1. Who we are#
EBOSSPro is a cloud business management platform operated by Awfatech Global Sdn Bhd (201201044764 / 1029241-W) ("Awfatech", "we", "us"), a company incorporated in Malaysia on 26 December 2012 and registered with the Ministry of Finance (357-02203949).
We are the data user responsible for personal data processed through this website and through your EBOSSPro account, and we handle that data in accordance with the Malaysian Personal Data Protection Act 2010 ("PDPA").
| Detail | Value |
|---|---|
| Registered name | Awfatech Global Sdn Bhd |
| Company registration | 201201044764 (1029241-W) |
| Registered address | No. 5-1, Jalan USJ 1/1A, Regalia Business Centre, 47600 Subang Jaya, Selangor, Malaysia |
| info@awfatech.com | |
| Telephone | 03-8023 4361 |
| Information security certification | ISO/IEC 27001:2013 (cert. MSIT1002) |
2. The two roles we play#
EBOSSPro is sold to organisations, not to individuals, and that changes who is responsible for what. This policy covers two different relationships, and it matters which one applies to you.
- Data we control
- Information about the organisation that subscribes and the people who deal with us directly — enquiry forms, support tickets, account administrators, billing contacts and website visitors. We decide how this data is used, and this policy governs it in full.
- Data we process for a customer
- Information an organisation puts into its own EBOSSPro tenant about its employees, students, residents, members or customers. The subscribing organisation decides what to collect and why; we hold and process it on that organisation's instructions to deliver the service. We do not use it for our own purposes.
3. What we collect#
Information you give us
- Contact details — name, job title, organisation, work email, phone number
- Account credentials — username and a password we store only as a cryptographic hash
- Billing and subscription details — company registration, billing address, tax details, plan and payment records
- Anything you send us in a support ticket, enquiry form, email or call
Information your organisation puts into the platform
The modules an organisation switches on determine what it uploads. Across the HR, Finance and add-on suites this can include:
- Employee and member records — identity details, contact information, employment history, documents
- Attendance and time records, including check-in and check-out times and shift data
- Face templates used to verify identity at clock-in, and the GPS coordinates recorded with each check-in
- Leave, claim, disciplinary and appraisal records
- Payroll and statutory contribution data, and bank account details for salary payment
- Recruitment data — applications, resumes, interview notes and AI-generated candidate assessments
- Financial records — invoices, receipts, payments, customer and supplier details
- Student, resident, tenant and unit records, depending on the solution in use
Information collected automatically
- Log data — IP address, timestamps, pages and screens accessed, actions taken in the application
- Device and browser information, including operating system and app version
- Cookies and similar technologies, as described in section 11
4. Face data and location data#
Face-verified attendance and GPS-verified check-in deserve their own section, because face data is sensitive personal data under the PDPA and location data reveals where a person was at a given moment.
- Face verification is used only to confirm that the person clocking in is the employee on record. It is not used for surveillance, emotion analysis, or identifying anyone outside the organisation's own staff list.
- A face scan is converted into a mathematical template for comparison. The template cannot be turned back into a photograph of the person.
- GPS coordinates are captured at the moment of check-in to confirm the employee is within the branch radius the employer configured. We do not track location continuously or between check-ins.
- Both are collected because the subscribing organisation switched the feature on. That organisation is responsible for telling its staff, and for obtaining the consent the PDPA requires for sensitive personal data, before enabling it.
- Face templates and location records are deleted with the rest of a tenant's data when a subscription ends, on the timetable in section 9.
5. How we use personal data#
- To create and administer accounts, and to authenticate users signing in
- To deliver the modules an organisation has subscribed to, and to store the records it creates
- To process subscription payments, issue invoices and meet our tax and accounting obligations
- To provide support — diagnosing a fault sometimes requires our engineers to view the affected record
- To send service communications: security notices, maintenance windows, billing notices and changes to these documents
- To monitor security, detect abuse and investigate incidents
- To generate the AI features described on this site, such as candidate fit scores and drafted content, within the tenant that requested them
- To improve the platform, using aggregate usage patterns rather than the content of anyone's records
- To send marketing about our products, where you asked for it or where you are a business contact who has not opted out
6. Who we share it with#
We disclose personal data only in the situations below, and only to the extent needed.
- Within your organisation
- Records are visible to the users your administrators authorise, according to the roles and permissions they configure. We do not control who inside an organisation is granted access.
- Service providers
- The third parties listed below, which host, transmit or monitor data on our behalf under contract, and may use it only to provide their service to us.
- Professional advisers
- Auditors, accountants, insurers and lawyers, where necessary and under a duty of confidentiality.
- Legal and regulatory
- Where we are required by Malaysian law, a court order or a lawful request from an authority, or where disclosure is necessary to protect our rights, safety or property. We will tell the affected customer unless we are legally prohibited from doing so.
