PDPA Compliance
Personal Data Protection Act 2010 (Malaysia)
Last updated: June 2025
MarketOS is committed to full compliance with the Personal Data Protection Act 2010 (PDPA) of Malaysia — the primary legislation governing the collection, processing, and protection of personal data in commercial transactions. This statement explains how we meet our obligations under the Act.
1. About the PDPA
The Personal Data Protection Act 2010 (Act 709) is a Malaysian law that regulates the processing of personal data in commercial transactions. It applies to any person who processes or has control over or authorises the processing of any personal data in respect of commercial transactions.
The PDPA is built on seven key principles that organisations must comply with when handling personal data:
2. How MarketOS Complies
3. Personal Data We Process
In operating MarketOS, we act as a data processor on behalf of our users and as a data controller in respect of our own users' account data. The categories of personal data we process include:
| Category | Examples | Purpose |
|---|---|---|
| Identity Data | Name, company name | Account management |
| Contact Data | Email, phone number | Communication, billing |
| Transactional Data | Subscription, payment history | Billing, compliance |
| Technical Data | IP address, browser type | Security, analytics |
| Usage Data | Feature interactions, logs | Platform improvement |
| CRM Data | Customer contacts uploaded by user | User-controlled CRM feature |
4. Your Rights Under the PDPA
As a data subject under Malaysian law, you have the right to:
To exercise any of these rights, submit a written request to pdpa@marketos.my. We will acknowledge your request within 7 business days and respond fully within 21 days.
5. Cross-Border Data Transfer
Some of our service providers are located outside Malaysia (e.g. AI model providers, cloud infrastructure). Any transfer of personal data outside Malaysia is conducted only where the receiving country provides a level of protection equivalent to that under the PDPA, or where appropriate contractual safeguards are in place.
6. Data Breach Notification
In the event of a data breach that may affect your personal data, we will:
- Conduct an immediate investigation and containment
- Notify affected users promptly via email
- Report to relevant Malaysian authorities where required
- Provide guidance on steps you can take to protect yourself
7. Data Protection Officer
MarketOS has designated a Data Protection Officer (DPO) responsible for overseeing compliance with this policy and the PDPA.
Data Protection Officer
Email: pdpa@marketos.my
Website: marketos.my
Response time: Within 7 business days
8. Updates to This Statement
We review and update this PDPA Compliance Statement regularly to reflect changes in our practices or applicable law. The date at the top of this page reflects the last revision. Material changes will be communicated via email to registered users.