Privacy Policy

What we do with your data,
and what we don’t.

AJ ENDLESS ASIA SDN BHD (“we”) processes personal data under Malaysia’s Personal Data Protection Act 2010 (PDPA).

Version 1.0 · Effective 3 August 2026. This is the operative text for AJ ENDLESS ASIA SDN BHD, matching the version published at qiai.tech. This document is published in English and Simplified Chinese. In the event of any inconsistency between the versions, the English version prevails. ← 返回中文版

01 · About this notice

AJ ENDLESS ASIA SDN BHD (Registration No. 202501007910 / 1609324-P), trading as Q.AI ("we", "us", "our"), is committed to protecting the personal data we handle.

This Notice is issued under section 7 of the Personal Data Protection Act 2010 ("PDPA") and explains how we collect, use, disclose, store, and protect personal data when you visit our websites, create an account, or use our conversational AI, marketing, and automation products (together, the "Services").

This Notice is published in English and Simplified Chinese. In the event of any inconsistency between the versions, the English version prevails.

02 · Personal data we process

Depending on how you interact with us, we may process the following categories of personal data:

  • Identity and contact data — name, business name, email address, phone and WhatsApp number, job title, and country.
  • Account data — username, password (stored in hashed form), account and sub-account settings and identifiers, and your support history with us.
  • Billing data — billing name and address, invoices, transaction records, subscription status, and credit balances. Full payment card details are collected and stored by our payment processor, not by us.
  • Usage and technical data — IP address, device and browser type, operating system, referring pages, timestamps, feature usage, and diagnostic logs.
  • Communications data — messages, attachments, voice notes, and conversation transcripts sent to or through the Services, including conversations between your customers and our AI on messaging channels you connect.
  • Content you submit — text, images, audio, video, prompts, and files you upload to our AI tools.
  • Website interactions — details you submit through our contact forms, blog comments, newsletter sign-ups, consultation and demo bookings, and any social media handles you provide when sharing our content.
We do not intentionally collect sensitive personal data as defined in the PDPA — including data on health, political opinions, religious beliefs, biometric data, and records of criminal offences. Please do not submit sensitive personal data through the Services unless it is necessary and you have a lawful basis for doing so.

03 · How we obtain your personal data

  • Directly from you, when you fill in a form, create an account, make a payment, or contact our support team.
  • Automatically, through your use of the Services and through cookies and similar technologies.
  • From third-party platforms you authorise us to connect to, such as GoHighLevel, Meta WhatsApp Business, Facebook, and Instagram.
  • From your organisation, where your account was created for you by an administrator or account owner.
  • From our resellers, agency partners, and referral partners.
  • From publicly available sources, such as company registries and business directories.

04 · Why we process your personal data

We process personal data for the following purposes:

  • To provide, operate, and maintain the Services, and to create and administer your account.
  • To authenticate users and secure access to accounts and sub-accounts.
  • To process payments, credits, invoices, refunds, and applicable taxes.
  • To generate AI responses, content, and automations that you or your connected platforms request.
  • To provide customer support and respond to your enquiries.
  • To detect, investigate, and prevent abuse, fraud, spam, and security incidents.
  • To monitor, troubleshoot, and improve the reliability, performance, and quality of the Services.
  • To send service, transactional, and administrative communications about your account.
  • To send marketing communications, where you have consented. Every marketing email contains an unsubscribe link, and you may also withdraw consent at any time by emailing us. Withdrawing marketing consent does not stop service and transactional emails about your account.
  • To comply with legal, tax, accounting, and regulatory obligations, and to establish, exercise, or defend legal claims.
We do not sell personal data. We do not use your data, or the content of your conversations and uploads, to train artificial intelligence models — neither our own models nor those of any third party — and we do not provide that content to third parties for training purposes. Where we use data to improve the quality of the Services, we use aggregated or de-identified data that cannot reasonably be used to identify an individual.

05 · Our role: controller and processor

Where we process personal data about you as our customer — your account, billing, and support records — we act as a data controller.

Where you use the Services to process personal data about your own customers and contacts, you are the data controller and we act as a data processor acting on your instructions.

In that case, you are responsible for having a lawful basis for the processing, for issuing your own personal data protection notice to your contacts, and for obtaining any consent required — including consent for direct marketing under the PDPA and any consent required by the messaging platforms you connect to the Services.

