1. Introduction
GDG LIVE SDN. BHD. respects the privacy of every person who interacts with our company, our website and our professional services. This Privacy Policy explains, in plain language, what personal data we collect, why we collect it, how we use it, how long we keep it and what choices you have. It applies to prospective clients, current clients, suppliers, partners, website visitors, job applicants and any other individual whose information reaches our business.
GDG Live is the developer and operator of this website. The company behind it is GDG LIVE SDN. BHD., a computer systems design and integration firm registered in Malaysia and working from our studio at 26 Jalan Liku Bangsar, Kuala Lumpur - 59100, Malaysia (MY). We build and operate connected technical systems for other organisations, and in doing so we handle information with the same discipline we apply to the systems themselves.
We wrote this policy to be readable rather than intimidating. Where the law requires a more formal term, we explain it. Where a practice might surprise you, we describe it clearly. Our guiding principle is simple: we collect the minimum amount of personal data needed for a legitimate purpose, and we protect it as though it were our own.
By using our website, engaging our services or otherwise communicating with us, you acknowledge that you have read and understood this Privacy Policy. If you do not agree with the practices described here, please refrain from using our website or providing personal data to us.
2. Scope of This Policy
This policy covers personal data processed through our public website, our written and verbal communications, our commercial agreements, our support channels and our internal business operations. It applies to data held in electronic form and to structured paper records that we maintain as part of an organised filing system.
This policy does not apply to data that we process solely on behalf of a client as a service provider, where the client remains the controller and determines the purposes and means of processing. In those situations the client privacy notice governs the relationship, and our handling is defined by the written agreement between the client and GDG LIVE SDN. BHD.
This policy also does not apply to third party websites that we link to from our pages. We do not control those destinations and we encourage you to review the privacy notices published by each external provider before submitting information to them.
3. Definitions We Use
Personal data means any information relating to an identified or identifiable natural person. An identifiable person is one who can be recognised, directly or indirectly, by reference to an identifier such as a name, an identification number, location data or an online identifier.
Processing means any operation performed on personal data, including collection, recording, organisation, storage, adaptation, retrieval, consultation, use, disclosure, alignment, restriction, erasure and destruction.
Controller means the organisation that determines why and how personal data is processed. For the purposes described in this policy, GDG LIVE SDN. BHD. acts as the controller.
Processor means an organisation that processes personal data on behalf of a controller and under the controller written instructions. Data subject means the individual to whom personal data relates. Special category data means sensitive information such as health records, biometric data or information revealing political or religious beliefs, which we do not seek in the ordinary course of business.
4. Personal Data We Collect
We collect contact details you choose to provide, including your name, professional email address, telephone number, job title, employer name and the content of any message you send to us. When you engage our services, we may also collect billing information, correspondence records and project related details that are necessary to deliver the work.
We collect technical information generated automatically when you visit our website, such as the internet protocol address assigned to your device, browser type and version, operating system, approximate location derived from the address, referring pages, pages viewed and the time and date of each request. This information is used in aggregate to keep the site secure and functional.
If you apply for a role with us, we may collect employment history, qualifications, references and other information you supply as part of your application. We do not request special category data unless a specific legal duty requires it, and we ask that you do not send such information to us without a prior written request.
We do not knowingly collect personal data from children, and we do not purchase personal data from data brokers for marketing purposes. The categories of information we hold are limited to what a professional services business genuinely needs to operate.
5. How We Collect Personal Data
We collect personal data directly from you when you complete a contact form, send us an email, call our office, meet our team, sign a proposal or correspond with us during a project. In these cases you decide what to share, and we ask only for details relevant to your enquiry.
We collect technical data automatically through our web server and any analytics tooling we deploy. We may also receive information indirectly from a colleague who introduces you to us, from a partner who refers your enquiry, or from a publicly available professional profile that you have chosen to publish.
Where we work inside a client environment, we may encounter operational data as part of delivering a service. We treat such material strictly as client confidential data, we access it only as authorised, and we never repurpose it for our own marketing or analytics purposes.
6. Lawful Basis for Processing
We process personal data only where we have a valid legal basis. The bases we rely on include your consent, the performance of a contract with you, compliance with a legal obligation, and our legitimate interests in running and improving a professional services business.
When we rely on consent, you may withdraw it at any time by contacting us, and withdrawal will not affect the lawfulness of processing carried out before that point. When we rely on legitimate interests, we balance those interests against your rights and expectations, and we limit processing to what is proportionate.
