Legal & Compliance

Privacy Policy

Effective date: 13 July 2026 Last updated: 13 July 2026 Version: 2.0
This Privacy Policy describes how Codemax Sdn Bhd and its subsidiaries, affiliates, and jointly controlled entities (collectively "Codemax," "we," "us," or "our") collect, use, process, and disclose your personal data when you access or use our software-as-a-service (SaaS) platform, mobile applications, websites, APIs, and related services (collectively, "Services"). It applies to customers, end users, agents, vendors, contractors, and service providers (collectively "you" or "your").
Section 01

Data We Collect

We collect information that is necessary to provide, maintain, and improve our Services. The categories below outline what we collect and why.

1.1 Types of Personal Data

Category Examples
Contact Information Full name, business email address, postal address, phone number.
Account Credentials Username, hashed password, multi-factor authentication tokens, and other access credentials.
Billing & Payment Company name, billing address, payment method details (processed by our PCI-DSS compliant payment processors — we do not store full card numbers).
Usage & Log Data IP address, browser type, operating system, pages visited, feature interactions, API call logs, error reports, and session timestamps.
Device Information Device model, unique device identifiers, mobile network information.
Location Data Approximate location derived from IP address; precise GPS data only where you have explicitly granted permission.
Communications Records of support tickets, live chat transcripts, emails, and survey responses.
Customer Content Data, files, or information you upload to or generate within our platform in the course of using the Services.
Other Voluntary Data Any additional information you choose to provide when completing forms or during onboarding.

1.2 How We Collect Data

We collect personal data through the following means:

  • Directly from you during account registration, onboarding, and product setup.
  • Automatically through our platform, APIs, and web technologies (cookies, web beacons, server logs).
  • From your interactions with our customer support, sales, and marketing teams.
  • Through third-party integrations and connected services you authorise.
  • From business partners, resellers, or referral sources with your consent.
  • When you participate in surveys, events, webinars, or feedback programmes.
Section 02

How We Use Your Data

We process your personal data on the lawful bases of contractual necessity, legitimate interest, legal obligation, and/or your explicit consent, depending on the purpose.

Purpose Description
Service Delivery To provision, operate, and maintain your account, process transactions, and deliver the features you've subscribed to.
Customer Support To investigate and resolve issues, respond to queries, and improve our support quality and response times.
Platform Improvement To conduct research, analyse usage patterns, identify bugs, and develop new features and enhancements.
Security & Fraud Prevention To monitor for suspicious activity, enforce our Terms of Service, and protect the integrity of our platform.
Communications To send service-related notifications, product updates, maintenance alerts, and (where consented) marketing communications via email, push notification, or in-app messaging.
Billing & Finance To process payments, issue invoices, manage subscriptions, and comply with financial record-keeping requirements.
Legal Compliance To fulfil obligations under applicable laws, respond to lawful requests, and enforce our contractual rights.
Analytics & Reporting To generate aggregated, anonymised insights about platform performance and customer behaviour that inform product decisions.
We will never sell your personal data to third parties, and we will not use your Customer Content to train our AI or machine-learning models without your explicit written consent.
Section 03

Disclosure of Personal Data

We may share your personal data with third parties only under the circumstances described below. All third parties are required to handle your data in a manner consistent with this Privacy Policy and applicable law.

Recipient Circumstances & Safeguards
Service Providers Sub-processors (e.g., cloud hosting, payment gateways, analytics vendors) who assist in operating our platform. All are bound by data processing agreements and prohibited from using your data for any other purpose.
Group Companies Our subsidiaries, associated companies, and affiliates, where necessary to deliver the Services or improve shared infrastructure.
Business Partners Technology partners or resellers with whom you have established a separate relationship, and only to the extent necessary to fulfil that arrangement.
Legal & Regulatory Authorities Government agencies, courts, or law enforcement where we are required to do so by law, court order, or to protect the safety and rights of our users or the public.
Corporate Transactions Potential acquirers, investors, or successors in the context of a merger, acquisition, or asset sale, subject to confidentiality obligations. You will be notified of any change of controller.
With Your Consent Any other third parties where you have explicitly authorised the disclosure. If documentation you provide contains unnecessary sensitive personal data, please redact it before submission.
Section 04

Data Retention

We retain personal data for as long as necessary to fulfil the purposes described in this Privacy Policy, unless a longer retention period is required or permitted by law.

