Privacy Policy Sections
Statutory Notice & 7 PDPA Principles
This Personal Data Protection Notice is issued by Qim Lab Enterprise (SSM Registration No: 202603007186 / 003810616-X) in strict compliance with the Personal Data Protection Act 2010 of Malaysia ("PDPA").
We are committed to respecting and protecting the confidentiality and privacy of our clients, institutional subscribers, business partners, website visitors, and sub-contractors. Our data processing operations are strictly grounded in the 7 General Principles of the PDPA:
Personal data is processed only with explicit, informed consent and for lawful commercial purposes directly related to our business.
We inform you of data types collected, purposes, and provide clear choices regarding communication and processing.
Personal data is never disclosed to unauthorized third parties without your consent unless mandated by Malaysian law.
We maintain robust technical, organizational, and physical controls to prevent unauthorized access, loss, or misuse.
Personal data is stored only as long as required for fulfillment of service or statutory tax and legal requirements.
We take all reasonable steps to ensure that personal data is accurate, complete, not misleading, and kept current.
You are entitled to request access to and correct your personal data held by us through our official Data Protection Officer.
Categories of Personal Data We Collect
The personal data we collect depends on the specific divisional services you engage with:
A. General Commercial, Quotation & Invoicing Data
Full name, commercial organization name, SSM registration number, designation, business email address, telephone/mobile number, billing and delivery address, tax identification numbers (TIN/SST), and official banking/payment receipts.
B. Campus Hub SaaS Platform Data (campushub.my)
Administrative login credentials, institutional administrator and staff emails, student/teacher enrollment identifiers, system audit trails, IP addresses, browser agent headers, and diagnostic logs necessary for multi-tenant institution management.
C. Civil & Electrical Site Project Data
Physical installation addresses, facility manager contact numbers, premises blueprints, site photographs, electrical distribution panel layouts, and security gate entry pass records.
D. Precision Machining & Open Source Projects
Client engineering drawings, CAD models (DXF/STEP/DWG), dimensional parameters, and procurement officer contact details. For public open-source software (project_iman, MyMET), we do not harvest personal identifying details from end users.
Purposes for Processing Your Data
We process your personal data exclusively for the following lawful business purposes:
- Fulfilling contracted services, manufacturing custom components, deploying software systems, and completing electrical/civil works.
- Operating, authenticating, and maintaining the security and availability of Campus Hub SaaS (campushub.my).
- Issuing official Malaysian commercial quotations, milestone delivery notes, and tax invoices in compliance with Inland Revenue Board (LHDN) e-Invoicing guidelines.
- Processing electronic transactions via our authorized payment partners, including Curlec by Razorpay, FPX, and Malaysian commercial banks.
- Conducting on-site technical evaluations, civil site inspections, and dispatching electrical service technicians.
- Providing customer service, technical debugging support, and responding to warranty or rectification inquiries.
- Complying with statutory audits, judicial orders, and Malaysian legislative mandates.
Security Standards & Technical Safeguards
Qim Lab Enterprise takes the security of client data seriously and enforces comprehensive technical and operational controls:
256-Bit SSL/TLS
All data in transit across our web properties and APIs is encrypted using modern TLS cryptographic suites.
Access Control & MFA
Database and code repositories are secured by role-based access controls and mandatory multi-factor authentication.
Staff Confidentiality
All engineers, technicians, and project managers sign binding non-disclosure agreements (NDAs).
Disclosure to Third Parties & Data Processors
We disclose personal data strictly to the following authorized parties where strictly necessary:
- Payment Processors & Financial Institutions: Authorized Malaysian financial institutions, payment gateways (including Curlec by Razorpay), and the PayNet FPX network to settle invoiced transactions.
- Cloud Infrastructure Partners: Enterprise hosting providers, database servers, and encrypted backup facilities operating under strict contractual data confidentiality clauses.
- Legal & Regulatory Authorities: Government bodies such as the Inland Revenue Board of Malaysia (LHDN), Companies Commission of Malaysia (SSM), or law enforcement agencies when strictly compelled by valid legal summons, court orders, or statutory legislation.
Data Retention & Disposal
Personal data is retained only for as long as necessary to fulfill the operational purposes for which it was collected, or to satisfy legal, accounting, and reporting obligations:
- Financial & Invoicing Records: Kept for a minimum statutory period of seven (7) years in compliance with Malaysian tax laws (Income Tax Act 1967).
- Campus Hub SaaS Data: Tenant data is preserved during the active subscription period and permanently purged or exported to the client within sixty (60) days following formal subscription termination.
- Technical Blueprints & CAD Files: Client CAD drawings are archived securely for re-order purposes, or permanently deleted upon written client request following job completion.
Cookies & Digital Telemetry
Our public websites utilize strictly functional cookies and session storage necessary to preserve user interface preferences, maintain authentication state across Campus Hub SaaS, and secure form submissions against CSRF attacks. We do not use intrusive cross-site third-party advertising cookies. You may disable cookies through your browser settings, though certain SaaS portal capabilities may become degraded.
Your Rights & Data Protection Officer Contact
Under the provisions of the Malaysian Personal Data Protection Act 2010, you possess the legal right to:
Request a formal copy of personal data maintained in our records.
Request correction or updating of inaccurate, outdated, or misleading records.
Withdraw consent for non-essential communications or marketing notices.
Request deletion of non-statutory data following contract completion.
Contact Our Data Protection Officer (DPO)
To exercise any of your statutory data rights, or if you have questions regarding this Privacy Policy, please send a written request to our compliance team: