Privacy Policy

This privacy policy sets out how NetInfinium Solutions Sdn Bhd may collect, use and disclose your personal data that you provide us when you access or use this website, formulated in accordance with the Personal Data Protection Act 2010 (“Act”), which describes how your information (“Personal Data”) is collected and used and your choices with respect to your Personal Data. For the avoidance of doubt, any reference to “we”, “our” or “us” in this Privacy Policy shall include any member of NetInfinium Group of Companies.

NetInfinium Solutions Sdn Bhd is committed to ensure that your Personal Data is protected. Should we ask you to provide certain Personal Data by which you can be identified when using this website, you can be assured that it will only be used in accordance with this Privacy Policy.

You can access this website without having to provide your Personal Data. You will remain anonymous and at no time we can identify you individually unless you choose to provide us with your Personal Data by contacting us on the ‘Contact Us’ page on this website or through your participation in certain activities including contests, forum, and polls; and through the use of cookies. When you request pages from our server, it automatically collects some information about your preferences, including your internet protocol (“IP”) address. We use this to help diagnose problems with our server, and to administer our websites.

What we collect from this website

We may typically collect the following Personal Data from or in relation to you:

What we do with the Personal Data collected from this website

Your Personal Data that we collected from this website may be used for one or more of the following purposes:

Who we disclose the Personal Data collected from this website

We may share the Personal Data that we collect from this website with our subsidiaries, joint ventures, partners, agents, principals and/or affiliates for the purpose as set out above.

Retention and storage of Personal Data collected from this website

Your Personal Data shall be stored either in hard copies in our offices or in servers located in Malaysia. It may be necessary to transfer your Personal Data to third party service providers based/located outside Malaysia. By continuing to use the websites, products and/or services of NetInfinium, you hereby consent to such transfer.

Any Personal Data supplied by you will be retained by us as long as necessary for the compliance and fulfilment of legal, regulatory, accounting requirements or to protect our interests.

We are committed to ensure that the Personal Data collected from this website is secure. To prevent unauthorised access or disclosure, we have put in place reasonable security measures to safeguard and secure the Personal Data collected from this website.

Access, correction or deletion of Personal Data

If you wish to access, correct or update the Personal Data that you have provided us on this website, you may do so at any time by writing to or emailing us at admin_dept@netinfinium.com.

You may request deletion of your Personal Data that we collected from this website by writing to or emailing us at admin_dept@netinfinium.com.

How we use cookies

A cookie is a small file which asks permission to be placed on your computer’s hard drive. Once you agree, the file is added and the cookie helps analyse web traffic or lets you know when you visit a site.

Cookies allow web applications to respond to you as an individual. The web application can tailor its operations to your needs, likes and dislikes by gathering and remembering information about your preferences.

We use traffic log cookies to identify which pages are being used. This helps us analyse data about web page traffic and improve our website to tailor it to customer needs. We only use this information for statistical analysis purposes and then the data is removed from the system. Overall, cookies help us provide you with a better website, by enabling us to monitor which pages you find useful and which you do not. A cookie in no way gives us access to your computer or any information about you, other than the data you choose to share with us.

You can choose to accept or decline cookies. Most web browsers automatically accept cookies, but you can modify your browser setting to decline cookies if you prefer. This, however, may prevent you from taking full advantage of the website.

Confidentiality

Personal Data held by us will be kept confidential in accordance with this Privacy Policy pursuant to any applicable law that may from time to time be in force.

Any questions, comments, suggestions or information other than Personal Data sent or posted to the websites, or any part thereof by users will be deemed voluntarily provided to us on a non-confidential and non-proprietary basis.

We reserve the right to use, reproduce, disclose, transmit, publish, broadcast and/or post elsewhere such information freely without further reference to you.

Changes to Privacy Policy

We reserve the right to amend this Privacy Policy from time to time without prior notice. Any changes to the Privacy Policy will be uploaded onto our websites and therefore, we encourage you to check/visit the websites from time to time for any changes on a regular basis.

