Privacy Policy

Last updated 20 August 2026 · Version 1.0

1. WHO WE ARE AND WHEN THIS POLICY APPLIES

This Privacy Policy explains how Asteriq Kinesis PLT ("AsteriQ", "we", "us" or "our") collects, uses, discloses, stores, transfers and protects personal data in connection with AsteriQ's Services.

The Services include AttendX, Centre Management, Digital Cards, SiteBuilder and related websites and support services provided through www.asteriqhq.com, attend.asteriqhq.com, centre.asteriqhq.com and www.rezekimu.com, as applicable.

2. OUR ROLE — DATA CONTROLLER AND DATA PROCESSOR

2.1 When AsteriQ Is the Data Controller

AsteriQ generally acts as the data controller for personal data that we collect and use for our own business and operation of the Services, including account registration information, Customer contact information, billing and payment administration, support communications, security and fraud-prevention records, service access logs and information required to manage our relationship with a Customer or user.

2.2 When AsteriQ Is the Data Processor

For business data that a Customer enters into AttendX, Centre Management or SiteBuilder, the Customer normally determines why the data is collected and how it will be used. In those situations, the Customer is generally the data controller and AsteriQ processes the information on the Customer's behalf to provide the Service.

Examples include employee payroll and attendance records, student and parent records, and personal data submitted by visitors through a Customer's website. Where AsteriQ acts as a processor, the Customer is responsible for ensuring that its collection and use of personal data complies with applicable law, while AsteriQ remains responsible for the obligations that applicable law places directly on data processors.

3. WHAT PERSONAL DATA WE PROCESS

3.1 AsteriQ Account and Service Information

  • name, business or organisation name, email address and telephone number;
  • account credentials and authentication information;
  • subscription, billing and payment-administration information;
  • support requests and communications;
  • login information, IP address, browser or device information; and
  • security, fraud-prevention and service logs.

3.2 AttendX

  • employee names and identifiers;
  • employment, salary, allowance, overtime and deduction information;
  • shift, roster, leave and attendance information;
  • clock-in and clock-out timestamps;
  • GPS coordinates associated with clocking events where location verification is enabled;
  • device or browser identifiers;
  • bank account information;
  • EPF, SOCSO/PERKESO, EIS, PCB/MTD and other payroll or statutory information; and
  • other information entered by the Customer that is reasonably required to operate attendance or payroll functions.

3.3 Centre Management

  • student names and dates of birth;
  • parent or guardian names and contact details;
  • class, programme and attendance information;
  • teacher or staff information;
  • payment and transaction records; and
  • other information entered by the centre in connection with managing students and classes.

Some information processed through Centre Management may relate to persons under 18.

3.4 Digital Cards and SiteBuilder

  • names, business or organisation names and job titles;
  • telephone numbers and email addresses;
  • social-media, website and other contact links;
  • photographs, logos, website content and Digital Card content uploaded by users;
  • information submitted through enquiry, registration or contact forms;
  • IP addresses and device/browser information used for security, operation or abuse prevention; and
  • private editing, access or authentication tokens used to manage a Digital Card or website.

Customers are responsible for ensuring that personal data they publish or submit about other persons has been collected and used lawfully.

4. HOW WE COLLECT PERSONAL DATA

Depending on the Service, personal data may be collected:

  • directly from a Customer, account administrator or individual user;
  • from End Users, employees, students, parents or website visitors who use the Services or submit information;
  • from a Customer that uploads or enters information about its staff, students, customers or other authorised persons;
  • automatically from a device, browser or application when a user logs in, clocks in or out, uses location verification, or interacts with the Services; and
  • from service providers that support authentication, hosting, email delivery, security, payments or other operational functions.

5. WHY WE PROCESS PERSONAL DATA

We process personal data where reasonably necessary to provide, operate, secure and support the Services. Purposes may include:

  • creating and administering accounts;
  • authenticating users and managing access;
  • recording attendance and verifying workplace location or beacon proximity where enabled;
  • performing payroll calculations and generating payroll-related reports;
  • managing classes, students, attendance and centre records;
  • hosting websites and Digital Cards;
  • processing enquiries and delivering transactional communications;
  • providing customer support and troubleshooting;
  • maintaining security, preventing misuse, detecting fraud and protecting the integrity of the Services;
  • monitoring system performance and improving reliability and functionality; and
  • meeting legal, regulatory, contractual and recordkeeping obligations.

AsteriQ does not sell personal data to advertisers or other third parties.

