- Introduction
- This Data Processing Agreement (DPA) is an addendum to the Terms of Service (TOS) and applies when Net Onboard Sdn Bhd processes personal data on behalf of its customers.
- This DPA ensures compliance with:
- Malaysia’s Personal Data Protection Act (PDPA) 2010
- General Data Protection Regulation (GDPR) (for EU users, if applicable)
- Other relevant data protection laws
- By using our services, you agree to this DPA, which defines the rights, responsibilities, and obligations related to data processing.
- Definitions
- “Data Controller” – The customer who determines how and why personal data is processed.
- “Data Processor” – Net Onboard Sdn Bhd, which processes data on behalf of the Data Controller.
- “Personal Data” – Any information related to an identifiable individual.
- “Processing” – Any operation performed on personal data, such as collection, storage, transfer, or deletion.
- Processing of Personal Data
- Purpose of Processing:
- Net Onboard processes personal data solely to provide cloud computing and IT services.
- Types of Data Processed:
- User Information: Name, email, contact details, and business information.
- Service Data: Logs, configurations, and usage analytics.
- Billing Information: Payment records, transaction history.
- Legal Basis for Processing:
- Contractual necessity – Required to deliver services.
- Legal compliance – To meet regulatory obligations.
- Legitimate interests – To enhance security and user experience.
- Purpose of Processing:
- Data Security Measures
- Net Onboard implements strict security controls to protect data, including:
- AES-256 encryption for data storage & transmission.
- Multi-Factor Authentication (MFA) for account security.
- ISO 27001-certified security framework for cloud infrastructure.
- Regular security audits, penetration testing & compliance checks.
- Data Access Control:
- Only authorized personnel have access to personal data.
- Access is restricted based on role-based permissions.
- Net Onboard implements strict security controls to protect data, including:
- Data Retention & Deletion
- Personal data is retained only as long as necessary for legal, regulatory, and operational requirements.
- Standard retention periods:
- Account Information – Retained for the duration of the contract + five (5) years after termination.
- Billing & Transaction Data – Retained for seven (7) years for financial compliance.
- Users may request data deletion upon account termination by contacting [email protected].
- Data Transfers & Data Sovereignty
- Data is stored within Malaysia, unless an international transfer is necessary for service fulfillment.
- For cross-border transfers, we:
- Ensure GDPR-standard protection measures for EU-based users.
- Use legally binding contracts and industry-approved security mechanisms.
- Subprocessors
- Net Onboard engages third-party vendors (e.g., cloud storage providers, analytics platforms, payment processors) under strict Data Processing Agreements (DPA).
- A list of approved subprocessors is available upon request.
- Data Breach Notification
- In case of a personal data breach, Net Onboard will:
- Assess the impact and take immediate action.
- Notify affected customers and authorities within 72 hours, as required by PDPA & GDPR.
- Provide remediation steps and security enhancements.
- In case of a personal data breach, Net Onboard will:
- Customer Rights & Obligations
- Customers have the right to:
- Access, correct, or delete their personal data.
- Withdraw consent for non-essential data processing.
- Request data portability in a structured, digital format.
- Customers must:
- Ensure compliance with applicable data protection laws.
- Not use Net Onboard’s services for unauthorized or illegal data processing.
- Customers have the right to:
- Governing Law & Dispute Resolution
- This DPA is governed by Malaysian law.
- Disputes will be handled through negotiation and mediation before proceeding to arbitration or litigation.
- Amendments & Updates
- Net Onboard reserves the right to update this DPA at any time.
- Users will be notified of material changes via email or system notifications.
For data protection inquiries, contact [email protected].