Data protection and professional practice

General Information

NexaTsoft operates as a provider of bespoke business software development and process automation services. This privacy policy describes the categories of personal data we process, the purposes for processing, legal bases relied upon, and the rights available to individuals. We process data necessary to design, deploy and maintain software solutions, deliver support, and to comply with contractual and legal obligations. We apply technical and organisational measures appropriate to the risk to maintain confidentiality and integrity of data. This policy applies to data collected via NexaTsoft.vip, direct client communications, and services delivered on behalf of clients in Malaysia and internationally. Our business registration details and contacts are provided for transparency and regulatory correspondence.

05-02-2026 NexaTsoft (Business ID: 085922950505) [email protected]
NexaTsoft secure software and automation illustration
01

Definitions

For clarity, the following definitions are used throughout this policy to describe terms related to personal data and processing activities.

Personal data means any information relating to an identified or identifiable natural person, including contact details, identifiers, and information used to provide or support services.
Processing refers to any operation performed on personal data, whether automated or not, such as collection, storage, use, transfer, disclosure, retention, or deletion.
User refers to any individual who interacts with NexaTsoft services, including clients, their designated users, and visitors to NexaTsoft.vip.
Service refers to the software development, automation, integration, support and consultancy services provided by NexaTsoft to clients.
Cookies are small files stored on a device by a website to maintain session state, preferences, or to collect analytics data. Similar technologies include local storage and device fingerprints.
02

Data Collection

We collect data necessary to provide our services, improve our products, and meet contractual and legal obligations. Data collection is limited to what is relevant and proportionate for the stated purposes.

03

Data You Provide

Data you provide directly to NexaTsoft typically includes operational and contact information required to deliver services and support.

  • Contact information: name, business email address and company phone number
  • Company and billing details: company name, business registration, billing address and invoicing information
  • Project information: technical requirements, system specifications and documentation provided for development
  • Account credentials and access preferences when you register for a client portal or management dashboard
  • Communications: records of support requests, emails and meeting notes necessary for project delivery
  • Optional feedback and surveys: satisfaction ratings and comments provided voluntarily
04

Data Collected Automatically

We also collect certain technical and usage data automatically when users interact with our websites and services to maintain operation and improve performance.

  • Device and browser information: device type, operating system, browser version
  • Network information: IP address, approximate location, and connection details
  • Usage metrics: pages visited, session duration, feature usage and error logs
  • Performance and diagnostic data needed to identify and resolve faults
  • Cookies and similar identifiers used for session management and analytics
  • Security logs such as authentication attempts and access records
05

Data From Third Parties

In certain scenarios we receive data from third parties such as clients, integrated service providers, or partners. We limit such transfers to what is necessary for service provision.

  • Client-provided directories and user lists for onboarding and access control
  • Payment and billing details from payment processors required to complete transactions
  • Analytics and telemetry data from third-party monitoring tools integrated with our services
06

Purposes of Processing

We process personal data for a restricted set of purposes directly related to delivering our core services, legal compliance, and improving our operations.

  • To deliver and maintain software, automation workflows and integrations requested by clients
  • To manage client relationships, billing, and contractual obligations
  • To provide technical support, incident handling and operational communications
  • To perform security monitoring, vulnerability management and fraud detection
  • To conduct analytics that inform product improvements and operational efficiency
  • To comply with legal obligations, regulatory requests and lawful audits
  • To enable safe deployment of updates, backups and disaster recovery processes
  • To facilitate mergers, acquisitions or corporate reorganisations subject to appropriate safeguards
07

Legal Bases for Processing

Where applicable law requires a legal basis for processing personal data, NexaTsoft relies on one or more of the following lawful grounds depending on the specific processing activity.

  • Contractual necessity: processing necessary to perform services agreed with a client
  • Legitimate interests: processing to ensure service security, fraud prevention and business operations, balanced against individuals' rights
  • Consent: where explicit consent has been obtained for optional activities such as marketing communications or non-essential cookies
  • Legal obligations: processing required to comply with statutory duties or court orders
08

Cookies and Similar Technologies

NexaTsoft.vip and associated service portals use cookies and similar technologies to support site functionality, session management, analytics and, where consented, targeted communication.

We use session cookies (temporary), persistent cookies (to remember preferences) and third-party cookies for analytics and embedded services. Cookie identifiers do not, by themselves, reveal personal data beyond analytics aggregations.

Categories include strictly necessary cookies for operation, performance cookies for analytics, and optional functional cookies for preferences. We do not use cookie data for profiling beyond service improvement without consent.

You may manage cookie preferences through your browser settings and our cookie consent banner. Disabling non-essential cookies may affect some features of the website or client portals.

Full cookie policy and consent management

09

Data Sharing and Disclosure

We share personal data only with trusted parties that require access to deliver services or where required by law. All recipients are contractually bound to protect the data and to use it only for specified purposes.

  • Service providers engaged to host infrastructure, run analytics or process payments on our behalf
  • Subcontractors performing project tasks under NexaTsoft direction and confidentiality terms
  • Professional advisors, auditors and legal counsel when necessary for compliance or dispute resolution
  • Law enforcement, regulatory or government authorities when required by applicable law or court order
  • Prospective buyers or partners in the event of a corporate transaction, subject to confidentiality protections
  • Aggregated or anonymised data may be shared publicly for research or benchmarking without identifying individuals
10

International Data Transfers

Because our services and suppliers may operate across borders, personal data may be transferred to jurisdictions outside Malaysia. Transfers are managed in accordance with applicable law and only when necessary for service provision.

