Legal

Privacy Policy

Effective date: 14 May 2026

Last updated: 14 May 2026

Operator / service provider: OC Global Technology Sdn Bhd, Johor Bahru, Malaysia

Controller roles: Participating Schools are controllers for school-provisioned student, staff, and parent records. OCare is controller for account operations, security, support, and legal-compliance data.

Applies to: OCare mobile application (iOS & Android) and the OCare administration dashboard.

This Privacy Policy explains how OC Global Technology Sdn Bhd ("OCare", "we", "us", or "our") collects, uses, discloses, retains, and protects personal data of students, parents, teachers, school coordinators, and administrators who use the OCare platform (the "Service"). We act as a data processor on behalf of participating schools (the "School", which is the data controller for student, staff, and parent records) and as an independent data controller for the limited operational data we collect directly (account credentials, support requests, technical logs).

Summary for parents and guardians. OCare is a school safety and wellbeing app. We collect only what the School and the app need to keep students safe. We do not sell personal data. We do not use student content to train third-party AI models. You can review, correct, or delete an account at any time — see Section 10.
Not a medical device or emergency service. OCare is a wellbeing and safeguarding support tool for schools. It is not a medical device, diagnostic tool, emergency-response service, or substitute for professional counselling, medical advice, or emergency assistance. AI-generated risk scores are screening signals only, may be inaccurate, and are used to assist authorised human reviewers — never to make automated clinical, disciplinary, or enforcement decisions. In a life-threatening emergency, contact your local emergency number (Malaysia: 999) first. We do not display third-party advertising, do not use personal data for advertising or marketing profiling, and do not track users across apps or websites operated by other companies.

1. Scope & Roles

This policy covers personal data processed through the OCare iOS and Android applications, the OCare administration dashboard, the OCare API, and the OCare AI content-moderation service.

For data uploaded or generated by School users in the course of using the Service, the School is the data controller and OCare is the data processor under a written Data Processing Addendum (DPA). For account-level data (login credentials, audit logs, support correspondence), OCare is the data controller.

2. Data We Collect

The categories below align with Apple App Privacy and Google Play Data Safety disclosures.

CategoryExamplesLinked to identity?
Contact InfoName, email, school affiliation, roleYes
IdentifiersUser ID, device ID (for push), session tokensYes
User ContentDiary entries, posts, chat messages, attachments, mood check-ins, SOS alertsYes
Health & WellbeingSelf-reported mood scores, distress indicators from AI moderationYes
Sensitive InfoEmergency contacts, AI-derived safety risk levelsYes
LocationApproximate/coarse location attached to SOS alerts only when the user triggers SOS. OCare does not store precise GPS coordinates.Yes
Photos & MediaAvatar uploads, post and message attachments, voice notesYes
Usage DataScreens viewed, feature interactions, crash logs, performance metricsYes
DiagnosticsApp version, OS, device model, error stack tracesYes
Administrative & audit dataRole, permissions, school affiliation, alert review actions, case escalation status, timestamps, IP/device/session logs, communications with supportYes

We do not collect: precise GPS coordinates outside SOS, contacts list, calendar, microphone or camera streams (only user-initiated captures), browsing history, or financial data.

3. Sources of Data

4. Purposes & Legal Bases

PurposeLegal basis (GDPR Art. 6)
Provide and operate the Service (accounts, feed, chat, diary)Performance of a contract; legitimate interests
Safety features — SOS, emergency contacts, AI moderationVital interests of the data subject; legitimate interests of the School
Wellbeing analytics for schools and parentsPerformance of a contract; legitimate interests
Authentication, audit logging, abuse preventionLegitimate interests; legal obligation
Push notifications for messages, alerts, and announcementsPerformance of a contract; consent (where required)
Service improvement, debugging, security monitoringLegitimate interests
Comply with court orders, regulators, child-protection lawLegal obligation; vital interests

Where processing relies on consent, you may withdraw consent at any time without affecting the lawfulness of processing carried out before withdrawal.

