Privacy Policy & PDPA Notice Malaysia
Effective date: 23 October 2025
Who we are
FAR Tech (“FAR Tech”, “we”, “us” or “our”) provides AI and chatbot solutions, automation, and related consulting and support services in Malaysia. This Privacy Policy explains how we collect, use, disclose, store and protect personal data when you use our website fartech.com.my, our products, demos, chatbots, and when you communicate with us (collectively, the “Services”).
This Policy is prepared in accordance with the Personal Data Protection Act 2010 (Malaysia) (“PDPA“) and its seven data protection principles.
Scope
This Policy applies to personal data we process as a data user/controller for our own website and business operations, and—where we provide AI/chatbot services to business customers—as a data processor acting on documented instructions from such customers. If you interact with a chatbot that we build or host for a specific client, that client is typically the data controller of your conversation data; their privacy notice may also apply.
The PDPA Principles we follow
1) General Principle (Consent & Lawfulness)
We collect and process personal data only for lawful, explicit purposes and with your consent where required or where another lawful basis applies under the PDPA.
2) Notice & Choice
We provide clear notices on the data we collect and how we use it. You may choose not to provide certain data; however, this may limit your ability to use some features.
3) Disclosure
We do not disclose your personal data except as described in this Policy, with your consent, or as required/permitted by law.
4) Security
We implement appropriate technical and organisational measures to protect personal data against loss, misuse, unauthorised access, modification or disclosure.
5) Retention
We retain personal data only for as long as necessary to fulfil the purposes we collected it for, or to satisfy legal, regulatory, tax, or accounting requirements.
6) Data Integrity
We take reasonable steps to ensure that personal data is accurate, complete, not misleading and kept up to date for its intended use.
7) Access & Correction
You have the right to request access to, and correction of, your personal data that we hold, subject to PDPA conditions and any applicable fees.
What personal data we collect
- Website & analytics: IP address, device identifiers, browser type, pages viewed, referring/exit pages, timestamps, and cookies or similar technologies.
- Contact & business info: name, email, phone, company, role, and message content when you request a demo, contact us, or sign up for updates.
- Chatbot interactions: messages you send to our demos or to solutions we host for clients; metadata such as conversation IDs, timestamps, and language; optional files you upload.
- Support & operations: ticket history, call notes, feedback, logs, and diagnostics related to service quality and security events.
- Commercial data: order details, invoices, payment references (processed by payment providers), contract documents and audit trails.
- Recruitment: CV/resume details, references, interview notes where you apply for roles with us.
Sensitive personal data is collected only with explicit consent or where permitted by law and only if necessary for the stated purpose (e.g., handling vulnerabilities or fraud prevention requiring identity verification).
How we use your data (purposes)
- Provide, operate and improve our website, demos and AI/chatbot Services.
- Configure, train, evaluate and monitor chatbots and automations for you or our business customers.
- Respond to enquiries, provide support, and communicate service updates.
- Ensure security, prevent abuse, detect fraud and troubleshoot incidents.
- Carry out analytics, quality assurance, and product research (including aggregated and de-identified analysis).
- Comply with legal obligations, enforce agreements, and protect our rights.
- Send marketing communications with your consent (you can opt-out anytime).
AI/LLM transparency
- Human-in-the-loop: We may review small samples of anonymised conversation data to improve safety, accuracy and reliability.
- Model providers: If an AI model is hosted by a third-party provider, necessary inputs/outputs may be processed by that provider solely to deliver the requested functionality, subject to contractual safeguards.
- Training: Unless agreed otherwise in writing with a business customer, we do not use identifiable customer data to train public models. We may use de-identified and aggregated statistics to improve our Services.
- Automated decisions: Our chatbots typically assist rather than make legal or similarly significant decisions. Where automated decision-making occurs, we implement safeguards and provide ways to request human review.
Legal bases under the PDPA
We rely on one or more of the following PDPA-compliant bases: your consent; performance of a contract or steps at your request; compliance with legal obligations; protection of vital interests; administration of justice; or our legitimate interests (for example, to secure our Services, prevent fraud, or improve user experience) where such interests are not overridden by your interests or fundamental rights and freedoms.
Cookies & tracking technologies
We use cookies and similar technologies to remember your preferences, analyse site usage and improve our Services. You can control cookies through your browser settings. Disabling some cookies may affect site functionality.
- Essential
- Analytics
- Performance
- Security
- Preference
Disclosures & recipients
We may disclose personal data to:
- Service providers acting on our behalf (e.g., hosting, cloud, analytics, security, support desk), bound by confidentiality and data protection terms;
- Business customers (when we process chatbot data as their processor), according to their instructions;
- Professional advisors, insurers and auditors where necessary;
- Regulators, government authorities or law enforcement where required by law or to protect rights, safety, and security; and
- A successor entity in the event of a merger, acquisition or restructuring, under obligations ensuring continued protection of your data.
International transfers
Your data may be transferred to and processed in countries outside Malaysia (for example, where our cloud or model providers host their infrastructure). We will take reasonable steps to ensure that such transfers comply with PDPA requirements and that your data receives a comparable degree of protection.
Data security
- Access controls, role-based permissions and multi-factor authentication where appropriate.
- Encryption in transit (TLS) and at rest where supported.
- Network and application monitoring, vulnerability management and backup procedures.
- Employee confidentiality obligations and security awareness.
- Vendor due diligence and data processing agreements for third parties.
Retention
We retain personal data for the duration necessary to fulfil the purposes set out in this Policy unless a longer retention period is required or permitted by law. Typical retention periods include:
- Website analytics: 13–26 months (aggregated thereafter).
- Chatbot logs: 6–24 months, configurable for business customers.
- Contracts & billing: 7 years to meet accounting/legal requirements.
- Support tickets: up to 24 months after closure.
- Recruitment: up to 24 months (or sooner upon request).
Your rights
Subject to PDPA and other applicable laws, you may:
- Request access to personal data we hold about you;
- Request correction of inaccurate, incomplete or misleading data;
- Withdraw consent where processing is based on consent;
- Object to processing for direct marketing; and
- Raise questions or complaints about our data practices.
We may need to verify your identity and may charge a reasonable fee to cover administrative costs for access requests as permitted by PDPA.
Children’s privacy
Our Services are not directed to children under the age of 13. We do not knowingly collect personal data from children. If you believe a child has provided personal data to us, please contact us so that we can take appropriate action.
Third-party links & services
Our website and chatbots may link to or integrate with third-party sites and services. This Policy does not cover those third parties, and we are not responsible for their privacy practices. Please review their policies before providing personal data.
Marketing communications
With your consent, we may send you updates about our products and events. You can opt out at any time by using the unsubscribe link in the email or by contacting us.
Contact us
To exercise your rights or for any privacy-related enquiries, please contact our Data Protection Officer:
Email: privacy@fartech.com.my
Postal: FAR Tech – Data Protection Officer, [Insert business address]
Phone: [Insert contact number]
For chatbot solutions operated for a business customer, please also contact that organisation directly, as they are the primary data controller for your conversation data.
Changes to this Policy
We may update this Policy from time to time to reflect changes in technology, law or our practices. The updated version will be posted at this page with an updated effective date. Material changes will be highlighted where appropriate.
Language
This Policy is provided in English. If translated into Bahasa Malaysia or other languages, the English version will prevail in the event of any inconsistency.
Quick glossary
- Personal data: Any information that relates directly or indirectly to an identifiable individual.
- Processing: Any operation performed on personal data (e.g., collection, use, disclosure, storage).
- Data controller/data user: The party who determines the purposes and means of processing personal data.
- Data processor: A party who processes personal data on behalf of a controller.