Personal Data Protection Policy

1. Purpose

NetInfinium Solutions Sdn Bhd (“NIS”, “Company”, “our”, “we”, or “us”) are committed to complying with the Personal Data Protection Act 2010 of Malaysia (“PDPA”). This Personal Data Protection Policy (“Policy”) contains the policies and practices of the Group to comply with the PDPA.

2. Requirements

2.1  The requirements of the Company under the PDPA are as follows:

  1. develop and implement policies and practices necessary for the Company to meet its obligations under the PDPA;
  2. develop a process to receive and respond to complaints that may arise with respect to the application of the PDPA;
  3. communicate to its employees information about this Policy;
  4. make information available on request about the Policy and the complaint process referred to in paragraph (b) above; and
  5. (i) appoint one or more data protection officers. These are the persons responsible for ensuring that the Company complies with the PDPA (“Data Protection Officers” or “DPO”); and (ii) make available to the public the business contact information of at least one of the Data Protection Officers.

2.2  NetInfinium has implemented this Policy and certain personal data protection internal practices (“PDP Internal Practices”) attached hereto as Annex A for the Group to meet the requirements under the PDPA.

3. Primary Data Protection Rules

The Company MUST comply with the following rules when collecting, using or disclosing Personal Data of any individual:

 Rules
(a)Obtain the consent of the individual or, if consent is not obtained, ensure that the collection, use or disclosure is permitted under Malaysia law.
(b)Ensure that the individual is informed of the purpose of such collection, use or disclosure.
(c)Ensure that the Personal Data is only collected, used or disclosed for such purpose, and no other purpose.
(d)Ensure that the Personal Data is properly retained, protected and disposed of in accordance with the PDP Internal Practices.

4. What is Personal Data

4.1  Personal Data is data (whether true or not) about an individual who can be identified:

4.2  Non-exhaustive examples of an individual’s Personal Data:

Personal Data does NOT cover an individual’s “business contact information” such as his/her position, title, business address, business email/fax number.

4.3  The PDPA deals only with the Personal Data of individuals (i.e. natural persons), and does not extend to data of companies or corporations.

5. Purposes of Collection, Use and/or Disclosure of Personal Data

5.1  Examples of some situations where the Company collects, uses and/or discloses Personal Data, and the purposes of such, are set out below.

 PersonPersonal Data CollectedPurpose(s)
(a) Job applicants Information in job applicant’s curriculum vitae or the job application forms (e.g. personal email, telephone number, address, educational history and background, salary at current/previous place of employment). To evaluate the applicant and to attend to all administrative work to process the job application.
(b) Employees Personal Data of its employees (e.g. information in (a) above, bank account details, information relating to their salary, tax etc.). Personal Data of employees within the Group and related corporations of the Group. For legal, audit and other compliance purposes, managing the employment relationship, including filings with or disclosure to authorities and bankers.
(c) Directors and other officers Personal Data of its directors and other officers (e.g. information in (a) above, bank account details, information relating to their fee, tax etc.). Personal Data of directors and other officers within the Group and related corporations of the Group. For legal, audit and other compliance purposes, administrative, business, operational and/or management purposes, including filings with or disclosure to authorities and bankers.
(d) Shareholders and investors Personal Data of shareholders/investors of NetInfinium when they write to NetInfinium to raise queries or when they submit forms to NetInfinium (e.g. relating to proxy forms/dividends/general meetings). Personal Data of shareholders/investors of NetInfinium with their shareholding interests (e.g. CDS account holders in dealings with Bursa Depository for Malaysian securities (e.g. stock listed on Bursa Malaysia) and other regulatory bodies). To implement or undertake corporate actions such as dividend payments, general meetings (e.g. processing of proxy forms). To respond and deal with enquiries/feedback and for other shareholder or investor related activities, including delivery of documents to shareholders/investors.
(e) Third parties including contracting parties
  • When an individual interacts with the employees and officers of the Company, for example, via telephone calls, correspondence and face-to-face meetings (including at shareholder meetings).
  • When an individual visits the Company’s premises where CCTV may be deployed for security purposes.
  • When a party transacts or contracts with the Company, it may provide Personal Data of its directors and employees.
  • When an individual approaches, signs, subscribes, engages, transacts and/or deals with the Company.
To respond, deal with, manage and/or for other legitimate purposes for the business and operations of the Group.

