Privacy Policy

How we collect, use, and protect your personal information

Last Updated: November 6, 2025 | Compliant with Malaysian PDPA

Your Privacy Matters

At TradeAssets Malaysia, we are committed to protecting your privacy and personal data. This Privacy Policy explains how we collect, use, disclose, and safeguard your information in compliance with the Malaysian Personal Data Protection Act 2010 (PDPA) and other applicable data protection laws.

1. Information We Collect

1.1 Information You Provide Directly

Account Registration:

  • Full name and email address
  • Phone number and contact details
  • Password (encrypted and hashed)
  • User role selection (Buyer/Seller)

Business Information (for Sellers):

  • Company name and registration number (SSM/ROC/ROB)
  • Business registration documents
  • Business address and operational details
  • Identity verification documents (IC/Passport)
  • Bank account information (for commission payments)

Listing Information (for Sellers):

  • Equipment descriptions, specifications, and condition
  • Photos and media uploads
  • Pricing and auction parameters
  • Location information

Transaction Information:

  • Bid history and amounts
  • Auction participation records
  • Communication between Buyers and Sellers
  • Feedback and ratings

1.2 Information Collected Automatically

Usage Data:

  • IP address and geographic location
  • Browser type and version
  • Device information (type, OS, screen resolution)
  • Pages visited and time spent
  • Referring URLs and search terms
  • Click patterns and navigation paths

Cookies and Similar Technologies:

  • Session cookies for authentication
  • Preference cookies for user settings
  • Analytics cookies for platform improvement

2. How We Use Your Information

We use your personal information for the following purposes:

Platform Operations

  • Create and manage your user account
  • Verify seller identities and business registrations
  • Process and facilitate auctions and transactions
  • Enable communication between Buyers and Sellers
  • Display your contact information to transaction parties

Customer Service

  • Respond to your inquiries and support requests
  • Resolve disputes and mediate conflicts
  • Provide technical assistance
  • Send important account and platform notifications

Security and Compliance

  • Detect and prevent fraud, abuse, and illegal activities
  • Enforce our Terms of Service and policies
  • Comply with legal obligations and law enforcement requests
  • Protect user safety and platform integrity

Platform Improvement

  • Analyze usage patterns and trends
  • Improve features and user experience
  • Develop new services and functionality
  • Conduct research and analytics

Marketing (With Consent)

  • Send promotional emails about new features
  • Notify you of relevant equipment listings
  • Share industry news and platform updates
  • Conduct surveys and request feedback

Your Consent: By creating an account, you consent to these uses of your information. You can withdraw consent for marketing communications at any time by clicking "unsubscribe" in our emails or adjusting your account preferences.

3. Information Sharing

We share your information in the following circumstances:

3.1 With Other Users

To facilitate transactions, we display:

  • Sellers to Buyers: Company name, contact information, location, and seller rating
  • Buyers to Sellers (upon winning): Name, phone number, and email address
  • Public Information: Username, feedback ratings, and transaction history (anonymized)

3.2 With Service Providers

We engage third-party companies to perform services on our behalf:

  • Hosting Providers: Store platform data and content
  • Email Services: Send transactional and marketing emails
  • Payment Processors: Process platform commission payments (Sellers only)
  • Analytics Tools: Understand platform usage and performance
  • Customer Support Tools: Manage support tickets and inquiries

All service providers are bound by confidentiality agreements and PDPA compliance requirements.

3.3 For Legal Reasons

We may disclose your information when required by law or to:

  • Comply with legal process, court orders, or government requests
  • Enforce our Terms of Service and policies
  • Investigate fraud, security issues, or illegal activities
  • Protect the rights, property, or safety of TradeAssets, users, or the public
  • Cooperate with law enforcement agencies (PDRM, CCID, etc.)

3.4 Business Transfers

If TradeAssets is involved in a merger, acquisition, or asset sale, your information may be transferred. We will notify you via email and/or prominent notice on our Platform of any change in ownership or uses of your personal information.

