DATAKEY SDN BHD — PRIVACY NOTICE
Effective Date: 10 August 2026
Last Updated: 10 August 2026
NOTIS PERLINDUNGAN DATA PERIBADI (BAHASA MALAYSIA)
In accordance with Section 7(3) of the Personal Data Protection Act 2010 (PDPA), this Privacy Notice is issued in both English and Bahasa Malaysia. In the event of any conflict between the English version and the Bahasa Malaysia version, the English version shall prevail.
Datakey Sdn Bhd ("DataKey", "kami", atau "kita") komited untuk melindungi data peribadi anda mengikut Akta Perlindungan Data Peribadi 2010 ("APDP 2010") dan Pindaan 2024. Notis Privasi ini menjelaskan bagaimana kami mengumpul, mengguna, memproses, menyimpan, dan melepaskan data peribadi anda apabila anda melawat laman web kami (https://datakey.com.my), memuat turun bahan pemasaran, mendaftar akaun, atau menggunakan perkhidmatan sandaran berasaskan awan (cloud backup services) kami.
1. DATA USER / CONTROLLER IDENTIFICATION
This Privacy Notice applies to personal data processed by Datakey Sdn Bhd in its capacity as a Data Controller / Data User under the PDPA.
- Legal Entity Name: Datakey Sdn Bhd
- Registration Number: 199901008738 (0483638X)
- Registered Address: Level 1, Synergy 9, 9 Jalan Kajibumi U1/70, Temasya Glenmarie, 40150 Shah Alam, Selangor, Malaysia
- Website: https://datakey.com.my
- Contact Phone: +603 5163 2888
- Dedicated Privacy Email:
privacy@datakey.com.my
Important Operational Distinction (Data Controller vs. Data Processor):
- Data Controller Role: DataKey acts as a Data Controller for personal data collected directly through our website, lead-capture forms, self-serve account signups, sales outreach, billing records, and system telemetry logs.
- Data Processor Role: When business customers (e.g., medical clinics, law firms, accounting practices) use DataKey's software to back up their own operational files ("Customer Content"), the customer acts as the Data Controller, and DataKey acts as a Data Processor. The processing of Customer Content inside backup vaults is governed separately by our B2B Data Processing Agreement (DPA) and not by this Public Privacy Notice.
2. PERSONAL DATA WE COLLECT & SOURCES
We collect personal data directly from you and automatically via your interactions with our services:
A. Website Lead-Capture & Marketing Forms
- Data Collected: Full Name, Work Email Address, Phone Number, Company Name, Industry Sector, Number of Employees, Package Preference, Marketing Consent Preferences, Lead Source, and Marketing Campaign Metadata.
- Source: Submitted directly by you via our checklist download modals, demo request forms, or contact forms.
B. Account Signup, Billing & Grant Filing Data
- Data Collected: Corporate Entity Details, SSM Registration Number, Company Tax ID, Corporate Contact Address, Corporate Email, Billing Preferences, Payment Method/Tokens, and Director/Authorized Representative details (Full Name, Designation, NRIC/Passport Number, Official Email, Corporate Address, and Specimen Signature).
- Source: Submitted directly by your authorized administrative representative during onboarding, checkout, or technology grant-claim processing (e.g., MDEC / BSG grant claims).
C. Desktop Agent Telemetry & Portal Access Logs
- Data Collected: Machine Device IDs, IP Addresses, Operating System Build/Version, Agent Error Codes, Backup Execution Status, File System Metadata (file paths, file sizes, creation timestamps, SHA-256 hashes), and Staff Support Access Trails.
- Source: Automatically transmitted by the DataKey Desktop Agent and logged by our Management Portal during routine operation.
