Privacy Policy

Last Updated: January 15, 2026

Effective Date: January 15, 2026

Nexalis is committed to protecting your privacy and handling your personal data responsibly. This privacy policy explains how we collect, use, store, and protect your personal information when you interact with our services. We comply with the Personal Data Protection Act 2010 (PDPA) of Malaysia and maintain transparency about our data practices.

1. Data Collection Information

Personal Data We Collect

We collect personal data that you provide directly to us through our website forms, email communications, phone conversations, and during service engagements. This includes:

  • Name and contact information (email address, phone number)
  • Company name and job title
  • Communication preferences
  • Project-related information you share during consultations
  • Feedback and testimonials you choose to provide

How We Collect Data

Personal data is collected through:

  • Contact forms on our website
  • Email correspondence initiated by you
  • Phone conversations when you contact us
  • Service agreements and project documentation
  • Analytics cookies and website usage data (see our Cookie Policy)

Legal Basis for Processing

We process your personal data based on:

  • Consent: When you submit forms or agree to receive communications
  • Contract: When necessary to provide services you have requested
  • Legitimate Interest: For business operations, improving our services, and responding to inquiries

Data Retention

We retain personal data for as long as necessary to fulfill the purposes outlined in this policy. Specifically:

  • Inquiry data: retained for 2 years unless you request earlier deletion
  • Client project data: retained for 7 years to comply with business record requirements
  • Marketing communications data: retained until you unsubscribe or request deletion
  • Website analytics: aggregated data retained indefinitely, individual data for 26 months

2. Data Usage Explanation

How We Use Your Personal Data

We use collected personal data for the following purposes:

  • Service Delivery: To provide AI integration services, strategic planning, team training, and technical support
  • Communication: To respond to your inquiries, provide updates about your projects, and maintain our business relationship
  • Service Improvement: To analyze how our services are used and identify opportunities for enhancement
  • Marketing: To send information about our services (only with your consent, and you can opt out at any time)
  • Legal Compliance: To meet regulatory requirements and maintain business records

Data Sharing with Third Parties

We do not sell or rent your personal data. We may share data with:

  • Service Providers: Cloud hosting providers, email services, analytics platforms that help us operate our business
  • Professional Advisors: Lawyers, accountants, or consultants when necessary for business operations
  • Legal Requirements: Authorities when required by law or to protect our legal rights

All third parties are required to maintain confidentiality and use data only for specified purposes.

Marketing Communications

If you have consented to receive marketing communications, we may send you information about our services, industry insights, and company updates. You can opt out at any time by clicking the unsubscribe link in any email or contacting us at [email protected].

3. Data Protection Measures

We implement comprehensive security measures to protect your personal data from unauthorized access, alteration, disclosure, or destruction.

Security Measures

  • Encryption: Data transmitted to and from our website is encrypted using SSL/TLS protocols
  • Secure Storage: Personal data is stored on secure servers with restricted access
  • Access Controls: Only authorized personnel have access to personal data, limited to what is necessary for their roles
  • Regular Security Audits: We conduct periodic reviews of our security practices and systems
  • Employee Training: Staff members receive training on data protection responsibilities

Breach Notification

In the event of a data breach that poses risk to your rights and freedoms, we will notify affected individuals within 72 hours of becoming aware of the breach, as required by PDPA regulations. We will provide information about the nature of the breach and steps being taken to address it.

4. Cookie Information

Our website uses cookies to enhance your browsing experience and analyze site usage. Cookies are small text files stored on your device.

Types of Cookies We Use

  • Essential Cookies: Required for website functionality and security
  • Analytics Cookies: Help us understand how visitors use our website
  • Preference Cookies: Remember your settings and preferences

For detailed information about our cookie usage and how to manage your preferences, please see our Cookie Policy.

5. Your Rights

Under the Personal Data Protection Act 2010 (PDPA) of Malaysia, you have the following rights regarding your personal data:

Right to Access

You have the right to request confirmation of whether we are processing your personal data and to receive a copy of that data. We will provide this information within 21 days of your request.

Right to Correction

If your personal data is inaccurate or incomplete, you have the right to request correction. We will update the information promptly upon verification.

Right to Erasure

You can request deletion of your personal data when it is no longer necessary for the purposes for which it was collected, or if you withdraw consent. Please note that we may be required to retain certain information for legal or business record purposes.

Right to Object

You have the right to object to processing of your personal data for direct marketing purposes. You can opt out of marketing communications at any time.

Right to Withdraw Consent

Where we process your data based on consent, you can withdraw that consent at any time. This will not affect the lawfulness of processing before withdrawal.

Right to Lodge a Complaint

If you believe we have not handled your personal data appropriately, you have the right to lodge a complaint with the Personal Data Protection Commissioner of Malaysia.

How to Exercise Your Rights

To exercise any of these rights, please contact us at [email protected]. We will respond to your request within 21 days and may need to verify your identity before processing certain requests.

6. Third-Party Links

Our website may contain links to third-party websites. We are not responsible for the privacy practices or content of these external sites. We encourage you to review the privacy policies of any third-party sites you visit.

7. Children's Privacy

Our services are intended for business use and not directed at individuals under 18 years of age. We do not knowingly collect personal data from minors. If we become aware that we have collected data from a person under 18, we will delete it promptly.

8. Policy Updates

We may update this privacy policy periodically to reflect changes in our practices or legal requirements. When we make significant changes, we will notify you by posting a notice on our website or sending you an email. The "Last Updated" date at the top of this policy indicates when it was last revised.

9. Contact Information

If you have questions about this privacy policy or how we handle your personal data, please contact us:

Data Controller: Nexalis

Email: [email protected]

Phone: +60 3-2726 8349

Address: Suite 21-01, Q Sentral, Jalan Stesen Sentral 2, 50470 Kuala Lumpur, Malaysia