Legal

Privacy Policy

How Escal8 collects, uses, and safeguards data when you operate AI conversations across WhatsApp and web channels.

Last updated: 24 August 2026 · Bahasa Melayu

Escalate Tech Services Sdn Bhd, trading as Escal8, is responsible for the personal data described in this policy when we determine why and how it is processed. This policy covers our public website, sales and support, account administration, and Escal8 products and services.

Our Roles

Escal8 acts as controller for website, account, billing, security, abuse prevention, and business communications. When a customer configures Escal8 to process conversations or operational data for its own purposes, the customer generally acts as controller and Escal8 acts as processor or service provider under the customer agreement. The customer remains responsible for notices, lawful authority, consent, connected data sources, retention, and human review.

Personal Data We Collect

  • Identity, business contact, organization, role, account, authentication, billing, and support data.
  • Device, browser, IP address, page, referral, consent choice, security, and service usage data.
  • Documents, knowledge bases, prompts, configurations, catalogs, schedules, policies, and connected-system data supplied by customers.
  • Customer-controlled messages, phone numbers, conversation content, attachments, reservations, orders, tool inputs and outputs, summaries, handoffs, and operational outcomes.

Sources

We receive data from visitors, account users, customers, authorized customer integrations, people communicating with customer-operated agents, Meta and WhatsApp services, payment and identity providers, security systems, and other service providers. Customers must have authority to provide data obtained from their own systems, staff, and end users.

Purposes and Legal Bases

We process data to respond to enquiries, enter and perform contracts, create and administer accounts, provide configured products, process messages and workflows, invoice customers, provide support, secure the service, prevent fraud and abuse, investigate incidents, comply with law, and improve reliability. Where a legal basis is required, we rely on contract, requested pre-contract steps, legal obligations, legitimate interests in operating and protecting the service, or consent where consent is appropriate. Optional website analytics relies on consent.

Customer-Controlled Processing

For customer-controlled data, we process documented instructions to provide and secure the selected service. Customers determine the purpose, audience, lawful basis, channel notices, opt-outs, permissions, integrations, and retention. A person interacting with a customer-operated service should also read that customer's privacy notice. Rights requests may be directed to the customer when it controls the relevant data.

AI and Automated Processing

Escal8 can classify requests, retrieve approved knowledge, generate responses, call configured tools, and route work. AI output can be inaccurate or incomplete. The service is not designed to make final decisions that produce legal or similarly significant effects without appropriate lawful authority and meaningful human review. Customers must disclose automated participation where required and provide a human path appropriate to the risk.

Website Storage and Analytics

The website uses essential first-party storage to remember privacy choices. Google Tag Manager and connected analytics remain blocked until a visitor selects Allow analytics. Rejecting analytics does not limit public content. Global Privacy Control signals default optional analytics to denied. Visitors can change the choice through Privacy choices in the footer. See the Cookie Policy.

Sharing and Service Providers

We disclose data only as needed to provide, secure, support, or comply with obligations relating to the service. Recipients may include Microsoft Azure, Google analytics after consent, Meta and WhatsApp providers, selected AI and messaging providers, identity and payment services, professional advisers, and authorities where disclosure is legally required. Customer-selected integrations receive data according to the customer's configuration. We do not sell personal data or share it for cross-context behavioural advertising.

International Transfers

Providers and customer deployments may process data in countries other than the country where it was collected. Where transfer safeguards are required, we use an applicable contractual, statutory, consent-based, adequacy, or other lawful mechanism together with technical and organizational safeguards appropriate to the transfer. Customer-specific location commitments must be recorded in the applicable agreement.

Retention

Retention depends on purpose, contract, customer configuration, security needs, dispute requirements, backup lifecycle, and applicable law. Account data is kept while the account is active and for a reasonable period needed for billing, audit, fraud prevention, legal obligations, and claims. Customer content and conversation data are retained according to the configured service and are deleted or de-identified when no longer required. Protected backups expire through their normal lifecycle. See Data Deletion.

Security and Incidents

We use safeguards appropriate to the service, including encrypted transport, access controls, scoped credentials, environment separation, logging, dependency maintenance, backup protection, and incident response. No internet service can guarantee absolute security. We assess personal data breaches and make required notifications to customers, regulators, and affected people under applicable law.

Your Rights and Choices

Depending on location and law, you may have rights to receive notice, access data, correct inaccurate data, request deletion, restrict or object to processing, receive portable data, withdraw consent, and complain to a supervisory authority. Withdrawing consent does not affect earlier lawful processing. Eligible requests are handled without discriminatory treatment. Email privacy@escal8.tech and identify the relevant account, organization, interaction, and requested action. We verify identity and authority before disclosing or deleting data.

Regional Disclosures

Where Malaysia's Personal Data Protection Act 2010 applies, Escal8 follows the applicable notice and choice, disclosure, security, retention, data integrity, and access principles. Complaints may be made to the Personal Data Protection Commissioner Malaysia. Where European or United Kingdom law applies, a person may also contact the relevant supervisory authority. Where the California Consumer Privacy Act applies, eligible residents may exercise applicable rights to know, correct, delete, opt out, limit, and receive non-discriminatory treatment. Escal8 does not sell personal information or share it for cross-context behavioural advertising.

Children

The public website and business services are not directed to children. Customers must not configure services involving children unless they have established the lawful authority, notices, consent, safety controls, and supervision required for that use. Contact us if you believe a child's data was provided improperly.

Changes and Contact

We may update this policy when services, providers, laws, or practices change. The last-updated date identifies the current version. Privacy questions and rights requests can be sent to privacy@escal8.tech. Legal notices can be sent to legal@escal8.tech.