Privacy Policy
This privacy policy sets out how NetInfinium Solutions Sdn Bhd may collect, use and disclose your personal data that you provide us when you access or use this website, formulated in accordance with the Personal Data Protection Act 2010 (“Act”), which describes how your information (“Personal Data”) is collected and used and your choices with respect to your Personal Data. For the avoidance of doubt, any reference to “we”, “our” or “us” in this Privacy Policy shall include any member of NetInfinium Group of Companies.
NetInfinium Solutions Sdn Bhd is committed to ensure that your Personal Data is protected. Should we ask you to provide certain Personal Data by which you can be identified when using this website, you can be assured that it will only be used in accordance with this Privacy Policy.
You can access this website without having to provide your Personal Data. You will remain anonymous and at no time we can identify you individually unless you choose to provide us with your Personal Data by contacting us on the ‘Contact Us’ page on this website or through your participation in certain activities including contests, forum, and polls; and through the use of cookies. When you request pages from our server, it automatically collects some information about your preferences, including your internet protocol (“IP”) address. We use this to help diagnose problems with our server, and to administer our websites.
What we collect from this website
We may typically collect the following Personal Data from or in relation to you:
- Name;
- Address;
- Phone number(s);
- Date of birth;
- Email address;
- Gender;
- Identity card number or passport number.
What we do with the Personal Data collected from this website
Your Personal Data that we collected from this website may be used for one or more of the following purposes:
- We may use the Personal Data to communicate with you, including to respond to your queries and requests.
- We may periodically send promotional emails about new products, special offers or other information which we think you may find interesting using the email address which you have provided.
- We may use the Personal Data to comply with law, the requests of law enforcement and regulatory officials, or order or court.
- We may use the Personal Data for such other purposes notified to you on or before collection, use and/or disclosure of the Personal Data.
Who we disclose the Personal Data collected from this website
We may share the Personal Data that we collect from this website with our subsidiaries, joint ventures, partners, agents, principals and/or affiliates for the purpose as set out above.
Retention and storage of Personal Data collected from this website
Your Personal Data shall be stored either in hard copies in our offices or in servers located in Malaysia. It may be necessary to transfer your Personal Data to third party service providers based/located outside Malaysia. By continuing to use the websites, products and/or services of NetInfinium, you hereby consent to such transfer.
Any Personal Data supplied by you will be retained by us as long as necessary for the compliance and fulfilment of legal, regulatory, accounting requirements or to protect our interests.
We are committed to ensure that the Personal Data collected from this website is secure. To prevent unauthorised access or disclosure, we have put in place reasonable security measures to safeguard and secure the Personal Data collected from this website.
Access, correction or deletion of Personal Data
If you wish to access, correct or update the Personal Data that you have provided us on this website, you may do so at any time by writing to or emailing us at admin_dept@netinfinium.com.
You may request deletion of your Personal Data that we collected from this website by writing to or emailing us at admin_dept@netinfinium.com.
How we use cookies
A cookie is a small file which asks permission to be placed on your computer’s hard drive. Once you agree, the file is added and the cookie helps analyse web traffic or lets you know when you visit a site.
Cookies allow web applications to respond to you as an individual. The web application can tailor its operations to your needs, likes and dislikes by gathering and remembering information about your preferences.
We use traffic log cookies to identify which pages are being used. This helps us analyse data about web page traffic and improve our website to tailor it to customer needs. We only use this information for statistical analysis purposes and then the data is removed from the system. Overall, cookies help us provide you with a better website, by enabling us to monitor which pages you find useful and which you do not. A cookie in no way gives us access to your computer or any information about you, other than the data you choose to share with us.
You can choose to accept or decline cookies. Most web browsers automatically accept cookies, but you can modify your browser setting to decline cookies if you prefer. This, however, may prevent you from taking full advantage of the website.
Confidentiality
Personal Data held by us will be kept confidential in accordance with this Privacy Policy pursuant to any applicable law that may from time to time be in force.
Any questions, comments, suggestions or information other than Personal Data sent or posted to the websites, or any part thereof by users will be deemed voluntarily provided to us on a non-confidential and non-proprietary basis.
We reserve the right to use, reproduce, disclose, transmit, publish, broadcast and/or post elsewhere such information freely without further reference to you.
Changes to Privacy Policy
We reserve the right to amend this Privacy Policy from time to time without prior notice. Any changes to the Privacy Policy will be uploaded onto our websites and therefore, we encourage you to check/visit the websites from time to time for any changes on a regular basis.
