This Personal Data Protection Notice (“Notice”) is issued pursuant to the Personal Data Protection Act 2010 [Act 709], as amended from time to time (“PDPA”).
This Notice explains how:
Sumaiyah Technology Solutions Sdn. Bhd.
Registration No.: 202401049816 (1595660-W)
Trading as: Bereh
collects, records, holds, stores, uses, processes, discloses, transfers and otherwise handles personal data.
This Notice should be read together with the Bereh Privacy Policy, Terms of Service, Service Level Agreement and any applicable contract, quotation, order form or separate notice.
1. Data Controller
For personal data where Bereh determines the purpose and means of processing, the data controller is:
Sumaiyah Technology Solutions Sdn. Bhd.
Registration No.: 202401049816 (1595660-W)
Trading as: Bereh
Website: bereh.com.my
Privacy enquiries: contact@bereh.com.my
Support enquiries: support@bereh.com.my
Where Bereh processes personal data solely on behalf of a customer using the Bereh Digital Workspace, Bereh may act as a data processor, while the relevant customer may act as the data controller.
2. Scope of This Notice
This Notice may apply to:
- website visitors;
- prospective customers;
- customers and subscribers;
- registered users;
- trial and demonstration users;
- customer employees and authorised users;
- suppliers and vendors;
- contractors;
- business partners;
- affiliates and referrers;
- persons making enquiries;
- support users;
- persons whose information is entered into Bereh by a customer; and
- other individuals who interact with Bereh.
3. Personal Data We May Process
Depending upon your relationship with Bereh and the Services used, we may process the following categories of personal data.
3.1 Identification and contact data
This may include:
- name;
- username;
- telephone number;
- WhatsApp number;
- email address;
- correspondence address;
- billing address;
- delivery address;
- identification information where required;
- job title;
- employer;
- company name; and
- other contact information.
3.2 Account and authentication data
This may include:
- account identifiers;
- usernames;
- encrypted or hashed passwords;
- user roles;
- access permissions;
- login history;
- account status;
- authentication records;
- tenant or organisation identifiers; and
- account recovery information.
3.3 Business and operational data
Depending on the modules used, this may include information relating to:
- customers;
- leads;
- suppliers;
- employees;
- products;
- inventory;
- quotations;
- sales;
- invoices;
- receipts;
- payments;
- purchases;
- projects;
- work orders;
- deliveries;
- accounting records;
- appointments;
- communications;
- referrals;
- affiliates;
- documents;
- files;
- notes; and
- attachments.
Some business information may constitute personal data where it relates to an identifiable individual.
3.4 Transaction and payment data
This may include:
- subscription information;
- invoice information;
- amounts paid or payable;
- payment status;
- payment date;
- transaction references;
- refund information;
- billing data; and
- limited payment-related metadata.
Complete banking or payment credentials may be processed directly by third-party payment providers and may not be stored by Bereh.
3.5 Communications data
This may include information contained in:
- emails;
- telephone calls;
- WhatsApp messages;
- support requests;
- enquiries;
- complaints;
- feedback;
- surveys;
- demonstrations;
- training requests; and
- other communications.
3.6 Technical and usage data
This may include:
- internet protocol address;
- browser type;
- device type;
- operating system;
- approximate location derived from an IP address;
- login times;
- pages and features accessed;
- activity records;
- audit logs;
- error reports;
- security logs; and
- performance information.
3.7 Cookies and similar technologies
We may use cookies, local storage, session storage and similar technologies for:
- authentication;
- account security;
- session management;
- preferences;
- service functionality;
- analytics;
- performance; and
- marketing measurement where applicable.
3.8 Sensitive personal data
Bereh does not generally require sensitive personal data unless it is necessary for a specific service or lawful purpose.
You should not submit sensitive personal data unless:
- it is necessary;
- you are authorised to do so;
- an appropriate legal basis exists;
- required notices have been provided;
- required consent has been obtained; and
- suitable safeguards are in place.
