General Privacy Statement

WorkLabApps collects and processes personal data necessary to deliver professional application development, integration and support services. We process information in a manner consistent with applicable data protection laws and industry best practices. Our practices are designed to ensure confidentiality, integrity and availability of client and user data while enabling operational requirements for project delivery.

28-01-2026 WorkLabApps [email protected]

Definitions

This section clarifies the terminology used throughout the policy to describe categories of data, processing activities and the parties involved in service delivery.

Personal data means any information relating to an identified or identifiable natural person, such as names, contact details, identifiers, or data that can be reasonably linked to an individual when combined with other information.
Processing refers to any operation performed on personal data, including collection, recording, organization, storage, adaptation, retrieval, consultation, use, disclosure, erasure and destruction.
User refers to any individual whose personal data is collected by WorkLabApps in the context of providing development, deployment or support services; this includes client contacts, end users of deployed applications, and subcontractor personnel.
Service describes the professional development, implementation, integration and maintenance of business applications provided by WorkLabApps to corporate clients and partners.
Cookies are small text files placed on a device to store preferences, session identifiers and usage information. They support functionality, security and analytics for web properties and client portals.

Data We Collect

We collect information provided directly by users, data generated automatically during use of our services, and certain data from third parties where necessary to perform contracted services. Collection is limited to what is adequate and relevant for each purpose.

Data Provided by Users

When engaging with WorkLabApps, users may supply personal data necessary for onboarding, project delivery, support and billing.

  • Contact details: name, business email address, business telephone number and job title.
  • Company information: legal entity name, billing address and business registration identifiers (for example Business ID 444671878886).
  • Project-related inputs: requirements documents, user lists, role descriptions and sample datasets required for development and testing.
  • Credentials and access information provided by the client for integration testing, stored securely and used only for project-related activities.
  • Support communications and feedback supplied via email, ticketing systems or telephone during the engagement.
  • Billing and payment information used to process invoices and related business records.

Automatically Collected Data

Certain technical and usage information is collected automatically to maintain services, improve performance and ensure security. This data does not typically include sensitive personal details.

  • Device and browser information when accessing client portals (device type, OS, browser version).
  • IP addresses, timestamps and session identifiers required for security logging and troubleshooting.
  • Usage metrics and event logs within applications to diagnose issues and improve functionality.
  • Performance telemetry and error reports to support maintenance and incident response.
  • Cookie identifiers and preferences used to manage sessions and user settings.
  • Aggregated analytics used for product development and service optimization, with personal identifiers removed where feasible.

Third-Party Sources

In some cases we obtain information from third-party sources to verify data, support integrations or fulfill contractual obligations. We only obtain what is necessary and rely on lawful transfer mechanisms.

  • Authentication and identity providers when users authenticate via corporate single sign-on solutions.
  • Payment processors and invoicing partners for transaction reconciliation and fraud prevention.
  • Subcontractors and hosting providers that deliver infrastructure, analytics or support services on our behalf.

Purposes of Processing

We process personal data for specific, limited and documented purposes necessary for service delivery, legal compliance and security.

  • Provisioning and operation of business applications, including development, testing and deployment activities.
  • Customer support, incident management and technical troubleshooting.
  • Billing, invoicing and business record-keeping required for contractual performance.
  • Security monitoring, threat detection and fraud prevention to maintain service integrity.
  • Compliance with legal obligations, audits and regulatory requests applicable to our business operations.
  • Improvement of services through aggregated analytics and product development insights.
  • Communications about project status, service changes and important operational notices.
  • Data portability and exports when requested by an authorized client under agreed-upon procedures.

Legal Bases for Processing

Where applicable under data protection laws such as GDPR, we rely on one or more lawful bases to process personal data including contractual necessity and legitimate interests.

  • Performance of a contract: processing necessary to deliver development and support services requested by a client.
  • Legal compliance: processing required to satisfy statutory obligations and regulatory requirements.
  • Legitimate interests: processing for security, fraud prevention and improvement of services after a careful assessment of user rights.
  • Consent: where specific processing activities (such as certain marketing communications) require explicit consent, we will request it separately and record consent choices.

Data Subject Rights (GDPR Framework)

Under data protection frameworks such as the GDPR, data subjects have specific rights regarding their personal data. We maintain processes to respond to valid requests and to support data protection principles.

  • Right of access — request a copy of personal data we hold about you.
  • Right to rectification — request correction of inaccurate or incomplete data.
  • Right to erasure — request deletion of personal data where processing is no longer necessary and no overriding legal grounds exist.
  • Right to restriction of processing — request limitation of processing in certain circumstances.
  • Right to data portability — request transfer of data to another controller in a commonly used format when applicable.
  • Right to object — object to processing based on legitimate interests or direct marketing in line with applicable law.

Cookies and Tracking

We use cookies and similar technologies to enable essential functionality, enhance experience and gather performance metrics. Cookie usage is limited to necessary and performance categories unless consent is obtained for marketing cookies.

Types of cookies used include session cookies for logins, persistent cookies for user preferences, security cookies for fraud protection, and analytics cookies for aggregated performance insights.

Cookies are categorized as strictly necessary, performance/analytics and optional marketing; only strictly necessary cookies are required for core functionality.

