Privacy Policy
Last Updated: 31 March 2025 · Cortexium · Petaling Jaya, Malaysia
1. Introduction
Cortexium ("we", "us", "our") is committed to protecting the personal data of individuals who interact with our services, website, and communications. This Privacy Policy explains how we collect, use, store, and protect personal information in accordance with Malaysia's Personal Data Protection Act 2010 (PDPA).
If you have questions about this policy, please contact us at privacy@cortexiumxs.
2. Data We Collect
We collect personal data in the following circumstances:
- When you submit an enquiry through our contact form (name, email, phone, message)
- When you communicate with us by email or phone
- When you visit our website (anonymous usage data via analytics cookies, if consent is given)
- When you enter into a service agreement with us (name, organisation, billing address)
We do not collect sensitive personal data (as defined under PDPA) unless explicitly required for a specific engagement and with your written consent.
3. How We Use Your Data
Personal data collected is used for the following purposes:
- Responding to enquiries and providing information about our services
- Delivering contracted services and managing the client relationship
- Issuing invoices and processing payments
- Understanding how our website is used (analytics, with consent only)
- Complying with legal and regulatory obligations
We do not use your personal data for marketing communications without your prior consent. We do not sell or rent personal data to third parties.
4. Legal Basis for Processing
We process personal data on the following bases:
- Consent — for analytics cookies and marketing communications where applicable
- Contract performance — for data necessary to deliver our services
- Legitimate interests — for responding to enquiries and maintaining business records
- Legal obligation — for compliance with Malaysian law
5. Data Retention
We retain personal data only for as long as necessary for the purpose it was collected. Typical retention periods:
- Enquiry records: up to 12 months from last contact
- Client records (active engagements): duration of engagement plus 7 years for legal compliance
- Analytics data: as configured in the analytics platform (typically 26 months)
Data is securely deleted or anonymised at the end of the applicable retention period.
6. Data Security
We implement appropriate technical and organisational measures to protect personal data against unauthorised access, disclosure, or loss. These include:
- Encrypted storage and transmission (TLS/HTTPS)
- Access controls and internal data handling policies
- Regular review of data security practices
In the event of a data breach that may affect your rights, we will notify you and the relevant authorities as required under applicable law.
7. Cookies
Our website uses cookies to improve functionality and, where consent is given, to collect usage analytics. For full details on the cookies we use and how to manage them, see our Cookie Policy.
8. Third-Party Services
We may share data with the following categories of third-party service providers to deliver our services:
- Cloud infrastructure and hosting providers
- Analytics platforms (only with your consent)
- Accounting and invoicing software
- Email communication tools
All third-party providers are selected based on their data protection practices and are bound by contractual obligations to handle data appropriately.
9. Your Rights
Under Malaysia's PDPA, you have the right to:
- Access the personal data we hold about you
- Request correction of inaccurate data
- Withdraw consent for processing where consent is the legal basis
- Object to processing in certain circumstances
- Request deletion of data where there is no continuing legal basis for retention
To exercise any of these rights, contact us at privacy@cortexiumxs. We will respond within 21 days.
10. Children's Privacy
Our services are directed at business users aged 18 and above. We do not knowingly collect personal data from individuals under 18. If you believe we have inadvertently collected data from a minor, please contact us immediately.
11. External Links
Our website may contain links to third-party websites. We are not responsible for the privacy practices of those sites and encourage you to review their policies independently.
12. Policy Updates
We may update this Privacy Policy from time to time. Material changes will be communicated via an updated "Last Updated" date at the top of this page. Continued use of our website after changes are posted constitutes your acknowledgement of the updated policy.
13. Contact
For any privacy-related enquiries:
- Email: privacy@cortexiumxs
- Address: 9 Jalan PJU 5/1, 47810 Petaling Jaya, Selangor, Malaysia
- Phone: +60 3-7493 6182