Specifically:

  • Account data is retained for the duration of your subscription and for up to 7 years after account closure to comply with legal and tax obligations.
  • Customer Content is deleted or returned to you within 90 days of account termination, unless legally required to be retained longer.
  • Log and security data is retained for up to 12 months for incident investigation and fraud prevention.
  • Marketing data is retained until you withdraw consent or request erasure, whichever comes first.

When data is no longer required, we securely delete or anonymise it in accordance with industry best practices.

Section 05

International Transfers of Personal Data

As a SaaS provider, your personal data may be processed in countries other than your country of residence, including countries whose data protection laws may differ from those in your jurisdiction.

Where data is transferred outside Malaysia, we implement appropriate safeguards including:

  • Standard contractual clauses approved by relevant data protection authorities.
  • Binding corporate rules for intra-group transfers.
  • Transfers only to jurisdictions with an adequate level of data protection as recognised by the applicable regulator.

All such transfers are conducted in compliance with the Personal Data Protection Act 2010 (PDPA) and other applicable laws.

Section 06

Security of Personal Data

We implement technical and organisational security measures commensurate with the sensitivity of the data we process. Our controls include, but are not limited to:

  • Encryption of data in transit (TLS 1.2+) and at rest (AES-256).
  • Role-based access controls and principle of least privilege.
  • Multi-factor authentication for internal system access.
  • Regular penetration testing and vulnerability assessments.
  • Security incident response and breach notification procedures.
  • Vendor due diligence and sub-processor security assessments.
While we apply industry-standard safeguards, no method of electronic transmission or storage is 100% secure. We cannot guarantee absolute security, and any transmission of data to our platform is at your own risk. We will notify you promptly in the event of a data breach affecting your personal data, in accordance with applicable law.
Section 07

Your Rights Over Your Data

Subject to applicable law and reasonable verification of your identity, you have the following rights with respect to your personal data:

Access

Request a copy of the personal data we hold about you and information about how it is processed.

Rectification

Correct inaccurate or incomplete personal data. Most account data can be updated directly in your account settings.

Erasure

Request deletion of your personal data where it is no longer necessary for the purposes collected, or where you withdraw consent.

Data Portability

Receive a copy of your data in a structured, machine-readable format to transfer to another service provider.

Restriction

Request that we limit the processing of your personal data under certain circumstances.

Objection

Object to processing based on our legitimate interests or for direct marketing purposes at any time.

Withdraw Consent

Where processing is based on your consent, withdraw it at any time without affecting prior lawful processing.

Lodge a Complaint

File a complaint with the relevant data protection authority in your jurisdiction if you believe your rights have been violated.

To exercise any of these rights, please contact us at the details provided in the Contact section. We will respond within 30 days.

Section 08

Cookies & Tracking Technologies

We use cookies and similar tracking technologies on our websites and platform to support functionality, analyse usage, and personalise your experience.

Types of cookies we use

  • Essential cookies — required for the platform to function and cannot be disabled.
  • Analytics cookies — help us understand how users interact with our platform (e.g., pages viewed, session duration). Data is aggregated and anonymised where possible.
  • Preference cookies — remember settings such as language, timezone, and display preferences.
  • Marketing cookies — used only with your consent to deliver relevant advertising and measure campaign effectiveness.

You can manage or withdraw cookie consent at any time through our cookie preference centre or your browser settings. Note that disabling certain cookies may affect platform functionality.

Section 09

Children's Privacy

Our Services are intended for use by businesses and individuals aged 18 and above. We do not knowingly collect personal data from children under the age of 18. If we become aware that personal data from a minor has been submitted to our platform without verifiable parental consent, we will take steps to delete that data promptly.

If you believe a minor has provided us with personal data, please contact us immediately at the address below.

Section 10

Amendments & Policy Updates

We may revise this Privacy Policy periodically to reflect changes in our practices, technology, legal requirements, or business operations. When we make material changes, we will:

  • Update the "Last updated" date at the top of this page.
  • Send a notification to the primary email address associated with your account, or display a prominent in-product notice.
  • Where required by law, obtain your renewed consent before the changes take effect.

Your continued use of our Services after the effective date of any update constitutes your acceptance of the revised Privacy Policy. We encourage you to review this page regularly.

Contact

Contact Us

If you have questions, concerns, or requests relating to this Privacy Policy or the processing of your personal data — including requests to exercise your data subject rights — please reach out to us:

Codemax Sdn Bhd

Address 12F-1, Level 12, PFCC @ Tower 4,
Bandar Puteri Puchong,
47100 Selangor, Malaysia
DPO For data protection matters: privacy@codemax.my

We aim to respond to all enquiries within 5 business days and to fulfil data subject requests within 30 days of receipt.