Privacy Policy

Last updated: 11 August 2026 Version 1.0 Document: Personal Data Protection Notice
Baca notis ini dalam Bahasa Malaysia →

This notice is issued in both the national language (Bahasa Malaysia) and English, as required by section 7(3) of the Personal Data Protection Act 2010. The Bahasa Malaysia version (Notis Privasi) is available at all times. In the event of any inconsistency between the two versions, the English version prevails.

1. Who we are

NUL TECHNOLOGY (Business Registration No. 202603148027 (003857548-W)) is a business registered in Malaysia under the Registration of Businesses Act 1956 and carried on as a sole proprietorship. NUL TECHNOLOGY operates the Othersmind platform and this website (othersmind.ai). "Othersmind" and "TK-C3" are product and brand names of NUL TECHNOLOGY; they are not separate legal entities.

Registered business address: A-15-02, VILLA ORKID BUKIT PRIMA PELANGI, JLN PELANGI 7, 51200 KUALA LUMPUR, WILAYAH PERSEKUTUAN, MALAYSIA.

For the purposes of the Personal Data Protection Act 2010 (Act 709) ("PDPA"), as amended by the Personal Data Protection (Amendment) Act 2024 (Act A1727), NUL TECHNOLOGY is the data controller of the personal data described in this notice. Our privacy and data protection contact is chiewaylee@gmail.com (see section 18).

Othersmind is a business-to-business platform for construction contractors. Our customers are businesses; the individuals whose personal data we process are typically our customers' personnel, and the people who correspond with a mailbox our customer connects to the platform.

2. About this notice

This notice explains how we collect, use, disclose, store and protect personal data when you use Othersmind or visit this website. It is issued under section 7 of the PDPA and reflects the PDPA as amended with effect from 2025, including the seven Personal Data Protection Principles (General; Notice and Choice; Disclosure; Security; Retention; Data Integrity; and Access), the data breach notification duty (section 12B), the data portability right (section 43A) and the amended cross-border transfer regime (section 129).

Where our customer (the business that holds a Othersmind subscription) asks us to process personal data contained in its own records — for example, correspondence in a mailbox it connects — we process that data to provide the service to that customer under our agreement with them. The customer is responsible for ensuring it is entitled to make that data available to us.

3. Personal data we collect

3.1 Account data

When you sign in with Google, we store: your name, email address, a Google account identifier, your sign-in method, your assigned role on the platform, and sign-in timestamps. We never see or store your Google password.

3.2 Gmail data (only if a mailbox is connected)

If your business connects a Gmail mailbox, we sync and store the following fields for recent inbox messages, and only these fields:

What we do not collect: we do not read or store message bodies — messages are fetched in Gmail's metadata format only. We do not download or store attachments (we record only whether an attachment exists). We do not access contacts, calendar, Drive, or any other Google service, and we cannot send, modify or delete email (see section 4).

3.3 Project and operational data

Data your business enters into the platform: project details, progress claims and valuations, variation orders, purchase orders, supplier records (which may include supplier contact persons' names, email addresses and phone numbers), consultant contact details, document registers, schedules, checklists and notes.

3.4 Technical and audit data

Server logs (with authentication tokens and cookies automatically redacted), an audit trail of actions taken on the platform, agent run records (including AI agent inputs and outputs relating to your projects), in-app notifications, and a session cookie used to keep you signed in.

3.5 Website visitors

This marketing website sets no analytics or advertising cookies and runs no trackers. Web fonts are loaded from Google Fonts, which means your browser sends your IP address to Google when the page loads.

3.6 Whether providing data is obligatory

Account data is required to provide the service — without it we cannot give you access. Connecting a Gmail mailbox is optional: if you choose not to connect one, the platform's Gmail-related features will simply be unavailable, and the rest of the platform will still work.

3.7 Sources of personal data

We obtain personal data: directly from you (sign-in and data you enter); from the Gmail mailbox your business chooses to connect (which will include personal data of the people who correspond with that mailbox, such as consultants, suppliers and client representatives); and from records your business's authorised users enter about their colleagues and business contacts.

4. How we access Gmail data

Othersmind connects to Gmail through Google's official Gmail API, with your explicit consent given on Google's own consent screen. Our access is deliberately minimal:

You can revoke Othersmind's access at any time from your Google Account security settings at myaccount.google.com/permissions, which immediately invalidates our access. See section 12 for what disconnection does and does not delete.

5. Why we process personal data

We process personal data for the following purposes:

We do not use personal data for advertising, and we do not sell personal data to anyone.

6. Google API Limited Use disclosure

Limited Use

Othersmind's use of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements. Our use of information received from Google Workspace APIs also adheres to the Google Workspace API user data and developer policy, including its Limited Use requirements.

In practice this means, for all data Othersmind receives from Gmail:

  • we use it only to provide and improve user-facing features that are prominent in Othersmind's interface — inbox classification, urgency flags, linking emails to claims and approvals, CIPAA deadline tracking and morning briefings;
  • we transfer it to others only as necessary to provide those features (the service providers named in section 8), for security purposes, or to comply with applicable law;
  • we do not use it for advertising of any kind, and we do not sell it;
  • we do not allow humans to read it except with your affirmative agreement, where necessary for security purposes (such as investigating abuse), to comply with applicable law, or where it has been aggregated for internal operations as the policy permits; and
  • we do not use it to create, train or improve any machine-learning or artificial-intelligence model — and our AI providers are contractually prohibited from training their models on it (see section 7).

