Definitions
The terms below clarify how we use common privacy-related words in this policy. Definitions are accompanied by short examples from real AppMBuild projects to show what each term means in practice.
- Personal data means information that identifies or can reasonably be used to identify an individual, for example a contact name on an invoice, an employee email in a timesheet, or a phone number submitted through a support form.
- Processing refers to any operation performed on personal data, including collection, storage, analysis, transfer, anonymization, and deletion. For instance, transforming raw GPS traces collected by a field app into daily route summaries is processing.
- User means any person who interacts with AppMBuild services or client systems built by AppMBuild, including corporate users, administrators, and end customers of our clients.
- Service refers to the custom software, integrations, APIs, mobile applications, and support services that AppMBuild designs and operates for clients across Malaysia and the region.
- Cookies are small text files stored by a browser or device to remember preferences or track sessions, such as an authentication voucher for a client portal or an analytics cookie that records page visits.
Information we collect
We collect data directly from users, automatically through system logs and cookies, and sometimes from third parties such as payment processors or analytics providers. Below are specific categories and practical examples tied to typical project scenarios.
Data you provide directly
These are data elements users enter in forms, during onboarding, or via direct communications with our team during a project deployment.
- Contact and identity details: full name, business email, job title, company name used while registering for a client portal or support ticket.
- Account and billing information: billing address, purchase orders, and invoicing contact details supplied when activating paid services.
- Project content: configuration files, sample datasets, and business rules uploaded to design and test integrations.
- Support communications: messages, screenshots, and logs sent to our technical team to diagnose issues.
- Device-provided information given by mobile apps: location coordinates when explicitly enabled by the user for service functionality.
- Consents and preferences: marketing preferences and agreement choices recorded during onboarding.
Data collected automatically
Systems supporting our services collect technical and usage data to operate, secure, and improve software. The following list outlines common automated data types and how they are used in practice.
- Usage data such as pages accessed, API endpoints called, and feature usage metrics collected to prioritize product improvements.
- Technical data like IP addresses, device type, browser version, and operating system used for troubleshooting and security monitoring.
- Performance logs and error reports that help our engineers reproduce and fix defects in a controlled environment.
- Authentication and session vouchers necessary to maintain secure sessions for client portals and admin consoles.
- Analytics events collected through third-party analytics providers to understand workflows and reduce friction in enterprise applications.
- Crash reports from mobile applications that include stack traces and limited runtime context for resolving stability issues.
Data from third parties
In certain projects AppMBuild receives data from external providers or from our clients' existing systems. Example sources and contexts are listed below.
- Payment processors providing transaction confirmations and partial payer details necessary to reconcile invoices.
- Identity providers (single sign-on) that share verified user attributes for access control in client applications.
- Cloud-hosting platforms that supply monitoring metrics and alerts to maintain service uptime.
Why we collect data
We use collected data for discrete operational purposes. Each purpose includes an example scenario so businesses can assess relevance to their own deployments.
- Service delivery: creating, maintaining, and operating custom software solutions such as ERP connectors and mobile field apps.
- Account management: handling onboarding, billing, and subscription changes when clients sign or update agreements.
- Support and troubleshooting: diagnosing and resolving incidents reported by users, using support logs and error reports.
- Security and fraud prevention: detecting unauthorized access and responding to suspicious activity in client systems.
- Product improvement and research: analyzing anonymized usage patterns to refine feature prioritization and performance.
- Legal compliance: retaining records and responding to lawful requests from authorities under applicable law.
- Client-specific integrations: exchanging data with third-party systems when implementing connectors or APIs as requested by a client.
- Communication: sending operational messages about system status, scheduled maintenance, and important service notices.
Legal bases for processing
When applicable data protection rules require a legal basis for processing, the following describe common bases we rely on with practical project examples.
- Performance of a contract: processing necessary to deliver agreed development services, such as deploying a client portal or API integration.
- Consent: where explicit consent is obtained, for example when enabling optional analytics or marketing communications.
- Legal obligation: processing required to comply with applicable laws, such as tax record retention for billing.
- Legitimate interests: processing to secure systems, prevent fraud, and manage business operations, balanced against user rights and expectations.
User rights (GDPR-style overview)
Although AppMBuild is based in Malaysia, we provide this section to summarize user rights commonly recognized in international privacy frameworks and to explain practical steps for exercising those rights.
- Right of access: you may request a copy of personal data we hold about you and an explanation of how it is used.
- Right to rectification: if your data is incomplete or inaccurate, you can request corrections.
- Right to erasure: in certain circumstances you can request deletion of your personal data, subject to legal and contractual retention needs.
- Right to restrict processing: you can request limitation of processing while a dispute is resolved or while we verify a request.
- Right to object: where processing is based on legitimate interests or for direct marketing, you may object and we will review the request.
- Right to data portability: where technically feasible we can provide structured, machine-readable copies of personal data you provided.
Cookies and tracking
Our services use cookies and similar technologies to support authentication, remember preferences, and gather analytics. The descriptions below explain common cookie types and how they are used in project contexts.