3. PURPOSE AND LEGAL BASIS OF PROCESSING
We process your personal data in accordance with the General Principle and Notice & Choice Principle of the PDPA for the following legal bases:
| Purpose of Processing | Categories of Personal Data Involved | Legal Basis (PDPA) |
|---|---|---|
| 1. Service Delivery & Provisioning Setting up tenant accounts, executing automated backups, monitoring system health, providing customer support, and restoring files. |
Account Credentials, Telemetry Data, Device IDs, Admin Contact Info. | Contractual Necessity: Necessary to perform the contract with your organization or take steps at your request prior to entering a contract. |
| 2. Billing, Invoicing & Financial Operations Processing monthly/annual subscription fees, tax compliance, invoicing, and handling renewals. |
SSM Registration, Tax IDs, Corporate Billing Addresses, Transaction History, Payment Tokens. | Contractual Necessity & Legal Obligation: Necessary to issue valid tax invoices and meet statutory accounting rules. |
| 3. Digitization Grant-Claim Filing Filing, verifying, and claiming government-subsidized technology grant claims on your behalf. |
Director/Rep Name, NRIC/Passport Number, Official Email, Specimen Signatures, SSM Certificate. | Explicit Consent & Contractual Mandate: Collected upon explicit instruction to process grant applications. |
| 4. Security, System Integrity & Fraud Prevention Verifying backup integrity, auditing administrative actions, detecting brute-force attacks, and investigating security incidents. |
IP Addresses, Portal Access Audit Logs, Telemetry Streams, System Error Codes. | Statutory Obligation & Legitimate Interest: Fulfilling statutory duties under the PDPA Security Principle (Section 9). |
| 5. Direct Marketing & Promotional Updates Sending product updates, backup security insights, newsletters, and promotional offerings. |
Lead-capture details (Name, Email, Phone Number, Company Name). | Explicit Consent (Unbundled Opt-In): Processed strictly when you tick an optional marketing consent checkbox. |
4. DIRECT MARKETING & CONSENT CHOICE
In compliance with Section 43 of the PDPA:
- Downloading a requested resource (e.g., our Free Backup & PDPA Checklist) does not automatically subscribe you to ongoing promotional emails.
- Marketing communications are sent only if you affirmatively check the optional marketing opt-in box on our forms.
- Opt-Out Right: You have the statutory right to withdraw your consent for direct marketing at any time, free of charge, by clicking the "Unsubscribe" link in any promotional email or contacting
privacy@datakey.com.my.
5. DATA LOCATION & CROSS-BORDER TRANSFERS (SECTION 129 COMPLIANCE)
A. Primary Data Residency
DataKey hosts primary Customer Content and account data at rest within cloud data centers physically located in Malaysia (e.g., AWS Malaysia Region ap-southeast-5).
B. Third-Party Subprocessors & Overseas Remote Access
To deliver our cloud service, DataKey engages vetted third-party subprocessors for payment processing, transactional email relays, and infrastructure hosting:
- Cloud Infrastructure & Hosting: Amazon Web Services (AWS) / Alibaba Cloud (Primary data at rest stored in Malaysia).
- Payment Processing: Paydee Sdn Bhd (Payment tokens and transaction routing).
- Internal Site Infrastructure: Custom-built analytics and database pipelines (No external advertising tracking pixels or ad cookies are deployed on
datakey.com.my).
Notice of Cross-Border Support Access:
Under Section 129 of the PDPA and PDP Commissioner Guidelines, remote access or administrative viewing of systems by overseas personnel constitutes a cross-border data transfer. While your primary backup vault data remains strictly at rest in Malaysia, global support, engineering maintenance, or automated telemetry control planes operated by global vendors (such as AWS global infrastructure support) may access system metadata remotely from outside Malaysia.
Safeguards Applied: DataKey enforces client-side, zero-knowledge AES-256 encryption using Customer Managed Keys (CMKs). Overseas infrastructure support personnel viewing host hypervisors can only ever view encrypted, unreadable binary blocks and have no access to unencrypted payloads or decryption keys. Furthermore, DataKey maintains executed Data Processing Addendums (DPAs) with all subprocessors incorporating statutory transfer safeguards.
6. RETENTION PERIODS, IMMUTABLE VAULTS & CRYPTO-SHREDDING
A. Data Retention Schedules
- Website Leads & Sales Contacts: Retained for up to twenty-four (24) months from your last interaction, unless you request earlier deletion or withdraw consent.
- Account Billing & Tax Records: Retained for seven (7) years following contract termination to comply with statutory legal and tax audit requirements under Malaysian law.
- Backed-Up Customer Vault Data: Retained strictly according to your selected plan tier:
- Shield Tier: 30 Days rolling retention lock.
- Vault Tier: 90 Days rolling retention lock.
- Fortress Tier: 90 Days rolling retention lock (with custom enterprise retention extensions).
B. Immutable Storage (WORM) & Crypto-Shredding
Backup data committed to DataKey's primary vault architecture is stored under Write-Once-Read-Many (WORM) / Immutable Lock configurations to prevent malicious deletion or ransomware encryption.
Because active WORM storage blocks cannot be physically overwritten prior to the expiry of the retention lock, DataKey executes permanent data deletion and erasure requests via "Crypto-Shredding":
- Each customer tenant vault is encrypted with a unique, dedicated cryptographic key.
- Upon a valid erasure request, account cancellation, or expiration of the 14-day post-termination grace period, DataKey permanently destroys and purges the tenant's cryptographic key.
- Crypto-Shredding renders the underlying data forensically unrecoverable and unreadable noise, permanently satisfying the requirement to destroy personal data under Section 10 (Retention Principle) of the PDPA.