Where we process personal data to comply with tax, accounting, anti money laundering or other statutory duties, the basis is legal obligation. Where processing is necessary to respond to your enquiry or to prepare a quotation, the basis is a contract or steps taken at your request before entering a contract.
7. Purposes of Processing
We use personal data to respond to enquiries, prepare proposals, deliver and support our services, manage client relationships, issue invoices, maintain accounting records and meet our legal and regulatory obligations. We also use it to operate, secure and improve our website.
With appropriate consent, we may use your contact details to send you occasional updates about our services, technical notes or invitations to events. You can opt out of these communications at any time, and an unsubscribe option is included in every such message.
We use technical and aggregate information to monitor performance, diagnose faults, prevent abuse and understand which parts of our website are useful. This analysis is performed on de identified or aggregated data wherever practicable, so that individual visitors are not singled out.
We do not sell personal data, and we do not use personal data for automated decisions that produce legal or similarly significant effects without human involvement.
10. Service Providers and Subprocessors
We use a limited number of service providers to operate our business. These may include website hosting, email delivery, cloud infrastructure, backup, accounting software and customer relationship management tools. Each provider is selected with care and is bound by a written agreement that requires confidentiality and appropriate security.
Our providers may engage subprocessors of their own. Where they do, we require prior notice of material changes and we assess whether the arrangement maintains the level of protection we promised to you. Providers process personal data only on our documented instructions and only for the purposes we have agreed.
We review our provider list on a regular schedule and remove any service that no longer meets our standards. Access granted to providers is limited to the minimum scope needed for the task, and it is revoced promptly when the engagement ends.
11. International Data Transfers
Some of our service providers operate infrastructure in countries other than Malaysia. When personal data is transferred across a national border, we take steps to ensure that it continues to receive an adequate level of protection.
These steps may include contractual clauses approved for the purpose, a documented assessment of the destination legal environment, and technical measures such as encryption in transit and at rest. We keep records of transfers and of the safeguards applied to each one.
Where a transfer would create an unacceptable risk to your rights, we will either avoid the transfer or seek a different solution. You may contact us for more information about the safeguards used for any particular transfer of your personal data.
12. Data Retention
We keep personal data only for as long as it is needed for the purpose for which it was collected, or for as long as a legal or contractual duty requires us to retain it. After that period the data is securely deleted or, where deletion is not immediately possible, placed beyond ordinary use.
Enquiry records are generally kept for the duration of the relationship and for a reasonable period afterwards so that we can answer follow up questions. Financial and tax records are kept for the period required by Malaysian law. Recruitment records are kept for a defined period and then removed, unless you ask us to keep them on file.
When retention ends, we remove the data from active systems, from backups on their normal rotation and from any remaining archives. We document our retention decisions so that the process is consistent and auditable.
13. How We Protect Personal Data
We apply administrative, technical and physical safeguards to protect personal data against loss, misuse, unauthorised access, alteration and disclosure. These safeguards reflect the sensitivity of the information we hold and the risk of harm if it were compromised.
Technical controls include encryption of data in transit, encrypted storage where appropriate, role based access control, multi factor authentication for our team, network segmentation, logging and alerting. Administrative controls include written policies, confidentiality commitments for staff and contractors, least privilege access reviews and regular training.
Physical controls limit access to our premises and to any equipment that stores data. We dispose of storage media securely when it reaches end of life, and we verify that hosted environments are configured to the standards we describe in our agreements.
No method of protection is perfect. We therefore design our systems to limit the impact of any failure, and we test our controls through review and rehearsal rather than relying on assumption.
14. Security Incident Response
We maintain an incident response process to detect, contain, investigate and recover from security events that affect personal data. Team members are trained to report suspected incidents promptly, and a named owner coordinates the response.
Where an incident is likely to result in a risk to the rights and freedoms of individuals, we will notify the relevant authority without undue delay and within any period required by law. Where the risk is high, we will also inform affected individuals directly, describing the nature of the incident, likely consequences and the measures taken.
After an incident is resolved, we perform a review to identify root causes and to improve our controls. Lessons learned are recorded and applied so that the same failure is not repeated. We cooperate fully with regulators and with client security teams where the incident touches data we hold on their behalf.
15. Your Privacy Rights
Depending on where you live, you may have the right to access the personal data we hold about you, to request correction of inaccurate information, to request deletion of data that is no longer needed, and to restrict or object to certain processing.