- Corporate transactions
- If Awfatech is involved in a merger, acquisition or sale of assets, data may transfer to the acquirer, who remains bound by this policy or a materially equivalent one.
Service providers we use
| Purpose | Provider and location |
|---|---|
| Cloud infrastructure and storage | Amazon Web Services (AWS) — Malaysia and Singapore regions |
| Data centre and hosting facilities | CJ1 Center, Menara AIMS, Equinix SG1 — Malaysia and Singapore |
| Transactional and notification email | SendGrid — Regional infrastructure |
| SMS delivery | One Way SMS — Malaysia |
| Mobile push notifications | Google Firebase — Regional infrastructure |
| Application logging and performance monitoring | Loggly, Grafana — Regional infrastructure |
7. Where your data is stored#
EBOSSPro runs on Amazon Web Services and on our own hosting and data centre infrastructure. Customer data is held in the following facilities:
| Facility | Location |
|---|---|
| CJ1 Center | Cyberjaya, Malaysia |
| Menara AIMS | Kuala Lumpur, Malaysia · ANSI/TIA-942-B:2017 Rated-3 |
| Equinix SG1 | Singapore |
Data may therefore be stored or processed in Malaysia and Singapore. Where personal data leaves Malaysia, we take reasonable steps to ensure it receives a level of protection comparable to that required by the PDPA, including contractual commitments from the providers involved. Some service providers named in section 6 operate regional infrastructure, which may mean transmission through other jurisdictions.
8. How we protect it#
Awfatech's administration systems are certified to ISO/IEC 27001:2013 for information security management (certificate MSIT1002, issued by QAS International, first approved 3 March 2016), for the scope of Software-as-a-Service (SaaS) cloud-based applications and IT services.
The controls in place include:
- TLS/SSL encryption for all data in transit, with certificates managed through AWS Certificate Manager
- Encryption of stored data and managed encryption keys via AWS Key Management Service (KMS)
- Web application firewall, intrusion prevention system (IPS) and anti-DDoS protection
- Threat detection across accounts and workloads using Amazon GuardDuty
- Regular web vulnerability scanning and continuous web monitoring
- Administrative access over VPN only, with role-based permissions per user
- Action-level audit trails of infrastructure changes via AWS CloudTrail
- High-availability infrastructure with redundant power, network and hardware, and multiple backups
- 24/7 monitoring of servers, network and performance by our operations team
Access to customer data by our own staff is limited to the personnel who need it for support, operations or security, and is logged.
9. How long we keep it#
| Data | Retention |
|---|---|
| Records inside an active tenant | Kept for as long as the subscription is active, or until the customer deletes them |
| Tenant data after a subscription ends | Retained for 90 days so the customer can export or reactivate, then deleted from live systems |
| Encrypted backups | Rotated out within a further 90 days |
| Billing, invoicing and tax records | Retained for 7 years, as Malaysian tax and company law require |
| Support tickets and correspondence | Up to 3 years after the matter is closed |
| Security and access logs | Up to 12 months |
| Marketing contact details | Until you unsubscribe, and removed from active lists thereafter |
Where a customer instructs us to delete data sooner, we will do so unless we are required to keep it by law. We do not keep personal data for longer than the purpose it was collected for requires.
10. Your rights#
Under the PDPA you may:
- Ask for access to the personal data we hold about you
- Ask us to correct data that is inaccurate, incomplete or out of date
- Withdraw consent to processing, where processing rests on your consent
- Ask us to limit processing for direct marketing purposes
- Ask about our practices, and complain if you believe we have got something wrong
To exercise any of these, email info@awfatech.com or write to us at the address in section 13. We will respond within 21 days. We may need to verify your identity first, and a fee permitted by the PDPA may apply to a data access request.
12. Children and students#
EBOSSPro is not offered directly to children. Our education solutions do hold records about students, including children, but those records are entered and controlled by the school or institution, which is responsible for obtaining parental consent where the law requires it. We process that data only on the institution's instructions.
13. Changes, and how to reach us#
We may update this policy as the platform or the law changes. The effective date at the top of this page always reflects the current version, and we will give notice of any change that materially affects how we handle personal data — by email to account administrators, or by a notice in the console.
Contact
Privacy questions, requests and complaints go to info@awfatech.com, or by post to Awfatech Global Sdn Bhd, No. 5-1, Jalan USJ 1/1A, Regalia Business Centre, 47600 Subang Jaya, Selangor, Malaysia. You can also call 03-8023 4361.
If you are not satisfied with our response, you may refer the matter to the Personal Data Protection Commissioner, Malaysia.
Privacy Policy · Awfatech Global Sdn Bhd · Version dated 12 August 2026. Governed by the laws of Malaysia.