Personal Data Protection Policy
1. Purpose
NetInfinium Solutions Sdn Bhd (“NIS”, “Company”, “our”, “we”, or “us”) are committed to complying with the Personal Data Protection Act 2010 of Malaysia (“PDPA”). This Personal Data Protection Policy (“Policy”) contains the policies and practices of the Group to comply with the PDPA.
2. Requirements
2.1 The requirements of the Company under the PDPA are as follows:
- develop and implement policies and practices necessary for the Company to meet its obligations under the PDPA;
- develop a process to receive and respond to complaints that may arise with respect to the application of the PDPA;
- communicate to its employees information about this Policy;
- make information available on request about the Policy and the complaint process referred to in paragraph (b) above; and
- (i) appoint one or more data protection officers. These are the persons responsible for ensuring that the Company complies with the PDPA (“Data Protection Officers” or “DPO”); and (ii) make available to the public the business contact information of at least one of the Data Protection Officers.
2.2 NetInfinium has implemented this Policy and certain personal data protection internal practices (“PDP Internal Practices”) attached hereto as Annex A for the Group to meet the requirements under the PDPA.
3. Primary Data Protection Rules
The Company MUST comply with the following rules when collecting, using or disclosing Personal Data of any individual:
| Rules | |
|---|---|
| (a) | Obtain the consent of the individual or, if consent is not obtained, ensure that the collection, use or disclosure is permitted under Malaysia law. |
| (b) | Ensure that the individual is informed of the purpose of such collection, use or disclosure. |
| (c) | Ensure that the Personal Data is only collected, used or disclosed for such purpose, and no other purpose. |
| (d) | Ensure that the Personal Data is properly retained, protected and disposed of in accordance with the PDP Internal Practices. |
4. What is Personal Data
4.1 Personal Data is data (whether true or not) about an individual who can be identified:
- from such data alone; or
- from such data and other information that the organisation has or is likely to have access.
4.2 Non-exhaustive examples of an individual’s Personal Data:
- Personal contact information, including name, personal address, personal email address and telephone number, bank account and tax details;
- NRIC, passport or other equivalent identification number; and
- Other information where the individual can be identified from such information.
Personal Data does NOT cover an individual’s “business contact information” such as his/her position, title, business address, business email/fax number.
4.3 The PDPA deals only with the Personal Data of individuals (i.e. natural persons), and does not extend to data of companies or corporations.
5. Purposes of Collection, Use and/or Disclosure of Personal Data
5.1 Examples of some situations where the Company collects, uses and/or discloses Personal Data, and the purposes of such, are set out below.
| Person | Personal Data Collected | Purpose(s) | |
|---|---|---|---|
| (a) | Job applicants | Information in job applicant’s curriculum vitae or the job application forms (e.g. personal email, telephone number, address, educational history and background, salary at current/previous place of employment). | To evaluate the applicant and to attend to all administrative work to process the job application. |
| (b) | Employees | Personal Data of its employees (e.g. information in (a) above, bank account details, information relating to their salary, tax etc.). Personal Data of employees within the Group and related corporations of the Group. | For legal, audit and other compliance purposes, managing the employment relationship, including filings with or disclosure to authorities and bankers. |
| (c) | Directors and other officers | Personal Data of its directors and other officers (e.g. information in (a) above, bank account details, information relating to their fee, tax etc.). Personal Data of directors and other officers within the Group and related corporations of the Group. | For legal, audit and other compliance purposes, administrative, business, operational and/or management purposes, including filings with or disclosure to authorities and bankers. |
| (d) | Shareholders and investors | Personal Data of shareholders/investors of NetInfinium when they write to NetInfinium to raise queries or when they submit forms to NetInfinium (e.g. relating to proxy forms/dividends/general meetings). Personal Data of shareholders/investors of NetInfinium with their shareholding interests (e.g. CDS account holders in dealings with Bursa Depository for Malaysian securities (e.g. stock listed on Bursa Malaysia) and other regulatory bodies). | To implement or undertake corporate actions such as dividend payments, general meetings (e.g. processing of proxy forms). To respond and deal with enquiries/feedback and for other shareholder or investor related activities, including delivery of documents to shareholders/investors. |
| (e) | Third parties including contracting parties |
|
To respond, deal with, manage and/or for other legitimate purposes for the business and operations of the Group. |
5.2 The Group collects Personal Data primarily from the persons identified in the table set out above. Unless permitted by laws, the collection, use and/or disclosure of Personal Data should be limited to that which is necessary for the identified purposes in the table above.
