Skip to main content
Xennobyte Technologies
  • Home
  • About Us
  • Our Services
  • Our Products
  • Request a quote

Legal

Privacy Policy

Last updated: 6 September 2026

How we collect, use, store, and protect personal data in line with Malaysia's PDPA 2010.

Terms & Conditions Privacy Policy Refund Policy

XENNOBYTE TECHNOLOGIES

Sole proprietorship registered in Malaysia under the Registration of Businesses Act 1956

Trading name Xennobyte Technologies
SSM registration 202303060483 (CT0118592-M)
SST registration B16-2303-32100008
Registered office No. 37, Jalan Panglima Awang 35/116, Alam Impian, Section 35, 40470 Shah Alam, Selangor, Malaysia
Email [email protected] Telephone +6014 649 1820 Website https://xennobyte.com

Contents

  1. 1. Introduction
  2. 2. Data Controller
  3. 3. Data Protection Officer
  4. 4. Personal Data We Collect
  5. 5. How We Collect Personal Data
  6. 6. Providing Personal Data
  7. 7. Purposes of Processing
  8. 8. Disclosure of Personal Data
  9. 9. Transfer of Personal Data Outside Malaysia
  10. 10. Cookies and Similar Technologies
  11. 11. Retention
  12. 12. Security
  13. 13. Your Rights
  14. 14. Direct Marketing
  15. 15. Children
  16. 16. Third-Party Websites and Services
  17. 17. Changes to This Policy
  18. 18. Contact
  19. 19. Governing Law

1. Introduction

This Privacy Policy explains how XENNOBYTE TECHNOLOGIES ("Xennobyte", "Xennobyte Technologies", "we", "us" or "our") collects, uses, discloses, stores, transfers and otherwise processes personal data.

We process personal data in accordance with the Personal Data Protection Act 2010 of Malaysia, including amendments, regulations, standards and guidelines issued under that Act (together, the "PDPA"), and other applicable Malaysian law.

This Policy applies to:

  • visitors to our website at https://xennobyte.com (the "Website");
  • persons who contact us by email, telephone or social media;
  • clients, prospective clients and their authorised representatives;
  • users of our software-as-a-service products, including DIMS (Driving Institute Management System); and
  • other individuals whose personal data we process in the course of our business.

If you provide personal data of another person (for example, an employee, student, instructor or supplier), you must ensure that you are authorised to do so and that the other person has been provided with this Policy or an equivalent notice where required by law.

2. Data Controller

XENNOBYTE TECHNOLOGIES is the data controller for personal data for which it determines the purposes and means of processing. Our details are:

  • Registered business name: XENNOBYTE TECHNOLOGIES
  • Trading name: Xennobyte Technologies
  • SSM registration number: 202303060483 (CT0118592-M)
  • Business type: Sole proprietorship registered in Malaysia under the Registration of Businesses Act 1956
  • Registered / head office: No. 37, Jalan Panglima Awang 35/116, Alam Impian, Section 35, 40470 Shah Alam, Selangor, Malaysia
  • Email: [email protected]
  • Telephone: +6014 649 1820
  • Website: https://xennobyte.com

Privacy and data-protection requests should be sent to [email protected].

Where we process personal data on behalf of a client in connection with a SaaS product or a managed engagement, we act as a data processor for that client to the extent of that processing. The client remains responsible for providing any notice and obtaining any consent required from the relevant individuals, unless we have expressly agreed otherwise in writing. Where Xennobyte acts as a data processor, Xennobyte remains responsible for complying with obligations imposed directly on data processors under applicable Malaysian data-protection law, including applicable Security Principle requirements.

3. Data Protection Officer

Where Xennobyte is required under applicable Malaysian law to appoint a Data Protection Officer, the relevant DPO contact information will be made available through this Privacy Policy or another appropriate channel.

4. Personal Data We Collect

The personal data we collect depends on how you interact with us. It may include:

4.1 Identity and contact data

Name, job title, organisation, email address, telephone number, correspondence address and other contact details.

4.2 Business and engagement data

Information contained in enquiries, quotations, statements of work, contracts, project communications, support tickets and related records.

4.3 Billing and payment data

Invoice details, billing contact information, payment references, transaction amounts, payment method type and payment status. Card numbers and similar payment credentials are collected and processed by our payment processor, Xendit, and are not stored by us in full.

4.4 Account and usage data (SaaS)

Account identifiers, login credentials (stored in a protected form), role or permission settings, audit logs, configuration data and records of how an authorised user uses a Service.

4.5 Client-supplied data

Information, files and records that a client uploads to or processes through our Services, which may include personal data of that client's staff, students, instructors, customers or other third parties.

4.6 Technical data

Internet protocol address, browser type, device type, operating system, referring URL, pages viewed, date and time of access, and similar server-log or security-log information.

