Loading data protection framework
Legal / Privacy Policy

How TheManager collects, uses, discloses, and protects personal data under Malaysia's Personal Data Protection Act 2010, as amended by the Personal Data Protection (Amendment) Act 2024.

Effective date: 20 August 2026  ·  Last reviewed: 20 August 2026

Notice

This policy is published as a good-faith description of TheManager's current data practices. It has not yet been reviewed by a Malaysian-qualified data protection lawyer. Items marked [review] below need attorney or operational sign-off before this policy should be treated as final.

01
Scope

Who this policy applies to.

This Privacy Policy applies to personal data processed through TheManager's platform (themanagers.app and related domains), including our corporate website, client applications, and the modules our client organizations (“Tenants”) activate — Human Resources, Finance, Procurement, Cooperative Management, Ar-Rahnu, Gold & Silver Savings, Asset Management, Budgeting, Energy Management, E-Commerce, Travel & Tourism, and related services.

It covers two distinct groups of people, because our role — and your rights — differ between them:

  • Visitors and prospective customers of our corporate website and sales process (you, browsing this site or requesting a demonstration).
  • Tenant end-users — the employees, members, customers, or other individuals whose data a Tenant organization processes using TheManager's platform.
02
Our Role

Controller vs. processor.

Under the PDPA, the entity that determines the purposes and manner of processing personal data is the “data user” (equivalent to a “controller” under other data protection laws); an entity that processes data solely on that data user's instructions is generally treated as a processor.

Where we are the data user: for data collected directly through our corporate website (contact forms, demo requests, newsletter sign-ups) and our own account/billing relationship with Tenant organizations.

Where we act on a Tenant's instructions: for the personal data a Tenant organization uploads into or generates within its own workspace. The Tenant is the data user for that data, and is responsible for having its own lawful basis and privacy notice covering its own employees, members, and customers. If your data was entered by a Tenant, please direct data protection requests to that organization first; we support Tenants in responding to such requests.

Two aspects of our service go beyond pure processor status: our AI-assisted document processing applies automated extraction techniques we design and operate, not merely storage on instruction; and our Payslip Verifier Portal independently manages verification requests from third parties (such as banks) who are not necessarily the Tenant's own personnel.

03
Data We Collect

Personal data categories.

Depending on which modules a Tenant activates, personal data processed through the platform may include:

  • Identity data: name, NRIC/passport number and images, date of birth, nationality, citizenship/Bumiputera status where relevant to cooperative or government-linked reporting.
  • Contact data: address, phone number, email address.
  • Employment data: job title, department, employment history, dependents' information for statutory benefit purposes.
  • Financial data: bank account details, salary, payroll records, cooperative share capital, Ar-Rahnu pledge and transaction records, Gold & Silver Savings holdings.
  • Location data: geofenced attendance clock-in/out coordinates, where enabled.
  • Identity verification data: documents and extracted data used for eKYC across regulated financial modules.
  • Authentication data: WebAuthn/passkey public key credentials — underlying biometric data is processed on your own device and never transmitted to or stored by TheManager.
  • Health data (Nutritionist module): dietary and weight logs, medical profile information.
  • Website usage data: pages visited, demo requests, and contact form submissions.

We do not collect every category for every individual — it depends entirely on which modules the relevant Tenant has activated.

04
Sensitive Data

Sensitive personal data.

The PDPA defines certain categories as “sensitive personal data” — including health data, religious beliefs, and data relating to the commission of an offence — requiring explicit consent. TheManager may process:

  • Health and medical data (Nutritionist module).
  • Data connected to religious financial practices — Zakat, Infaq, and Islamic financing records (Ar-Rahnu, Cooperative Financing) — to the extent these reveal religious affiliation.

Where sensitive personal data is processed, explicit consent is obtained by the relevant Tenant organization before it is entered into the platform. [review: confirm consent-capture UI exists at point of data entry for every sensitive-data module — only Cooperative Membership currently has an explicit consent field in the schema]

05
How We Use It

Purposes of processing.

  • Provide, operate, and maintain the specific modules a Tenant has activated.
  • Process payroll, statutory, and financial calculations as configured by the Tenant.
  • Verify identity for eKYC and regulated financial products.
  • Extract and structure data from uploaded documents using AI-assisted OCR (currently Google Gemini) to reduce manual data entry.
  • Operate geofenced attendance verification where enabled.
  • Respond to demonstration requests and communicate with prospective and current customers.
  • Maintain security, audit logs, and prevent fraud across the platform.

We do not sell personal data. [review: confirm no-model-training statement against the actual AI provider data-processing terms before publishing]

06
Legal Basis

Consent & lawful processing.

Where TheManager is the data user, we process personal data based on: your consent (demo requests, marketing communications), the necessity of processing to perform a contract with you or your organization, and our legitimate interests in operating and securing the platform.

