Back to Home
Legal

Privacy Policy

Last updated:

Siap (“we”, “our”, or “us”) is a Field Service Management (FSM) platform developed for Malaysian businesses. We are committed to protecting your personal data and handling it responsibly in accordance with Malaysia’s Personal Data Protection Act 2010 (PDPA). This Privacy Policy explains what information we collect, how we use it, and your rights regarding your data.

1. Information We Collect

When you register and use Siap, we collect the following categories of information:

  • Account Information: Your name, business name, email address, and password when you create an account.
  • Job & Dispatch Data: Work orders, job descriptions, scheduled dates and times, GPS locations of job sites, job status updates, and technician assignments.
  • Customer Data: Names, phone numbers, email addresses, and physical addresses of your end-customers as entered by you or your team members.
  • Photos & Attachments: Images uploaded as job evidence, site photos, or document attachments within the platform.
  • Invoice & Financial Data: Invoice line items, amounts, payment status, and billing contact details.
  • Team Information: Names and roles of technicians and staff accounts created under your organisation.
  • Usage Data: Log data, device information, IP addresses, browser type, and pages accessed, collected automatically to improve our service.

2. How We Use Your Information

We use the information we collect solely to provide and improve the Siap platform:

  • Creating and managing your account and organisation profile.
  • Dispatching jobs to field technicians and enabling real-time status updates.
  • Generating, storing, and sharing invoices with your customers.
  • Enabling offline-first data synchronisation across your team’s devices.
  • Sending transactional communications such as account verification and password reset emails.
  • Monitoring platform performance, diagnosing bugs, and improving features.
  • Complying with applicable Malaysian laws and regulations.

We do not sell, rent, or share your personal data or your customers’ data with third parties for marketing purposes.

3. Data Storage & Security

Your data is stored securely using enterprise-grade cloud infrastructure:

  • Encryption at rest and in transit: All data is encrypted using AES-256 at rest and TLS 1.2+ in transit.
  • Access controls: Access to production data is strictly limited to authorised personnel on a need-to-know basis.
  • PDPA Compliance: We process personal data in accordance with the seven principles of the Personal Data Protection Act 2010, including the General, Security, Retention, Data Integrity, Access, Disclosure, and Correction Principles.
  • Data Retention: Your account data is retained for as long as your subscription is active. Upon account deletion, data is purged within 30 days, unless retention is required by law.

While we employ industry-standard measures, no system can guarantee absolute security. We encourage you to use a strong, unique password and to report any suspected security incidents to us immediately.

4. Third-Party Services

Siap uses the following trusted third-party services to deliver its functionality:

  • Supabase: Provides our backend database, authentication, and file storage infrastructure. Data is processed under Supabase’s data processing agreement in compliance with GDPR and international standards. Supabase Privacy Policy ↗
  • PowerSync: Enables offline-first data synchronisation for our mobile and desktop clients. PowerSync Privacy Policy ↗
  • Expo (Expo Application Services): Used to build, distribute, and update our mobile application. Expo Privacy Policy ↗

5. Your Rights

Under the PDPA and our own commitment to user privacy, you have the following rights:

  • Right of Access: You may request a copy of the personal data we hold about you.
  • Right to Correction: You may request that we correct inaccurate or incomplete personal data.
  • Right to Withdraw Consent: Where processing is based on consent, you may withdraw it at any time.
  • Right to Deletion: You may request deletion of your account and associated personal data, subject to legal retention obligations.
  • Right to Limit Processing: You may request that we restrict how we process your data in certain circumstances.

To exercise any of these rights, please contact us using the details below. We will respond to verified requests within 21 days as required under the PDPA.

6. Cookies & Tracking

Siap uses essential cookies and local storage to maintain your authenticated session. We do not use advertising cookies or third-party tracking pixels. You may disable cookies in your browser settings; however, doing so may prevent you from logging in or using core features of the platform.

7. Changes to This Policy

We may update this Privacy Policy from time to time. We will notify you of significant changes by email or by displaying a prominent notice within the platform. Continued use of Siap after any changes constitutes your acceptance of the updated policy. The “Last updated” date at the top of this page will always reflect the most recent revision.

8. Contact Us

If you have any questions, concerns, or requests regarding this Privacy Policy or the handling of your personal data, please contact our Data Protection Officer:

Siap Technologies, Malaysia