7. AI processing of your data

Othersmind's agents use large language models (LLMs) operated by third-party providers. What is sent to the LLM provider is deliberately limited:

Depending on our configuration, inference is performed by one of the following providers, and we will process your data only with providers whose terms prohibit training on it by default:

We have not granted either provider permission to train on data we send. AI outputs (classifications, urgency labels, briefings, drafts) are informational aids and are always subject to the human review described in our Terms of Service. Automated classification does not produce any decision with legal effect about an individual; classifications can be reviewed and corrected by your team in the platform.

8. Who we share data with

We disclose personal data only to the service providers (data processors) we use to run Othersmind, listed below, and otherwise only with consent or where the law requires or permits it. We do not sell personal data, and we do not share it with advertisers or data brokers.

ProviderRoleLocation
Railway CorporationApplication and database hosting (our MySQL database, containing the data in section 3, runs here)United States
Vercel Inc.Web application hosting and content deliveryUnited States / global edge network
Google LLCGoogle Sign-In, Gmail API access, web fontsUnited States / global
Anthropic PBCLLM inference (default provider — see section 7)United States
Z.AI (JINGSHENG HENGXING TECHNOLOGY PTE. LTD.)LLM inference (alternative provider — see section 7)Singapore
Telegram (optional)If your business enables Telegram notifications, alert titles and short summaries (which can include email subject lines) are delivered via Telegram's Bot APIGlobal

Each processor processes personal data on our documented instructions under its service terms. Under the amended PDPA, data processors are directly bound by the Security Principle (section 5(1A) read with section 9 of the PDPA).

9. Transfers outside Malaysia

Personal data processed by Othersmind genuinely leaves Malaysia. Our application and database are hosted in the United States (Railway), our web layer is served from the United States and a global edge network (Vercel), LLM inference takes place in the United States (Anthropic) or Singapore (Z.AI), and Gmail data is received from Google's global infrastructure. This section is the notice of those transfers contemplated by the Personal Data Protection Guidelines on Cross Border Personal Data Transfer (issued 29 April 2025).

We rely on the following grounds under section 129(3) of the PDPA (as amended with effect from 1 April 2025):

10. How we protect data

The Security Principle (section 9 of the PDPA) requires practical steps to protect personal data. The controls we actually operate are:

An honest limitation: the Google OAuth tokens we store are protected by access controls, transport encryption and our hosting provider's managed database protections, but are not currently encrypted at the application level in our database. Application-level encryption of stored tokens is on our engineering roadmap; our Security page tracks this openly. You can invalidate these tokens at any time by revoking access from your Google Account (section 4).

We do not claim any security certification (such as ISO 27001 or SOC 2), and we make no compliance claim we cannot verify.

11. How long we keep data

Under the Retention Principle (section 10 of the PDPA), personal data must not be kept longer than necessary. Our actual retention practice is:

If you ask us to delete data, or a customer agreement ends, we will delete the relevant personal data within a reasonable period, except where we are required or permitted by law to retain it (for example, records needed for tax or dispute purposes).

12. Disconnecting Gmail and deletion

We describe disconnection exactly as it works, because two different actions do two different things:

To have synced email data and stored tokens deleted, email chiewaylee@gmail.com with the subject "Othersmind Data Deletion Request". After verifying the request, we will delete the synced email records and stored tokens for the relevant mailbox and confirm to you in writing. We recommend doing both: disconnect (or revoke) first, then request deletion.

13. Your rights

Under the PDPA you have the right to:

To exercise any of these rights, email chiewaylee@gmail.com. We will verify your identity before acting, respond within the timeframes the PDPA prescribes, and charge only such fees as the PDPA permits (if any). If you are an employee or business contact of one of our customers, we may refer aspects of your request to that customer where the data belongs to their records.

14. Data breach notification

If a personal data breach occurs, we will act in accordance with section 12B of the PDPA and the Personal Data Protection Guideline on Data Breach Notification (issued 25 February 2025):

15. Cookies

The Othersmind application uses a single essential session cookie to keep you signed in. It is marked HTTP-only (inaccessible to page scripts) and is not used for tracking. Neither the application nor this website uses analytics or advertising cookies.

16. Children

Othersmind is a business platform for construction contractors. It is not directed at children, and we do not knowingly collect personal data from anyone under 18. Accounts are provisioned only for our customers' authorised personnel.

17. Changes to this notice

When we change this notice, we will update the version number and "Last updated" date at the top of this page, in both language versions. For material changes — for example, a new category of data, a new processor, or a new purpose — we will notify account holders by email or an in-app notice before the change takes effect.

18. Contact and complaints

Privacy and data protection contact: chiewaylee@gmail.com
NUL TECHNOLOGY (202603148027 (003857548-W))
A-15-02, VILLA ORKID BUKIT PRIMA PELANGI,
JLN PELANGI 7,
51200 KUALA LUMPUR,
WILAYAH PERSEKUTUAN, MALAYSIA

NUL TECHNOLOGY has not formally appointed a Data Protection Officer under section 12A of the PDPA, because our current processing falls below the thresholds set out in the JPDP Guideline on the Appointment of a Data Protection Officer (issued 25 February 2025). The contact above is our designated privacy contact, not a registered Data Protection Officer. We monitor our processing scale and activities against those thresholds and will appoint and register a Data Protection Officer if they are met.

If you are not satisfied with how we handle your personal data or a request, you may complain to the Personal Data Protection Commissioner, Jabatan Perlindungan Data Peribadi (JPDP), Malaysia — www.pdp.gov.my.