Legal

Privacy Policy

Effective date: 6 July 2026

Two data relationships

This policy explains how JCSS Consultancy PLT handles personal data for which it is the controller — account, billing, and website data. Where your organisation uploads its own records (staff details, declarations, whistleblowing reports), your organisation is the controller and we act only as a processor on your instructions; see Section 8.

1. Who We Are

Ethytude (the “Platform”) is a product of JCSS Consultancy PLT(“we”, “us”, or “our”). This Privacy Policy describes how we collect, use, disclose, and protect personal data, and the rights available to you under the Malaysian Personal Data Protection Act 2010 (“PDPA”) and other applicable data protection laws.

This policy applies to visitors to our website, individuals who create or administer an account, and other individuals whose personal data we process as a controller. It should be read together with our Terms of Service.

2. Personal Data We Collect

We collect the following categories of personal data:

  • Account data — name, work email address, phone number, job position, department, and organisation details provided at sign-up or by an administrator;
  • Authentication data — hashed passwords, session tokens, email-verification and password-reset tokens;
  • Billing data — subscription plan, seat counts, and billing identifiers. Card details are handled directly by our payment processor and are not stored by us;
  • Usage & log data — actions taken in the Platform, timestamps, IP address, and device/browser information, recorded in our audit and security logs;
  • Communications — messages you send us (e.g. support or legal enquiries).

Personal data contained in your organisation’s compliance records (for example declarants named in a gift declaration, or a whistleblower’s details) is “Customer Data” and is addressed in Section 8.

3. How We Use Personal Data

We use personal data for which we are the controller to:

  • Create, operate, secure, and support your account and the Platform;
  • Authenticate users and maintain an audit trail of security-relevant events;
  • Process subscriptions, seats, and payments, and send billing and service notices;
  • Respond to your enquiries and provide customer support;
  • Detect, prevent, and investigate fraud, abuse, and security incidents;
  • Improve and develop the Platform, using aggregated or de-identified data where practicable;
  • Comply with our legal obligations and enforce our Terms.

We do not sell your personal data, and we do not use Customer Data to train models or for advertising.

5. How We Share Data

We share personal data only as necessary and never sell it. We may disclose it to:

  • Service providers (processors) who help us run the Platform, under contract and only on our instructions (see Section 6);
  • Your organisation’s administrators, who can access and manage the accounts and records within their organisation;
  • Professional advisers, auditors, or insurers, where reasonably necessary;
  • Authorities, regulators, or courts where required by law or valid legal process;
  • A successor entity in connection with a merger, acquisition, reorganisation, or sale of assets, subject to this policy.

6. Third-Party Processors

We rely on trusted third parties to provide the Platform. Each processes personal data only to provide their service to us and is bound by contractual confidentiality and security obligations. Current categories include:

  • Cloud hosting & database — to host the application and store data;
  • File / object storage — to store uploaded documents and evidence;
  • Payment processing — to handle subscriptions and card payments (card data is processed by the payment provider, not stored by us);
  • Email delivery — to send verification, notification, and service emails.

We may change or add providers over time and will update this policy accordingly. A current list of processors is available on request from the contact below.

7. International Data Transfers

Some of our processors may store or process data on servers located outside Malaysia. Where personal data is transferred outside Malaysia, we take reasonable steps to ensure it receives a standard of protection comparable to that under the PDPA, including through contractual safeguards with the recipient.

8. Customer Data & Our Role as Processor

Your organisation controls the compliance records it enters into the Platform, including any personal data those records contain (“Customer Data”). For that data, your organisation is the data user/controller and JCSS Consultancy PLT acts as a data processor, processing it only to provide the Platform and on your documented instructions.

Your organisation is responsible for having a lawful basis to collect that personal data, for issuing its own privacy notices to the individuals concerned (including its employees, business associates, and whistleblowers), and for responding to those individuals’ requests. We will provide reasonable assistance and, where required, enter into a separate Data Processing Agreement.

The Platform’s public whistleblowing channel is designed to allow reports to be made anonymously; where a report is submitted anonymously, the Platform does not record the reporter’s identity.

Our authorised staff may access your organisation’s account and administrative information — such as company profile, registration and tax identifiers, subscription, billing, and usage metadata — where necessary to provide support, manage billing, and administer the Platform. Such access is limited to authorised personnel and is recorded in your organisation’s audit trail. It does not extend to routine browsing of the compliance records within your account.

9. Data Retention & Deletion

We retain personal data for as long as your account is active and as needed to provide the Platform, comply with our legal obligations, resolve disputes, and enforce our agreements.

On termination of a subscription, we retain the organisation’s data for a 30-daywindow during which an administrator may export it. After that period we may permanently delete it. Administrators may also request deletion of the organisation’s account, which starts a guarded 30-day grace period before permanent, irreversible deletion. Certain records (such as billing records and security logs) may be retained for longer where required by law.

10. Security

We implement commercially reasonable technical and organisational measures to protect personal data, including encryption in transit, tenant isolation enforced at the application layer, role-based access with least-privilege controls, hardened authentication, and an immutable audit trail of security-relevant events.

No method of transmission or storage is completely secure, and we cannot guarantee absolute security. If we become aware of a personal-data breach that affects you, we will act in accordance with applicable law.

11. Your Rights Under the PDPA

Subject to applicable law and any exemptions, you may:

  • Request access to the personal data we hold about you;
  • Request correction of inaccurate or incomplete data;
  • Withdraw consent to processing, or limit the processing of your personal data;
  • Request a copy of your account data in a portable format (an export function is provided in-app);
  • Make a complaint about how your data has been handled.

To exercise these rights, contact us at info@simplified-now.com. If your data was provided to the Platform by an organisation (for example your employer), please direct your request to that organisation, which controls that data; we will assist them as their processor.

12. Cookies & Similar Technologies

We use strictly necessary cookies to keep you signed in and to protect against cross-site request forgery. These are essential to operate the Platform and cannot be switched off through our system. We do not use advertising or third-party tracking cookies.

13. Children

The Platform is a business tool intended for use by organisations and their personnel. It is not directed to children, and we do not knowingly collect personal data from individuals under the age of 18.

14. Changes to This Policy

We may update this Privacy Policy from time to time. We will post the revised version on this page with a new effective date and, where changes are material, provide reasonable notice by email or within the Platform. Your continued use after the effective date constitutes acceptance of the updated policy.

15. Contact & Complaints

For any question, request, or complaint about this Privacy Policy or your personal data, contact:

If you are not satisfied with our response, you may lodge a complaint with the Personal Data Protection Commissioner of Malaysia.

This Privacy Policy was last updated on 6 July 2026.

This document is provided for transparency and does not constitute legal advice. JCSS Consultancy PLT recommends obtaining independent legal counsel on your specific obligations.