6. WHETHER PROVIDING DATA IS REQUIRED

Some personal data is necessary to create an account or operate a particular Service. For example, AttendX cannot perform payroll functions without relevant employee and payroll information, and location verification cannot operate without the required device permission where that feature is enabled.

Where required information is not provided, AsteriQ or the relevant Customer may be unable to create an account, provide the requested feature, complete a transaction or provide part or all of the relevant Service.

Where information is optional, the relevant form, setting or Customer process should identify it as optional where reasonably practicable.

7. ATTENDX LOCATION AND BEACON INFORMATION

AttendX may collect GPS location information in connection with an employee clock-in or clock-out event where location verification is enabled. The purpose is to verify whether the clocking event occurred at or near an authorised work location.

AsteriQ does not use AttendX to continuously collect GPS location unless a specific feature requiring continuous or background location processing is introduced, enabled and clearly disclosed.

AttendX may support Bluetooth beacon technology. A beacon allows a compatible device to detect that it is near a particular workplace beacon. If the feature operates only during clocking, beacon proximity is checked in connection with the clocking event. If a Customer enables a feature that requires background beacon detection, the application may periodically detect proximity while the feature is enabled and the device permits background operation.

AsteriQ will provide appropriate information about any new background location or beacon-processing feature before it is introduced or activated.

8. CHILDREN AND STUDENT DATA

Centre Management is intended to be used by centres and other organisations that manage their own student relationships. The Customer determines what student information it needs to collect and is responsible for providing appropriate privacy information and obtaining parent or guardian permission where required by applicable law.

AsteriQ processes student information on behalf of the Customer for the purpose of operating Centre Management and does not use student information processed on behalf of a Customer for independent advertising purposes.

9. PAYROLL AND FINANCIAL INFORMATION

AttendX may process salary, bank account and statutory information because that information is required to provide payroll functionality. Customers should restrict access to payroll information to authorised personnel and remain responsible for deciding which employees or administrators are permitted to access it.

Customers should promptly remove or update access when a person no longer requires payroll or administrative access.

10. COOKIES AND SIMILAR TECHNOLOGIES

The Services may use cookies, local storage or similar technologies where reasonably necessary for login, authentication, security, preferences, session management and operation of the Services.

Individual websites and Digital Cards created through SiteBuilder may use Google Analytics, Google Tag Manager, Meta Pixel, TikTok Pixel or similar third-party analytics or advertising technologies where the Customer who owns that site or card has enabled them. AsteriQ does not control the cookies or tracking technologies a Customer chooses to enable on their own site, and the Customer is responsible for providing any notice to, or obtaining any consent from, their own visitors as required by applicable law.

If AsteriQ introduces optional advertising, behavioural tracking or non-essential analytics technologies at the platform level, AsteriQ will update this Privacy Policy and implement any consent or choice mechanism required by applicable law.

11. WHERE PERSONAL DATA IS PROCESSED AND CROSS-BORDER TRANSFERS

AsteriQ uses cloud-based technology providers to operate the Services. Our primary application database may be hosted using Supabase, including infrastructure located in Singapore where the relevant project is configured to use that region.

Other service providers, including hosting, content-delivery, security and email providers, may operate infrastructure in Malaysia, Singapore, the United States or other locations. As a result, personal data may be transferred to or processed outside Malaysia.

Where cross-border processing occurs, AsteriQ will take reasonable steps to use an applicable legal basis and safeguards required under Malaysian personal-data-protection law, including appropriate contractual, security and due-diligence measures where required.

12. SERVICE PROVIDERS AND SUB-PROCESSORS

AsteriQ currently uses third-party providers that may include:

  • Supabase — database, authentication and storage infrastructure;
  • Vercel — application and website hosting infrastructure;
  • Cloudflare — DNS, content delivery, network performance and security services; and
  • Resend — transactional email delivery.

These providers process information only as required to provide their respective services to AsteriQ, subject to applicable contracts, privacy terms and security arrangements. Our service-provider list may change as our technology, features and infrastructure develop.

13. WHEN PERSONAL DATA MAY BE DISCLOSED

AsteriQ does not sell personal data. Personal data may be disclosed or made available where reasonably necessary to:

  • provide the Services through AsteriQ's infrastructure, professional advisers and service providers;
  • act on a Customer's lawful instructions where AsteriQ acts as processor;
  • complete billing, support, security or operational activities;
  • protect the security and integrity of the Services;
  • investigate fraud, abuse or security incidents;
  • comply with a legal obligation, court order or lawful request; or
  • protect the legal rights of AsteriQ, Customers, End Users or other persons.

