Last updated: 10 September 2026
This Privacy Notice explains how Praxis Systems Sdn. Bhd. collects, uses, discloses, stores and protects Personal Data when Praxis acts as a Data Controller. It also explains your rights and how to contact us.
Praxis Systems Sdn. Bhd. (202601029878 (1691973-D)) is the Data Controller responsible for this Notice.
Registered address: 7-2, Plaza Danau 2, Jalan 2/109F, Taman Danau Desa, Kuala Lumpur, Wilayah Persekutuan Kuala Lumpur, Malaysia.
Privacy and legal enquiries: legal@praxissystems.my
In this Notice, Praxis, we, us and our refer to Praxis Systems Sdn. Bhd.
This Notice applies to Personal Data Praxis processes as Data Controller in connection with our websites; accounts; subscriptions, billing and payments; communications and support; sales and business enquiries; events and programmes; security and fraud prevention; business administration; Praxis Integrity and other verification services where Praxis determines the continuing purpose; and other interactions where Praxis determines why and how Personal Data is processed.
It does not generally govern Personal Data within customer assessments, uploaded evidence, client matters or regulatory workspaces where Praxis acts only on a customer's instructions. That processing is governed by the Data Processing Agreement and the customer's own privacy obligations.
Applicable Data Protection Law means the Malaysian Personal Data Protection Act 2010 as amended, including the Personal Data Protection (Amendment) Act 2024, and any other privacy or data-protection law that applies to the relevant processing.
Data Controller means the person that determines the purposes and means of processing Personal Data, including a data controller under the Malaysian Personal Data Protection Act 2010.
Data Processor means a person that processes Personal Data on behalf of a Data Controller.
Personal Data means information relating directly or indirectly to an identified or identifiable individual.
Sensitive Personal Data has the meaning in Applicable Data Protection Law and may include information concerning health, physical or mental condition, political opinions, religious or similar beliefs, the commission or alleged commission of an offence, and other categories designated by law.
Praxis is a business-to-business regulatory intelligence platform for businesses, professional practices, law firms, consultants, privacy and compliance professionals, corporate teams and other institutional users. The Services are not primarily intended for personal, domestic or household use and are not directed to children.
Depending on how you interact with Praxis, we may collect:
Payment card or banking credentials may be collected directly by payment providers. Praxis normally receives only limited confirmation, reference, amount and method information.
Customers may submit information about employees, clients, customers, suppliers or other individuals for privacy assessments, Data Protection Impact Assessments, transfer assessments, regulatory research, breach management, audits, compliance workflows, questionnaires, documents and evidence.
Where the customer decides why that Personal Data is processed, the customer is the Data Controller or a Data Processor for another Controller, and Praxis is its Data Processor or Subprocessor. Praxis does not become the Data Controller merely because the information passes through our technology.
If your information was entered by a Praxis customer, direct your request to that organisation. If you contact Praxis, we may refer the request to the relevant customer unless law requires otherwise.
We obtain Personal Data directly from you; from your organisation when it creates or manages an account; from payment and service providers supporting our operations; from limited publicly available professional sources used for legitimate business communications; and automatically through use of the websites and Services.
We process Personal Data for purposes reasonably connected with our business and Services, including to create and administer accounts; authenticate users and manage permissions; provide purchased Services; enforce capacity entitlements; prepare quotations and invoices; collect payments and maintain financial records; provide support; operate, secure and troubleshoot systems; prevent fraud and misuse; improve reliability and usability; communicate operational notices; comply with law; establish or defend legal rights; and administer our business.
Where practicable, we use aggregated or anonymised information for improvement. Customer Personal Data and Customer Confidential Information are not used to train Praxis or third-party general-purpose artificial intelligence models.
Depending on the circumstances, we process Personal Data with consent or where necessary to perform or prepare a contract, comply with a legal obligation, protect vital interests, administer justice, or pursue a legitimate purpose that is not prejudicial to your rights, as permitted by Applicable Data Protection Law.
Required fields are identified at collection. If you do not provide required information, we may be unable to create an account, provide a Service, process payment, maintain the relationship or respond. Marketing consent is optional and is never a condition of purchasing the core Services.
We may offer information about products, updates, research, events, programmes and publications. Where consent is required, we ask separately. You may unsubscribe through the communication or by contacting legal@praxissystems.my. Operational, security, billing and contractual messages may continue where necessary.
Certain Services use artificial intelligence and automated systems to support regulatory research, extraction, classification, assessment and generation of Outputs. Production inference may use models operated on infrastructure controlled by Praxis. If a hosted third-party AI provider is used to process Customer Personal Data, it will be governed by the DPA and subprocessor notice process.
Praxis does not sell Customer Personal Data to AI providers and does not permit Customer Personal Data or Customer Confidential Information to train third-party general-purpose AI models.
Praxis systems support professional human decision-making. They may generate assessments, classifications, scores, research results or recommendations, but are not intended by themselves to make legally binding or similarly significant decisions about individuals. Customers remain responsible for human review and decisions using Outputs.
Where Praxis itself uses automated decision-making or profiling in circumstances that give you rights under Applicable Data Protection Law, we will provide required information, a means to object or refuse where applicable, and access to human review.
Praxis does not seek Sensitive Personal Data in ordinary account, sales or support interactions. Please do not include it unless necessary. It may nevertheless be provided incidentally, or appear in customer workspaces because regulatory assessments concern such processing.
