Data Protection Policy
1. Introduction
At Greenwave Technology Sdn Bhd (“the Company”), we are committed to safeguarding the personal data entrusted to us. As a software development company specializing in web and mobile applications, we process personal data from our clients, end users, employees, and partners. We are committed to handling this data responsibly and in compliance with the Personal Data Protection Act 2010 (PDPA) of Malaysia.
2. Scope
This policy applies to all employees, contractors, and third-party service providers who access or process personal data on behalf of the Company. It applies to all personal data handled by our internal systems, as well as personal data processed through software platforms or applications we develop or manage for clients.
3. Definitions
Personal Data: Any information that can identify an individual, directly or indirectly.
Sensitive Personal Data: Includes data relating to health, religion, biometric information, etc.
Data Subject: Any individual whose personal data is collected and processed.
Processing: Includes collection, use, storage, modification, disclosure, and deletion of personal data.
Third Party: Any external party with whom we share data for operational, support, or regulatory reasons.
4. Data Protection Principles
We comply with the PDPA’s 7 Data Protection Principles:
4.1 General Principle
We will not process personal data without consent, unless processing is necessary for contractual, legal, or legitimate business reasons.
4.2 Notice and Choice Principle
We will provide data subjects with clear notice regarding the purpose of data collection and offer choices where applicable.
4.3 Disclosure Principle
We will not disclose personal data to third parties without consent, except where required by law or contractual obligation.
4.4 Security Principle
We implement adequate security measures (technical and organizational) to protect personal data from unauthorized access, alteration, or destruction.
4.5 Retention Principle
Personal data will be retained only as long as necessary to fulfill the stated purposes or as required by law.
4.6 Data Integrity PrincipleWe strive to ensure that all data collected is accurate, complete, and up to date.
4.7 Access PrincipleData subjects have the right to access and correct their personal data upon request.
5. Data We Collect
Depending on the nature of the project and relationship, we may collect:
We may collect this data via project documentation, user registrations, APIs, or analytics tools integrated into apps.
6. Purpose of Processing
We collect and process personal data for the following purposes:
7. Data Disclosure and Third Parties
We may share data with:
All third parties are required to comply with our data protection standards and applicable laws.
8. Data Security Measures
We use industry-standard security practices, including:
9. Rights of Data Subjects
Individuals whose data we collect (directly or on behalf of clients) have the right to:
Requests can be directed to our Data Protection Officer using the contact information below.
10. Data Retention
We retain personal data only for as long as necessary for the purposes described in this policy or as required by law. Upon expiration of the retention period, data will be securely deleted or anonymized.
11. Policy on Client Software Projects
If our company develops software that collects personal data on behalf of our clients, we act as a data processor, and our clients are the data controllers. We ensure that our software solutions include features that support PDPA compliance (e.g. consent mechanisms, audit logs, data export/delete functions).
Clients are responsible for configuring these features and ensuring their own privacy policies are aligned with PDPA.
12. Cross-Border Data Transfer
When using cloud services or international platforms, we may transfer data outside Malaysia. In such cases, we ensure the recipient country provides adequate data protection or contractual safeguards are in place.
13. Policy Updates
This policy may be reviewed and updated periodically to reflect changes in legal requirements, business processes, or technology used. The latest version will be available on our website or internal portal.