5.2  The Group collects Personal Data primarily from the persons identified in the table set out above. Unless permitted by laws, the collection, use and/or disclosure of Personal Data should be limited to that which is necessary for the identified purposes in the table above.

6. Personal Behaviour & Conduct in NetInfinium

6.1  Before collecting, using or disclosing Personal Data, the consent of the individual must be obtained. There are two types of consent:

Generally, the Company should seek actual consent. When seeking consent, the purpose for which the consent is sought must be notified to the individual.

6.2  The Company may collect, use or disclose an individual’s Personal Data without his/her consent in the following circumstances:

7. Withdrawal of Consent / Correction and Access to Personal Data

7.1  An individual who has provided the Company with Personal Data is entitled under the PDPA to withdraw his/her consent, request for corrections to be made and for access to such Personal Data. In such cases, the Company MUST comply with the following:

CircumstanceRequirement
Withdrawal of ConsentAn individual is entitled at any time to withdraw his/her consent to the continued collection, use and disclosure of the Personal Data. Such withdrawal shall be made formally in writing to the office of the DPO. The Company must not prohibit an individual from withdrawing his/her consent.
Correction of Personal DataUpon request by the individual concerned, the Company must, in accordance with the PDPA, correct or complete any Personal Data found to be inaccurate or incomplete as soon as practicable unless the Company is satisfied on reasonable grounds that the correction should not be made.
Access to Personal DataUpon request by an individual, the Company is required under the PDPA to provide the individual with his/her Personal Data which is in the possession or under the control of the Company. There are some exceptions to the obligation to provide the above. Please see the PDP Internal Practices (para 4(a)).

8. Retention, Protection and Disposal of Personal Data

The PDPA regulates how Personal Data in the Company’s possession is to be protected or dealt with. Some of the basic obligations and the corresponding required practices and policies of the Company are set out below and must be complied with at all times:

ActionPolicies / Practices
Protection of Personal DataThe Company shall protect Personal Data in its possession or under its control against risk of unauthorised access, collection, use, disclosure, copying, modification or disposal through reasonable security measures. These measures are dealt with in the PDP Internal Practices.
Retention and Disposal of Personal DataThe Company must cease to retain documents containing Personal Data or remove the means by which the Personal Data can be associated with particular individuals as soon as it is reasonable to assume that: (i) the purpose for which the Personal Data was collected is no longer being served by the retention of such Personal Data; and (ii) retention is no longer necessary for legal or business purposes. In such event, the Company must ensure that the Personal Data is properly disposed of in accordance with the PDP Internal Practices.
Transfer of Personal DataThe Company shall not transfer any Personal Data of an individual to a recipient outside Malaysia unless the standard of protection to Personal Data in the foreign country is comparable to the protection under the PDPA.

9. Powers of PDPC and Consequences of Non-Compliance with PDPA

9.1  The Personal Data Protection Commission (“PDPC”) may, upon receiving a complaint or of its own motion, conduct an investigation to determine whether an organisation is in compliance with the PDPA. For the purposes of an investigation, the PDPC’s powers include, amongst others, requiring documents or information which relates to any matter relevant to the investigation to be produced by the organisation.

