Privacy Policy
PRIVACY POLICY for CARBON NEXT SDN. BHD.
1. Introduction
Carbon Next Sdn. Bhd. (“we,” “us,” or “our”) is committed to protecting the privacy and security of your personal data. This Privacy Policy (the “Policy”) explains how we collect, use, disclose, and safeguard your information when you use our cloud-based carbon accounting software (the “Service”). By accessing or using the Service, you agree to the terms of this Policy.
2. Data Collection
2.1 Types of Data Collected
- We may collect and process the following types of personal data:
Contact Information: Includes but is not limited to your name, email address, phone number, and mailing address.
Company Information: Includes but is not limited to your company name, industry, size, and address.
Usage Data: Includes but is not limited to information about how you interact with our Service, such as log data, usage statistics, and activity logs.
Financial Information: Includes but is not limited to payment details, billing address, and transaction records.
Technical Data: Includes but is not limited to IP address, browser type, operating system, and device information.
2.2 Methods of Data Collection
- We collect data through various methods, including:
Directly from You: Information you provide directly through forms, registrations, and communications with us.
Automated Technologies: Information collected automatically through the use of cookies, web beacons, and similar tracking technologies.
Third-Party Sources: Information received from third-party sources, such as social media platforms and partners, where applicable and legally permissible.
3. Data Usage
3.1 Purposes of Data Usage
- We use your personal data for the following purposes:
Service Delivery: To provide, operate, and maintain our Service, including processing transactions, managing accounts, and providing customer support.
Improvement and Personalization: To understand user behavior and preferences, improve our Service, and provide personalized content and features.
Communication: To send updates, newsletters, marketing materials, and respond to your inquiries and support requests.
Legal Compliance: To comply with legal obligations, enforce our terms and conditions, protect our rights and interests, and resolve disputes.
Security: To protect our Service, detect and prevent fraud, and ensure the security and integrity of your data.
3.2 Legal Basis for Processing
- We process your personal data based on the following legal grounds:
Consent: Where you have provided explicit consent for specific purposes.
Contractual Necessity: Where processing is necessary for the performance of a contract with you or to take steps at your request before entering into a contract.
Legal Obligation: Where processing is necessary to comply with legal obligations.
Legitimate Interests: Where processing is necessary for our legitimate interests, provided that such interests are not overridden by your rights and interests.
4. Data Storage and Security
4.1 Security Measures
- We implement a variety of security measures to maintain the safety and confidentiality of your personal
data, including: Encryption: Encryption of data during storage and transmission to protect against unauthorized access.
Access Controls: Restricted access to personal data to authorized personnel only, based on a need-toknow basis.
Regular Audits: Regular security audits and vulnerability assessments to identify and mitigate risks.
Data Minimization: Collection and retention of only the minimum amount of data necessary for the specified purposes.
4.2 Data Retention
- We retain your personal data only for as long as necessary to fulfill the purposes outlined in this Policy, or as required by law. The retention period is determined based on the following criteria:
The duration of your use of our Service and your relationship with us.
The necessity of retaining data for legal or regulatory purposes.
The necessity of retaining data for dispute resolution or to protect our legal rights.
5. Data Sharing and Disclosure
5.1 Sharing with Third Parties
- We may share your personal data with the following categories of third parties:
Service Providers: Third-party vendors who assist us in operating our Service, such as hosting providers, payment processors, and analytics services. These service providers are bound by contractual obligations to protect your personal data and use it only for the specified purposes.
Business Partners: In connection with business collaborations and partnerships, where applicable and legally permissible.
Legal Authorities: Government authorities, regulators, and law enforcement agencies when required by law or to protect our legal rights.
Business Transfers: In the event of a merger, acquisition, or sale of assets, your data may be transferred to the new owner, subject to the same protections outlined in this Policy.
5.2 Conditions for Data Disclosure
- We may disclose your personal data under the following circumstances:
To comply with legal obligations, such as responding to subpoenas, court orders, or legal processes.
To protect the rights, property, or safety of Carbon Next Sdn. Bhd., our users, or the public.
To enforce our terms and conditions or other contractual agreements.
With your explicit consent, for other purposes not covered by this Policy.
