Privacy Policy
We collect only the information needed to respond to you, deliver our services, operate our website, and meet our legal obligations.
This notice explains what personal data Axelyn collects, why we use it, who we may share it with, how long we keep it, and the choices available to you.
1. About This Notice
This Privacy Policy and Personal Data Protection Notice explains how Axelyn collects, uses, stores, discloses, transfers, and protects personal data.
It applies when you:
visit axelyn.com;
submit an enquiry or contact form;
communicate with Axelyn by email, messaging platform, telephone, or video call;
request a quotation, proposal, audit, consultation, or demonstration;
purchase or use an Axelyn service;
participate in a project;
provide files, documents, credentials, or system access;
subscribe to updates or marketing communications;
otherwise interact with Axelyn in a commercial or professional context.
In this notice, “Axelyn,” “we,” “us,” or “our” means Axelyn, Business Registration No. 202503264439 (PG0577243-P).
2. Our Role
Axelyn may process personal data in two different roles.
When Axelyn decides how data is used
Axelyn acts as the data controller when we collect and use information for our own business purposes. This includes website enquiries, project discussions, quotations, contracts, billing, client management, security, and business communications.
When Axelyn processes data for a client
Axelyn may act as a data processor when we handle personal data solely on behalf of a client while building, deploying, maintaining, or supporting a system.
In those situations, the client generally decides why and how the data is processed. Our processing will be governed by the Project Agreement, the client’s documented instructions, and any separate data-processing terms.
3. Personal Data We May Collect
The personal data we collect depends on how you interact with us.
Identity and contact information
This may include:
your name;
company or organisation;
job title or role;
email address;
telephone or messaging number;
business address;
social media or professional profile;
preferred communication method.
Enquiry and project information
This may include:
information submitted through our contact form;
project requirements;
business problems or operational needs;
requested services;
budget and timeline information;
meeting notes;
proposals, quotations, and approvals;
feedback and support requests;
communications between you and Axelyn.
Contract, payment, and administrative information
This may include:
billing details;
invoice information;
payment status;
transaction references;
contractual records;
company registration details;
tax-related information;
records required for accounting or legal purposes.
Axelyn does not normally receive or store complete payment-card information. Payments may be handled through banks or payment providers under their own privacy practices.
Technical and website information
When you visit our website or interact with our systems, we may receive:
IP address;
browser and device type;
operating system;
referring page;
pages visited;
approximate location derived from an IP address;
access date and time;
cookie or similar technology identifiers;
website performance, security, and error logs.
Project files and system information
During a project, you may provide:
documents;
spreadsheets;
images;
source code;
database samples;
application logs;
system configurations;
API information;
server details;
deployment information;
user requirements;
internal process information;
test data;
temporary access credentials.
We will only request information that is reasonably relevant to the agreed work.
4. Sensitive Personal Data
Axelyn does not normally need sensitive personal data such as health information, religious beliefs, political opinions, biometric information, or information concerning alleged or committed offences.
Please do not send sensitive personal data unless:
it is necessary for the project;
Axelyn has been informed in advance;
the handling requirements have been agreed in writing;
you have the authority and lawful basis to provide it.
Where sensitive personal data is required, additional security, access, retention, and processing conditions may be included in the Project Agreement.
5. Information About Other People
You may sometimes provide personal data relating to employees, customers, contractors, users, or other individuals.
When you provide another person’s personal data, you confirm that you:
have the authority or lawful basis to provide it;
have given any required notice to that person;
have obtained any required consent;
have not provided more information than is reasonably necessary.
6. How We Collect Personal Data
We may collect personal data:
directly from you;
through our website or contact form;
through email, telephone, messaging platforms, or meetings;
through proposals, quotations, invoices, or contracts;
while providing or supporting a service;
from a colleague or representative within your organisation;
from a referral partner or professional contact;
from public business sources, websites, or professional profiles;
automatically through website, hosting, security, or system logs;
from service providers used to operate our website and business.
Where practical, we will inform you when personal data is obtained from another source.
7. Why We Process Personal Data
We may process personal data to:
respond to enquiries;
understand your requirements;
arrange meetings or consultations;
prepare quotations, proposals, audits, or recommendations;
assess whether Axelyn is suitable for a project;
enter into and perform a contract;
plan, build, customise, deploy, host, support, or maintain software;
manage project communication and approvals;
provide technical support;
verify, diagnose, and resolve system problems;
manage invoices, payments, and accounting records;
maintain business and contractual records;
protect our website, infrastructure, clients, and systems;
prevent misuse, unauthorised access, fraud, or security incidents;
improve our services, internal processes, and website;
manage professional relationships;
send relevant service updates or marketing communications where permitted;
respond to legal claims, disputes, regulatory requests, or lawful authorities;
comply with applicable legal and regulatory obligations.
Depending on the circumstances, processing may be necessary to respond to a request, prepare or perform a contract, comply with a legal obligation, protect legitimate business and security interests, or act with your consent.
8. Required and Optional Information
Some personal data is required for Axelyn to respond to you or deliver a service.
For example, we normally require:
your name;
a working contact method;
enough project information to understand your request;
billing details when purchasing a service;
access or technical information needed to complete agreed work.
Where required information is not supplied, we may be unable to:
respond to your enquiry;
prepare an accurate quotation;
enter into a contract;
complete the project;
provide support;
meet legal or accounting obligations.
Information marked as optional may be omitted without preventing you from submitting an enquiry.
9. Client Project Data
A project may require Axelyn to access data stored inside a client’s application, server, database, document collection, or internal system.
We will process that data only:
for the agreed project purpose;
within the agreed scope;
according to the client’s instructions;
using access reasonably necessary to perform the work;
subject to applicable confidentiality and security obligations.
The client remains responsible for ensuring that its collection and use of personal data is lawful and that affected individuals have received appropriate notices.
Where appropriate, the parties may agree to:
data-processing terms;
permitted processing instructions;
access restrictions;
approved service providers;
hosting locations;
retention and deletion requirements;
incident-response procedures;
security measures;
confidentiality obligations.
10. AI-Assisted Processing
Some Axelyn projects may involve artificial intelligence, language models, document retrieval, automated classification, summarisation, recommendation, or generated output.
When personal data is processed through an AI-assisted system, the relevant Project Agreement may specify:
what data is used;
the purpose of the processing;
which AI or infrastructure providers are involved;
where the data may be processed;
whether data is retained by a provider;
who may access the results;
what human review is required;
when the data will be deleted.
Axelyn will not intentionally use confidential client data to train Axelyn-owned or third-party general-purpose AI models unless the client has expressly agreed in writing.
AI-generated results may be inaccurate or incomplete. Important decisions should be reviewed by an appropriate person rather than being made solely from automated output.
11. Who We May Disclose Personal Data To
We do not sell personal data.
We may disclose personal data where reasonably necessary to the following classes of recipients:
Technology and operational providers
These may include providers of:
website hosting;
cloud infrastructure;
domain and DNS services;
email;
file storage;
project management;
communications;
databases;
analytics;
security;
monitoring;
backups;
AI or API services.
Professional and administrative providers
These may include:
accountants;
auditors;
legal advisers;
insurers;
banks;
payment providers;
business consultants.
Project collaborators
We may disclose limited information to employees, contractors, developers, designers, technical specialists, or delivery partners involved in an agreed project.
They will receive only the access reasonably required for their role and will be subject to appropriate confidentiality or contractual obligations.
Authorities and other parties
We may disclose information:
when required by law;
in response to a valid court, regulatory, or governmental request;
to investigate fraud, misuse, or security incidents;
to establish, exercise, or defend legal rights;
during a business restructuring, transfer, merger, or sale, subject to appropriate confidentiality protections;
with your instructions or consent.
12. International and Cross-Border Processing
Some technology providers, cloud services, communication tools, or project collaborators may process personal data outside Malaysia.
Where personal data is transferred internationally, Axelyn will take reasonable steps to ensure that the transfer is permitted under applicable Malaysian law and that the recipient provides appropriate protection.
These steps may include:
reviewing the recipient and processing location;
limiting the personal data transferred;
applying contractual confidentiality and security obligations;
using access controls and encryption where appropriate;
selecting providers with suitable data-protection practices;
obtaining consent where required;
maintaining relevant transfer records.
Malaysia’s current cross-border guidance also requires data controllers to inform individuals about intended transfers and to take practical steps to protect transferred data.
13. Cookies and Website Technologies
Our website may use cookies, local storage, logs, or similar technologies.
These technologies may be used to:
keep the website functioning;
maintain security;
remember basic preferences;
understand website performance;
identify technical errors;
measure general website usage.