Health and wellbeing data

OCare processes wellbeing-related data, such as mood check-ins, distress indicators, SOS alerts, and AI-derived risk signals, solely to provide school safeguarding and wellbeing support. OCare does not provide medical diagnosis, treatment, or clinical decision-making, and does not use or share wellbeing data for advertising, marketing profiling, or any unrelated purpose.

5. Device Permissions

OCare requests the following device permissions on a strict need-to-use basis. Each can be revoked from the operating system's settings.

PermissionWhyWhen asked
CameraProfile photo, posts, chat attachmentsWhen you tap the camera button
Photo LibraryUpload media to posts, chat, profileWhen you tap the gallery button
MicrophoneVoice notes in chatWhen you start a voice recording
NotificationsDeliver messages, SOS responses, and admin alertsAt first launch
Location (coarse)Attach approximate location to an SOS alertWhen you trigger SOS

6. AI Content Moderation

To support student safety, OCare runs automated content moderation on diary entries, posts, and chat messages. The AI service is operated by us on infrastructure we control. User content is not used to train any third-party model.

Models in use

In-app disclosure

Before students submit diary entries, posts, chat messages, mood check-ins, or SOS alerts, OCare shows an in-app disclosure explaining that the content may be analysed by automated safety systems and, if risk is detected, may be surfaced to authorised school coordinators or administrators for human review. AI scores do not automatically create disciplinary action or formal cases. The full disclosure is repeated during onboarding and remains accessible from Settings → Privacy.

What we send and what we keep

Human oversight

Only named school coordinators and OCare administrators with role-based access can open alerts. AI verdicts never trigger automated disciplinary action; cases are escalated only by a human reviewer. You have the right to contest a verdict from any AI badge in the app ("Tell us this is wrong"), and to request human review under Section 11.

Crisis support

When an own diary entry is rated CRITICAL, OCare surfaces an in-app sheet with crisis resources (Talian Kasih 15999, Befrienders Malaysia +60 3-7956 8145, and a link to your school counsellor) before any other action is taken.

7. User-Generated Content Safety

OCare hosts user-generated content (posts, diary entries, chat messages, media attachments, and voice notes). To reduce harm we combine automated filtering (see Section 6) with human moderation and in-app safety controls.

For urgent content-safety concerns email support@ocare.ocgt.app.

8. Disclosure & Sub-processors

We do not sell personal data and do not share it for cross-context behavioural advertising. We disclose personal data only to:

Current sub-processors

Sub-processorPurposeLocation
OC Global Technology AI serviceContent moderation (operated by us)Malaysia / Singapore
Firebase Cloud Messaging (Google LLC)Push notification deliveryUnited States / EU
AWS Simple Email Service (Amazon Web Services)Transactional emailSingapore (ap-southeast-1)
Cloudflare R2 (Cloudflare, Inc.)Media storage (avatars, attachments)Asia-Pacific
Container hosting providerApplication hostingSingapore
Google Fonts (Google LLC)Web font delivery for public legal pages; receives IP address and user agent of visitors to the public website only. Not used by the mobile app.United States / global CDN

The current list is maintained at https://ocare.ocgt.app/subprocessors. We give schools at least 30 days' notice before adding a new sub-processor.

9. International Transfers

Personal data is primarily hosted in Singapore. Some sub-processors (notably Firebase) may process data in the United States or European Union. Where data leaves Malaysia, the EEA, or the United Kingdom, transfers are protected by Standard Contractual Clauses, adequacy decisions, or equivalent safeguards as required by the Personal Data Protection Act 2010 (Malaysia), the GDPR (EU/EEA), and the UK GDPR.

10. Retention & Account Deletion

DataRetention
Active account profile and contentUntil account deletion or School termination
Deleted account — soft-delete grace period30 days, then permanent erasure
Diary entries and private messages of a deleted accountErased at end of 30-day grace period
Public posts authored by a deleted accountAuthor name and all personally identifiable information within the post are permanently removed/anonymised; only the de-identified text is preserved for shared context. @mentions of the deleted user are stripped.
Resolved admin alerts (AI moderation)90 days
Unresolved admin alertsUntil reviewed
AI alert metadata (linkage to source content)Resolved alerts purged after 90 days; unresolved retained until reviewed. Raw user content associated with an alert remains governed by the retention period of the underlying diary entry, post, message, media attachment, or voice note — it is not held in a separate review copy.
Security audit logs12 months
Backups≤ 35 days, then overwritten

How to delete your account

From the app: Settings → Account → Delete Account. Your account is immediately locked and you are signed out. After 30 days the deletion is irreversible. Signing in again before the grace period ends cancels the deletion.

