Rebana — Privacy Notice
Canang Technologies Sdn Bhd · Registration No. ⚠ [No. Pendaftaran SSM]
Status: DRAFT for legal review — not yet published, not legal advice.
Last updated: ⚠ [date of publication]
1. Who we are and what this notice covers
Canang Technologies Sdn Bhd ("Canang", "we", "us") builds and operates Rebana, a suite of applications for Malaysian local authorities (PBT) and public agencies.
This notice explains how Canang, as data user (data controller), handles personal data about you when you:
- visit our websites, https://rebana.io and https://rebana.canang.com.my (the "Site");
- contact us, ask for a demo, fill in an enquiry or pilot-application form, or message us on WhatsApp;
- meet us at an event, briefing or booth;
- receive our newsletter or other updates;
- deal with us as an officer of a customer, prospective customer or partner organisation; or
- apply to work with us or to join one of our programmes.
What this notice does not cover. When a local authority or agency uses the Rebana applications — for licences, rentals, complaints, payroll, bookings and so on — the personal data of residents, traders, staff and other users in those applications belongs to that organisation. The organisation is the data user; Canang handles that data only as its data processor, on its instructions, under a contract (our Data Processing Addendum). If you are a resident or officer using a Rebana application, the organisation's own privacy notice applies, and requests about that data should go to the organisation. If you send such a request to us, we will forward it to the organisation.
2. Personal data we collect
Information you give us
- Contact and role details — name, job title, organisation, department, official e-mail address, office and mobile phone numbers.
- Enquiry content — what you write to us by e-mail, WhatsApp or form, and any attachments. Please do not send us personal data of your residents or staff, or classified information.
- Form responses — answers to our readiness checks and pilot-application forms (for example, which systems your organisation uses today and what it wants to improve).
- Event details — details you give us at an event, including the tag on a WhatsApp prefill (such as
SDARA26-…) that tells us which event and interest you came from. - Meeting and account records — for officers of customer and prospective customer organisations: notes of meetings, your role in a procurement or project, and correspondence with you.
- Application details — if you apply to work with us or to join a programme: your CV, employment and service history, qualifications, references, and details needed for conflict-of-interest and cooling-off checks.
- Newsletter preferences — your e-mail address and whether you have unsubscribed.
Information collected automatically
- Server logs. Our web servers record each request: IP address, date and time, the page requested, referring page, and browser user-agent. We use these only to operate and secure the Site. ⚠ [retention period, §8]
- No cookies, no analytics, no advertising trackers. The Site does not set cookies and does not run Google Analytics or any other analytics or advertising script. If that changes, we will update this notice before it happens.
- Newsletter e-mails ⚠ — confirm whether the sending tool records opens or link clicks; if it does, say so here.
Sensitive personal data. We do not ask for sensitive personal data (as defined in PDPA s.4, such as health, religious or political information). Please do not send it to us.
3. Why we use it
We use personal data to:
- reply to your enquiry, arrange and run demos and briefings, and follow up;
- assess and prepare proposals, quotations and pilot or programme applications;
- manage our relationship with customer and partner organisations — contracts, onboarding, support, invoicing and collection;
- send you updates and newsletters about Rebana, where you have asked for them or where you are an officer of an organisation we work with (you can opt out at any time — §6);
- assess job and programme applications, including the integrity checks required of us (§4);
- operate, secure and troubleshoot the Site;
- meet our legal obligations and our anti-corruption procedures under section 17A of the Malaysian Anti-Corruption Commission Act 2009, and establish or defend legal claims; and
- produce aggregated, anonymised statistics that do not identify you.
We do not sell personal data. We do not use enquiry contents or form responses to train artificial-intelligence models.
Is providing it obligatory? No, except that we need your name and a contact channel to reply to you, and the details listed for applications to assess them. If you do not provide them we may not be able to respond or proceed.
4. Who we disclose it to
We disclose personal data only as needed for the purposes in §3, to:
- our staff and the members of our programmes (for example Felo Rebana) who need it for their work, bound by confidentiality;
- service providers who handle data for us, currently: ⚠ [confirm list] — our hosting providers for the Site (⚠ [DigitalOcean — region] and ⚠ [cPanel host for rebana.io]); our e-mail provider ⚠ [provider]; Notion (forms); WhatsApp / Meta (messages you send to our WhatsApp number); and our newsletter sending tool ⚠ [provider];
- your own organisation, where you contact us on its behalf (for example, copying your head of department);
- professional advisers, auditors and insurers;
- authorities, where the law requires it — including the Malaysian Anti-Corruption Commission, the Personal Data Protection Commissioner, the police or a court; and
- a successor to our business, if Canang or part of it is merged or sold, subject to this notice.
We will not name you, or your organisation, as a customer, pilot partner or reference in any public material without the organisation's written consent.
5. Where it is held
Personal data we hold is stored ⚠ [in Malaysia / in Singapore — confirm the hosting regions]. Some of our service providers (Notion, Meta, ⚠ [e-mail provider]) process data outside Malaysia. We transfer personal data outside Malaysia only as allowed by section 129 of the PDPA — where the destination has laws substantially similar to the PDPA or ensures an adequate level of protection, or on another ground the section allows — and we require those providers to protect it.
6. Your rights and choices
Under the PDPA you may:
- access the personal data we hold about you and ask for a copy (PDPA s.30);
- ask us to correct it if it is inaccurate, incomplete, misleading or out of date (s.34);
- withdraw consent to our processing (s.38), in which case we will stop unless another lawful ground applies;
- ask us to stop direct marketing to you (s.43) — every newsletter has an unsubscribe link, or write to us;
- ask us to transmit your personal data to another data user, where the PDPA's data portability right applies and it is technically feasible; and
- complain to the Personal Data Protection Commissioner (Jabatan Perlindungan Data Peribadi).
Send requests to our Data Protection Officer (§10). We will respond within 21 days, as the PDPA requires. We may ask you to verify your identity, and may charge the fee the regulations allow for a copy of your data.
7. Security
We protect personal data with administrative, technical and physical measures proportionate to the risk — including encrypted connections, access limited to people who need it, and logging of administrative access. If a personal data breach occurs, we will notify the Personal Data Protection Commissioner and, where the breach is likely to cause you significant harm, notify you, within the time limits set under the PDPA.
No system is perfectly secure, and e-mail and messaging sent to us travel over networks we do not control.
8. How long we keep it
We keep personal data only as long as needed for the purpose we collected it for, and then delete or anonymise it:
| Data | Retention ⚠ |
|---|---|
| Enquiries and demo requests that do not lead to a relationship | ⚠ [24 months after last contact] |
| Customer and partner contact records | For the relationship, then ⚠ [7 years] for audit and tax |
| Event and form responses | ⚠ [24 months] |
| Job and programme applications not taken forward | ⚠ [12 months], unless you ask us to keep them longer |
| Server logs | ⚠ [90 days] |
| Newsletter list | Until you unsubscribe; we keep a suppression record so we do not e-mail you again |
9. Children
The Site is for public-sector and business audiences. It is not directed at children, and we do not knowingly collect personal data from anyone under 18.
10. Contact us — Data Protection Officer
Data Protection Officer, Canang Technologies Sdn Bhd ⚠ [registered address] E-mail: ⚠ [dpo@canang.com.my] General enquiries: us@canang.com.my
11. Changes to this notice
We will publish any change on this page with a new "Last updated" date. Where a change materially affects how we use personal data we already hold, we will tell you before it takes effect.
12. Language
This notice is published in Bahasa Malaysia and English. ⚠ [If the two differ, the Bahasa Malaysia version prevails.]
Rebana