Where a Tenant organization is the data user, that organization is responsible for establishing its own lawful basis, including obtaining explicit consent for sensitive personal data, before entering it into the platform.

07
Disclosure

Who we share data with.

  • Payment processors: Stripe, Billplz, and ToyyibPay.
  • AI/document processing: Google Gemini, for OCR and document data extraction.
  • Cloud infrastructure: Amazon Web Services, Google Cloud Platform, and Cloudflare.
  • Email delivery: the Tenant organization's own configured email provider.
  • Travel service providers: Amadeus and Duffel, where the Travel & Tourism module is active.
  • Regulators and authorities: where required by law, including LHDN, EPF, SOCSO, SKM, and BNM as applicable.

We require third parties to protect personal data consistent with this policy and do not disclose data for their own independent marketing purposes.

08
Cross-Border

International data transfers.

Personal data is currently hosted outside Malaysia — our primary database is hosted in Singapore (AWS ap-southeast-1) and AI-processing infrastructure runs in Taiwan (Google Cloud asia-east1). This is a cross-border transfer under Section 129 of the PDPA.

Following the Personal Data Protection (Amendment) Act 2024, Malaysia removed the previous “whitelist” approach — transfers now require the receiving jurisdiction to have substantially similar or adequate protection, or another lawful basis such as consent. [review: obtain a documented adequacy/safeguards assessment for Singapore and Taiwan hosting under the Commissioner's recently issued cross-border transfer guidelines]

09
Retention

How long we keep data.

  • HR and payroll records: retained 6–7 years following the end of employment, per the Employment Act 1955, LHDN, EPF, and SOCSO requirements.
  • Payslip Verifier Portal records: retained 7 years, then archived and securely purged, subject to safeguards for pending verification requests.
  • Identity/KYC documents: retained for the duration required by the applicable regulated module, then securely deleted.

Retention and deletion are enforced through automated, scheduled processes, in addition to manual review where required.

10
Security

How we protect data.

  • Encryption of sensitive identity documents at rest (AES-256-GCM).
  • Multi-tenant data isolation, enforced at the data layer, not only the interface.
  • Role-based access control restricting data access to what a role requires.
  • Passkey/WebAuthn biometric authentication support alongside passwords.
  • Full audit logging of sensitive data access and administrative actions.
  • Cryptographic signing and independent verification for legally significant documents.

No system is completely secure, and we cannot guarantee absolute security of information transmitted to us.

11
Your Rights

What you can ask us to do.

  • Access the personal data we (or, where applicable, the relevant Tenant) hold about you.
  • Correct inaccurate or incomplete personal data.
  • Withdraw consent to processing based on consent.
  • Limit processing for purposes you have not agreed to.
  • Data portability, subject to technical feasibility, following the 2024 Amendment Act.
  • Prevent processing likely to cause damage or distress.

If your data was entered by your employer or another Tenant, direct your request to that organization first. Where TheManager processes data you gave us directly, contact us via Section 17 below. [review: DSAR handling is currently manual, with an automated endpoint planned but not built — confirm this section reflects actual, not aspirational, capability]

12
Governance

Data Protection Officer.

Following the Personal Data Protection (Amendment) Act 2024, appointment of a Data Protection Officer is mandatory for qualifying data users and processors. [review: confirm whether TheManager meets the qualifying thresholds and appoint a DPO meeting the residency and language requirements before finalizing]

Data Protection Officer contact: [placeholder — to be completed]

13
Incident Response

Data breach notification.

Following the 2024 Amendment Act, we are required to notify the Personal Data Protection Commissioner within 72 hours of becoming aware of a data breach causing significant harm, and to notify affected individuals without unnecessary delay where significant harm is likely. We maintain an internal breach-response process to support this obligation. [review: confirm the internal breach-response runbook is documented and tested, not only the database-level breach log table]

14
Cookies

Cookies & similar technologies.

Our corporate website may use cookies and similar technologies to remember your preferences and understand how visitors use the site. [placeholder — complete once a cookie/analytics vendor is selected; none found in the current codebase]

15
Minors

Children's data.

Our corporate website and platform are not directed at children, and we do not knowingly collect personal data directly from children. Where a Tenant records dependents' data (including children) for statutory benefit purposes, that data is entered and controlled by the Tenant, and used solely for that administrative purpose.

16
Updates

Changes to this policy.

We may update this Privacy Policy to reflect changes in our practices or legal requirements. We will post the updated policy here with a revised “Last reviewed” date. Material changes will be communicated to Tenant organizations directly.

17
Contact

Get in touch.

If you have questions about this Privacy Policy or how we handle personal data, please contact us:

TheManager
Kuala Lumpur, Malaysia
Contact form

// FINAL_CALL

Questions about how we handle your data?

Reach out and our team will point you to the right answer, or the right Tenant to ask.