Privacy Policy
Last Updated: September 2026
NexESG is an enterprise ESG data management platform operated by SomaTech ("we," "our," or "us"). We are committed to protecting your privacy and to ensuring your data is handled in compliance with the Personal Data Protection Act 2010 (PDPA) of Malaysia, as amended, and other applicable data protection regulations.
1. Information We Collect
As an enterprise B2B platform, we collect information primarily to provide our Services to your organisation. This includes:
- Account Information: Names, business email addresses, and roles of authorised users.
- Corporate Data: ESG metrics, sustainability disclosures, and uploaded evidence documents (invoices, receipts, meter readings) submitted to the platform.
- Communications: Messages exchanged between users in your organisation, including any voice recordings sent through the platform, review comments left against data entries, and your conversation history with the AI assistant.
- Usage Data: System logs, audit trails, and authentication records to maintain platform security and integrity.
- Website Measurement: Aggregated visit and performance measurement on our public website, collected by our hosting provider without advertising cookies or cross-site tracking.
2. How We Use Your Data
We use the collected data strictly to:
- Provide, operate, and maintain the NexESG platform.
- Facilitate the processing of your ESG data via our document extraction and drafting features.
- Generate regulatory-aligned sustainability reports for your organisation.
- Provide customer support and send critical system notifications.
We do not use your corporate data, documents or communications to train any machine learning model, and the AI provider we rely on is contractually prohibited from using content submitted through their interface to train theirs.
3. Where Your Data Is Held
Your database records and uploaded documents are stored in Singapore. The application itself is delivered from a global hosting network, and requests to our AI provider are processed in the United States. Data transferred outside Malaysia is protected by the contractual terms we hold with each provider named below.
If your organisation requires that data remain within a particular jurisdiction, please raise this with us before onboarding so we can confirm whether we are able to meet that requirement.
4. Data Sharing & Service Providers
We do not sell, rent, or trade your corporate or personal data, and we do not disclose it to any third party for their own purposes. To operate the platform we rely on the following categories of provider, each bound by contractual confidentiality and security obligations:
- Database, authentication and file storage — managed infrastructure located in Singapore, holding your records, documents and account credentials.
- Application hosting and website measurement — serves the platform and records aggregated usage and performance data for our public website.
- AI processing — document extraction, narrative drafting and the AI assistant send the relevant content to a third-party AI provider in order to return a result. That content is not used to train their models.
We will also disclose data where required by law or by a valid order of a competent authority. A current list of our providers and the locations in which they operate is available on request.
5. Administrative Access
Access between customer organisations is blocked by security policies enforced by the database itself, so one customer cannot reach another customer's data.
Separately, a small number of our authorised personnel hold administrative access, used to provision organisations, issue and revoke access keys, provide support, and carry out a data wipe at your request. That access is limited to named individuals, is subject to confidentiality obligations, and is used only to operate the service or when you ask us to act.
6. Personal Data Within Your Submissions
Sustainability reporting may require you to submit information about your workforce, such as headcount breakdowns or commuting data. Where that information relates to identifiable individuals, your organisation remains responsible for it as the data controller and we process it on your instructions. You are responsible for having a lawful basis to provide it, and we recommend submitting workforce information in aggregate wherever the relevant indicator permits.
7. Data Subject Rights
Under the PDPA, users have the right to request access to, correction of, or deletion of their personal data. To exercise these rights, please contact your organisation's Master Admin or reach out to us directly at info@somatech.my.