Definitions
For clarity, the following definitions are used throughout this policy to describe terms related to personal data and processing activities.
NexaTsoft operates as a provider of bespoke business software development and process automation services. This privacy policy describes the categories of personal data we process, the purposes for processing, legal bases relied upon, and the rights available to individuals. We process data necessary to design, deploy and maintain software solutions, deliver support, and to comply with contractual and legal obligations. We apply technical and organisational measures appropriate to the risk to maintain confidentiality and integrity of data. This policy applies to data collected via NexaTsoft.vip, direct client communications, and services delivered on behalf of clients in Malaysia and internationally. Our business registration details and contacts are provided for transparency and regulatory correspondence.
For clarity, the following definitions are used throughout this policy to describe terms related to personal data and processing activities.
We collect data necessary to provide our services, improve our products, and meet contractual and legal obligations. Data collection is limited to what is relevant and proportionate for the stated purposes.
Data you provide directly to NexaTsoft typically includes operational and contact information required to deliver services and support.
We also collect certain technical and usage data automatically when users interact with our websites and services to maintain operation and improve performance.
In certain scenarios we receive data from third parties such as clients, integrated service providers, or partners. We limit such transfers to what is necessary for service provision.
We process personal data for a restricted set of purposes directly related to delivering our core services, legal compliance, and improving our operations.
Where applicable law requires a legal basis for processing personal data, NexaTsoft relies on one or more of the following lawful grounds depending on the specific processing activity.
NexaTsoft.vip and associated service portals use cookies and similar technologies to support site functionality, session management, analytics and, where consented, targeted communication.
We use session cookies (temporary), persistent cookies (to remember preferences) and third-party cookies for analytics and embedded services. Cookie identifiers do not, by themselves, reveal personal data beyond analytics aggregations.
Categories include strictly necessary cookies for operation, performance cookies for analytics, and optional functional cookies for preferences. We do not use cookie data for profiling beyond service improvement without consent.
You may manage cookie preferences through your browser settings and our cookie consent banner. Disabling non-essential cookies may affect some features of the website or client portals.
Full cookie policy and consent management
We share personal data only with trusted parties that require access to deliver services or where required by law. All recipients are contractually bound to protect the data and to use it only for specified purposes.
Because our services and suppliers may operate across borders, personal data may be transferred to jurisdictions outside Malaysia. Transfers are managed in accordance with applicable law and only when necessary for service provision.
When transferring data internationally we use standard contractual clauses, data processing agreements, encryption and access restrictions to maintain an adequate level of protection consistent with Malaysia law and recognised international practices.
We retain personal data only as long as necessary to fulfil the purposes described, to satisfy contractual and legal obligations, and to resolve disputes or enforce agreements.
Account and project data is retained for the duration of the client relationship and for a defined period thereafter to allow for invoicing, support continuity and regulatory compliance. Retention periods are documented in client agreements.
Communications and support records are retained for a period aligned to operational needs and dispute resolution, typically not exceeding industry-standard retention periods unless otherwise required by law.
Technical and security logs are retained for incident contribute and security purposes. Retention duration is set according to risk assessment and legal requirements, with periodic review.
When retention periods expire or upon valid request where applicable law permits, data is securely deleted or anonymised. Some data may be retained in backup systems for operational resilience for a limited time.
NexaTsoft applies a defence-in-depth security approach to protect personal data. Measures include encryption in transit and at rest, role-based access controls, secure development lifecycle practices, vulnerability scanning, and regular security assessments. Access to personal data is limited to authorised personnel strictly on a need-to-know basis.
Subject to applicable law, individuals have rights to exercise control over their personal data. Requests will be handled in a timely manner and in accordance with legal requirements.
NexaTsoft collects and processes personal data necessary to deliver business software development and process automation services. We process data lawfully, transparently and with documented purposes such as contract performance, legitimate business interests and compliance with legal obligations. This section outlines how we handle personal data for individuals in jurisdictions where additional rights apply.
The protections described here apply to individuals located in the European Economic Area (EEA) and the United Kingdom when NexaTsoft processes their personal data in the context of offering services or monitoring behavior. If you are in the EEA or UK, you may have specific rights under local law; we describe those rights and how to exercise them below.
If you believe NexaTsoft has processed your personal data in a way that does not comply with applicable law, you may contact us to raise a concern. For individuals in the EEA or UK, you also have the right to lodge a complaint with your local supervisory authority.
To exercise any privacy right described in this policy, submit a request using the contact details below. Include sufficient information to verify your identity and to enable us to locate the relevant records. We will not comply with requests that would adversely affect the privacy rights of others or where we are legally prevented from doing so.
We aim to acknowledge requests within 7 business days and respond substantively within 30 calendar days of verification. Complex requests or those requiring additional verification may take longer; if so, we will notify you and provide an estimated timeframe.
NexaTsoft may send marketing communications about our software development services, automation solutions and events to contacts who have opted in or where we have a legitimate interest and local law permits. Marketing messages will clearly identify NexaTsoft and provide a simple mechanism to opt out.
To stop receiving marketing emails, use the unsubscribe link included in every marketing message or contact us directly. We will process unsubscribe requests promptly and update your preferences in our systems.
Our services are intended for business users and professionals. NexaTsoft does not knowingly collect personal data from children under the age of 16. If you believe we have inadvertently collected information about a child, contact us and we will take steps to remove that information in accordance with applicable law.
Our website and communications may include links to third-party sites and services. NexaTsoft is not responsible for the privacy practices or content of those third parties. We recommend reviewing the privacy notices of any external sites you visit.
NexaTsoft may update this privacy policy to reflect changes in our practices, legal requirements or service offerings. Material changes will be made available on our website and where required by law we will provide additional notice. The effective date of the current policy is noted in this document.
Data controller: NexaTsoftAddress: Jalan Hospital, Bandar Baru Gua Musang, 18300 Gua Musang, Kelantan, MalaysiaBusiness ID: 085922950505Phone: +60127217993For privacy inquiries or to submit a rights request, contact us via the contact form on NexaTsoft.vip or by postal mail to the address above. Please include sufficient detail to help us process your request.