pages, to measure advertising effectiveness. You can control ad preferences in your Facebook settings.

You can disable cookies in your browser settings; essential features may stop working. Where required by law we will ask for your consent before setting non-essential cookies.

13. Children

Our services are intended for individuals aged 18 and above, or minors enrolled in our training programmes with the consent of a parent or guardian. We do not knowingly collect personal data from children under 13. If you believe a child has provided us personal data, contact us and we will delete it.

14. Contact us

Data protection contact (Personal Data Protection Officer):

  • Registered business: DERYK YEO & CO (002945678-K · Firm No. AF002288) — operating the AIGC brand
  • Affiliated companies: AIGC Sdn. Bhd. (202401046806, Malaysia) · AIGC (S) PTE. LTD. (202607120E, Singapore)
  • Address: Lot 9071, 1st Floor, Batu 2 1/4, Jalan Bakri, 84000 Muar, Johor, Malaysia
  • Email: max@aigcmy.com
  • WhatsApp: +6011-8888 1329

15. Changes to this Policy

We may update this Privacy Policy from time to time. The "Last updated" date at the top shows the latest revision. Material changes will be announced on our Sites or notified to registered users by email. Continued use of our services after an update constitutes acceptance of the revised Policy.