PRIVACY NOTICE – AIVALS AI COACH

Last Updated: January 8, 2026

1. Introduction

AIVALS Pte. Ltd. and its affiliated entities ("AIVALS", "we", "us", or "our") process personal data when employees use the AIVALS AI Coach platform for workplace training. This Privacy Notice explains what data we collect, why we collect it, how we protect it, and your rights under applicable data protection laws, including:

  • Singapore's Personal Data Protection Act 2012 (PDPA);
  • The EU General Data Protection Regulation (GDPR), where applicable;
  • Malaysia's Personal Data Protection Act 2010 (PDPA MY);
  • Indonesia's Personal Data Protection Law No. 27 of 2022 (PDPL ID);
  • And other relevant national or regional privacy regulations.

In this context, the enterprise client is the data controller, and AIVALS acts as a data processor. Employees should direct primary privacy inquiries to their employer, but may also contact us directly as described below.

2. What Data Do We Process?

On instructions from the client, we process the following categories of personal data:

  • Employee Profile: Full name, job title, department, corporate email address, employee ID.
  • Training Session Data: Audio and/or video recordings of simulated interactions (e.g., mock sales calls, leadership conversations), AI-generated transcripts, text-based self-reflections, and multiple-choice responses.
  • AI Feedback Metrics: Behavioral and performance indicators such as confidence level, speech clarity, use of filler words, active listening cues, objection handling, and sales skills (e.g., needs identification, value proposition delivery).
  • Technical & Usage Data: IP address, device type, browser version, operating system, session duration, modules completed, retry attempts, and interaction logs.

We do not perform biometric identification. Voice or behavioral analysis is used solely to generate coaching feedback, not to verify identity.

3. Purposes of Processing & Legal Bases

We process data strictly as instructed by the client controller for the following purposes:

PurposeLegal Basis (as Processor)
Deliver interactive coaching simulations and real-time AI feedbackBased on the client's lawful basis (e.g., employee consent or legitimate interest in professional development)
Enable designated personnel within your organization to review individual or team progress (as configured by your employer)As directed by the client controller

We do not use employee data for advertising, automated decision-making with legal effect, commercial resale, or any purpose outside of authorized training activities.

4. Who Receives Your Data?

  • Within Your Organization: Managers or other authorized team members may access your session data and feedback reports, depending on permissions set by your employer.
  • Sub-processors: Trusted vendors providing cloud infrastructure (e.g., Amazon Web Services, Google Cloud Platform), video processing, and analytics services. All sub-processors are bound by data processing agreements that meet PDPA and GDPR standards.
  • Legal Authorities: We disclose data only if required by law, court order, or regulatory request.

Our infrastructure is global. When transferring data internationally (e.g., from Singapore to the United States), we implement safeguards such as Standard Contractual Clauses (SCCs), binding corporate rules, or obtain explicit consent where required by PDPA MY, PDPL ID, or GDPR.

5. Data Retention

Training session recordings and associated feedback are retained for up to 24 months from the date of last activity, unless:

  • The client configures a shorter retention period;
  • Local law requires earlier deletion (e.g., upon valid employee request under GDPR);
  • Retention is extended due to a legal hold or investigation.

After the applicable retention period, data is securely deleted or irreversibly anonymized.

6. Security Measures

We implement industry-standard technical and organizational safeguards to protect personal data, including:

  • Encryption of data in transit using TLS 1.3 or higher, and at rest using AES-256 encryption;
  • Strict role-based access controls and mandatory multi-factor authentication for internal systems;
  • Regular security assessments, including penetration testing and vulnerability scanning;
  • Comprehensive audit logging and monitoring for unauthorized access;
  • Vendor security reviews aligned with ISO/IEC 27001 principles.

7. Data Breach Notification

In the event of a personal data breach likely to result in significant harm, we will:

  • Notify the affected enterprise client without undue delay;
  • Where required by law (e.g., under GDPR or PDPA), assist the client in notifying the relevant supervisory authority (such as Singapore's PDPC) within 72 hours;
  • Support the client in communicating with affected individuals, if necessary;
  • Take immediate remedial actions to contain and mitigate the impact.

8. Children's Data

The Service is not intended for individuals under 18 years of age. We do not knowingly collect or process personal data from minors. If such data is inadvertently collected, it will be deleted promptly upon discovery.

9. Your Rights

Although your employer is the data controller, you may contact AIVALS to exercise certain rights under applicable law, including:

  • Requesting access to a copy of your personal data processed by us;
  • Requesting correction of inaccurate or incomplete information;
  • Requesting erasure of your data before the standard retention period expires (subject to legal or contractual constraints);
  • Objecting to processing based on legitimate interests (where applicable).

To submit a request, email legal@AIVALS.com. We will respond within 30 days (or as required by local law) and coordinate with your employer as needed.

10. Updates to This Notice

We may revise this Notice to reflect changes in our practices or legal obligations. The "Last Updated" date will be modified accordingly. For material changes, we will provide prominent notice (e.g., via email to administrators or in-app banner). Continued use of the Service constitutes acceptance of the updated Notice.

11. Contact Us

For privacy inquiries or to contact our Data Protection Officer:

AIVALS Pte. Ltd.

10 Anson Road, #26-08A, International Plaza

Singapore 079903

Email: legal@AIVALS.com