06 · Who we disclose personal data to

We may disclose personal data to the following classes of third parties:

  • Cloud hosting, database, storage, and content delivery providers.
  • Payment processors and billing platforms.
  • Providers of artificial intelligence and machine-learning models used to generate responses and content.
  • Operators of messaging, CRM, and marketing platforms whose channels you connect to the Services.
  • Email, SMS, and notification delivery providers.
  • Analytics, logging, and error-monitoring providers.
  • Professional advisers, including auditors, lawyers, and accountants.
  • Government departments, regulators, courts, and law-enforcement agencies, where required or permitted by law.
  • A purchaser or successor, in connection with any merger, acquisition, restructuring, or transfer of our business or assets in whole or in part.

We require our service providers to process personal data only on our instructions and to maintain appropriate security measures.

07 · Transfer outside Malaysia

Some of our service providers operate outside Malaysia. Your personal data may therefore be transferred to, stored in, or accessed from jurisdictions outside Malaysia.

Where we transfer personal data outside Malaysia, we take reasonable steps to satisfy ourselves that the receiving party provides a level of protection at least comparable to that required under the PDPA — including through contractual safeguards and by assessing the destination in line with the Personal Data Protection Guidelines on Cross Border Personal Data Transfer.

By providing personal data to us, you consent to such transfers on the basis described above.

08 · Security, breaches, and retention

Security. We apply technical and organisational measures appropriate to the risk, including encryption of data in transit, role-based access controls, row-level security on our databases, activity logging and monitoring, and periodic review of access rights. No system is completely secure, and we cannot guarantee absolute security.

Breach notification. If a personal data breach occurs, we will notify the Personal Data Protection Commissioner as soon as practicable, and where the breach is likely to cause significant harm, we will also notify affected individuals without unnecessary delay, in accordance with the PDPA.

Retention. We retain personal data only for as long as necessary for the purposes set out in this Notice, or for as long as required by law. Financial and tax records are generally retained for seven years in line with Malaysian requirements. When personal data is no longer needed, we delete it or irreversibly anonymise it.

09 · Your rights

Subject to the PDPA, you may:

  • Request access to the personal data we hold about you.
  • Request correction of personal data that is inaccurate, incomplete, misleading, or out of date.
  • Withdraw your consent to our processing of your personal data.
  • Limit our processing of your personal data, including for direct marketing purposes.
  • Request that your personal data be transmitted to another data controller, where technically feasible.
  • Request deletion of your personal data where we no longer have a lawful basis to retain it.
  • Lodge a complaint with the Personal Data Protection Commissioner (Jabatan Perlindungan Data Peribadi, Malaysia).

To exercise any of these rights, email us at [email protected]. We may ask you to verify your identity, and we may charge the prescribed fee for a data access request as permitted under the PDPA. We will respond within the period prescribed by law.

If your personal data is held inside an account operated by one of our customers, please direct your request to that customer. We will assist them in responding, in our capacity as their data processor.

10 · Whether supply is obligatory

The personal data marked as required in our forms and sign-up flows must be supplied in order for us to create your account, provide the Services, process payments, and meet our legal obligations. If you do not supply it, we may be unable to provide the Services to you or to continue operating your account.

All other personal data is supplied voluntarily, and choosing not to supply it will not affect your access to the core Services.

11 · Children and age requirement

You must be at least 18 years old to create an account or use the Services. The Services are not directed at children, and we do not knowingly collect personal data from anyone under 18.

If you are a customer using the Services to communicate with your own contacts, you are responsible for ensuring that you have a lawful basis, and any parental or guardian consent required, before processing the personal data of anyone under 18 through our platform.

If we become aware that we have collected personal data from a child under 18 without appropriate consent, we will delete it promptly. If you believe we hold such data, contact us at the address in Section 13.

12 · Cookies and similar technologies

We use strictly necessary cookies for authentication, session management, and security. We may also use analytics and performance cookies to understand how our sites and Services are used so that we can improve them.

We use both session cookies, which expire when you close your browser, and persistent cookies, which remain on your device until they expire or you delete them.

You can control or delete cookies through your browser settings. Disabling strictly necessary cookies may prevent you from logging in or using parts of the Services.

13 · Changes and how to contact us

We may update this Notice from time to time. When we do, we will change the version number and date shown at the top of this page. Where a change is material, we will post it on this page and, where appropriate, notify account holders. Your continued use of the Services after an update constitutes acceptance of the updated Notice.

Questions, requests, or complaints about this Notice or about how we handle personal data can be sent to:

AJ ENDLESS ASIA SDN BHD

202501007910 (1609324-P) · trading as Q.AI

Bandar Damansara Perdana,
47820 Petaling Jaya, Selangor, Malaysia.

[email protected]