6. Personal Behaviour & Conduct in NetInfinium
6.1 Before collecting, using or disclosing Personal Data, the consent of the individual must be obtained. There are two types of consent:
- actual consent; and
- deemed consent under the PDPA.
Generally, the Company should seek actual consent. When seeking consent, the purpose for which the consent is sought must be notified to the individual.
6.2 The Company may collect, use or disclose an individual’s Personal Data without his/her consent in the following circumstances:
- the collection, use or disclosure is necessary to respond to an emergency that threatens the life, health or safety of the individual or another individual;
- the Personal Data is publicly available;
- the collection, use or disclosure is necessary for any purpose which is clearly in the interests of the individual, if consent for its collection, use or disclosure cannot be obtained in a timely way;
- the collection, use or disclosure is necessary for any investigation or proceedings;
- the collection, use or disclosure is necessary for evaluative purposes; and/or
- in any other circumstances set out in the PDPA.
7. Withdrawal of Consent / Correction and Access to Personal Data
7.1 An individual who has provided the Company with Personal Data is entitled under the PDPA to withdraw his/her consent, request for corrections to be made and for access to such Personal Data. In such cases, the Company MUST comply with the following:
| Circumstance | Requirement |
|---|---|
| Withdrawal of Consent | An individual is entitled at any time to withdraw his/her consent to the continued collection, use and disclosure of the Personal Data. Such withdrawal shall be made formally in writing to the office of the DPO. The Company must not prohibit an individual from withdrawing his/her consent. |
| Correction of Personal Data | Upon request by the individual concerned, the Company must, in accordance with the PDPA, correct or complete any Personal Data found to be inaccurate or incomplete as soon as practicable unless the Company is satisfied on reasonable grounds that the correction should not be made. |
| Access to Personal Data | Upon request by an individual, the Company is required under the PDPA to provide the individual with his/her Personal Data which is in the possession or under the control of the Company. There are some exceptions to the obligation to provide the above. Please see the PDP Internal Practices (para 4(a)). |
8. Retention, Protection and Disposal of Personal Data
The PDPA regulates how Personal Data in the Company’s possession is to be protected or dealt with. Some of the basic obligations and the corresponding required practices and policies of the Company are set out below and must be complied with at all times:
| Action | Policies / Practices |
|---|---|
| Protection of Personal Data | The Company shall protect Personal Data in its possession or under its control against risk of unauthorised access, collection, use, disclosure, copying, modification or disposal through reasonable security measures. These measures are dealt with in the PDP Internal Practices. |
| Retention and Disposal of Personal Data | The Company must cease to retain documents containing Personal Data or remove the means by which the Personal Data can be associated with particular individuals as soon as it is reasonable to assume that: (i) the purpose for which the Personal Data was collected is no longer being served by the retention of such Personal Data; and (ii) retention is no longer necessary for legal or business purposes. In such event, the Company must ensure that the Personal Data is properly disposed of in accordance with the PDP Internal Practices. |
| Transfer of Personal Data | The Company shall not transfer any Personal Data of an individual to a recipient outside Malaysia unless the standard of protection to Personal Data in the foreign country is comparable to the protection under the PDPA. |
9. Powers of PDPC and Consequences of Non-Compliance with PDPA
9.1 The Personal Data Protection Commission (“PDPC”) may, upon receiving a complaint or of its own motion, conduct an investigation to determine whether an organisation is in compliance with the PDPA. For the purposes of an investigation, the PDPC’s powers include, amongst others, requiring documents or information which relates to any matter relevant to the investigation to be produced by the organisation.
9.2 It is important for the Company to ensure that its employees comply with the requirements of the PDPA as non-compliance can affect the Company. It is to be noted that enforcement decisions of the PDPC are made public, and the PDPC may issue warnings to the organisation. Amongst others, the PDPC may:
- if it is satisfied that an organisation is in breach, impose a financial penalty of up to RM500,000.00 and/or jail imprisonment up to 3 years;
- give directions for the destruction of Personal Data collected or that the organisation ceases to collect or use Personal Data in breach of the PDPA;
- review any complaint by an individual against an organisation for refusal to provide access to his/her Personal Data; and
- give such directions as it thinks fit to ensure compliance with the PDPA.
