Legal
Privacy Policy
Last updated 16 June 2026
This Privacy Policy explains how Innovo AI ("Innovo", "we", "us") collects, uses, discloses, and protects your personal data when you use our recruitment platform. We handle personal data in accordance with Malaysia’s Personal Data Protection Act 2010 (PDPA). By using the platform, you consent to the processing described here.
1. Personal data we collect
Account data: your name, email address, password (stored only as a secure hash), and role (job seeker or employer).
Profile data: for job seekers, your résumé, skills, experience, and preferences; for employers, your company details. Résumés and profiles are sensitive personal data and are treated accordingly.
Usage and technical data: log data, device and browser information, and activity on the platform, used for security, debugging, and improving the service.
2. How we use your data
To provide the service: to create and manage your account, generate AI-assisted job matches, run interviews, process applications, and (for employers) issue invoices.
To communicate with you: account, security, and service notifications.
To keep the platform safe: to detect and prevent fraud, abuse, and security incidents, and to comply with legal obligations.
3. Consent and legal basis
We process your personal data based on the consent you give at sign-up and, where applicable, to perform our contract with you and to meet legal obligations. We record the date you accept this Policy and our Terms.
You may withdraw consent at any time (see "Your rights"), though doing so may mean we can no longer provide some or all of the service.
4. Disclosure of your data
To employers: your profile and résumé are disclosed to an employer only when you apply to their role or otherwise choose to share them.
To service providers: we use trusted processors for cloud hosting, database and file storage, AI processing, error monitoring, and email delivery. They process data on our instructions and are bound to protect it.
For legal reasons: where required by law, regulation, or valid legal process, or to protect our rights and the safety of users.
5. International transfer
Some of our service providers process data on servers located outside Malaysia (for example, within the region or in other jurisdictions). Where data is transferred outside Malaysia, we take reasonable steps to ensure it is afforded a comparable level of protection.
6. Data retention
We retain personal data for as long as your account is active and as needed to provide the service, comply with legal obligations, resolve disputes, and enforce our agreements. When data is no longer required, we delete or anonymise it.
7. Security
We use technical and organisational measures to protect your data, including encryption in transit, access controls, private storage for résumés (served via short-lived signed links), audit logging, and multi-factor authentication for administrators. No system is perfectly secure, but we work to protect your data and to respond promptly to incidents.
8. Your rights
Under the PDPA you may request access to and correction of your personal data, withdraw consent, and limit how your data is processed. You may also request deletion of your account and associated personal data, subject to legal retention requirements.
To exercise these rights, contact us through the platform. We will respond within the timeframes required by applicable law.
9. Cookies
We use strictly necessary cookies to keep you signed in and to secure the platform. We do not use third-party advertising cookies.
10. Changes and contact
We may update this Policy from time to time; material changes will be notified through the platform. For questions or data-protection requests, contact our support team via the platform.