← Back to Home
Legal & Compliance — Privacy Notice / Notis Privasi

DATAKEY SDN BHD — PRIVACY NOTICE

Effective Date: 10 August 2026

Last Updated: 10 August 2026


NOTIS PERLINDUNGAN DATA PERIBADI (BAHASA MALAYSIA)

In accordance with Section 7(3) of the Personal Data Protection Act 2010 (PDPA), this Privacy Notice is issued in both English and Bahasa Malaysia. In the event of any conflict between the English version and the Bahasa Malaysia version, the English version shall prevail.

Datakey Sdn Bhd ("DataKey", "kami", atau "kita") komited untuk melindungi data peribadi anda mengikut Akta Perlindungan Data Peribadi 2010 ("APDP 2010") dan Pindaan 2024. Notis Privasi ini menjelaskan bagaimana kami mengumpul, mengguna, memproses, menyimpan, dan melepaskan data peribadi anda apabila anda melawat laman web kami (https://datakey.com.my), memuat turun bahan pemasaran, mendaftar akaun, atau menggunakan perkhidmatan sandaran berasaskan awan (cloud backup services) kami.


1. DATA USER / CONTROLLER IDENTIFICATION

This Privacy Notice applies to personal data processed by Datakey Sdn Bhd in its capacity as a Data Controller / Data User under the PDPA.

Important Operational Distinction (Data Controller vs. Data Processor):

  • Data Controller Role: DataKey acts as a Data Controller for personal data collected directly through our website, lead-capture forms, self-serve account signups, sales outreach, billing records, and system telemetry logs.
  • Data Processor Role: When business customers (e.g., medical clinics, law firms, accounting practices) use DataKey's software to back up their own operational files ("Customer Content"), the customer acts as the Data Controller, and DataKey acts as a Data Processor. The processing of Customer Content inside backup vaults is governed separately by our B2B Data Processing Agreement (DPA) and not by this Public Privacy Notice.

2. PERSONAL DATA WE COLLECT & SOURCES

We collect personal data directly from you and automatically via your interactions with our services:

A. Website Lead-Capture & Marketing Forms

B. Account Signup, Billing & Grant Filing Data

C. Desktop Agent Telemetry & Portal Access Logs


3. PURPOSE AND LEGAL BASIS OF PROCESSING

We process your personal data in accordance with the General Principle and Notice & Choice Principle of the PDPA for the following legal bases:

Purpose of Processing Categories of Personal Data Involved Legal Basis (PDPA)
1. Service Delivery & Provisioning
Setting up tenant accounts, executing automated backups, monitoring system health, providing customer support, and restoring files.
Account Credentials, Telemetry Data, Device IDs, Admin Contact Info. Contractual Necessity: Necessary to perform the contract with your organization or take steps at your request prior to entering a contract.
2. Billing, Invoicing & Financial Operations
Processing monthly/annual subscription fees, tax compliance, invoicing, and handling renewals.
SSM Registration, Tax IDs, Corporate Billing Addresses, Transaction History, Payment Tokens. Contractual Necessity & Legal Obligation: Necessary to issue valid tax invoices and meet statutory accounting rules.
3. Digitization Grant-Claim Filing
Filing, verifying, and claiming government-subsidized technology grant claims on your behalf.
Director/Rep Name, NRIC/Passport Number, Official Email, Specimen Signatures, SSM Certificate. Explicit Consent & Contractual Mandate: Collected upon explicit instruction to process grant applications.
4. Security, System Integrity & Fraud Prevention
Verifying backup integrity, auditing administrative actions, detecting brute-force attacks, and investigating security incidents.
IP Addresses, Portal Access Audit Logs, Telemetry Streams, System Error Codes. Statutory Obligation & Legitimate Interest: Fulfilling statutory duties under the PDPA Security Principle (Section 9).
5. Direct Marketing & Promotional Updates
Sending product updates, backup security insights, newsletters, and promotional offerings.
Lead-capture details (Name, Email, Phone Number, Company Name). Explicit Consent (Unbundled Opt-In): Processed strictly when you tick an optional marketing consent checkbox.

