Privacy Policy
Last updated: May 2026
1. About this Policy
This Privacy Policy ("Policy") describes how Codemax Sdn Bhd ("Codemax", "we", "us" or "our") collects, uses, discloses, transfers, retains, and otherwise processes personal data when you visit https://codemax.my (the "Site"), interact with our marketing, register for an event, request a demo, contact our sales or support teams, apply for a job, or use any product, platform, or service we provide (collectively, the "Services").
We are committed to handling personal data lawfully, fairly, and transparently in accordance with:
- the Personal Data Protection Act 2010 of Malaysia (the "PDPA") and its subsidiary legislation (including subsequent amendments);
- the EU General Data Protection Regulation (Regulation (EU) 2016/679) and the UK GDPR, to the extent applicable to our processing of personal data of individuals in the European Economic Area, the United Kingdom, or Switzerland; and
- other applicable data protection laws in jurisdictions where we operate or offer Services.
2. Data Controller
For the purposes of the PDPA, Codemax Sdn Bhd is the "data user". For the purposes of the GDPR, Codemax Sdn Bhd is the "data controller" of personal data we collect directly from you in connection with our website, marketing, sales, and support activities.
When we host or process personal data on behalf of business customers as part of the Services (for example, end-user data inside our products), the customer is the controller / data user and we act as a "data processor" under the GDPR (and as a service provider under the PDPA). That processing is governed by the customer's agreement with us and any Data Processing Addendum executed with the customer, which take precedence over this Policy for the data covered by them.
Privacy queries should be sent to our Data Protection Officer at info@codemax.my.
3. Categories of Personal Data We Collect
We collect personal data in the following categories:
- Identity and contact data — name, business email, phone number, job title, company name and address, country.
- Account data — username, hashed credentials, account preferences, role, audit logs.
- Commercial data — billing contact, billing address, tax identification number, purchase history (note: payment card data is processed by our payment processors and is not stored by Codemax).
- Usage and technical data — IP address, browser type and version, device identifiers, operating system, referring URL, pages visited, timestamps, performance and diagnostic logs.
- Marketing data — preferences for receiving communications and any feedback you provide.
- Communications — content of emails, chat messages, and support tickets you send us.
- Event data — information collected when you register for or attend an event we organise or co-host.
- Recruitment data — CV, work history, references, and other information you provide when applying for a role with us.
We do not knowingly collect personal data from children under the age of 18. We also do not actively collect special categories of personal data (such as health information, political opinions, or biometric data) through our Site or marketing. Where any such data is processed inside our Vision AI or other operational products, it is processed on behalf of our customers under the applicable agreement.
4. Sources of Personal Data
We collect personal data from the following sources:
- Directly from you — when you fill in a form, request a demo, subscribe, attend an event, contact us, or apply for a job.
- Automatically — through cookies and similar technologies, as described in our Cookie Policy.
- From our customers — when our customers configure the Services or grant access to their users.
- From third parties — such as business directories, partners, resellers, professional networks, and publicly available sources, where permitted by law.
5. Purposes and Legal Bases for Processing
We process personal data only where we have a valid legal basis. Under the PDPA, our processing is based on your consent (express or, where permitted, deemed) and on the lawful conditions in the PDPA. Under the GDPR, we rely on the legal bases set out below:
- Performance of a contract — to provide the Services, manage your account, process orders and payments, and provide support.
- Legitimate interests — to operate, secure, and improve the Services and our business; to detect and prevent fraud; to communicate with customers and prospects about products they have shown interest in; to maintain anti-money-laundering and sanctions screening; and to defend legal claims. Where we rely on legitimate interests, we balance them against your rights and freedoms.
- Consent — for marketing communications, certain cookies, and any other processing for which consent is required. You can withdraw consent at any time without affecting the lawfulness of prior processing.
- Legal obligation — to comply with tax, accounting, anti-money-laundering, anti-bribery, and other regulatory obligations.
- Vital interests / public interest — in the rare cases where processing is necessary to protect someone's life or to comply with a public interest task imposed by law.
6. How We Use Personal Data
We use personal data to:
- operate, maintain, and deliver the Services to you and your organisation;
- verify your identity, manage your account, and provide customer support;
- process payments, issue invoices, and meet our tax and accounting obligations;
- secure the Services, detect and respond to fraud, abuse, and security incidents;
- communicate with you about your account, transactions, security alerts, and policy changes;
- send you marketing communications where you have opted in (or where permitted by applicable law);
- understand how the Site and Services are used and to improve them, including by performing analytics, research, and product development;
- organise events, run webinars, and engage with attendees;
- assess job applications and manage our recruitment processes;
- enforce our terms, protect our and others' rights, and defend legal claims; and
- comply with applicable laws and respond to lawful requests from authorities.
7. Disclosure of Personal Data
We may disclose personal data to:
- Affiliates within the Codemax group, on the same terms as this Policy.
