Legal
Privacy Policy
Last updated: 13 July 2026
Version 2.1
1. Introduction
This Privacy Policy explains how Code Tigris PLT ("Gydr", "we", "our", or "us"), a limited liability partnership registered in Malaysia (Registration No. LLP0038657-LGN / 202404001169), collects, uses, discloses, stores, and safeguards information when you access or use the Gydr customizable AI chatbot platform and related services (collectively, the "Services"), including via our website at gydr.ai, our console at console.gydr.ai, and embeddable chatbot widgets deployed through our platform. We act as the data controller for personal data of our customers (account holders) and as a data processor for personal data of end users interacting with chatbots deployed by our customers (see Section 2.3). By accessing or using the Services, you acknowledge that you have read, understood, and agree to be bound by this Privacy Policy. If you do not agree, you must discontinue use of the Services.
2. Information We Collect
2.1 Information You Provide
- Account registration information (name, email address, company name, phone number, display name)
- Billing and payment details, including billing name, email, phone number, and billing address (processed securely through third-party payment processors; we do not store full credit card numbers)
- Chatbot configuration data, skills, training content, knowledge base documents, product catalogues, and AI tool configurations you upload or create
- Third-party service credentials and configuration you provide when connecting external integrations (such as spreadsheet services or messaging platforms) through our AI tool system
- Communications with our support team or through contact forms
- Team member invitations and account management data (when you invite a team member, we collect their email address and display name to create an identity record on their behalf)
- Any other information you voluntarily provide to us through the Services
2.2 Information Collected Automatically
- Device and browser information (IP address, user agent, browser type, operating system, device category, language preferences)
- Usage data and analytics (pages visited, features used, session duration, click patterns)
- Real-time connection metadata (connection identifiers, timestamps, browser fingerprints derived from IP address and user agent for session management purposes in accordance with industry security guidelines)
- Visitor identifiers stored on end-user devices (via local storage and session storage) for session continuity and returning visitor recognition
- Credit usage and consumption metrics, including token counts and interaction records, for billing and account management purposes
- Audit trail data for security and compliance purposes, including records of account activity, data access, and administrative actions
- Approximate geographic information (country level) derived from IP addresses, and referral source information (domain only, no full URL)
- Log data, error reports, and performance metrics
- Cookies and similar tracking technologies
2.3 End-User Data
When end users interact with chatbot widgets deployed by our customers — including widgets embedded on third-party websites, hosted at Gydr-provided URLs, or displayed as chat bubbles on customer domains — we may process the following on behalf of our customers: chat messages and conversation history; session identifiers; visitor identifiers (which may be automatically generated or provided by the customer through their integration); IP addresses; user agent information; approximate geographic location (country level); device category; language preferences; and referral source (domain only). Visitor identifiers may be stored on the end user's device for session continuity purposes. Conversation data is persisted for the duration of the applicable retention period and may be archived to long-term storage for record-keeping purposes. In this capacity, Gydr acts as a data processor. Our customers (the chatbot operators) are the data controllers and are solely responsible for providing appropriate privacy notices to their end users and obtaining any required consents.
Where you (the chatbot operator) enable Bring Your Own Model ("BYOM"), end-user chat content is routed directly to the third-party LLM provider you have selected, using credentials you supply, and is subject to that provider's own terms, retention, and data-handling practices. See Section 6 and our Sub-processor List for the list of supported BYOM providers. Gydr does not control end-user chat data routed via BYOM beyond establishing the encrypted transit.
3. How We Use Your Information
We use the information we collect for the following purposes:
- To provide, operate, maintain, and improve our Services, including AI-powered chatbot functionality
- To process transactions, manage subscriptions, and administer credit balances
- To send technical notices, updates, security alerts, and support messages
- To respond to your comments, questions, and requests
- To monitor and analyze trends, usage, and activities for operational and business purposes
- To detect, investigate, and prevent fraudulent transactions, abuse, security incidents, and other harmful activities
- To maintain audit trails for security, compliance, and regulatory purposes, including in accordance with applicable international standards
- To facilitate AI tool integrations with third-party services that you configure (such as spreadsheet or messaging platforms), using credentials and configuration you provide
- To comply with applicable laws, regulations, legal processes, or governmental requests
- To enforce our Terms of Service and other agreements
- To create anonymized or aggregated data for analytics and service improvement (which is no longer personal data)
4. Legal Basis for Processing (EEA/UK Users)
If you are located in the European Economic Area (EEA) or United Kingdom, our legal basis for collecting and using your personal data depends on the context:
- Performance of a contract: Processing necessary to provide the Services you have requested
- Legitimate interests: Processing for our legitimate business interests (e.g., fraud prevention, security, analytics, service improvement), provided these are not overridden by your rights
- Consent: Where you have given explicit consent for a specific processing purpose
- Legal obligation: Processing necessary to comply with applicable laws
5. Data Storage, Security, and Retention
We implement commercially reasonable technical and organizational measures designed to protect your personal information against unauthorized access, alteration, disclosure, or destruction, including encryption at rest and in transit. However, no method of transmission over the Internet or method of electronic storage is 100% secure.
