Legal

PDPA Compliance

Personal Data Protection Act 2010 (Malaysia)

Last updated: June 2025

MarketOS is committed to full compliance with the Personal Data Protection Act 2010 (PDPA) of Malaysia — the primary legislation governing the collection, processing, and protection of personal data in commercial transactions. This statement explains how we meet our obligations under the Act.

1. About the PDPA

The Personal Data Protection Act 2010 (Act 709) is a Malaysian law that regulates the processing of personal data in commercial transactions. It applies to any person who processes or has control over or authorises the processing of any personal data in respect of commercial transactions.

The PDPA is built on seven key principles that organisations must comply with when handling personal data:

01
General Principle
Personal data may only be processed with consent and for a lawful purpose.
02
Notice & Choice Principle
Data subjects must be informed of the purposes for which their data is being collected.
03
Disclosure Principle
Personal data shall not be disclosed for any purpose other than what was stated at collection.
04
Security Principle
Practical steps must be taken to protect personal data from loss, misuse, or unauthorised access.
05
Retention Principle
Personal data shall not be kept longer than is necessary.
06
Data Integrity Principle
Personal data must be accurate, complete, not misleading, and kept up to date.
07
Access Principle
Data subjects have the right to access and correct their personal data.

2. How MarketOS Complies

General Principle
We collect and process personal data only with the user's consent, obtained during registration and use of our platform. We do not process personal data for purposes beyond those disclosed.
Notice & Choice Principle
We inform users of the types of personal data we collect, the purposes of collection, their right to withdraw consent, and any third parties to whom data may be disclosed — at the point of collection and through this statement.
Disclosure Principle
We do not share personal data with third parties except as described in our Privacy Policy (e.g. service providers, legal requirements). We never sell personal data.
Security Principle
We implement TLS/SSL encryption, encrypted storage, access controls, and regular security reviews. Our infrastructure is hosted on secured cloud servers in Singapore and Malaysia.
Retention Principle
We retain personal data only for as long as necessary to provide our services or comply with legal obligations. Account data is deleted within 30 days of account closure.
Data Integrity Principle
Users can update their personal data at any time via their account settings. We maintain data accuracy through validation at point of entry and regular reviews.
Access Principle
Users may request access to or correction of their personal data at any time by contacting us at pdpa@marketos.my. We will respond within 21 days as required by the Act.

3. Personal Data We Process

In operating MarketOS, we act as a data processor on behalf of our users and as a data controller in respect of our own users' account data. The categories of personal data we process include:

CategoryExamplesPurpose
Identity DataName, company nameAccount management
Contact DataEmail, phone numberCommunication, billing
Transactional DataSubscription, payment historyBilling, compliance
Technical DataIP address, browser typeSecurity, analytics
Usage DataFeature interactions, logsPlatform improvement
CRM DataCustomer contacts uploaded by userUser-controlled CRM feature

4. Your Rights Under the PDPA

As a data subject under Malaysian law, you have the right to:

Right to Access
Request a copy of the personal data we hold about you.
Right to Correction
Request correction of inaccurate or incomplete personal data.
Right to Withdraw Consent
Withdraw your consent to the processing of your personal data for direct marketing at any time.
Right to Prevent Processing
Prevent processing of your personal data for purposes that are likely to cause damage or distress.
Right to Erasure
Request deletion of your personal data upon account closure (subject to legal retention obligations).

To exercise any of these rights, submit a written request to pdpa@marketos.my. We will acknowledge your request within 7 business days and respond fully within 21 days.

5. Cross-Border Data Transfer

Some of our service providers are located outside Malaysia (e.g. AI model providers, cloud infrastructure). Any transfer of personal data outside Malaysia is conducted only where the receiving country provides a level of protection equivalent to that under the PDPA, or where appropriate contractual safeguards are in place.

6. Data Breach Notification

In the event of a data breach that may affect your personal data, we will:

  • Conduct an immediate investigation and containment
  • Notify affected users promptly via email
  • Report to relevant Malaysian authorities where required
  • Provide guidance on steps you can take to protect yourself

7. Data Protection Officer

MarketOS has designated a Data Protection Officer (DPO) responsible for overseeing compliance with this policy and the PDPA.

Data Protection Officer

Email: pdpa@marketos.my

Website: marketos.my

Response time: Within 7 business days

8. Updates to This Statement

We review and update this PDPA Compliance Statement regularly to reflect changes in our practices or applicable law. The date at the top of this page reflects the last revision. Material changes will be communicated via email to registered users.