Legal

Privacy Policy

Last updated: August 2025 · Effective date: 1 August 2025

Plain language summary: Polar Packet is a data engineering firm. We collect only the business information necessary to deliver our services. We use Google Analytics (with IP anonymisation) to understand website usage. We do not sell your data. We implement enterprise-grade security because data protection is our core expertise. This policy explains exactly what we collect, why, and how you can exercise your rights under Malaysia's Personal Data Protection Act 2010 (PDPA).

1. Scope and Application

This Privacy Policy applies to all personal data processed by Polar Packet Sdn Bhd ("Company", "we", "us") in connection with:

  • Visits to our website (polarpacket.com)
  • Inquiries submitted through our contact forms
  • Service engagements governed by separate Statements of Work
  • Recruitment applications

Where a signed Statement of Work ("SOW") contains specific data processing terms, those terms prevail for that engagement. This policy governs all other processing activities.

2. Information We Collect

2.1 Information You Provide Directly

When you contact us or engage our services, we collect:

  • Business contact information: Name, job title, business email address, phone number, company name
  • Project information: Data infrastructure requirements, technical specifications, business objectives
  • Engagement data: Contract details, billing information, project deliverables
  • Recruitment data: Resume/CV, cover letter, interview notes (for job applicants only)

2.2 Information Collected Automatically

When you visit our website, we collect:

  • Technical data: IP address (anonymised), browser type and version, operating system, device type
  • Usage data: Pages visited, time spent, referring URL, click patterns, navigation paths
  • Cookies: Session cookies and analytics cookies (see Section 9)

We use Google Analytics to understand how visitors interact with our website. Google Analytics collects anonymised usage data including page views, session duration, traffic sources, and device information. IP addresses are anonymised before storage. We do not use advertising cookies, tracking pixels, or cross-site tracking technologies.

2.3 Information from Third Parties

We may receive your business contact information from:

  • Professional networking platforms (e.g., LinkedIn) when you connect with our team
  • Business partners who refer you to our services (with your consent)
  • Publicly available business directories

3. Legal Basis for Processing (PDPA Principles)

Under Malaysia's Personal Data Protection Act 2010, we process personal data based on the following legal grounds:

Processing Activity Legal Basis
Responding to inquiries and providing requested information Consent (your voluntary submission)
Delivering contracted data engineering services Performance of contract
Processing client data on your behalf during engagements Contractual obligation (as data processor)
Website analytics and improvement (Google Analytics) Legitimate interest (improving user experience)
Recruitment and hiring decisions Consent (application submission)
Compliance with legal obligations (tax, regulatory) Legal obligation

4. How We Use Your Information

We use personal data solely for the following purposes:

  • To respond to your inquiries and provide information about our services
  • To deliver data engineering, analytics, and AI/ML consulting services as contracted
  • To communicate about project status, deliverables, and invoices
  • To improve our website and service offerings based on usage patterns
  • To comply with legal, regulatory, and contractual obligations
  • To evaluate job applications and conduct recruitment processes
  • To protect against fraud, unauthorized access, and security threats

We do not: Sell personal data to third parties. Use personal data for automated decision-making or profiling. Process personal data for purposes incompatible with those stated above without your additional consent.

5. Data Sharing and Disclosure

We share personal data only in the following circumstances:

5.1 Service Providers (Data Processors)

We engage trusted third parties to support our operations. These processors act only on our instructions and are bound by confidentiality agreements:

  • Cloud infrastructure: Amazon Web Services (AWS), Microsoft Azure, Google Cloud Platform (GCP)
  • Data platforms: Snowflake, Databricks
  • Data integration: Fivetran, dbt, Apache Airflow
  • Analytics and BI: Looker, Domo
  • Website analytics: Google Analytics (Google LLC)
  • Communication: Email service providers, video conferencing platforms

All processors are contractually obligated to implement appropriate security measures and return or delete data upon engagement termination.

5.2 Legal and Regulatory Disclosure

We may disclose personal data when required by:

  • Court orders, subpoenas, or legal proceedings
  • Regulatory authorities (e.g., Department of Personal Data Protection Malaysia)
  • Law enforcement agencies in cases of suspected illegal activity

5.3 Business Transfers

In the event of a merger, acquisition, or sale of assets, personal data may be transferred to the acquiring entity. We will notify affected individuals via email or website notice prior to such transfer.

