Privacy Policy
Your privacy is important to us. This policy explains how we collect, use, and protect your personal data.
Last updated: January 26, 2025
1 Introduction
MYLEJA SDN. BHD. (Company Registration No. 202501030490 / 1631902-U), operating under the brand name "Leja", is committed to protecting your privacy and ensuring the security of your personal information.
This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our cloud-based business management platform, including our HR, Finance, and Inventory modules, as well as our website at leja.my.
This policy complies with the Personal Data Protection Act 2010 (PDPA) of Malaysia and reflects our commitment to protecting your personal data.
2 Data We Collect
Personal Information
We may collect the following personal information:
- Contact Information: Name, email address, phone number, mailing address
- Account Information: Username, password (encrypted), profile settings
- Business Information: Company name, registration number, business address
- Employee Data: When you use our HR module, you may input employee information including names, IC numbers, EPF/SOCSO numbers, and salary details
- Financial Data: Invoices, payment records, banking information for transactions
Usage Data
We automatically collect certain information when you use our platform:
- IP address and device information
- Browser type and version
- Pages visited and features used
- Date and time of access
- Error logs and performance data
Cookies and Tracking
We use cookies and similar technologies to enhance your experience. See our Cookies section for more details.
3 How We Use Your Data
We use your personal data for the following purposes:
Service Provision
- To provide and maintain our services
- To process transactions
- To manage your account
Communications
- To send service notifications
- To respond to inquiries
- To send updates (with consent)
Analytics
- To understand usage patterns
- To improve our services
- To develop new features
Legal Compliance
- To comply with Malaysian laws
- To meet regulatory requirements
- To protect our legal rights
4 Data Sharing
We do not sell your personal data. We may share your information with:
Service Providers
Third-party companies that help us operate our services, such as cloud hosting providers (Microsoft Azure), payment processors, and email service providers. These providers are contractually obligated to protect your data.
Government Authorities
We may disclose your information to Malaysian government agencies when required by law, including:
- LHDN (Inland Revenue Board) for e-Invoice submissions
- EPF, SOCSO, and EIS for statutory contributions
- Other regulatory bodies as required by Malaysian law
Business Transfers
In the event of a merger, acquisition, or sale of assets, your personal data may be transferred to the acquiring entity. We will notify you before your data is transferred and becomes subject to a different privacy policy.
5 Data Security
We implement robust security measures to protect your data:
Encryption
TLS 1.3 in transit, AES-256 at restAccess Control
Role-based permissions, MFA supportInfrastructure
Microsoft Azure Southeast AsiaWhile we strive to use commercially acceptable means to protect your personal data, no method of transmission over the Internet or electronic storage is 100% secure. We cannot guarantee absolute security.
6 Your Rights Under PDPA
Under the Personal Data Protection Act 2010 (PDPA) of Malaysia, you have the following rights:
| Right | Description |
|---|---|
| Right to Access | You may request access to your personal data held by us |
| Right to Correction | You may request correction of inaccurate or incomplete data |
| Right to Withdraw Consent | You may withdraw consent for processing of personal data |
| Right to Data Portability | You may request a copy of your data in a portable format |
| Right to Limit Processing | You may request limitation of how we process your data |
To exercise any of these rights, please contact us at privacy@leja.my. We will respond to your request within 21 days as required by PDPA.
8 Data Retention
We retain your personal data for as long as necessary to:
- Provide our services to you
- Comply with legal obligations (e.g., tax records for 7 years as required by Malaysian law)
- Resolve disputes and enforce our agreements
When you terminate your account, we will delete or anonymize your personal data within 90 days, except where retention is required by law.
9 Children's Privacy
Our services are not intended for individuals under the age of 18. We do not knowingly collect personal information from children. If you are a parent or guardian and believe your child has provided us with personal information, please contact us immediately.
10 Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of any material changes by:
- Posting the new Privacy Policy on this page
- Updating the "Last updated" date
- Sending an email notification for significant changes
We encourage you to review this Privacy Policy periodically for any changes.
11 Contact Us
If you have any questions about this Privacy Policy, please contact us:
MYLEJA SDN. BHD.
18, Jalan Sepah Puteri 5/20A,
Sek 5, Kota Damansara,
47810 Petaling Jaya,
Selangor, Malaysia