Effective date: 16 July 2026
This Privacy Policy (also referred to as our "Privacy Notice") explains how Xyberteq Innovations Sdn Bhd collects, uses, discloses, transfers, retains and protects personal data when you visit our websites, contact us, or request a briefing or demonstration of our services. It is issued in accordance with the Malaysian Personal Data Protection Act 2010, as amended by the Personal Data Protection (Amendment) Act 2024 ("PDPA"), and, where applicable to individuals in the European Economic Area ("EEA") and the United Kingdom, the EU General Data Protection Regulation (Regulation (EU) 2016/679) and the ePrivacy rules ("GDPR").
This Privacy Notice is published in English at www.xyberteq.com and in Bahasa Malaysia at ms.xyberteq.com. In line with Section 7(3) of the PDPA, both the English and Bahasa Melayu versions of this Privacy Notice are equally authentic.
1. Who We Are
Xyberteq Innovations Sdn Bhd (formerly Peranti Technologies Sdn Bhd) is the data controller responsible for your personal data.
- Company name: Xyberteq Innovations Sdn Bhd (formerly Peranti Technologies Sdn Bhd)
- Company registration number: 201701035190 (1249361-M)
- Registered office: Kuala Lumpur, Malaysia
- Telephone: +603 2083 0133
- Website (English): www.xyberteq.com
- Website (Bahasa Malaysia): ms.xyberteq.com
We are a business-to-business cybersecurity vendor. Our services include AI-driven security operations, penetration testing and adversarial exposure validation, digital risk protection, mobile threat defence, and sovereign artificial intelligence, provided principally to regulated financial institutions and government organisations in Malaysia and the wider Southeast Asia region.
1.1 Data protection contact
For any question about this notice, to exercise your rights, or to make a complaint, you can contact us using the details below. We have not appointed a separate Data Protection Officer; where the appointment of a Data Protection Officer becomes mandatory for our class of data controller under the Personal Data Protection (Amendment) Act 2024, we will appoint one and update these details accordingly:
- Data protection contact, Xyberteq Innovations Sdn Bhd
- Email: info.sec@xyberteq.com
- Telephone: +603 2083 0133
2. Scope of This Notice
This Privacy Notice applies to personal data we process about visitors to our websites, prospective customers, business contacts, and other individuals who interact with us through our marketing channels. Our websites are marketing websites intended for business audiences; they are not intended for use by children, and we do not knowingly collect personal data from anyone under the age of 18.
Where we process personal data on behalf of our customers as part of delivering our cybersecurity services (for example, data handled within a customer's security operations environment), we act as a data processor and that processing is governed by our contract with the relevant customer, not by this Privacy Notice.
3. Personal Data We Collect and Why
We collect and process the following categories of personal data:
3.1 Information you provide through our contact / briefing form
When you complete the contact or briefing request form on our website, we collect:
- Your name
- Your work email address
- Your company or organisation name
- The content of your message or enquiry
We use this information to respond to your enquiry, to arrange briefings, demonstrations or meetings, to provide the information you request, and to follow up in the course of a legitimate business relationship. Please do not submit sensitive personal data or confidential technical details through the form.
Providing this information is voluntary. However, if you choose not to provide it, we may be unable to respond to your enquiry or to arrange the briefing, demonstration or meeting you have requested.
3.2 Server logs and technical data
When you visit our websites, our web servers and hosting provider automatically collect certain technical information for security, diagnostics and the reliable operation of the site. This may include:
- Your IP address
- Browser type and version, device and operating system information
- The pages you access, referring pages, and the date and time of access
- Other standard HTTP request and log data
We use this data to keep our websites secure and available, to detect and prevent abuse or attacks, and to troubleshoot technical issues.
3.3 Cookies and similar technologies
We currently use only first-party, strictly necessary (essential) cookies required for the basic operation and security of our websites. We do not currently deploy analytics, advertising or marketing tracking technologies. Please see Section 7 (Cookies) for further detail, including our approach should we introduce non-essential cookies in the future.
4. Lawful Bases for Processing
We only process personal data where we have a lawful basis to do so.
4.1 Under the Malaysian PDPA
Under the PDPA, we process your personal data on the basis of your consent, which you give by voluntarily submitting your details through our contact or briefing form, and/or where the processing is necessary for the performance of, or the taking of steps at your request with a view to entering into, a business relationship or transaction with you. Our processing is carried out in accordance with the seven Personal Data Protection Principles under the PDPA — the General, Notice and Choice, Disclosure, Security, Retention, Data Integrity, and Access Principles.
4.2 Under the GDPR (for individuals in the EEA and the UK)
Where the GDPR applies, we rely on the following lawful bases:
- Legitimate interests (Article 6(1)(f)): to respond to your enquiries, to conduct and develop our business-to-business relationships, to operate and secure our websites, and to prevent fraud and misuse. We balance these interests against your rights and freedoms.
