Privacy Policy
Effective date: 19 July 2026
1. Introduction
This Privacy Policy explains how Workcyte Digital Academy (SSM Registration No. 202603071928), operating the Bibliomatica service, collects, uses, discloses, and protects your personal data. This Policy is issued in accordance with the Malaysian Personal Data Protection Act 2010, as amended by the Personal Data Protection (Amendment) Act 2024 ("PDPA"). It is also informed by internationally recognized data protection principles, including the EU General Data Protection Regulation ("GDPR"), for users outside Malaysia. We act as the "data controller" for the personal data described in this Policy.
2. Personal Data We Collect
Account and authentication data: email address (required, for authentication via magic link), name (optional, provided at onboarding), session cookies and authentication tokens. Content: bibliographic corpora you upload (CSV, RIS, BibTeX, or exported search results), analysis outputs (citation networks, computed metrics, generated manuscripts), and project metadata. Encrypted credentials: bring-your-own-key (BYOK) API keys for Large Language Model providers, encrypted at rest using AES-256-GCM. Billing and subscription data: subscription status, tier, and renewal history; payment metadata (transaction IDs, amounts). We do not store your payment card details; card and account details are held by our payment processors (Stripe and CHIP). Technical data: IP address (for security, geo-detection, and abuse prevention), user agent, access logs and audit trails.
3. Purposes of Processing
We process your personal data to authenticate you and provide the Service; process your Subscription payments and send billing communications; execute analyses you initiate (which may require sending queries to Third-Party Services on your behalf); communicate with you about the Service (transactional emails only, no marketing without your consent); prevent, detect, and investigate abuse, fraud, and security incidents; improve the Service in aggregated, non-identifying form; and comply with our legal obligations.
4. Legal Basis for Processing
We process your personal data under contract performance (to provide the Service you have subscribed to); legitimate interest (to secure the Service, prevent abuse, and improve reliability); consent (where you have provided consent, for example for optional analytics); and legal obligation (where required by applicable law).
5. Data Sharing and Sub-Processors
We do not sell your personal data. We share your data only with the following categories of recipients. Infrastructure sub-processors necessary to operate the Service: Vercel Inc. (United States) for web application hosting; Neon (Singapore, ap-southeast-1) for PostgreSQL database; Fly.io (Singapore) for statistical compute; Tigris Data (Fly.io Storage) for object storage of uploaded corpora; Resend (Tokyo, ap-northeast-1) for transactional email; Sentry (European Union) for application error monitoring and alerting. Payment processors: Stripe Inc. (United States and globally) for international USD subscriptions; CHIP In (Malaysia) for Malaysian MYR subscriptions. Academic metadata APIs queried on your behalf when you run analyses: OpenAlex, ROR (Research Organization Registry), ORCID. Large Language Model providers you connect via BYOK: your API keys and prompts are sent directly to these providers. Their handling of your data is governed by their respective privacy policies. Bibliomatica does not retain LLM prompt or response content beyond the immediate request. Legal and compliance: government authorities or courts where required by law.
6. Cross-Border Data Transfers
Some of our sub-processors are located outside Malaysia. We transfer personal data to these locations in accordance with the PDPA and the Personal Data Protection Guidelines No. 03/2025 on Cross-Border Personal Data Transfer, relying on one or more of: performance of your subscription contract (PDPA Section 129(3)(b)); your consent, given by accepting this Privacy Policy (PDPA Section 129(3)(a)); or substantially similar law or adequate protection where destinations such as Singapore (under its PDPA 2012) and Japan (under its APPI) provide protection assessed by us as at least equivalent to the Malaysian PDPA (PDPA Section 129(2)). We conduct Transfer Impact Assessments as required by law before onboarding new sub-processors handling personal data.
7. Data Retention
We retain your personal data for as long as your Account is active. After cancellation, your Account transitions to read-only and we retain your Content indefinitely so you can access it upon resubscription, unless you request deletion. Upon written request to security@bibliomatica.app, we will delete your Account and Content within 30 days, subject to legal retention obligations (for example, billing records for tax purposes, retained for 7 years per Malaysian tax law). Deleted data may persist in encrypted backups for up to 30 days after deletion, after which it is permanently removed.
8. Your Rights
Under the PDPA and, where applicable, the GDPR, you have the right of access (to obtain confirmation of whether we process your personal data and receive a copy); right of correction (to correct inaccurate or incomplete personal data); right to withdraw consent (to withdraw any consent you have given); right to data portability (to receive your personal data in a structured, machine-readable format and, where technically feasible, have it transmitted directly to another controller, per PDPA Section 43A); right to erasure (to request deletion, subject to our legal retention obligations); and right to object (to processing based on legitimate interest, in specific circumstances). To exercise any of these rights, email security@bibliomatica.app. We will respond within 21 days as required by the PDPA. If you believe our processing of your personal data violates the PDPA, you may file a complaint with the Personal Data Protection Commissioner (Jabatan Perlindungan Data Peribadi, JPDP) at pdp.gov.my.
9. Data Breach Notification
In the event of a personal data breach that is likely to cause significant harm to you, we will notify the Personal Data Protection Commissioner as soon as practicable and within 72 hours where feasible, as required by Section 12B of the PDPA; notify you directly, without unnecessary delay; and provide guidance on protective steps you can take.
10. Cookies and Similar Technologies
We use only strictly necessary cookies: a session cookie to keep you signed in during your session, and a CSRF token cookie to protect against cross-site request forgery attacks. We do not use marketing cookies, third-party advertising trackers, or cross-site tracking. Our analytics (via Vercel Analytics) is privacy-friendly and aggregated, without individual user tracking.
11. Children
The Service is intended for users aged 18 and older. We do not knowingly collect personal data from children under 18. If you believe we have collected data from a child, contact security@bibliomatica.app and we will delete it.
12. Security Measures
We implement technical and organizational measures to protect your personal data, including encryption in transit (TLS 1.3); encryption at rest for sensitive data (BYOK keys with AES-256-GCM); access controls and audit logging; regular security reviews and updates; and sub-processor security assessments.
13. Changes to This Policy
We may update this Policy from time to time. We will notify you of material changes by email at least 14 days before the changes take effect.
14. Contact
Data Controller: Workcyte Digital Academy (SSM No. 202603071928), Malaysia. Privacy and data protection matters: security@bibliomatica.app. General support: support@bibliomatica.app.