This notice explains Curved Solution's current website data flows, including forms, Firebase records and uploads, consented analytics, website audits, and AI processing through Curvo and OpenRouter.
This website wording should be reviewed by a qualified Malaysian legal professional before it is treated as legal advice or a compliance guarantee.
1. About this notice
This Privacy Policy is Curved Solution's personal data protection notice for curvedsolution.com. Curved Solution operates from Cyberjaya, Malaysia and is responsible for deciding how personal data submitted through this website is processed.
This notice explains what we collect, where it comes from, why we use it, who may receive it, how long it is kept, and how to request access or correction. It is written with the Personal Data Protection Act 2010 (PDPA) and its notice-and-choice principles in mind, but it is not a legal opinion or a guarantee of compliance in every circumstance.
2. Personal data and information we collect
Most information comes directly from you when you use a form or choose to save or send a result.
- Contact and project enquiries: name, email address, phone number, company, preferred contact method, service, project type, goals, requirements, timeline, budget range, reference URLs, and message content.
- Consultation requests: contact details, selected date and time, project type, and the summary you provide.
- Quote requests and project configurators: selected products, features, integrations, complexity, number of pages, timeline, planning budget, and the rules-based estimate produced from those selections.
- AI project briefs and idea-planning tools: the non-confidential business problem, audience, goals, features, constraints, timeline, budget range, and generated brief when you explicitly save or send it.
- Support requests: contact details, project name, issue category, priority, description, and supporting files.
- Uploaded files: requirement documents, reference designs, images, or other material you choose to attach. File name, type, size, and storage path are also recorded.
- Website audit submissions: the public website URL you ask us to analyse and the resulting public-page audit data.
- Authentication data: account identifier, email address, sign-in provider, and authorisation claims where an administrator account is used. Client accounts are not currently offered publicly.
- Technical and usage data: browser or device information, user-agent string, pages and features used, timestamps, approximate request source represented by a salted IP hash, error and latency data, cookie choices, and analytics events where you consent to non-essential analytics.
3. Required and optional information
Fields marked as required are needed to process the relevant request. Other fields and file uploads are optional. If required information is not provided, we may be unable to respond, calculate an estimate, reserve a consultation request, or investigate a support issue.
You may browse the public website without submitting a form. Non-essential analytics are optional and can be rejected or changed through Cookie Preferences.
4. How and why we use information
- Respond to enquiries, qualify project requirements, recommend relevant services, prepare consultations, and communicate requested next steps.
- Generate and save project briefs, process rules-based quote requests, and connect a non-confidential AI result to a separate contact workflow when you choose to do so.
- Operate client support, review uploaded material, deliver email notifications, and maintain records of business communications.
- Secure the website, enforce rate limits, verify legitimate application requests, prevent spam and abuse, diagnose failures, and maintain service reliability.
- Measure feature use, performance, and conversions with non-essential analytics only after the applicable consent choice.
- Comply with applicable law, maintain accounting or contractual records, establish or defend legal claims, and protect Curved Solution, its users, and service providers.
5. AI privacy and Curvo
Curved Solution provides AI-powered features including the Curvo AI Assistant, AI Project Advisor, Project Brief Generator, Idea Builder, Intelligent Search, Portfolio AI, and related project-planning tools. When an AI-generated response is required, the prompt, recent conversation context, current page, and relevant verified Curved Solution content may be sent through Curved Solution's server to OpenRouter and the selected model provider. Curved Solution keeps the OpenRouter key server-side.
AI chat messages are kept in your browser session to support conversation memory. Curved Solution records limited operational analytics about AI requests, such as the tool and intent used, response status, model route, latency, character count, browser information, and a salted IP hash; it does not intentionally store the full Curvo conversation in AI analytics. A project brief is stored in Firebase only when you explicitly save or submit it.
Do not enter names, email addresses, phone numbers, passwords, authentication credentials, payment details, confidential company information, sensitive personal data, or material subject to secrecy obligations into Curvo or another free-form AI field. Use the separate contact, consultation, or support form for contact details. Those forms are not sent to the AI model unless a future feature clearly asks for permission first.
AI-generated content can be incomplete, outdated, or wrong. It is general planning and technical information, not guaranteed professional, legal, financial, security, medical, accessibility, or other specialist advice. Independently verify important decisions and current product documentation.
6. Website audit privacy
When you submit a website URL, the server may send that URL to Google PageSpeed Insights and retrieve information that is publicly accessible from the submitted page. The audit does not sign in, use passwords, access private dashboards, bypass access controls, or inspect non-public systems.
Audit results reflect an automated test at a point in time and may vary by network, device profile, or provider availability.
8. Service providers and disclosures
We disclose information only as reasonably necessary for the purposes described above, to professional advisers where necessary, or where required or permitted by law. Current website providers include:
- Firebase and Google Cloud infrastructure for administrator authentication, Firestore records, private file storage, App Check, and consented Firebase Analytics.
- Vercel for website hosting, server functions, security, delivery, and consented Analytics and Speed Insights.
- OpenRouter and the configured AI model provider for AI response generation when an AI feature is used.
- Resend for transactional email notifications and consultation confirmations where email delivery is configured.
- Google PageSpeed Insights for analysis of a public URL submitted to the Website Audit tool.
9. Cross-border processing
Some providers operate infrastructure or support teams outside Malaysia. This means information may be processed in another country when required to provide hosting, email, analytics, storage, security, or AI generation. Curved Solution will use providers and safeguards appropriate to the service and the applicable Malaysian requirements for cross-border transfers.
Because AI providers and routing availability can change, do not place sensitive or confidential information in AI prompts even where a provider states that it applies privacy controls.
10. Data retention
We keep information only for as long as it is reasonably needed for the purpose collected, an active enquiry or client relationship, support and security, dispute resolution, or an applicable legal, tax, accounting, or contractual requirement. Retention depends on the record: an unsent Curvo conversation normally remains only in the browser session; submitted enquiries, consultation requests, quotes, briefs, support records, and files may be retained while follow-up is active and for a reasonable business-record period afterwards.
When information is no longer required, it is deleted, anonymised, or placed beyond routine use in line with the relevant system's deletion and backup cycle. You may ask about the retention basis for a specific submission.
11. Data security
Curved Solution uses server-side validation, rate limiting, Firebase App Check where enforced, restricted Firestore and Storage rules, private upload paths, Firebase Authentication with administrator claims, access controls, and encrypted provider connections. API keys and Firebase administrator credentials are not delivered to the browser.
No internet service can guarantee absolute security. Please avoid sending unnecessary sensitive information and contact us promptly if you believe a submission or account may have been compromised.
12. Access, correction, withdrawal, and deletion requests
Subject to applicable law and any permitted exception, you may ask whether Curved Solution holds personal data about you, request access, ask for inaccurate or incomplete data to be corrected, withdraw consent for future consent-based processing, or request deletion where the data is no longer required. You can also change non-essential analytics consent at any time.
Send a request to info@curvedsolution.com with enough information to identify the relevant submission. We may need to verify your identity and may retain information that must be kept for legal, security, contractual, or record-keeping reasons. We will explain a refusal or limitation where required.
13. Changes and privacy contact
We may update this notice when services, providers, data practices, or legal requirements change. The current version and updated date will remain on this page.
For privacy questions, access or correction requests, consent withdrawal, or concerns about a submission, email info@curvedsolution.com or use the contact page and state that the request concerns privacy.
Contact
Questions or data requests can be sent to info@curvedsolution.com or through our contact page.