4. Sources of Personal Data
Bereh may obtain personal data:
- directly from you;
- through registration forms;
- through the Bereh website;
- through the Digital Workspace;
- through enquiries or communications;
- through subscription or payment activities;
- from your employer or organisation;
- from an authorised account administrator;
- from Bereh customers;
- from affiliates or referrers;
- from payment providers;
- from connected applications;
- from social-media platforms;
- from service providers;
- from lawful public sources; and
- automatically when you use the Services.
Where another person provides your personal data to Bereh, that person is responsible for ensuring that they have appropriate authority to do so.
5. Purposes of Processing
Bereh may process personal data for the following purposes.
5.1 Providing and managing Services
This includes:
- creating and managing accounts;
- authenticating users;
- configuring Digital Workspaces;
- providing subscribed modules;
- processing transactions;
- generating business records;
- maintaining customer accounts;
- managing subscriptions;
- providing demonstrations;
- providing trials; and
- delivering requested functionality.
5.2 Customer support and communications
This includes:
- responding to enquiries;
- providing technical support;
- investigating issues;
- arranging demonstrations;
- arranging training;
- handling complaints;
- providing updates;
- communicating billing matters; and
- maintaining customer relationships.
5.3 Security and fraud prevention
This includes:
- protecting accounts;
- detecting unauthorised access;
- preventing fraud;
- preventing misuse;
- monitoring system security;
- maintaining audit records;
- investigating security incidents;
- enforcing permissions; and
- protecting Bereh and its users.
5.4 Service operation and improvement
This includes:
- maintaining the Services;
- identifying and correcting errors;
- analysing usage;
- improving performance;
- developing features;
- testing functionality;
- producing statistics; and
- improving the user experience.
Where reasonably possible, Bereh may use anonymised or aggregated information for analytics and development.
5.5 Sales and marketing
Subject to applicable law, this includes:
- responding to sales enquiries;
- arranging demonstrations;
- following up with prospective customers;
- providing product information;
- communicating offers;
- administering referrals or affiliate programmes; and
- evaluating marketing effectiveness.
You may opt out of non-essential promotional communications.
5.6 Artificial intelligence and automation
Where an AI-enabled or automated feature is used, relevant information may be processed to:
- generate content;
- draft text;
- summarise information;
- provide suggestions;
- automate workflows;
- classify information; and
- perform other requested automated functions.
Relevant information may be transmitted to an external AI provider where necessary to produce the requested output.
5.7 Social-media publishing
Bereh may process content and technical information to publish approved content to Bereh’s official social-media accounts, including through Meta or Facebook APIs.
The current Meta integration is not intended as a general Facebook Login service or to collect profile information from members of the public who merely view or follow Bereh’s Facebook Page.
5.8 Legal and regulatory purposes
This includes:
- complying with applicable law;
- maintaining financial, tax and corporate records;
- responding to lawful requests;
- investigating suspected misconduct;
- enforcing agreements;
- establishing or defending legal claims; and
- protecting legal rights.
5.9 Other notified purposes
Bereh may process personal data for another purpose that is compatible with the original purpose or that has been separately notified to you.
Where required, Bereh will obtain consent before processing personal data for a materially different purpose.
6. Whether Providing Personal Data Is Mandatory
Some personal data is required for Bereh to:
- create an account;
- provide access to the Services;
- authenticate users;
- process subscriptions;
- process payments;
- provide customer support;
- perform requested functions;
- maintain security;
- comply with legal obligations; or
- administer the customer relationship.
Where required data is not supplied, Bereh may be unable to:
- create or maintain your Account;
- provide certain modules;
- complete a transaction;
- process a request;
- provide support; or
- continue providing some or all of the Services.
Information marked as optional may generally be withheld, although doing so may limit certain features or communications.
7. Disclosure of Personal Data
Bereh may disclose personal data where reasonably necessary and permitted by law to:
- authorised Bereh personnel;
- related service personnel;
- hosting providers;
- cloud infrastructure providers;
- database and storage providers;
- backup providers;
- cybersecurity providers;
- payment processors;
- email and communications providers;
- artificial-intelligence providers;
- Meta and other social-media platforms;
- authentication providers;
- analytics providers;
- contractors;
- consultants;
- professional advisers;
- lawyers;
- accountants;
- auditors;
- insurers;
- relevant customer administrators;
- regulators;
- law-enforcement authorities;
- courts; and
- other parties authorised by you or the relevant customer.
