Privacy & PDPA Notice
This notice explains how VECTOR DYNAMIC SDN. BHD. processes data for the Payroll Control diagnostic and requirement-review request.
Effective 4 September 2026 · Version pdpa-v1.4-2026-09-041. Who we are, data sources and processing purposes
VECTOR DYNAMIC SDN. BHD. (202401039918) is the data controller for this workflow. Data comes directly from you through this site or from allow-listed entry, referrer and campaign-attribution information supplied by your browser. We use it to generate a diagnostic recommendation and management Business Case, save and respond to a requirement-review request, secure the service, and perform non-PII analytics or advertising measurement under the default tracking preference; you can turn either choice off from the footer at any time.
2. Information processed and whether it is required
The diagnostic processes six operational answers: employee band, payroll method, attendance method, complexity, main problem and timeline. You may complete it without saving or providing identity details. To save a full review, name, company, email address, phone number and role are required; industry is optional. A Quick B2B handoff also requires industry, employee band and main problem. Without required details or consent, we cannot save the request or offer a WhatsApp handoff. We do not request employee names, IDs/passports, salary amounts, bank, medical or disciplinary data, or Payroll files.
3. How the diagnostic, lead, owner notification and WhatsApp workflow operates
The server calculates the diagnostic result authoritatively and revalidates answers and consent on save, with CSRF, bot, rate-limit, idempotency and transaction controls. Name, company, email and phone are encrypted at the application layer, and raw IP addresses are not stored in the lead database. After a successful save, the system may send an authorised VECTOR owner a Google Workspace email containing contact details, lead reference, qualification status, language, entry mode, role and industry; diagnostic answers and employee or Payroll data are excluded. An SMTP failure does not undo the saved lead and is retried safely. Only after a successful save and a second explicit click may a prefilled WhatsApp page open; no message is sent automatically.
4. Contact consent and tracking choices
Requirement-review consent is stored with this notice version, locale and UTC time and may be withdrawn through a PDPA request. Analytics and advertising are separate choices that can be changed at any time. Both are allowed by default on a first visit and the choices panel is not shown automatically; you can turn either off at any time through Change tracking choices in the footer. Analytics enables GTM/GA4 and stores strictly filtered UTM, referring-site and first/last-touch attribution. Advertising enables Meta Pixel and, when a lead is saved, allows the server to encrypt gclid/gbraid/wbraid/fbclid and to send _fbp/_fbc browser or ad-click identifiers plus the Lead/QualifiedLead stage through Meta Conversions API for attribution and measurement. Turning off a category clears its saved browser attribution and prevents that category from being submitted with a lead. Name, phone, email, company, role, address, free text, lead reference, exact headcount, diagnostic answers and form payloads are not sent to GTM, GA4 or Meta.
5. Disclosures and service providers
Data is processed only as needed by authorised VECTOR personnel and bound providers supporting website/VPS hosting, databases, encrypted backup, security, technical support and requested communications. Google Workspace Email may process a lead-contact notification sent to the VECTOR owner. Google Analytics/Tag Manager and Meta process only the stated non-PII measurement data under the current tracking choices; name, company, email, phone and form content are not sent to those tracking systems. WhatsApp receives only the content you choose to send after a successful save and handoff click. We do not sell personal data and disclose it to authorities only where permitted or required by law.
6. Security and cross-border processing
Controls include HTTPS, CSRF, contact-field encryption, rate limiting, honeypot, idempotency, a transactional outbox, secrets outside Git, a least-privilege database, restricted backups, and application logs that exclude form payloads, PII and SMTP credentials. Some hosting, Google Workspace, Google tracking, Meta or WhatsApp services may process data outside Malaysia; appropriate contractual, access, security and cross-border safeguards will be applied under applicable law. No network or storage system can guarantee absolute security.
7. Retention, deletion and exceptions
Lead, encrypted attribution, internal lifecycle records and contact data are normally kept for 24 months (730 days) after the last meaningful interaction and then securely deleted on schedule. Authorised staff may record meeting booked, proposal sent and deposit paid against an exact lead reference as the internal audit source; this version does not automatically send those stages to GA4, Google Ads or Meta. If applicable law, accounting records, a dispute, fraud or a security investigation requires longer retention, the exception is documented, use and access are restricted, and the data is deleted when the exception ends. Backups follow the approved expiry policy; restoring a backup does not restart the retention period.
8. Your rights and how to make a request
Subject to applicable law, you may request access, correction, withdrawal of consent, restriction or objection to processing likely to cause damage or distress, an end to direct marketing, or deletion. Email vector@vector-dynamic.com with the subject PDPA Request and enough information to verify the request; do not send employee Payroll data. Withdrawal or deletion may be limited by legal, accounting or dispute-retention obligations.
9. Updates, effective date and contact
Effective date: 4 September 2026. Version: pdpa-v1.4-2026-09-04. Material changes to purposes, data categories, providers, retention or consent will increment the version and, where applicable, seek consent again. Privacy contact: vector@vector-dynamic.com (subject: PDPA Request).