4.7 Communications data

The content of emails, calls and messages you send to us, and records needed to manage those communications.

We do not seek to collect sensitive personal data (as defined in the PDPA) unless it is necessary for a Service and permitted by law. If a client uploads such data into a Service, the client is responsible for ensuring that it has a lawful basis to do so.

5. How We Collect Personal Data

We may collect personal data:

  • directly from you when you email us, call us, message us, request a quotation, enter a contract, create an account or make a payment;
  • from the organisation that employs or authorises you, where that organisation is our client or prospective client;
  • from payment processors such as Xendit when you make or attempt a payment;
  • automatically from your device when you visit the Website or use a Service; and
  • from publicly available business sources or referrals, where it is reasonable and lawful to do so.

The Website does not currently use an online contact form. Enquiries are received through the published email address, telephone number and Facebook page.

6. Providing Personal Data

Unless otherwise stated, providing personal data is voluntary. However, certain information may be required for us to enter into or perform a contract, provide a Service, process payment, comply with law or respond to a request. If required information is not provided, we may be unable to provide the relevant Service or complete the requested transaction.

7. Purposes of Processing

We process personal data for the following purposes:

  1. to respond to enquiries and provide quotations;
  2. to enter into, perform and administer contracts for professional services and SaaS products;
  3. to create and manage user accounts and provide technical support;
  4. to process payments, issue invoices and tax invoices, and manage refunds or billing disputes;
  5. to charge and account for Sales and Service Tax where required under the Service Tax Act 2018;
  6. to communicate about a project, subscription, service change or security matter;
  7. to maintain the security, availability and integrity of the Website and Services;
  8. to detect, investigate and prevent fraud, misuse or unauthorised access;
  9. to comply with legal, tax, accounting and regulatory obligations;
  10. to establish, exercise or defend legal claims; and
  11. to improve our Services and business operations, using aggregated or de-identified information where practicable.

Personal data will be processed with consent where required and may otherwise be processed without consent where such processing is permitted under the PDPA, including where necessary in connection with contractual arrangements, compliance with legal obligations or other circumstances recognised by applicable Malaysian law.

8. Disclosure of Personal Data

We may disclose personal data to:

  • our personnel and professional advisers who need it to perform their duties;
  • Xendit and other payment, banking or e-wallet providers that process transactions;
  • hosting and infrastructure providers used to operate the Website (located in Malaysia) and our SaaS products, including providers located in Singapore and other jurisdictions in which our approved service providers and subprocessors operate;
  • domain, DNS, email and security providers;
  • Google, to the limited extent that the Website loads fonts from Google Fonts;
  • a client's authorised administrators, where the data relates to that client's account;
  • a purchaser or successor in the event of a business transfer, subject to appropriate safeguards; and
  • courts, regulators, enforcement authorities or other third parties where disclosure is required or permitted by law.

We do not sell personal data.

Third-party providers process personal data only as needed to provide their services to us, and they are required to protect it in accordance with applicable law and their contracts with us.

9. Transfer of Personal Data Outside Malaysia

The public Website is hosted on infrastructure located in Malaysia. Our SaaS products, including DIMS, may be hosted in Singapore and other jurisdictions in which our approved service providers and subprocessors operate. Personal data may therefore be transferred to, stored in or accessed from those locations.

Where we transfer personal data outside Malaysia, we will do so in accordance with the PDPA, including any conditions applicable to cross-border transfers. We take reasonable steps to ensure that the recipient provides a standard of protection that is substantially similar to the protection under Malaysian law, including through contractual safeguards and provider security measures where appropriate.

Where Xennobyte transfers personal data outside Malaysia, the transfer will be made in accordance with section 129 of the PDPA and applicable guidance issued by the Personal Data Protection Commissioner. Where consent is relied upon as the applicable condition for a transfer, appropriate consent will be obtained.

10. Cookies and Similar Technologies

The Website uses cookies and similar technologies that are reasonably necessary for the site to function, including session and security-related cookies.

The Website loads fonts from Google Fonts. When you visit a page that uses those fonts, Google may receive technical information such as your IP address and browser details, subject to Google's own privacy practices.

We do not currently use advertising cookies or third-party analytics pixels on the Website. If we introduce additional cookies that are not strictly necessary, we will update this Policy and, where required, provide an appropriate choice.

You can control cookies through your browser settings. Blocking some cookies may affect the appearance or function of the Website.

11. Retention

We retain personal data only for as long as necessary for the purposes set out in this Policy, including:

  • enquiry records, generally for up to 24 months after the last relevant communication, unless a longer period is required;
  • contracts, invoices, tax records and SST records, generally for at least seven years, in line with Malaysian tax and accounting requirements;
  • SaaS account data, for the life of the account and for a limited period afterwards to allow data export, security investigation and legal compliance; and
  • server and security logs, for a period appropriate to security and operational needs.

