How we collect, use, disclose, and protect personal data across our website, business relationships, and client services.
Rubiksbyt (Rubiks Byt Enterprise) is established and operates from Kuala Lumpur, Malaysia. We provide information technology services including AI/ML development, blockchain development, business intelligence & data analytics, cloud services, cybersecurity & compliance, DevOps as a service, IT consulting, managed IT services, network infrastructure for retail, OSPO & governance, IT retailing, and software development. Our target demographic for our services spans Malaysia and outside of Malaysia.
This privacy policy explains how we collect, use, disclose, and protect personal data in connection with our website, www.rubiks-byt.com, our business relationships, and the services we deliver to clients.
As a Malaysian-based company, we comply first with Malaysia's Personal Data Protection Act 2010, as amended by the Personal Data Protection (Amendment) Act 2024 ("PDPA"). For clients outside of Malaysia or global clients, we follow the EU/UK General Data Protection Regulation ("GDPR"), the California Consumer Privacy Act as amended by the California Privacy Rights Act ("CCPA/CPRA"), and other applicable U.S. state privacy laws based on the data we process.
This policy addresses two distinct data relationships, discussed separately throughout this document:
Where we act as a processor on behalf of a client, that client's own privacy policy and our applicable data processing agreement ("DPA") or master services agreement ("MSA") govern our handling of that data. This policy describes our general practices and safeguards but does not override contractual terms agreed with a specific client.
We do not sell, or process client data for our own independent purposes beyond providing the contracted service, and client data is encrypted and requires approved access from the business owner.
We use personal data as a controller to:
As the law of the jurisdiction in which Rubiksbyt (Rubiks Byt Enterprise) is established, the PDPA governs our handling of personal data as a baseline, in addition to any other laws described in this policy.
We process personal data only with the consent of the data subject, or otherwise on a basis permitted under the PDPA, such as to perform a contract, comply with a legal obligation, or protect the vital interests of the data subject.
In accordance with Section 12 of the PDPA, we have appointed a data protection officer ("DPO") responsible for overseeing our compliance with the PDPA. This appointment reflects our engagement in regular and systematic monitoring of personal data through services such as network, endpoint, and infrastructure monitoring delivered under our cybersecurity & compliance and managed IT practices. Our DPO can be contacted using the details in Section 16, Contact us, below.
Where we have reason to believe a personal data breach has occurred, we will notify the Personal Data Protection Commissioner of Malaysia as soon as possible and in any event within 72 hours. If the breach is likely to result in significant harm to any data subject, we will notify affected data subjects without undue delay, and no later than 7 days after our notification to the Commissioner.
Because we accept and deliver engagements for clients located outside Malaysia, personal data is regularly transferred into and outside of Malaysia. We assess these transfers under the PDPA's risk-based cross-border transfer framework, permitting transfer where the receiving jurisdiction has data protection laws substantially similar to, or providing protection adequate to, the PDPA, or where a recognized exception applies, such as data subject consent, necessity for performance of a contract, or contractual safeguards. This assessment operates alongside, and independently of, the GDPR and other transfer mechanisms described in Section 8, International data transfers.
Subject to applicable exceptions, data subjects have the right to:
For clients or data subjects located in the EEA or UK, GDPR applies, and we rely on the following legal bases:
We do not sell or auction personal data to data brokers. However, with appropriate safeguards we may share personal data with:
A current list of categories of sub-processors used in service delivery is available on request and is referenced in client data processing agreements.
Appropriate safeguards, such as the European Commission's Standard Contractual Clauses (SCC), the UK International Data Transfer Addendum, or other legally recognized transfer mechanisms, are applied where personal data is transferred outside the country or region where it was collected, including to the United States or other jurisdictions where Rubiksbyt or its sub-processors operate.
If GDPR or UK GDPR applies, clients or data subjects have the right to:
Clients or data subjects based in California have the right to:
Residents of states with comprehensive privacy laws in effect — including but not limited to Colorado, Virginia, Utah, Texas, Oregon, Montana, Delaware, New Jersey, New Hampshire, Indiana, Kentucky, and Rhode Island — generally have similar rights to access, correct, delete, and port personal data, and to opt out of targeted advertising, the sale of personal data, and certain profiling. Where required, we honor universal opt-out mechanisms. To exercise any rights described in this Section 9, or Section 5 for PDPA rights, contact us using the details in Section 16.
As part of our AI/ML development services, we may design, build, or operate automated systems on behalf of clients, including systems that may involve profiling or automated decision-making that processes personal data:
Consistent with our cybersecurity & compliance practice, we maintain administrative, technical, and organizational safeguards designed to protect personal data against unauthorized access, disclosure, alteration, and destruction. These measures include access controls, encryption in transit and at rest where appropriate, network monitoring, vulnerability management, and incident response procedures, including the PDPA breach notification process described in Section 5.
We retain personal data we control for as long as necessary to fulfill the purposes described in this policy, including to satisfy legal, accounting, or reporting obligations, resolve disputes, and enforce our agreements. Client data we process as a processor is retained and deleted in accordance with the applicable client contract and instructions, and is returned or deleted at the end of the engagement unless a longer retention period is required by law.
Our website and services are directed to businesses and professionals and are not intended for individuals under 18 years of age. We do not knowingly collect personal data or any identifiable data from minors. If you believe a minor has provided us with personal data, please contact us so we can delete it.
Our website uses cookies and similar technologies to operate core functionality, remember preferences, and understand website usage through analytics. This includes Google Analytics and Google Tag Manager, third-party services provided by Google, which help us understand how visitors interact with our website. These services may set cookies and collect information such as pages visited, time on site, and general location. Analytics cookies are only activated once you provide consent through our cookie banner or preference center; you can withdraw this consent at any time via the "Cookie Preferences" link in the footer. You can also control cookies through your browser settings. Disabling certain cookies may affect site functionality.
We may update this policy from time to time to reflect changes in our practices, services, or applicable law. The "last updated" date indicates when the policy was last revised. Material changes will be communicated through our website or other appropriate means.
If you have questions about this privacy policy or wish to exercise your privacy rights, please contact us through the following channels:
| Business name | Rubiks Byt Enterprise (ref. Rubiksbyt) |
| Location | Kuala Lumpur, Malaysia |
| Website | www.rubiks-byt.com |
| team@rubiks-byt.com |
For clients or data subjects with a specific data processing agreement in place, please refer to the contact and notification procedures in that agreement.
Reach out to our team directly and we'll walk you through it.
Get in Touch