(PDPA/GDPR) - We’ve updated our privacy policy (Policy) | QuickHR Malaysia

Privacy & Data Protection
Notice (PDPA)

Guidelines on personal data handling within the QuickHR platform.

Enable Business Sdn. Bhd. (“QuickHR”, “we”, “us”, “our”)
(Company Registration No.: 202001007429)

  • 1. Scope of This Notice

    This Data Protection Notice (“Notice”) explains how QuickHR collects, uses, discloses, and safeguards personal data in accordance with the Personal Data Protection Act 2010 (Malaysia) (“PDPA”).

    This Notice applies to:

    • 1. QuickHR as a Data User (Controller) — for individuals who interact directly with QuickHR (e.g., job applicants, employees, visitors, enquiries); and
    • 2. QuickHR as a Data Processor — for personal data processed on behalf of our customers using the QuickHR HRMS platform.

    Where QuickHR processes personal data on behalf of a customer, the customer remains the party responsible as the data controller/employer, and processing is governed by the applicable contract and Data Processing Addendum (“DPA”).

    QuickHR processes personal data only where consent has been obtained, where processing is necessary for the provision of services, or where otherwise permitted under the PDPA and applicable Malaysian law.

    In certain circumstances, QuickHR may process Personal Data without consent where permitted under the PDPA, including for legal compliance, fraud prevention, or security incident response.

  • 2. Personal Data We Collect

“Personal Data” refers to any information relating to an identified or identifiable individual, including but not limited to:

  • Name, contact details, identification details
  • Employment and payroll information (where provided by customers)
  • Account credentials and usage data
  • Support communications
  • System logs and security monitoring data

QuickHR does not use personal data for direct marketing without consent, and individuals may opt out of marketing communications at any time.

Certain Personal Data may constitute “Sensitive Personal Data” under the PDPA (including health-related or biometric identifiers), and will only be processed where lawful and necessary for service delivery.

Biometric processing will only occur where enabled by Customer and with lawful employee authorisation.

  • 3. How We Collect Personal Data

    Personal data may be collected through:

    • Use of our websites, platform, or mobile services
    • Customer onboarding and contractual engagement
    • Support requests, emails, live chat, or calls
    • Job applications and recruitment processes
    • Lawful regulatory or compliance obligations

    If you provide personal data relating to another individual, you confirm that you have obtained the necessary authorisation to do so.

    The Customer remains solely responsible for obtaining any required employee notice, consent, and lawful basis for biometric processing under the PDPA.

  • 4. Purposes of Processing

  • 5. Data Controller vs Processor Roles

    Where QuickHR processes employee or workforce data uploaded by customers:

    • The customer/employer remains the Data Controller
    • QuickHR acts only as a Data Processor, processing such data strictly to provide the Services

    Customers are responsible for ensuring they have obtained lawful consent or authority to process employee data under the PDPA.

  • 6. Disclosure to Third Parties and Sub-Processors

  • 7. Cross-Border Transfers

    QuickHR primarily processes customer platform data within approved operational environments.

    QuickHR’s primary hosting environment for Malaysian customers is Amazon Web Services (AWS) Singapore.

    By using the Services, Customers acknowledge that Personal Data will be processed and stored in Singapore by default, subject to comparable protection safeguards under Section 129 PDPA.

    Where cross-border processing is required for:

    • Disaster recovery
    • Business continuity
    • Approved Sub-Processors

    QuickHR ensures that any cross-border transfer is made only where a comparable standard of protection is maintained, including through contractual safeguards, vendor due diligence, and technical security controls consistent with PDPA requirements.

  • 8. Protection of Personal Data

  • QuickHR maintains appropriate administrative, technical, and organisational safeguards including

    • Encryption in transit and at rest
    • Role-based access controls
    • Multi-factor authentication for administrative access
    • Security monitoring and audit logging
    • Regular vulnerability testing
    • Incident response procedures

    While no system can be guaranteed fully secure, QuickHR takes reasonable and proportionate measures aligned with industry best practices.

  • 9. Retention and Deletion

  • QuickHR retains personal data only for as long as necessary for contractual, operational, compliance, and lawful business purposes, after which it will be securely deleted or anonymised in accordance with standard retention cycles.

    Following termination:

    • Customer data may be exported within a defined post-termination period
    • Data is deleted from active systems in accordance with standard retention and encrypted backup cycles
    • Residual encrypted backups may persist temporarily until overwritten in the ordinary course

    QuickHR is not obligated to provide deletion certificates unless expressly agreed in writing.

    Deletion is subject to technical limitations inherent in encrypted backup systems, and residual copies may persist until overwritten in the ordinary course of operations.

  • 10. Access, Correction, and Withdrawal of Consent

  • Individuals have the right under the PDPA to:

    • request access to their personal data;
    • request correction of inaccurate or incomplete personal data; and
    • withdraw consent, subject to legal and contractual restrictions.

    Requests may be submitted to our Data Protection Officer. QuickHR will respond within a reasonable timeframe, generally within twenty-one (21) business days, subject to verification of identity and applicable PDPA exceptions.

    For HRMS platform users (employees whose data is controlled by an employer), such requests should be directed to the relevant employer (the Data Controller). QuickHR will provide reasonable assistance to the Customer where required under the DPA.

  • 11. Complaints and Queries

  • If you have concerns about how your personal data is handled, you may contact our Data Protection Officer. We will investigate and respond in accordance with applicable PDPA requirements.

  • 12. Data Protection Officer

  • For enquiries or requests:

    Data Protection Officer
    Enable Business Sdn. Bhd.
    Email: dpo@quickhr.co

  • 13. Updates to This Notice

  • QuickHR may update this Notice from time to time. The latest version will always be published on our website with the effective date stated above.

Close