Privacy Policy
Baca notis ini dalam Bahasa Malaysia →This notice is issued in both the national language (Bahasa Malaysia) and English, as required by section 7(3) of the Personal Data Protection Act 2010. The Bahasa Malaysia version (Notis Privasi) is available at all times. In the event of any inconsistency between the two versions, the English version prevails.
1. Who we are
NUL TECHNOLOGY (Business Registration No. 202603148027 (003857548-W)) is a business registered in Malaysia under the Registration of Businesses Act 1956 and carried on as a sole proprietorship. NUL TECHNOLOGY operates the Othersmind platform and this website (othersmind.ai). "Othersmind" and "TK-C3" are product and brand names of NUL TECHNOLOGY; they are not separate legal entities.
Registered business address: A-15-02, VILLA ORKID BUKIT PRIMA PELANGI, JLN PELANGI 7, 51200 KUALA LUMPUR, WILAYAH PERSEKUTUAN, MALAYSIA.
For the purposes of the Personal Data Protection Act 2010 (Act 709) ("PDPA"), as amended by the Personal Data Protection (Amendment) Act 2024 (Act A1727), NUL TECHNOLOGY is the data controller of the personal data described in this notice. Our privacy and data protection contact is chiewaylee@gmail.com (see section 18).
Othersmind is a business-to-business platform for construction contractors. Our customers are businesses; the individuals whose personal data we process are typically our customers' personnel, and the people who correspond with a mailbox our customer connects to the platform.
2. About this notice
This notice explains how we collect, use, disclose, store and protect personal data when you use Othersmind or visit this website. It is issued under section 7 of the PDPA and reflects the PDPA as amended with effect from 2025, including the seven Personal Data Protection Principles (General; Notice and Choice; Disclosure; Security; Retention; Data Integrity; and Access), the data breach notification duty (section 12B), the data portability right (section 43A) and the amended cross-border transfer regime (section 129).
Where our customer (the business that holds a Othersmind subscription) asks us to process personal data contained in its own records — for example, correspondence in a mailbox it connects — we process that data to provide the service to that customer under our agreement with them. The customer is responsible for ensuring it is entitled to make that data available to us.
3. Personal data we collect
3.1 Account data
When you sign in with Google, we store: your name, email address, a Google account identifier, your sign-in method, your assigned role on the platform, and sign-in timestamps. We never see or store your Google password.
3.2 Gmail data (only if a mailbox is connected)
If your business connects a Gmail mailbox, we sync and store the following fields for recent inbox messages, and only these fields:
- Gmail message ID and thread ID;
- sender name and email address, and recipient email address;
- subject line;
- the short snippet (preview text) that Gmail provides for the message;
- Gmail label IDs and the received timestamp;
- whether the message has attachments (a yes/no flag only);
- labels our platform derives: a construction-workflow classification (for example "material approval", "RFI", "claim certificate"), an urgency level, read state, and links to the claim or document the email relates to.
What we do not collect: we do not read or store message bodies — messages are fetched in Gmail's metadata format only. We do not download or store attachments (we record only whether an attachment exists). We do not access contacts, calendar, Drive, or any other Google service, and we cannot send, modify or delete email (see section 4).
3.3 Project and operational data
Data your business enters into the platform: project details, progress claims and valuations, variation orders, purchase orders, supplier records (which may include supplier contact persons' names, email addresses and phone numbers), consultant contact details, document registers, schedules, checklists and notes.
3.4 Technical and audit data
Server logs (with authentication tokens and cookies automatically redacted), an audit trail of actions taken on the platform, agent run records (including AI agent inputs and outputs relating to your projects), in-app notifications, and a session cookie used to keep you signed in.
3.5 Website visitors
This marketing website sets no analytics or advertising cookies and runs no trackers. Web fonts are loaded from Google Fonts, which means your browser sends your IP address to Google when the page loads.
3.6 Whether providing data is obligatory
Account data is required to provide the service — without it we cannot give you access. Connecting a Gmail mailbox is optional: if you choose not to connect one, the platform's Gmail-related features will simply be unavailable, and the rest of the platform will still work.
