Privacy Policy
Last Updated: 12 March 2025 · Effective: 12 March 2025
Cerebo is committed to handling personal information with care and transparency. This policy explains what data we collect, why we collect it, how it is used, and the choices available to you. It applies to all visitors and clients who interact with our website or services.
Contents
1. Data Controller Information
The data controller responsible for your personal information is:
Cerebo
7 Jalan Taman Seputeh, 58000 Kuala Lumpur, Malaysia
Phone: +60 3-4582 7163
Email: [email protected]
Cerebo operates in accordance with the Personal Data Protection Act 2010 (PDPA) of Malaysia, which governs the collection and processing of personal data in commercial transactions.
2. Data We Collect
Information You Provide Directly
- Full name and contact name when submitting our enquiry form
- Business or personal email address
- Phone number (optional, if provided)
- Message content and service-related details shared with us
Information Collected Automatically
- IP address and general geographic location (country/city level)
- Browser type, operating system, and device information
- Pages visited, session duration, and referral sources
- Cookie identifiers and analytics data (see Section 7)
Data Retention
Enquiry data is retained for up to 24 months from the date of last contact. Analytics data is retained for up to 14 months. After these periods, data is either deleted or anonymised. You may request earlier deletion at any time (see Section 8).
Third-Party Services
- Google Analytics — website traffic analysis
- Google Maps — location display on our website
- Meta (Facebook) Pixel — optional advertising measurement
3. Legal Basis for Processing
Under the PDPA 2010 and applicable data protection principles, we process your personal data on the following bases:
- Consent — when you voluntarily submit the contact form or accept optional cookies, you consent to the associated processing activities.
- Contractual necessity — when data processing is required to deliver a service you have engaged us for.
- Legitimate interests — for analytics and service improvement purposes, where these do not override your rights and freedoms.
- Legal obligation — where we are required to retain or disclose data to comply with Malaysian law or a lawful authority request.
4. How We Use Your Data
- To respond to enquiries and provide information about our cybersecurity services
- To prepare and deliver service engagements including AI threat monitoring, vulnerability assessments, and advisory work
- To send relevant communications about your project or service status
- To understand how our website is used and improve content and functionality
- To comply with applicable Malaysian regulations and legal obligations
Marketing: We do not send unsolicited marketing emails. If you would like to receive updates from Cerebo, you may opt in when contacting us. You can opt out at any time by replying to any email or writing to [email protected].
5. Data Sharing
We do not sell or trade personal information. Data may be shared only in these circumstances:
- Service providers — third parties who assist in operating our website or delivering services (e.g., hosting, analytics), bound by confidentiality and data processing agreements.
- Legal requirements — when disclosure is required by Malaysian law, court order, or a lawful request from a public authority.
- Business transfers — in the event of a merger, acquisition, or asset sale, affected parties will be notified.
All third-party processors are required to handle data in a manner consistent with this policy and applicable data protection law.
6. Data Protection Measures
- Encryption — data transmitted to and from our website is protected by TLS/SSL encryption.
- Access controls — personal data is accessible only to authorised team members who need it to perform their duties.
- Secure storage — data is stored on access-controlled servers with regular security reviews.
- Incident response — in the event of a data breach affecting your rights, we will notify you and the relevant authority within the timeframe required by applicable law.
- Periodic reviews — our data handling practices and technical safeguards are reviewed regularly.
Given the nature of our work in cybersecurity, we take data protection seriously and apply the same diligence to our own data practices that we recommend to clients.
8. Your Rights
Under the PDPA 2010 and applicable data protection principles, you have the following rights regarding your personal data:
- Right of access — request a copy of the personal data we hold about you.
- Right to correction — request that inaccurate or incomplete data be corrected.
- Right to erasure — request deletion of your data where it is no longer necessary or you withdraw consent.
- Right to object — object to processing carried out on the basis of legitimate interests.
- Right to withdraw consent — withdraw consent at any time where processing is consent-based, without affecting prior processing.
- Right to data portability — receive a copy of your data in a structured, machine-readable format where technically feasible.
- Right to lodge a complaint — if you believe your data has been mishandled, you may lodge a complaint with the Department of Personal Data Protection Malaysia (JPDP).
To exercise any of these rights, contact us at [email protected]. We aim to respond within 21 days.
9. Children's Privacy
Our services are intended for organisations and professionals aged 18 and above. We do not knowingly collect personal data from individuals under 18. If we become aware that data from a minor has been submitted, it will be deleted promptly. If you believe a minor has provided data through our site, please contact us at [email protected].
10. Third-Party Links
Our website may include links to external sites, including resources on cybersecurity topics or partner organisations. We are not responsible for the privacy practices of those sites and encourage you to review their privacy policies before sharing any personal information.
11. International Data Transfers
Some of the third-party services we use (such as analytics providers) may process data outside Malaysia. Where such transfers occur, we take reasonable steps to ensure that appropriate safeguards are in place, consistent with the requirements of the PDPA 2010 and any applicable international data transfer standards.
12. Policy Updates
We may update this Privacy Policy periodically to reflect changes in our practices, services, or legal requirements. When material changes are made, we will update the "Last Updated" date at the top of this page. Where appropriate, we may also notify you directly.
Continued use of our website following any update constitutes acceptance of the revised policy.
13. Contact for Privacy Queries
For any questions, requests, or concerns about this Privacy Policy or how Cerebo handles personal data, please reach out to us:
Cerebo — Data Privacy
+60 3-4582 7163
7 Jalan Taman Seputeh, 58000 Kuala Lumpur, Malaysia