6. International Data Transfers

As a data engineering firm serving international clients, your data may be transferred to and processed in jurisdictions outside Malaysia, including:

  • United States: Where AWS, Azure, GCP, Snowflake, Databricks, and Google Analytics operate data centers
  • European Union: Where certain cloud providers maintain EU regions
  • Singapore: Regional hub for Southeast Asian operations

For international transfers, we ensure appropriate safeguards through:

  • Contractual clauses requiring equivalent data protection standards
  • Processor agreements compliant with PDPA requirements
  • Technical measures including encryption in transit and at rest

7. Data Security

Data security is our core competency. We implement enterprise-grade protections:

  • Encryption: AES-256 encryption at rest, TLS 1.3 encryption in transit
  • Access controls: Role-based access, multi-factor authentication, principle of least privilege
  • Network security: Firewalls, intrusion detection systems, regular vulnerability assessments
  • Operational security: Security training for all staff, incident response procedures, regular audits
  • Compliance frameworks: ISO 27001-aligned practices, SOC 2 Type II controls where applicable

Despite these measures, no method of transmission over the Internet or electronic storage is 100% secure. In the event of a data breach affecting your personal data, we will notify you within 72 hours of discovery as required by PDPA, and provide guidance on protective steps.

8. Data Retention

We retain personal data only as long as necessary:

Data Category Retention Period Basis
Website inquiry data 2 years from last contact Legitimate interest
Client engagement data Per SOW terms + 7 years Contractual + legal obligation
Recruitment applications (unsuccessful) 12 months Consent
Website analytics data (Google Analytics) 26 months Legitimate interest
Financial and tax records 7 years Legal obligation

Upon expiry of retention periods, we securely delete or anonymize personal data. You may request earlier deletion subject to legal obligations (see Section 10).

9. Cookies and Tracking Technologies

Our website uses only essential and analytics cookies:

9.1 Essential Cookies

Required for website functionality. These cannot be disabled:

  • Session management cookies (maintain your browsing session)
  • Security cookies (protect against CSRF attacks)
  • Load balancing cookies (distribute traffic across servers)

9.2 Analytics Cookies

We use Google Analytics 4 (GA4) to understand website usage and improve user experience. GA4 collects:

  • Page views and screen views
  • Session duration and engagement time
  • Traffic sources (referring sites, search queries, campaigns)
  • Device and browser information (type, OS, screen resolution)
  • Geographic data (country, city — derived from anonymised IP)
  • Event data (button clicks, form submissions, scroll depth)

IP anonymisation: We have enabled IP anonymisation in Google Analytics. Your full IP address is never written to disk — it is truncated before storage. Google cannot identify individual users by IP address.

Data retention: Google Analytics data is retained for 26 months, after which it is automatically deleted.

Your controls: You can disable Google Analytics cookies through your browser settings or by installing the Google Analytics Opt-out Browser Add-on. This will not affect website functionality.

For more information on how Google processes analytics data, see Google's Privacy Policy.

9.3 What We Do NOT Use

  • Advertising or marketing cookies (Google Ads, Facebook Pixel, etc.)
  • Social media tracking pixels
  • Cross-site tracking technologies
  • Fingerprinting techniques

10. Your Rights Under PDPA

Under Malaysia's Personal Data Protection Act 2010, you have the following rights regarding your personal data:

  • Right of Access: Request a copy of the personal data we hold about you. We will respond within 30 days.
  • Right to Correction: Request correction of inaccurate, incomplete, or misleading data.
  • Right to Withdraw Consent: Withdraw consent for data processing at any time (subject to contractual and legal obligations).
  • Right to Limit Processing: Request that we limit how we process your data in certain circumstances.
  • Right to Deletion: Request deletion of your personal data where no legal obligation requires retention.
  • Right to Data Portability: Request transfer of your data to another organization in a machine-readable format (where technically feasible).
  • Right to Object: Object to processing based on legitimate interests.

To exercise any of these rights, contact us at hi@polarpacket.com. We will respond within 30 days and may request verification of your identity.

You also have the right to lodge a complaint with the Department of Personal Data Protection Malaysia if you believe your rights have been violated.

11. Children's Privacy

Our services are directed to businesses and professionals. We do not knowingly collect personal data from individuals under 18 years of age. If you believe we have inadvertently collected such data, please contact us immediately for deletion.

12. Changes to This Policy

We may update this Privacy Policy to reflect changes in our practices, technology, legal requirements, or other factors. When we make material changes:

  • We will update the "Last updated" date at the top of this policy
  • For significant changes, we will notify you via email (if you are a current client) or post a prominent notice on our website
  • We will obtain your consent where required by law

We encourage you to review this policy periodically. Your continued use of our website or services after changes constitutes acceptance of the updated policy.

13. Contact Information

For privacy-related inquiries, data subject requests, or concerns about this policy:

Polar Packet Sdn Bhd

Address: Level U1, Block D2, D2-1-9, 1, Jln Dutamas 1, Solaris Dutamas, 50480 Kuala Lumpur, Wilayah Persekutuan Kuala Lumpur

Email: hi@polarpacket.com

Company registration: 202101044216 (1444516-V)

For questions about data processing in specific engagements, please contact your project lead or account manager directly.