After the applicable period, we delete or anonymise personal data, except where a longer retention period is required by law, needed for a legal claim, or contained in a backup that is overwritten in the ordinary backup cycle.

For SaaS products, unless a product-specific agreement states otherwise, a client may request a reasonable export of available Client Data for up to 30 days after termination or expiry of the Service. After that period, we may delete or anonymise the data subject to legal, backup and security requirements.

12. Security

We take reasonable technical and organisational measures to protect personal data against loss, misuse, unauthorised access, disclosure, alteration and destruction. These measures may include access controls, encrypted transport, password protection, least-privilege administration, and monitoring of systems.

No method of transmission or storage is completely secure. You are responsible for keeping your own passwords and devices confidential and for notifying us promptly of any suspected unauthorised use of an account.

We maintain procedures to identify, investigate, contain, remediate and document data incidents. Where a data incident occurs that we are required to notify under the PDPA or other applicable law, we will notify the Personal Data Protection Commissioner and affected data subjects where required, within the applicable timeframes.

13. Your Rights

Subject to the PDPA and any applicable exemptions, you may:

  • request access to your personal data;
  • request correction of personal data that is inaccurate, incomplete, misleading or not up to date;
  • withdraw consent to processing that is based on consent, where withdrawal is permitted by law;
  • limit the processing of your personal data in the circumstances recognised by the PDPA; and
  • require us to stop using your personal data for direct marketing.

Data portability. Where applicable under the PDPA, you may request us by electronic written notice to transmit eligible personal data to another data controller of your choice, subject to technical feasibility, compatibility of data formats and applicable legal requirements.

To exercise these rights, email [email protected] with sufficient information for us to verify your identity and locate the relevant records. We may charge a fee where the PDPA permits it, and we may refuse a request where the PDPA allows us to do so.

Withdrawal of consent or a request to limit processing may mean that we cannot continue to provide a Service that depends on that data. Amounts already due remain payable.

If you are not satisfied with our response, you may refer the matter to the Personal Data Protection Commissioner of Malaysia.

14. Direct Marketing

We do not use personal data for third-party advertising. We may send service, billing and security messages that are necessary to perform a contract.

If we send optional business updates or promotional messages, we will do so only where permitted by law, and you may opt out at any time by emailing [email protected] or using any unsubscribe method provided in the message. Operational messages about an existing contract, invoice, security issue or service change are not marketing messages.

15. Children

Our Website and Services are directed at businesses and adult representatives of those businesses. We do not knowingly collect personal data from children for our own purposes. If a client uses a Service to process personal data of minors (for example, driving-institute students), the client is responsible for ensuring that it has a lawful basis and any required consent or notice.

16. Third-Party Websites and Services

The Website may contain links to third-party sites, including our Facebook page. Those sites are governed by their own privacy practices. We are not responsible for the content or privacy practices of third-party sites.

Payments made through Xendit are also subject to Xendit's terms and privacy notice.

17. Changes to This Policy

We may update this Policy from time to time to reflect changes in law, our Services, our providers or our operations. The updated Policy will show a revised "Last updated" date and will be published on the Website. Material changes will apply prospectively unless the law requires otherwise.

18. Contact

Questions, access requests, correction requests and other privacy notices may be sent to:

XENNOBYTE TECHNOLOGIES

Trading as Xennobyte Technologies

SSM Registration No.: 202303060483 (CT0118592-M)

No. 37, Jalan Panglima Awang 35/116

Alam Impian, Section 35

40470 Shah Alam

Selangor, Malaysia

Email: [email protected]

Telephone: +6014 649 1820

Website: https://xennobyte.com

19. Governing Law

This Policy is governed by the laws of Malaysia.

Xennobyte Technologies

Founded in Malaysia in 2023, Xennobyte Technologies helps enterprises solve complex business and technology challenges with secure, scalable, and dependable digital solutions.

Our Services

  • Custom software
  • Cloud solutions
  • Cybersecurity
  • IT consulting
  • System integration
  • SaaS products

Quicklinks

  • Home
  • About us
  • Services
  • Products
  • Contact

Legal

  • Terms & Conditions
  • Privacy Policy
  • Refund Policy

Contact Us

  • [email protected]
  • +6014 649 1820
  • Xennobyte Technologies
  • No. 37, Jalan Panglima Awang 35/116, Alam Impian, Section 35, 40470 Shah Alam, Selangor, Malaysia.

Copyright © 2026 by XENNOBYTE TECHNOLOGIES (202303060483 (CT0118592-M)). All rights reserved.

  • Terms & Conditions
  • Privacy Policy
  • Refund Policy