AXIONONE SDN. BHD.

Privacy Policy

How Xcent.ai collects, uses, discloses, and protects personal data.

AXIONONE SDN. BHD. (operator of the Xcent.ai platform)

Effective date: 28 July 2026. Version: 1.1

This Privacy Policy explains how AXIONONE SDN. BHD. (Company No. 202501015006 (1616421-P)) ("Xcent", "we", "us" or "our") collects, uses, discloses and protects personal data when you visit xcent.ai, create an account, or use the Xcent platform and related services (the "Service").

We handle personal data in accordance with the Personal Data Protection Act 2010 of Malaysia, as amended by the Personal Data Protection (Amendment) Act 2024 (the "PDPA"), and the guidelines issued by the Personal Data Protection Commissioner.

1. Two roles: controller and processor

1.1 For personal data about you as a visitor, account holder, or billing contact, Xcent acts as a data controller. This Policy governs that data.

1.2 When you use the Service to manage conversations and records belonging to your own customers and contacts ("Customer End-User Data"), Xcent acts as a data processor and you are the controller. Our handling of Customer End-User Data is governed by the Data Processing Terms in our Terms of Service, not by this Policy.

2. Personal data we collect

2.1 Data you provide

  • Account and identity data: name, business email, phone number, company name, job role, and login credentials.
  • Billing data: billing name, company address, and tax identification. Card and bank details are collected and stored by our payment processor, not by us.
  • Communications data: messages, enquiries, and support requests you send to us.
  • Marketing data: information you submit through advertisements, sign-up forms, event registrations, or lead forms.

2.2 Data collected automatically

  • Usage and device data: IP address, browser type, device identifiers, pages viewed, actions taken, and timestamps.
  • Cookies and similar technologies, as described in section 9.

2.3 Data from third parties

  • Data from advertising and analytics platforms (for example Meta), lead sources, and integrations you connect to your account.

We do not knowingly collect sensitive personal data about you as an account holder unless you choose to provide it. Where you route sensitive personal data of your own end-customers through the Service (for example financial information in insurance or automotive workflows), you do so as controller and remain responsible for the lawful basis of that processing.

3. How and why we use personal data

We process personal data for the following purposes. Where the PDPA requires consent, we rely on the consent you give when you register or submit your data. Where processing is necessary to perform our contract with you, to comply with law, or for our legitimate business interests, we rely on those bases to the extent permitted under the PDPA.

  • To create and administer your account and provide the Service.
  • To process payments, issue invoices, and manage subscriptions.
  • To provide customer support and respond to your enquiries.
  • To operate, secure, maintain, and improve the Service.
  • To send service messages, and, where you have consented, marketing about our products.
  • To comply with legal and regulatory obligations, and to detect and prevent fraud or misuse.

4. Direct marketing

4.1 We send marketing only where permitted. You may opt out at any time using the unsubscribe link in our messages or by contacting us at the address in section 12.

4.2 Under section 43 of the PDPA you have the right to require us to stop processing your personal data for direct marketing purposes.

5. Disclosure of personal data

We do not sell your personal data. We disclose it only to:

  • Service providers and subprocessors who help us run the Service, including cloud hosting and infrastructure providers, communication providers (such as the WhatsApp Business Platform operated by Meta, email delivery, and voice providers), payment processors, and analytics providers.
  • Professional advisers, auditors, and insurers, where reasonably required.
  • Authorities, regulators, or courts where required by law or to protect our rights.
  • A successor entity in connection with a merger, acquisition, or sale of assets, subject to this Policy.

We require our subprocessors to protect personal data to a standard consistent with the PDPA. A current list of subprocessors is available on request.

6. Cross-border transfer

6.1 Some of our providers store or process data on servers located outside Malaysia. Where we transfer personal data outside Malaysia, we do so in accordance with the PDPA and the Commissioner's guidance on cross-border transfers, and we take reasonable steps to ensure a comparable level of protection.

6.2 By using the Service, you acknowledge that your data may be processed outside Malaysia for the purposes set out in this Policy, including in countries where our cloud hosting, infrastructure, communications, payment, analytics, and support providers operate. These locations may include the United States, Singapore, the European Economic Area, and other jurisdictions where our subprocessors maintain systems or personnel.

7. Data retention

We keep personal data only for as long as necessary for the purposes described in this Policy, or as required by law. Account data is retained for the life of your account and for a reasonable period afterwards to meet legal, tax, audit, security, dispute-resolution, and accounting obligations, after which it is deleted or anonymised. Financial and transaction records are retained for at least 7 years in line with Malaysian tax and accounting requirements. Support messages, marketing records, technical logs, and security records are retained only for as long as needed for the relevant business, compliance, or security purpose.

8. Security

8.1 We apply technical and organisational measures designed to protect personal data against loss, misuse, and unauthorised access, including access controls, encryption in transit, and regular review of our systems.

8.2 No system is completely secure. If a personal data breach occurs that is likely to cause significant harm, we will notify the Personal Data Protection Commissioner and affected individuals in accordance with the PDPA, including within the 72-hour timeframe where it applies.

9. Cookies

We use cookies and similar technologies to keep you signed in, remember preferences, measure usage, secure the Service, and support marketing. Some cookies are necessary for the Service to work. Where we use optional analytics or advertising cookies, we provide notice and choices where required by applicable law. You can also control cookies through your browser settings. Disabling some cookies may affect how the Service works.

10. Your rights

Subject to the PDPA, you have the right to:

  • Request access to the personal data we hold about you (section 30).
  • Request correction of inaccurate or incomplete data (section 34).
  • Withdraw consent to processing (section 38).
  • Require us to stop processing for direct marketing (section 43).
  • Request data portability, where applicable under the amended PDPA.
  • Lodge a complaint with the Personal Data Protection Commissioner (Jabatan Perlindungan Data Peribadi).

To exercise any of these rights, contact us using the details in section 12. We may need to verify your identity and may charge a prescribed fee for access requests where the law allows.

11. Children

The Service is intended for businesses and is not directed at individuals under 18. We do not knowingly collect personal data from children.

12. Contact and data protection officer

If you have questions about this Policy or wish to exercise your rights, contact:

Data Protection Officer / Privacy Contact

AXIONONE SDN. BHD.

Registered office: A-11-1, Pusat Komersial Arena Bintang, Seksyen U5, 40150 Shah Alam, Selangor, Malaysia

Business address: 16, JALAN ANGGERIK VANILLA 31/93, SEKSYEN 31, KOTA KEMUNING, 40460 SHAH ALAM, Kota Kemuning, 40460 Kuala Lumpur, Selangor

Email: hello@xcent.ai Phone: 018 409 6771

13. Changes to this Policy

We may update this Policy from time to time. We will post the updated version with a new effective date, and where changes are significant we will take reasonable steps to notify you.

14. Governing law

This Policy is governed by the laws of Malaysia.