4. DIRECT MARKETING & CONSENT CHOICE

In compliance with Section 43 of the PDPA:


5. DATA LOCATION & CROSS-BORDER TRANSFERS (SECTION 129 COMPLIANCE)

A. Primary Data Residency

DataKey hosts primary Customer Content and account data at rest within cloud data centers physically located in Malaysia (e.g., AWS Malaysia Region ap-southeast-5).

B. Third-Party Subprocessors & Overseas Remote Access

To deliver our cloud service, DataKey engages vetted third-party subprocessors for payment processing, transactional email relays, and infrastructure hosting:

Notice of Cross-Border Support Access:

Under Section 129 of the PDPA and PDP Commissioner Guidelines, remote access or administrative viewing of systems by overseas personnel constitutes a cross-border data transfer. While your primary backup vault data remains strictly at rest in Malaysia, global support, engineering maintenance, or automated telemetry control planes operated by global vendors (such as AWS global infrastructure support) may access system metadata remotely from outside Malaysia.

Safeguards Applied: DataKey enforces client-side, zero-knowledge AES-256 encryption using Customer Managed Keys (CMKs). Overseas infrastructure support personnel viewing host hypervisors can only ever view encrypted, unreadable binary blocks and have no access to unencrypted payloads or decryption keys. Furthermore, DataKey maintains executed Data Processing Addendums (DPAs) with all subprocessors incorporating statutory transfer safeguards.


6. RETENTION PERIODS, IMMUTABLE VAULTS & CRYPTO-SHREDDING

A. Data Retention Schedules

B. Immutable Storage (WORM) & Crypto-Shredding

Backup data committed to DataKey's primary vault architecture is stored under Write-Once-Read-Many (WORM) / Immutable Lock configurations to prevent malicious deletion or ransomware encryption.

Because active WORM storage blocks cannot be physically overwritten prior to the expiry of the retention lock, DataKey executes permanent data deletion and erasure requests via "Crypto-Shredding":


7. DATA SUBJECT RIGHTS & HANDLING PROCEDURES

Under the PDPA, individuals have statutory rights regarding their personal data processed by DataKey:

  1. Right to Access: Request a copy of the personal data we hold about you.
  2. Right to Correction: Request that inaccurate, incomplete, or out-of-date personal data be updated.
  3. Right to Withdraw Consent: Revoke consent for processing (e.g., marketing communications).
  4. Right to Limit Processing: Request that we limit how your personal data is used.

A. How to Exercise Your Rights (Dual-Track Handling Process)

Track A — Direct DataKey Account Data

Track B — End-Customer Files Inside a Backup

B. Statutory Handling Timelines


8. SECURITY MEASURES

In compliance with Section 9 (Security Principle) of the PDPA, DataKey enforces robust technical and administrative controls:


9. BREACH NOTIFICATION COMMITMENT

In the event of a confirmed Personal Data Breach impacting systems managed directly by DataKey:


10. COOKIES AND WEBSITE TRACKING

As of the effective date of this notice, datakey.com.my utilizes strictly necessary functional cookies required for site navigation, security, and portal session management. We do not run invasive third-party ad pixels or cross-site tracking scripts. Any future deployment of analytics cookies will be accompanied by an interactive cookie consent management banner.


11. MINORS' PRIVACY

DataKey provides B2B commercial software and does not knowingly collect or solicit personal data from individuals under eighteen (18) years of age. If we learn that we have inadvertently collected personal data from a minor without verified parental/legal guardian consent, we will purge that information immediately.


12. CONTACT DETAILS & DATA PROTECTION OFFICER (DPO)

For privacy inquiries, statutory access requests, or complaints regarding our data handling practices, please contact our privacy team:


13. MODIFICATIONS TO THIS PRIVACY NOTICE

DataKey reserves the right to update or modify this Privacy Notice from time to time to reflect regulatory changes under the PDPA, updated subprocessor lists, or evolving security standards. Non-material changes take effect immediately upon posting to datakey.com.my/privacy. Material changes will be communicated to active account administrators via email or prominent portal notifications thirty (30) days prior to becoming effective.