Privacy Policy
Aethon · Last Updated: 10 April 2026
1. Introduction
Aethon ("we", "us", "our") is committed to protecting the personal data of individuals who interact with our services, website, and communications. This Privacy Policy explains what data we collect, how we use it, and what rights you have under the Malaysian Personal Data Protection Act 2010 (PDPA).
This policy applies to all personal data processed by Aethon in connection with our website at aethona.biz and our AI consultancy services. For questions or concerns, contact us at [email protected].
2. Data We Collect
Information you provide
- Name and contact details submitted through our contact form
- Email address, phone number, and any message content you send us
- Business information shared during project scoping or engagement
Data collected automatically
- Browser type, operating system, and device type
- Pages visited and time spent on site (analytics cookies, if consented)
- IP address and general geographic location
- Referral source (how you found our website)
Client project data
When engaged for a project, we process client-provided data (which may include personal data of your customers or employees) under a separate Data Processing Agreement. That data is handled exclusively for project delivery purposes and is subject to its own retention and deletion terms.
3. How We Use Your Data
- To respond to your enquiry or service request
- To communicate about project scope, progress, and delivery
- To issue invoices and maintain financial records
- To improve our website and understand how visitors use it (analytics, if consented)
- To comply with legal obligations under Malaysian law
We do not sell personal data to third parties. We do not use personal data for automated profiling that produces legal or significant effects.
4. Legal Basis for Processing
- Consent — for analytics cookies and marketing communications, where you have opted in
- Contractual necessity — to deliver services you have engaged us for
- Legitimate interest — to respond to enquiries, maintain records, and operate our business securely
- Legal obligation — to comply with Malaysian law, including tax and accounting requirements
5. Data Retention
Enquiry data from the contact form is retained for up to 12 months unless a project engagement begins, in which case it forms part of the project record. Project records are retained for 7 years for legal and accounting purposes. After retention periods expire, data is securely deleted or anonymised.
6. Data Sharing
We do not share personal data with third parties except in the following circumstances:
- Service providers who support our operations (e.g., cloud infrastructure, accounting software) — governed by data processing agreements
- Where required by Malaysian law or regulatory authorities
- With your explicit consent
We do not transfer personal data outside Malaysia without appropriate safeguards in place.
7. Data Protection Measures
- Encrypted data transmission (HTTPS) on all web communications
- Access controls limiting staff access to personal data on a need-to-know basis
- Isolated project environments — client data is not shared across engagements
- Secure deletion procedures at end of retention period
- Regular review of data handling practices
8. Cookies
We use essential cookies for basic website operation and, with your consent, analytics cookies to understand site usage. For full details, see our Cookie Policy. You can manage your cookie preferences at any time via the Cookie Policy page.
9. Your Rights Under the Malaysian PDPA
You have the right to:
- Access personal data we hold about you
- Correct inaccurate or incomplete data
- Withdraw consent where processing is consent-based
- Request erasure of data where there is no legal basis for retention
- Object to processing for direct marketing purposes
To exercise any of these rights, contact [email protected]. We will respond within 21 days. Requests relating to the PDPA may also be submitted to the Department of Personal Data Protection Malaysia.
10. Third-Party Links
Our website may contain links to external websites. We are not responsible for the privacy practices of third-party sites and recommend reviewing their policies before sharing personal information.
11. Children's Privacy
Our services are intended for business organisations and professionals aged 18 and above. We do not knowingly collect personal data from minors. If you believe a minor has submitted data through our site, contact us and we will delete it promptly.
12. Changes to This Policy
We may update this policy periodically. The "Last Updated" date at the top of this page reflects the most recent revision. Material changes will be communicated by updating this page. Continued use of our services after an update constitutes acceptance of the revised policy.
13. Contact for Data Matters
Data Controller: Aethon
14 Jalan Tun Razak, 50400 Kuala Lumpur, Wilayah Persekutuan, Malaysia
Email: [email protected]
Phone: +60 3-2168 4735