Users can manage cookie preferences through their browser settings or via consent controls presented on our web portals. Disabling certain cookies may affect functionality of client portals.

Detailed cookie settings and consent management are available in our Cookie Policy.

Data Sharing and Recipients

We share personal data only with parties required to fulfill contractual obligations or as required by law, and under strict contractual controls to protect your information.

  • Service providers and subcontractors engaged to deliver hosting, analytics, payment processing and support services under written agreements.
  • Professional advisers such as auditors or legal advisors when necessary to comply with legal obligations or to protect legal interests.
  • Law enforcement or regulatory authorities when disclosure is required by applicable law or court order.
  • Affiliates and partners for legitimate business operations where appropriate safeguards are in place.
  • Potential acquirers or supporter in the event of a business transaction, subject to confidentiality obligations.
  • Clients themselves when they request exports or reports related to their projects and user data under the terms of the contract.

International Transfers

WorkLabApps may transfer personal data to jurisdictions outside the country of collection to provide services, host infrastructure or manage backups. Transfers are carried out in accordance with applicable law and with appropriate safeguards.

Where transfers occur we use mechanisms such as adequacy decisions, standard contractual clauses, encryption and access controls to protect personal data and ensure an adequate level of protection consistent with Malaysian and international standards.

Data Retention

We retain personal data only as long as necessary for the purposes for which it was collected, including to meet contractual and legal obligations. Retention periods depend on the type of data and the nature of the service; for example, project records and business documentation are retained in accordance with accounting and tax regulations, while support logs are retained for operational troubleshooting and then purged according to our retention schedules.

We retain account records and associated personal data for as long as the account is active and for a period necessary to comply with legal obligations and legitimate business purposes. After account closure we generally retain basic account records for up to 24 months for fraud prevention, tax and accounting compliance, and to resolve disputes.

Messages platform via WorkLabApps (including support tickets and in-app messages) are retained to provide continuity of service and for quality assurance. Typical retention for message content is 12 months, after which data may be archived or deleted in accordance with our data minimization policy, unless required otherwise for legal reasons.

Operational logs and diagnostic records (access logs, system events, error reports) are retained for security monitoring, incident response and service improvement. Standard retention is up to 12 months, with aggregated or anonymized logs kept longer to support analytics and product development.

When you request deletion of personal data, we will verify the request and remove data from active systems within 30 days where practicable. Residual copies may persist in backup media for up to 90 days for disaster recovery and integrity checks, after which they are deleted or rendered irreversibly anonymized.

Data Security and Protection

WorkLabApps applies a layered security approach to protect personal and business data. We combine technical measures, administrative controls and policies to reduce risks of unauthorized access, disclosure and misuse. Security practices are reviewed regularly and aligned with recognized industry standards to maintain confidentiality, integrity and availability of data.

  • Encryption in transit (TLS) and encryption at rest for sensitive data stores where applicable.
  • Role-based access control, least-privilege principles and regular access reviews for personnel and service accounts.
  • Ongoing vulnerability management, periodic security assessments, logging and incident response procedures.

User Rights and How to Exercise Them

Depending on applicable law, individuals have certain rights regarding their personal data. WorkLabApps provides mechanisms to exercise these rights and will respond to verified requests in accordance with legal requirements.

  • Right to access: request a copy of personal data we hold about you.
  • Right to rectification: request correction of inaccurate or incomplete personal data.
  • Right to erasure: request deletion of personal data where processing is no longer necessary and no legal basis prevents deletion.
  • Right to restriction: request limitation of processing while accuracy or legal issues are being resolved.
  • Right to data portability: where applicable, receive personal data in a structured, commonly used and machine-readable format.
  • Right to object: object to processing based on legitimate interests or direct marketing where allowed by law.
  • Right to withdraw consent: withdraw previously given consent for processing at any time, without affecting processing done prior to withdrawal.
  • Right to lodge a complaint with a supervisory authority if you consider our processing does not comply with applicable law.

How to Submit a Rights Request

To exercise your privacy rights, submit a request by email to [email protected] or by postal mail to our registered address. Include your name, relevant account details, a clear description of the request and a copy of an identity document for verification when required. We will take reasonable steps to confirm your identity before fulfilling requests.

[email protected]

We aim to acknowledge requests promptly and to respond substantively within 30 days of receipt. If more time is needed due to complexity or volume, we will notify you and provide an estimated response timeframe.

Marketing Communications

WorkLabApps may send marketing related to our services, events and product updates if you have opted in or if permitted by applicable law. Marketing messages include clear information on how to unsubscribe and are sent only in line with your consent and communication preferences.

You can opt out of marketing communications at any time via the unsubscribe link in emails or by updating your preferences in your account. You may also contact us at [email protected] to update marketing preferences.

Children's Privacy

Our services are not directed to children under the age of 16. We do not knowingly collect personal data from minors below this age. If we become aware that we have collected personal data from a child under 16 without appropriate consent, we will take steps to delete the information promptly.

Third-Party Links and Services

WorkLabApps may link to or integrate with third-party services. These services have their own privacy practices and terms. We are not responsible for third-party privacy practices; review their privacy policies before providing personal data to them.

Changes to This Privacy Policy

We may update this privacy statement to reflect changes in our practices, legal requirements or service features. Material changes will be posted with an updated effective date. This version is effective as of 07-03-2026.