Privacy Policy
How we collect, use, disclose, and protect personal data across our website, business relationships, and client services.
1. Introduction
Rubiksbyt (Rubiks Byt Enterprise) is established and operates from Kuala Lumpur, Malaysia. We provide information technology services including cybersecurity & compliance, IT consulting, IT hardware reselling as a value added reseller (VAR), managed IT and service integration, and open source program office (OSPO) & governance. Our target demographic for our services spans Malaysia and outside of Malaysia.
This privacy policy explains how we collect, use, disclose, and protect personal data in connection with our website, www.rubiks-byt.com, our business relationships, and the services we deliver to clients.
As a company based in Malaysia, we comply first with Malaysia's Personal Data Protection Act 2010, as amended by the Personal Data Protection (Amendment) Act 2024 ("PDPA"). For clients outside of Malaysia or global clients, we follow the EU/UK General Data Protection Regulation ("GDPR"), the California Consumer Privacy Act as amended by the California Privacy Rights Act ("CCPA/CPRA"), and other applicable U.S. state privacy laws based on the data we process.
2. Policy scope
This policy addresses two distinct data relationships, discussed separately throughout this document:
- Data we collect directly, as a controller: personal data from website visitors, prospective clients, business contacts, vendors, and job applicants.
- Client data we process, as a processor / subprocessor: personal data that our clients (or their end users) provide to us in the course of delivering contracted services, such as managed IT operations, network monitoring, cybersecurity assessments, and hardware deployment.
Where we act as a processor on behalf of a client, that client's own privacy policy and our applicable data processing agreement ("DPA") or master services agreement ("MSA") govern our handling of that data. This policy describes our general practices and safeguards but does not override contractual terms agreed with a specific client.
3. Information we collect
Automated data collection as a controller
- Device and browser information, including IP address, device identifiers, operating system, and browser type.
- Log data consisting of access timestamps, pages viewed, and referring URLs.
- Cookies, pixels, and similar tracking technologies used to recognize returning visitors and analyze site usage (see Section 14, Cookies and tracking technologies).
- Usage and performance analytics collected through our website and services.
User provided information as a controller
- Account registration details, including name, email address, and passwords.
- Information submitted through contact forms, support requests, or inquiries.
- Billing and payment information provided during transactions.
- Communication preferences and correspondence with our team.
- Any additional information voluntarily submitted through surveys, feedback forms, or account settings.
Client data on our platform as processor
- Network traffic, log, and endpoint data monitored under our cybersecurity & compliance services.
- Employee or contractor access data relevant to our IT consulting engagements.
- Procurement, asset, and configuration data relevant to our IT hardware reselling and value added reseller services.
- Operational, monitoring, and vendor coordination data relevant to our managed IT and service integration services.
- Policy, licensing, and governance data relevant to our open source program office and governance services.
- Data processed and stored in accordance with applicable data processing agreements ("DPA") or master services agreements ("MSA").
We do not sell, or process client data for our own independent purposes beyond providing the contracted service, and client data is encrypted and requires approved access from the business owner.
4. How we use information
We use personal data as a controller to:
- Respond to inquiries and provide requested information about our services.
- Negotiate, enter into, and administer client and vendor contracts.
- Operate, maintain, secure, and improve our website and internal systems.
- Evaluate job applicants and manage recruitment.
- Send service updates, invoices, and, where permitted, marketing communications.
- Comply with legal, tax, and regulatory obligations.
- Detect, investigate, and prevent fraud, security incidents, and misuse of our services.
5. Malaysia Personal Data Protection Act ("PDPA") compliance
As the law of the jurisdiction in which Rubiksbyt (Rubiks Byt Enterprise) is established, the PDPA governs our handling of personal data as a baseline, in addition to any other laws described in this policy.
Legal base for processing
We process personal data only with the consent of the data subject, or otherwise on a basis permitted under the PDPA, such as to perform a contract, comply with a legal obligation, or protect the vital interests of the data subject.
Data protection officer
In accordance with Section 12 of the PDPA, we have appointed a data protection officer ("DPO") responsible for overseeing our compliance with the PDPA. This appointment reflects our engagement in regular and systematic monitoring of personal data through services such as network, endpoint, and infrastructure monitoring delivered under our cybersecurity & compliance and managed IT practices. Our DPO can be contacted using the details in Section 16, Contact us, below.
Data breach notification
Where we have reason to believe a personal data breach has occurred, we will notify the Personal Data Protection Commissioner of Malaysia as soon as possible and in any event within 72 hours. If the breach is likely to result in significant harm to any data subject, we will notify affected data subjects without undue delay, and no later than 7 days after our notification to the Commissioner.
Cross border data transfer (Malaysia)
Because we accept and deliver engagements for clients located outside Malaysia, personal data is regularly transferred into and outside of Malaysia. We assess these transfers under the PDPA's risk based cross border transfer framework, permitting transfer where the receiving jurisdiction has data protection laws substantially similar to, or providing protection adequate to, the PDPA, or where a recognized exception applies, such as data subject consent, necessity for performance of a contract, or contractual safeguards. This assessment operates alongside, and independently of, the GDPR and other transfer mechanisms described in Section 8, International data transfers.
Your rights under PDPA
Subject to applicable exceptions, data subjects have the right to:
- Request access to the personal data we hold about you.
- Request correction of inaccurate personal data provided.
- Withdraw consent to processing at any time.
- Request that processing likely to cause damage or distress be prevented.
- Prevent processing of your data for direct marketing purposes.
- Request data portability, where your data is transmitted directly to another data controller, where technically feasible.
