Legal
Privacy Policy
What personal data we collect, why we collect it, how long we keep it, where it is stored, and the rights you have over it. This policy is written to meet our obligations under the Malaysian Personal Data Protection Act 2010.
- Applies to
- Agentic Forge Consulting
- Company no.
- 202603080686
- Last updated
- 17 August 2026
Bahasa Malaysia. A Bahasa Malaysia version of this notice is available at Dasar Privasi. Where the two differ, the English version prevails except where the law requires otherwise.
1. Who we are, and in what capacity
Agentic Forge Consulting (company registration number 202603080686), registered at Jalan Desiran Tanjung 4, Tanjung Tokong, 10470 Georgetown, Pulau Pinang, Malaysia, is responsible for the personal data described in this policy under the Malaysian Personal Data Protection Act 2010 (“PDPA”). The Act refers to that party as the data controller — previously “data user”.
Our capacity differs depending on the data:
- As data controller — for personal data whose use we determine ourselves: website request logs, enquiries sent to us, the contact details of the people we work with at client organisations, and our own billing and accounting records.
- As data processor — for personal data contained in the business data a client provides so that we can deliver the services. There the client remains the data controller and decides what the data is used for; we process it only on that client’s instructions.
For any question about this policy, or to exercise any right described in section 9, contact us at team@agenticforgeconsulting.com.
2. What this policy covers
This policy covers personal data we handle in three situations:
- When you visit this website
- When you contact us, whether or not you become a client
- When we deliver services to a client, including data belonging to that client’s own staff or customers
3. This website
This website is a static site. It sets no cookies, runs no analytics and embeds no third-party tracking scripts. There is no contact form and no account to create, so there is nothing for you to submit here.
The site is served by Google’s Firebase Hosting. Like any web host, it records standard technical request logs — including IP address, the page requested, timestamp, referring page and browser user-agent — for security, abuse prevention and service operation. We do not use these logs to build a profile of you or to identify individual visitors, and we do not combine them with any other data.
4. When you contact us
If you email us, we receive the contents of your message together with your name, email address, and whatever else you choose to include — typically your company, role and phone number.
We use this to respond to you, to assess whether we can help, and to keep a record of our correspondence. If the enquiry becomes an engagement, this information becomes part of the client record described below. If it does not, we retain it as described in section 7.
5. When we work with you as a client
Client contact data
We hold names, business email addresses, phone numbers, job titles and correspondence for the people at your organisation we work with. We use it to deliver the services, manage the relationship, and issue and collect invoices.
Data you provide for the engagement
Delivering our services requires your business data — sales history, product and inventory records, outlet and location records, and operational data. This is predominantly commercial rather than personal data. Where it does contain personal data — for example the names of field staff in a routing dataset, or named contacts at retail outlets — we handle it strictly on your instructions and only to deliver the agreed services.
You remain responsible for having a lawful basis to give us that data, and for having given the individuals concerned any notice the PDPA requires. We do not use it for our own purposes, do not sell it, and do not disclose it except as set out in this policy.
Platform user accounts
For users you nominate to access the platform, we hold the account identifier, authentication records and a log of activity within the system, for access control, support and security.
6. Why we may process personal data
Under the PDPA, processing rests on your consent unless one of the limited statutory exceptions applies. Ours rests on one or more of the following:
- Your consent, given when you contact us or provide data to us, which you may withdraw at any time
- Performance of a contract with you, or steps taken at your request with a view to entering one
- Compliance with a legal obligation to which we are subject, in particular Malaysian tax and company-records requirements
Supplying personal data to us is voluntary. You are not obliged to give us any of it. But if you do not provide the contact details we need in order to reply, we cannot respond to your enquiry; and if a client does not provide the data an engagement depends on, we cannot deliver the services.
7. How long we keep it
- Enquiries that do not become engagements — up to twenty-four (24) months from the last contact, then deleted
- Client contact and correspondence records — for the duration of the engagement and seven (7) years afterwards, in line with Malaysian record-keeping requirements
- Client business data held in the platform — for the duration of the subscription. On termination it is retained for thirty (30) days so you can request an export, then deleted from active systems, with backup copies expiring on their own cycle within ninety (90) days
- Invoicing and financial records — seven (7) years, as required by Malaysian law
- Web server logs — retained by our hosting provider on its standard cycle, typically not more than twelve (12) months
8. Who we share it with, and where it is stored
We do not sell personal data and we do not share it for anyone else’s marketing. We disclose it only to:
- Service providers who process data on our behalf — principally Google Cloud Platform and Firebase for hosting, application infrastructure, authentication and storage, and our payment processor for handling payments. Each is bound to process data only on our instructions and to keep it secure.
- Professional advisers — accountants, auditors and lawyers, where required and under a duty of confidentiality.
- Authorities — where we are required to disclose by law, court order or a regulator.
- A successor entity — if the business is sold or reorganised, under equivalent protections and with notice to you.
Cross-border transfer
We are established in Malaysia, and we work with clients outside Malaysia, including in the United States. As a result, personal data may be transferred to, stored in, or accessed from countries outside Malaysia — in particular where our cloud infrastructure providers operate facilities, and where a client’s own users access the platform from their country.
Where we transfer personal data outside Malaysia, we do so only on a basis the PDPA permits — which may include your consent, the necessity of the transfer for the performance of a contract with you or in your interest, or our having satisfied ourselves that the recipient provides protection comparable to that required under the PDPA. In practice that means contractual commitments with our providers, encryption in transit and at rest, and access limited to those who need it. We keep this basis under review as the applicable requirements develop.
Where a client is subject to data protection law in its own jurisdiction that imposes additional requirements, we will agree those terms separately in writing as part of the engagement.
9. Your rights
Under the PDPA you have the right to:
- Access the personal data we hold about you, and be told how it is being processed
- Correct personal data that is inaccurate, incomplete, misleading or out of date
- Withdraw consent to our processing, at any time
- Limit processing for direct marketing purposes, or where processing is likely to cause damage or distress
- Have data transmitted onward — where the PDPA provides for it, ask us to transmit personal data you have given us to another data controller, in a commonly used format and where doing so is technically feasible
To exercise any of these, email team@agenticforgeconsulting.com with enough detail for us to identify you and the data concerned. We will respond within twenty-one (21) days. We may need to verify your identity first, and there are limited circumstances in which the PDPA permits us to refuse a request — if that applies, we will tell you why.
Where we hold personal data on behalf of a client, requests from that client’s staff or customers should be directed to the client in the first instance. We will support the client in responding.
If you are not satisfied with how we have handled a request, you may complain to the Personal Data Protection Commissioner, Malaysia.
10. How we protect personal data
We apply organisational and technical security measures proportionate to the nature and sensitivity of the personal data we hold, and we build on established cloud providers rather than operating our own infrastructure. No system is completely secure, and we do not represent that our measures will prevent every possible incident.
If a personal data breach occurs we will assess it promptly and make any notification the PDPA requires — which may include notifying the Personal Data Protection Commissioner and, where the breach is likely to cause significant harm, the individuals affected. Where a breach concerns data we hold on behalf of a client, we will notify that client without undue delay so it can meet its own obligations.
11. Children
Our services are provided to businesses. We do not knowingly collect personal data from anyone under 18. If you believe we have, contact us and we will delete it.
12. Changes to this policy
We may update this policy as our services or the law change. The current version and its date are shown at the top of this page. Where a change materially affects how we handle your personal data, we will notify affected clients directly.
Questions about this policy
Write to us at team@agenticforgeconsulting.com. We reply within two business days.