Purpose
Misarma Enterprise Sdn. Bhd. is committed to protecting personal data and ensuring compliance with the Malaysian Personal Data Protection Act 2010 (PDPA). This Policy explains how the Company collects, uses, stores, protects, and discloses personal data while safeguarding the privacy rights of Data Subjects.
Scope
Applies to all employees, contractors, suppliers, customers, and other stakeholders who handle personal or sensitive data on behalf of the company. It encompasses all data processing activities, regardless of the format or medium in which the data is stored or transmitted, including electronic, paper-based, and verbal communication.
Definitions (Interpretation)
For this policy, the following definitions apply:
- Personal Data: Any information relating to a commercial or non-commercial transaction that can be used to identify an individual (e.g., Name, IC Number, Passport, Address, Phone Number, Email, Bank Details, Biometrics, and Photographs).
- Sensitive Personal Data: Personal data relating to health, political opinions, religious beliefs, criminal records, or biometric data, requiring explicit consent for processing.
- Processing: Any operation performed on Personal Data, including collecting, recording, storing, retrieving, transferring, erasing, or destroying.
- Data Subject: The individual to whom the Personal Data belongs (e.g., Customers, Employees, Suppliers).
- Data Protection Officer (DPO): An individual responsible for overseeing an organization's compliance with the Personal Data Protection Act 2010 (PDPA) and related data protection requirements.
Use of Personal Data
Personal data is collected and processed for purposes related to recruitment, employment administration, payroll processing, employee benefits, performance management, communication, customer and supplier management, security administration, and compliance with legal and regulatory requirements. The Company will only process personal data for legitimate business purposes and in accordance with applicable laws.
Disclosure of Personal Data
Where necessary, the Company may disclose personal data to government authorities, regulatory agencies, banks, insurance providers, payroll processors, information technology service providers, professional advisers, and other authorized third parties. Such disclosures will only be made for legitimate business, contractual, or legal purposes and appropriate safeguards will be implemented to protect the information.
Protection of Personal Data
The Company maintains appropriate administrative, technical, and physical security measures to safeguard personal data against unauthorized access, disclosure, alteration, loss, misuse, or destruction. Access to personal data is limited to authorized personnel who require the information for their work responsibilities. In the event of a data breach, the Company will take reasonable steps to investigate, contain, and address the incident in accordance with legal obligations.
Retention of Personal Data
Personal data will be retained only for as long as necessary to fulfil the purposes for which it was collected, or to comply with applicable legal, regulatory, tax, audit, and business requirements. When personal data is no longer required, it will be securely deleted, destroyed, or anonymized.
Rights of Individuals
Individuals have the right to request access to their personal data, request correction of inaccurate or incomplete information, withdraw consent where consent forms the basis of processing, and raise concerns regarding the handling of their personal data. The Company will consider and respond to such requests in accordance with applicable legal requirements. They also have the right to request the transfer their personal data from the Company to another data controller in a portable format. The Company will consider and respond to such requests within 21 days of receiving the requests.
Cookies and Website Tracking
The Company's website and online services may use cookies and similar technologies to improve functionality, analyse website performance, enhance user experience, and support security measures. Users may manage cookie preferences through their browser settings, although some website functions may be affected if cookies are disabled.
Contact Information
Any questions, requests, complaints, or concerns regarding this Privacy Policy or the Company's handling of personal data should be directed to:
Privacy Contact PersonHuman Resources Department/ IT Department
Misarma Enterprise Sdn. Bhd.
Email: hr@misarma.com/ itsupport@misarma.com
Telephone: +6085 416 320
The Company may appoint a Data Protection Officer ("DPO") in accordance with applicable legal and regulatory requirements. Upon appointment, the DPO's contact details will be published and updated in this Policy.
Policy Review
This Privacy Policy may be updated periodically to reflect changes in business practices, legal requirements, or regulatory obligations. The latest version will be made available through the Company's official communication channels.
Acknowledgment
All employees, contractors, suppliers, customers, and stakeholders are required to read, understand, and comply with the provisions outlined in this policy.