- Lodge a complaint with the Personal Data Protection Commissioner of Malaysia.
6. Legal bases for processing (GDPR)
For clients or data subjects located in the EEA or UK, GDPR applies, and we rely on the following legal bases:
- Contract: processing necessary to perform or enter into a contract with a client or data subject.
- Legitimate interests: for direct marketing to business contacts, website analytics, and networking or information security, balanced against client or data subject rights.
- Consent: required for tracking cookies or marketing communications, which clients or data subjects may withdraw at any time.
- Legal obligation: processing required to comply with applicable law.
7. Sharing and disclosure of information
We do not sell or auction personal data to data brokers. However, with appropriate safeguards we may share personal data with:
- Subprocessors and service providers who support our operations, such as: analytics providers, cloud infrastructure providers, payment processors, and communication tools. We are bound by contractual confidentiality and data protection obligations with each.
- Professional advisors such as legal, accounting, and audit firms, where necessary.
- Regulators, law enforcement, or other parties where required by law or to protect our rights, property, or safety, or that of others.
- A successor entity in connection with a merger, acquisition, financing, or sale of assets.
A current list of categories of subprocessors used in service delivery is available on request and is referenced in client data processing agreements.
8. International data transfers
Appropriate safeguards, such as the European Commission's Standard Contractual Clauses (SCC), the UK International Data Transfer Addendum, or other legally recognized transfer mechanisms, are applied where personal data is transferred outside the country or region where it was collected, including to the United States or other jurisdictions where Rubiksbyt or its subprocessors operate.
9. Your privacy rights
GDPR / UK GDPR rights (EEA, UK, and Switzerland)
If GDPR or UK GDPR applies, clients or data subjects have the right to:
- Access the personal data we hold about them.
- Request the correction of inaccurate or incomplete data.
- Request erasure ("right to be forgotten"), subject to legal exceptions.
- Request restriction of, or object to, certain processing.
- Request data portability.
- Withdraw consent at any time, where processing is based on consent.
- Lodge a complaint with their local supervisory authority.
California rights (CCPA/CPRA)
Clients or data subjects based in California have the right to:
- Know what personal information we collect, use, disclose, and sell or share (if applicable), and access that information.
- Delete personal information we hold about them, subject to exceptions.
- Correct inaccurate personal information.
- Opt out of the sale or sharing of personal information.
- Limit the use and disclosure of sensitive personal information.
- Not receive discriminatory treatment for exercising these rights.
- Rely on opt out preference signals, including the Global Privacy Control, as a valid method of exercising the right to opt out of sale or sharing where required by applicable state law.
Other U.S. state privacy rights
Residents of states with comprehensive privacy laws in effect, including but not limited to Colorado, Virginia, Utah, Texas, Oregon, Montana, Delaware, New Jersey, New Hampshire, Indiana, Kentucky, and Rhode Island, generally have similar rights to access, correct, delete, and port personal data, and to opt out of targeted advertising, the sale of personal data, and certain profiling. Where required, we honor universal opt out mechanisms. To exercise any rights described in this Section 9, or Section 5 for PDPA rights, contact us using the details in Section 16.
10. Automated decision making and profiling
Our website, and certain managed IT and cybersecurity & compliance services, use automated tools, such as analytics, security monitoring, and alerting systems, that may involve profiling or automated decision making that processes personal data:
- Where we act as a processor for a client, we support the client, as data controller, in providing required transparency about the logic, significance, and consequences of automated processing.
- We do not use client data to train general purpose or shared models unless expressly authorized in writing by the client.
- Automated monitoring and alerting used in our services is designed to support human review and does not, on its own, make decisions with legal or similarly significant effect about individuals.
- Individuals subject to automated decisions with legal or similarly significant effect may have the right to request human review, consistent with applicable law and the relevant controller's own policies.
11. Data security
Consistent with our cybersecurity & compliance practice, we maintain administrative, technical, and organizational safeguards designed to protect personal data against unauthorized access, disclosure, alteration, and destruction. These measures include access controls, encryption in transit and at rest where appropriate, network monitoring, vulnerability management, and incident response procedures, including the PDPA breach notification process described in Section 5.
12. Data retention
We retain personal data we control for as long as necessary to fulfill the purposes described in this policy, including to satisfy legal, accounting, or reporting obligations, resolve disputes, and enforce our agreements. Client data we process as a processor is retained and deleted in accordance with the applicable client contract and instructions, and is returned or deleted at the end of the engagement unless a longer retention period is required by law.
13. Children's privacy
Our website and services are directed to businesses and professionals and are not intended for individuals under 18 years of age. We do not knowingly collect personal data or any identifiable data from minors. If you believe a minor has provided us with personal data, please contact us so we can delete it.
14. Cookies and tracking technologies
Our website uses cookies and similar technologies to operate core functionality, remember preferences, and understand website usage through analytics. This includes Google Analytics and Google Tag Manager, third party services provided by Google, which help us understand how visitors interact with our website. These services may set cookies and collect information such as pages visited, time on site, and general location. Analytics cookies are only activated once you provide consent through our cookie banner or preference center; you can withdraw this consent at any time via the "Cookie Preferences" link in the footer. You can also control cookies through your browser settings. Disabling certain cookies may affect site functionality.
15. Changes to this policy
We may update this policy from time to time to reflect changes in our practices, services, or applicable law. The "last updated" date indicates when the policy was last revised. Material changes will be communicated through our website or other appropriate means.
16. Contact us
If you have questions about this privacy policy or wish to exercise your privacy rights, please contact us through the following channels:
For clients or data subjects with a specific data processing agreement in place, please refer to the contact and notification procedures in that agreement.