Where Praxis acts as Data Controller, we will obtain explicit consent or rely on another condition permitted by law before processing Sensitive Personal Data. Where Praxis acts as Data Processor, the customer is responsible for the necessary notices, explicit consent or other lawful condition, and Praxis applies the DPA safeguards.
We do not sell Personal Data or disclose it for third-party behavioural advertising. We may disclose limited Personal Data where reasonably necessary to:
Material processors of Customer Personal Data are identified in Schedule 3 of the Praxis Data Processing Agreement, which is the single source of truth for the current subprocessor list. Locally operated software and AI models are not separate recipients or subprocessors.
Praxis is established and primarily operates in Malaysia. Our core production systems and locally operated AI inference are hosted on infrastructure controlled by Praxis in Malaysia. Some providers may process or transmit limited Personal Data outside Malaysia, including internet-edge, email and payment data.
Where section 129 of the Malaysian Personal Data Protection Act 2010 applies, we take reasonable steps to use a permitted transfer condition and appropriate safeguards. These may include evaluating the destination and recipient, contractual and technical safeguards, a transfer-impact assessment, consent where appropriate, or another lawful condition. Foreign laws may require additional mechanisms.
Our public website uses essential technologies needed to provide pages, secure sessions and remember basic preferences. It does not currently use non-essential analytics or advertising cookies. Authenticated products may use essential session, security and preference technologies needed to provide the Services.
If Praxis introduces non-essential analytics, advertising or similar tracking that requires notice or consent, we will update the applicable cookie information and obtain consent where required. Customer Personal Data is not used for third-party behavioural advertising.
See our Cookie Notice for further detail on how this website uses cookies.
We maintain reasonable administrative, technical and organisational measures designed to protect Personal Data against loss, misuse, unauthorised or accidental access or disclosure, alteration, destruction and other unlawful processing. Measures are proportionate to the nature of the data, foreseeable threats and available technology.
No method is completely secure. You must protect your credentials, use available multi-factor authentication and notify us promptly of suspected compromise.
We maintain processes for identifying, assessing and responding to Personal Data Breaches. Where Praxis is the Data Controller and a breach causes or is likely to cause significant harm, we will notify the Personal Data Protection Commissioner as soon as practicable and within 72 hours after becoming aware, and notify affected individuals without unnecessary delay and within seven days after notifying the Commissioner, subject to Applicable Data Protection Law and official guidance.
Where Praxis acts as Data Processor for Customer Personal Data, we will notify the affected customer without undue delay and in any event within 24 hours after becoming aware of a suspected breach, to the extent legally permitted, and provide available information under the DPA.
We retain Personal Data only as long as necessary for the stated purpose, legal requirements, security and claims. Unless a longer or shorter period is required by law or reasonably necessary for a documented legal, security or claims reason, our current target periods are:
After termination, Praxis uses reasonable efforts to email a Customer Data export link within 48 hours after the termination process is completed. The customer has 30 days from the email to download it. Customer Personal Data is then deleted from active systems unless a lawful exception applies. Backup copies are deleted or overwritten no later than 60 days after the 30-day retrieval period ends.
Subject to conditions and exemptions under Applicable Data Protection Law, you may ask whether we process your Personal Data; request access and a copy; correct inaccurate, incomplete, misleading or outdated data; withdraw consent; prevent processing likely to cause damage or distress; object to direct marketing; and make a data-portability request.
The Malaysian data-portability right under section 43A is in force and permits a written electronic request for direct transmission to another Data Controller, subject to technical feasibility, compatible formats and any prescribed requirements. We will respond within the applicable statutory period.
To exercise a right, email legal@praxissystems.my with enough detail to identify the information. We may verify identity and may charge only a fee permitted by law. If the information is controlled by a customer, we will normally refer you to that customer.
We take reasonable steps to keep Personal Data accurate, complete, not misleading and up to date for its purpose. Please update account details or contact us when information changes.
The Services are not directed to children and we do not knowingly collect Personal Data from a person under 18 in our independent Data Controller capacity. If you believe a child has provided such information, contact us. Customer workspace data involving a child remains the customer's responsibility as Controller, including parental consent or other lawful authority.
Personal Data may be disclosed for legitimate due diligence, financing, investment, reorganisation, merger or sale, subject to confidentiality and data-protection safeguards. We may also disclose information to comply with a binding request, court order or law, and will limit disclosure and notify the affected person where legally permitted and appropriate.
Praxis does not sell Personal Data; does not disclose it to data brokers or advertisers for their independent marketing; does not use Customer Personal Data for third-party behavioural advertising; and does not permit Customer Personal Data or Customer Confidential Information to train general-purpose AI models.
Not every organisation must appoint a Data Protection Officer. Praxis will assess its operations against the statutory thresholds, including the number of data subjects, volume of Sensitive Personal Data and any regular and systematic monitoring. If appointment becomes mandatory, Praxis will appoint and register a qualified Data Protection Officer within the required period and publish current business contact details.
Until then, privacy enquiries and rights requests should be sent to legal@praxissystems.my. This statement does not represent that a statutory Data Protection Officer has already been appointed.
We may update this Notice as our practices, Services or the law change. The updated date will show the current version. Where a change materially affects existing processing, we will provide appropriate notice before it takes effect where practicable and legally required.
Please send complaints first to legal@praxissystems.my so we can investigate. You may also complain to the Personal Data Protection Commissioner or the Personal Data Protection Department through www.pdp.gov.my.
This Notice is issued in English and Bahasa Malaysia to comply with applicable notice requirements. Both versions are intended to have the same substance. If an inconsistency arises, the English version prevails to the extent permitted by law.
Contact: legal@praxissystems.my