7. DATA SUBJECT RIGHTS & HANDLING PROCEDURES
Under the PDPA, individuals have statutory rights regarding their personal data processed by DataKey:
- Right to Access: Request a copy of the personal data we hold about you.
- Right to Correction: Request that inaccurate, incomplete, or out-of-date personal data be updated.
- Right to Withdraw Consent: Revoke consent for processing (e.g., marketing communications).
- Right to Limit Processing: Request that we limit how your personal data is used.
A. How to Exercise Your Rights (Dual-Track Handling Process)
Track A — Direct DataKey Account Data
- You are a DataKey Lead, Client Admin, or User.
- DataKey is the Data Controller.
- Action: Email
privacy@datakey.com.mydirectly. - Processed by DataKey within 21 days.
Track B — End-Customer Files Inside a Backup
- You are a patient/client of an SME using DataKey.
- DataKey is the Data Processor.
- Action: Contact the SME (clinic/law firm/etc.) directly.
-
DataKey assists the SME upon their instruction once notified.
-
Track A (Direct DataKey Accounts): If you are a client admin, website user, or lead exercising rights regarding your account profile or marketing data, contact our DPO Lead at
privacy@datakey.com.my. - Track B (Files Inside Customer Backups): If you are an individual (e.g., a patient, legal client, or employee) seeking to access or correct records stored inside a customer's backed-up vault, you must contact that specific organization directly. DataKey acts strictly as a Data Processor and cannot decrypt or access tenant vault contents directly; we will notify the SME controller and assist them in fulfilling your request.
B. Statutory Handling Timelines
- Standard Deadline: We will respond to and comply with valid requests within twenty-one (21) calendar days of receipt and identity verification.
- Extension Window: If a complex technical extraction is required, we may extend the timeline by up to fourteen (14) additional days by providing you with written notice explaining the reasons before the initial 21-day period expires.
8. SECURITY MEASURES
In compliance with Section 9 (Security Principle) of the PDPA, DataKey enforces robust technical and administrative controls:
- Encryption Standards: Client-side AES-256-GCM encryption at rest and TLS 1.3 encryption in transit for all data transmissions.
- Key Isolation: Zero-knowledge architecture utilizing per-tenant Customer Managed Keys (CMKs). DataKey staff do not hold or store unencrypted customer payload keys.
- Access Controls: Multi-Factor Authentication (MFA), role-based access control (RBAC), and strict Four-Eyes quorum approval protocols for administrative management actions.
- Malware Quarantine: Automated malware scanning pipelines executed during restore requests to prevent re-infection of client environments.
9. BREACH NOTIFICATION COMMITMENT
In the event of a confirmed Personal Data Breach impacting systems managed directly by DataKey:
- Timely Notification: DataKey will notify affected customer administrative contacts without undue delay following confirmation of the security incident.
- Incident Report Content: The notification will outline the nature of the breach, estimated scope, mitigation steps taken by DataKey, and recommended actions for the customer.
- Customer Responsibility: Customers remain responsible for maintaining the confidentiality of their primary account credentials and determining whether the incident triggers statutory reports to regulators or affected data subjects under their own legal duties.
10. COOKIES AND WEBSITE TRACKING
As of the effective date of this notice, datakey.com.my utilizes strictly necessary functional cookies required for site navigation, security, and portal session management. We do not run invasive third-party ad pixels or cross-site tracking scripts. Any future deployment of analytics cookies will be accompanied by an interactive cookie consent management banner.
11. MINORS' PRIVACY
DataKey provides B2B commercial software and does not knowingly collect or solicit personal data from individuals under eighteen (18) years of age. If we learn that we have inadvertently collected personal data from a minor without verified parental/legal guardian consent, we will purge that information immediately.
12. CONTACT DETAILS & DATA PROTECTION OFFICER (DPO)
For privacy inquiries, statutory access requests, or complaints regarding our data handling practices, please contact our privacy team:
- Attn: Data Protection Lead / Founder
- Data Protection Office Email:
privacy@datakey.com.my - Official Website: https://datakey.com.my
- Corporate Address: Datakey Sdn Bhd, Level 1, Synergy 9, 9 Jalan Kajibumi U1/70, Temasya Glenmarie, 40150 Shah Alam, Selangor, Malaysia
- Telephone: +603 5163 2888
13. MODIFICATIONS TO THIS PRIVACY NOTICE
DataKey reserves the right to update or modify this Privacy Notice from time to time to reflect regulatory changes under the PDPA, updated subprocessor lists, or evolving security standards. Non-material changes take effect immediately upon posting to datakey.com.my/privacy. Material changes will be communicated to active account administrators via email or prominent portal notifications thirty (30) days prior to becoming effective.