- Consent (Article 6(1)(a)): where you voluntarily provide your details for us to contact you, and — where required — for the use of any non-essential cookies or similar technologies.
- Steps prior to entering into a contract (Article 6(1)(b)): where you ask us to take steps, such as arranging a briefing or proposal, before entering into a contract.
5. How We Use Your Personal Data
We use the personal data described above to:
- Respond to and manage your enquiries and briefing requests;
- Arrange and conduct meetings, demonstrations and product briefings;
- Communicate with you about our services in the context of a legitimate business relationship;
- Operate, maintain, secure and improve our websites;
- Detect, investigate and prevent security incidents, abuse and unlawful activity;
- Comply with our legal, regulatory and contractual obligations.
We do not sell your personal data, and we do not use it for automated decision-making that produces legal or similarly significant effects concerning you.
6. Disclosure of Personal Data and Our Processors
We do not sell or rent personal data. We may disclose your personal data to the following categories of recipients, who act as our service providers (data processors) or where disclosure is otherwise permitted or required:
6.1 Form delivery — FormSubmit.co
Our contact / briefing form is delivered to us using FormSubmit.co, a third-party form-handling service. When you submit the form, the information you provide (your name, work email, company and message) is transmitted to and processed by FormSubmit.co in order to deliver your submission to us by email. This means your data leaves our website and is handled by a third party outside our direct infrastructure. FormSubmit.co processes this data in accordance with its own privacy practices and terms; we encourage you not to include sensitive or confidential information in the form.
6.2 Hosting and email providers
- Website hosting provider: GoDaddy.com, LLC — cPanel web hosting (primary server located in Singapore), with the Website fronted by the Sucuri (GoDaddy) Web Application Firewall (United States) — hosts our websites and generates server logs.
- Email / business communications provider: Google Workspace (Google LLC / Google Ireland Limited) — provides our business email that receives enquiries; Website contact-form submissions are delivered to us by FormSubmit.co (United States) — receives and stores enquiry emails and our correspondence with you.
- Other processors: We do not currently engage additional processors such as CRM or analytics tools; if we introduce any, this notice will be updated before they are used.
6.3 Other disclosures
We may also disclose personal data to professional advisers, auditors, and to regulators, law enforcement or other authorities where we are legally required or permitted to do so, or where necessary to protect our rights, property or safety or that of others. In the event of a corporate transaction such as a merger, acquisition or reorganisation, personal data may be disclosed to the relevant counterparties subject to appropriate confidentiality protections.
7. Cookies and Similar Technologies
Cookies are small text files placed on your device when you visit a website. We currently use only strictly necessary (essential) first-party cookies that are required for the secure and reliable operation of our websites. These do not require your consent under applicable law and cannot be switched off through our site without affecting basic functionality.
We do not currently use analytics, advertising or marketing cookies or trackers. Should we introduce non-essential technologies in the future — for example Google Analytics 4 (GA4) or Google Tag Manager (GTM) — we will do so only after obtaining your prior consent through a cookie consent banner or preference tool, in line with the GDPR and ePrivacy requirements, and consistent with the Notice and Choice Principle under the PDPA. You will be able to accept, reject or manage such non-essential cookies, and to withdraw your consent at any time. This notice will be updated to describe any such technologies before they are activated.
You can also control cookies through your browser settings, including deleting or blocking cookies, although blocking essential cookies may affect how our websites function.
8. International Transfers of Personal Data
We are based in Malaysia, and some of our service providers (including FormSubmit.co and our hosting and email providers) may store or process personal data on servers located outside Malaysia, including outside your country of residence. This means your personal data may be transferred to, and processed in, jurisdictions that may have different data protection standards from your own.
Where we transfer personal data across borders, we take steps to ensure it is protected consistent with this notice and applicable law:
- Under the PDPA: we transfer personal data outside Malaysia only where a lawful basis for such transfer applies, including where you have consented, where the transfer is necessary for the performance of, or steps taken at your request in relation to, our dealings with you, or where the recipient is in a place that provides a level of protection to personal data substantially similar to, or is subject to a level of protection comparable with, that under the PDPA.
- Under the GDPR: where personal data of individuals in the EEA or the UK is transferred to a country that has not been recognised as providing an adequate level of protection, we rely on an appropriate safeguard such as the European Commission's Standard Contractual Clauses (and the UK International Data Transfer Addendum where relevant), or another lawful transfer mechanism.
You may contact us for further information about the safeguards applied to a specific transfer.
9. Data Retention
We retain personal data only for as long as necessary to fulfil the purposes described in this notice, to maintain our legitimate business relationships, and to comply with our legal, regulatory, tax and accounting obligations, after which it is securely deleted or anonymised in accordance with the Retention Principle under the PDPA.
- Contact / briefing form submissions and related correspondence: retained for 24 months.
- Server logs and technical data: retained for 24 months.
- Cookie-related data (where non-essential cookies are later introduced): retained for 24 months.
Where a specific period is not stated above, we retain the data for no longer than is necessary for the purpose for which it was collected and any related legal requirements.
10. Security
We implement appropriate technical and organisational measures to protect personal data against loss, misuse, unauthorised access, disclosure, alteration and destruction, consistent with the Security Principle under the PDPA and the security requirements of the GDPR. These measures include access controls, encryption in transit where appropriate, network and application security controls, logging and monitoring, and staff confidentiality obligations. As a cybersecurity vendor, information security is central to how we operate. However, no method of transmission or storage is completely secure, and we cannot guarantee absolute security.
10.1 Personal data breach notification
We maintain procedures to detect, investigate and respond to personal data breaches. Where a breach triggers a legal obligation to do so, we will notify the relevant authority and, where required, affected individuals. Under the personal data breach notification requirements introduced by the Personal Data Protection (Amendment) Act 2024, we will notify the Personal Data Protection Commissioner as soon as practicable, and in any event within 72 hours of becoming aware of the breach, and we will notify affected individuals without unnecessary delay where the breach is likely to cause significant harm. Where the GDPR applies, we will comply with the corresponding obligations, including notification to the competent supervisory authority without undue delay and, where feasible, within 72 hours, and notification to affected individuals where the breach is likely to result in a high risk to their rights and freedoms.
11. Your Rights and How to Exercise Them
11.1 Your rights under the Malaysian PDPA
Subject to the conditions and exceptions in the PDPA, you have the right to:
- Access the personal data we hold about you;
- Correct personal data that is inaccurate, incomplete, misleading or out of date;
- Withdraw your consent to our processing of your personal data;
- Data portability — to request, where technically feasible and in accordance with the Personal Data Protection (Amendment) Act 2024 and any standards issued under it, that your personal data be transmitted directly to another data controller;
- Prevent processing that is likely to cause you unwarranted damage or distress, or for the purposes of direct marketing.
11.2 Your rights under the GDPR (for individuals in the EEA and the UK)
Where the GDPR applies, you have the right to:
- Access — obtain confirmation of, and a copy of, the personal data we process about you;
- Rectification — have inaccurate or incomplete data corrected;
- Erasure — request deletion of your personal data in certain circumstances ("right to be forgotten");
- Restriction — request that we restrict processing in certain circumstances;
- Data portability — receive the personal data you provided to us in a structured, commonly used, machine-readable format, and have it transmitted to another controller where technically feasible;
- Object — object to processing based on our legitimate interests, and to object to direct marketing at any time;
- Withdraw consent — where processing is based on consent, withdraw that consent at any time without affecting the lawfulness of processing carried out before withdrawal.
11.3 How to exercise your rights
To exercise any of these rights, please contact us at info.sec@xyberteq.com or by telephone at +603 2083 0133. We may need to verify your identity before responding, and we will respond within the timeframes required by applicable law. A prescribed fee may apply to certain PDPA data access requests to the extent permitted by law. Requests under the GDPR are generally handled free of charge.
12. Complaints
If you have any concern about how we handle your personal data, we encourage you to contact us first so that we can address it. You also have the right to lodge a complaint with the relevant authority:
- Malaysia: the Personal Data Protection Commissioner, through the Personal Data Protection Department (Jabatan Perlindungan Data Peribadi, JPDP), Ministry of Digital, Malaysia.
- EEA: your local data protection supervisory authority in the EU/EEA Member State of your residence, place of work or the place of the alleged infringement.
- United Kingdom: the Information Commissioner's Office (ICO).
13. Third-Party Websites
Our websites may contain links to third-party websites or services that we do not operate or control. This Privacy Notice does not apply to those third parties, and we are not responsible for their privacy practices. We encourage you to review the privacy notices of any third-party sites you visit.
14. Changes to This Privacy Notice
We may update this Privacy Notice from time to time to reflect changes in our practices, technologies, legal requirements or other factors — for example, if we introduce analytics or marketing cookies, or engage new service providers. When we make material changes, we will update the effective date below and, where appropriate, provide additional notice. We encourage you to review this notice periodically.
15. Contact Us
If you have any questions, requests or concerns regarding this Privacy Notice or our handling of your personal data, please contact:
- Data protection contact, Xyberteq Innovations Sdn Bhd
- Kuala Lumpur, Malaysia
- Email: info.sec@xyberteq.com
- Telephone: +603 2083 0133
Effective date: 16 July 2026
A Bahasa Malaysia version of this Privacy Notice is available at ms.xyberteq.com, in accordance with the requirement under the Malaysian Personal Data Protection Act 2010 to make a privacy notice available in both Bahasa Malaysia and English.