01Scope and our role
This Privacy & Personal Data Protection Notice explains how NexSense collects, uses, discloses, stores and protects personal data through its website, NexCircle, NexAccess, portals, applications, support and related services.
For website enquiries, sales, account administration and NexSense’s own operations, NexSense generally acts as a data controller. When a merchant manages information about its customers, tenants, students, parents, staff, members or visitors, the merchant generally acts as data controller and NexSense processes that data for the merchant as data processor or technology provider. The exact role depends on the deployment and agreement.
02Personal data we may process
Depending on the Service, this may include identity and contact details; organisation, branch, property, unit and user-role information; customer, tenant, student, parent, member or staff account links; recurring charges, bills, receipts and transaction metadata; access and attendance events; IP address, device, browser, security and diagnostic logs; and communications with NexSense.
03How we obtain data
We may obtain data directly from you, from the merchant or organisation that creates or manages your account, from authorised administrators, from devices connected to NexAccess, and from service providers such as payment gateways and messaging or email providers.
04Purposes of processing
We process personal data to provide, configure, support and secure the Services; administer accounts, bills, reminders, receipts, payment status, transaction records, access permissions and attendance; respond to enquiries and support; prevent fraud and misuse; improve reliability; meet legal, audit and dispute obligations; send service messages; and, where permitted, share relevant NexSense information. You may opt out of marketing at any time.
05Consent, notice and choice
We process personal data with consent where consent is required, to provide requested or contracted Services, and for other purposes permitted by the Personal Data Protection Act 2010 (Act 709), as amended, and applicable law. If you provide another person’s data, you confirm that you are authorised to do so and have given any required notice.
06Children and dependent accounts
NexCircle may be used by tuition centres, kindergartens and childcare providers. The merchant is responsible for obtaining parent or guardian authority and providing suitable notices before entering a child’s personal data. Children should not submit personal data directly through the public website without parent or guardian involvement.
07Payment information
Online payment entry and processing take place through the merchant’s independent payment gateway under its own privacy notice. NexSense generally receives transaction metadata needed to update status and records, such as amount, payment-method category, gateway reference and result—not a customer’s full card number, online-banking password or eWallet credentials.
08Access and biometric data
Where face recognition is enabled, the deployment may process facial images or biometric templates for identity verification and access control. Biometric data is treated as sensitive personal data. Depending on deployment, it may be held on the merchant’s premises or systems, with NexSense acting as technology provider or processor. The merchant must establish a lawful purpose, give clear notice, obtain consent where required, limit access and provide an appropriate alternative where required by law or agreement.
09Disclosure and service providers
We may disclose data only as reasonably required to the relevant merchant and authorised users; payment gateways, banks and payment-method providers; hosting, communications, email, security, device and support providers; professional advisers and auditors; a genuine corporate successor; and regulators, courts or authorities where required or permitted by law. Providers are expected to use data only for the agreed purpose and with appropriate safeguards.
10Cross-border processing
Some service providers may process data outside Malaysia. Where personal data is transferred across borders, NexSense will take reasonable steps required by applicable law to ensure an adequate level of protection, including contractual and security safeguards and any required notice or consent.
11Security
We use reasonable technical and organisational measures appropriate to the data and deployment. These may include access controls, encryption in transit, password protection, logging, backups, environment separation, provider review and incident procedures. No electronic system is completely secure, so users must also protect their credentials and devices.
12Retention
We retain personal data only for as long as needed for the stated purpose, merchant relationship, security, dispute handling and legal, accounting or audit requirements. Periods vary by data type and agreement. When data is no longer required, we take reasonable steps to delete, destroy or anonymise it, subject to backups and legal holds.
13Your choices and rights
Subject to the PDPA and applicable exceptions, you may ask about processing, request access or correction, withdraw consent, object to direct marketing, or raise a concern. If your data is controlled by a merchant, contact that merchant first; NexSense will support the merchant where required. We may verify identity before responding and may refuse or limit a request where law permits.
14Website technology
The current public website stores a language preference in your browser so it can display English or Bahasa Malaysia. Web hosting and security systems may also create routine server logs such as IP address, browser and request time. If analytics or non-essential cookies are introduced later, this Notice and any consent controls will be updated as required.
15Data incidents
We maintain procedures to assess and respond to suspected personal-data breaches. NexSense and the relevant merchant will cooperate according to their roles, and the responsible data controller will notify the Personal Data Protection Commissioner and affected data subjects where required by applicable law.
16Merchant responsibilities
Each merchant must provide its own privacy notice where required, collect only necessary data, maintain accurate records, manage authorised users, obtain valid consent or other authority, configure suitable retention, respond to data-subject requests and use NexSense consistently with law. This is especially important for financial information, children’s data, employee monitoring and biometric access.
17Updates and contact
We may update this Notice when our Services, providers or legal obligations change. The revised date will be shown at the top and material changes may also be communicated through the Services or to the registered business contact.
For privacy questions, access or correction requests, contact sales@nexsense.com.my. Include your name, the merchant or organisation involved and enough detail to locate the relevant record. You may also contact Malaysia’s Personal Data Protection Commissioner at www.pdp.gov.my.