When transferring data internationally we use standard contractual clauses, data processing agreements, encryption and access restrictions to maintain an adequate level of protection consistent with Malaysia law and recognised international practices.

11

Data Retention

We retain personal data only as long as necessary to fulfil the purposes described, to satisfy contractual and legal obligations, and to resolve disputes or enforce agreements.

Account and project data is retained for the duration of the client relationship and for a defined period thereafter to allow for invoicing, support continuity and regulatory compliance. Retention periods are documented in client agreements.

Communications and support records are retained for a period aligned to operational needs and dispute resolution, typically not exceeding industry-standard retention periods unless otherwise required by law.

Technical and security logs are retained for incident contribute and security purposes. Retention duration is set according to risk assessment and legal requirements, with periodic review.

When retention periods expire or upon valid request where applicable law permits, data is securely deleted or anonymised. Some data may be retained in backup systems for operational resilience for a limited time.

12

Security Measures

NexaTsoft applies a defence-in-depth security approach to protect personal data. Measures include encryption in transit and at rest, role-based access controls, secure development lifecycle practices, vulnerability scanning, and regular security assessments. Access to personal data is limited to authorised personnel strictly on a need-to-know basis.

  • Encryption for data at rest and in transit using industry-standard protocols
  • Access controls, two-factor authentication for administrative interfaces and least-privilege policies
  • Regular security testing, patch management and incident response planning
13

Your Rights

Subject to applicable law, individuals have rights to exercise control over their personal data. Requests will be handled in a timely manner and in accordance with legal requirements.

  • Right to access: obtain confirmation of processing and a copy of personal data
  • Right to rectification: request correction of inaccurate or incomplete data
  • Right to erasure: request deletion when retention is no longer necessary and no legal basis to retain the data applies
  • Right to restriction of processing: request limitation of processing under certain circumstances
  • Right to data portability: receive personal data in a structured, commonly used and machine-readable format where applicable
  • Right to object: object to processing based on legitimate interests or direct marketing, as permitted by law
  • Right to withdraw consent: where processing is based on consent, withdraw it without affecting the lawfulness of prior processing
  • Right to lodge a complaint with a supervisory authority if you believe your data rights have been infringed
14

Cross-border Legal Considerations

NexaTsoft collects and processes personal data necessary to deliver business software development and process automation services. We process data lawfully, transparently and with documented purposes such as contract performance, legitimate business interests and compliance with legal obligations. This section outlines how we handle personal data for individuals in jurisdictions where additional rights apply.

The protections described here apply to individuals located in the European Economic Area (EEA) and the United Kingdom when NexaTsoft processes their personal data in the context of offering services or monitoring behavior. If you are in the EEA or UK, you may have specific rights under local law; we describe those rights and how to exercise them below.

  • Right to access: You may request confirmation whether we process your personal data and obtain a copy of the personal data we hold about you.
  • Right to rectification: If your personal data is inaccurate or incomplete, you can ask us to correct it.
  • Right to erasure and restriction: Subject to legal limits, you may request deletion or restriction of processing of your personal data.
  • Right to data portability and objection: Where applicable, you may request a portable copy of your data and object to certain processing activities, including direct marketing.

If you believe NexaTsoft has processed your personal data in a way that does not comply with applicable law, you may contact us to raise a concern. For individuals in the EEA or UK, you also have the right to lodge a complaint with your local supervisory authority.

15

Exercising your privacy rights

To exercise any privacy right described in this policy, submit a request using the contact details below. Include sufficient information to verify your identity and to enable us to locate the relevant records. We will not comply with requests that would adversely affect the privacy rights of others or where we are legally prevented from doing so.

[email protected]

We aim to acknowledge requests within 7 business days and respond substantively within 30 calendar days of verification. Complex requests or those requiring additional verification may take longer; if so, we will notify you and provide an estimated timeframe.

16

Marketing communications

NexaTsoft may send marketing communications about our software development services, automation solutions and events to contacts who have opted in or where we have a legitimate interest and local law permits. Marketing messages will clearly identify NexaTsoft and provide a simple mechanism to opt out.

To stop receiving marketing emails, use the unsubscribe link included in every marketing message or contact us directly. We will process unsubscribe requests promptly and update your preferences in our systems.

17

Children's privacy

Our services are intended for business users and professionals. NexaTsoft does not knowingly collect personal data from children under the age of 16. If you believe we have inadvertently collected information about a child, contact us and we will take steps to remove that information in accordance with applicable law.

18

Third-party links

Our website and communications may include links to third-party sites and services. NexaTsoft is not responsible for the privacy practices or content of those third parties. We recommend reviewing the privacy notices of any external sites you visit.

19

Changes to this privacy policy

NexaTsoft may update this privacy policy to reflect changes in our practices, legal requirements or service offerings. Material changes will be made available on our website and where required by law we will provide additional notice. The effective date of the current policy is noted in this document.

Contact Information and Data Controller

Data controller: NexaTsoftAddress: Jalan Hospital, Bandar Baru Gua Musang, 18300 Gua Musang, Kelantan, MalaysiaBusiness ID: 085922950505Phone: +60127217993For privacy inquiries or to submit a rights request, contact us via the contact form on NexaTsoft.vip or by postal mail to the address above. Please include sufficient detail to help us process your request.

+60127217993 [email protected] Jalan Hospital, Bandar Baru Gua Musang, 18300 Gua Musang, Kelantan, Malaysia