9.2  It is important for the Company to ensure that its employees comply with the requirements of the PDPA as non-compliance can affect the Company. It is to be noted that enforcement decisions of the PDPC are made public, and the PDPC may issue warnings to the organisation. Amongst others, the PDPC may:

10. General

10.1  If you are in any doubt or unclear as to the policies or practices set out in this Policy, please contact the DPO for assistance.

10.2  NetInfinium may revise, amend or supplement this Policy or PDP Internal Practices at its discretion from time to time. Employees of the Company are encouraged to check periodically to ensure that they are aware of any such changes.

10.3  Further information on the PDPA can be found at www.pdp.gov.my.

Annex A — PDP Internal Practices

1. Data Protection Officer(s)

The department or office of the DPO has been set up to oversee the Group’s compliance with the PDPA. Other employees within the Group may be delegated to act on behalf of the DPO or to take responsibility for the day-to-day collection and processing of Personal Data. The DPO may be contacted at:

The Data Protection Officer NETINFINIUM SOLUTIONS SDN BHD
Level 9, Wisma N2N,
Tower 2, Avenue 3, Bangsar South,
No. 8, Jalan Kerinchi,
59200 Kuala Lumpur, Malaysia.
Email: dpo@n2nconnect.com

2. Consent for Collection, Use and Disclosure of Personal Data

When seeking such consent, employees must:

If consent is obtained, the Personal Data must only be collected, used or disclosed by the Company for the purposes for which the consent was obtained, and not for any other purpose.

The individual is entitled to WITHDRAW CONSENT given, on giving reasonable notice to the Company. In such event:

3. Protection, Retention and Disposal of Personal Data

4. Access to, Correction and Accuracy of Personal Data

Upon request by an individual, the Company must provide him/her with:

There are some exceptions to the above obligations:

Personal Data and information must NOT be provided where it could reasonably be expected to:

To access the information set out above in 4(a), the individual is required to submit his/her request by using the form set out in Appendix 1 (Access Form).

Note: When processing an access request, it is important for employees to establish and verify the identity of the individual making the request.

In order to comply with an access request made by an individual as set out above in 4(a)(ii), the employee who is managing or handling the relevant Personal Data must maintain a disclosure list substantially in the form set out in Appendix 2 (Disclosure List).

An individual is entitled to request that an error in his/her Personal Data be corrected. Upon receipt of such a request, the employee shall:

Employees should make reasonable efforts to ensure that Personal Data collected from an individual is correct, accurate and complete. This should be done at the stage when consent is first obtained or when the correction to the Personal Data is made.

5. Specific Requirement Relating to Collection, Use and/or Disclosure of NRIC Numbers

The Company may collect, use and/or disclose NRIC in the following specified circumstances (the “Permitted Circumstances”):

It is important to note that the treatment for NRIC numbers applies to other national identification numbers such as foreign identification numbers (FIN), work permit numbers, driver’s license numbers, birth certificate numbers and passport numbers and copies thereof.

Law Exception

Some of the examples are as follows:

High Fidelity Exception

The Company and its employees may collect, use or disclose an individual’s NRIC number if the following conditions are met:

Both conditions (i) and (ii) must be met.

The Company should assess whether its specific situation meets the above conditions before collecting the individual’s NRIC number. The Company must be able to provide justification on request of either the individual or the Commission as to why the collection, use or disclosure of the NRIC number is necessary to accurately establish or verify the identity of the individual to a high degree of fidelity.

Some alternatives to NRIC numbers that have been adopted by companies include user-generated ID, tracking number, organisation-issued QR Code or monetary deposit. However, the Company should consider whether the alternatives provided are reasonable, and avoid collecting excessive personal data as an alternative to the individual’s NRIC number.

The Company may consider collecting partial NRIC number when other alternatives are not satisfactory (for e.g. ‘6789’ from the full NRIC number of 80123-45-6789). This would not be subject to the Commission’s rules for treatment of NRIC numbers as it is not considered to be collection of full NRIC numbers.