10. General
10.1 If you are in any doubt or unclear as to the policies or practices set out in this Policy, please contact the DPO for assistance.
10.2 NetInfinium may revise, amend or supplement this Policy or PDP Internal Practices at its discretion from time to time. Employees of the Company are encouraged to check periodically to ensure that they are aware of any such changes.
10.3 Further information on the PDPA can be found at www.pdp.gov.my.
Annex A — PDP Internal Practices
1. Data Protection Officer(s)
The department or office of the DPO has been set up to oversee the Group’s compliance with the PDPA. Other employees within the Group may be delegated to act on behalf of the DPO or to take responsibility for the day-to-day collection and processing of Personal Data. The DPO may be contacted at:
Level 9, Wisma N2N,
Tower 2, Avenue 3, Bangsar South,
No. 8, Jalan Kerinchi,
59200 Kuala Lumpur, Malaysia.
Email: dpo@n2nconnect.com
2. Consent for Collection, Use and Disclosure of Personal Data
- Employees must OBTAIN THE CONSENT of an individual BEFORE the: (i) collection; (ii) use; and/or (iii) disclosure of an individual’s Personal Data.
- All consents must be obtained IN WRITING. This is to mitigate against disputes.
When seeking such consent, employees must:
- notify the individual IN WRITING of the PURPOSE(S) for which the Company intends to collect, use or disclose his/her Personal Data. The purpose should be clearly set out;
- obtain the individual’s WRITTEN confirmation that the Personal Data provided is accurate and complete.
If consent is obtained, the Personal Data must only be collected, used or disclosed by the Company for the purposes for which the consent was obtained, and not for any other purpose.
The individual is entitled to WITHDRAW CONSENT given, on giving reasonable notice to the Company. In such event:
- Employees should direct the individual to submit their notice of withdrawal in writing to the DPO;
- On receipt of the withdrawal notice, the DPO shall inform the individual of the likely consequences of withdrawing the consent; and
- Upon withdrawal, the Company MUST CEASE to collect, use or disclose the Personal Data of such individual (as the case may be).
3. Protection, Retention and Disposal of Personal Data
- Employees must keep all documents containing any Personal Data and confidential information secure and locked at all times.
- Employees must activate the self-locking mechanism for his/her computer if the computer is left unattended for a certain period.
- Employees must encrypt all electronic documents containing Personal Data.
- Documents containing Personal Data should be removed or disposed of once the purposes for which the Personal Data was collected are no longer being served by the retention of the Personal Data and the retention is no longer necessary for legal or business purposes.
- Recycling of paper is encouraged but employees shall ensure that papers or documents containing Personal Data are SHREDDED BEFORE recycling.
- Employees must delete the electronic files containing Personal Data PRIOR to the disposal of IT devices in which the Personal Data was kept or stored.
- Copying of Personal Data to removable storage devices or transmitting such data via email is strictly prohibited unless prior approval of the DPO is obtained.
4. Access to, Correction and Accuracy of Personal Data
Upon request by an individual, the Company must provide him/her with:
- his/her Personal Data which is in the possession or under the control of the Company; and
- information about the ways in which the Personal Data has been or may have been used or disclosed during the past 1 year.
There are some exceptions to the above obligations:
- opinion data kept solely for an evaluative purpose;
- Personal Data which is subject to legal privilege;
- Personal Data which, if disclosed, would reveal confidential commercial information that could, in the opinion of a reasonable person, harm the competitive position of the organisation; or
- any request for information that does not exist or cannot be found.
Personal Data and information must NOT be provided where it could reasonably be expected to:
- threaten the safety or physical or mental health of an individual, other than the individual who made the request;
- cause immediate or grave harm to the safety or to the physical or mental health of the individual who made the request; or
- reveal Personal Data about another individual.
To access the information set out above in 4(a), the individual is required to submit his/her request by using the form set out in Appendix 1 (Access Form).
Note: When processing an access request, it is important for employees to establish and verify the identity of the individual making the request.
In order to comply with an access request made by an individual as set out above in 4(a)(ii), the employee who is managing or handling the relevant Personal Data must maintain a disclosure list substantially in the form set out in Appendix 2 (Disclosure List).
An individual is entitled to request that an error in his/her Personal Data be corrected. Upon receipt of such a request, the employee shall:
- provide the individual with the form set out in Appendix 3 (Correction Form) for his/her completion; and
- correct the Personal Data as soon as practicable and send the corrected Personal Data to every other organisation to which the Personal Data was disclosed by the Company within 1 year before the correction was made, unless that other organisation does not need the corrected Personal Data for any legal or business purpose.
