DRAF / DRAFT — Dokumen ini masih dalam semakan undang-undang dan belum berkuat kuasa. This document is under legal review and is not yet in effect; items marked ⚠ are still to be settled.
Rebana

Rebana — Privacy Notice

Canang Technologies Sdn Bhd · Registration No. ⚠ [No. Pendaftaran SSM]
Status: DRAFT for legal review — not yet published, not legal advice.
Last updated: ⚠ [date of publication]


1. Who we are and what this notice covers

Canang Technologies Sdn Bhd ("Canang", "we", "us") builds and operates Rebana, a suite of applications for Malaysian local authorities (PBT) and public agencies.

This notice explains how Canang, as data user (data controller), handles personal data about you when you:

What this notice does not cover. When a local authority or agency uses the Rebana applications — for licences, rentals, complaints, payroll, bookings and so on — the personal data of residents, traders, staff and other users in those applications belongs to that organisation. The organisation is the data user; Canang handles that data only as its data processor, on its instructions, under a contract (our Data Processing Addendum). If you are a resident or officer using a Rebana application, the organisation's own privacy notice applies, and requests about that data should go to the organisation. If you send such a request to us, we will forward it to the organisation.

2. Personal data we collect

Information you give us

Information collected automatically

Sensitive personal data. We do not ask for sensitive personal data (as defined in PDPA s.4, such as health, religious or political information). Please do not send it to us.

3. Why we use it

We use personal data to:

  1. reply to your enquiry, arrange and run demos and briefings, and follow up;
  2. assess and prepare proposals, quotations and pilot or programme applications;
  3. manage our relationship with customer and partner organisations — contracts, onboarding, support, invoicing and collection;
  4. send you updates and newsletters about Rebana, where you have asked for them or where you are an officer of an organisation we work with (you can opt out at any time — §6);
  5. assess job and programme applications, including the integrity checks required of us (§4);
  6. operate, secure and troubleshoot the Site;
  7. meet our legal obligations and our anti-corruption procedures under section 17A of the Malaysian Anti-Corruption Commission Act 2009, and establish or defend legal claims; and
  8. produce aggregated, anonymised statistics that do not identify you.

We do not sell personal data. We do not use enquiry contents or form responses to train artificial-intelligence models.

Is providing it obligatory? No, except that we need your name and a contact channel to reply to you, and the details listed for applications to assess them. If you do not provide them we may not be able to respond or proceed.

4. Who we disclose it to

We disclose personal data only as needed for the purposes in §3, to:

We will not name you, or your organisation, as a customer, pilot partner or reference in any public material without the organisation's written consent.

5. Where it is held

Personal data we hold is stored ⚠ [in Malaysia / in Singapore — confirm the hosting regions]. Some of our service providers (Notion, Meta, ⚠ [e-mail provider]) process data outside Malaysia. We transfer personal data outside Malaysia only as allowed by section 129 of the PDPA — where the destination has laws substantially similar to the PDPA or ensures an adequate level of protection, or on another ground the section allows — and we require those providers to protect it.

6. Your rights and choices

Under the PDPA you may:

Send requests to our Data Protection Officer (§10). We will respond within 21 days, as the PDPA requires. We may ask you to verify your identity, and may charge the fee the regulations allow for a copy of your data.

7. Security

We protect personal data with administrative, technical and physical measures proportionate to the risk — including encrypted connections, access limited to people who need it, and logging of administrative access. If a personal data breach occurs, we will notify the Personal Data Protection Commissioner and, where the breach is likely to cause you significant harm, notify you, within the time limits set under the PDPA.

No system is perfectly secure, and e-mail and messaging sent to us travel over networks we do not control.

8. How long we keep it

We keep personal data only as long as needed for the purpose we collected it for, and then delete or anonymise it:

Data Retention ⚠
Enquiries and demo requests that do not lead to a relationship ⚠ [24 months after last contact]
Customer and partner contact records For the relationship, then ⚠ [7 years] for audit and tax
Event and form responses ⚠ [24 months]
Job and programme applications not taken forward ⚠ [12 months], unless you ask us to keep them longer
Server logs ⚠ [90 days]
Newsletter list Until you unsubscribe; we keep a suppression record so we do not e-mail you again

9. Children

The Site is for public-sector and business audiences. It is not directed at children, and we do not knowingly collect personal data from anyone under 18.

10. Contact us — Data Protection Officer

Data Protection Officer, Canang Technologies Sdn Bhd ⚠ [registered address] E-mail: ⚠ [dpo@canang.com.my] General enquiries: us@canang.com.my

11. Changes to this notice

We will publish any change on this page with a new "Last updated" date. Where a change materially affects how we use personal data we already hold, we will tell you before it takes effect.

12. Language

This notice is published in Bahasa Malaysia and English. ⚠ [If the two differ, the Bahasa Malaysia version prevails.]