We Never:

  • Sell your personal information to third parties
  • Share your information for third-party marketing without consent
  • Publicly disclose sensitive business or financial information

4. Data Security

We implement industry-standard security measures to protect your personal information:

Technical Safeguards

  • Encryption: SSL/TLS encryption for data transmission; AES encryption for stored data
  • Secure Authentication: Password hashing using bcrypt; optional two-factor authentication
  • Firewalls: Network-level protection against unauthorized access
  • Regular Security Audits: Vulnerability assessments and penetration testing
  • Secure Servers: Hosted in SOC 2 compliant data centers

Organizational Safeguards

  • Access Controls: Limited employee access on need-to-know basis
  • Confidentiality Agreements: All employees sign NDAs
  • Security Training: Regular staff training on data protection
  • Incident Response Plan: Procedures for handling data breaches

Your Responsibility:

While we implement strong security measures, you are responsible for maintaining the confidentiality of your account credentials. Use strong passwords, don't share your account, and log out from shared devices. Report any suspected unauthorized access immediately.

Data Breach Notification: In the unlikely event of a data breach affecting your personal information, we will notify you within 72 hours as required by Malaysian PDPA and provide details on the nature of the breach and remedial steps.

5. Your Rights Under PDPA

Under the Malaysian Personal Data Protection Act 2010, you have the following rights:

Right to Access

Request a copy of your personal data we hold

Right to Correction

Update or correct inaccurate information

Right to Withdraw Consent

Opt-out of marketing communications

Right to Data Portability

Request your data in machine-readable format

How to Exercise Your Rights

To exercise any of these rights:

  1. Email us at privacy@tradeassets.com.my
  2. Include your name, email address, and specific request
  3. We will respond within 21 days (as required by PDPA)
  4. We may request additional information to verify your identity

Data Access Request Fee: RM 10 administrative fee may apply for data access requests, as permitted by PDPA regulations.

6. Cookies & Tracking Technologies

We use cookies and similar technologies to enhance your experience on our Platform.

Types of Cookies We Use

  • Essential Cookies: Required for platform functionality (login, session management)
  • Preference Cookies: Remember your settings (language, dark mode, etc.)
  • Analytics Cookies: Help us understand how users interact with our Platform
  • Marketing Cookies: Track advertising effectiveness (with your consent)

Managing Cookies

You can control cookies through your browser settings:

  • Block all cookies (may affect platform functionality)
  • Delete existing cookies
  • Allow cookies from specific sites only

Note: Some features may not work properly if you disable essential cookies.

7. Data Retention

We retain your personal information for as long as necessary to:

  • Provide our services and maintain your account
  • Comply with legal, accounting, or reporting requirements
  • Resolve disputes and enforce our agreements
  • Prevent fraud and ensure platform security

Retention Periods:

  • Account information: Duration of account + 7 years
  • Transaction records: 7 years (Malaysian business law requirement)
  • Marketing data: Until consent withdrawal + 90 days
  • Usage logs: 2 years for security and analytics

8. Children's Privacy

TradeAssets Malaysia is a B2B platform intended for business users aged 18 and above. We do not knowingly collect personal information from individuals under 18 years of age.

If we become aware that we have collected personal information from someone under 18, we will take steps to delete that information immediately. If you believe we have inadvertently collected such information, please contact us at privacy@tradeassets.com.my.

9. International Data Transfers

Your personal information is primarily stored on servers located in Malaysia. However, some of our service providers may be located outside Malaysia.

When we transfer your data internationally, we ensure:

  • Compliance with PDPA requirements for international transfers
  • Adequate data protection measures are in place
  • Service providers commit to PDPA-equivalent standards
  • Data processing agreements are executed

10. Changes to This Privacy Policy

We may update this Privacy Policy from time to time to reflect changes in our practices, technology, legal requirements, or other factors.

When we make changes:

  • We will update the "Last Updated" date at the top of this policy
  • We will notify you via email for significant changes
  • We may display a prominent notice on the Platform
  • Your continued use of the Platform constitutes acceptance of the updated policy

We encourage you to review this Privacy Policy periodically to stay informed about how we protect your information.

11. Contact Us

If you have questions, concerns, or requests regarding this Privacy Policy or our data practices, please contact our Data Protection Officer:

Email

privacy@tradeassets.com.my

Phone

+603 1234 5678

Mailing Address

Data Protection Officer
TradeAssets Malaysia Sdn Bhd
Level 15, Menara KL
Jalan Sultan Ismail
50250 Kuala Lumpur
Malaysia

PDPA Complaints:

If you are not satisfied with our response to your privacy concerns, you may lodge a complaint with the Personal Data Protection Commissioner of Malaysia at www.pdp.gov.my

Your Trust is Our Priority

We are committed to protecting your privacy and complying with all applicable data protection laws. If you have any concerns, please don't hesitate to reach out.