- Service providers and processors — including cloud hosting (e.g. major public cloud providers), email delivery, analytics, CRM, customer support, payment processing, accounting, fraud-prevention, and identity-verification providers, who act on our documented instructions under appropriate contracts.
- Channel partners and resellers — where they introduced you to Codemax or where required to deliver the Services.
- Professional advisors — auditors, lawyers, bankers, and insurers, under duties of confidentiality.
- Authorities — courts, regulators, and law-enforcement agencies, where required by law or to protect rights, property, or safety.
- In a corporate transaction — in connection with a financing, merger, acquisition, restructuring, or sale of assets, subject to confidentiality safeguards.
We do not sell personal data and we do not share personal data for cross-context behavioural advertising in the meaning of "sale" or "share" under applicable consumer-privacy laws.
8. International Transfers
Codemax is headquartered in Malaysia and uses service providers in multiple jurisdictions. Personal data may be transferred to, stored in, or processed in countries outside your country of residence, including outside the European Economic Area, the United Kingdom, and Malaysia.
Where required by law, we put in place safeguards for international transfers, including:
- the European Commission's Standard Contractual Clauses and the UK International Data Transfer Addendum, where transferring personal data of EU/UK individuals to countries that do not benefit from an adequacy decision;
- conducting transfer impact assessments where appropriate; and
- complying with the PDPA's restrictions on transfers outside Malaysia, including obtaining your consent or relying on the permitted grounds in the PDPA.
Contact info@codemax.my for a copy of the relevant transfer mechanism applicable to your data.
9. Data Retention
We retain personal data only for as long as is necessary for the purposes set out in this Policy or as required by law. Specifically:
- Customer account data — for the duration of your subscription, plus a reasonable period afterwards for legal, audit, and dispute-resolution purposes;
- Marketing data — until you opt out, plus a short period to honour the opt-out;
- Transaction and tax records — for the period required by Malaysian tax and corporate laws (generally seven years);
- Recruitment data — for up to twelve (12) months after the application is closed, unless you consent to a longer retention period for talent-pool purposes; and
- Website logs and telemetry — typically up to twelve (12) months, except where required to investigate security incidents.
When retention ends, we securely delete or anonymise personal data.
10. Your Rights
Subject to applicable law, you have the following rights in relation to your personal data:
- Access — to request confirmation of whether we hold your personal data and a copy of it.
- Correction / Rectification — to ask us to correct inaccurate or incomplete personal data.
- Erasure — to ask us to delete personal data in certain circumstances (the "right to be forgotten" under GDPR).
- Restriction — to ask us to restrict processing in certain circumstances.
- Objection — to object to processing based on our legitimate interests or to direct marketing.
- Withdrawal of consent — to withdraw any consent you previously gave, without affecting the lawfulness of prior processing.
- Data portability — to receive certain data in a structured, commonly used, machine-readable format and to transmit it to another controller (where the GDPR applies).
- No solicitation — under the PDPA, to require us to stop or not begin processing your personal data for the purpose of direct marketing.
- Complaints — to lodge a complaint with the Department of Personal Data Protection (Jabatan Perlindungan Data Peribadi, "JPDP") in Malaysia or, where applicable, with your local EU/UK supervisory authority.
To exercise any of these rights, email info@codemax.my. We will verify your identity and respond within the timeframes required by applicable law (generally 21 days under the PDPA and one month under the GDPR, which may be extended for complex requests).
11. Automated Decision-Making
We do not make decisions producing legal or similarly significant effects about you solely on the basis of automated processing. Where any such processing occurs (for example, fraud screening), we will inform you and provide the rights required by applicable law, including the right to obtain human intervention, to express your view, and to contest the decision.
12. Security
We implement administrative, technical, and physical safeguards designed to protect personal data against accidental or unlawful destruction, loss, alteration, unauthorised disclosure, or access. These include encryption in transit and at rest where appropriate, access controls and least-privilege principles, network segmentation, vulnerability management, secure development practices, employee training, and regular reviews of our security posture. No method of transmission or storage is 100% secure; in the event of a personal data breach affecting you, we will notify you and the relevant authorities where required by law.
13. Cookies and Similar Technologies
We use cookies and similar technologies on the Site. For details, see our Cookie Policy. You can manage your preferences at any time via the "Cookie settings" link in the footer of any page.
14. Third-Party Sites
The Site may contain links to third-party websites or services. We are not responsible for the privacy practices of those third parties, and we encourage you to read their privacy notices.
15. Changes to this Policy
We may update this Policy from time to time. The "Last updated" date at the top of this page indicates the latest revision. For material changes, we will give reasonable advance notice (for example, by email or by prominent notice on the Site). Continued use of the Services after the effective date constitutes acceptance of the updated Policy.
16. How to Contact Us
Data Protection Officer
Codemax Sdn Bhd
Email: info@codemax.my
Web: Contact us
If you are based in the EU/UK and prefer to contact a representative, please write to the address above; we will provide the relevant representative's details on request.