From the web: https://ocare.ocgt.app/delete-account. You may also email privacy@ocare.ocgt.app with the subject line "Account deletion request" — we respond within 30 days.

11. Your Rights

Subject to your jurisdiction you may have the right to:

To exercise any right, email privacy@ocare.ocgt.app. We verify identity before responding and reply within 30 days (extendable by a further 60 days for complex requests). Student requests are processed in coordination with the School where required by law.

12. Children & Minimum Age

OCare is intended for users aged 13 and older. We do not knowingly create accounts for, or collect personal data from, children under 13.

OCare is not intended for Apple's Kids Category and is not marketed as "for kids" or "for children." It is a school-provisioned safeguarding platform for authorised school communities and users aged 13 or older, unless a higher local minimum age applies.

Student accounts are provisioned by the school administrator. As part of provisioning, the School confirms each student's date of birth and the platform rejects any student under 13. On first launch, every user must confirm they are 13 or older before signing in.

Where local law sets a higher minimum age (for example, GDPR-K in the European Union, where the age may range from 13 to 16 depending on member state), the higher local minimum applies and the School must record appropriate parental authorisation before creating the account.

For US users: OCare complies with the Children's Online Privacy Protection Act (COPPA). Schools provide consent for student users under applicable school-authorisation provisions. Parents may review, refuse, or request deletion of their child's data by contacting the School or privacy@ocare.ocgt.app.

If you become aware that a child under 13 has been registered, contact us at privacy@ocare.ocgt.app and we will delete the account and associated data promptly.

13. Security

No method of transmission or storage is 100% secure. We continuously improve our controls and invite responsible disclosure at security@ocare.ocgt.app.

14. Data Breach Notification

If we become aware of a personal-data breach likely to result in a risk to the rights and freedoms of natural persons, we will notify the affected School(s) without undue delay and, where required by law, the relevant supervisory authority within 72 hours. Affected users will be notified directly when the breach is likely to result in a high risk.

15. Region-Specific Disclosures

15.1 Malaysia (PDPA 2010)

We are registered with the Personal Data Protection Department where required. You may lodge a complaint with the PDP Commissioner at www.pdp.gov.my.

15.2 European Economic Area & United Kingdom (GDPR / UK GDPR)

Our EU/UK representative can be reached at eu-rep@ocare.ocgt.app. Supervisory authorities: EDPB members (EU) and the Information Commissioner's Office (UK).

15.3 California, USA (CCPA / CPRA)

California residents have the right to know, delete, correct, and limit the use of sensitive personal information, and to opt out of "sale" or "sharing". OCare does not sell or share personal information as those terms are defined under the CPRA. To exercise California rights, email privacy@ocare.ocgt.app.

15.4 Other US states

Residents of Virginia, Colorado, Connecticut, Utah, and other states with comprehensive privacy laws have equivalent rights and may contact us at the same address.

16. Changes to This Policy

We may update this Privacy Policy from time to time. Material changes will be notified in the app and/or by email at least 14 days before they take effect. The "Last updated" date at the top reflects the most recent revision. Continued use of the Service after the effective date constitutes acceptance.

17. Contact & Complaints

Data controller: OC Global Technology Sdn Bhd
Privacy / DPO: privacy@ocare.ocgt.app
General support: support@ocare.ocgt.app
Security disclosure: security@ocare.ocgt.app
Postal address: OC Global Technology Sdn Bhd, Unit 09-04, Level 9, City Plaza, Jalan Tebrau, 80300 Johor Bahru, Johor Malaysia

If you are not satisfied with our response, you have the right to complain to the Personal Data Protection Commissioner (Malaysia) or your local supervisory authority.