Privacy Policy

Last updated: 24 June 2026

CoTender ("CoTender", "we", "us" or "our") operates the website at cotender.my and the related CoTender service (the "Service"), which aggregates publicly available Malaysian government procurement information and provides eligibility matching, a contractor directory, market intelligence and related tools. This Privacy Policy explains what personal data we collect, how we use and protect it, and the choices and rights you have. It is issued in accordance with the Personal Data Protection Act 2010 of Malaysia (the "PDPA"). By using the Service, you acknowledge the practices described here.

The party responsible for your personal data (the data user under the PDPA) is J.E. AI Ventures (Registration No. 202603148600 (MA0347902-X)), which operates CoTender. Questions about this Policy or your personal data can be sent to admin@cotender.my.

1. Personal data we collect

We collect the following categories of personal data:

(a) Information you provide.

  • Account and identity: your email address (used for one-time-passcode sign-in), and the company name and registration details you enter or select.
  • Eligibility profile: company grade, categories, specialisations, field codes (CIDB/MOF), certifications and related attributes used to match you to tenders. Where you select a company from our directory these may be pre-filled from public-register data; you may also enter them yourself.
  • Activity you create: saved tenders, saved searches and filters, custom calendar events, and alert preferences.
  • Billing information: when you subscribe, your payment-card details are collected and processed directly by our payment processor (Stripe); we do not receive or store full card numbers. We retain billing metadata such as your subscription status, plan, trial usage and the processor's customer/subscription identifiers.
  • Communications: messages you send us and your contact preferences.

(b) Information from public and third-party sources.

  • Our contractor directory is compiled from publicly available government registers and procurement portals (including the CIDB contractor register and Malaysian government tender portals). For listed contractors this may include the business or registered name, registration number, grade, categories and specialisations, registered address, certification status, award history, and publicly listed contact details (such as email, telephone and fax). This information is obtained from sources that make it publicly available.

(c) Information collected automatically.

  • Usage and device data such as pages viewed, actions taken, approximate location derived from IP address, browser and device type, and similar log data, collected through cookies and analytics tools to operate, secure and improve the Service.

2. How and why we use personal data

We use personal data to:

  • create and administer your account and authenticate sign-in;
  • provide the Service, including matching tenders to your eligibility profile, the directory, calendars, alerts and market intelligence;
  • process subscriptions, trials, payments and related billing, and prevent payment abuse (for example, limiting one free trial per account);
  • send you service and transactional messages (such as sign-in codes, billing notices, and the deadline, tender and digest alerts you have opted into);
  • communicate with businesses about the Service, including relevant outreach, subject to the choices in section 5;
  • maintain the security, integrity and availability of the Service, including audit-logging of sensitive actions (such as when contact details are revealed) and rate-limiting to deter bulk extraction;
  • analyse and improve the Service and develop new features; and
  • comply with legal obligations and enforce our Terms.

3. Legal basis and consent

We process personal data on the basis of your consent (given by providing your data and using the Service), to perform our contract with you, to comply with legal obligations, and for our legitimate interests in operating, securing and improving the Service and informing relevant businesses about it, in each case consistent with the PDPA. Where we rely on consent you may withdraw it as described in section 9; withdrawing consent may mean we can no longer provide some or all of the Service.

4. The contractor directory and publicly sourced data

A core function of the Service is to organise publicly available procurement and contractor-register information. Contractor records in our directory are derived from public government sources; they are not provided to us by the listed contractors. We present this information to help businesses understand the market and identify counterparties. If you are a listed contractor and wish to review, correct, restrict or remove your information, contact us at admin@cotender.my and we will action reasonable requests in accordance with the PDPA. The same information may remain available at its original public source, which we do not control.

5. Marketing and communications; your choices

  • Transactional and service messages (sign-in codes, billing, security, and the tenders and alerts you have requested) are part of the Service and are not promotional.
  • We may contact businesses by email about the Service. Every promotional email contains an unsubscribe link, and you may opt out at any time by using it or by contacting us; once you opt out we will stop sending promotional messages to that address. You may also require us to cease processing your personal data for direct marketing, which we will honour in accordance with the PDPA.

6. Disclosure and sharing

We do not sell your personal data. We share personal data only:

  • with service providers (data processors) who operate the Service on our behalf under confidentiality and security obligations, including Stripe (payments), Supabase (database and authentication hosting), Vercel (application hosting), Resend (transactional and notification email), and product-analytics providers (such as PostHog);
  • where required to comply with law, legal process or a lawful request by a public authority, or to protect our rights, our users or the public, or to enforce our Terms; and
  • in connection with a merger, acquisition, financing or sale of assets, subject to this Policy.

7. Cross-border transfer

The providers above may store and process data outside Malaysia (for example in Singapore or other locations). Where we transfer personal data outside Malaysia, we take reasonable steps so that it remains protected to a standard consistent with the PDPA.

8. Data retention

We retain personal data for as long as your account is active and as needed to provide the Service, and thereafter as required to comply with legal, accounting, tax and dispute-resolution obligations, after which we delete or anonymise it. Directory information sourced from public records is retained for as long as it remains relevant to the Service or until a valid removal request is actioned.

9. Your rights

Subject to the PDPA, you may request access to the personal data we hold about you; request correction of inaccurate or incomplete data; withdraw consent or limit how we process your data; and object to direct marketing. To exercise these rights, contact admin@cotender.my. We may need to verify your identity, and certain requests may be subject to legal limits or reasonable fees as permitted by law. You also have the right to lodge a complaint with the Personal Data Protection Commissioner of Malaysia.

10. Security

We use technical and organisational measures to protect personal data, including access controls and database row-level security, encryption in transit, restricted server-side access to sensitive data, audit-logging of contact reveals, and rate-limiting to deter bulk extraction. No method of transmission or storage is completely secure, and we cannot guarantee absolute security.

11. Cookies and analytics

We use cookies and similar technologies for authentication, to remember preferences, and to measure and improve usage. You can control cookies through your browser settings; disabling some cookies may affect how the Service works.

12. Children

The Service is intended for businesses and persons aged 18 and over and is not directed at children. We do not knowingly collect personal data from children.

13. Third-party links

The Service links to third-party websites, including government portals and source documents. We are not responsible for the privacy practices or content of those sites.

14. Changes to this Policy

We may update this Policy from time to time. We will post the updated version with a new "Last updated" date and, where appropriate, notify you. Your continued use of the Service after changes take effect constitutes acknowledgement of the updated Policy.

15. Contact

Questions, requests or complaints about this Policy or your personal data: admin@cotender.my, J.E. AI Ventures (Registration No. 202603148600 (MA0347902-X)). See also our Terms of Service.