Cookie types include session cookies for logged-in access, persistent cookies to remember preferences, and third-party cookies used by analytics or payment providers during integrations.
We classify cookies as strictly necessary (authentication), performance/analytics (usage metrics), and functional (UI preferences). Marketing cookies are used only with explicit consent.
Users can manage cookie preferences via their browser settings, mobile app permissions, or a cookie consent tool displayed in client-facing portals. Disabling non-essential cookies may limit certain features.
Cookie details and settings
Sharing and disclosure
AppMBuild discloses personal data only as needed for service delivery and legal compliance. Typical recipients and purposes are outlined below with real-world integration scenarios.
- Service providers and subcontractors: hosting providers, CI/CD systems, and analytics vendors engaged to operate and monitor client solutions.
- Affiliates and partners: where a client project requires joint delivery with a local systems integrator or reseller.
- Professional advisors: auditors, lawyers, and accountants when their involvement is necessary for lawful business operations.
- Purchasers and acquirers: in a business transfer or sale where data is part of transferred assets, handled under confidentiality terms.
- Law enforcement and regulators: when required by lawful demands, subpoenas, or to protect legal rights.
- Client-authorized third parties: external systems or APIs integrated at a client's direction, e.g., a third-party CRM receiving lead data via an agreed connector.
International transfers
AppMBuild may transfer personal data between Malaysia and other jurisdictions to deliver cloud hosting, analytics, or development support. Transfers are limited to necessary recipients and structured to align with legal requirements and contractual safeguards.
Where transfers occur we use contractual data processing agreements, standard contractual clauses when appropriate, encryption in transit and at rest, and access restrictions to protect data during cross-border processing.
Data retention
Retention periods are based on the purpose of data collection, legal requirements, and operational needs. Below are examples indicative of typical project settings.
Account records and billing data are normally retained for a minimum of seven years to satisfy business and tax obligations, unless a client requests earlier deletion and legal requirements permit it.
Support messages and project correspondence are retained for a practical period (commonly 2–5 years) to retain operational context for ongoing maintenance, unless a deletion request is valid and applicable.
Operational logs and telemetry used for troubleshooting are kept for limited periods (often 30–90 days) unless required for security incident contribute, in which case relevant logs may be retained longer under controlled access.
When data is no longer required for operational or legal reasons, AppMBuild follows documented deletion procedures that remove data from production systems and backups in a phased manner consistent with industry practices.
Security measures
Security is integrated into project delivery and operation. AppMBuild applies technical and organizational measures that match the risk profile of each engagement and follow established practices for protecting data throughout its lifecycle.
- Encryption: data encrypted in transit (TLS) and at rest for client-hosted databases and storage used in production deployments.
- Access controls and role-based permissions to limit who can view or change personal data during development and in production.
- Operational controls including incident response plans, periodic security reviews, logging, and vulnerability scanning tied to sprint cycles and release cadences.
Your rights
If you are a data subject with rights under applicable law, AppMBuild describes below practical examples and steps to exercise those rights. Requests are assessed in context of contractual obligations and legal requirements.
- Access: request a copy of personal data we hold about you and details of processing purposes.
- Rectification: ask us to correct inaccurate or incomplete personal data.
- Erasure: request deletion when retention is no longer necessary and no legal grounds require continued storage.
- Restriction: request limitation of processing while accuracy or lawfulness is verified.
- Objection: object to processing based on legitimate interests or for direct marketing.
- Portability: request a machine-readable copy of personal data you provided, when technically feasible.
- Withdraw consent: withdraw any consent previously given for optional processing such as marketing.
- Complain to a regulator: you may lodge a complaint with an appropriate data protection authority if you believe your rights have been infringed.
How to submit rights requests
To exercise your rights, contact AppMBuild at [email protected] or by postal mail to our address. Please include your name, contact details, a clear description of the request, and any supporting documents to verify your identity. For client projects, requests may be routed via the contractually designated data controller.
[email protected]
We aim to respond to rights requests promptly. Typical response windows are aligned with industry norms and legal requirements; complex requests may require additional verification or coordination with clients or third parties before a substantive response is provided.
Marketing communications
We may send email updates about product improvements, case studies, and events to contacts who opted in during engagement or through our website. Communications are tailored to business audiences and include practical examples and lessons from recent projects.
Every marketing message includes an unsubscribe link. You can also change your communication preferences by contacting [email protected]. Opting out will stop marketing emails but will not affect service-related communications.
Children's privacy
Our services are designed for business use and are not directed to children under the age of 13. We do not knowingly collect personal data from children; if a parent or guardian believes we have such data, they should contact [email protected] to request deletion or correction.
Third-party links
Client applications built by AppMBuild may include links to third-party sites or integrate third-party services. We do not control third-party privacy practices; users should review each third party's privacy policy before providing personal data.
Policy changes
This policy may be updated to reflect changes in our services or legal requirements. Material changes will be posted on AppMBuild.digital and, where appropriate, communicated to clients and registered contacts. The effective date at the top indicates the latest revision.