Legal

Privacy Policy

Effective date: [to be inserted on publication]

Last updated: [to be inserted on publication]

Nexagate Sdn Bhd (Company No. [registration number]) (Nexagate, we, us, our) is a cybersecurity consulting and managed services provider. We take the protection of personal data seriously — it is the business we are in.

This Policy explains how we collect, use, disclose and protect personal data when you visit nexagate.com, enquire about our services, engage us, attend Nexa Academy training, or apply to work with us. It is issued in accordance with the Personal Data Protection Act 2010, as amended by the Personal Data Protection (Amendment) Act 2024 (together, the PDPA).

1. Who is responsible for your data

For the activities described in this Policy, Nexagate Sdn Bhd is the data controller.

Data controller: Nexagate Sdn Bhd BO2-D-13A-1, Boutique Office 2, Menara 3, KL Eco City, Jalan Bangsar, 59200 Kuala Lumpur, Malaysia

Data Protection Officer: [name and title] Email: dpo@nexagate.com Telephone: +603 2935 9363

Our Indonesian subsidiary, PT Nexagate Siber Sekuriti, processes personal data in Indonesia under Indonesian law. Where this Policy applies to that processing it is noted.

2. What we collect

2.1 When you visit the Site

  • IP address, approximate location derived from it, browser and device type, operating system
  • Pages visited, referring URL, time and duration of visit
  • Cookie identifiers, where you have consented to non-essential cookies

2.2 When you enquire or request a quotation

  • Name, business email address, telephone number
  • Company name, job title, industry
  • The content of your enquiry, including any information you choose to give us about your environment or requirements
  • How you heard about us

2.3 When you become a client

  • Contact details of your personnel involved in the engagement
  • Billing and business contact information
  • Correspondence and meeting records relating to the engagement

2.4 When you register for Nexa Academy

  • Name, email, telephone, employer
  • Employment status and educational background, where relevant to a programme
  • Assessment results and certification records

2.5 When you apply for a role

  • CV and the information in it, including employment and education history
  • Contact details, right to work information, references

2.6 Sensitive personal data

We do not routinely collect sensitive personal data. Where an engagement or a role requires it — for example security vetting information, or biometric data, which is classified as sensitive personal data under the amended PDPA — we will tell you separately and obtain your explicit consent.

2.7 Sources

Most personal data comes directly from you. We may also receive it from your employer, from a colleague who refers you, from publicly available professional sources such as LinkedIn, or from our technology and channel partners.

3. Why we process your data

PurposeLawful basis under the PDPA
Responding to enquiries and preparing quotationsConsent; necessary for the performance of a transaction you have requested
Delivering contracted services and managing the engagementNecessary for the performance of a contract
Invoicing, collections and financial record-keepingLegal obligation; legitimate business interest
Operating Nexa Academy programmes, assessment and certificationNecessary for the performance of a contract; consent
Recruitment and candidate assessmentConsent; steps taken at your request before entering a contract
Sending service updates, threat advisories and marketingConsent, which you may withdraw at any time
Maintaining the security of our own systemsLegitimate interest; legal obligation
Meeting regulatory, audit and certification requirementsLegal obligation

We do not use personal data for automated decision-making that produces legal effects concerning you, and we do not sell personal data.

4. Client data — where we act as processor, not controller

This distinction matters and is easy to miss.

As controller, we determine the purposes of processing — your enquiry, your engagement with us, your attendance at a course, your job application. That is what the rest of this Policy covers.

As processor, we handle personal data that sits inside a client's own environment while delivering services — for example log data flowing through our Global SOC, data encountered during a penetration test, or records reviewed during an ISMS assessment. In those cases the client is the data controller and determines the purpose. We process that data only on the client's documented instructions, under the terms of the engagement agreement and any data processing addendum to it.

If you are an individual whose data was processed by us in that capacity, your request should be directed to the organisation that engaged us. We will support them in responding.

5. Who we share it with

We disclose personal data only where necessary, and only to:

  • Group companies — PT Nexagate Siber Sekuriti, where an engagement involves our Indonesian operation
  • Service providers acting on our instructions — cloud hosting, email and collaboration platforms, CRM, marketing automation, payment processing and professional advisers
  • Technology partners, where a service you have engaged is delivered on their platform and the disclosure is necessary to provision or support it
  • Regulators, law enforcement and courts, where we are required to disclose by law or to establish, exercise or defend a legal claim
  • A purchaser or successor, in connection with a merger, acquisition or restructuring, subject to the same protections as this Policy

We require every service provider to protect personal data to a standard no lower than our own, and to process it only for the purpose we have specified.