6. Transfer of Personal Data

Employees transferring Personal Data of an individual to a recipient outside Malaysia must ascertain and ensure that the recipient is bound by legally enforceable obligations that provide a standard of protection to the Personal Data that is comparable to the protection under the PDPA. If in doubt, please check with the DPO.

Legally enforceable obligations include any law, contracts, binding corporate rules or any other legally binding instrument.

7. Data Breaches

Data breaches can occur for various reasons. These may be caused by employees, external parties or computer system errors. The following are some possible ways in which a data breach may occur. The list is not meant to be exhaustive.

CauseExamples
Malicious activities
  • Hacking incidents / illegal access to databases containing Personal Data.
  • Theft of computer notebooks, data storage devices or paper records containing Personal Data.
  • Scams that trick organisations into releasing Personal Data of individuals.
Human error
  • Loss of computer notebooks, data storage devices or paper records containing Personal Data.
  • Sending Personal Data to a wrong e-mail or physical address, or disclosing data to a wrong recipient.
  • Unauthorised access or disclosure of Personal Data by employees.
  • Mistakes in the printing process which may lead to the exposure of Personal Data.
  • Improper disposal of Personal Data (e.g. hard disk, storage media or paper documents sold or discarded before Personal Data is properly deleted).
Computer system error
  • Errors or bugs in the programming code of websites, databases and other software which may be exploited to gain access to Personal Data stored on computer systems.

When a data breach occurs or is likely to occur, employees MUST comply with the following:

StageSteps to be taken
Containing the breachWhere applicable:
  • Notify IT Department immediately.
  • Shut down and isolate the compromised system that led to the data breach.
  • IT Department shall establish whether steps can be taken to recover lost data and limit any damage caused by the breach.
  • Reset passwords.
  • Address lapses in processes that led to the data breach.
  • Put a stop to practices that led to the data breach.
Reporting the incident
  • Employee and IT Department to immediately report the matter to the DPO with details on how and when the data breach occurred, and the types of Personal Data involved in the data breach.
  • DPO to report to the management of the Company to consider whether to notify the police if criminal activity is suspected and preserve evidence for investigation.
  • DPO to notify the affected individuals and/or PDPC taking into account the prevailing PDPC guidelines.

8. Complaint Handling Process

StageSteps to be takenPerson-in-charge
Initial handling of complaintsUpon receipt of a complaint:
  • Employee must inform the DPO of all information relating to the complaint.
  • Employee or (where appropriate) DPO to send an acknowledgement reply to the complainant.
  • A data protection complaint register will be maintained by the DPO to keep track of the status of the complaint.
DPO (or such person delegated to act on behalf of the DPO)
Assessing the complaintsUpon receipt of a complaint:
  • DPO to follow up and assess the validity of the complaint.
  • If the complaint is valid, to determine which data protection provisions the Company has not complied with, and to assess the impact and severity of the complaint.
  • Assess the timeframe needed to achieve closure for the complaint and inform the complainant accordingly.
Investigating / reporting the complaints
  • Determine what caused the non-compliance to take place, who was involved, how and why it happened.
  • Provide interim updates to the complainant and find out from the complainant how he/she might want his/her complaint to be resolved.
  • Submit an investigation report to the appropriate level of management of the Company, including findings made and recommendations on remedial actions to be taken to achieve resolution of the complaint.
  • If need be, report to and inform the relevant authorities such as the police and PDPC.
Responding to complaints
  • Inform the complainant about the results of the investigation and the remedial actions to be taken.
  • If the complainant disagrees with the remedial actions, this could be escalated to the management of the Company or an independent third party for resolution.
Taking corrective actions
  • Analyse current and past complaints to determine if there are systemic issues that might cause such complaints to be lodged in the first place.
  • Once these systemic issues are identified, recommend specific actions such as fine-tuning of specific data protection policies and processes and employee training to prevent future recurrences.

—  End  —