Employees should make reasonable efforts to ensure that Personal Data collected from an individual is correct, accurate and complete. This should be done at the stage when consent is first obtained or when the correction to the Personal Data is made.
5. Specific Requirement Relating to Collection, Use and/or Disclosure of NRIC Numbers
The Company may collect, use and/or disclose NRIC in the following specified circumstances (the “Permitted Circumstances”):
- where collection, use or disclosure of NRIC numbers is required under the law (or an exception under the PDPA applies) (“Law Exception”); or
- where collection, use or disclosure of NRIC numbers is necessary to accurately establish or verify the identities of the individuals to a high degree of fidelity (“High Fidelity Exception”).
It is important to note that the treatment for NRIC numbers applies to other national identification numbers such as foreign identification numbers (FIN), work permit numbers, driver’s license numbers, birth certificate numbers and passport numbers and copies thereof.
Law Exception
Some of the examples are as follows:
- Under the Employment Act, all employers must maintain detailed employment records of employees covered by the Employment Act, which includes employees’ NRIC number and other relevant information. Organisations are therefore allowed to collect, use or disclose NRIC numbers (or copies of NRIC) for this purpose.
- An individual at an organisation becomes unconscious after sustaining a fall and has to be admitted to hospital. The staff at the organisation provides the hospital with the individual’s personal data including his name, NRIC number and medical allergies, without his consent as there is an applicable exception in the PDPA.
High Fidelity Exception
The Company and its employees may collect, use or disclose an individual’s NRIC number if the following conditions are met:
- it is necessary to accurately establish or verify the identity of the individual to a high degree of fidelity in the following situations:
- where the failure to accurately identify the individual to a high degree of fidelity may pose a significant safety or security risk. For example, visitor entry to preschools where ensuring the safety and security of young children is an overriding concern; OR
- where the inability to accurately identify an individual to a high degree of fidelity may pose a risk of significant impact or harm to an individual and/or the organisation. Such transactions typically relate to healthcare, financial or real estate matters, insurance applications and claims, applications and disbursements of substantial financial aid, background credit checks with bureau;
- AND the individual has been notified and his consent has been obtained in accordance with the requirements under the PDPA.
Both conditions (i) and (ii) must be met.
The Company should assess whether its specific situation meets the above conditions before collecting the individual’s NRIC number. The Company must be able to provide justification on request of either the individual or the Commission as to why the collection, use or disclosure of the NRIC number is necessary to accurately establish or verify the identity of the individual to a high degree of fidelity.
Some alternatives to NRIC numbers that have been adopted by companies include user-generated ID, tracking number, organisation-issued QR Code or monetary deposit. However, the Company should consider whether the alternatives provided are reasonable, and avoid collecting excessive personal data as an alternative to the individual’s NRIC number.
The Company may consider collecting partial NRIC number when other alternatives are not satisfactory (for e.g. ‘6789’ from the full NRIC number of 80123-45-6789). This would not be subject to the Commission’s rules for treatment of NRIC numbers as it is not considered to be collection of full NRIC numbers.
6. Transfer of Personal Data
Employees transferring Personal Data of an individual to a recipient outside Malaysia must ascertain and ensure that the recipient is bound by legally enforceable obligations that provide a standard of protection to the Personal Data that is comparable to the protection under the PDPA. If in doubt, please check with the DPO.
Legally enforceable obligations include any law, contracts, binding corporate rules or any other legally binding instrument.
7. Data Breaches
Data breaches can occur for various reasons. These may be caused by employees, external parties or computer system errors. The following are some possible ways in which a data breach may occur. The list is not meant to be exhaustive.
| Cause | Examples |
|---|---|
| Malicious activities |
|
| Human error |
|
| Computer system error |
|
When a data breach occurs or is likely to occur, employees MUST comply with the following:
| Stage | Steps to be taken |
|---|---|
| Containing the breach | Where applicable:
|
| Reporting the incident |
|
8. Complaint Handling Process
| Stage | Steps to be taken | Person-in-charge |
|---|---|---|
| Initial handling of complaints | Upon receipt of a complaint:
| DPO (or such person delegated to act on behalf of the DPO) |
| Assessing the complaints | Upon receipt of a complaint:
| |
| Investigating / reporting the complaints |
| |
| Responding to complaints |
| |
| Taking corrective actions |
|
— End —