3.7 Sources of personal data
We obtain personal data: directly from you (sign-in and data you enter); from the Gmail mailbox your business chooses to connect (which will include personal data of the people who correspond with that mailbox, such as consultants, suppliers and client representatives); and from records your business's authorised users enter about their colleagues and business contacts.
4. How we access Gmail data
Othersmind connects to Gmail through Google's official Gmail API, with your explicit consent given on Google's own consent screen. Our access is deliberately minimal:
- We request the
gmail.readonlyscope only — read-only access. - We never request scopes that would allow us to send, modify or delete email. The platform has no capability to send email from your mailbox, and it cannot alter or remove anything in your mailbox.
- Signing in to Othersmind is a separate flow that uses identity-only scopes (your name, email address and profile) — signing in alone gives us no access to any mailbox.
- Messages are fetched in metadata format: headers and the Gmail-provided snippet, never full message bodies, and never attachment contents.
You can revoke Othersmind's access at any time from your Google Account security settings at myaccount.google.com/permissions, which immediately invalidates our access. See section 12 for what disconnection does and does not delete.
5. Why we process personal data
We process personal data for the following purposes:
- to provide the Othersmind service: classifying synced emails into construction workflow categories, flagging urgency, linking correspondence to claims and approvals, tracking statutory payment-response timelines under CIPAA 2012, generating morning briefings, monitoring materials and approvals, and drafting documents for human review;
- to administer accounts, roles and project access;
- to secure the platform: authentication, access control, audit trails, abuse and incident investigation;
- to operate, maintain and improve the platform, including troubleshooting from redacted logs;
- to communicate service notifications; and
- to comply with legal obligations.
We do not use personal data for advertising, and we do not sell personal data to anyone.
6. Google API Limited Use disclosure
Limited Use
Othersmind's use of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements. Our use of information received from Google Workspace APIs also adheres to the Google Workspace API user data and developer policy, including its Limited Use requirements.
In practice this means, for all data Othersmind receives from Gmail:
- we use it only to provide and improve user-facing features that are prominent in Othersmind's interface — inbox classification, urgency flags, linking emails to claims and approvals, CIPAA deadline tracking and morning briefings;
- we transfer it to others only as necessary to provide those features (the service providers named in section 8), for security purposes, or to comply with applicable law;
- we do not use it for advertising of any kind, and we do not sell it;
- we do not allow humans to read it except with your affirmative agreement, where necessary for security purposes (such as investigating abuse), to comply with applicable law, or where it has been aggregated for internal operations as the policy permits; and
- we do not use it to create, train or improve any machine-learning or artificial-intelligence model — and our AI providers are contractually prohibited from training their models on it (see section 7).
7. AI processing of your data
Othersmind's agents use large language models (LLMs) operated by third-party providers. What is sent to the LLM provider is deliberately limited:
- Email classification: the subject line, the Gmail snippet, and the sender's name and address of a synced email — never message bodies or attachments, which we do not hold.
- Morning briefings: a summary of your projects' operational state — project names, contract and claim amounts, claim statuses, and findings from other agents.
- Draft generation: the project and document context needed to draft a follow-up email or purchase order for your review.
Depending on our configuration, inference is performed by one of the following providers, and we will process your data only with providers whose terms prohibit training on it by default:
- Anthropic PBC (Claude API, United States — our default provider). Anthropic's Commercial Terms of Service (effective 17 June 2025) state that Anthropic "may not train models on Customer Content from Services". Anthropic's published default is that API inputs and outputs are deleted from its backend within 30 days, with longer retention only for content flagged for trust-and-safety review.
- Z.AI (GLM models via the international api.z.ai platform, operated from Singapore by JINGSHENG HENGXING TECHNOLOGY PTE. LTD.). Z.AI's Terms of Use (last updated 14 April 2026) state for API services: "We will not use End User Content for developing or improving Services, unless you explicitly agree to such use" — and we do not so agree. Z.AI's Privacy Policy states it does not store API customer content.
We have not granted either provider permission to train on data we send. AI outputs (classifications, urgency labels, briefings, drafts) are informational aids and are always subject to the human review described in our Terms of Service. Automated classification does not produce any decision with legal effect about an individual; classifications can be reviewed and corrected by your team in the platform.
