Introduction and scope
Centralize Asia Enterprise (referred to as the Company, we, us, or our) is committed to the highest standards of data privacy and protection. This notice sets out our practices regarding the collection, processing, use, disclosure, and safeguarding of personal data.
This notice is formulated in compliance with the Personal Data Protection Act 2010 of Malaysia (PDPA) and the General Data Protection Regulation (EU) 2016/679 (GDPR). It applies to personal data processed by the Company, including data collected from clients, business partners, suppliers, employees, and visitors to our official website.
By engaging with our services, visiting our website, or otherwise providing personal data, you acknowledge that you have read and understood this notice.
Collection of personal data
The Company collects personal data in the course of its commercial activities. The information collected may include:
- Identity and contact data, including full name, job title, company name, national identification numbers where required by law, physical address, email address, and telephone number.
- Financial and transactional data, including bank account details, payment information, and details of products and services acquired from us.
- Technical data from interactions with our website and digital platforms, including IP address, login data, browser type and version, time zone and location, browser plug-ins, operating system, platform, and device technology.
- Profile and usage data, including how you use our products, services, and website, plus marketing and communication preferences.
The Company generally does not collect sensitive personal data, or special categories of personal data under the GDPR. Where it is necessary for a specific purpose, such as employee health data for human-resources management, we process it only with explicit consent or where required by law.
Lawful basis for processing
Our processing of personal data is based on one or more lawful bases prescribed by the PDPA and GDPR:
- Contractual necessity: processing required to perform a contract or take requested steps before entering into one.
- Legal obligation: processing required to comply with obligations such as tax laws or corporate reporting requirements.
- Legitimate interests: processing required for the legitimate interests of the Company or a third party, except where those interests are overridden by your rights and freedoms.
- Consent: clear, explicit consent to process personal data for a specific purpose. Consent may be withdrawn at any time.
- Vital interests: processing required to protect your vital interests or those of another person.
Purposes of use
We may use personal data for the following purposes:
- Delivering our products and services.
- Managing our commercial and contractual relationship with you or your organization.
- Processing payments, invoices, and other financial transactions.
- Complying with applicable legal and regulatory requirements.
- Internal administration, including record-keeping, auditing, and business planning.
- Managing and securing our IT systems, infrastructure, and website.
- Communicating about our services, marketing information, and updates, subject to your communication preferences.
Disclosure of personal data
The Company maintains a strict policy of confidentiality. We disclose personal data to third parties only when legally permissible and in the following circumstances:
- Service providers and vendors performing functions on our behalf, such as cloud hosting, data analytics, or payment processing. They are contractually required to maintain data confidentiality and security.
- Professional advisers, including auditors, legal counsel, and consultants, on a need-to-know basis.
- Government, regulatory, and law-enforcement authorities where required by law, court order, or legal process.
- Parties involved in a corporate merger, acquisition, consolidation, or sale of assets.
International data transfers
Where personal data is transferred outside Malaysia or the European Economic Area, the Company ensures that the transfer complies with applicable data-protection laws. We implement appropriate safeguards, such as European Commission adequacy decisions or Standard Contractual Clauses, to provide protection equivalent to that afforded by the PDPA and GDPR.
Data security
We implement appropriate technical, physical, and administrative security measures to protect personal data against unauthorized access, disclosure, alteration, loss, or destruction. Access is restricted to authorized personnel on a need-to-know basis.
Data retention
The Company retains personal data only for as long as necessary to fulfil the purpose for which it was collected and to meet legal, financial, and reporting obligations. We determine retention periods by considering the nature of the data, the purpose of processing, and relevant legal or business requirements. At the end of the retention period, personal data is securely and permanently destroyed or anonymized.
Rights of the data subject
Subject to the PDPA and GDPR, you may exercise the following rights in relation to your personal data:
- The right to be informed about our processing activities.
- The right to access a copy of the personal data we hold about you.
- The right to request correction of inaccurate or incomplete personal data.
- The right to request erasure where no compelling legal or business reason requires continued processing.
- The right to restrict or suppress processing in certain circumstances.
- The right to receive personal data in a structured, commonly used, machine-readable format and transmit it to another controller.
- The right to object to processing based on legitimate interests or for direct marketing.
- The right not to be subject to a decision based solely on automated processing that produces legal or similarly significant effects.
To exercise any of these rights, submit a formal request to our Data Protection Officer using the privacy contact provided below.
Amendments to this notice
The Company reserves the right to amend this Privacy Policy at any time. Amendments will be published on our official website and become effective on publication. We encourage you to review this page periodically to remain informed about our data-protection practices.
Contact information
For questions, requests, or concerns about this Privacy Policy or the processing of personal data, contact Centralize Asia using the privacy address below.