Legal
Effective date: 6 July 2026
Two data relationships
This policy explains how JCSS Consultancy PLT handles personal data for which it is the controller — account, billing, and website data. Where your organisation uploads its own records (staff details, declarations, whistleblowing reports), your organisation is the controller and we act only as a processor on your instructions; see Section 8.
Contents
Ethytude (the “Platform”) is a product of JCSS Consultancy PLT(“we”, “us”, or “our”). This Privacy Policy describes how we collect, use, disclose, and protect personal data, and the rights available to you under the Malaysian Personal Data Protection Act 2010 (“PDPA”) and other applicable data protection laws.
This policy applies to visitors to our website, individuals who create or administer an account, and other individuals whose personal data we process as a controller. It should be read together with our Terms of Service.
We collect the following categories of personal data:
Personal data contained in your organisation’s compliance records (for example declarants named in a gift declaration, or a whistleblower’s details) is “Customer Data” and is addressed in Section 8.
We use personal data for which we are the controller to:
We do not sell your personal data, and we do not use Customer Data to train models or for advertising.
Under the PDPA, we process personal data on the basis of your consent and/or because processing is necessary for the performance of our contract with you, for our legitimate business interests in operating and securing the Platform, or to comply with a legal obligation. Where we rely on consent, you may withdraw it at any time (see Section 11), though this may affect our ability to provide the service.
We rely on trusted third parties to provide the Platform. Each processes personal data only to provide their service to us and is bound by contractual confidentiality and security obligations. Current categories include:
We may change or add providers over time and will update this policy accordingly. A current list of processors is available on request from the contact below.
Some of our processors may store or process data on servers located outside Malaysia. Where personal data is transferred outside Malaysia, we take reasonable steps to ensure it receives a standard of protection comparable to that under the PDPA, including through contractual safeguards with the recipient.
Your organisation controls the compliance records it enters into the Platform, including any personal data those records contain (“Customer Data”). For that data, your organisation is the data user/controller and JCSS Consultancy PLT acts as a data processor, processing it only to provide the Platform and on your documented instructions.
Your organisation is responsible for having a lawful basis to collect that personal data, for issuing its own privacy notices to the individuals concerned (including its employees, business associates, and whistleblowers), and for responding to those individuals’ requests. We will provide reasonable assistance and, where required, enter into a separate Data Processing Agreement.
The Platform’s public whistleblowing channel is designed to allow reports to be made anonymously; where a report is submitted anonymously, the Platform does not record the reporter’s identity.
Our authorised staff may access your organisation’s account and administrative information — such as company profile, registration and tax identifiers, subscription, billing, and usage metadata — where necessary to provide support, manage billing, and administer the Platform. Such access is limited to authorised personnel and is recorded in your organisation’s audit trail. It does not extend to routine browsing of the compliance records within your account.
We retain personal data for as long as your account is active and as needed to provide the Platform, comply with our legal obligations, resolve disputes, and enforce our agreements.
On termination of a subscription, we retain the organisation’s data for a 30-daywindow during which an administrator may export it. After that period we may permanently delete it. Administrators may also request deletion of the organisation’s account, which starts a guarded 30-day grace period before permanent, irreversible deletion. Certain records (such as billing records and security logs) may be retained for longer where required by law.
We implement commercially reasonable technical and organisational measures to protect personal data, including encryption in transit, tenant isolation enforced at the application layer, role-based access with least-privilege controls, hardened authentication, and an immutable audit trail of security-relevant events.
No method of transmission or storage is completely secure, and we cannot guarantee absolute security. If we become aware of a personal-data breach that affects you, we will act in accordance with applicable law.
Subject to applicable law and any exemptions, you may:
To exercise these rights, contact us at info@simplified-now.com. If your data was provided to the Platform by an organisation (for example your employer), please direct your request to that organisation, which controls that data; we will assist them as their processor.
The Platform is a business tool intended for use by organisations and their personnel. It is not directed to children, and we do not knowingly collect personal data from individuals under the age of 18.
We may update this Privacy Policy from time to time. We will post the revised version on this page with a new effective date and, where changes are material, provide reasonable notice by email or within the Platform. Your continued use after the effective date constitutes acceptance of the updated policy.
For any question, request, or complaint about this Privacy Policy or your personal data, contact:
Email: info@simplified-now.com
If you are not satisfied with our response, you may lodge a complaint with the Personal Data Protection Commissioner of Malaysia.