We do not disclose personal data to third parties for their own marketing purposes.

6. Transfers outside Malaysia

Some of our service providers operate outside Malaysia. Where personal data is transferred out of Malaysia, we do so in accordance with the cross-border transfer requirements of the PDPA as amended, and on the basis that the receiving jurisdiction provides protection substantially similar to the PDPA, or that adequate safeguards are in place under our contract with the recipient.

We maintain a record of the jurisdictions to which personal data is transferred. You may request that information from our Data Protection Officer.

7. How long we keep it

DataRetention
Website analytics[x] months from collection
Enquiries that do not become engagements[x] months from last contact
Client engagement recordsDuration of the engagement plus [x] years, to meet contractual, audit and limitation requirements
Financial and tax records7 years, as required by the Income Tax Act 1967
Academy assessment and certification records[x] years, to allow certificate verification
Unsuccessful job applications[x] months, unless you ask us to keep them longer
Marketing consent recordsUntil consent is withdrawn, plus a record of the withdrawal

When the retention period ends, we securely destroy or irreversibly anonymise the data.

8. How we protect it

We operate an Information Security Management System certified to ISO/IEC 27001:2022, with cloud controls aligned to ISO/IEC 27017:2015, and an AI Management System certified to ISO/IEC 42001. Our controls include access control on a least-privilege basis, encryption in transit and at rest, network segmentation, logging and monitoring through our Global SOC, vetted personnel bound by confidentiality obligations, and periodic independent testing.

No system is perfectly secure. We do not guarantee absolute security, but we take the measures a reasonable organisation in our position should take, and we test them.

9. If something goes wrong

Where a personal data breach occurs, we follow the notification regime introduced by the Personal Data Protection (Amendment) Act 2024:

  • We notify the Personal Data Protection Commissioner as soon as practicable and in any event within 72 hours of becoming aware of a qualifying breach.
  • Where the breach causes or is likely to cause significant harm to affected individuals, we notify those individuals without undue delay, and in any event within 7 days of notifying the Commissioner.
  • We maintain an internal breach register and a documented response procedure.

10. Your rights

Under the PDPA you have the right to:

  • Access the personal data we hold about you
  • Correct it where it is inaccurate, incomplete, misleading or out of date
  • Withdraw consent to any processing based on consent, including marketing
  • Limit processing for direct marketing purposes
  • Data portability — request that your data be transmitted to another data controller, where technically feasible, a right introduced by the 2024 amendment
  • Be informed of the third parties to whom your data has been or may be disclosed

To exercise any of these rights, contact our Data Protection Officer at dpo@nexagate.com. We may ask for proof of identity before acting — we will not disclose your data to someone claiming to be you.

We respond within 21 days. Where a request is complex we will tell you and explain the delay. A prescribed fee may apply to a data access request, as permitted by the PDPA.

Withdrawing consent does not affect the lawfulness of processing carried out before the withdrawal, and may mean we can no longer provide a service to you.

11. Cookies

The Site uses cookies. Strictly necessary cookies are set without consent because the Site cannot function without them. Analytics and preference cookies are set only where you consent through our cookie banner, and you may change or withdraw that choice at any time.

You can also block or delete cookies through your browser settings, though parts of the Site may then not work as intended.

[If a separate Cookie Policy is published, link it here.]

12. Children

The Site is not directed at children. We do not knowingly collect personal data from anyone under 18 except in the context of a Nexa Academy programme, where a parent or guardian's consent is obtained in accordance with the PDPA.

13. Changes to this Policy

We may update this Policy. The current version is always available at nexagate.com/privacy with its effective date. Where a change materially affects how we use your personal data, we will notify you directly.

14. Contact and complaints

Data Protection Officer Nexagate Sdn Bhd BO2-D-13A-1, Boutique Office 2, Menara 3, KL Eco City, Jalan Bangsar, 59200 Kuala Lumpur Email: dpo@nexagate.com Telephone: +603 2935 9363

If you are not satisfied with our response, you may complain to:

Jabatan Perlindungan Data Peribadi (JPDP) Kementerian Digital, Malaysia www.pdp.gov.my