Privacy Policy WiSoft Solutions Sdn. Bhd. (Company No. 1131956-M)
WiSoft Solutions Sdn. Bhd. (“WiSoft“, “we“, “us“, “our“) respects your privacy and is committed to protecting the personal data you share with us. This Privacy Policy explains how we collect, use, disclose, store and protect your personal data, and the choices and rights available to you, in accordance with the Personal Data Protection Act 2010 of Malaysia (Act 709), as amended by the Personal Data Protection (Amendment) Act 2024 (together, the “PDPA“).
By providing your personal data to us — for example, through our website, contact and demo request forms, event and webinar registrations, or by communicating with us — you acknowledge that you have read and understood this Privacy Policy.
1. Who we are
WiSoft Solutions Sdn. Bhd. is a business software solutions company founded in 2007 and headquartered in Penang, Malaysia, with offices across Peninsular Malaysia. We implement accounting, payroll, point-of-sale, e-invoicing and inventory management software for businesses.
Registered / principal address: 72-03-17, Arena Curve @ The Arena, Jalan Mahsuri, 11950 Bayan Lepas, Penang, Malaysia.
For the purposes of the PDPA, WiSoft is the data controller in respect of the personal data described in this Policy.
2. What personal data we collect
Depending on how you interact with us, we may collect:
- Identity and contact details — your name, business email address, mobile or telephone number, and company name.
- Enquiry and interest details — the product(s) you are interested in, messages you send us, and how you heard about us.
- Event and webinar data — registration details for seminars, webinars, roadshows and other events we host or co-host, and attendance records.
- Communication records — correspondence with us by email, phone, WhatsApp, social media or our contact forms.
- Technical and usage data — when you visit our website, information such as your IP address, browser type, device information, pages viewed and referring source, collected through cookies and similar technologies (see Section 12).
We collect business-context personal data for commercial purposes. We do not intentionally collect sensitive personal data (such as data on health, religious beliefs, or biometric data) through this website. Please do not submit sensitive personal data to us unless we specifically request it and you have consented to its use.
3. How we collect your personal data
We collect personal data:
- Directly from you — when you complete a form on our website (including the Free Demo and Contact forms), register for an event or webinar, subscribe to updates, request a quotation or support, or otherwise communicate with us.
- Automatically — through cookies and analytics tools when you use our website.
- From third parties — such as our business partners, event co-organisers, or referrals, where you have consented or where we are otherwise permitted by law.
4. Why we use your personal data (purposes)
We use your personal data for the following purposes:
- To respond to your enquiries, demo requests, and support requests.
- To provide, implement, and support the software solutions and services you engage us for.
- To register and manage your participation in our seminars, webinars, roadshows and events.
- To send you marketing, promotional and informational communications — including news, event invitations, product updates, compliance updates (such as e-invoicing and payroll matters), tips and offers — by email (EDM), WhatsApp, phone or other channels, where you have consented to receive them.
- To maintain and improve our website, products, services and customer experience.
- To manage our customer relationship and internal record-keeping.
- To comply with applicable laws, regulations and lawful requests from authorities.
If we intend to use your personal data for a purpose materially different from those above, we will notify you and, where required, obtain your consent.
5. Consent and legal basis
We process your personal data on the basis of your consent and, where applicable, for the performance of a contract with you, our legitimate business interests, or to comply with a legal obligation.
Where consent is required — in particular for direct marketing communications — we will obtain it from you at the point of collection (for example, through a checkbox or by your act of submitting a form or registering for updates). You may withdraw your consent at any time (see Section 6 and Section 9).
6. Direct marketing and your choices
We will only send you marketing communications where you have consented, or where otherwise permitted by law.
You may opt out of marketing communications at any time, at no cost, by:
- clicking the “unsubscribe” link in any of our marketing emails;
- replying STOP to a marketing WhatsApp message; or
- contacting us using the details in Section 15.
If you opt out of marketing, we may still contact you for non-marketing purposes, such as responding to a support request or providing information relating to a service you have engaged us for.
7. Disclosure of your personal data
We do not sell your personal data. We may disclose your personal data, on a need-to-know basis, to:
- Our group of companies — related and affiliated entities under our group, for the purposes described in this Policy;
- Software principals and technology partners — such as the vendors of the platforms we implement (for example, our accounting, payroll and POS software principals), where necessary to provision, license, support or service the solutions you request;
- Service providers — including IT, cloud hosting, email and CRM, event management, analytics and professional service providers who process data on our behalf under confidentiality and data-protection obligations;
- Event co-organisers or sponsors — where you register for a jointly organised event, and where you have been informed at registration;
- Authorities and regulators — where required or permitted by law, regulation, court order or lawful request.
