Last updated: 16 April 2026
Kyoik.com ("we", "us", or "our") is operated by Vessel Business Network (202003085850), registered in Malaysia.
We are committed to protecting your personal data and respecting your privacy. This Privacy Policy explains how we collect, use, store, and protect your information when you visit our website at https://kyoik.com, in compliance with Malaysia's Personal Data Protection Act 2010 (PDPA) and the General Data Protection Regulation (GDPR).
When you create an account to access our courses, we collect:
Account creation and authentication is handled by Clerk, a third-party authentication service (see Section 6).
When you fill in our contact form, we collect:
When you browse our website, we may automatically collect:
This data is collected through cookies and similar technologies (see Section 4).
When you enrol in a course, we store the following in our database:
This data is stored on our servers in a Neon PostgreSQL database (see Section 6).
When you use our courses, the following data is stored locally in your browser (localStorage):
This data is stored only in your browser and is not transmitted to our servers. You can clear this data at any time by clearing your browser's local storage for this site.
Our mini courses include AI-powered features that send data to third-party AI services:
These requests are processed through our server and do not include your name, email, or other personal identifiers. See Section 6 for details on the AI services we use.
When you complete a course and claim a certificate, we collect:
This information is submitted via Web3Forms and is shared with Kyoik and the course leader to support your learning.
We may also collect information from emails, WhatsApp messages, and other communications exchanged in the course of serving you.
We use the information we collect for the following purposes:
We process your personal data based on your consent, which you provide when submitting our contact form or accepting cookies on our website. You may withdraw your consent at any time by contacting us.
We process your data based on:
Our website uses cookies to enhance your browsing experience and analyse website traffic.
Cookies are small text files stored on your device when you visit a website. They help us understand how you use our site and improve your experience.
| Cookie | Provider | Purpose | Duration |
|---|---|---|---|
| _ga | Google Analytics | Distinguishes unique visitors to track site usage | 2 years |
| _ga_* | Google Analytics | Maintains session state for analytics | 2 years |
| cookie_consent | Kyoik.com | Stores your cookie preference | 1 year |
| __session | Clerk | Maintains your signed-in session | Session / up to 7 days |
| __client_uat | Clerk | Tracks authentication state for session management | Session / up to 7 days |
In addition to cookies, our mini courses use browser local storage to save your progress:
| Key | Purpose | Duration |
|---|---|---|
| kyoik_course_* | Stores course progress, quiz scores, and chat history for each mini course | Until manually cleared |
| cookie_consent | Stores your cookie consent preference | Until manually cleared |
Local storage data stays on your device and is not sent to our servers. You can clear it at any time through your browser settings.
When you first visit our website, you will see a cookie consent banner. You can:
If you click Decline, no Google Analytics scripts are loaded and no tracking cookies are set.
You can also manage cookies through your browser settings. Note that disabling cookies may affect your browsing experience. You can change your cookie preference at any time by clearing your browser's local storage for this site.
We use the following third-party services that may process your data:
We use Google Analytics to understand how visitors interact with our website. Google Analytics collects data such as pages visited, session duration, and general location. This data is aggregated and anonymised. Google's privacy policy: https://policies.google.com/privacy.
You can opt out of Google Analytics by declining cookies on our website or by installing the Google Analytics Opt-out Browser Add-on.
Our contact form submissions are processed through Web3Forms. When you submit our contact form, your data is sent to Web3Forms for delivery to our email. Web3Forms' privacy policy: https://web3forms.com/privacy.
We use Clerk to manage user accounts, sign-up, sign-in, and session management. When you create an account, Clerk collects and stores your email address, name, phone number (if provided), and profile image. Clerk sets session cookies on your device to maintain your signed-in state. Clerk's privacy policy: https://clerk.com/legal/privacy.
We use Neon, a serverless PostgreSQL database service, to store your enrolment records and account details (synced from Clerk). This data is stored securely and used solely for providing course access and your dashboard. Neon's privacy policy: https://neon.tech/privacy-policy.
Our mini courses use AI-powered features provided through OpenRouter, which routes requests to AI models:
These requests are made through our server. No personal identifiers (name, email, etc.) are included in the requests. OpenRouter's privacy policy: https://openrouter.ai/privacy.
Our mini courses embed YouTube videos using the privacy-enhanced mode (youtube-nocookie.com). This means YouTube does not set tracking cookies on your device until you play a video. When you play a video, YouTube may collect usage data according to their privacy policy. Google's privacy policy: https://policies.google.com/privacy.
We load fonts from Google Fonts (fonts.googleapis.com). When you visit our website, your browser makes a request to Google's servers to download the font files. This may transmit your IP address and browser information to Google. Google Fonts' privacy information: https://developers.google.com/fonts/faq/privacy.
We do not sell, rent, or trade your personal data to third parties. We may share your data only in these circumstances:
We retain your personal data only for as long as necessary:
We implement appropriate technical and organisational measures to protect your personal data, including:
While we strive to protect your personal data, no method of internet transmission is 100% secure. We cannot guarantee absolute security.
You have the right to:
In addition to the above, you also have the right to:
To exercise any of these rights, including requesting deletion of your account and all associated data, please contact us at hi@kyoik.com. We will respond to your request within 21 days (PDPA) or 30 days (GDPR).
Our website is hosted and may process data outside of Malaysia and the EU/EEA. When data is transferred internationally, we ensure appropriate safeguards are in place through the use of reputable service providers who comply with applicable data protection laws.
If our business is sold or transferred to another party, your personal data may be disclosed to the new owners to enable them to continue operating the business. We will take reasonable steps to ensure that your personal data remains protected and is used solely for the purposes for which it was collected. We will comply with all applicable data protection laws when disclosing personal data in the context of a business transfer.
Our services are intended for professionals and business owners. We do not knowingly collect personal data from children under 18. If you believe we have collected data from a child, please contact us immediately at hi@kyoik.com.
We may update this Privacy Policy from time to time to reflect changes in our practices or applicable laws. When we make changes, we will update the "Last updated" date at the top of this page. The latest version of this policy is always available on this page. We encourage you to review this policy periodically.
| Date | Changes |
|---|---|
| 16 Apr 2026 | Added disclosures for Clerk authentication (account data, session cookies), Neon PostgreSQL database (enrolment records), certificate claim data sharing with course leaders, and updated data retention and third-party service sections accordingly. |
| 13 Mar 2026 | Initial version. Covers contact forms, Google Analytics, course progress (localStorage), AI services (TTS and chat via OpenRouter), YouTube embeds, Google Fonts, cookie consent, and PDPA/GDPR compliance. |
If you have questions about this Privacy Policy or wish to exercise your data protection rights, please contact us: