Malaysian PDPA 2010 Notice • SSM Reg: 202603007186 (003810616-X)

Privacy Policy & Personal Data Notice

This Privacy Policy details how Qim Lab Enterprise collects, safeguards, and processes personal data across our software platforms (Campus Hub SaaS), civil and electrical engineering projects, and precision fabrication services.

Effective Date: September 2026
Framework: Personal Data Protection Act 2010 (Malaysia)
Section 1.0

Statutory Notice & 7 PDPA Principles

This Personal Data Protection Notice is issued by Qim Lab Enterprise (SSM Registration No: 202603007186 / 003810616-X) in strict compliance with the Personal Data Protection Act 2010 of Malaysia ("PDPA").

We are committed to respecting and protecting the confidentiality and privacy of our clients, institutional subscribers, business partners, website visitors, and sub-contractors. Our data processing operations are strictly grounded in the 7 General Principles of the PDPA:

1. General Principle

Personal data is processed only with explicit, informed consent and for lawful commercial purposes directly related to our business.

2. Notice & Choice Principle

We inform you of data types collected, purposes, and provide clear choices regarding communication and processing.

3. Disclosure Principle

Personal data is never disclosed to unauthorized third parties without your consent unless mandated by Malaysian law.

4. Security Principle

We maintain robust technical, organizational, and physical controls to prevent unauthorized access, loss, or misuse.

5. Retention Principle

Personal data is stored only as long as required for fulfillment of service or statutory tax and legal requirements.

6. Data Integrity Principle

We take all reasonable steps to ensure that personal data is accurate, complete, not misleading, and kept current.

7. Access Principle

You are entitled to request access to and correct your personal data held by us through our official Data Protection Officer.


Section 2.0

Categories of Personal Data We Collect

The personal data we collect depends on the specific divisional services you engage with:

A. General Commercial, Quotation & Invoicing Data

Full name, commercial organization name, SSM registration number, designation, business email address, telephone/mobile number, billing and delivery address, tax identification numbers (TIN/SST), and official banking/payment receipts.

B. Campus Hub SaaS Platform Data (campushub.my)

Administrative login credentials, institutional administrator and staff emails, student/teacher enrollment identifiers, system audit trails, IP addresses, browser agent headers, and diagnostic logs necessary for multi-tenant institution management.

C. Civil & Electrical Site Project Data

Physical installation addresses, facility manager contact numbers, premises blueprints, site photographs, electrical distribution panel layouts, and security gate entry pass records.

D. Precision Machining & Open Source Projects

Client engineering drawings, CAD models (DXF/STEP/DWG), dimensional parameters, and procurement officer contact details. For public open-source software (project_iman, MyMET), we do not harvest personal identifying details from end users.


Section 3.0

Purposes for Processing Your Data

We process your personal data exclusively for the following lawful business purposes:

  • Fulfilling contracted services, manufacturing custom components, deploying software systems, and completing electrical/civil works.
  • Operating, authenticating, and maintaining the security and availability of Campus Hub SaaS (campushub.my).
  • Issuing official Malaysian commercial quotations, milestone delivery notes, and tax invoices in compliance with Inland Revenue Board (LHDN) e-Invoicing guidelines.
  • Processing electronic transactions via our authorized payment partners, including Curlec by Razorpay, FPX, and Malaysian commercial banks.
  • Conducting on-site technical evaluations, civil site inspections, and dispatching electrical service technicians.
  • Providing customer service, technical debugging support, and responding to warranty or rectification inquiries.
  • Complying with statutory audits, judicial orders, and Malaysian legislative mandates.

Section 4.0

Security Standards & Technical Safeguards

Qim Lab Enterprise takes the security of client data seriously and enforces comprehensive technical and operational controls:

256-Bit SSL/TLS

All data in transit across our web properties and APIs is encrypted using modern TLS cryptographic suites.

Access Control & MFA

Database and code repositories are secured by role-based access controls and mandatory multi-factor authentication.

Staff Confidentiality

All engineers, technicians, and project managers sign binding non-disclosure agreements (NDAs).


Section 5.0

Disclosure to Third Parties & Data Processors

Zero Data Monetization Guarantee: Qim Lab Enterprise DOES NOT sell, rent, monetize, or barter personal information to advertisers or marketing aggregators under any circumstance.

We disclose personal data strictly to the following authorized parties where strictly necessary:

  • Payment Processors & Financial Institutions: Authorized Malaysian financial institutions, payment gateways (including Curlec by Razorpay), and the PayNet FPX network to settle invoiced transactions.
  • Cloud Infrastructure Partners: Enterprise hosting providers, database servers, and encrypted backup facilities operating under strict contractual data confidentiality clauses.
  • Legal & Regulatory Authorities: Government bodies such as the Inland Revenue Board of Malaysia (LHDN), Companies Commission of Malaysia (SSM), or law enforcement agencies when strictly compelled by valid legal summons, court orders, or statutory legislation.

Section 6.0

Data Retention & Disposal

Personal data is retained only for as long as necessary to fulfill the operational purposes for which it was collected, or to satisfy legal, accounting, and reporting obligations:

  • Financial & Invoicing Records: Kept for a minimum statutory period of seven (7) years in compliance with Malaysian tax laws (Income Tax Act 1967).
  • Campus Hub SaaS Data: Tenant data is preserved during the active subscription period and permanently purged or exported to the client within sixty (60) days following formal subscription termination.
  • Technical Blueprints & CAD Files: Client CAD drawings are archived securely for re-order purposes, or permanently deleted upon written client request following job completion.

Section 7.0

Cookies & Digital Telemetry

Our public websites utilize strictly functional cookies and session storage necessary to preserve user interface preferences, maintain authentication state across Campus Hub SaaS, and secure form submissions against CSRF attacks. We do not use intrusive cross-site third-party advertising cookies. You may disable cookies through your browser settings, though certain SaaS portal capabilities may become degraded.


Section 8.0

Your Rights & Data Protection Officer Contact

Under the provisions of the Malaysian Personal Data Protection Act 2010, you possess the legal right to:

Right of Access

Request a formal copy of personal data maintained in our records.

Right of Correction

Request correction or updating of inaccurate, outdated, or misleading records.

Right to Withdraw Consent

Withdraw consent for non-essential communications or marketing notices.

Right to Request Deletion

Request deletion of non-statutory data following contract completion.

Contact Our Data Protection Officer (DPO)

To exercise any of your statutory data rights, or if you have questions regarding this Privacy Policy, please send a written request to our compliance team:

Attention: Data Protection Liaison, Qim Lab Enterprise
Location: Malacca, Malaysia
Statutory Response Window: Within twenty-one (21) calendar days of verified identity.
Privacy Office

Privacy & Data Rights Inquiries

To submit a Data Subject Access Request (DSAR), request data correction, or discuss data processing agreements, reach out directly to our Data Protection Liaison.

Direct Privacy Desk

contact@qimlab.com.my

Call / WhatsApp

+60 10-504 4177

Headquarters

Malacca, Malaysia

SSM Reg: 202603007186 (003810616-X)

Submit Privacy Request

Subject to verification under Malaysian PDPA 2010.