Code Tigris PLT follows the ISO/IEC 27001 information security management framework — encryption at rest (AES-256-GCM) and in transit (TLS 1.2+), role-based access controls, audit logging, secure-development practices, sub-processor risk management, and incident response. Code Tigris PLT is not currently certified to ISO/IEC 27001. Where ISO 27001 certification is a contractual requirement, please raise it during procurement so we can align expectations.
WE DO NOT WARRANT OR GUARANTEE THE SECURITY OF ANY INFORMATION YOU TRANSMIT TO US, AND YOU DO SO AT YOUR OWN RISK. We are not responsible for the circumvention of any privacy settings or security measures contained in the Services.
Your data may be stored and processed on servers located in various jurisdictions, including but not limited to Malaysia, the Asia-Pacific region, and other regions where our cloud infrastructure providers operate data centers.
Retention periods
We retain personal data only as long as necessary. Specific retention periods:
| Data category | Retention |
|---|---|
| Real-time connection records (WebSocket session metadata) | 24 hours |
| Client-side session data (localStorage / sessionStorage) | 24 hours |
| Purchased credits | 1 year from purchase (then expire) |
| Chat conversation data — Free tier | 7 days, after which conversations are deleted or archived to long-term storage per the customer's configuration |
| Chat conversation data — Starter tier | 30 days |
| Chat conversation data — Growth tier | 90 days |
| Chat conversation data — Scale tier | 180 days |
| Chat conversation data — custom monthly commitment | The retention period stated in your agreed custom plan; where no period was negotiated, the period for your subscription tier above applies |
| Audit trail records (security, compliance) | As required by applicable law; minimum 12 months |
| Account registration information | Duration of account + 6 years post-termination (for tax/legal recordkeeping) |
| Billing / payment records | 7 years (consistent with Malaysia Income Tax Act 1967 and Companies Act 2016 record-keeping requirements) |
If you downgrade between tiers, your future chat-data retention will match the new tier; historical chats already past the new tier's window may be deleted at the next scheduled deletion cycle.
Data Breach Notification
If we become aware of a personal data breach affecting your information, we will notify the Malaysia Personal Data Protection Commissioner as soon as practicable, and in any event within seventy-two (72) hours of becoming aware of the breach, in accordance with section 12B of the Personal Data Protection Act 2010 (as amended by the PDP (Amendment) Act 2024). Where the breach is likely to cause significant harm to affected individuals, we will also notify those individuals without unnecessary delay through the email address associated with the account or, where applicable, via the chatbot operator who is the data controller.
6. Data Sharing and Disclosure
We do not sell your personal information. We may share or disclose your information in the following circumstances:
- Service providers and sub-processors: Third-party vendors who assist in our operations (e.g., cloud hosting, payment processing, AI model providers, analytics), subject to contractual obligations of confidentiality. The current list is published at our Sub-processor List.
- AI model providers: Chat messages and content may be processed by third-party AI model providers and their underlying foundation model providers to generate chatbot responses. These providers may process data in accordance with their own terms and privacy policies
- Customer-configured external integrations: When customers connect third-party services through our AI tool system (such as spreadsheet platforms or messaging services), data may be transmitted to those third-party services using credentials and configuration provided by the customer. This may include chat conversation data, end-user information, or other content relevant to the integration. Gydr facilitates these connections but does not control the third-party services' data handling practices
- Professional advisors: Lawyers, accountants, auditors, and insurers where necessary
- Law enforcement and legal requirements: When required by applicable law, regulation, legal process, or governmental request, or to protect our rights, safety, or property
- Business transfers: In connection with a merger, acquisition, reorganization, sale of assets, or bankruptcy, your information may be transferred as a business asset
- Partners: If your account is managed by a partner (reseller or distributor), certain account information, usage data, and credit balance information may be shared with that partner to facilitate account management, credit allocation, and billing administration
- With your consent: In any other circumstance where you have provided explicit consent
7. International Data Transfers
Your personal data may be transferred to and processed in countries other than your country of residence. Where we transfer data outside Malaysia, we rely on the framework set out in section 129 of the PDPA 2010 (as amended in 2024), which permits transfers to jurisdictions whose law is substantially similar to the PDPA or that ensure an adequate level of protection at least equivalent to the protection afforded by the PDPA, and on additional safeguards (such as standard contractual clauses) where required.
Our primary infrastructure provider operates data centres in Singapore (AWS region ap-southeast-1). Where you use BYOM, your data may transit to additional jurisdictions based on the provider you have chosen — see the Sub-processor List for the geographic footprint.
If you are located in the European Economic Area or United Kingdom, transfers from the EEA/UK to Malaysia are made on the basis of appropriate safeguards under GDPR Chapter V (typically, Standard Contractual Clauses).
8. Your Rights
Subject to applicable law, you may have certain rights regarding your personal information, including:
- Access your personal information and obtain a copy
- Correct inaccurate or incomplete data
- Request deletion or erasure of your data (subject to legal retention requirements)
- Object to or restrict processing of your data
- Data portability (receive your data in a structured, machine-readable format)
- Data portability under PDPA s.43A (where technically feasible and the data format is compatible) — you may request that personal data we hold about you be transmitted directly to another data controller
- Withdraw consent at any time (without affecting the lawfulness of prior processing)
- Lodge a complaint with a supervisory authority
To exercise any of these rights, please contact us. We may require verification of your identity before processing your request. We will respond within the timeframe required by applicable law. Please note that certain data may be exempt from such requests under applicable law, and we may need to retain certain information for legitimate business purposes or to comply with our legal obligations.
Please note that exercising any data rights does not affect your payment obligations or entitle you to any refund. For details on our refund and billing policies, please refer to our Terms of Service.
If you believe we have not complied with your data protection rights, you may also lodge a complaint with the Department of Personal Data Protection (Jabatan Perlindungan Data Peribadi, JPDP) of Malaysia, the supervisory authority under the PDPA. For EEA/UK data subjects, you may lodge a complaint with your local supervisory authority.
9. Cookies and Tracking Technologies
We use cookies and similar tracking technologies (such as web beacons and local storage) to collect and track information and to improve and analyze our Services. Cookies are small data files stored on your device. We use:
- Essential cookies: Required for the operation of our Services (e.g., authentication, session management)
- Analytics cookies: Help us understand how our Services are used and improve performance
- Preference cookies: Remember your settings and preferences (e.g., language selection)
You can manage your preferences at any time via the "Cookie Preferences" link in the footer, or by following the controls described in our Cookie Policy.
10. Third-Party Services and Links
Our Services may contain links to third-party websites, services, or integrations that are not operated by us. We have no control over, and assume no responsibility for, the content, privacy policies, or practices of any third-party services. We strongly advise you to review the privacy policy of every third-party service you interact with.
11. AI-Generated Content and Data Processing
Our Services utilize artificial intelligence and machine learning technologies to generate chatbot responses. By using our Services:
- You acknowledge that chat messages and uploaded content may be processed by AI models to generate responses
- You acknowledge that content you upload (including product catalogues, knowledge base documents, and training data) may be transformed into vector embeddings — mathematical representations stored for retrieval purposes
- You acknowledge that our AI tool system may connect to third-party services (such as spreadsheet platforms or messaging services) using credentials and configuration provided by our customers, and that data exchanged through these connections is subject to those third parties' data handling practices
- You understand that AI-generated outputs may be inaccurate, incomplete, or unsuitable for any particular purpose
- You are solely responsible for reviewing, validating, and approving any AI-generated content before relying upon it
- We do not guarantee the accuracy, reliability, completeness, or suitability of any AI-generated output
For disclaimers and limitations of liability relating to AI-generated content, please refer to our Terms of Service.
12. Malaysia PDPA Compliance
In compliance with the Personal Data Protection Act 2010 (Act 709) as amended by the Personal Data Protection (Amendment) Act 2024 (Act A1727) in force from 1 June 2025, we process personal data in accordance with the seven PDPA principles:
- General Principle (s.6) — we process personal data only with consent or on another lawful basis.
- Notice and Choice Principle (s.7) — this Privacy Policy provides notice in English and Bahasa Malaysia (a translated copy is available on request).
- Disclosure Principle (s.8) — we disclose personal data only to sub-processors listed at /sub-processors and only for the purposes described in this Policy.
- Security Principle (s.9) — we implement encryption at rest (AES-256-GCM) and in transit (TLS 1.2+), access controls, and audit logging.
- Retention Principle (s.10) — see retention table in Section 5.
- Data Integrity Principle (s.11) — you may correct inaccurate data at any time via the Console or by emailing privacy@gydr.ai.
- Access Principle (s.12) — you may request a copy of personal data we hold about you.
In addition, pursuant to the 2024 amendments:
- We have appointed a Data Protection Officer (DPO) as required by section 12 of the amended PDPA. The DPO is contactable at privacy@gydr.ai.
- We commit to the 72-hour breach notification timeline under section 12B (see Section 5 above).