14. DATA SECURITY

AsteriQ recognises the importance of protecting business, employee, payroll and student information. We implement reasonable technical and organisational safeguards appropriate to the nature of the Services and information processed.

Measures may include access controls, authentication, encrypted network communications, system logging, restricted administrative access, infrastructure security controls and backup or recovery arrangements.

No electronic service or internet transmission can be guaranteed to be completely secure. Customers also play an important role in security and should protect credentials, appropriately manage user access, secure their own devices and maintain independent copies of important business records.

15. BACKUPS AND CUSTOMER RESPONSIBILITY

AsteriQ may maintain backups, redundancy and recovery arrangements for the purpose of operating and recovering the Services. These arrangements are part of AsteriQ's infrastructure and should not be treated as the Customer's only archive or statutory recordkeeping system.

Customers should periodically export and securely retain important records. For AttendX in particular, AsteriQ strongly recommends that Customers create an independent export or backup after completing each payroll run and after significant payroll changes, statutory submissions or year-end processing.

Customers remain responsible for meeting legal or operational record-retention requirements that apply to their organisation.

16. HOW LONG WE KEEP PERSONAL DATA

AsteriQ retains personal data only for as long as reasonably required for the purposes for which it is processed, to provide the Services, to maintain security and audit records, to satisfy contractual requirements, or to comply with applicable law.

16.1 Active Business Accounts

Customer Data is generally retained while the relevant Service remains active, subject to the Customer's settings, AsteriQ's technical design and applicable legal requirements.

16.2 After Cancellation or Termination

Following cancellation or termination, Customer Data will normally remain available for up to 30 days to allow the Customer to export its data, unless a shorter period is required for security or legal reasons or a different period is agreed.

After that period, the data may be deleted or anonymised unless longer retention is required by law or another agreed arrangement applies. Residual copies may remain temporarily in backups until replaced through AsteriQ's normal backup and recovery cycle.

16.3 AttendX Clocking Records

Original clocking events may be retained as part of an audit trail and may not be directly overwritten when an administrator makes a correction. An adjustment may instead be recorded separately so that the record history can be identified.

Clocking information is not guaranteed to be retained permanently and remains subject to the Customer account, applicable retention requirements and legal obligations. Customers are responsible for exporting and maintaining records they are independently required to retain.

16.4 Digital Cards

An unclaimed free Digital Card may be unpublished after 14 days. Information associated with an unpublished card may be retained for a limited recovery or claiming period and may then be deleted or anonymised.

17. PERSONAL DATA BREACHES

AsteriQ maintains procedures intended to identify, investigate, contain and respond to security incidents involving personal data.

Where AsteriQ acts as a processor and becomes aware of a personal-data breach involving Customer Data, AsteriQ will take reasonable steps to investigate and inform the relevant Customer so that the Customer can assess and fulfil its obligations as data controller.

Where AsteriQ acts as data controller, AsteriQ will make notifications to the Personal Data Protection Commissioner and affected individuals where required by applicable law.

18. YOUR RIGHTS AND CHOICES

Subject to applicable law and any permitted exceptions, an individual may have rights in relation to personal data for which AsteriQ is the data controller, including the right to request access to and correction of personal data.

Where applicable, an individual may also withdraw consent, object to or prevent certain processing, request that direct-marketing processing stop, or request data portability in accordance with applicable law and subject to technical feasibility and compatibility requirements.

Where the information forms part of an AttendX, Centre Management or Customer SiteBuilder account and AsteriQ processes that information on behalf of a Customer, AsteriQ may refer the request to the Customer that controls the relevant information.

AsteriQ may need to verify the identity and authority of a requester before acting on a request.

19. DATA PROTECTION OFFICER

Where AsteriQ is required under applicable law to appoint or register a Data Protection Officer, the relevant DPO contact information will be made available through this Privacy Policy, the Services or another appropriate channel.

20. CHANGES TO THIS PRIVACY POLICY

AsteriQ may update this Privacy Policy to reflect changes to the Services, technology, service providers, security practices or legal obligations.

Material changes will be identified through an updated date or version number and may be communicated to Customers or users where appropriate.

21. CONTACT

The organisation responsible for this Privacy Policy is Asteriq Kinesis PLT.

Website: www.asteriqhq.com

Email: hello@asteriqhq.com

See also our Terms of Service.