8. Who we share data with
We disclose personal data only to the service providers (data processors) we use to run Othersmind, listed below, and otherwise only with consent or where the law requires or permits it. We do not sell personal data, and we do not share it with advertisers or data brokers.
| Provider | Role | Location |
|---|---|---|
| Railway Corporation | Application and database hosting (our MySQL database, containing the data in section 3, runs here) | United States |
| Vercel Inc. | Web application hosting and content delivery | United States / global edge network |
| Google LLC | Google Sign-In, Gmail API access, web fonts | United States / global |
| Anthropic PBC | LLM inference (default provider — see section 7) | United States |
| Z.AI (JINGSHENG HENGXING TECHNOLOGY PTE. LTD.) | LLM inference (alternative provider — see section 7) | Singapore |
| Telegram (optional) | If your business enables Telegram notifications, alert titles and short summaries (which can include email subject lines) are delivered via Telegram's Bot API | Global |
Each processor processes personal data on our documented instructions under its service terms. Under the amended PDPA, data processors are directly bound by the Security Principle (section 5(1A) read with section 9 of the PDPA).
9. Transfers outside Malaysia
Personal data processed by Othersmind genuinely leaves Malaysia. Our application and database are hosted in the United States (Railway), our web layer is served from the United States and a global edge network (Vercel), LLM inference takes place in the United States (Anthropic) or Singapore (Z.AI), and Gmail data is received from Google's global infrastructure. This section is the notice of those transfers contemplated by the Personal Data Protection Guidelines on Cross Border Personal Data Transfer (issued 29 April 2025).
We rely on the following grounds under section 129(3) of the PDPA (as amended with effect from 1 April 2025):
- Consent — section 129(3)(a): you consent to these transfers when you create an account or connect a mailbox after being shown this notice, which names the classes of recipients (section 8) and the purposes (section 5);
- Contractual necessity — section 129(3)(b): the transfers are necessary for the performance of our contract to provide the service, which cannot be delivered without hosting and processing on the named infrastructure; and
- Reasonable precautions and due diligence — section 129(3)(f): we take all reasonable precautions, including selecting providers bound by written terms restricting their use of the data (including the no-training commitments in section 7), so that the data will not be processed in the receiving country in any manner that would contravene the PDPA.
10. How we protect data
The Security Principle (section 9 of the PDPA) requires practical steps to protect personal data. The controls we actually operate are:
- all traffic between your browser, our servers and third-party APIs is encrypted in transit (HTTPS/TLS);
- sign-in is restricted to an explicit allow-list of authorised email addresses — if an address is not on the list, sign-in fails closed (nobody is allowed by default);
- project-level access control: users can only access data for projects they are members of, with role-based permissions enforced at the API layer;
- the Gmail connection flow is protected against forgery with cryptographically signed (HMAC), time-limited state tokens that expire after 10 minutes;
- internal service credentials are compared using timing-safe methods, and API endpoints are rate-limited;
- authentication tokens, cookies and OAuth tokens are automatically redacted from our server logs; and
- Gmail access is read-only by scope, so even a compromise of our systems could not be used to send, alter or delete your email.
An honest limitation: the Google OAuth tokens we store are protected by access controls, transport encryption and our hosting provider's managed database protections, but are not currently encrypted at the application level in our database. Application-level encryption of stored tokens is on our engineering roadmap; our Security page tracks this openly. You can invalidate these tokens at any time by revoking access from your Google Account (section 4).
We do not claim any security certification (such as ISO 27001 or SOC 2), and we make no compliance claim we cannot verify.
11. How long we keep data
Under the Retention Principle (section 10 of the PDPA), personal data must not be kept longer than necessary. Our actual retention practice is:
- Account, project, Gmail and audit data: retained for as long as the customer account remains active. We do not currently operate an automated deletion schedule for these records; they are deleted on verified request (section 12) and following termination of the customer agreement.
- Agent findings history: automatically deleted after approximately 90 days.
- OAuth tokens: stored until deleted on request; revoking access from your Google Account invalidates them immediately regardless of storage.
- LLM provider copies: our default provider deletes API inputs and outputs within 30 days (section 7); Z.AI states it does not store API content.
