Privacy Policy
Last updated: 12 June 2026
BOSS Unified is operated by Raudhah Tech (Brainy Bunch Group) ("we", "us", "our"). This policy explains what personal data we collect, how we use it, and your rights under Malaysia's Personal Data Protection Act 2010 ("PDPA"). Where equivalents such as the EU GDPR or California's CCPA apply to you, we honour comparable rights. The Service is intended for adult business owners and is not directed at minors.
1. What We Collect
- Account data — your email address and optional full name, used to create and secure your account.
- Business data you enter — your business profile (name, industry, team size, challenges, goals), brand-voice samples, financial figures such as pasted P&L numbers, and chat history with the AI executives. This content may contain commercially sensitive information.
- Billing data — your Stripe customer ID and subscription status. Card details are handled entirely by Stripe and are never stored by us.
- Usage metadata — token usage, login timestamps, and IP address, used for security and to operate the Service.
2. How We Use It
We use your data to:
- Provide, maintain, and secure the Service;
- Generate AI outputs tailored to your business context;
- Process payments and manage your subscription;
- Provide support, respond to requests, and send service-related communications;
- Comply with legal obligations and prevent abuse.
3. AI Processing
When you use AI features, the relevant prompts and business context are sent to Anthropic (the provider of the Claude models) to generate a response. Under Anthropic's API terms, your inputs and outputs are not used to train Anthropic's models and are retained only for a limited period for abuse-monitoring before deletion.
Because AI features process the content you submit, avoid pasting data you are not comfortable sending for processing. AI outputs are decision-support only — see our Terms of Service.
4. Legal Basis & Consent
We process your data on the basis of your consent (given when you create an account and use the Service), to perform our contract with you, and to pursue our legitimate interests in operating and securing the Service. You may withdraw consent at any time as described in Your PDPA Rights below; withdrawal does not affect processing carried out before withdrawal.
5. Data Sharing & Sub-processors
We do not sell your personal data. We share it only with the sub-processors needed to run the Service:
- Supabase — database, authentication, and storage (hosted in Singapore, ap-southeast-1).
- Cloudflare — application hosting and network delivery.
- Anthropic — AI processing for the Command Executives.
- Stripe — payment processing and billing.
- Resend — transactional email delivery.
Each sub-processor handles data under its own terms and applicable data-protection law. We may also disclose data where required by law.
6. Data Retention
We keep your data for as long as your account is active and as needed to provide the Service. When you delete your account, your workspace data is deleted from our database, with related records cascading on deletion. Backups and provider logs (for example, Cloudflare request logs) are retained for short periods on their normal cycles. We retain limited records where required for legal, tax, or accounting purposes.
7. Your PDPA Rights
Under the PDPA, you have the right to:
- Access — request a copy of the personal data we hold about you;
- Correction — ask us to correct inaccurate or incomplete data;
- Withdraw consent — withdraw your consent to processing, and request deletion of your data, subject to legal retention requirements.
To exercise these rights, contact us using the details below. We aim to respond within 30 days.
8. Security
We protect your data with row-level security (RLS) in our database — so each workspace owner can only access their own workspace — and with encryption in transit (TLS) and at rest. Service keys are held only in a server-side secret store and are never exposed to the browser. No system is perfectly secure, but we work to safeguard your data and respond promptly to any incident.
9. Cookies
We use essential cookies to keep you signed in and to remember your preferences (such as your light/dark theme). These are required for the Service to function; we do not use them for third-party advertising.
10. International Transfer
Your data is stored in Singapore (Supabase) and processed by providers that may operate in other countries, including the United States (Anthropic, Stripe, Cloudflare, Resend). Where data is transferred outside Malaysia, we rely on the protections offered by these providers and applicable data-protection safeguards.
11. Contact / Data Protection Officer
For privacy questions or to exercise your rights, contact our Data Protection Officer at privacy@brainybunch.com, or by post at: Raudhah Tech (Brainy Bunch Group), [registered address].