Service providers may process information only for relevant operational purposes, subject to appropriate arrangements where applicable.
Bereh may also disclose personal data where reasonably necessary to:
- comply with law;
- respond to a lawful request;
- prevent or investigate fraud;
- address a security incident;
- protect the rights or safety of Bereh or another person;
- enforce an agreement; or
- establish, exercise or defend a legal claim.
8. Artificial Intelligence Providers
When a user invokes an AI-enabled feature, relevant prompts, instructions, selected records or content may be transmitted to an external AI service provider.
Bereh may use services provided by OpenAI or other AI providers.
Users should not submit personal data, confidential information or sensitive information through an AI feature unless they:
- have authority to do so;
- have a lawful processing purpose;
- have provided required notices;
- have obtained any necessary consent; and
- have assessed whether the information is appropriate for that feature.
AI-generated output should be reviewed before publication or reliance.
9. Meta and Social-Media Services
Bereh currently uses a Meta application to support publishing content from the Bereh Automation module to the official Bereh Facebook Page.
Depending upon the relevant permissions and operation, Bereh may process:
- Page identifiers;
- Page names;
- access tokens;
- publishing permissions;
- post content;
- media;
- post identifiers;
- publication status;
- API responses; and
- technical logs.
Meta processes information independently according to its own terms, policies and systems.
Bereh does not control Meta’s independent data-processing practices.
10. Cross-Border Processing
Some Bereh service providers may process or store information outside Malaysia.
Personal data may therefore be:
- transferred outside Malaysia;
- stored on overseas infrastructure;
- remotely accessed from another country; or
- processed by an overseas service provider.
Bereh will take reasonable steps to ensure that applicable cross-border transfer requirements are addressed, which may include:
- contractual safeguards;
- provider assessments;
- access restrictions;
- encryption;
- security controls;
- transfer assessments;
- consent where appropriate; and
- other measures permitted under applicable law.
Malaysia’s current cross-border transfer guideline explains the conditions under section 129 of the PDPA for transferring personal data outside Malaysia.
11. Security
Bereh uses reasonable administrative, organisational and technical measures intended to protect personal data against:
- unauthorised access;
- unlawful processing;
- loss;
- alteration;
- destruction;
- misuse; and
- unauthorised disclosure.
Measures may include:
- account authentication;
- role-based permissions;
- password controls;
- encryption where appropriate;
- firewalls;
- system logging;
- software updates;
- backups;
- vulnerability remediation;
- access restrictions; and
- incident-response procedures.
No electronic system can be guaranteed to be completely secure.
Users are responsible for protecting their own passwords, accounts, devices, networks and access credentials.
12. External Hosting
Bereh may use external hosting, cloud, storage and infrastructure providers.
Where an external provider experiences a security or infrastructure incident, Bereh will use reasonable efforts to:
- investigate;
- obtain information from the provider;
- contain affected systems;
- protect affected data;
- restore Services;
- restore available backups where reasonably possible;
- notify affected customers; and
- comply with applicable legal notification obligations.
Bereh does not guarantee that all data can be recovered following every destructive incident.
Customers should maintain independent copies of business-critical information where appropriate.
13. Personal Data Breaches
Where Bereh becomes aware of a personal data breach, Bereh may:
- investigate;
- contain the incident;
- preserve relevant evidence;
- assess affected data;
- assess possible harm;
- remediate vulnerabilities;
- notify affected customers;
- notify affected individuals where required; and
- notify the Personal Data Protection Commissioner where required.
Where Bereh acts as a processor, Bereh may notify the relevant customer so that the customer can assess its own obligations.
Malaysia’s current data-breach notification guideline sets out procedures for notifying the Commissioner and affected data subjects where the applicable thresholds are met.
14. Retention
Bereh retains personal data for as long as reasonably necessary to:
- provide the Services;
- maintain customer accounts;
- provide support;
- maintain security;
- comply with legal and financial requirements;
- resolve disputes;
- prevent fraud;
- enforce agreements; and
- maintain appropriate business records.