- Where you are a Malaysian data subject and you exercise the new right of data portability under section 43A, we will respond within the timeframe set out in the PDP Commissioner's guidelines.
13. GDPR Compliance (EEA/UK Users)
If you are located in the European Economic Area or United Kingdom, you have additional rights under the General Data Protection Regulation (GDPR) or UK GDPR, including the right to erasure ("right to be forgotten"), the right to restrict processing, and the right to data portability. Where Gydr processes personal data on behalf of customers (as a data processor), we do so under appropriate data processing agreements. You may lodge a complaint with your local data protection supervisory authority if you believe we have violated your data protection rights.
Our customers are responsible for ensuring that, where their use of the Services produces legal or similarly significant effects on individuals (for example, in fully-automated decisions on lending, insurance, employment, eligibility, or pricing), they obtain explicit consent and provide for meaningful human review consistent with GDPR Article 22. By default, AI-generated chatbot responses on the Services are informational and do not produce such effects; customers configuring the Services for high-stakes automated decisions must impose appropriate controls themselves.
14. California Privacy Rights (CCPA/CPRA)
If you are a California resident, the California Consumer Privacy Act (CCPA) as amended by the California Privacy Rights Act (CPRA) provides you with rights regarding your personal information.
Categories of personal information collected (last 12 months): identifiers (name, email, IP address), commercial information (subscription and credit-usage data), internet activity information (usage data, log data), professional information (company name, role), geolocation data (country level), and inferences drawn from the above.
Categories of sources: directly from you (account registration, content uploads, support interactions), automatically (cookies, log data, device data), and from third-party services you connect (e.g., payment processor returning billing metadata).
Business purposes: providing the Services, billing, security, fraud prevention, analytics, customer support, and legal compliance.
Categories of third parties to whom we disclose: cloud infrastructure providers, payment processors, AI model providers, analytics services, and (when enabled by you) integration partners — see our Sub-processor List for the full list.
We do not sell or share (as those terms are defined in the CCPA/CPRA) your personal information.
Your CCPA/CPRA rights include the right to know, the right to delete, the right to correct, the right to limit use of sensitive personal information, and the right to opt out of the sale or sharing of personal information. We will not discriminate against you for exercising these rights. To exercise any right, email privacy@gydr.ai with subject line "CCPA Request". We may ask for verification of your identity before responding.
15. "Do Not Track" Disclosure
Some web browsers may transmit "Do Not Track" (DNT) signals to the websites you visit. We currently do not respond to "Do Not Track" signals. We will continue to review and assess new technologies and will update this disclosure if our practices change in the future.
16. Children's Privacy
Our Services are not intended for individuals under the age of 18 (or the applicable age of majority in your jurisdiction). We do not knowingly collect personal information from children. If we become aware that we have collected personal information from a child without verification of parental consent, we will take steps to delete that information. If you believe we may have collected information from a child, please contact us immediately.
17. Changes to This Policy
Gydr reserves the right to update, modify, or replace this Privacy Policy at any time and at our sole discretion. Changes become effective immediately upon posting of the revised Privacy Policy on this page. We will update the "Last updated" date at the top of this page to reflect the date of the most recent revision. For material changes, we may also provide notice through the Services or via email. Your continued use of the Services following the posting of any changes constitutes your acceptance of those changes. We encourage you to review this Privacy Policy periodically to stay informed about how we protect your information.
18. Contact Us
If you have any questions, concerns, or complaints about this Privacy Policy or our data practices, contact us by email:
- Data Protection Officer (DPO): privacy@gydr.ai
- General Privacy Inquiries: privacy@gydr.ai
Code Tigris PLT's registered office address is on file with the Companies Commission of Malaysia (SSM) and is available on the public SSM register (search for LLP No. LLP0038657-LGN). Where formal postal correspondence is required (for example, service of legal process or a regulatory notice), please first email legal@gydr.ai so we can confirm the current registered office in writing.
We endeavour to respond to all inquiries within thirty (30) days, or sooner where required by applicable law.
19. Changelog
- v2.1 — 13 July 2026 — Retention table corrected to match the current plan structure: chat conversation data is retained by subscription tier (Free, Starter, Growth, Scale), and customers on a custom monthly commitment are retained for the period stated in their agreed plan.
- v2.0 — 28 May 2026 — Substantial rewrite to reflect the PDP (Amendment) Act 2024 (effective 1 June 2025): DPO contact, 72-hour breach notification under s.12B, data portability under s.43A, updated cross-border transfer basis under amended s.129. Tier-by-tier retention table added. BYOM data routing disclosed. CCPA disclosure expanded. Entity identified as Code Tigris PLT.
- v1.0 — 26 February 2026 — Initial publication.