Where we engage third parties to process personal data on our behalf (data processors), we require them to protect your data in a manner consistent with this Policy and the PDPA.
8. Cross-border data transfer
Some of our service providers (for example, cloud hosting, email or analytics providers) may store or process personal data on servers located outside Malaysia. Where we transfer personal data outside Malaysia, we will take reasonable steps to ensure that the data continues to be protected to a standard comparable with the PDPA, in line with the Commissioner’s Cross-Border Personal Data Transfer guidelines. [Confirm with your IT/legal team which of your tools host data overseas; you may wish to name the main providers here.]
9. Your rights under the PDPA
Subject to the conditions and exceptions under the PDPA, you have the right to:
- Access the personal data we hold about you and request information about how it is processed;
- Correct personal data that is inaccurate, incomplete, misleading or out of date;
- Withdraw your consent to our processing of your personal data;
- Limit the processing of your personal data, including requiring us to stop processing it for direct marketing purposes;
- Data portability — request that your personal data be transmitted to another data controller, where technically feasible and permitted under the PDPA.
To exercise any of these rights, please contact us using the details in Section 15. We may need to verify your identity before acting on your request. We will respond within the timeframe required by law. A reasonable fee may apply to certain access requests, as permitted under the PDPA.
Please note that if you withdraw your consent or ask us to limit processing, we may be unable to continue providing certain services or communications to you.
10. Data retention
We retain your personal data only for as long as necessary to fulfil the purposes for which it was collected, including to satisfy any legal, accounting, tax or reporting requirements. When personal data is no longer required, we will take reasonable steps to securely destroy, delete or permanently anonymise it.
11. Data security
We implement reasonable administrative, technical and physical safeguards designed to protect your personal data against loss, misuse, unauthorised access, disclosure, alteration or destruction. While we strive to protect your personal data, no method of transmission or storage is completely secure, and we cannot guarantee absolute security.
In the event of a personal data breach that meets the notification thresholds under the PDPA, we will notify the Personal Data Protection Commissioner and, where the breach is likely to cause significant harm, affected individuals, in accordance with the law.
12. Cookies and tracking technologies
Our website uses cookies and similar technologies (including analytics tools and tag managers) to operate the site, remember your preferences, understand how the site is used, and improve our services and marketing.
You can manage or disable cookies through your browser settings. Please note that disabling certain cookies may affect the functionality of our website. [If you deploy a cookie consent banner, reference it here.]
13. Third-party websites
Our website may contain links to third-party websites and social media platforms (such as Facebook, LinkedIn, Instagram and YouTube). This Privacy Policy does not apply to those third-party sites, and we are not responsible for their privacy practices. We encourage you to review the privacy policies of any third-party site you visit.
14. Children
Our website and services are intended for businesses and are not directed at children. We do not knowingly collect personal data from individuals under the age of 18. If you believe we have inadvertently collected such data, please contact us so that we can delete it.
15. How to contact us
If you have any questions about this Privacy Policy, wish to exercise your rights, or want to make a complaint about how we handle your personal data, please contact:
WiSoft Solutions Sdn. Bhd. (Company No. 1131956-M) Attn: Data Protection Contact [appoint and name a Data Protection Officer / contact person] 72-03-17, Arena Curve @ The Arena, Jalan Mahsuri, 11950 Bayan Lepas, Penang, Malaysia. Email:
privacy@wisoft.my [recommended — set up a dedicated domain mailbox; do not use a public Gmail address for a data-protection contact] Phone:
If you are not satisfied with our response, you have the right to lodge a complaint with the Personal Data Protection Department (Jabatan Perlindungan Data Peribadi), Malaysia (www.pdp.gov.my).
16. Changes to this Privacy Policy
We may update this Privacy Policy from time to time to reflect changes in our practices, technology, or legal requirements. The updated version will be posted on this page with a revised “Last updated” date. We encourage you to review this page periodically.
17. Governing law
This Privacy Policy is governed by and construed in accordance with the laws of Malaysia.
This Privacy Policy is available in English. [Consider publishing a Bahasa Malaysia and 中文 version for accessibility; the English version prevails in the event of any inconsistency.