Retention periods may depend upon:
- the type of information;
- the relevant module;
- customer instructions;
- subscription status;
- legal requirements;
- security needs;
- backup cycles; and
- existing disputes.
Where a Bereh customer remains inactive for six consecutive months, its tenant, workspace, allocated domain resource and Customer Data may become subject to permanent removal, subject to applicable law and mandatory retention obligations.
Customers may request an available data or database export before removal by contacting support@bereh.com.my.
Once data has been permanently deleted and relevant backups have expired or been overwritten, it may no longer be recoverable.
15. Access and Correction
Subject to the PDPA and applicable exceptions, you may request:
- access to personal data held about you; and
- correction of personal data that is inaccurate, incomplete, misleading or not current.
Requests should be submitted to:
contact@bereh.com.my
Your request should include sufficient information to identify:
- you;
- the relevant Account or organisation;
- the personal data concerned; and
- the correction or access requested.
Bereh may require proof of identity or authority before responding.
Where the personal data is controlled by a Bereh customer, Bereh may refer you to that customer.
A fee may be charged where permitted by applicable law.
16. Withdrawal of Consent
Where Bereh relies upon consent, you may withdraw that consent by providing reasonable written notice to:
contact@bereh.com.my
Withdrawal of consent:
- does not affect processing lawfully carried out before withdrawal;
- may be subject to legal or contractual restrictions; and
- may prevent Bereh from continuing to provide Services requiring the relevant information.
17. Direct Marketing
You may request that Bereh stop using your personal data for direct-marketing purposes.
You may opt out by:
- following an unsubscribe instruction;
- replying to the relevant communication; or
- contacting contact@bereh.com.my.
Bereh may retain limited suppression information to ensure that your preference continues to be respected.
Opting out of marketing will not prevent necessary account, billing, security, support or legal communications.
18. Data Deletion Requests
You may request deletion of personal data controlled by Bereh where applicable.
Requests should be submitted to:
contact@bereh.com.my
Bereh may retain information where required or permitted for:
- legal compliance;
- tax and financial records;
- security;
- fraud prevention;
- dispute resolution;
- legal claims;
- protecting another individual’s rights; or
- another lawful purpose.
Where the information is controlled by a Bereh customer, the request may need to be submitted directly to that customer.
Information contained in backups may remain until overwritten or removed through normal backup cycles.
19. Customer-Controlled Data
Bereh customers may enter personal data relating to their:
- customers;
- employees;
- suppliers;
- leads;
- contractors;
- users; and
- other individuals.
In these circumstances, the relevant Bereh customer may determine the purposes for which the information is processed.
Questions or requests concerning such data should generally be directed first to the relevant customer or organisation.
Bereh may assist the customer where reasonably required and technically possible.
20. Accuracy of Personal Data
You are responsible for ensuring that information you provide is accurate, complete and current.
You should notify Bereh where information held directly by Bereh requires correction.
Customers are responsible for the accuracy of Customer Data entered through their Digital Workspace.
21. Changes to This Notice
Bereh may update this Notice to reflect:
- changes in law;
- changes to the Services;
- new modules;
- new integrations;
- changes in service providers;
- operational changes; or
- changes to data-processing practices.
The updated Notice will be published with a revised “Last Updated” date.
Where required, Bereh may provide additional notice through the website, Digital Workspace, email or another appropriate method.
22. Language
This Notice is prepared in English.
Where multiple language versions are provided and an inconsistency arises, the version designated by Bereh will apply to the extent permitted by law.
Nothing in this section overrides a mandatory requirement concerning the language of a personal data notice.
23. Acknowledgement
By providing personal data to Bereh or continuing to use the Services after this Notice has been made available, you acknowledge that you have been informed about the processing described in this Notice.
Where consent is legally required for a particular processing activity, Bereh will rely on an appropriate consent mechanism and not merely upon this acknowledgement.
© 2026 Sumaiyah Technology Solutions Sdn. Bhd.
Registration No. 202401049816 (1595660-W). All rights reserved.
Bereh — Digital Workspace for Growing Businesses.
For questions or requests concerning this PDPA, contact contact@bereh.com.my. For technical or account support, contact support@bereh.com.my.