- Personal data breach records (if any breach occurs): kept for at least 2 years as required by the JPDP Data Breach Notification Guideline.
If you ask us to delete data, or a customer agreement ends, we will delete the relevant personal data within a reasonable period, except where we are required or permitted by law to retain it (for example, records needed for tax or dispute purposes).
12. Disconnecting Gmail and deletion
We describe disconnection exactly as it works, because two different actions do two different things:
- Disconnecting in Othersmind (the "disconnect" action in the Gmail inbox module) marks the connection inactive and stops all further syncing. It does not delete the email records already synced into the platform, and it does not delete the stored OAuth tokens.
- Revoking access in your Google Account (myaccount.google.com/permissions) invalidates our tokens with Google, so they no longer grant any access — but the already-synced email records also remain in the platform.
To have synced email data and stored tokens deleted, email chiewaylee@gmail.com with the subject "Othersmind Data Deletion Request". After verifying the request, we will delete the synced email records and stored tokens for the relevant mailbox and confirm to you in writing. We recommend doing both: disconnect (or revoke) first, then request deletion.
13. Your rights
Under the PDPA you have the right to:
- Access your personal data (section 30) and correct inaccurate, incomplete, misleading or out-of-date data (section 34);
- Withdraw consent to processing at any time by written notice (section 38), subject to any legal or contractual restriction;
- Prevent processing likely to cause damage or distress (section 42) and stop direct marketing (section 43) — for the record, we do not use personal data for direct marketing;
- Data portability (section 43A, in force since 1 June 2025): you may request, in writing by electronic means, that we transmit your personal data to another data controller of your choice, subject to technical feasibility and compatibility of data formats.
To exercise any of these rights, email chiewaylee@gmail.com. We will verify your identity before acting, respond within the timeframes the PDPA prescribes, and charge only such fees as the PDPA permits (if any). If you are an employee or business contact of one of our customers, we may refer aspects of your request to that customer where the data belongs to their records.
14. Data breach notification
If a personal data breach occurs, we will act in accordance with section 12B of the PDPA and the Personal Data Protection Guideline on Data Breach Notification (issued 25 February 2025):
- where the breach causes or is likely to cause significant harm, we will notify the Personal Data Protection Commissioner as soon as practicable, and in any event within 72 hours;
- where the breach causes or is likely to cause significant harm to affected individuals, we will notify those individuals directly, without unnecessary delay and no later than 7 days after the Commissioner notification; and
- we maintain internal records of any breach for at least 2 years.
15. Cookies
The Othersmind application uses a single essential session cookie to keep you signed in. It is marked HTTP-only (inaccessible to page scripts) and is not used for tracking. Neither the application nor this website uses analytics or advertising cookies.
16. Children
Othersmind is a business platform for construction contractors. It is not directed at children, and we do not knowingly collect personal data from anyone under 18. Accounts are provisioned only for our customers' authorised personnel.
17. Changes to this notice
When we change this notice, we will update the version number and "Last updated" date at the top of this page, in both language versions. For material changes — for example, a new category of data, a new processor, or a new purpose — we will notify account holders by email or an in-app notice before the change takes effect.
18. Contact and complaints
Privacy and data protection contact: chiewaylee@gmail.com
NUL TECHNOLOGY (202603148027 (003857548-W))
A-15-02, VILLA ORKID BUKIT PRIMA PELANGI,
JLN PELANGI 7,
51200 KUALA LUMPUR,
WILAYAH PERSEKUTUAN, MALAYSIA
NUL TECHNOLOGY has not formally appointed a Data Protection Officer under section 12A of the PDPA, because our current processing falls below the thresholds set out in the JPDP Guideline on the Appointment of a Data Protection Officer (issued 25 February 2025). The contact above is our designated privacy contact, not a registered Data Protection Officer. We monitor our processing scale and activities against those thresholds and will appoint and register a Data Protection Officer if they are met.
If you are not satisfied with how we handle your personal data or a request, you may complain to the Personal Data Protection Commissioner, Jabatan Perlindungan Data Peribadi (JPDP), Malaysia — www.pdp.gov.my.