6. User Rights
6.1 Access and Correction
- You have the right to request access to your personal data and to correct any inaccuracies. To exercise these rights, please contact us at +6011-16261920 or email us at [email protected].
6.2 Deletion and Objection
- You have the right to request the deletion of your personal data, subject to legal and contractual restrictions. You also have the right to object to the processing of your data in certain circumstances. To exercise these rights, please contact us at +6011-16261920 or email us at [email protected].
6.3 Restriction and Portability
- You have the right to request the restriction of processing your data and to receive a copy of your data in a structured, commonly used, and machine-readable format. To exercise these rights, please contact us at +6011-16261920 or email us at [email protected].
6.4 Withdrawal of Consent
- You have the right to withdraw your consent at any time, without affecting the lawfulness of processing based on consent before its withdrawal. To exercise this right, please contact us at +6011-16261920 or email us at [email protected].
7. Cookies and Tracking Technologies
7.1 Use of Cookies
- We use cookies and similar tracking technologies to:
Enhance User Experience: Remember your preferences and settings.
Analyze Usage: Understand how you use our Service and improve functionality.
Targeted Advertising: Provide personalized advertisements based on your browsing activities.
7.2 Managing Cookies
- You can manage your cookie preferences through your browser settings. Most browsers allow you to refuse cookies or to alert you when cookies are being sent. However, if you disable cookies, some features of our Service may not function properly.
8. International Data Transfers
8.1 Data Transfers Outside Malaysia
- If we transfer your personal data outside Malaysia, we ensure that it is protected by appropriate safeguards, in accordance with the Personal Data Protection Act (PDPA) 2010 requirements. These safeguards may include:
Standard Contractual Clauses: Agreements that include data protection obligations.
Privacy Shield Frameworks: Compliance with recognized data protection frameworks, where applicable.
Binding Corporate Rules: Internal policies ensuring data protection across the organization.
8.2 Adequacy Decisions
- Where applicable, we will rely on adequacy decisions issued by the relevant authorities to ensure that the level of data protection in the recipient country is equivalent to that in Malaysia.
9. Compliance with Laws and Regulations
9.1 Personal Data Protection Act (PDPA) 2010
- We comply with the Malaysian Personal Data Protection Act (PDPA) 2010, which governs the collection, use, and disclosure of personal data in commercial transactions. Our practices are designed to ensure:
Transparency: Providing clear information about data processing activities.
Consent: Obtaining explicit consent for data collection and processing, where required.
Data Minimization: Collecting only the data necessary for specified purposes.
Security: Implementing appropriate security measures to protect personal data.
Accountability: Ensuring that our data protection practices are regularly reviewed and updated.
9.2 Communications and Multimedia Act 1998
- We adhere to the provisions of the Communications and Multimedia Act 1998, regulated by the Malaysian Communications and Multimedia Commission (MCMC), which includes data protection standards for the communications and multimedia industry.
10. Third-Party Links
Our Service may contain links to third-party websites. We are not responsible for the privacy practices or content of these websites. We encourage you to review the privacy policies of any third-party sites you visit.
11. Children’s Privacy
Our Service is not intended for children under the age of 13. We do not knowingly collect personal data from children under 13. If we become aware that we have collected personal data from a child under 13, we will take steps to delete such information promptly.
12. Contact Information
For any questions, concerns, or requests regarding your privacy, please contact us at:
Carbon Next Sdn. Bhd.
Address: A3-1-32, OUG PARKLANE, JALAN 1/152, TAMAN OUG PARKLANE,
JALAN PUCHONG, 58200 KUALA LUMPUR W.P. KUALA LUMPUR
MALAYSIA.
Email: [email protected].
Phone: +6011-16261920
13. Policy Updates
We may update this Privacy Policy from time to time to reflect changes in our practices or for legal, operational, or regulatory reasons. We will notify you of any significant changes by posting the new policy on our website and indicating the effective date. Your continued use of our Service after any changes constitutes your acceptance of the updated Privacy Policy.
14. Governing Law and Dispute Resolution
This Privacy Policy shall be governed by and construed in accordance with the laws of Malaysia. Any disputes arising out of or in connection with this Policy shall be resolved through negotiation in good faith. If a resolution cannot be reached, the dispute shall be submitted to the exclusive jurisdiction of the courts of Malaysia.