Privacy
Policy
Effective Date: September 9, 2026. Your privacy and commercial confidentiality are paramount. Here is how we collect, protect, and process your information.
Information We Collect
We may collect and process the following categories of personal data when you engage with Zennesis Studio:
- Identification & Contact Data: Full name, business name, registration number, email address, WhatsApp/telephone number, and billing/mailing address.
- Client Portal Account Data: Email address, hashed authentication credentials, display profile names, and project workspace settings managed securely via Supabase.
- Billing & Transaction Details: Billing records, subscription plan selections, transaction history, currency, and invoice identifiers. Note: All credit/debit card numbers are tokenized and processed directly by Stripe under PCI-DSS Level 1 certification. We never store raw credit card credentials on our servers.
- Project Content & Communications: Design briefs, brand guidelines, images, logos, copy, feedback notes, and conversation records transmitted via email, WhatsApp, or the Client Portal.
- Technical & Analytical Data: IP addresses, browser types, device specifications, operating system versions, and page usage logs collected automatically to maintain site performance and cybersecurity.
Purpose of Processing Your Data
Your personal information is collected, processed, and maintained strictly for legitimate commercial purposes, including:
- Providing, developing, engineering, and publishing custom websites and web applications.
- Administering recurring subscription accounts, executing invoicing, and preventing fraudulent transactions via Stripe.
- Maintaining continuous customer service, revision handling, and priority client support via WhatsApp and email.
- Deploying, configuring, and updating DNS, domains, SSL certificates, and hosting servers.
- Transmitting critical service alerts, security advisories, and system upgrade notifications.
- Complying with statutory reporting, accounting standards, and legal mandates under Malaysian regulatory frameworks.
Third-Party Processors & Data Sharing
We do not sell, rent, or lease your personal information to advertisers or unaffiliated third parties. We share data solely with trusted infrastructure service providers who are bound by stringent confidentiality and security obligations:
- Stripe Inc.: Payment processing, PCI-compliant tokenization, subscription billing cycles, and automated receipts.
- Supabase: Scalable authentication infrastructure, encrypted database storage, and secure user session management.
- Meta / WhatsApp: Instant client messaging, onboarding correspondence, and daily revision updates.
- Cloud Hosting & CDN Networks: Enterprise server clusters for high-speed website hosting, automated backups, and global caching.
- Legal & Regulatory Authorities: Law enforcement or government bodies only when compelled by valid court orders or applicable Malaysian statutory requirements.
Data Security & Retention Periods
Security Standards: We enforce enterprise-grade security protocols, including 256-bit SSL/TLS encryption for all data in transit, encrypted database tables, strict role-based access restrictions, and automated daily backups.
Retention Period: Personal data is maintained only for as long as necessary to fulfill the operational purposes for which it was collected, or to comply with statutory accounting and legal retention periods under Malaysian tax and commercial legislation (typically 7 years for financial records). Following this period, data is securely anonymized or permanently erased.
Your Rights Under Malaysia's PDPA 2010
Under the Personal Data Protection Act 2010, you are entitled to the following rights regarding your personal data:
- Right to Access: Request a copy of the personal data we hold about you.
- Right to Rectification: Request correction of inaccurate, incomplete, or out-of-date personal data.
- Right to Withdraw Consent: Withdraw your consent for ongoing processing or direct marketing communications at any time.
- Right to Restrict Processing: Request the limitation of processing if there are disputes concerning accuracy or legality.
To exercise any of these rights, or to submit a formal data privacy inquiry, please contact our Data Protection Officer at hello@zennesis.com. We will respond within twenty-one (21) days as provided under the PDPA.
Need to update your personal data?
Reach out to our Data Protection Officer for fast, secure assistance.