Essential technologies may operate because they are necessary for the website to function securely.
Where Axelyn uses non-essential analytics or marketing technologies, we will provide appropriate information and choices where required.
You may be able to control cookies through your browser settings. Blocking certain technologies may affect how parts of the website function.
14. Marketing Communications
Axelyn may send service updates, articles, invitations, or relevant business communications where permitted.
You may opt out of marketing communications at any time by:
using an unsubscribe option, where available;
replying to the message;
contacting Axelyn using the details below.
Opting out of marketing does not prevent us from sending communications that are necessary for an active enquiry, contract, project, invoice, security matter, or service update.
15. Security Measures
Axelyn takes reasonable technical and organisational measures to protect personal data against loss, misuse, unauthorised access, disclosure, alteration, or destruction.
Depending on the system and project, measures may include:
restricted access;
individual user accounts;
strong authentication;
encrypted connections;
secure credential handling;
firewall and network controls;
access logging;
software updates;
backups;
confidentiality obligations;
vendor assessment;
data minimisation;
removal of access after project completion.
No internet-connected system can be guaranteed to be completely secure. You are also responsible for protecting passwords, access keys, devices, and accounts under your control.
16. Personal Data Retention
Axelyn keeps personal data only for as long as it is reasonably needed for the purpose for which it was collected, or as required for legal, accounting, contractual, security, or dispute-resolution purposes.
Our typical retention approach is:
Enquiries and unsuccessful proposals: up to 24 months after the last meaningful communication.
Client and project records: generally up to seven years after project completion or termination.
Invoices and payment records: generally up to seven years or any longer period required by law.
Temporary credentials: only for as long as needed to perform the agreed work, followed by return, rotation, revocation, or secure deletion.
Technical and security logs: based on operational and security needs, generally no longer than 12 months unless an incident or legal reason requires longer retention.
Marketing information: until you unsubscribe, withdraw consent, or the information is no longer needed.
When personal data is no longer required, we will take reasonable steps to delete it, destroy it, anonymise it, or remove access to it.
17. Your Rights and Choices
Subject to applicable law and permitted exceptions, you may request to:
access personal data held about you;
correct inaccurate, incomplete, misleading, or outdated information;
withdraw consent where processing depends on consent;
limit certain processing;
object to or stop direct marketing;
request deletion where the information is no longer required;
request information about how your data is used or disclosed;
request data portability where applicable under Malaysian law;
make a complaint about our handling of personal data.
We may need to verify your identity before completing a request.
Some requests may be restricted where retention or processing is required by law, contract, security obligations, legal claims, or the rights of another person.
Withdrawing consent does not affect processing that occurred before the withdrawal. It may also prevent Axelyn from continuing a service where the relevant data is necessary for that service.
18. Personal Data Breaches
If Axelyn becomes aware of a personal data breach, we will take reasonable steps to:
contain and investigate the incident;
assess the data and individuals affected;
reduce the risk of further harm;
preserve relevant records;
notify affected clients;
notify the Personal Data Protection Commissioner or affected individuals where required by law.
Malaysia’s Personal Data Protection Commissioner has issued guidelines covering notification to the Commissioner and affected data subjects.
19. Children’s Personal Data
Axelyn’s website and general services are not directed at children under 18.
We do not intentionally collect children’s personal data through the website. A person under 18 should not submit personal data without the involvement of a parent or legal guardian.
Where a client project involves children’s data, the collection and processing requirements must be specifically assessed and agreed before the data is provided to Axelyn.
20. External Websites and Services
Our website may link to external websites, products, or services.
Axelyn does not control how those external parties collect or use personal data. Their own privacy notices and terms apply when you interact with them.
21. Changes to This Notice
We may update this notice when:
our services change;
our data-handling practices change;
we introduce new providers or technologies;
legal or regulatory requirements change.
The current version will be published on this page with an updated revision date.
Where a change materially affects how existing personal data is used, we will provide additional notice or obtain consent where required.
22. Contact and Privacy Requests
Questions, access requests, correction requests, withdrawals, complaints, or other privacy enquiries may be sent to:
Axelyn
Business Registration No. 202503264439 (PG0577243-P)
Privacy contact: Founder, Axelyn
Email: aminh@axelyn.com
Website: axelyn.com
Contact
Whether it’s a new app, a ready-made system, or an existing platform that needs help, send us a short message. We’ll help you figure out the clearest next step.