Privacy & PDPA Notice
This notice explains how VECTOR DYNAMIC SDN. BHD. processes data for the Payroll Control diagnostic and requirement-review request.
Effective 15 August 2026 · Version pdpa-v1-2026-08-151. Who we are, data sources and processing purposes
VECTOR DYNAMIC SDN. BHD. (202401039918) is the data controller for this workflow. Data comes directly from you through this site or from allow-listed entry, referrer and campaign-attribution information supplied by your browser. We use it to generate a diagnostic recommendation and management Business Case, save and respond to a requirement-review request, secure the service, and perform non-PII analytics or advertising measurement only when you make a separate choice.
2. Information processed and whether it is required
The diagnostic processes six operational answers: employee band, payroll method, attendance method, complexity, main problem and timeline. You may complete it without saving or providing identity details. To save a full review, name, company and role are required; industry is optional. A Quick B2B handoff also requires industry, employee band and main problem. Without required details or consent, we cannot save the request or offer a WhatsApp handoff. We do not request employee names, IDs/passports, salary amounts, bank, medical or disciplinary data, or Payroll files.
3. How the diagnostic, lead and WhatsApp workflow operates
The server calculates the diagnostic result authoritatively and revalidates answers and consent on save, with CSRF, bot, rate-limit, idempotency and transaction controls. Contact identity is encrypted at the application layer and raw IP addresses are not stored in the lead database. A failed save never produces a WhatsApp handoff. Only after a successful save and a second explicit click may a prefilled WhatsApp page open; no message is sent automatically.
4. Contact consent and tracking choices
Requirement-review consent is stored with this notice version, locale and UTC time and may be withdrawn through a PDPA request. Analytics and advertising are separate choices that can be changed at any time and both default to denied. Google Tag Manager may load only after the relevant choice is granted; GA4 and Meta Pixel may run only through GTM. Name, phone, email, company, role, address, free text, lead reference, exact headcount, diagnostic answers and form payloads are not sent to GTM, GA4 or Meta.
5. Disclosures and service providers
Data is processed only as needed by authorised VECTOR personnel and bound providers supporting website/VPS hosting, databases, encrypted backup, security, technical support and requested communications. Google/Meta participate only after the relevant tracking consent; WhatsApp/Meta receive only the content you choose to send after a successful save and handoff click. We do not sell personal data and disclose it to authorities only where permitted or required by law.
6. Security and cross-border processing
Controls include HTTPS, CSRF, contact-field encryption, rate limiting, honeypot, idempotency, secrets outside Git, a least-privilege database, restricted backups, and application logs that exclude form payloads and PII. Some hosting, Google, Meta or WhatsApp services may process data outside Malaysia; appropriate contractual, access, security and cross-border safeguards will be applied under applicable law. No network or storage system can guarantee absolute security.
7. Retention, deletion and exceptions
Lead and contact data are normally kept for 24 months (730 days) after the last meaningful interaction and then securely deleted on schedule. If applicable law, accounting records, a dispute, fraud or a security investigation requires longer retention, the exception is documented, use and access are restricted, and the data is deleted when the exception ends. Backups follow the approved expiry policy; restoring a backup does not restart the retention period.
8. Your rights and how to make a request
Subject to applicable law, you may request access, correction, withdrawal of consent, restriction or objection to processing likely to cause damage or distress, an end to direct marketing, or deletion. Email vector@vector-dynamic.com with the subject PDPA Request and enough information to verify the request; do not send employee Payroll data. Withdrawal or deletion may be limited by legal, accounting or dispute-retention obligations.
9. Updates, effective date and contact
Effective date: 15 August 2026. Version: pdpa-v1-2026-08-15. Material changes to purposes, data categories, providers, retention or consent will increment the version and, where applicable, seek consent again. Privacy contact: vector@vector-dynamic.com (subject: PDPA Request).