1. Who we are
This Privacy Policy describes how THEBRG Enterprise (Business Registration No. 003120480-W), a business registered in Malaysia, trading under the brand NAX ("NAX", "we", "us", "our"), collects, uses, discloses and protects personal data in connection with the website nax.com.my and the services we provide.
This Policy is published in accordance with the Personal Data Protection Act 2010 of Malaysia ("PDPA") and, where applicable, the EU General Data Protection Regulation ("GDPR") and other relevant data protection laws.
2. Information we collect
We collect the following categories of information:
- Contact data — name, email address, phone number, company name and role when you contact us, request a proposal or subscribe.
- Project data — information you share with us to scope, deliver and support an engagement, including credentials and content you grant us access to.
- Technical data — IP address, browser type, device identifiers, referring URL, pages visited and approximate location, collected automatically by our hosting and analytics providers.
- Cookies & similar technologies — strictly necessary cookies for site operation and, with consent where required, analytics cookies to understand usage.
- Billing data — company name, billing address, tax identifiers and transaction records for invoicing.
3. How we use your information
We process personal data for the following purposes:
- Responding to enquiries and providing the services you request.
- Delivering, supporting and improving our products and engagements.
- Issuing invoices, collecting payment and meeting tax and accounting obligations.
- Sending service updates, security notices and — only with your consent — marketing communications.
- Detecting, preventing and addressing fraud, security incidents and abuse.
- Complying with applicable laws and lawful requests from authorities.
4. Legal bases
Where the GDPR applies, we rely on the following legal bases: performance of a contract, our legitimate interests in operating and growing the business, your consent, and compliance with legal obligations. Under the PDPA, we rely on your consent and the applicable exemptions in Section 39 of the Act.
5. Sharing & sub-processors
We do not sell personal data. We share information only with carefully selected sub-processors who help us run the business — hosting, email, analytics, accounting, payment processing and CRM providers — under written agreements that require them to protect the data and use it only on our instructions.
6. International transfers
Because we serve clients worldwide, your information may be processed in Malaysia, Singapore, the European Union, the United Kingdom, the United States and other countries where our sub-processors operate. We rely on standard contractual safeguards and the recipient country's adequacy where available.
7. Retention
We retain personal data only for as long as necessary to fulfil the purposes for which it was collected, including any legal, accounting or reporting requirements. Project data is typically retained for seven (7) years from project completion to meet Malaysian tax and audit requirements, after which it is deleted or anonymised.
8. Security
We apply organisational and technical measures appropriate to the risk — including encryption in transit and at rest, least-privilege access controls, audit logging, multi-factor authentication, regular backups and incident response procedures. No system is completely secure, and we ask you to also do your part by keeping your account credentials confidential.
9. Your rights
You have the right to access, correct, update, withdraw consent for or request deletion of your personal data, subject to the PDPA and applicable laws. You may also lodge a complaint with the Personal Data Protection Department of Malaysia or your local supervisory authority.
10. Contact us
Privacy questions and requests can be sent to hello@nax.com.my. Postal address: THEBRG Enterprise (003120480-W), Kuala Lumpur, Malaysia.
11. Updates
We may update this Policy from time to time. The "Last updated" date at the top reflects the latest revision. Material changes will be communicated through the website or directly where appropriate.