You may also have the right to data portability, meaning a copy of the information you provided in a structured and commonly used format. Where processing relies on consent, you may withdraw that consent at any time without penalty.
We will respond to valid requests within the period required by applicable law, and we will explain any extension where a request is complex. There is no charge for a reasonable request, though a fee may apply where requests are manifestly unfounded or excessive. We may need to verify your identity before acting.
If you believe we have handled your information improperly, please contact us first so that we can address the matter. You also have the right to complain to the relevant supervisory authority in your jurisdiction.
16. Making an Access or Deletion Request
To exercise any right described in this policy, contact us at admin@gdglive.lol or write to GDG LIVE SDN. BHD. at 26 Jalan Liku Bangsar, Kuala Lumpur - 59100, Malaysia (MY). Please describe the request clearly and provide enough detail for us to locate the relevant records.
We may ask for proof of identity and for information needed to protect against unauthorised disclosure. Once verified, we will action the request and confirm the outcome in writing, explaining any information we cannot act on and the reason.
If you authorise another person to act on your behalf, we will require evidence of that authority. If your request concerns data we hold on behalf of a client as a processor, we will forward it to that client and support them in responding, because they control that information.
17. Privacy for Children
Our website and services are intended for professionals and organisations. We do not direct our services to children, and we do not knowingly collect personal data from a child without the involvement of a parent or guardian where such involvement is required.
If you believe that a child has provided personal data to us, please contact us so that we can investigate and remove the information promptly. Where we learn that we have collected data from a child in breach of this policy, we will delete it without undue delay.
Parents and guardians who have questions about how our website or services interact with younger users are welcome to contact us using the details in this policy.
18. Marketing Communications
We send marketing messages only where we have a lawful basis to do so. You can opt out of marketing at any time by using the unsubscribe link in a message or by contacting us directly. We honour opt out requests promptly and keep a record of your preference.
We do not share your contact details with third parties for their own marketing. If a partner sends a message on our behalf, we require them to observe this policy and to act only on our documented instructions.
Service and transaction messages, such as confirmation of a support request, are not marketing messages and may still be sent while an agreement is active.
19. Third Party Sites and Services
Our website may contain links to external websites and may embed content from third party providers. We are not responsible for the privacy practices of those services, and this policy does not extend to them.
We encourage you to read the privacy notice of any external site before providing personal data. If you believe a linked service is behaving in a way that conflicts with this policy, please tell us so that we can review whether the link should remain.
Where we integrate a third party tool into a client environment, the client privacy notice and our service agreement govern the processing rather than this website policy.
20. Automated Decision Making
We do not make decisions that produce legal or similarly significant effects about you using solely automated means. Our profiling activity, where it occurs at all, is limited to aggregate reporting that helps us understand service use and improve quality.
If we ever introduce a process that involves automated decision making, we will update this policy, describe the logic involved and provide a route to request human review. Your rights in relation to such processing will be respected at all times.
21. Client Data and Confidential Information
When we deliver services, we may access systems and data owned by a client. We treat all such material as confidential, access it only as authorised, and use it only to perform the agreed work. We do not extract, retain or reuse client data for our own purposes.
Our personnel are bound by confidentiality obligations that survive the end of an engagement. Where a client requires specific technical measures, such as data residency restrictions or dedicated access controls, we agree those terms in writing before work begins.
On completion of an engagement, client data in our possession is returned or securely destroyed according to the agreement and the client instructions, and we confirm the action in writing where requested.
22. Changes to This Policy
We review this Privacy Policy regularly and may update it to reflect changes in our practices, technology or legal obligations. When we make a material change, we will update the effective date at the top of this page and provide notice where appropriate.
We encourage you to review this page periodically so that you remain aware of how we protect personal data. Continued use of our website or services after an update constitutes acceptance of the revised policy.
Previous versions are retained internally so that we can demonstrate the basis on which earlier processing took place, and we can provide a summary of changes on request.
23. How to Contact Us
If you have questions, concerns or requests about this Privacy Policy or about how we handle personal data, please contact our team. We take privacy seriously and we will respond as quickly as we can.
GDG LIVE SDN. BHD.
26 Jalan Liku Bangsar, Kuala Lumpur - 59100, Malaysia (MY)
Email: admin@gdglive.lol
Phone: +19039646963
You may also contact us through our website contact page, and we will route your message to the person responsible for privacy matters. We are grateful for your trust and we work every day to deserve it.